Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Laut e-mails wurde ein RAT installiert. Stimmt das?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Thema geschlossen
Alt 29.07.2026, 11:42   #1
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Servus,

ich hab gestern 300 mails gekriegt:

Code:
ATTFilter
SYSTEM ALERT // CRITICAL PRIVACY BREACH DETECTED

> INITIATING MESSAGE...

Check the "From" field. This message was sent from your own email account: ka.schirmer@t-online.de. I bypassed your mail server's authentication protocols, which allowed me to intercept your credentials and route this message directly to your inbox. This is your proof that I currently have access.

Your compromised password: xxxxxxxx [steht im Klartext]

Over the past few weeks, I have been silently monitoring your activity. I gained initial access through a compromised application, and shortly after, I deployed a Remote Access Trojan (RAT). Because it operates at the driver level, it is completely invisible to your antivirus software.

Through this access, I have collected your messaging history, files, and contact lists. More importantly, I have recorded explicit video footage of you via your webcam while you were visiting adult entertainment websites. I have compiled these videos alongside your contact list into a single archive.

This is not personal; it is strictly business. I have no interest in ruining your reputation, but I will release this footage to your colleagues, family, and friends if you do not comply.

Action Required

WARNING: Opening this email triggered a remote ping to my server.
The automated release script is now active.

You have exactly 8 hours from the moment you read this message to complete the payment.

Required Payment (BTC)

$500.00 USD

Bitcoin Wallet Address

bc1qkx5mfvxdf9548qqweg6wse9d3ddpv9glnts487

To ensure the permanent deletion of your data, you must make a one-time payment of $500 in Bitcoin (BTC). An automated script is tracking the blockchain for my wallet. If the payment is not received within 8 hours, the script will automatically initiate the distribution of the video file to your contacts. Once the funds are confirmed, the script aborts, and the malware self-destructs. We will never contact each other again.

> IMPORTANT RESTRICTIONS:

1. Do not reply to this email.
2. Do not contact law enforcement.
3. Do not reset your devices.

Your data is already backed up on my remote servers. Any attempt to interfere will trigger an immediate release of the files before the timer expires.

System Notice: How to complete the transaction

If you do not own Bitcoin, you can acquire it quickly within the 8-hour window:
1. Create an account on a trusted exchange (e.g., Coinbase, Binance, or Kraken).
2. Purchase $500 USD worth of Bitcoin (BTC) using your credit/debit card.
3. Withdraw the BTC to the wallet address provided above.
Alternatively, search for a local Bitcoin ATM to purchase with cash.

> END OF MESSAGE.
         

Ist das bekannt? Muss ich was machen?

E-mail Kennwörter sind geändert.


FRST-logs:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2026
durchgeführt von ich (Administrator) auf MINIKISTE (29-07-2026 11:59:30)
Gestartet von C:\Users\ich\Desktop\FRST64.exe
Geladene Profile: ich
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\146.0.3856.84\msedgewebview2.exe
(DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atieclxx.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(explorer.exe ->) (TradingView, Inc. -> TradingView, Inc.) C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj\TradingView.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <17>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\146.0.3856.84\msedgewebview2.exe <5>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <28>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2605.9.0_x64__8wekyb3d8bbwe\CalculatorApp.exe <2>
(svchost.exe ->) (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.6465_none_7e0fb53c7c8be091\TiWorker.exe
(TradingView, Inc. -> TradingView, Inc.) C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj\TradingView.exe <11>

==================== Registry (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [878584 2020-02-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\Installer\setup.exe [5379912 2026-07-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [MicrosoftEdgeAutoLaunch_751C59213C62DD7EB8DB14A3F1AC059D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5003304 2026-03-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [VLC Plus Player Updater] => C:\Users\ich\AppData\Local\VLC Plus Player Updater\Updater.exe [199888 2023-11-17] (Aller Media e.K. -> ) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [131508072 2026-07-23] (Microsoft Corporation -> Microsoft Corporation) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (Keine Datei) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.045.0308.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.045.0308.0001" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.040.0301.0001_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.040.0301.0001_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.051.0316.0004] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.051.0316.0004" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.045.0308.0001_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.045.0308.0001_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.055.0323.0004] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.055.0323.0004" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.062.0402.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.062.0402.0002" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.062.0402.0002_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.062.0402.0002_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.070.0414.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.070.0414.0001" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.078.0426.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.078.0426.0002" (Keine Datei)
IFEO\eucloneserver.exe: [GlobalFlag] 

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {1C78BB52-D722-4176-9808-8042632697F8} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {148BF502-EBE0-4840-A89D-529297418C7F} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AC27279C-89A1-4D48-9A6A-ABE2307D4BE1} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {A35FC8BE-A762-4580-8F3F-169579B3EEC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {C31F4F16-1598-4CF6-AC7F-E3F71929F506} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {9161EDBC-D5DC-430D-AF8B-9B1809BE10CF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {E07A43E3-4BC0-431A-988C-4E2964CED342} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E528E4C-8E64-4DAB-8DAB-F37E97A1E71B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D62085FB-4AE8-44EA-ABEB-A7F82CAF653A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {0705BE94-4705-40F5-8202-6DFBF49E7FA7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3DD69CE5-C8B8-4C64-9988-EF794F4EBFB3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {11F50817-2A45-46DA-AA8F-7D8C9AED6AD4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5205BAD0-1544-4EAB-AFEA-DD741539AA13} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4BFDD6AC-F72E-43AC-A2F1-2F9A123102B5} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {EE9F17DF-2969-4532-8F12-AF68198FEF75} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2554665034-2769250351-2666445128-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {4D777CA7-B499-4232-85EB-BFFC65C9281B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {E99244D7-9235-4B43-9515-62E8897C0AC6} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [622040 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
Task: {09BAA0E5-10B4-4424-8E70-0544213E7D5A} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {51C54EF4-49F1-4345-85A9-C704CE822DA4} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {85CB1741-D3B6-4B7C-95A5-E44C56527E48} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {873F6BCD-35F7-4A77-9359-954B776C85B8} - System32\Tasks\VLC Plus Player Updater => C:\Users\ich\AppData\Local\VLC Plus Player Updater\Updater.exe [199888 2023-11-17] (Aller Media e.K. -> ) <==== ACHTUNG
Task: {0A7B7829-72E1-4435-A3F8-F9FBD38107C9} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001 => C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpNameServer] 192.168.111.15
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpDomain] fritz.box

FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: jz7hsqat.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\fp3qcvzs.default [2020-02-24]
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release [2026-07-29]
FF Session Restore: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
FF Extension: (Lush – Balanced) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\lush-balanced-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (New Tab) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\newtab@mozilla.org.xpi [2026-07-28]
FF Extension: (Visionary – Bold) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\visionary-bold-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (Snowflake) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{b11bea1f-a888-4332-8d8a-cec2be7d24b9}.xpi [2026-06-16]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-29]
Edge DefaultSearchURL: Default -> hxxps://www.ecosia.org/search?q={searchTerms}&addon=opensearch
Edge DefaultSearchKeyword: Default -> ecosia.org
Edge DefaultSuggestURL: Default -> hxxps://ac.ecosia.org/autocomplete?q={searchTerms}&type=list
Edge Extension: (Google Docs Offline) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-27]
Edge Extension: (Edge relevant text changes) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-30]

==================== Dienste (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [510936 0] (Advanced Micro Devices Inc. -> AMD)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9514352 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_8e2568524f674315\amdsafd.sys [100768 2021-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [62056 2020-07-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)

==================== SvcHost (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2026-07-29 11:59 - 2026-07-29 12:00 - 000023625 _____ C:\Users\ich\Desktop\FRST.txt
2026-07-29 11:57 - 2026-07-29 12:00 - 000000000 ____D C:\FRST
2026-07-29 11:55 - 2026-07-29 11:55 - 002449920 _____ (Farbar) C:\Users\ich\Desktop\FRST64.exe
2026-07-26 16:53 - 2026-07-26 22:46 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-07-26 16:53 - 2026-07-26 16:53 - 004162299 _____ C:\Users\ich\Downloads\Baupläne Igelburgen Stand 23.04.2025(1).pdf
2026-07-26 16:52 - 2026-07-26 16:52 - 000393984 _____ C:\Users\ich\Downloads\Geeignetes Nassfutter für Igel.pdf
2026-07-26 16:51 - 2026-07-26 16:51 - 000201064 _____ C:\Users\ich\Downloads\Geeignetes Trockenfutter für Igel.pdf
2026-07-25 18:02 - 2026-07-25 18:02 - 002082252 _____ C:\Users\ich\Downloads\ein_schlafhaus_fuer_igel_selber_bauen.pdf
2026-07-24 17:30 - 2026-07-24 17:30 - 000222611 _____ C:\Users\ich\Downloads\OS_FS-40 test-1.pdf
2026-07-24 15:52 - 2026-07-24 15:52 - 002000904 _____ C:\Users\ich\Downloads\4T_Leitfaden_02a-1.pdf
2026-07-23 21:54 - 2026-07-23 21:54 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 23:33 - 2026-07-21 23:33 - 000229156 _____ C:\Users\ich\Downloads\modellbautool.zip
2026-07-21 10:53 - 2026-07-21 10:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER

==================== Ein Monat (geänderte) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2026-07-29 11:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-29 11:29 - 2020-07-14 19:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-29 10:47 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-29 10:47 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-29 10:44 - 2020-06-17 19:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-29 10:43 - 2021-12-18 15:18 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-29 00:12 - 2022-02-11 18:23 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-28 16:51 - 2024-12-19 12:01 - 000004250 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-28 11:15 - 2021-10-20 14:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-28 11:15 - 2020-02-24 18:46 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 22:46 - 2020-03-08 18:45 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-07-26 20:41 - 2020-02-24 18:17 - 000000000 ____D C:\Users\ich\AppData\Local\D3DSCache
2026-07-23 17:20 - 2025-01-29 23:08 - 000003572 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2021-12-11 13:22 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2020-07-14 19:24 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2020-07-14 19:05 - 000002377 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-23 10:24 - 2021-02-02 13:28 - 000000000 ____D C:\Users\ich\AppData\Roaming\Microsoft\Excel
2026-07-22 10:24 - 2020-07-14 19:24 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-22 10:24 - 2020-07-14 19:24 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-21 10:53 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2026-07-21 10:52 - 2020-03-04 11:51 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-17 15:38 - 2020-02-24 15:51 - 000000000 ____D C:\Users\ich\AppData\Local\Packages
2026-07-16 20:11 - 2020-02-24 18:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-16 20:08 - 2020-02-24 18:39 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-09 21:01 - 2020-02-24 15:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========

2026-03-02 22:50 - 2026-03-02 22:50 - 000000028 _____ () C:\Users\ich\AppData\Roaming\epm_user.ini
2023-11-26 17:26 - 2023-11-26 17:26 - 000000036 _____ () C:\Users\ich\AppData\Local\_LOCAL_GUID

==================== SigCheck ============================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

==================== Ende von FRST.txt ========================
         

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 27-07-2026
durchgeführt von ich (29-07-2026 12:02:26)
Gestartet von C:\Users\ich\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) (2020-07-14 17:24:24)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

Administrator (S-1-5-21-2554665034-2769250351-2666445128-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2554665034-2769250351-2666445128-503 - Limited - Disabled)
Gast (S-1-5-21-2554665034-2769250351-2666445128-501 - Limited - Disabled)
ich (DisplayName: )  (S-1-5-21-2554665034-2769250351-2666445128-1001 - Administrators - Enabled) => C:\Users\ich
WDAGUtilityAccount (S-1-5-21-2554665034-2769250351-2666445128-504 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

5KPlayer (HKLM-x32\...\5KPlayer) (Version: 6.3 - DearMob, Inc.)
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.116 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.11.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 5.0.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 21.6.1 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{72ADA61A-C86E-4954-8B2B-1CDDC30D2F88}) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.)
ATTO Disk Benchmark (HKLM-x32\...\{B483E952-8CDD-4EDA-9CD1-956FA1DF3846}) (Version: 4.010.4001 - ATTO Technology)
Branding64 (HKLM\...\{C871FC62-0186-40ED-BAEA-7C65BE367755}) (Version: 1.00.0006 - Advanced Micro Devices, Inc.) Hidden
DRmare Spotify Music Converter 2.9.2.470 (HKLM-x32\...\DRmare Spotify Music Converter_is1) (Version:  - DRmare Studio.)
FinanzmanagerV8 (HKLM-x32\...\{78E2401D-39D5-4023-B0BF-7FA96F3FD425}_is1) (Version: 12.1.1.2 - Ackisoft)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.105 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Volume - de-de) (Version: 16.0.10417.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\OneDriveSetup.exe) (Version: 26.123.0628.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 (HKLM-x32\...\{855e31d2-9031-46e1-b06d-c9d7777deefb}) (Version: 14.28.29913.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 (HKLM-x32\...\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 (HKLM-x32\...\{6F0267F3-7467-350D-A8C8-33B72E3658D8}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 (HKLM-x32\...\{7753EC39-3039-3629-98BE-447C5D869C09}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 (HKLM\...\{620A7633-7A09-42A8-8580-076A4483C4B0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 (HKLM\...\{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 153.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.6.0 - Mozilla)
Mozilla Thunderbird ESR (x64 de) (HKLM\...\Mozilla Thunderbird 140.13.0 ESR (x64 de)) (Version: 140.13.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8710.1 - Realtek Semiconductor Corp.)
RyzenMasterSDK (HKLM\...\{22DFF94E-1F6F-463F-9F14-425610714166}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Spotify (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Spotify) (Version: 1.2.67.560.g46a15f6b - Spotify AB)
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.13.6 - TeamViewer)
Telegram Desktop (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.10 - Telegram FZ-LLC)
Trader Workstation (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\5889-6375-8446-2021) (Version: latest (10.39.1d) 20250729 16:04:39 - Interactive Brokers LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
VLC Plus Player Updater (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\AM VLC Plus Player Updater) (Version: 1.2.231101 - ) <==== ACHTUNG
Windows-PC-Integritätsprüfung (HKLM\...\{63EFBDB5-01B0-4614-BE9F-7F1908E42275}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows-PC-Integritätsprüfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Zoom Workplace (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)

Packages:
=========
Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-09-22] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_165.4.1108.0_x64__v10z8vjag6ke6 [2026-07-14] (HP Inc.)
Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-09-18] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
PDF X -> C:\Program Files\WindowsApps\6760NGPDFLab.PDFX_1.4.26.0_x64__sbe4t8mqwq93a [2026-04-27] (NG PDF Lab)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2020-02-24] (Realtek Semiconductor Corp)
TradingView -> C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj [2026-07-17] (TradingView, Inc.) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm [2026-04-01] (WhatsApp Inc.) [Startup Task]
XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.9.0_x86__xpfg3f7e9an52 [2026-05-23] (New Work SE)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{2C72ECAC-94DB-4B5A-9A7B-DFBB8F91600D}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{c0ad642c-00c1-4a64-9231-64a029585d50}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> Keine Datei
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============

2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 003567616 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 000912896 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 003109888 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000575488 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Device.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000048640 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Platform.dll
2020-10-13 14:34 - 2019-02-21 18:00 - 000078336 _____ (Igor Pavlov) [Datei ist nicht signiert] C:\Program Files\7-Zip\7-zip.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000039424 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000414720 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000025088 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000024576 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000023552 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000532992 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001441792 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001189888 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000134656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006184448 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006867456 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000735232 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Multimedia.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000120832 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5MultimediaQuick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001104896 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000325120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 003668480 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000517120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlModels.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000051712 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlWorkerScript.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 004228608 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000171008 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001085440 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000480256 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5RemoteObjects.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000205824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000329728 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000127488 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000390656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 095598080 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 005587968 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000462848 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000188928 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 002878464 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000055808 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000059392 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000262144 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtMultimedia\declarative_multimedia.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQml\qmlplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000284160 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000333824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000136704 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000090112 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000313856 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000091648 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

DNS Servers: 192.168.178.1
 ist aktiviert.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ich\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\1823424666669546968\134296975926575021.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{61DAA257-E0C3-4F25-910C-565F1BDD5E19}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{44552941-A547-419B-AC9A-4FAF93919AA4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E3AA84FE-6205-4252-90DD-A762CF95E430}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{18EF6F25-1412-4775-A9F9-25B9D8FC2677}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{45B79D01-1582-45CB-8EF4-B68F2698C36A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04B6C09F-8A95-4A1D-A8C0-D4FFFCD172AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3B1FA3A1-C9DF-4F04-B816-5BBC85DCE4B4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D267263A-8AAD-44BB-8631-5E3FA416F0EB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{374EA369-A884-4DCC-A03F-22F8A88C6DFA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{36C32310-F6A8-4642-A399-FCDAE182241A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E867D3D0-A4E7-454A-BBA7-317EF443BE51}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{927AB9BB-26EE-4E53-9E51-BFEDF15EF318}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{76EF7034-F429-4CB1-9B18-7FCDB7CEB806}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [{9D80857B-3AB5-437A-8D60-1FEBD0BD3E9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{74B3FD42-45BD-4A9B-AD42-ADBC6D52F56A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{79E1FF7C-5958-43B7-914D-38BB35A903D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0FC30D72-008B-465F-A3F4-003A3D09303F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{598FC530-827C-435E-A0ED-4845AD284CF1}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{822C11B3-B37F-4DD7-9828-38EB47660BF6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AA1F03BE-7545-4453-8473-F5EB37BD3031}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{87EEB120-96CB-49BC-BEB6-A4C31D654E60}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{61D1FF96-53A5-4C23-B2E6-0DC6E02AC31F}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{DE9743AE-5721-4EBB-ABE0-A85296D8D925}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{76719E5A-8201-4551-AA76-089599D2AA01}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56823129-AA6B-4BA5-8697-5F90CDCC2CC4}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{B93C0938-E753-418F-8FF9-882A4A0AE3C5}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [TCP Query User{EB4FC249-39F8-4AE0-B8D3-D2CDD8F77B6A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{C59548F9-4A18-48AA-A17F-465B4B3AFC61}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{733EC7B5-130F-4EB0-945C-27417A924A57}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{61890F17-7742-4040-961E-6F72946863CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{76EC9F12-C838-402A-85DC-130235097AB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3DD5003D-EEC0-4B76-8AD1-CFC2CD17D253}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:100.59 GB) (Free:30.69 GB) (31%)

==================== Fehlerhafte Geräte im Gerätemanager ============

==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (04/12/2026 09:32:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x14e4
Startzeit der fehlerhaften Anwendung: 0x01dcc2071af365ef
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 4e7b1853-af90-4211-8701-9198bf15de72
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (04/01/2026 08:41:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 01 Apr 2026 18:41:31 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d47307eb-d44b-4fc1-8e6f-7b73a64a57f3

Methode: GET(734ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/13/2026 10:58:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x1254
Startzeit der fehlerhaften Anwendung: 0x01dcae30e59bf607
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 60b38bb2-e4c1-4c39-b9e5-572064572a80
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (03/07/2026 02:50:35 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sat, 07 Mar 2026 12:50:36 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8adcde60-a460-4738-b6f3-760a6307c300

Methode: GET(328ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/05/2026 10:55:25 AM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Thu, 05 Mar 2026 08:55:24 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: fd264e2e-0cdf-4351-b129-4d42eb912658

Methode: GET(453ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/02/2026 10:52:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Das Programm AISprite.exe Version 0.0.0.0 hat die Interaktion mit Windows beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1ca0

Startzeit: 01dcaa8645c4c42b

Beendigungszeit: 167

Anwendungspfad: C:\Program Files\EaseUS\EaseUS Partition Master\bin\AISprite.exe

Bericht-ID: 3af370b9-136f-45b2-b388-ea2c66b29163

Vollständiger Name des fehlerhaften Pakets: 

Relative Anwendungs-ID des fehlerhaften Pakets: 

Absturztyp: Unknown

Error: (03/02/2026 10:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: dwm.exe, Version: 10.0.19041.4355, Zeitstempel: 0x6564cf4e
Name des fehlerhaften Moduls: dwmcore.dll, Version: 10.0.19041.6456, Zeitstempel: 0x071e2bd4
Ausnahmecode: 0xc00001ad
Fehleroffset: 0x0000000000216f2f
ID des fehlerhaften Prozesses: 0x624
Startzeit der fehlerhaften Anwendung: 0x01dc902026ae90ff
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\dwm.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\dwmcore.dll
Berichtskennung: 887e0236-f9c6-474e-94dc-24c44b43acda
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (02/27/2026 03:49:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: msedge.exe, Version: 144.0.3719.115, Zeitstempel: 0x6983cd0b
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.19041.6280, Zeitstempel: 0x56511854
Ausnahmecode: 0xe0000008
Fehleroffset: 0x0000000000025369
ID des fehlerhaften Prozesses: 0x20b8
Startzeit der fehlerhaften Anwendung: 0x01dc9aa654e409ed
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\KERNELBASE.dll
Berichtskennung: 697e523a-7bbf-42c9-89c2-94af170e001f
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:


Systemfehler:
=============
Error: (07/29/2026 10:46:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop

Error: (07/29/2026 10:46:10 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/28/2026 07:25:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/27/2026 03:52:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop

Error: (07/27/2026 03:38:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/26/2026 08:41:53 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/25/2026 06:23:01 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop

Error: (07/25/2026 06:03:54 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller


Windows Defender:
================
TimeCreated : 28.07.2026 22:56:36 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F4838B2A-8F1C-4208-A563-A4F0E8D5B5B6}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 27.07.2026 22:41:05 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{97CCA619-B1D6-40F6-B049-4D8485303A5E}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 27.07.2026 15:52:56 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{0F5ECE31-8205-4EC4-BC6E-C1B3AF0E667E}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 25.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{58D50D97-2BA7-4DCA-B98E-FDA1FC876235}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 24.07.2026 22:58:44 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F1E3ED12-ADA8-43AC-8FE6-285FF5EB5EF6}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 22.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F005FCA6-B5F5-4BB2-9B45-F060534EFFAD}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 21.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{46A80609-5805-4BF8-9C5F-E019B177665C}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 20.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{EEC40400-621D-43AB-9DE8-60E0B84D1041}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 

CodeIntegrity:
===============
Date: 2023-11-15 22:38:04
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-11-04 12:40:43
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-09-14 14:38:27
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-08-15 17:01:02
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-08-10 00:12:03
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

BIOS: American Megatrends Inc. P3.50 05/15/2019
Hauptplatine: ASRock A300M-STX
Prozessor: AMD Athlon 200GE with Radeon Vega Graphics 
Prozentuale Nutzung des RAM: 66%
Installierter physikalischer RAM: 14269.9 MB
Verfügbarer physikalischer RAM: 4730.62 MB
Summe virtueller Speicher: 32701.9 MB
Verfügbarer virtueller Speicher: 14076.85 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:100.59 GB) (Free:30.69 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
Drive d: (Daten) (Fixed) (Total:263.96 GB) (Free:160.77 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS

\\?\Volume{2588bb51-4ecb-4703-927e-87241e53487c}\ (Wiederherstellung) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{2e77b4c7-e5c8-462c-995d-caa9d9a39aa9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partitionstabelle ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0833C066)

Partition: GPT.

==================== Ende von Addition.txt =======================
         
Danke und Grüße

Karsten

Alt 29.07.2026, 13:40   #2
M-K-D-B
/// TB-Ausbilder
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?






Mein Name ist Matthias und ich werde dir bei der Analyse und Bereinigung deines Systems helfen.





Zitat:
Zitat von Knecht Beitrag anzeigen
Ist das bekannt? Muss ich was machen?
Ja, das ist alles bekannt.
Das ist zu 100% eine Fake-Email. Alle Informationen darin sind gelogen.
Du kannst ganz locker bleiben, was das angeht.

Bitte die betroffenen Mails einfach als Spam markieren und löschen (lassen). Zukünftige Mails dieser Art sollten dann automatisch abgefangen werden.




Unabhängig von den Spam-Mails sehe ich etwas PUP auf deinem System.
Das sollten wir entfernen.
Bist du bereit dafür?
__________________


Alt 29.07.2026, 13:46   #3
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Das ist Spam. Ignorieren und löschen. Dein weitaus größeres Problem lautet Windows 10!

Zitat:
Microsoft Windows 10 Pro Version 22H2 19045.6466
Updatestand von November 2025. Also fast ein Jahr alt.
Der Rechner insbesondere die CPU ist nicht gerade neuwertig...ich würde an deiner Stelle mal einen neuen PC einplanen.

Alternativen:
a) Alle Daten sichern und dann mit einem neu installierten Linux weitermachen.
b) Bei Windows 10 bleiben und und versuchen die ESU-Updates zu aktivieren. Geht nur mit Microsoft-Konto. Und nur bei privaten Kisten, die kein Domänenmitglied sein dürfen.

Variante (b) ist keine echte Lösung, da sie das Unvermeidliche nur für ein Jahr hinauszögert.
__________________
__________________

Alt 29.07.2026, 15:08   #4
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Hi Matthias,
wow, schnelle Antwort und ich bin schonmal entspannt, dass ich keine Infektion hab! Ich frage mich aber schon, wo das Kennwort herkommt, das in der mail bei "xxxxxx" steht. Das war mein Kennwort für das Telekom-Kundencenter (webmailing).

Ansonsten,
Code:
ATTFilter
Unabhängig von den Spam-Mails sehe ich etwas PUP auf deinem System.
Das sollten wir entfernen.
Bist du bereit dafür?
         
ja, kann losgehen.

Code:
ATTFilter
Updatestand von November 2025. Also fast ein Jahr alt.
Der Rechner insbesondere die CPU ist nicht gerade neuwertig...ich würde an deiner Stelle mal einen neuen PC einplanen.
         
Steht schon auf dem Plan. Erstmal mit dem Trick von der c't auf W11 upgraden, obwohl die Hardware es eigentlich nicht hergibt, später Umstieg auf Linux.

Alt 29.07.2026, 15:29   #5
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Zitat:
Zitat von Knecht Beitrag anzeigen
Ich frage mich aber schon, wo das Kennwort herkommt, das in der mail bei "xxxxxx" steht. Das war mein Kennwort für das Telekom-Kundencenter (webmailing).
Da musst du jetzt mal in dich gehen und überlegen, ob du etwas leichtsinnig mit deinen Passwörtern umgehst. Und ob du ein und dasselbe Passwort bei verschiedenen Logins nutzt. Oft ist nämlich genau das ein Riesenproblem, weil eben Betreiber von Shopsystemen oder anderen wo ein Kundenlogin erforderlich ist, selbst ein lohnendes Angriffsziel sind, weil dort wegen sehr unkluger Designentscheidungen Passwörter leicht auslesbarin ihrer Datenbank stehen (im Klartext oder immerhin noch ungesalzen)
Und die Angreifer wissen genau, dass viele Menschen faul sind und sich nicht viele Passwörter merken wollen. Die gehen davon aus, dass viele ein einziges Standardpasswort haben, dass sie überall nutzen.
On Top kommen die vielen mittlerweile monatealten Sicherheitslücken in deinem Windows 10 da ja der Updatestand von November 2025 ist.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 29.07.2026, 20:20   #6
M-K-D-B
/// TB-Ausbilder
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Zitat:
Zitat von Knecht Beitrag anzeigen
ja, kann losgehen.
Ok, lass uns anfangen.




Schritt 1
Die folgenden Programme sind veraltet, stören die Bereinigung oder es handelt sich um Werbesoftware (Adware) bzw. Potentiell Unerwünschte Programme (PUP) und müssen entfernt werden.
  • Deinstalliere über Start > Einstellungen > Apps die folgenden Programme:
    • VLC Plus Player Updater
  • Starte den Rechner im Anschluss neu.
  • Gib eine kurze Rückmeldung, ob die Deinstallation erfolgreich war.



Schritt 2
Führe AdwCleaner gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei.



Schritt 3
Führe Malwarebytes' AntiMalware (MBAM) gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei.

Alt 30.07.2026, 08:47   #7
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



29.07.:

Läuft.

VLC ist deinstalliert.


AdwCleaner:

Code:
ATTFilter
# -------------------------------
# Malwarebytes AdwCleaner 8.8.1.639
# -------------------------------
# Build:    05-13-2026
# Database: 2026-04-29.3 (Local)
# Support:  https://help.malwarebytes.com/
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    07-29-2026
# Duration: 00:00:17
# OS:       Windows 10 (Build 19045.6466)
# Scanned:  32087
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
         


In MBAM finde ich nichts, um den Bericht aufzurufen. Ich kann auch keinen screenshot hier einfügen.

30.07.:

Moin,

nach dem automatischen scan der MBAM Testversion von eben konnte ich einen Bericht aufrufen:

Code:
ATTFilter
Malwarebytes
www.malwarebytes.com

-Protokolldetails-
Scan-Datum: 30.07.2026
Scan-Zeit: 09:33
Protokolldatei: ff704362-8be8-11f1-a8b9-7085c2fb617c.json

-Softwaredaten-
Version: 5.6.3.277
Komponentenversion: 161.0.5685
Version des Aktualisierungspakets: 1.0.112698
Lizenz: Testversion

-Systemdaten-
Betriebssystem: Windows 10 (Build 19045.6466)
CPU: x64
Dateisystem: NTFS
Benutzer: System

-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Zeitplaner
Ergebnis: Abgeschlossen
Gescannte Objekte: 187.459
Erkannte Bedrohungen: 0
In die Quarantäne verschobene Bedrohungen: 0
Scandauer: 1 Min., 14 Sek.

-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung

-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)

Modul: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswert: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Daten-Stream: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Datei: 0
(keine bösartigen Elemente erkannt)

Physischer Sektor: 0
(keine bösartigen Elemente erkannt)

WMI: 0
(keine bösartigen Elemente erkannt)


(end)
         

Alt 30.07.2026, 14:06   #8
M-K-D-B
/// TB-Ausbilder
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Gut gemacht.


FRST-Scan
  • Starte FRST erneut und klicke auf Untersuchen.
  • FRST erstellt nun zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.

Alt 30.07.2026, 14:57   #9
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Zitat:
Gut gemacht.
Danke

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 29-07-2026
durchgeführt von ich (Administrator) auf MINIKISTE (30-07-2026 15:52:24)
Gestartet von C:\Users\ich\Desktop\FRST64.exe
Geladene Profile: ich
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe
(DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atieclxx.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <20>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2605.9.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(svchost.exe ->) (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.129.0706.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [878584 2020-02-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Beschränkung <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [MicrosoftEdgeAutoLaunch_751C59213C62DD7EB8DB14A3F1AC059D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
IFEO\eucloneserver.exe: [GlobalFlag] 

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {1C78BB52-D722-4176-9808-8042632697F8} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {148BF502-EBE0-4840-A89D-529297418C7F} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AC27279C-89A1-4D48-9A6A-ABE2307D4BE1} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {A35FC8BE-A762-4580-8F3F-169579B3EEC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {C31F4F16-1598-4CF6-AC7F-E3F71929F506} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {9161EDBC-D5DC-430D-AF8B-9B1809BE10CF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {E07A43E3-4BC0-431A-988C-4E2964CED342} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E528E4C-8E64-4DAB-8DAB-F37E97A1E71B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D62085FB-4AE8-44EA-ABEB-A7F82CAF653A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {4BFDD6AC-F72E-43AC-A2F1-2F9A123102B5} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {EE9F17DF-2969-4532-8F12-AF68198FEF75} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2554665034-2769250351-2666445128-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {4D777CA7-B499-4232-85EB-BFFC65C9281B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {E99244D7-9235-4B43-9515-62E8897C0AC6} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [622040 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
Task: {09BAA0E5-10B4-4424-8E70-0544213E7D5A} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {51C54EF4-49F1-4345-85A9-C704CE822DA4} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {85CB1741-D3B6-4B7C-95A5-E44C56527E48} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {0A7B7829-72E1-4435-A3F8-F9FBD38107C9} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001 => C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpNameServer] 192.168.111.15
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpDomain] fritz.box

FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: jz7hsqat.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\fp3qcvzs.default [0]
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release [0]
FF Session Restore: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
FF Extension: (Lush – Balanced) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\lush-balanced-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (New Tab) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\newtab@mozilla.org.xpi [2026-07-28]
FF Extension: (Visionary – Bold) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\visionary-bold-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2026-07-29]
FF Extension: (Snowflake) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{b11bea1f-a888-4332-8d8a-cec2be7d24b9}.xpi [2026-06-16]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default [0]
Edge DefaultSearchURL: Default -> hxxps://www.ecosia.org/search?q={searchTerms}&addon=opensearch
Edge DefaultSearchKeyword: Default -> ecosia.org
Edge DefaultSuggestURL: Default -> hxxps://ac.ecosia.org/autocomplete?q={searchTerms}&type=list
Edge Extension: (Google Docs Offline) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [0]
Edge Extension: (Edge relevant text changes) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [0]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Dienste (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [510936 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9514352 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_8e2568524f674315\amdsafd.sys [100768 2021-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [62056 2020-07-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-07-29] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt.sys [215656 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2026-07-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [616880 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)

==================== SvcHost (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2026-07-30 15:52 - 2026-07-30 15:53 - 000020403 _____ C:\Users\ich\Desktop\FRST.txt
2026-07-30 15:50 - 2026-07-30 15:50 - 002449408 _____ (Farbar) C:\Users\ich\Desktop\FRST64.exe
2026-07-30 09:43 - 2026-07-30 09:43 - 000001412 _____ C:\Users\ich\Desktop\Malwarebytes Bedrohungsscan-Bericht 2026-07-30 093345.txt
2026-07-29 22:10 - 2026-07-29 22:10 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-07-29 22:08 - 2026-07-30 09:47 - 000000000 ____D C:\Users\ich\AppData\Local\Malwarebytes
2026-07-29 22:08 - 2026-07-29 22:08 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-29 22:08 - 2026-07-29 22:08 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-07-29 22:08 - 2026-07-29 22:08 - 000000000 ____D C:\Users\ich\AppData\Local\Sentry
2026-07-29 22:07 - 2026-07-29 22:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-29 22:07 - 2026-07-29 22:07 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-29 22:03 - 2026-07-29 22:03 - 000000000 ____D C:\AdwCleaner
2026-07-29 21:51 - 2026-07-29 21:51 - 002862824 _____ (Malwarebytes) C:\Users\ich\Desktop\MBSetup-7.7.exe
2026-07-29 21:50 - 2026-07-29 21:50 - 009630992 _____ (Malwarebytes) C:\Users\ich\Desktop\adwcleaner.exe
2026-07-29 19:32 - 2026-07-29 19:32 - 000002163 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive Photos.lnk
2026-07-29 19:22 - 2026-07-29 19:22 - 000000000 ___HD C:\$Windows.~WS
2026-07-29 11:57 - 2026-07-30 15:52 - 000000000 ____D C:\FRST
2026-07-26 16:53 - 2026-07-29 22:00 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-07-26 16:53 - 2026-07-26 16:53 - 004162299 _____ C:\Users\ich\Downloads\Baupläne Igelburgen Stand 23.04.2025(1).pdf
2026-07-26 16:52 - 2026-07-26 16:52 - 000393984 _____ C:\Users\ich\Downloads\Geeignetes Nassfutter für Igel.pdf
2026-07-26 16:51 - 2026-07-26 16:51 - 000201064 _____ C:\Users\ich\Downloads\Geeignetes Trockenfutter für Igel.pdf
2026-07-25 18:02 - 2026-07-25 18:02 - 002082252 _____ C:\Users\ich\Downloads\ein_schlafhaus_fuer_igel_selber_bauen.pdf
2026-07-24 17:30 - 2026-07-24 17:30 - 000222611 _____ C:\Users\ich\Downloads\OS_FS-40 test-1.pdf
2026-07-24 15:52 - 2026-07-24 15:52 - 002000904 _____ C:\Users\ich\Downloads\4T_Leitfaden_02a-1.pdf
2026-07-23 21:54 - 2026-07-30 15:26 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 23:33 - 2026-07-21 23:33 - 000229156 _____ C:\Users\ich\Downloads\modellbautool.zip
2026-07-21 10:53 - 2026-07-21 10:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER

==================== Ein Monat (geänderte) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2026-07-30 15:39 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-30 15:32 - 2020-07-14 19:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-30 10:05 - 2021-12-18 15:18 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-29 22:29 - 2022-02-11 18:23 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-29 22:09 - 2020-07-14 19:28 - 001632088 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-07-29 22:09 - 2019-12-07 16:51 - 000706062 _____ C:\WINDOWS\system32\perfh007.dat
2026-07-29 22:09 - 2019-12-07 16:51 - 000142356 _____ C:\WINDOWS\system32\perfc007.dat
2026-07-29 22:09 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-07-29 22:08 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-07-29 22:03 - 2020-02-24 18:17 - 000000000 ____D C:\Users\ich\AppData\Local\D3DSCache
2026-07-29 22:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-29 22:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-29 22:00 - 2020-07-14 19:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-07-29 22:00 - 2020-03-20 13:51 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2026-07-29 22:00 - 2020-02-24 18:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-07-29 22:00 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-07-29 19:42 - 2024-08-13 23:54 - 000000000 ____D C:\WINDOWS\Panther
2026-07-29 19:42 - 2021-01-22 13:19 - 000000000 ____D C:\ESD
2026-07-29 19:32 - 2025-01-29 23:08 - 000003572 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2021-12-11 13:22 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2020-07-14 19:24 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2020-07-14 19:05 - 000002377 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-29 19:21 - 2020-07-14 19:05 - 000000000 ____D C:\Users\ich
2026-07-29 10:44 - 2020-06-17 19:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-28 16:51 - 2024-12-19 12:01 - 000004250 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-28 11:15 - 2021-10-20 14:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-28 11:15 - 2020-02-24 18:46 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 22:46 - 2020-03-08 18:45 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-07-23 10:24 - 2021-02-02 13:28 - 000000000 ____D C:\Users\ich\AppData\Roaming\Microsoft\Excel
2026-07-22 10:24 - 2020-07-14 19:24 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-22 10:24 - 2020-07-14 19:24 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-21 10:53 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2026-07-21 10:52 - 2020-03-04 11:51 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-17 15:38 - 2020-02-24 15:51 - 000000000 ____D C:\Users\ich\AppData\Local\Packages
2026-07-16 20:11 - 2020-02-24 18:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-16 20:08 - 2020-02-24 18:39 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-09 21:01 - 2020-02-24 15:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========

2026-03-02 22:50 - 2026-03-02 22:50 - 000000028 _____ () C:\Users\ich\AppData\Roaming\epm_user.ini
2023-11-26 17:26 - 2023-11-26 17:26 - 000000036 _____ () C:\Users\ich\AppData\Local\_LOCAL_GUID

==================== SigCheck ============================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

==================== Ende von FRST.txt ========================
         

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 29-07-2026
durchgeführt von ich (30-07-2026 15:53:52)
Gestartet von C:\Users\ich\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) (2020-07-14 17:24:24)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

Administrator (S-1-5-21-2554665034-2769250351-2666445128-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2554665034-2769250351-2666445128-503 - Limited - Disabled)
Gast (S-1-5-21-2554665034-2769250351-2666445128-501 - Limited - Disabled)
ich (DisplayName: )  (S-1-5-21-2554665034-2769250351-2666445128-1001 - Administrators - Enabled) => C:\Users\ich
WDAGUtilityAccount (S-1-5-21-2554665034-2769250351-2666445128-504 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

5KPlayer (HKLM-x32\...\5KPlayer) (Version: 6.3 - DearMob, Inc.)
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.116 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.11.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 5.0.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 21.6.1 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{72ADA61A-C86E-4954-8B2B-1CDDC30D2F88}) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.)
ATTO Disk Benchmark (HKLM-x32\...\{B483E952-8CDD-4EDA-9CD1-956FA1DF3846}) (Version: 4.010.4001 - ATTO Technology)
Branding64 (HKLM\...\{C871FC62-0186-40ED-BAEA-7C65BE367755}) (Version: 1.00.0006 - Advanced Micro Devices, Inc.) Hidden
DRmare Spotify Music Converter 2.9.2.470 (HKLM-x32\...\DRmare Spotify Music Converter_is1) (Version:  - DRmare Studio.)
FinanzmanagerV8 (HKLM-x32\...\{78E2401D-39D5-4023-B0BF-7FA96F3FD425}_is1) (Version: 12.1.1.2 - Ackisoft)
Malwarebytes version 5.6.3.277 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.3.277 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.105 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Volume - de-de) (Version: 16.0.10417.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\OneDriveSetup.exe) (Version: 26.129.0706.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 (HKLM-x32\...\{855e31d2-9031-46e1-b06d-c9d7777deefb}) (Version: 14.28.29913.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 (HKLM-x32\...\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 (HKLM-x32\...\{6F0267F3-7467-350D-A8C8-33B72E3658D8}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 (HKLM-x32\...\{7753EC39-3039-3629-98BE-447C5D869C09}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 (HKLM\...\{620A7633-7A09-42A8-8580-076A4483C4B0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 (HKLM\...\{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 153.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.6.0 - Mozilla)
Mozilla Thunderbird ESR (x64 de) (HKLM\...\Mozilla Thunderbird 140.13.0 ESR (x64 de)) (Version: 140.13.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8710.1 - Realtek Semiconductor Corp.)
RyzenMasterSDK (HKLM\...\{22DFF94E-1F6F-463F-9F14-425610714166}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Spotify (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Spotify) (Version: 1.2.67.560.g46a15f6b - Spotify AB)
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.13.6 - TeamViewer)
Telegram Desktop (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.10 - Telegram FZ-LLC)
Trader Workstation (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\5889-6375-8446-2021) (Version: latest (10.39.1d) 20250729 16:04:39 - Interactive Brokers LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Windows-PC-Integritätsprüfung (HKLM\...\{63EFBDB5-01B0-4614-BE9F-7F1908E42275}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows-PC-Integritätsprüfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Zoom Workplace (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)

Packages:
=========
Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-09-22] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_165.4.1108.0_x64__v10z8vjag6ke6 [2026-07-14] (HP Inc.)
Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-02-15] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
PDF X -> C:\Program Files\WindowsApps\6760NGPDFLab.PDFX_1.4.26.0_x64__sbe4t8mqwq93a [2026-04-27] (NG PDF Lab)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2020-02-24] (Realtek Semiconductor Corp)
TradingView -> C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj [2026-07-17] (TradingView, Inc.) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm [2026-07-24] (WhatsApp Inc.) [Startup Task]
XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.9.0_x86__xpfg3f7e9an52 [2021-06-12] (New Work SE)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{2C72ECAC-94DB-4B5A-9A7B-DFBB8F91600D}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{c0ad642c-00c1-4a64-9231-64a029585d50}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-29] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> Keine Datei
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-29] (Malwarebytes Inc -> Malwarebytes)

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============

2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 003567616 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2021-03-12 06:18 - 2021-03-12 06:18 - 000756736 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AODDevice.dll
2021-03-12 06:18 - 2021-03-12 06:18 - 023854080 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AODPlatform.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 000912896 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 003109888 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000575488 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Device.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000048640 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Platform.dll
2020-10-13 14:34 - 2019-02-21 18:00 - 000078336 _____ (Igor Pavlov) [Datei ist nicht signiert] C:\Program Files\7-Zip\7-zip.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000039424 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000414720 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000025088 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000024576 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000023552 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000532992 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001441792 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001189888 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000134656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006184448 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006867456 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000735232 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Multimedia.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000120832 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5MultimediaQuick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001104896 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000325120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 003668480 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000517120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlModels.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000051712 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlWorkerScript.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 004228608 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000171008 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001085440 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000480256 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5RemoteObjects.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000205824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000329728 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000127488 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000390656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 095598080 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 005587968 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000462848 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000188928 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 002878464 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000055808 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000059392 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000262144 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtMultimedia\declarative_multimedia.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQml\qmlplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000284160 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000333824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000136704 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000090112 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000313856 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000091648 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\Users\ich\Desktop\FRST64.exe:MBAM.Zone.Identifier [225]

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

DNS Servers: 192.168.178.1
 ist aktiviert.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ich\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\1823424666669546968\134298008784579201.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{61DAA257-E0C3-4F25-910C-565F1BDD5E19}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{44552941-A547-419B-AC9A-4FAF93919AA4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E3AA84FE-6205-4252-90DD-A762CF95E430}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{18EF6F25-1412-4775-A9F9-25B9D8FC2677}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{45B79D01-1582-45CB-8EF4-B68F2698C36A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04B6C09F-8A95-4A1D-A8C0-D4FFFCD172AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3B1FA3A1-C9DF-4F04-B816-5BBC85DCE4B4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D267263A-8AAD-44BB-8631-5E3FA416F0EB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{374EA369-A884-4DCC-A03F-22F8A88C6DFA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{36C32310-F6A8-4642-A399-FCDAE182241A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E867D3D0-A4E7-454A-BBA7-317EF443BE51}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{927AB9BB-26EE-4E53-9E51-BFEDF15EF318}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{76EF7034-F429-4CB1-9B18-7FCDB7CEB806}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [{9D80857B-3AB5-437A-8D60-1FEBD0BD3E9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{74B3FD42-45BD-4A9B-AD42-ADBC6D52F56A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{79E1FF7C-5958-43B7-914D-38BB35A903D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0FC30D72-008B-465F-A3F4-003A3D09303F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{598FC530-827C-435E-A0ED-4845AD284CF1}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{822C11B3-B37F-4DD7-9828-38EB47660BF6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AA1F03BE-7545-4453-8473-F5EB37BD3031}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{87EEB120-96CB-49BC-BEB6-A4C31D654E60}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{61D1FF96-53A5-4C23-B2E6-0DC6E02AC31F}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{DE9743AE-5721-4EBB-ABE0-A85296D8D925}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{76719E5A-8201-4551-AA76-089599D2AA01}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56823129-AA6B-4BA5-8697-5F90CDCC2CC4}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{B93C0938-E753-418F-8FF9-882A4A0AE3C5}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [TCP Query User{EB4FC249-39F8-4AE0-B8D3-D2CDD8F77B6A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{C59548F9-4A18-48AA-A17F-465B4B3AFC61}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{733EC7B5-130F-4EB0-945C-27417A924A57}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{61890F17-7742-4040-961E-6F72946863CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{76EC9F12-C838-402A-85DC-130235097AB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3DD5003D-EEC0-4B76-8AD1-CFC2CD17D253}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:100.59 GB) (Free:31.73 GB) (32%)

==================== Fehlerhafte Geräte im Gerätemanager ============

==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (07/29/2026 10:00:44 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 29 Jul 2026 20:00:45 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8b42e0f9-c0c4-4e33-840e-6b17d2c7b24f

Methode: GET(422ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (04/12/2026 09:32:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x14e4
Startzeit der fehlerhaften Anwendung: 0x01dcc2071af365ef
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 4e7b1853-af90-4211-8701-9198bf15de72
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (04/01/2026 08:41:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 01 Apr 2026 18:41:31 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d47307eb-d44b-4fc1-8e6f-7b73a64a57f3

Methode: GET(734ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/13/2026 10:58:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x1254
Startzeit der fehlerhaften Anwendung: 0x01dcae30e59bf607
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 60b38bb2-e4c1-4c39-b9e5-572064572a80
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (03/07/2026 02:50:35 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sat, 07 Mar 2026 12:50:36 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8adcde60-a460-4738-b6f3-760a6307c300

Methode: GET(328ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/05/2026 10:55:25 AM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITÄT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung für WORKGROUP\MINIKISTE$ über https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Thu, 05 Mar 2026 08:55:24 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: fd264e2e-0cdf-4351-b129-4d42eb912658

Methode: GET(453ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/02/2026 10:52:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Das Programm AISprite.exe Version 0.0.0.0 hat die Interaktion mit Windows beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1ca0

Startzeit: 01dcaa8645c4c42b

Beendigungszeit: 167

Anwendungspfad: C:\Program Files\EaseUS\EaseUS Partition Master\bin\AISprite.exe

Bericht-ID: 3af370b9-136f-45b2-b388-ea2c66b29163

Vollständiger Name des fehlerhaften Pakets: 

Relative Anwendungs-ID des fehlerhaften Pakets: 

Absturztyp: Unknown

Error: (03/02/2026 10:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: dwm.exe, Version: 10.0.19041.4355, Zeitstempel: 0x6564cf4e
Name des fehlerhaften Moduls: dwmcore.dll, Version: 10.0.19041.6456, Zeitstempel: 0x071e2bd4
Ausnahmecode: 0xc00001ad
Fehleroffset: 0x0000000000216f2f
ID des fehlerhaften Prozesses: 0x624
Startzeit der fehlerhaften Anwendung: 0x01dc902026ae90ff
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\dwm.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\dwmcore.dll
Berichtskennung: 887e0236-f9c6-474e-94dc-24c44b43acda
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:


Systemfehler:
=============
Error: (07/30/2026 09:25:44 AM) (Source: DCOM) (EventID: 10001) (User: MINIKISTE)
Description: Ein DCOM-Server konnte nicht gestartet werden: {F4DF18B4-A2CF-4B0A-8D62-954CD6AD2E33} als Nicht verfügbar/Nicht verfügbar. Fehler:
"2147942593"
Aufgetreten beim Start dieses Befehls:
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_22606.1401.10.0_x64__8wekyb3d8bbwe\StoreDesktopExtension.exe" -Embedding

Error: (07/29/2026 10:05:26 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT-AUTORITÄT)
Description: Die Zertifizierungsstelle/Schlüssel für den sicheren Start müssen aktualisiert werden. Diese Gerätesignaturinformationen sind hier enthalten.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P3.50;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:A300M-STX;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: af6804523f69fa8ba945f8732703d84288a7fece0e3e2b352e10b0e5b86891c3
BucketConfidenceLevel: 
UpdateType: 0
HResult: 0

Error: (07/29/2026 10:00:25 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎29.‎07.‎2026 um 21:54:19 unerwartet heruntergefahren.

Error: (07/29/2026 10:46:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop

Error: (07/29/2026 10:46:10 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/28/2026 07:25:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller

Error: (07/27/2026 03:52:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop

Error: (07/27/2026 03:38:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller


Windows Defender:
================
TimeCreated : 28.07.2026 22:56:36 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F4838B2A-8F1C-4208-A563-A4F0E8D5B5B6}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 27.07.2026 22:41:05 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{97CCA619-B1D6-40F6-B049-4D8485303A5E}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 27.07.2026 15:52:56 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{0F5ECE31-8205-4EC4-BC6E-C1B3AF0E667E}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 25.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{58D50D97-2BA7-4DCA-B98E-FDA1FC876235}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 24.07.2026 22:58:44 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F1E3ED12-ADA8-43AC-8FE6-285FF5EB5EF6}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 22.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{F005FCA6-B5F5-4BB2-9B45-F060534EFFAD}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 21.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{46A80609-5805-4BF8-9C5F-E019B177665C}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 
TimeCreated : 20.07.2026 22:41:10 Uhr
(Message     : Microsoft Defender Antivirus ÅŸÑãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmÏℓėťîÅи.%п %τŞÑåй ) (ÌĎ:%ÑŠ{EEC40400-621D-43AB-9DE8-60E0B84D1041}%Å‹ %ţŚĉãи Тỳрε:%ÑŠAntimalware%ņ %тŞÄал ) (Ð*άřαmёťÎ*ŕś:%ÑŒSchnellüberprüfung%л  %ŧЦÅєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%вÅ*Ñĥēδūŀ℮δ ś¢ÄÅ„ щäš ) (šκÄ*Ñ€Ï℮δ ÑŠÎ*ÄÃ¡Å±ÅŸÑ Å¥Ñ›Ã© ℓáśŧ šц¢Ñęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē â„“Ç»Åŧ 7 δäÿş) 

CodeIntegrity:
===============
Date: 2026-07-29 22:12:59
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.

Date: 2023-11-15 22:38:04
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-11-04 12:40:43
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

BIOS: American Megatrends Inc. P3.50 05/15/2019
Hauptplatine: ASRock A300M-STX
Prozessor: AMD Athlon 200GE with Radeon Vega Graphics 
Prozentuale Nutzung des RAM: 57%
Installierter physikalischer RAM: 14269.9 MB
Verfügbarer physikalischer RAM: 5996.85 MB
Summe virtueller Speicher: 30653.9 MB
Verfügbarer virtueller Speicher: 18109.14 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:100.59 GB) (Free:31.73 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
Drive d: (Daten) (Fixed) (Total:263.96 GB) (Free:158.08 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS

\\?\Volume{2588bb51-4ecb-4703-927e-87241e53487c}\ (Wiederherstellung) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{2e77b4c7-e5c8-462c-995d-caa9d9a39aa9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partitionstabelle ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0833C066)

Partition: GPT.

==================== Ende von Addition.txt =======================
         

Alt 30.07.2026, 15:29   #10
M-K-D-B
/// TB-Ausbilder
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Wir entfernen ein paar verwaiste Einträge und kontrollieren die Systemdateien auf Fehler.





Wir führen eine Reparatur mit FRST durch.
Dabei werden schädliche und verwaiste Einträge entfernt sowie temporären Dateien und der Papierkorb geleert. Außerdem werden die Systemdateien auf Fehler überprüft.

Bitte gedulde dich, sobald du die Reparatur gestartet hast. Je nach Art und Umfang der notwendigen Reparaturen kann dies einige Minuten dauern.
Eventuell erhältst du während der Reparatur auch die Information "keine Rückmeldung" von FRST. Das ist normal, du musst nichts weiter tun, nur abwarten.



Reparatur mit FRST
HINWEIS AN ALLE MITLESER:
Dieses FRST-Skript ist ausschließlich für diesen Nutzer gedacht und sollte niemals 1:1 für ein anderes System verwendet werden!

  • Speichere deine Arbeiten und schließe alle offenen Programme, damit keine Daten verloren gehen.
  • Markiere den gesamten Inhalt der folgenden Code-Box mit der Maus und kopiere ihn (gleichzeitiges Drücken der beiden Tasten "STRG" + "C"):
    Code:
    ATTFilter
    Start::
    CreateRestorePoint:
    CloseProcesses:
    HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
    IFEO\eucloneserver.exe: [GlobalFlag] 
    FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
    CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
    CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
    AlternateDataStreams: C:\Users\ich\Desktop\FRST64.exe:MBAM.Zone.Identifier [225]
    
    CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv
    
    CMD: netsh winsock reset
    CMD: netsh int ip reset
    CMD: netsh advfirewall reset
    CMD: netsh advfirewall set allprofiles state ON
    CMD: netsh winhttp reset proxy
    RemoveProxy:
    
    CMD: Winmgmt /salvagerepository 
    CMD: Winmgmt /verifyrepository
    CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
    CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
    CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
    CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
    CMD: Winmgmt /resyncperf
    
    CMD: reg query "HKLM\System\CurrentControlSet\Control\Session Manager\Environment" /S
    CMD: reg query "HKCU\Environment" /S
    
    CMD: sfc /scannow
    Hosts:
    EmptyEventLogs:
    EmptyTemp:
    End::
             
  • Starte nun FRST und klicke direkt auf den Button Reparieren.
    Wichtig: Du brauchst den Inhalt der Code-Box nirgends einfügen, da sich FRST den Code aus der Zwischenablage holt!
  • Das Tool führt die gewünschten Schritte aus und erstellt die Datei fixlog.txt im selben Verzeichnis, in dem sich FRST befindet.
  • Zum Abschluss wird das System neu gestartet.
  • Poste mir den Inhalt der Datei fixlog.txt mit deiner nächsten Antwort.

Alt 30.07.2026, 21:29   #11
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Code:
ATTFilter
Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 29-07-2026
durchgeführt von ich (30-07-2026 17:03:00) Run:1
Gestartet von C:\Users\ich\Desktop
Geladene Profile: ich
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
IFEO\eucloneserver.exe: [GlobalFlag] 
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
AlternateDataStreams: C:\Users\ich\Desktop\FRST64.exe:MBAM.Zone.Identifier [225]

CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv

CMD: netsh winsock reset
CMD: netsh int ip reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winhttp reset proxy
RemoveProxy:

CMD: Winmgmt /salvagerepository 
CMD: Winmgmt /verifyrepository
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: Winmgmt /resyncperf

CMD: reg query "HKLM\System\CurrentControlSet\Control\Session Manager\Environment" /S
CMD: reg query "HKCU\Environment" /S

CMD: sfc /scannow
Hosts:
EmptyEventLogs:
EmptyTemp:
End::
         
*****************

Wiederherstellungspunkt wurde erfolgreich erstellt.
Prozesse erfolgreich geschlossen.
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Acrobat Synchronizer" => erfolgreich entfernt
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\eucloneserver.exe => erfolgreich entfernt
"FF Notifications:" => erfolgreich entfernt
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000} => erfolgreich entfernt
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000} => erfolgreich entfernt
C:\Users\ich\Desktop\FRST64.exe => ":MBAM.Zone.Identifier" ADS erfolgreich entfernt

========= cscript /nologo %systemroot%\System32\slmgr.vbs /dlv =========

Softwarelizenzierungsdienst-Version: 10.0.19041.6456

Name: Windows(R), Professional edition
Beschreibung: Windows(R) Operating System, RETAIL channel
Aktivierungs-ID: 4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Anwendungs-ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Erweiterte PID: 03612-03308-000-000000-00-1031-19041.0000-1962020
Product Key-Kanal: Retail
Installations-ID: 040596417152700085086813238177281342063154884582129214249674564
Lizenz-URL verwenden: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
URL fr die šberprfung: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx
Teil-Product Key: 3V66T
Lizenzstatus: Lizenziert
Verbleibende Windows Rearm-Anzahl: 1001
Verbleibende SKU Rearm-Anzahl: 1001
Vertrauenswrdige Zeit: 30.07.2026 17:03:20




========= Ende von CMD: =========


========= netsh winsock reset =========


Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.



========= Ende von CMD: =========


========= netsh int ip reset =========

Depotweiterleitung wird zurckgesetzt... OK
Depot wird zurckgesetzt... OK
Steuerungsprotokoll wird zurckgesetzt... OK
Echosequenzanforderung wird zurckgesetzt... OK
Global wird zurckgesetzt... OK
Schnittstelle wird zurckgesetzt... OK
Anycastadresse wird zurckgesetzt... OK
Multicastadresse wird zurckgesetzt... OK
Unicastadresse wird zurckgesetzt... OK
Nachbar wird zurckgesetzt... OK
Pfad wird zurckgesetzt... OK
Potentiell wird zurckgesetzt... OK
Pr„fixrichtlinie wird zurckgesetzt... OK
Proxynachbar wird zurckgesetzt... OK
Route wird zurckgesetzt... OK
Standordpr„fix wird zurckgesetzt... OK
Unterschnittstelle wird zurckgesetzt... OK
Reaktivierungsmuster wird zurckgesetzt... OK
Nachbar aufl”sen wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... Fehler
Zugriff verweigert

 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
 wird zurckgesetzt... OK
Starten Sie den Computer neu, um die Aktion abzuschlieáen.



========= Ende von CMD: =========


========= netsh advfirewall reset =========

OK.



========= Ende von CMD: =========


========= netsh advfirewall set allprofiles state ON =========

OK.



========= Ende von CMD: =========


========= netsh winhttp reset proxy =========


Aktuelle WinHTTP-Proxyeinstellungen:

    DirectAccess (kein Proxyserver).



========= Ende von CMD: =========


========= RemoveProxy: =========

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt


========= Ende von RemoveProxy: =========


========= Winmgmt /salvagerepository =========

Das WMI-Repository ist konsistent.


========= Ende von CMD: =========


========= Winmgmt /verifyrepository =========

Das WMI-Repository ist konsistent.


========= Ende von CMD: =========


========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= Ende von CMD: =========


========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= Ende von CMD: =========


========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= Ende von CMD: =========


========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= Ende von CMD: =========


========= Winmgmt /resyncperf =========

0

========= Ende von CMD: =========


========= reg query "HKLM\System\CurrentControlSet\Control\Session Manager\Environment" /S =========


HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
    ComSpec    REG_EXPAND_SZ    %SystemRoot%\system32\cmd.exe
    DriverData    REG_SZ    C:\Windows\System32\Drivers\DriverData
    OS    REG_SZ    Windows_NT
    Path    REG_EXPAND_SZ    %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
    PATHEXT    REG_SZ    .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    REG_SZ    AMD64
    PSModulePath    REG_EXPAND_SZ    %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules
    TEMP    REG_EXPAND_SZ    %SystemRoot%\TEMP
    TMP    REG_EXPAND_SZ    %SystemRoot%\TEMP
    USERNAME    REG_SZ    SYSTEM
    windir    REG_EXPAND_SZ    %SystemRoot%
    NUMBER_OF_PROCESSORS    REG_SZ    4
    PROCESSOR_LEVEL    REG_SZ    23
    PROCESSOR_IDENTIFIER    REG_SZ    AMD64 Family 23 Model 17 Stepping 0, AuthenticAMD
    PROCESSOR_REVISION    REG_SZ    1100



========= Ende von CMD: =========


========= reg query "HKCU\Environment" /S =========


HKEY_CURRENT_USER\Environment
    Path    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
    TEMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp
    TMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp
    OneDrive    REG_EXPAND_SZ    C:\Users\ich\OneDrive



========= Ende von CMD: =========


========= sfc /scannow =========



Systemsuche wird gestartet. Dieser Vorgang kann einige Zeit dauern.



Überprüfungsphase der Systemsuche wird gestartet.


Überprüfung 0 % abgeschlossen.
Überprüfung 1 % abgeschlossen.
Überprüfung 1 % abgeschlossen.
Überprüfung 2 % abgeschlossen.
Überprüfung 3 % abgeschlossen.
Überprüfung 3 % abgeschlossen.
Überprüfung 4 % abgeschlossen.
Überprüfung 4 % abgeschlossen.
Überprüfung 5 % abgeschlossen.
Überprüfung 6 % abgeschlossen.
Überprüfung 6 % abgeschlossen.
Überprüfung 7 % abgeschlossen.
Überprüfung 7 % abgeschlossen.
Überprüfung 8 % abgeschlossen.
Überprüfung 9 % abgeschlossen.
Überprüfung 9 % abgeschlossen.
Überprüfung 10 % abgeschlossen.
Überprüfung 11 % abgeschlossen.
Überprüfung 11 % abgeschlossen.
Überprüfung 12 % abgeschlossen.
Überprüfung 12 % abgeschlossen.
Überprüfung 13 % abgeschlossen.
Überprüfung 14 % abgeschlossen.
Überprüfung 14 % abgeschlossen.
Überprüfung 15 % abgeschlossen.
Überprüfung 15 % abgeschlossen.
Überprüfung 16 % abgeschlossen.
Überprüfung 17 % abgeschlossen.
Überprüfung 17 % abgeschlossen.
Überprüfung 18 % abgeschlossen.
Überprüfung 18 % abgeschlossen.
Überprüfung 19 % abgeschlossen.
Überprüfung 20 % abgeschlossen.
Überprüfung 20 % abgeschlossen.
Überprüfung 21 % abgeschlossen.
Überprüfung 22 % abgeschlossen.
Überprüfung 22 % abgeschlossen.
Überprüfung 23 % abgeschlossen.
Überprüfung 23 % abgeschlossen.
Überprüfung 24 % abgeschlossen.
Überprüfung 25 % abgeschlossen.
Überprüfung 25 % abgeschlossen.
Überprüfung 26 % abgeschlossen.
Überprüfung 26 % abgeschlossen.
Überprüfung 27 % abgeschlossen.
Überprüfung 28 % abgeschlossen.
Überprüfung 28 % abgeschlossen.
Überprüfung 29 % abgeschlossen.
Überprüfung 30 % abgeschlossen.
Überprüfung 30 % abgeschlossen.
Überprüfung 31 % abgeschlossen.
Überprüfung 31 % abgeschlossen.
Überprüfung 32 % abgeschlossen.
Überprüfung 33 % abgeschlossen.
Überprüfung 33 % abgeschlossen.
Überprüfung 34 % abgeschlossen.
Überprüfung 34 % abgeschlossen.
Überprüfung 35 % abgeschlossen.
Überprüfung 36 % abgeschlossen.
Überprüfung 36 % abgeschlossen.
Überprüfung 37 % abgeschlossen.
Überprüfung 37 % abgeschlossen.
Überprüfung 38 % abgeschlossen.
Überprüfung 39 % abgeschlossen.
Überprüfung 39 % abgeschlossen.
Überprüfung 40 % abgeschlossen.
Überprüfung 41 % abgeschlossen.
Überprüfung 41 % abgeschlossen.
Überprüfung 42 % abgeschlossen.
Überprüfung 42 % abgeschlossen.
Überprüfung 43 % abgeschlossen.
Überprüfung 44 % abgeschlossen.
Überprüfung 44 % abgeschlossen.
Überprüfung 45 % abgeschlossen.
Überprüfung 45 % abgeschlossen.
Überprüfung 46 % abgeschlossen.
Überprüfung 47 % abgeschlossen.
Überprüfung 47 % abgeschlossen.
Überprüfung 48 % abgeschlossen.
Überprüfung 48 % abgeschlossen.
Überprüfung 49 % abgeschlossen.
Überprüfung 50 % abgeschlossen.
Überprüfung 50 % abgeschlossen.
Überprüfung 51 % abgeschlossen.
Überprüfung 52 % abgeschlossen.
Überprüfung 52 % abgeschlossen.
Überprüfung 53 % abgeschlossen.
Überprüfung 53 % abgeschlossen.
Überprüfung 54 % abgeschlossen.
Überprüfung 55 % abgeschlossen.
Überprüfung 55 % abgeschlossen.
Überprüfung 56 % abgeschlossen.
Überprüfung 56 % abgeschlossen.
Überprüfung 57 % abgeschlossen.
Überprüfung 58 % abgeschlossen.
Überprüfung 58 % abgeschlossen.
Überprüfung 59 % abgeschlossen.
Überprüfung 60 % abgeschlossen.
Überprüfung 60 % abgeschlossen.
Überprüfung 61 % abgeschlossen.
Überprüfung 61 % abgeschlossen.
Überprüfung 62 % abgeschlossen.
Überprüfung 63 % abgeschlossen.
Überprüfung 63 % abgeschlossen.
Überprüfung 64 % abgeschlossen.
Überprüfung 64 % abgeschlossen.
Überprüfung 65 % abgeschlossen.
Überprüfung 66 % abgeschlossen.
Überprüfung 66 % abgeschlossen.
Überprüfung 67 % abgeschlossen.
Überprüfung 67 % abgeschlossen.
Überprüfung 68 % abgeschlossen.
Überprüfung 69 % abgeschlossen.
Überprüfung 69 % abgeschlossen.
Überprüfung 70 % abgeschlossen.
Überprüfung 71 % abgeschlossen.
Überprüfung 71 % abgeschlossen.
Überprüfung 72 % abgeschlossen.
Überprüfung 72 % abgeschlossen.
Überprüfung 73 % abgeschlossen.
Überprüfung 74 % abgeschlossen.
Überprüfung 74 % abgeschlossen.
Überprüfung 75 % abgeschlossen.
Überprüfung 75 % abgeschlossen.
Überprüfung 76 % abgeschlossen.
Überprüfung 77 % abgeschlossen.
Überprüfung 77 % abgeschlossen.
Überprüfung 78 % abgeschlossen.
Überprüfung 79 % abgeschlossen.
Überprüfung 79 % abgeschlossen.
Überprüfung 80 % abgeschlossen.
Überprüfung 80 % abgeschlossen.
Überprüfung 81 % abgeschlossen.
Überprüfung 82 % abgeschlossen.
Überprüfung 82 % abgeschlossen.
Überprüfung 83 % abgeschlossen.
Überprüfung 83 % abgeschlossen.
Überprüfung 84 % abgeschlossen.
Überprüfung 85 % abgeschlossen.
Überprüfung 85 % abgeschlossen.
Überprüfung 86 % abgeschlossen.
Überprüfung 86 % abgeschlossen.
Überprüfung 87 % abgeschlossen.
Überprüfung 88 % abgeschlossen.
Überprüfung 88 % abgeschlossen.
Überprüfung 89 % abgeschlossen.
Überprüfung 90 % abgeschlossen.
Überprüfung 90 % abgeschlossen.
Überprüfung 91 % abgeschlossen.
Überprüfung 91 % abgeschlossen.
Überprüfung 92 % abgeschlossen.
Überprüfung 93 % abgeschlossen.
Überprüfung 93 % abgeschlossen.
Überprüfung 94 % abgeschlossen.
Überprüfung 94 % abgeschlossen.
Überprüfung 95 % abgeschlossen.
Überprüfung 96 % abgeschlossen.
Überprüfung 96 % abgeschlossen.
Überprüfung 97 % abgeschlossen.
Überprüfung 97 % abgeschlossen.
Überprüfung 98 % abgeschlossen.
Überprüfung 99 % abgeschlossen.
Überprüfung 99 % abgeschlossen.
Überprüfung 100 % abgeschlossen.


Der Windows-Ressourcenschutz hat beschädigte Dateien gefunden und erfolgreich repariert.

Bei Onlinereparaturen finden Sie Details in der CBS-Protokolldatei unter 

windir\Logs\CBS\CBS.log. Beispiel C:\Windows\Logs\CBS\CBS.log. Bei Offlinereparaturen

finden Sie Details in der durch das /OFFLOGFILE-Kennzeichen angegebenen Protokolldatei.



========= Ende von CMD: =========

C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.

=========== EmptyEventLogs: ==========

1181 Event logs cleared. 


================================

=========== EmptyTemp: ==========

FlushDNS => abgeschlossen
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 217677519 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 12103675 B
Edge => 885744113 B
Firefox => 2236687804 B
Opera => 0 B

Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 3 B
ProgramData => 0 B
Public => 0 B
systemprofile => 452317 B
systemprofile32 => 0 B
LocalService => 4301 B
NetworkService => 1726675 B
ich => 344113511 B

RecycleBin => 0 B
EmptyTemp: => 3.4 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 17:12:20 ====
         
Zwischenbemerkung: nach dem FRST-fix hab ich ein inplace-upgrade gemacht. Aus W10 ist W11 25H2 geworden.

Für die Mitleser: Microsoft bietet für diese Hardware kein W11 an. Man kann aber registry-Einträge machen, so dass es geht. Das Verfahren ist von MS dokumentiert. Die Anleitung hab ich aus der c't 5/2025.

Alt 30.07.2026, 22:39   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Zitat:
Zitat von Knecht Beitrag anzeigen
Für die Mitleser: Microsoft bietet für diese Hardware kein W11 an. Man kann aber registry-Einträge machen, so dass es geht. Das Verfahren ist von MS dokumentiert. Die Anleitung hab ich aus der c't 5/2025.
Wir kennen das. Da raten wir aber von ab, weil Microsoft derart alte Hardware nicht mehr testet - und man somit mit noch mehr Fehlern unter Windows 11 rechnen muss als es ohnehin schon gibt. Ob du mit der langsamen CPU unter Windows 11 zufrieden sein wirst, wird sich auch noch zeigen. Und du wirst jedes Jahr manuellen Aufwand haben, weil sich solche Installation nicht auf das aktuelle Release hochziehen wie zB 26H2, das in ein paar Monaten erscheinen wird.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 31.07.2026, 14:47   #13
M-K-D-B
/// TB-Ausbilder
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Gut gemacht.





FRST und alle dazugehörigen Elemente kannst du wie folgt entfernen:
  • Rechtsklicke auf die Datei FRST64.exe und wähle Umbenennen.
  • Benenne FRST64 in Uninstall um.
  • Starte die Datei Uninstall.exe.
  • FRST entfernt sich vollständig. Dazu wird ein Neustart eingeleitet.



AdwCleaner und MBAM könntest du natürlich auch entfernen.
Wir empfehlen diese kostenlosen Tools jedoch für regelmäßige Kontrollscans, weil sie sehr gut gegen Adware und PUPs sind.




Dann wären wir durch!
Wenn du keine Probleme mehr mit Malware hast, dann sind wir hier fertig. Deine Logdateien sind sauber.

Wenn Du möchtest, kannst Du hier sagen, ob du mit uns und unserer Hilfe zufrieden warst...
Vielleicht möchtest du das Forum mit einer kleinen Spende unterstützen.



Zum Schluss bitte unbedingt die Sicherheitsmaßnahmen lesen und umsetzen:



Hinweis:
Bitte gib mir eine kurze Rückmeldung, sobald du die oben verlinkten Informationen gelesen hast, alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Alt 31.07.2026, 18:00   #14
Knecht
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Hey Matthias,

erstmal noch ein Hinweis für alle MITLESER:
dieser Rechner wird demnächst auf LINUX umgestellt. Wie cosinus völlig richtig sagte, ist dieser Trick KEINE Dauerlösung. Ich wollte eigentlich nur sehen, ob das upgrade hier funktioniert und wie der Rechner damit läuft. Mit Linux kann man den auch noch 10 Jahre weiter nutzen ...

Zu deiner Bitte: euer Service war wie immer Spitzenklasse!
Hab alles gelesen und soweit erforderlich getan, keine Fragen offen!
Herzlichen Dank und damit ihr das hier noch ne Weile weiter macht, geht gleich ne SPENDE raus!

Alt 31.07.2026, 22:26   #15
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Laut e-mails wurde ein RAT installiert. Stimmt das? - Standard

Laut e-mails wurde ein RAT installiert. Stimmt das?



Zitat:
Zitat von Knecht Beitrag anzeigen
Mit Linux kann man den auch noch 10 Jahre weiter nutzen ...:
Perfekte Entscheidung!
Du kannst natürlich noch mit Windows 11 dein Glück versuchen. Aber das Leiden wird wohl groß sein. Wie gesagt, auf das nächste Release upzugraden ist mir nur ein Weg bekannt: komplette ISO runterladen, das Setup darin so ausführen:

Code:
ATTFilter
setup.exe /product server
         
Ich bin mir aber nicht sicher, ob das noch funktionieren wird. Manche schreiben, dass Microsoft diese "Lücke" bereits geschlossen hat. Vgl https://windowsarea.de/2024/08/micro...anforderungen/
Andererseits hat mir unser damaliger PC-Lieferant gesagt, dass Microsoft genau diese Möglichkeit offen lassen muss, weil sonst ein großer Kunde komplett von Windows weg gewesen wäre.
Rufus ist auch noch ne Möglichkeit. Das Tool erstellt aus einem offiziellen Windows11-ISO einen Installationsstick, aber so, dass Hardwareeinschränkungen nicht mehr drin sind.

Wie auch immer, ich denke nicht, dass Windows eine große Zukunft haben wird wenn das weiter so geht. Weißt du schon welches Linux du nutzen wirst?
__________________
Logfiles bitte immer in CODE-Tags posten

Thema geschlossen

Themen zu Laut e-mails wurde ein RAT installiert. Stimmt das?
antivirus, converter, defender, desktop, email, firefox, google, internet, internet explorer, malware, mozilla, performance, prozesse, realtek, registry, rundll, scan, server, services.exe, svchost.exe, system, trojan, udp, updates, windows




Ähnliche Themen: Laut e-mails wurde ein RAT installiert. Stimmt das?


  1. Windows 7 befürchte das Keylogger installiert wurde
    Log-Analyse und Auswertung - 15.08.2019 (1)
  2. Mails verschickt von eigenem Rechner - RAT?
    Plagegeister aller Art und deren Bekämpfung - 17.09.2018 (3)
  3. Rechnleistung floppt : Laut Scan "HKEY_USERS\...\SOFTWARE\ILIVID" : Ersuche Rat
    Log-Analyse und Auswertung - 22.06.2016 (18)
  4. Mein Laptop installiert ein Programm und ich habe ihm nicht gesagt das er das tun soll.
    Plagegeister aller Art und deren Bekämpfung - 17.06.2016 (4)
  5. Trojaner laut Telekom Madznu, versendet Mails
    Plagegeister aller Art und deren Bekämpfung - 04.06.2016 (16)
  6. Seit Tagen habe ich das Gefühl das irgendwas nicht stimmt mit dem PC. Er braucht sehr lange zum Start, er bleibt bei Youtube Videos einfach
    Alles rund um Windows - 04.08.2015 (1)
  7. Detekt fand die Trojaner BlackShades RAT, DarkComet RAT, Xtreme RAT
    Plagegeister aller Art und deren Bekämpfung - 25.11.2014 (5)
  8. DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden
    Plagegeister aller Art und deren Bekämpfung - 24.11.2014 (21)
  9. yahoo account meines Vaters versendet laut den Bekannten öfter Spam Mails
    Plagegeister aller Art und deren Bekämpfung - 18.06.2014 (5)
  10. wurde gehackt! laut rapidshare
    Log-Analyse und Auswertung - 27.08.2009 (7)
  11. Wurm- & Trojanerverseucht trotz Schutz - stimmt das???
    Log-Analyse und Auswertung - 07.11.2007 (12)
  12. Ich soll hier was löschen-stimmt das ??
    Mülltonne - 05.08.2007 (0)
  13. ich glaub es gibt vieles das hier nicht stimmt ^^
    Log-Analyse und Auswertung - 03.07.2007 (7)
  14. könnt ihr euch das ma ansehn und sagn ob hier was nich stimmt
    Log-Analyse und Auswertung - 23.04.2007 (6)
  15. das stimmt was nicht
    Log-Analyse und Auswertung - 02.03.2005 (6)
  16. stimmt! wie erstellt man ein gutes backup?
    Antiviren-, Firewall- und andere Schutzprogramme - 09.02.2005 (9)
  17. Stimmt es das man...
    Alles rund um Windows - 31.12.2004 (38)

Zum Thema Laut e-mails wurde ein RAT installiert. Stimmt das? - Servus, ich hab gestern 300 mails gekriegt: Code: Alles auswählen Aufklappen ATTFilter SYSTEM ALERT // CRITICAL PRIVACY BREACH DETECTED > INITIATING MESSAGE... Check the "From" field. This message was sent - Laut e-mails wurde ein RAT installiert. Stimmt das?...
Archiv
Du betrachtest: Laut e-mails wurde ein RAT installiert. Stimmt das? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.