![]() |
| |||||||
Überwachung, Datenschutz und Spam: Pishing Email angeklicktWindows 7 Fragen zu Verschlüsselung, Spam, Datenschutz & co. sind hier erwünscht. Hier geht es um Abwehr von Keyloggern oder aderen Spionagesoftware wie Spyware und Adware. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen. |
| | #1 |
| | Pishing Email angeklickt Guten Abend, ich habe versehentlich eine sehr gute pishing email angeklickt und dann auch noch meine Bank Zugangsdaten eingeben. Die Zugangsdaten für die Bank habe ich nach dem Bemerken des Fehlers geändert. Malwarebytes hat keine Bedrohungen gefunden. Code:
ATTFilter Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 16.12.2025
Scan-Zeit: 20:45
Protokolldatei: d7434f20-dab7-11f0-ac91-28c63fb1619b.json
-Softwaredaten-
Version: 5.4.5.226
Komponentenversion: 146.0.5441
Version des Aktualisierungspakets: 1.0.105693
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19045.6691)
CPU: x64
Dateisystem: NTFS
Benutzer: DESKTOP-NSB7UN7\andre
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 285138
Erkannte Bedrohungen: 3
In die Quarantäne verschobene Bedrohungen: 3
Abgelaufene Zeit: 9 Min., 37 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 1
Generic.Malware/Suspicious, HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{02f17a66-57eb-4cf9-ba5c-9b43a743572d}, In Quarantäne, 0, 392686, 1.0.105693, , shuriken, , ,
Registrierungswert: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 2
Generic.Malware/Suspicious, C:\USERS\ANDRE\APPDATA\ROAMING\LAVASOFT\WEB COMPANION\APPLICATION\WEBCOMPANION-INSTALLER.EXE, In Quarantäne, 0, 392686, 1.0.105693, , shuriken, , 48A6089102B086FDE182D7728C9012A4, AF556E718B230293B147C0AF2CE613BF82000D2A0FFB6B4743CC1309DE8DC2F8
PUP.Optional.WebCompanion, C:\USERS\ANDRE\APPDATA\ROAMING\LAVASOFT\WEB COMPANION\APPLICATION\LAVASOFT.WCASSISTANT.WINSERVICE.EXE, In Quarantäne, 4918, 1219671, 1.0.105693, , ame, , FCB02DD8FE263246A2BC79E4B9B4875E, A47472E7F857EE97B36E1294FB5AD139F0BE05A7D10CB3662052A61D72ABCEC0
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end)
Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2025
durchgeführt von andre (Administrator) auf DESKTOP-NSB7UN7 (HP HP Pavilion Desktop PC 570-p0xx) (16-12-2025 21:48:33)
Gestartet von C:\Users\andre\Desktop\FRST64.exe
Geladene Profile: andre
Plattform: Microsoft Windows 10 Home Version 22H2 19045.6691 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe ->) (AMD) [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\118.0.1.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe <15>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe <2>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
(explorer.exe ->) (Telekom Deutschland GmbH -> Deutsche Telekom AG) C:\Program Files\MagentaCLOUD\magentacloud.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\schtasks.exe <2>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <22>
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (AMD) [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RTUWPSrvcMain.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Program Files\TP-Link\WifiAutoInstall\WifiAutoInstallSrv.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Urban Cyber Security Inc. -> ) C:\Program Files (x86)\UrbanVPN\bin\urban-vpn-service.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2546.3.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Urban Cyber Security Inc. -> ) C:\Program Files (x86)\UrbanVPN\bin\urban-vpn-app.exe
(Westernacher Solutions GmbH -> BRAK) C:\Users\andre\AppData\Local\BRAK\beAClientSecurity\beAClientSecurity.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [UrbanVPN] => C:\Program Files (x86)\UrbanVPN\bin\urban-vpn-app.exe [3601968 2025-02-07] (Urban Cyber Security Inc. -> )
HKLM-x32\...\Run: [G Data ASM] => "C:\Program Files (x86)\G DATA\InternetSecurity\DelayLoader\AutorunDelayLoader.exe" /autostart (Keine Datei)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [5888320 2019-09-05] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\andre\AppData\Local\Microsoft\Teams\Update.exe [2508520 2022-06-01] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM-x32\...\Run: [TeamsMachineUninstallerProgramData] => %ProgramData%\Microsoft\Teams\Update.exe --uninstall --msiUninstall --source=default (Keine Datei)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Beschränkung <==== ACHTUNG
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe [91713176 2025-12-10] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe [91713176 2025-12-10] (Google LLC -> Google LLC.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [vidnotifier.exe] => C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe [1812800 2019-04-16] (Digital Wave Ltd -> Digital Wave Ltd)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Discord] => C:\Users\andre\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Lync] => "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe" /fromrunkey (Keine Datei)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Amazon Photos] => C:\Users\andre\AppData\Local\Amazon Drive\AmazonPhotos.exe [11028136 2023-03-30] (Amazon.com Services LLC -> Amazon.com Inc.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [49958368 2022-02-01] (Google LLC -> )
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [CiscoMeetingDaemon] => C:\Users\andre\AppData\Local\WebEx\ciscowebexstart.exe [4937544 2021-11-05] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe [91713176 2025-12-10] (Google LLC -> Google LLC.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [HoldemManager.Server] => C:\Users\andre\AppData\Roaming\Max Value Software\Holdem Manager\3.0\HoldemManager.Server.lnk [1227 2022-02-28] () [Datei ist nicht signiert]
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Samsung DeX] => D:\Samsung DeX\SamsungDeX.exe [10926952 2022-06-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [MagentaCLOUD] => C:\Program Files\MagentaCLOUD\magentacloud.exe [6458080 2023-02-17] (Telekom Deutschland GmbH -> Deutsche Telekom AG)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [696960 2025-12-05] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\Run: [Web Companion] => C:\Users\andre\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe [3429528 2025-07-03] (7270356 Canada Inc. -> Lavasoft) <==== ACHTUNG
HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\...\MountPoints2: {e6a8613f-f9f4-11e7-994a-806e6f6e6963} - "F:\start.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\118.0.1.0\GoogleDriveFS.exe [91713176 2025-12-10] (Google LLC -> Google LLC.)
HKLM\...\Windows x64\Print Processors\hpzppw72: C:\Windows\System32\spool\prtprocs\x64\hpzppw72.dll [266336 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\EPSON XP-412 413 415 Series 64MonitorBE: C:\WINDOWS\system32\E_ILMBLEE.DLL [179712 2014-12-02] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\WINDOWS\system32\enppmon.dll [558592 2012-11-12] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert]
HKLM\...\Print\Monitors\PCL hpz3lw72: C:\WINDOWS\system32\hpz3lw72.dll [55392 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\Software\...\AppCompatFlags\Custom\GDFirewallTray.exe: [{97a7185d-397f-4652-a72c-d3a08820d734}.sdb] -> G DATA Firewall Helper
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2025-11-06] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\142.0.7444.177\Installer\chrmstp.exe [2025-12-03] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\beAClientSecurity.lnk [2025-03-06]
ShortcutTarget: beAClientSecurity.lnk -> C:\Program Files\BRAK\beAClientSecurity\beAClientSecurity.exe (Westernacher Solutions GmbH -> BRAK)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {918C212D-5423-44FC-9514-5779CD027542} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {1B8AD741-46C4-4F06-8C54-4430142650B6} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {C5EF4074-F552-4B5B-8FF6-6A0840998378} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {645158C3-4F16-4B53-A7CD-64369104B621} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task (Keine Datei)
Task: {247E9090-3494-4630-AA58-F2512E098AB1} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c (Keine Datei)
Task: {D15270AF-3120-43B2-A1F5-9513BC85E394} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler (Keine Datei)
Task: {B0DF7DBB-31B7-4A44-80D3-C5BA012AB794} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {88FF893D-A778-4B1D-A8FA-E7B48E20F7EF} => C:\Windows\System32\spool\drivers\x64\3\E_ITSLEE.EXE [679488 2013-02-27] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {59992A3F-8F8D-47C9-858B-346F28D79CF6} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {CA42A70E-0E15-4E23-9A48-7D73866A977F} => C:\Windows\System32\spool\drivers\x64\3\E_ITSLEE.EXE [679488 2013-02-27] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {78ADE258-0A09-45DB-8E79-1118AEEB90CD} - System32\Tasks\EPSON XP-412 413 415 Series Update {88FF893D-A778-4B1D-A8FA-E7B48E20F7EF} => C:\Windows\System32\spool\drivers\x64\3\E_ITSLEE.EXE [679488 2013-02-27] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {4C994935-7077-472B-B13D-41F9F7E01075} - System32\Tasks\EPSON XP-412 413 415 Series Update {CA42A70E-0E15-4E23-9A48-7D73866A977F} => C:\Windows\System32\spool\drivers\x64\3\E_ITSLEE.EXE [679488 2013-02-27] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {F83AB708-E8D3-4EDB-B084-E49D90100584} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{7983665F-A255-48CF-95E7-6BED4354102D} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC)
Task: {F0ACA6B1-ED55-4EF6-BA39-0488858714AA} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2017-04-07] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\-task -source HPSA
Task: {93D6DA40-2CE5-47E7-89E3-D9626A193C35} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant printer driver installation => C:\windows\TEMP\sp80798.exe (Keine Datei) <==== ACHTUNG
Task: {5CA7C220-F632-4403-9207-258DBC3D8E77} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1490800 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\\/taskrestart
Task: {C195DACF-0B2C-4A68-8EB3-B5A2CCD6F9B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [120680 2017-06-22] (HP Inc. -> HP Inc.)
Task: {2BBA6962-F86B-4B0F-820B-808FAF94D87B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\\/u
Task: {97CAB777-31C7-4B1F-814D-FF47F86DEC1C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1490800 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\\/L Analysis
Task: {25A931AE-7651-4BAC-AE33-AD74D94266FF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [219512 2018-12-24] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\\/noreport
Task: {C87F0A32-46CE-4B12-9466-9BDBA7775A43} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1136984 2020-09-16] (HP Inc. -> HP Inc.)
Task: {253BBB7F-0A0A-4BA0-8CE2-77F17EC16763} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1136984 2020-09-16] (HP Inc. -> HP Inc.)
Task: {7DA2E34F-7B33-4969-BDB3-3D574F258452} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
Task: {E101397B-7FF9-4BBE-8CF1-973B4A454F6F} - System32\Tasks\HPCeeScheduleForandre => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-10] (HP Inc. -> HP Inc.)
Task: {7E377C72-7AE8-41E5-A08C-E9ED241E40A3} - System32\Tasks\HPEA3JOBS => C:\Program -> Files\HP\HP ePrint\hpeprint.exe /CheckJobs
Task: {8D9C3CC8-AA70-40A1-B764-84982E2B643E} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [459680 2017-05-12] (HP Inc. -> )
Task: {AB5C80E9-48F3-4520-A9C0-252B1134354C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572096 2025-10-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {DDDB89C9-A8B7-42DB-9EC8-BDCB1EB6BD1F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23572096 2025-10-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {66AC97FC-BD31-43DD-B5ED-AE5EAEF739F9} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209896 2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {C7C5BFD2-56B1-43B1-93BB-CCD4C3E42F87} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209896 2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {3B6511C7-1D7B-4707-8136-85961079FC2E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514912 2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {B5D85059-C2AA-4010-9626-0F0462127141} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514912 2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
Task: {19B29276-289B-49EC-B514-6C674D2A0143} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {32121831-6D7D-4231-8389-EB737DAC8A78} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [696960 2025-12-05] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {28CD72B0-CC24-48E6-9516-B8ADC8BB9598} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1848193933-1176477381-3855437060-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [696960 2025-12-05] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {8053371B-571F-4327-BF53-CFF891F4F58A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2025-12-05] (Mozilla Corporation -> Mozilla Foundation)
Task: {AEFDC7E2-B491-4F79-AB53-2A60ADE35391} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-1848193933-1176477381-3855437060-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4856440 2025-12-09] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {0E7722E5-6DDC-45C5-9101-C2F24FCA075A} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-1848193933-1176477381-3855437060-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [4856440 2025-12-09] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {ADC66D40-7B08-4FDC-90ED-B31998EF3DA6} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6274680 2025-12-09] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (Der Dateneintrag hat 58 weitere Zeichen).
Task: {8E3D99A8-E20B-4702-A36C-9FF9E057A078} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9239776 2025-11-25] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {08081B6F-B5EF-41A1-92F8-FB1797EEEF17} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279544 2018-09-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {E217856C-6DDC-4DF0-BA24-F09F64C7F295} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [49032 2017-10-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {EA76AA6E-5E07-411A-B3D0-A6AF7542334D} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [49032 2017-10-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {687FF7A8-ECE1-4515-9A37-6226A2F48100} - System32\Tasks\StartDVR => "C:\Program Files\AMD\CNext\CNext\RSServCmd.exe" (Keine Datei)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Invitation {88FF893D-A778-4B1D-A8FA-E7B48E20F7EF}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLEE.EXE
Task: C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Invitation {CA42A70E-0E15-4E23-9A48-7D73866A977F}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLEE.EXE
Task: C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Update {88FF893D-A778-4B1D-A8FA-E7B48E20F7EF}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLEE.EXE:/EXE:{88FF893D-A778-4B1D-A8FA-E7B48E20F7EF} /F:UpdateWORKGROUP\DESKTOP-NSB7UN7$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Update {CA42A70E-0E15-4E23-9A48-7D73866A977F}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLEE.EXE:/EXE:{CA42A70E-0E15-4E23-9A48-7D73866A977F} /F:UpdateWORKGROUP\DESKTOP-NSB7UN7$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForandre.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{389ef6bf-f96a-44c4-b1ef-0f111093ff44}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{389ef6bf-f96a-44c4-b1ef-0f111093ff44}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{389ef6bf-f96a-44c4-b1ef-0f111093ff44}\14E64627F69646140534235333: [DhcpNameServer] 10.90.81.78
Tcpip\..\Interfaces\{389ef6bf-f96a-44c4-b1ef-0f111093ff44}\34C616574696163702960586F6E656: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{389ef6bf-f96a-44c4-b1ef-0f111093ff44}\75C414E4D2656364142455: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{c034a3af-b3e4-445d-bcb3-e8d55f15023d}: [DhcpNameServer] 185.22.44.50 185.22.45.50
Tcpip\..\Interfaces\{d2f4a1cf-af1e-435e-bb7b-8439e561d685}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}: [DhcpDomain] speedport.ip
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}\14E64627F69646140534235333: [DhcpNameServer] 192.168.111.5
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}\34C616574696163702960586F6E656: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}\75C414E4D23354535443B4: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{f4373e96-994b-4485-a6bb-a15902d7e218}\75C414E4D23354535443B4: [DhcpDomain] speedport.ip
Edge:
=======
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\andre\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2025-11-25]
Edge Extension: (Google Docs Offline) - C:\Users\andre\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-30]
Edge Extension: (Edge relevant text changes) - C:\Users\andre\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-06-03]
FireFox:
========
FF DefaultProfile: hk0qqh0i.default-1586355490513
FF ProfilePath: C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513 [2025-12-16]
FF DownloadDir: G:\Dalina
FF Notifications: Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513 -> hxxps://www.urbia.de; hxxps://lotto-hessen.signalize.com; hxxps://www.medimops.de; hxxps://www.sailer-verlag.de; hxxps://www.instagram.com; hxxps://x2convert.com; hxxps://www.mydealz.de; hxxps://www.n-tv.de; hxxps://twitter.com; hxxps://www.ran.de; hxxps://www.facebook.com; hxxps://www.elternwissen.com; hxxps://mail.google.com; hxxps://www.hood.de; hxxps://kundenbereich.check24.de; hxxps://mail.aol.com; hxxps://www.ab-in-den-urlaub.de
FF Extension: (AdBlocker Ultimate) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\adblockultimate@adblockultimate.net.xpi [2021-07-26]
FF Extension: (Easy Screenshot) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\easyscreenshot@mozillaonline.com.xpi [2023-01-03]
FF Extension: (Expressionist – Balanced) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\expressionist-balanced-colorway@mozilla.org.xpi [2023-03-18]
FF Extension: (To Google Translate) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2025-10-09]
FF Extension: (Shoop Cashback & Gutscheine) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\lisa@qipu.de.xpi [2025-08-07]
FF Extension: (New Tab) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\newtab@mozilla.org.xpi [2025-11-25]
FF Extension: (Block Site) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\{54e2eb33-18eb-46ad-a4e4-1329c29f6e17}.xpi [2025-11-21]
FF Extension: (Video DownloadHelper) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-06-05]
FF Extension: (Zoom Extension) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\{bf855ead-d7c3-4c7b-9f88-9a7e75c0efdf}.xpi [2025-12-09]
FF Extension: (Page Screenshot) - C:\Users\andre\AppData\Roaming\Mozilla\Firefox\Profiles\hk0qqh0i.default-1586355490513\Extensions\{f52149fe-80cc-4d07-868d-c0e4a85453a0}.xpi [2025-12-13]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-11-18] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2025-12-06] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\andre\AppData\Local\Google\Chrome\User Data\Default [2025-12-16]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.faz.net
CHR Extension: (Google Docs Offline) - C:\Users\andre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-15]
CHR Extension: (Anwendungs-Launcher für Drive (von Google)) - C:\Users\andre\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-24]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\andre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-1848193933-1176477381-3855437060-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2020-01-17] (AMD) [Datei ist nicht signiert]
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [28341880 2025-12-09] (Gen Digital Inc. -> Gen Digital Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9499224 2025-10-27] (Microsoft Corporation -> Microsoft Corporation)
S3 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2019-09-05] (Dropbox, Inc -> Dropbox, Inc.)
S3 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [441664 2019-04-16] (Digital Wave Ltd -> Digital Wave Ltd.)
S3 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-16] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
S3 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [471040 2017-05-23] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (Hewlett-Packard Company -> HP)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-12-12] (Huawei Technologies Co., Ltd. -> ) [Datei ist nicht signiert]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11207664 2025-12-16] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-12-16] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.5-0\MpDefenderCoreService.exe [2063328 2025-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [714712 2017-06-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 RTUsbSwSrvc; C:\WINDOWS\RTUWPSrvcMain.exe [956816 2023-01-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182392 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2021-06-23] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [920768 2021-06-23] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 UrbanVPN-Service; C:\Program Files (x86)\UrbanVPN\bin\urban-vpn-service.exe [5149744 2025-02-07] (Urban Cyber Security Inc. -> )
S3 UrbanVPN-Updater; C:\Program Files (x86)\UrbanVPN\Urban Vpn Updater.exe [1038416 2025-02-07] (Urban Cyber Security Inc. -> Urban Cyber Security)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.5-0\NisSrv.exe [4426832 2025-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WifiAutoInstallSrv; C:\Program Files\TP-Link\WifiAutoInstall\WifiAutoInstallSrv.exe [141368 2021-02-08] (Realtek Semiconductor Corp. -> Realtek)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.5-0\MsMpEng.exe [290704 2025-12-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 dbupdate; "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /svc [X]
S3 dbupdatem; "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /medsvc [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2025-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-12] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2025-11-18] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234088 2025-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-12-16] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt.sys [212544 2025-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80984 2025-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245336 2025-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2025-12-16] (Malwarebytes Inc -> Malwarebytes)
R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2018-07-27] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 rtwlanu6; C:\WINDOWS\System32\drivers\rtwlanu6.sys [7487408 2023-01-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2025-12-11] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [635272 2025-12-11] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2025-12-11] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2025-12-16 21:48 - 2025-12-16 21:50 - 000038449 ____C C:\Users\andre\Desktop\FRST.txt
2025-12-16 21:48 - 2025-12-16 21:50 - 000000000 ____D C:\FRST
2025-12-16 21:47 - 2025-12-16 21:48 - 002444288 ____C (Farbar) C:\Users\andre\Desktop\FRST64.exe
2025-12-16 21:14 - 2025-12-16 21:14 - 000000000 ____H C:\Users\andre\BIT178B.tmp
2025-12-16 20:45 - 2025-12-16 20:49 - 000000000 ___DC C:\Users\andre\AppData\LocalLow\IGDump
2025-12-16 20:45 - 2025-12-16 20:45 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-12-16 20:44 - 2025-12-16 21:50 - 000000000 ____D C:\Users\andre\AppData\Local\Malwarebytes
2025-12-16 20:44 - 2025-12-16 20:44 - 000002100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-12-16 20:44 - 2025-12-16 20:44 - 000002088 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2025-12-16 20:43 - 2025-12-16 20:43 - 002844952 ____C (Malwarebytes) C:\Users\andre\Desktop\MBSetup.exe
2025-12-16 20:43 - 2025-12-16 20:43 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-12-16 12:27 - 2025-12-16 12:27 - 000001726 ____C C:\Users\andre\Desktop\partypoker.de.lnk
2025-12-12 18:16 - 2025-12-12 18:16 - 000002041 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Privater Modus.lnk
2025-12-12 18:16 - 2025-12-05 19:01 - 000390272 ____C (Mozilla Foundation) C:\Users\andre\Desktop\Firefox.exe
2025-12-11 09:28 - 2025-12-11 09:28 - 000001119 ____C C:\Users\andre\Desktop\888Poker.lnk
2025-12-11 09:28 - 2025-12-11 09:28 - 000001105 ____C C:\Users\andre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\888Poker.lnk
2025-12-11 09:28 - 2025-12-11 09:28 - 000001099 ____C C:\Users\andre\AppData\Roaming\Microsoft\Windows\Start Menu\888Poker.lnk
2025-12-11 09:28 - 2025-12-11 09:28 - 000000000 ____D C:\Users\andre\AppData\Roaming\888poker.de
2025-12-09 22:40 - 2025-12-09 22:40 - 000000000 ____D C:\Users\andre\AppData\Roaming\PokerInstallerLogs
2025-11-27 10:27 - 2025-11-27 10:27 - 000000000 ____D C:\Users\andre\AppData\Local\BRAK
2025-11-25 11:26 - 2025-12-09 13:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\Piriform
2025-11-25 11:26 - 2025-11-25 11:26 - 000002163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 7.lnk
2025-11-25 11:26 - 2025-11-25 11:26 - 000002151 _____ C:\Users\Public\Desktop\CCleaner 7.lnk
2025-11-25 11:26 - 2025-11-25 11:26 - 000000000 ____D C:\Users\andre\AppData\Roaming\CCleaner
2025-11-25 11:25 - 2025-11-25 11:25 - 000056128 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-11-25 11:25 - 2025-11-25 11:25 - 000000000 ____D C:\Program Files\Piriform
2025-11-25 11:25 - 2025-11-25 11:25 - 000000000 ____D C:\Program Files\Common Files\Piriform
2025-11-18 19:28 - 2025-11-18 19:28 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-11-17 10:15 - 2025-12-16 20:38 - 000003126 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2025-11-17 00:02 - 2025-11-17 00:02 - 000000000 ____D C:\WINDOWS\Panther
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2025-12-16 21:46 - 2020-08-10 20:29 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-12-16 21:28 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-12-16 21:17 - 2018-01-16 08:29 - 000000000 ___DC C:\Users\andre\AppData\Roaming\Microsoft\Word
2025-12-16 21:14 - 2022-03-01 12:42 - 000003256 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForandre
2025-12-16 21:14 - 2022-03-01 12:42 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForandre.job
2025-12-16 21:14 - 2020-08-10 19:31 - 000000000 ____D C:\Users\andre
2025-12-16 21:09 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-12-16 21:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-12-16 20:54 - 2018-01-15 17:12 - 000000000 __SDC C:\Users\andre\AppData\Roaming\Microsoft\Credentials
2025-12-16 20:44 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-12-16 20:44 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2025-12-16 20:43 - 2019-12-25 20:34 - 000000000 ____D C:\Program Files\Malwarebytes
2025-12-16 20:40 - 2022-02-09 16:58 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-12-16 20:39 - 2023-05-06 10:13 - 000000000 ___SD C:\Users\andre\MagentaCLOUD
2025-12-16 20:39 - 2021-12-18 00:14 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-12-16 20:38 - 2025-10-07 08:55 - 000003112 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2025-12-16 20:28 - 2020-08-10 20:35 - 001886680 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-12-16 20:28 - 2019-12-07 15:50 - 000785596 _____ C:\WINDOWS\system32\perfh007.dat
2025-12-16 20:28 - 2019-12-07 15:50 - 000167710 _____ C:\WINDOWS\system32\perfc007.dat
2025-12-16 20:23 - 2025-05-18 08:39 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-12-16 20:23 - 2020-08-10 20:37 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-12-16 20:23 - 2020-08-10 20:29 - 000008192 ___SH C:\DumpStack.log.tmp
2025-12-16 20:23 - 2018-01-15 17:24 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-12-16 20:01 - 2023-09-05 08:24 - 000000000 ____D C:\WINDOWS\RTUWPSrvcMain
2025-12-16 20:01 - 2023-05-06 10:11 - 000000000 ____D C:\Users\andre\AppData\Roaming\MagentaCLOUD
2025-12-16 20:01 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2025-12-16 20:01 - 2018-12-06 20:49 - 000000000 ___DC C:\Users\andre\AppData\Roaming\Microsoft\Excel
2025-12-16 20:01 - 2017-10-23 04:58 - 000065536 _____ C:\WINDOWS\psp_storage.bin
2025-12-16 19:58 - 2023-03-09 20:35 - 000000000 ____D C:\Users\andre\AppData\Local\CrashDumps
2025-12-16 12:27 - 2020-10-19 13:23 - 000001750 ____C C:\Users\andre\AppData\Roaming\Microsoft\Windows\Start Menu\partypoker.de.lnk
2025-12-15 19:52 - 2020-08-10 20:37 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-12-15 19:52 - 2020-08-10 20:37 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-12-12 21:42 - 2020-06-24 08:06 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-12-12 21:42 - 2020-06-24 08:06 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-12-12 18:16 - 2021-10-05 21:32 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-12-12 18:16 - 2018-01-15 17:24 - 000001072 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-12-12 11:56 - 2020-08-10 20:29 - 000528648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-12-12 11:56 - 2020-08-10 19:31 - 000000000 ____D C:\Users\postgres
2025-12-12 11:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-12-12 11:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-12-12 11:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-12-12 11:45 - 2018-01-15 22:42 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-12-12 11:40 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-12-12 11:40 - 2018-01-15 22:42 - 218369424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-12-12 11:36 - 2020-08-10 20:32 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-12-11 20:09 - 2022-10-13 11:47 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2025-12-11 09:28 - 2018-06-04 13:11 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-12-10 15:40 - 2021-09-08 18:19 - 000002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2025-12-10 15:40 - 2021-09-08 18:19 - 000002015 _____ C:\Users\Default\Desktop\Google Slides.lnk
2025-12-10 15:40 - 2021-09-08 18:19 - 000002015 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2025-12-10 15:40 - 2021-09-08 18:19 - 000002003 _____ C:\Users\Default\Desktop\Google Docs.lnk
2025-12-05 11:16 - 2018-02-16 10:26 - 000000000 ___DC C:\Users\andre\AppData\Local\Packages
2025-12-03 19:41 - 2018-10-09 10:25 - 000002300 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-12-03 19:41 - 2018-10-09 10:25 - 000002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-11-25 11:29 - 2020-12-15 11:35 - 000000000 ____D C:\Users\andre\AppData\Roaming\discord
2025-11-25 11:25 - 2022-07-08 10:41 - 000000000 ____D C:\ProgramData\Piriform
2025-11-25 11:25 - 2018-04-23 09:16 - 000000000 ____D C:\Program Files\CCleaner
2025-11-23 10:29 - 2022-10-13 11:47 - 000002131 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2025-11-18 19:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-11-18 19:26 - 2024-09-23 08:28 - 000000000 ____D C:\Program Files\Microsoft Office
2025-11-17 00:00 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-11-17 00:00 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-11-17 00:00 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-11-17 00:00 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-11-17 00:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-11-17 00:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-11-17 00:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-11-16 23:04 - 2023-12-18 13:05 - 000000000 ____D C:\Program Files (x86)\Akademische Arbeitsgemeinschaft
2025-11-16 17:40 - 2018-06-25 09:32 - 000000000 ___DC C:\Users\andre\AppData\Local\D3DSCache
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2018-01-15 22:58 - 2018-01-15 22:58 - 000000000 ____C () C:\Users\andre\AppData\Roaming\gdfw.log
2018-01-15 22:58 - 2018-01-15 22:58 - 000000779 ____C () C:\Users\andre\AppData\Roaming\gdscan.log
2020-08-25 21:05 - 2020-08-25 21:05 - 000000000 _____ () C:\Users\andre\AppData\Local\{63ADE9C1-5FF8-4811-9393-329A5E81912B}
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
Addition.txt in der Antwort |
| Themen zu Pishing Email angeklickt |
| .dll, 192.168.0.2, administrator, adobe, bonjour, defender, email, firefox, google, home, installation, mozilla, performance, pishing, pishingmail, port, prozesse, realtek, registry, security, services.exe, svchost.exe, temp, updates, usb, windows |