Moin, hier nochmal das FRST Log aus dem normalen Modus.
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 01-04-2025
durchgeführt von quart (Administrator) auf CORTEX (LENOVO 82DS) (06-04-2025 07:55:54)
Gestartet von E:\tools\FRST64.exe
Geladene Profile: quart
Plattform: Microsoft Windows 11 Pro Version 24H2 26100.3624 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Anthropic, PBC -> Anthropic) C:\Users\quart\AppData\Local\AnthropicClaude\app-0.9.1\claude.exe <10>
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveCrashHandler64.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\bckp_amgr.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\monitoring-mini.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\sh-inventory.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\task-manager.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH.) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\adp-agent.exe
(C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe ->) (Acronis International GmbH -> Acronis International GmbH.) C:\Program Files (x86)\Common Files\Acronis\Agent\bin\updater.exe
(C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantage-(GenericMessagingAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantage-(LenovoServiceBridgeAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantage-(SmartDisplayAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantage-(VantageCoreAddin).exe
(C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe ->) (Native Instruments GmbH -> ) C:\Program Files\Common Files\Native Instruments\NTK\crashpad_handler.exe
(C:\Program Files\GamingIntelligence\MonitorMicroKeyDetector.exe ->) (Micro-Star International CO., LTD. -> MSI) C:\Program Files\GamingIntelligence\OSDPopupHandler.exe
(C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\106.0.4.0\crashpad_handler.exe
(C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe
(C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (DroidMonkey Apps, LLC -> ) C:\Program Files\KeePassXC\keepassxc-proxy.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.4.0_x64__8wekyb3d8bbwe\WsaClient\WsaClient.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.4.0_x64__8wekyb3d8bbwe\WSACrashUploader\WSACrashUploader.exe
(D:\Portable\PortableApps\Notepad++Portable\Notepad++Portable.exe ->) (Notepad++ -> Don HO don.h@free.fr) D:\Portable\PortableApps\Notepad++Portable\App\Notepad++64\notepad++.exe
(D:\Portable\PortableApps\PortableApps.com\PortableAppsPlatform.exe ->) (RARE IDEAS, LLC -> PortableApps.com) D:\Portable\PortableApps\Notepad++Portable\Notepad++Portable.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxEM.exe
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_d59c8b8a329853e4\DAX3API.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~1.INF\DAX3API.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\FnHotkeyUtility.exe
(DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\SmartSense.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\SmartSenseController.exe
(DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\SmartSense.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\UserSSCtrl.exe
(explorer.exe ->) (50BDFD77-8903-4850-9FFE-6E8522F64D5B -> OpenAI) C:\Program Files\WindowsApps\OpenAI.ChatGPT-Desktop_1.2025.90.0_x64__2p2nqsd0c76g0\app\ChatGPT.exe <5>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Marti Climent Lopez -> ) C:\Program Files\UniGetUI\UniGetUI.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2501.31.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(explorer.exe ->) (Microsoft Corporation -> MSPCManager) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.16.2.0_x64__8wekyb3d8bbwe\PCManager\MSPCManager.exe
(explorer.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareAccessibilityHelper.exe
(Lenovo -> Lenovo) C:\ProgramData\Lenovo\Vantage\AddinData\LenovoBatteryGaugeAddin\x64\QSHelper.exe
(LNBITSSvc.exe ->) (Lenovo -> Lenovo(beijing) Limited) C:\Windows\System32\AutoModeDetect.exe
(Microsoft Corporation -> MSPCManagerCore) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.16.2.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerCore.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files\HESSENBOX\HESSENBOX\jre\bin\javaw.exe
(RARE IDEAS, LLC -> PortableApps.com) D:\Portable\PortableApps\PortableApps.com\PortableAppsPlatform.exe
(services.exe ->) (Acronis International GmbH -> ) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files\Acronis\CyberProtect\cyber-protect-service.exe
(services.exe ->) (Acronis International GmbH -> Acronis International GmbH) C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_d59c8b8a329853e4\DAX3API.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_82b77f8c4618e2d0\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_9cf4db1a1fd1b22d\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_f854c91489b3fbb5\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_f854c91489b3fbb5\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_ece153ca769ec179\aesm_service.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
(services.exe ->) (Intel Thunderbolt(TM) Technology -> ) C:\Windows\TbtP2pShortcutService.exe
(services.exe ->) (Intel Thunderbolt(TM) Technology -> Intel Corporation) C:\Windows\ThunderboltService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) Trust Services -> Intel(R) Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (Lenovo -> Lenovo(beijing) Limited) C:\Windows\System32\LNBITSSvc.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\SmartSense.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.4.0_x64__8wekyb3d8bbwe\WsaService\WsaService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\GameInputSvc.exe <2>
(services.exe ->) (Microsoft Corporation -> MSPCManagerService) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.16.2.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Locator.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_071505319ec619da\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e9f6c354061743a4\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\IAS\IntelAudioService.exe
(services.exe ->) (Texas Instruments Inc. -> Texas Instuments) C:\Windows\System32\TISmartAmpService.exe <2>
(sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(sihost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2503.28002.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\MicrosoftSecurityApp.exe
(sihost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.4.0_x64__8wekyb3d8bbwe\WsaClient\WsaClient.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25022.57.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(svchost.exe ->) (Adobe Systems Incorporated -> ) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.25.340.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.Todos_2.114.7122.0_x64__8wekyb3d8bbwe\Todo.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> ) C:\Program Files\GamingIntelligence\mysticlight\MysticLightController.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> MICRO-STAR INT'L,.LTD.) C:\Program Files\GamingIntelligence\GamingIntelligence.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> MSI) C:\Program Files\GamingIntelligence\MonitorMicroKeyDetector.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> MSI) C:\Program Files\GamingIntelligence\WeatherDetector.exe
(vmcompute.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\vmwp.exe
konnte nicht auf den Prozess zugreifen -> vmmemWSA
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e9f6c354061743a4\RtkAudUService64.exe [1270344 2021-07-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [643584 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3952720 2022-06-01] (Microsoft Windows Hardware Compatibility Publisher -> Logitech, Inc.)
HKLM-x32\...\Run: [XPE] => C:\Program Files (x86)\XPE Windows 10 DPI Fix\XPEWindows10_DPI.exe [28672 2015-08-21] (XPExplorer.com - 2015) [Datei ist nicht signiert]
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [2044576 2023-12-13] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6597048 2025-01-17] (Acronis International GmbH -> )
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe [443472 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
HKLM\...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [UploadUserActivities] 0
HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe [65444448 2025-04-02] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe [65444448 2025-04-02] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe [65444448 2025-04-02] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [LenovoVantageToolbar] => C:\ProgramData\Lenovo\Vantage\AddinData\LenovoBatteryGaugeAddin\x64\QSHelper.exe [87960 2025-01-22] (Lenovo -> Lenovo)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4412512 2024-11-05] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher [1866560 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Xvid] => WScript "C:\Program Files (x86)\Xvid\CheckUpdateLauncher.vbs" "C:\Program Files (x86)\Xvid\CheckUpdate.ps1" [16457 2016-10-17] () [Datei ist nicht signiert]
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [MicrosoftEdgeAutoLaunch_E9243080242DEBA1E75581223067271D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4418088 2025-04-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [CiscoMeetingDaemon] => C:\Users\quart\AppData\Local\WebEx\WebexHost.exe [? 0] (Zugriff verweigert) [Datei ist nicht signiert?]
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [12307864 2025-03-13] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [694848 2025-04-02] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Mathworks Service Host] => C:\Users\quart\AppData\Local\MathWorks\ServiceHost\v2024.6.0.6\bin\win64\MathWorksServiceHost.exe [579944 2024-06-12] (The MathWorks, Inc. -> The MathWorks Inc.)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [WingetUI] => C:\Program Files\UniGetUI\UniGetUI.exe [726672 2025-03-13] (Marti Climent Lopez -> )
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [Claude] => C:\Users\quart\AppData\Local\AnthropicClaude\claude.exe [363112 2025-04-02] (Anthropic, PBC -> Anthropic)
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Run: [CiscoSpark] => C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex\Webex.lnk [1454 2025-03-25] () [Datei ist nicht signiert]
HKU\S-1-5-21-2000400401-3484457797-169236058-1001\...\Policies\Explorer: [HideSCAMeetNow] 1
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\106.0.4.0\GoogleDriveFS.exe [65444448 2025-04-02] (Google LLC -> Google LLC.)
HKU\S-1-5-18\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\WINDOWS\system32\eed_ec.dll,SpeedLauncher [1866560 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Windows x64\Print Processors\ssi5mPC: C:\Windows\System32\spool\prtprocs\x64\ssi5mpc.dll [61760 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\ssi5m Langmon: C:\Windows\system32\ssi5mlm.dll [40744 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.42\Installer\chrmstp.exe [2025-04-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\135.1.77.95\Installer\chrmstp.exe [2025-04-02] (Brave Software, Inc. -> Brave Software, Inc.)
Startup: C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2023-12-13]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HESSENBOX.lnk [2025-01-23]
ShortcutTarget: HESSENBOX.lnk -> C:\Program Files\HESSENBOX\HESSENBOX\HESSENBOX.exe (HESSENBOX) [Datei ist nicht signiert]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NIHardwareAccessibilityHelper.exe.lnk [2024-11-01]
ShortcutTarget: NIHardwareAccessibilityHelper.exe.lnk -> C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareAccessibilityHelper.exe (Native Instruments GmbH -> Native Instruments GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpyderUtility.lnk [2024-04-13]
ShortcutTarget: SpyderUtility.lnk -> C:\Program Files (x86)\Datacolor\Spyder5Pro\Utility\SpyderUtility.exe ((c)2019 Datacolor) [Datei ist nicht signiert]
GroupPolicy: Beschränkung ? <==== ACHTUNG
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {F28DBFC1-845D-403F-AA29-AF3C0E592637} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2024-12-18] (Adobe Inc. -> Adobe Inc.)
Task: {C5FA56C4-114A-4B1F-80FB-1A70CE257079} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{D2488D7A-9D57-41AD-8C7C-0885E62196B0} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174960 2023-04-01] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {C6B6C1B3-96CA-4A85-8585-4960E7EAE84F} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA{7C7A04CD-46B5-4C7B-8AEF-DC7085F74298} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174960 2023-04-01] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {E9E39C08-A2D7-4704-8030-3FD5355B3113} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem135.0.7023.0{5B197E40-F00D-4649-9A67-216542AAE245} => C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe [5745760 2025-02-19] (Google LLC -> Google LLC)
Task: {E51E8C67-56C0-49C1-AAEF-B3EB7FB68702} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem136.0.7079.0{FCF82DD6-43F8-476A-A3D8-D7EB32CBFD4E} => C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\updater.exe [7017568 2025-03-20] (Google LLC -> Google LLC)
Task: {90D34E82-5716-4386-9389-78C61EC5569F} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4910680 2024-02-21] (Intel Corporation -> Intel Corporation)
Task: {F86A761E-B638-4BC3-ACE9-E0B12EB6D2C2} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4910680 2024-02-21] (Intel Corporation -> Intel Corporation)
Task: {37629D91-0995-4290-989C-E64FFA0AA11A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (Keine Datei)
Task: {CD9AC1AF-8D1D-4D9E-AA6D-8BE3158971EA} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [94496 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {D67EAF74-2B81-48CB-BC99-2973FA3B2D97} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => C:\WINDOWS\system32\sc.exe [102400 2025-02-17] (Microsoft Windows -> Microsoft Corporation) -> START ImControllerService
Task: {0221F0B0-5BFE-4895-BC93-8FFE996B4545} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => C:\WINDOWS\System32\reg.exe [110592 2025-02-17] (Microsoft Windows -> Microsoft Corporation) -> add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {C26555F4-CD33-4396-93BD-FBA8B22845C1} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\bf2f9e1a-da8a-4ba3-b317-167413dfbd5f => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {C3E58E1E-3FED-4B69-8080-3D6F40F4F402} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\cefba880-ca4a-451d-8e90-7693842a0d8f => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {CF570406-9E62-405D-BDE5-19E172F2B835} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\cf71a2d4-f2eb-4c7c-8d59-635ff1fa7a77 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
Task: {64DEC80D-2185-4B3E-BBF3-C99D9E096DDC} - System32\Tasks\Lenovo\LenovoNowLauncher => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.exe [3560352 2025-02-17] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\/task
Task: {122268C4-674D-4516-ADA7-719D57E5F230} - System32\Tasks\Lenovo\LenovoNowQuarterlyLaunch => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.Task.exe [2360224 2025-02-17] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\/QuarterlyLaunch
Task: {837A090B-8B54-40EB-9D66-4B1331C318F7} - System32\Tasks\Lenovo\LenovoNowTask => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.Task.exe [2360224 2025-02-17] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\$(EventData)
Task: {09B20D0E-4632-4D5C-90B6-E2358F9137F6} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [102400 2025-02-17] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {73867FD1-223D-4AD9-9316-D553BAD38361} - System32\Tasks\Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {88D7F9AA-C1AE-4A90-AAD3-913C6A7E4C62} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {1F505D02-1A55-4560-B546-A2E45DC59DEB} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {5700D973-91B7-4B8D-BE55-4FA35DAC3049} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {28204DA8-098B-46E8-A844-B437068C67B1} - System32\Tasks\Lenovo\Vantage\Schedule\IdeaNotebookAddinDailyEvent => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {1CCCB5F4-8DD9-4380-9103-1BE21D0B931E} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {0A2E4A5C-81C4-4DE2-9534-AA0B6DF1FD78} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.SScan => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {A74004C8-0FBE-4ECE-ABE2-51215BE8E2E0} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoBatteryPartSalesMonthlyToast => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {AE09B461-EFAE-4C95-8A6A-9090E8831B52} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {971A0E71-1251-4A40-8DE6-988969E91583} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {30413647-12C0-4A47-96A7-1E29DBACBAF6} - System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => C:\Program Files (x86)\Lenovo\VantageService\3.13.72.0\ScheduleEventAction.exe NotificationCenter (Keine Datei)
Task: {D387E6B7-1177-4008-9060-3FF7585B666C} - System32\Tasks\Lenovo\Vantage\Schedule\SettingsWidgetAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {FB72D4FB-6DF1-484F-898E-712886AC3405} - System32\Tasks\Lenovo\Vantage\Schedule\SmartLock.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {D3F5F34F-AB56-41C6-B122-E12629789AE6} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {1003B98D-FB86-469D-951D-438187668E4D} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinIdleScheduleTask => C:\ProgramData\Lenovo\Vantage\Addins\VantageCoreAddin\1.0.0.190\x64\IdleScheduleEventAction.exe [143768 2025-01-17] (Lenovo -> )
Task: {7F0B23C5-33EE-418B-926B-F8200E839E19} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\ScheduleEventAction.exe [278016 2025-02-20] (Lenovo -> Lenovo)
Task: {967DB92F-F546-42B5-9341-941EE90C947E} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.2.24.0\\uninstall.exe /repair (Keine Datei)
Task: {F6DEAFE2-797A-4C3E-9B40-0E2147F49EA5} - System32\Tasks\MATLAB R2023a Startup Accelerator => C:\Program Files\MATLAB\R2023a\bin\win64\MATLABStartupAccelerator.exe [98816 2022-11-20] () [Datei ist nicht signiert]
Task: {FD71EEA2-9873-4F8F-A2D8-E2705D309943} - System32\Tasks\MATLAB R2024a Startup Accelerator => C:\Program Files\MATLAB\R2024a\bin\win64\MATLABStartupAccelerator.exe (Keine Datei)
Task: {D67AA71A-10E5-4C44-80A8-01F063D49BB4} - System32\Tasks\Microsoft\Office\Office Apps Prewarm => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [315512 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {6F340DD0-CD28-44BD-9D31-DFECBA8E0014} - System32\Tasks\Microsoft\Office\Office Apps Prewarm Recurring => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [315512 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {E084DAB4-EBB2-4B36-AAD5-BB250D38A632} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29106392 2025-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {FFCF75D9-0AB5-4E32-B8EC-30AECF7268DD} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [68304 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {32968922-A999-4546-BF17-A808B455FE26} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29106392 2025-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {72612C00-0213-431F-BDEA-AC0D612E039A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [315512 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {56BA5686-C54F-4BCF-81B5-D15B421F51E2} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [315512 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {7A932A07-5FFC-4A34-BA38-B413999793CD} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [204400 2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {8A6F4F38-0B3C-44E5-83C3-65C2A444B2EA} - System32\Tasks\Microsoft\Windows\AccountHealth\RecoverabilityToastTask => {B7F5B442-EBF8-46CD-9F0B-D8E45ED43492} C:\WINDOWS\system32\AccountHealth.dll [258048 2025-03-27] (Microsoft Windows -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (Keine Datei)
Task: {27CE9D59-9D48-4D29-99BC-64657AEBA494} - System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask => {8702A841-D5CA-47C3-812D-9CEDC304C200}
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Keine Datei)
Task: {03688314-22A9-4886-8748-B24C90606E5D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8A2EF93B-FB60-45B5-ACF9-A4577CFCFB90} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6D28973A-4569-408A-9CBF-46C5371F88D9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DEB5E3EE-0205-4784-8BFE-0C8694AAC879} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DAF7B40B-1472-4A4F-907A-23D72FADF874} - System32\Tasks\MonitorMicroKey => C:\Program Files\GamingIntelligence\MonitorMicroKeyDetector.exe [101520 2024-02-21] (Micro-Star International CO., LTD. -> MSI)
Task: {6EB7AE91-E6AB-479F-A64A-F11094905B0A} - System32\Tasks\MonitorMysticLight => C:\Program Files\GamingIntelligence\MysticLight\MysticLightController.exe [31376 2024-02-21] (Micro-Star International CO., LTD. -> )
Task: {8ADAB363-5D76-4B0D-B0D4-EBD8AAE311EB} - System32\Tasks\MonitorWeatherDetector => C:\Program Files\GamingIntelligence\WeatherDetector.exe [43664 2024-02-21] (Micro-Star International CO., LTD. -> MSI)
Task: {2891745E-4241-4CA6-85ED-11BA4B1E4AF8} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-04-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {FE1AF715-36DE-4CB3-BA73-3D297E36DC9B} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3287072 2025-02-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2275554B-E300-4107-99E7-142401404A95} - System32\Tasks\OSDAppAutoStartUp => C:\Program Files\GamingIntelligence\GamingIntelligence.exe [15056528 2024-02-21] (Micro-Star International CO., LTD. -> MICRO-STAR INT'L,.LTD.)
Task: {273ABDB9-B3FA-437E-A609-C43CFB1A5238} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\System32\Wscript.exe [200704 2025-03-27] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {5614B5AF-8C46-4FFC-A108-7A2B14E9B39A} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2000400401-3484457797-169236058-1001 => C:\Users\quart\AppData\Roaming\Zoom\bin\Zoom.exe [? 0] (Zugriff verweigert) [Datei ist nicht signiert?] --action=UpdateSchedule (Zugriff verweigert) <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\MATLAB R2023a Startup Accelerator.job => C:\Program Files\MATLAB\R2023a\bin\win64\MATLABStartupAccelerator.exe C:\Program Files\MATLAB\R2023aCORTEX\quart.Sta
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c5b9cb35-caf2-4978-99b9-b6a478013b90}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c5b9cb35-caf2-4978-99b9-b6a478013b90}\14E64627F696461405: [DhcpNameServer] 192.168.151.46
Edge:
=======
Edge Profile: C:\Users\quart\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-05]
Edge Extension: (Google Docs Offline) - C:\Users\quart\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-03]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\quart\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Citavi Picker) - C:\Users\quart\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mielbhbkcliienpdicphhecpodcaeefg [2023-01-31]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge HKLM-x32\...\Edge\Extension: [mielbhbkcliienpdicphhecpodcaeefg]
FireFox:
========
FF DefaultProfile: 2k0lrm9m.default
FF DefaultProfile: 45adbgga.default
FF ProfilePath: C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\9ka8jhuq.default-release [nicht gefunden] <==== ACHTUNG
FF ProfilePath: C:\Users\quart\AppData\Roaming\Zotero\Zotero\Profiles\2k0lrm9m.default [2025-04-02]
FF Extension: (Better Notes for Zotero) - C:\Users\quart\AppData\Roaming\Zotero\Zotero\Profiles\2k0lrm9m.default\Extensions\Knowledge4Zotero@windingwind.com.xpi [2025-04-01] [ist nicht signiert] [UpdateUrl:hxxps://github.com/windingwind/zotero-better-notes/releases/download/release/update.json]
FF Extension: (__addonName__) - C:\Users\quart\AppData\Roaming\Zotero\Zotero\Profiles\2k0lrm9m.default\Extensions\zoterogpt@polygon.org.xpi [2025-03-28] [] [ist nicht signiert]
FF Extension: (Zutilo Utility for Zotero) - C:\Users\quart\AppData\Roaming\Zotero\Zotero\Profiles\2k0lrm9m.default\Extensions\zutilo@www.wesailatdawn.com.xpi [2025-03-26] [] [ist nicht signiert]
FF ProfilePath: C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\1smhagvz.4k [2025-03-20]
FF Extension: (Citavi Picker) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\1smhagvz.4k\Extensions\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}.xpi [2024-04-07]
FF ProfilePath: C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default [2025-04-06]
FF Homepage: Mozilla\Firefox\Profiles\45adbgga.default -> hxxps://startpage.com
FF Session Restore: Mozilla\Firefox\Profiles\45adbgga.default -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\45adbgga.default -> hxxps://web.threema.ch; hxxps://photos.google.com; hxxps://room-v2.edudip.com; hxxps://web.airdroid.com; hxxps://matrix.uni-marburg.de; hxxps://web.whatsapp.com; hxxps://my.okx.com
FF Extension: (Facebook Container) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\@contain-facebook.xpi [2025-03-25]
FF Extension: (Google Scholar-Schaltfläche) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\button@scholar.google.com.xpi [2021-05-08]
FF Extension: (Cookie AutoDelete) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\CookieAutoDelete@kennydo.com.xpi [2022-12-12]
FF Extension: (Canadian English Dictionary) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\en-CA@dictionaries.addons.mozilla.org.xpi [2024-07-09]
FF Extension: (English (US) Dictionary) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\en-US-mozilla@dictionaries.addons.mozilla.org.xpi [2025-01-08]
FF Extension: (Consent-O-Matic) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\gdpr@cavi.au.dk.xpi [2024-10-09]
FF Extension: (MyJDownloader Browser Erweiterung) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\jid1-OY8Xu5BsKZQa6A@jetpack.xpi [2022-05-23] [UpdateUrl:hxxps://my.jdownloader.org/extensions/firefox.json]
FF Extension: (KeePassXC-Browser) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\keepassxc-browser@keepassxc.org.xpi [2025-03-05]
FF Extension: (Language: English (CA)) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\langpack-en-CA@firefox.mozilla.org.xpi [2025-04-02]
FF Extension: (Language: English (GB)) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\langpack-en-GB@firefox.mozilla.org.xpi [2025-04-02]
FF Extension: (Language: English (US)) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\langpack-en-US@firefox.mozilla.org.xpi [2025-04-02]
FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\marcoagpinto@mail.telepac.pt.xpi [2025-04-01]
FF Extension: (Kein Name) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\simple-tab-groups@drive4ik.xpi [2025-03-11]
FF Extension: (uBlock Origin) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\uBlock0@raymondhill.net.xpi [2025-03-22]
FF Extension: (Zotero Connector) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\zotero@chnm.gmu.edu.xpi [2025-04-05] [UpdateUrl:hxxps://www.zotero.org/download/connector/firefox/release/updates.json]
FF Extension: (Startpage — Datenschutz-Suchmaschine) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\{20fc2e06-e3e4-4b2b-812b-ab431220cada}.xpi [2025-01-17]
FF Extension: (Citavi Picker) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}.xpi [2021-05-08]
FF Extension: (Borderless dark) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\{c4cb2b36-3932-4fac-ad9e-a723f81a04d3}.xpi [2021-05-08]
FF Extension: (Read Aloud: A Text to Speech Voice Reader) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\{ddc62400-f22d-4dd3-8b4a-05837de53c2e}.xpi [2025-03-07]
FF Extension: (Evernote Web Clipper) - C:\Users\quart\AppData\Roaming\Mozilla\Firefox\Profiles\45adbgga.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}.xpi [2025-02-04]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-03-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-04-04] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default [2025-04-02]
CHR Notifications: Default -> hxxps://matrix.uni-marburg.de
CHR Extension: (uBlock Origin) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2025-04-02]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-04-02]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Google Docs Offline) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-02]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (PlayTo für Chromecast™) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\jngkenaoceimiimeokpdbmejeonaaami [2024-04-03]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Anwendungs-Launcher für Drive (von Google)) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-09-13]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-10]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Monica: ChatGPT AI Assistant | DeepSeek, GPT-4o, Claude 3.5, o1 &More) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofpnmcalabcbjgholdjcjblkibolbppb [2025-03-10]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Citavi Picker) - C:\Users\quart\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2025-02-03]hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2000400401-3484457797-169236058-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2000400401-3484457797-169236058-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn]
Brave:
=======
BRA Profile: C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2025-03-11]
BRA Extension: (Citavi Picker) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2025-02-19]hxxps://clients2.google.com/service/update2/crx
BRA Extension: (Brave Ad Block Updater (Brave Ad Block First Party Filters (plaintext))) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2025-02-19]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2025-02-19]
BRA Extension: (Brave NTP background images) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2025-02-19]
BRA Extension: (Brave Ads Resources) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\bbefpembgddgdihpkcidgdgiojjlchji [2023-04-01]
BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext))) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2025-02-19]
BRA Extension: (Wallet Data Files Updater) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2023-09-16]
BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2025-02-19]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2023-04-17]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2025-02-19]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2025-02-19]
BRA Extension: (Brave Ads Resources) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\jcncoheihebhhiemmbmpfhkceomfipbj [2024-07-16]
BRA Extension: (Brave Ad Block Updater (EasyList Germany (plaintext))) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\lfmefmifdjlfneapckmpkinmlofjehbp [2025-02-19]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2025-02-19]
BRA Extension: (Brave NTP sponsored images) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\obbokncgfcbepeipkhpdepjjoncelefj [2025-02-19]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\quart\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-10-16]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 aakore; C:\Program Files (x86)\Common Files\Acronis\Agent\aakore.exe [18738640 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
R2 AcronisActiveProtectionService; C:\Program Files\Common Files\Acronis\ActiveProtection\active_protection_service.exe [13032744 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
R2 AcronisCyberProtectionService; C:\Program Files\Acronis\CyberProtect\cyber-protect-service.exe [1429240 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1871296 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2024-12-18] (Adobe Inc. -> Adobe Inc.)
R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6354456 2025-01-27] (Acronis International GmbH -> Acronis International GmbH)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174960 2023-04-01] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\135.1.77.95\elevation_service.exe [3520528 2025-04-02] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174960 2023-04-01] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13860056 2025-04-01] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_d59c8b8a329853e4\DAX3API.exe [1906648 2020-09-23] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [47000 2025-02-19] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [330136 2025-02-19] (Intel Corporation -> Intel)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3064848 2025-04-05] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [368088 2025-01-31] (Epic Games Inc. -> Epic Games, Inc.)
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [343928 2020-09-04] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [113224 2024-06-26] (Lenovo -> Lenovo Group Ltd.)
R2 LenovoFnAndFunctionKeys; C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe [182272 2025-02-20] (Lenovo -> Lenovo)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.3.21.0\LenovoVantageService.exe [34816 2025-02-20] (Lenovo -> Lenovo)
R2 LITSSVC; C:\WINDOWS\System32\LNBITSSvc.exe [1831672 2022-08-17] (Lenovo -> Lenovo(beijing) Limited)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4896488 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [3087408 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [2256424 2025-01-17] (Acronis International GmbH -> )
R2 NIHostIntegrationAgent; C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe [27580128 2024-05-07] (Native Instruments GmbH -> Native Instruments GmbH)
R2 NTKDaemonService; C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe [16895200 2024-09-09] (Native Instruments GmbH -> Native Instruments GmbH)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_071505319ec619da\Display.NvContainer\NVDisplay.Container.exe [1275560 2025-03-04] (NVIDIA Corporation -> NVIDIA Corporation)
R2 OptionsPlusUpdaterService; C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe [22443400 2025-03-28] (Logitech Inc -> Logitech, Inc.)
R2 PCManager Service Store; C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.16.2.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe [87584 2025-03-21] (Microsoft Corporation -> MSPCManagerService)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [5209072 2024-02-09] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559328 2025-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SmartSense; C:\WINDOWS\System32\DriverStore\FileRepository\lnvsst.inf_amd64_f352f4254b85e733\SmartSense.exe [209768 2024-06-19] (Lenovo -> Lenovo)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2022-10-04] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [920768 2022-10-04] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7377624 2024-12-12] (Acronis International GmbH -> )
R2 TbtP2pShortcutService; C:\WINDOWS\TbtP2pShortcutService.exe [252296 2021-03-17] (Intel Thunderbolt(TM) Technology -> )
S3 Tib Mounter Service; C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe [5921232 2024-12-12] (Acronis International GmbH -> Acronis International GmbH)
R2 TISmartAmpService; C:\WINDOWS\System32\TISmartAmpService.exe [537072 2020-06-17] (Texas Instruments Inc. -> Texas Instuments)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-03-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WsaService; C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.4.0_x64__8wekyb3d8bbwe\WsaService\WsaService.exe [320512 2024-12-18] (Microsoft Corporation -> )
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 acsock; C:\WINDOWS\system32\DRIVERS\acsock64.sys [310216 2023-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [800672 2024-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R3 bomebus; C:\WINDOWS\System32\drivers\bomebus.sys [56376 2018-05-16] (Bome Software GmbH & Co.KG -> Bome Software GmbH & Co. KG)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 droidvcam0_aud0; C:\WINDOWS\System32\DriverStore\FileRepository\droidcamaudio.inf_amd64_f08960db84657665\droidcamaudio.sys [33808 2022-06-22] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 droidvcam0_vid0; C:\WINDOWS\System32\DriverStore\FileRepository\droidcamvideo.inf_amd64_b02e702c2d1e7e03\droidcamvideo.sys [136360 2025-01-28] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [944648 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [389616 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
R0 fltsrv; C:\WINDOWS\System32\DRIVERS\fltsrv.sys [179200 2025-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [222528 2025-02-17] (Microsoft Windows -> Microsoft Corporation)
R2 googledrivefs31626; C:\Program Files\Google\Drive File Stream\Drivers\31626\googledrivefs31626.sys [384096 2024-07-25] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-03-31] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144840 2025-03-27] (Microsoft Windows -> Microsoft Corporation)
S3 mc2avs; C:\WINDOWS\System32\Drivers\mc2avs.sys [358520 2012-06-06] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH)
S3 mc2usb_svc; C:\WINDOWS\System32\Drivers\mc2usb.sys [81016 2012-06-06] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH)
S3 ng-netfilter; C:\WINDOWS\system32\DRIVERS\ng-netfilter.sys [164352 2025-01-17] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
S0 ngelam; C:\WINDOWS\System32\drivers\ngelam.sys [32272 2024-12-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Acronis International GmbH)
R1 ngscan; C:\WINDOWS\System32\DRIVERS\ngscan.sys [281584 2024-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
S3 nikz1audio; C:\WINDOWS\System32\Drivers\nikz1audio.sys [383928 2015-09-09] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH)
S3 nikz1usb; C:\WINDOWS\system32\DRIVERS\nikz1usb.sys [100200 2015-09-09] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH)
S3 NovationUsbMidi; C:\WINDOWS\system32\DRIVERS\NovationUsbMidi.sys [71384 2023-02-23] (Focusrite Audio Engineering Ltd -> Novation DMS, Ltd.)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-13] (Nvidia Corporation -> NVIDIA Corporation)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.)
R0 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [133944 2020-01-20] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd)
R0 snapman; C:\WINDOWS\System32\DRIVERS\snapman.sys [392640 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
S3 SoundcraftUSBAudio; C:\WINDOWS\System32\drivers\SoundcraftUSBAudio_x64.sys [269312 2015-09-03] () [Datei ist nicht signiert]
S3 SoundcraftUSBAudioks; C:\WINDOWS\System32\drivers\SoundcraftUSBAudioks_x64.sys [50688 2015-09-03] () [Datei ist nicht signiert]
S3 Spyder5; C:\WINDOWS\System32\drivers\dccmtr.sys [15360 2015-04-13] (Microsoft Windows Hardware Compatibility Publisher -> Datacolor)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [14224 2021-04-01] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 steamxbox; C:\WINDOWS\System32\drivers\steamxbox.sys [278208 2023-02-21] (Valve Corp. -> Valve Corporation)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-03-27] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [171080 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
R3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2023-05-03] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [335760 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2025-02-17] (Microsoft Windows -> Microsoft Corporation)
R0 volume_tracker; C:\WINDOWS\System32\DRIVERS\volume_tracker.sys [246320 2025-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Acronis International GmbH)
S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [74064 2023-12-13] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-03-31] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-03-31] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-03-31] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_bdb09ebda2834009\wini3ctarget.sys [75168 2025-03-27] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2025-04-05 21:58 - 2025-04-06 07:57 - 000000000 ____D C:\FRST
2025-04-05 21:06 - 2025-04-05 21:06 - 000748376 _____ C:\WINDOWS\system32\perfh007.dat
2025-04-05 21:06 - 2025-04-05 21:06 - 000159426 _____ C:\WINDOWS\system32\perfc007.dat
2025-04-05 21:02 - 2025-04-05 21:02 - 000000866 __RSH C:\ProgramData\ntuser.pol
2025-04-05 19:41 - 2025-04-05 19:41 - 000000000 ____D C:\Users\quart\OneDrive\Dokumente\PowerShell
2025-04-05 15:18 - 2025-04-05 15:18 - 002404864 _____ (Farbar) C:\Users\quart\Downloads\FRST64.exe
2025-04-05 10:41 - 2025-04-05 10:41 - 002834160 _____ (Malwarebytes) C:\Users\quart\Downloads\MBSetup.exe
2025-04-05 10:39 - 2025-04-05 10:39 - 000192952 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2025-04-05 10:39 - 2025-04-05 10:39 - 000000000 ____D C:\Users\quart\Desktop\mbar
2025-04-05 10:39 - 2025-04-05 10:39 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2025-04-04 23:03 - 2025-04-04 23:03 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-04-04 21:32 - 2025-04-04 21:32 - 000000000 ____D C:\Users\quart\AppData\Roaming\The Witcher 3
2025-04-04 21:31 - 2025-04-04 21:44 - 000000000 ____D C:\Users\quart\OneDrive\Dokumente\The Witcher 3
2025-04-04 21:31 - 2025-04-04 21:31 - 000000000 ____D C:\Users\quart\AppData\Local\REDEngine
2025-04-04 20:05 - 2025-04-04 20:06 - 000000000 ____D C:\Users\quart\OneDrive\Dokumente\Shadow of the Tomb Raider
2025-04-04 16:52 - 2025-04-04 16:52 - 001042012 _____ C:\Users\quart\Downloads\STEFAN_BECKER_Mietzuschuss_Erstantrag_20250404.pdf
2025-04-04 16:52 - 2025-04-04 16:52 - 001042012 _____ C:\Users\quart\Downloads\Antrag auf Wohngeld_unterschrieben.pdf
2025-04-03 12:21 - 2025-04-03 12:28 - 000000000 ____D C:\Users\quart\OneDrive
2025-04-02 12:22 - 2025-04-06 07:55 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-137.0
2025-04-02 10:58 - 2025-04-05 19:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-04-02 10:42 - 2025-04-02 10:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-04-02 10:34 - 2025-04-02 10:34 - 000004250 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2000400401-3484457797-169236058-1001
2025-04-02 10:34 - 2025-04-02 10:34 - 000002318 _____ C:\Users\quart\Desktop\Claude.lnk
2025-04-02 10:34 - 2025-04-02 10:34 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2025-03-29 10:21 - 2025-03-29 16:52 - 000000000 ____D C:\Program Files\LogiOptionsPlus
2025-03-29 10:21 - 2025-03-29 10:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2025-03-28 07:16 - 2025-04-02 10:21 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-136.0.4
2025-03-28 00:08 - 2025-03-28 00:08 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-03-27 22:01 - 2025-04-06 04:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-03-27 21:58 - 2025-03-27 21:58 - 000000000 ____D C:\WINDOWS\Panther
2025-03-27 21:25 - 2025-03-27 21:25 - 000029042 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-03-27 21:25 - 2025-03-27 21:25 - 000029042 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-03-27 02:49 - 2025-03-27 22:57 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-136.0.3
2025-03-27 01:50 - 2025-03-27 01:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yubico Authenticator
2025-03-26 18:40 - 2025-03-26 18:40 - 005004048 _____ C:\Users\quart\Downloads\zotero-gpt.xpi
2025-03-26 17:52 - 2025-03-26 17:52 - 000002353 _____ C:\Users\quart\Desktop\Element.lnk
2025-03-26 17:52 - 2025-03-26 17:52 - 000000000 ____D C:\Users\quart\AppData\Local\element-desktop
2025-03-26 14:22 - 2025-03-26 14:22 - 004204109 _____ C:\Users\quart\Downloads\better-notes-for-zotero.xpi
2025-03-26 11:28 - 2025-03-26 11:29 - 000124388 _____ C:\Users\quart\Downloads\zutilo.xpi
2025-03-26 00:00 - 2025-03-26 00:00 - 000001440 _____ C:\Users\quart\Desktop\Webex.lnk
2025-03-26 00:00 - 2025-03-26 00:00 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex
2025-03-25 15:17 - 2025-03-27 02:50 - 000000000 ____D C:\Users\quart\AppData\Roaming\Sider
2025-03-25 15:17 - 2025-03-25 15:17 - 000002287 _____ C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sider.lnk
2025-03-25 15:17 - 2025-03-25 15:17 - 000002279 _____ C:\Users\quart\Desktop\Sider.lnk
2025-03-25 15:17 - 2025-03-25 15:17 - 000000000 ____D C:\Users\quart\AppData\Local\sider-updater
2025-03-25 15:16 - 2025-03-25 15:16 - 097265528 _____ (Vidline Inc.) C:\Users\quart\Downloads\Sider_2.1.1.exe
2025-03-25 11:03 - 2025-03-25 11:03 - 000021908 _____ C:\Users\quart\.boto
2025-03-25 10:58 - 2025-03-25 11:04 - 000000000 ____D C:\Users\quart\.gsutil
2025-03-25 10:57 - 2025-03-25 10:57 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Cloud SDK
2025-03-25 10:55 - 2025-03-25 11:03 - 000000000 ____D C:\Users\quart\AppData\Roaming\gcloud
2025-03-25 10:50 - 2025-03-25 10:50 - 000000000 ____D C:\tools
2025-03-24 14:47 - 2025-04-02 10:29 - 000000000 ____D C:\Users\quart\Zotero
2025-03-24 14:47 - 2025-03-24 14:47 - 000000938 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zotero.lnk
2025-03-24 14:47 - 2025-03-24 14:47 - 000000926 _____ C:\Users\Public\Desktop\Zotero.lnk
2025-03-24 14:47 - 2025-03-24 14:47 - 000000000 ____D C:\Users\quart\AppData\Roaming\Zotero
2025-03-24 14:47 - 2025-03-24 14:47 - 000000000 ____D C:\Users\quart\AppData\Local\Zotero
2025-03-24 14:47 - 2025-03-24 14:47 - 000000000 ____D C:\ProgramData\Zotero
2025-03-24 14:47 - 2025-03-24 14:47 - 000000000 ____D C:\Program Files\Zotero
2025-03-24 14:46 - 2025-03-24 14:46 - 089475608 _____ (Corporation for Digital Scholarship) C:\Users\quart\Downloads\Zotero-7.0.15_x64_setup.exe
2025-03-23 13:20 - 2025-04-06 02:16 - 000000000 ____D C:\Users\quart\AppData\Roaming\Claude
2025-03-23 13:20 - 2025-04-02 10:34 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anthropic
2025-03-23 13:19 - 2025-04-02 10:34 - 000000000 ____D C:\Users\quart\AppData\Local\AnthropicClaude
2025-03-21 23:40 - 2025-03-21 23:40 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-03-21 23:40 - 2025-03-21 23:40 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-03-21 23:40 - 2025-03-21 23:40 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-03-21 20:51 - 2025-03-21 20:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git
2025-03-20 21:33 - 2025-03-26 23:59 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-136.0.2
2025-03-20 21:03 - 2025-03-20 21:03 - 000000000 ____D C:\Users\quart\AppData\Local\gargle
2025-03-20 16:06 - 2025-03-20 16:06 - 000001101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AusweisApp.lnk
2025-03-20 16:06 - 2025-03-20 16:06 - 000000000 ____D C:\Program Files\AusweisApp2
2025-03-20 13:27 - 2025-04-05 00:48 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2025-03-19 13:40 - 2025-03-19 13:40 - 000155774 _____ C:\Users\quart\Downloads\Introduction.pdf
2025-03-19 13:26 - 2025-03-19 13:26 - 002428935 _____ C:\Users\quart\Downloads\Time_Varying-1.pdf
2025-03-17 16:20 - 2025-03-17 16:20 - 002428935 _____ C:\Users\quart\Downloads\Time_Varying.pdf
2025-03-16 01:46 - 2025-03-16 01:46 - 000000367 _____ C:\Users\quart\Desktop\The Witcher 3 Wild Hunt - Game of the Year Edition.url
2025-03-14 23:36 - 2025-03-14 23:36 - 000000859 _____ C:\ProgramData\Microsoft\Windows\Start Menu\UniGetUI.lnk
2025-03-14 23:36 - 2025-03-14 23:36 - 000000853 _____ C:\Users\Public\Desktop\UniGetUI.lnk
2025-03-13 22:59 - 2025-03-13 22:59 - 000000865 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2025-03-12 13:28 - 2025-03-12 13:28 - 000001313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Now.lnk
2025-03-12 10:52 - 2025-03-12 10:52 - 000042947 _____ C:\Users\quart\Downloads\Briefmarken.1Stk.12.03.2025_0952.pdf
2025-03-12 10:49 - 2025-03-12 10:49 - 000058148 _____ C:\Users\quart\Downloads\Briefmarken.1Stk.12.03.2025_0949.pdf
2025-03-11 23:13 - 2025-03-20 19:33 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-136.0.1
2025-03-11 14:16 - 2025-04-05 00:53 - 000000000 ____D C:\Users\quart\AppData\Roaming\Signal
2025-03-11 14:16 - 2025-03-11 14:16 - 000002405 _____ C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Signal.lnk
2025-03-11 14:16 - 2025-03-11 14:16 - 000002397 _____ C:\Users\quart\Desktop\Signal.lnk
2025-03-10 10:56 - 2025-03-10 10:56 - 011409744 _____ (GitHub, Inc. ) C:\Users\quart\Downloads\git-lfs-windows-v3.6.1.exe
2025-03-10 10:56 - 2025-03-10 10:56 - 000000000 ____D C:\Program Files\Git LFS
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2025-04-06 07:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-06 07:55 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-04-06 07:55 - 2023-01-31 14:56 - 000000000 ____D C:\Users\quart\AppData\Local\LogiOptionsPlus
2025-04-06 07:55 - 2023-01-31 14:44 - 000000000 ___SD C:\Users\quart\AppData\Roaming\Microsoft\Credentials
2025-04-06 07:54 - 2025-02-17 21:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-06 07:54 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-06 04:04 - 2023-07-13 12:08 - 000000000 ____D C:\Users\quart\AppData\Roaming\HESSENBOX
2025-04-06 04:01 - 2023-01-31 14:50 - 000000000 ____D C:\Users\quart\AppData\Local\D3DSCache
2025-04-06 02:25 - 2023-02-18 13:17 - 000000000 ____D C:\Users\quart\AppData\Roaming\RStudio
2025-04-06 02:05 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-06 01:25 - 2023-02-18 13:17 - 000000000 ____D C:\Users\quart\AppData\Local\RStudio
2025-04-06 01:22 - 2023-01-31 15:04 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-04-06 01:20 - 2023-01-31 20:12 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-06 01:20 - 2023-01-31 14:50 - 000000000 __SHD C:\Users\quart\IntelGraphicsProfiles
2025-04-06 01:03 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-05 21:06 - 2025-02-17 21:06 - 001729576 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-05 21:06 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-05 21:04 - 2023-08-01 16:54 - 000000000 ____D C:\ProgramData\boost_interprocess
2025-04-05 21:03 - 2023-12-03 19:17 - 000000436 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2025-04-05 21:02 - 2025-02-17 21:08 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-05 21:02 - 2025-02-17 21:05 - 000002920 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-05 21:02 - 2025-01-02 13:01 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-05 21:02 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState
2025-04-05 21:02 - 2023-01-31 14:49 - 000000000 ____D C:\Intel
2025-04-05 20:51 - 2024-04-01 09:21 - 002883584 _____ C:\WINDOWS\system32\config\BBI
2025-04-05 19:40 - 2023-01-31 15:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-04-05 19:38 - 2023-01-31 15:25 - 000000000 ____D C:\Users\quart\AppData\Local\KeePassXC
2025-04-05 13:51 - 2023-02-03 22:07 - 000000000 ____D C:\Users\quart\AppData\Local\CrashDumps
2025-04-05 13:22 - 2023-01-31 14:30 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-05 00:53 - 2023-01-31 21:32 - 000000000 ____D C:\Users\quart\AppData\Roaming\Evernote
2025-04-05 00:50 - 2023-08-01 15:04 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2025-04-05 00:48 - 2023-12-07 11:47 - 000001067 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2025-04-05 00:48 - 2023-12-07 11:47 - 000001055 _____ C:\Users\Public\Desktop\Thunderbird.lnk
2025-04-04 23:01 - 2023-01-31 18:27 - 000000000 ____D C:\Program Files\Microsoft Office
2025-04-04 21:28 - 2024-02-06 17:43 - 000000000 ____D C:\Users\quart\AppData\Local\cache
2025-04-03 22:11 - 2023-02-02 19:29 - 000000000 ____D C:\Users\quart\Desktop\Browser
2025-04-03 12:21 - 2025-02-17 21:02 - 000000000 ____D C:\Users\quart
2025-04-02 20:50 - 2023-02-27 13:33 - 000000000 ____D C:\Users\quart\AppData\Local\gnupg
2025-04-02 20:41 - 2023-04-01 11:24 - 000002356 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2025-04-02 20:41 - 2023-04-01 11:24 - 000002315 _____ C:\Users\Public\Desktop\Brave.lnk
2025-04-02 20:40 - 2023-02-27 13:33 - 000000000 ____D C:\Users\quart\AppData\Roaming\gnupg
2025-04-02 20:39 - 2023-02-27 13:35 - 000000000 ____D C:\Users\quart\AppData\Roaming\kleopatra
2025-04-02 15:07 - 2023-01-31 15:18 - 000002177 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2025-04-02 13:02 - 2023-01-31 20:18 - 000000000 ____D C:\Users\quart\AppData\Roaming\Ledger Live
2025-04-02 11:50 - 2023-01-31 16:29 - 000000000 ____D C:\Users\quart\AppData\Roaming\Exodus
2025-04-02 11:42 - 2025-01-02 12:47 - 000000000 ____D C:\Users\quart\AppData\Roaming\droidcam-obs-client
2025-04-02 11:42 - 2023-01-31 20:18 - 000000000 ____D C:\Program Files\Ledger Live
2025-04-02 10:58 - 2023-01-31 15:04 - 000001071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-04-02 10:43 - 2023-05-10 11:51 - 000002311 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-02 10:43 - 2023-05-10 11:51 - 000002270 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-02 10:42 - 2024-10-30 09:44 - 000001059 _____ C:\Users\Public\Desktop\Firefox.lnk
2025-04-02 10:36 - 2023-08-26 15:02 - 000001052 _____ C:\Users\Public\Desktop\OBS Studio.lnk
2025-04-02 10:34 - 2024-11-07 16:53 - 000000000 ____D C:\Users\quart\AppData\Roaming\Zoom
2025-04-02 10:34 - 2023-01-31 16:29 - 000000000 ____D C:\Users\quart\AppData\Local\SquirrelTemp
2025-04-02 10:31 - 2025-02-17 21:00 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2025-03-31 23:36 - 2023-01-31 14:30 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-03-29 16:52 - 2025-03-03 12:59 - 000000000 ____D C:\Program Files\Logi
2025-03-29 10:21 - 2024-10-13 21:34 - 000000000 ____D C:\ProgramData\Logi
2025-03-28 07:41 - 2023-08-01 15:04 - 000000000 ____D C:\Users\quart\AppData\Roaming\Code
2025-03-28 00:33 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-03-28 00:09 - 2025-02-17 21:00 - 000472904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-03-28 00:08 - 2024-04-01 18:37 - 000000000 ____D C:\WINDOWS\InboxApps
2025-03-28 00:08 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-03-28 00:08 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-03-28 00:08 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-03-28 00:08 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-03-28 00:08 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2025-03-27 21:25 - 2025-02-17 21:03 - 003352064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-03-27 08:04 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-03-27 04:12 - 2024-07-07 11:13 - 000000000 ____D C:\Users\quart\Downloads\bin_enex2notion_0.3.1_win_x64
2025-03-27 01:50 - 2023-12-06 12:47 - 000000000 ____D C:\Program Files\Yubico
2025-03-26 20:44 - 2023-02-01 04:05 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Word
2025-03-26 17:52 - 2023-07-03 16:25 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Element
2025-03-25 17:52 - 2023-01-31 18:42 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Office
2025-03-25 16:23 - 2023-07-03 16:25 - 000000000 ____D C:\Users\quart\AppData\Roaming\Element
2025-03-25 12:45 - 2023-01-31 18:42 - 000000000 ____D C:\Users\quart\AppData\Roaming\Microsoft\Excel
2025-03-25 11:02 - 2023-01-31 18:05 - 000001100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2025-03-25 11:02 - 2023-01-31 18:04 - 000000000 ____D C:\Program Files\WinRAR
2025-03-25 10:54 - 2023-01-31 15:18 - 000000000 ____D C:\Users\quart\AppData\Local\Google
2025-03-24 15:53 - 2023-01-31 15:25 - 000000000 ____D C:\Users\quart\AppData\Roaming\KeePassXC
2025-03-22 22:41 - 2023-01-31 14:50 - 000000000 ____D C:\Users\quart\AppData\Local\Packages
2025-03-21 20:51 - 2023-08-01 15:06 - 000000000 ____D C:\Program Files\Git
2025-03-14 23:36 - 2024-07-04 08:35 - 000000000 ____D C:\Program Files\UniGetUI
2025-03-14 23:15 - 2024-07-04 08:35 - 000000000 ____D C:\Users\quart\AppData\Local\UniGetUI
2025-03-13 23:01 - 2024-04-09 00:39 - 000001329 _____ C:\Users\quart\Desktop\Ubisoft Connect.lnk
2025-03-13 22:59 - 2025-02-15 13:45 - 000000000 ____D C:\Program Files\Audacity
2025-03-12 13:28 - 2024-02-27 13:36 - 000000000 ____D C:\WINDOWS\TempInst
2025-03-12 00:41 - 2024-04-01 18:36 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-03-11 21:13 - 2025-03-05 13:56 - 000000000 ____D C:\Users\quart\Downloads\STG-backups-FF-136.0
2025-03-10 19:07 - 2023-05-03 21:20 - 000008050 _____ C:\Users\quart\AppData\Roaming\VoiceMeeterDefault.xml
2025-03-10 11:03 - 2024-11-02 14:51 - 000000000 ____D C:\Users\quart\.gk
2025-03-08 15:24 - 2024-12-12 14:42 - 000001272 _____ C:\Users\quart\Desktop\ESET Online Scanner.lnk
2025-03-08 15:24 - 2023-06-09 21:18 - 000001378 _____ C:\Users\quart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2025-03-08 10:20 - 2023-03-16 20:15 - 000000000 ____D C:\Users\quart\AppData\Local\Governikus GmbH & Co. KG
2025-03-08 09:16 - 2025-02-17 21:08 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-03-08 09:16 - 2025-02-17 21:08 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2025-01-02 12:45 - 2025-01-02 12:45 - 000000015 _____ () C:\Users\quart\AppData\Roaming\obs-virtualcam.txt
2023-05-03 21:20 - 2025-03-10 19:07 - 000008050 _____ () C:\Users\quart\AppData\Roaming\VoiceMeeterDefault.xml
==================== FLock ==============================
2024-07-10 01:43 C:\Users\quart\AppData\Local\WebEx
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== --- --- --- |