![]() |
| |||||||
Log-Analyse und Auswertung: Laut e-mails wurde ein RAT installiert. Stimmt das?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder stndig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu knnen, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswrdig ist und bis zur vollstndigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Servus, ich hab gestern 300 mails gekriegt: Code:
ATTFilter SYSTEM ALERT // CRITICAL PRIVACY BREACH DETECTED
> INITIATING MESSAGE...
Check the "From" field. This message was sent from your own email account: ka.schirmer@t-online.de. I bypassed your mail server's authentication protocols, which allowed me to intercept your credentials and route this message directly to your inbox. This is your proof that I currently have access.
Your compromised password: xxxxxxxx [steht im Klartext]
Over the past few weeks, I have been silently monitoring your activity. I gained initial access through a compromised application, and shortly after, I deployed a Remote Access Trojan (RAT). Because it operates at the driver level, it is completely invisible to your antivirus software.
Through this access, I have collected your messaging history, files, and contact lists. More importantly, I have recorded explicit video footage of you via your webcam while you were visiting adult entertainment websites. I have compiled these videos alongside your contact list into a single archive.
This is not personal; it is strictly business. I have no interest in ruining your reputation, but I will release this footage to your colleagues, family, and friends if you do not comply.
Action Required
WARNING: Opening this email triggered a remote ping to my server.
The automated release script is now active.
You have exactly 8 hours from the moment you read this message to complete the payment.
Required Payment (BTC)
$500.00 USD
Bitcoin Wallet Address
bc1qkx5mfvxdf9548qqweg6wse9d3ddpv9glnts487
To ensure the permanent deletion of your data, you must make a one-time payment of $500 in Bitcoin (BTC). An automated script is tracking the blockchain for my wallet. If the payment is not received within 8 hours, the script will automatically initiate the distribution of the video file to your contacts. Once the funds are confirmed, the script aborts, and the malware self-destructs. We will never contact each other again.
> IMPORTANT RESTRICTIONS:
1. Do not reply to this email.
2. Do not contact law enforcement.
3. Do not reset your devices.
Your data is already backed up on my remote servers. Any attempt to interfere will trigger an immediate release of the files before the timer expires.
System Notice: How to complete the transaction
If you do not own Bitcoin, you can acquire it quickly within the 8-hour window:
1. Create an account on a trusted exchange (e.g., Coinbase, Binance, or Kraken).
2. Purchase $500 USD worth of Bitcoin (BTC) using your credit/debit card.
3. Withdraw the BTC to the wallet address provided above.
Alternatively, search for a local Bitcoin ATM to purchase with cash.
> END OF MESSAGE.
Ist das bekannt? Muss ich was machen? E-mail Kennwrter sind gendert. FRST-logs: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2026
durchgefhrt von ich (Administrator) auf MINIKISTE (29-07-2026 11:59:30)
Gestartet von C:\Users\ich\Desktop\FRST64.exe
Geladene Profile: ich
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\146.0.3856.84\msedgewebview2.exe
(DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atieclxx.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(explorer.exe ->) (TradingView, Inc. -> TradingView, Inc.) C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj\TradingView.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <17>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\146.0.3856.84\msedgewebview2.exe <5>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <28>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2605.9.0_x64__8wekyb3d8bbwe\CalculatorApp.exe <2>
(svchost.exe ->) (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.6465_none_7e0fb53c7c8be091\TiWorker.exe
(TradingView, Inc. -> TradingView, Inc.) C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj\TradingView.exe <11>
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurckgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [878584 2020-02-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\Installer\setup.exe [5379912 2026-07-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [MicrosoftEdgeAutoLaunch_751C59213C62DD7EB8DB14A3F1AC059D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5003304 2026-03-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [VLC Plus Player Updater] => C:\Users\ich\AppData\Local\VLC Plus Player Updater\Updater.exe [199888 2023-11-17] (Aller Media e.K. -> ) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [131508072 2026-07-23] (Microsoft Corporation -> Microsoft Corporation) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (Keine Datei) <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.045.0308.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.045.0308.0001" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.040.0301.0001_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.040.0301.0001_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.051.0316.0004] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.051.0316.0004" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.045.0308.0001_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.045.0308.0001_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.055.0323.0004] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.055.0323.0004" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.062.0402.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.062.0402.0002" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.062.0402.0002_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.062.0402.0002_1" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.070.0414.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.070.0414.0001" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\RunOnce: [Uninstall 26.078.0426.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.078.0426.0002" (Keine Datei)
IFEO\eucloneserver.exe: [GlobalFlag]
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {1C78BB52-D722-4176-9808-8042632697F8} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {148BF502-EBE0-4840-A89D-529297418C7F} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AC27279C-89A1-4D48-9A6A-ABE2307D4BE1} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {A35FC8BE-A762-4580-8F3F-169579B3EEC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {C31F4F16-1598-4CF6-AC7F-E3F71929F506} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {9161EDBC-D5DC-430D-AF8B-9B1809BE10CF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {E07A43E3-4BC0-431A-988C-4E2964CED342} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E528E4C-8E64-4DAB-8DAB-F37E97A1E71B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D62085FB-4AE8-44EA-ABEB-A7F82CAF653A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {0705BE94-4705-40F5-8202-6DFBF49E7FA7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3DD69CE5-C8B8-4C64-9988-EF794F4EBFB3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {11F50817-2A45-46DA-AA8F-7D8C9AED6AD4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5205BAD0-1544-4EAB-AFEA-DD741539AA13} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4BFDD6AC-F72E-43AC-A2F1-2F9A123102B5} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {EE9F17DF-2969-4532-8F12-AF68198FEF75} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2554665034-2769250351-2666445128-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {4D777CA7-B499-4232-85EB-BFFC65C9281B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {E99244D7-9235-4B43-9515-62E8897C0AC6} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [622040 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
Task: {09BAA0E5-10B4-4424-8E70-0544213E7D5A} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {51C54EF4-49F1-4345-85A9-C704CE822DA4} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {85CB1741-D3B6-4B7C-95A5-E44C56527E48} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {873F6BCD-35F7-4A77-9359-954B776C85B8} - System32\Tasks\VLC Plus Player Updater => C:\Users\ich\AppData\Local\VLC Plus Player Updater\Updater.exe [199888 2023-11-17] (Aller Media e.K. -> ) <==== ACHTUNG
Task: {0A7B7829-72E1-4435-A3F8-F9FBD38107C9} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001 => C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurckgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpNameServer] 192.168.111.15
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpDomain] fritz.box
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: jz7hsqat.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\fp3qcvzs.default [2020-02-24]
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release [2026-07-29]
FF Session Restore: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
FF Extension: (Lush Balanced) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\lush-balanced-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (New Tab) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\newtab@mozilla.org.xpi [2026-07-28]
FF Extension: (Visionary Bold) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\visionary-bold-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (Snowflake) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{b11bea1f-a888-4332-8d8a-cec2be7d24b9}.xpi [2026-06-16]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-29]
Edge DefaultSearchURL: Default -> hxxps://www.ecosia.org/search?q={searchTerms}&addon=opensearch
Edge DefaultSearchKeyword: Default -> ecosia.org
Edge DefaultSuggestURL: Default -> hxxps://ac.ecosia.org/autocomplete?q={searchTerms}&type=list
Edge Extension: (Google Docs Offline) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-27]
Edge Extension: (Edge relevant text changes) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-30]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [510936 0] (Advanced Micro Devices Inc. -> AMD)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9514352 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_8e2568524f674315\amdsafd.sys [100768 2021-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [62056 2020-07-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
==================== SvcHost (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-29 11:59 - 2026-07-29 12:00 - 000023625 _____ C:\Users\ich\Desktop\FRST.txt
2026-07-29 11:57 - 2026-07-29 12:00 - 000000000 ____D C:\FRST
2026-07-29 11:55 - 2026-07-29 11:55 - 002449920 _____ (Farbar) C:\Users\ich\Desktop\FRST64.exe
2026-07-26 16:53 - 2026-07-26 22:46 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-07-26 16:53 - 2026-07-26 16:53 - 004162299 _____ C:\Users\ich\Downloads\Bauplne Igelburgen Stand 23.04.2025(1).pdf
2026-07-26 16:52 - 2026-07-26 16:52 - 000393984 _____ C:\Users\ich\Downloads\Geeignetes Nassfutter fr Igel.pdf
2026-07-26 16:51 - 2026-07-26 16:51 - 000201064 _____ C:\Users\ich\Downloads\Geeignetes Trockenfutter fr Igel.pdf
2026-07-25 18:02 - 2026-07-25 18:02 - 002082252 _____ C:\Users\ich\Downloads\ein_schlafhaus_fuer_igel_selber_bauen.pdf
2026-07-24 17:30 - 2026-07-24 17:30 - 000222611 _____ C:\Users\ich\Downloads\OS_FS-40 test-1.pdf
2026-07-24 15:52 - 2026-07-24 15:52 - 002000904 _____ C:\Users\ich\Downloads\4T_Leitfaden_02a-1.pdf
2026-07-23 21:54 - 2026-07-23 21:54 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 23:33 - 2026-07-21 23:33 - 000229156 _____ C:\Users\ich\Downloads\modellbautool.zip
2026-07-21 10:53 - 2026-07-21 10:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
==================== Ein Monat (genderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-29 11:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-29 11:29 - 2020-07-14 19:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-29 10:47 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-29 10:47 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-29 10:44 - 2020-06-17 19:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-29 10:43 - 2021-12-18 15:18 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-29 00:12 - 2022-02-11 18:23 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-28 16:51 - 2024-12-19 12:01 - 000004250 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-28 11:15 - 2021-10-20 14:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-28 11:15 - 2020-02-24 18:46 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 22:46 - 2020-03-08 18:45 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-07-26 20:41 - 2020-02-24 18:17 - 000000000 ____D C:\Users\ich\AppData\Local\D3DSCache
2026-07-23 17:20 - 2025-01-29 23:08 - 000003572 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2021-12-11 13:22 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2020-07-14 19:24 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-23 17:20 - 2020-07-14 19:05 - 000002377 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-23 10:24 - 2021-02-02 13:28 - 000000000 ____D C:\Users\ich\AppData\Roaming\Microsoft\Excel
2026-07-22 10:24 - 2020-07-14 19:24 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-22 10:24 - 2020-07-14 19:24 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-21 10:53 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2026-07-21 10:52 - 2020-03-04 11:51 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-17 15:38 - 2020-02-24 15:51 - 000000000 ____D C:\Users\ich\AppData\Local\Packages
2026-07-16 20:11 - 2020-02-24 18:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-16 20:08 - 2020-02-24 18:39 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-09 21:01 - 2020-02-24 15:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2026-03-02 22:50 - 2026-03-02 22:50 - 000000028 _____ () C:\Users\ich\AppData\Roaming\epm_user.ini
2023-11-26 17:26 - 2023-11-26 17:26 - 000000036 _____ () C:\Users\ich\AppData\Local\_LOCAL_GUID
==================== SigCheck ============================
(Es ist kein automatischer Fix fr Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ========================
Code:
ATTFilter Zustzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 27-07-2026
durchgefhrt von ich (29-07-2026 12:02:26)
Gestartet von C:\Users\ich\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) (2020-07-14 17:24:24)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
Administrator (S-1-5-21-2554665034-2769250351-2666445128-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2554665034-2769250351-2666445128-503 - Limited - Disabled)
Gast (S-1-5-21-2554665034-2769250351-2666445128-501 - Limited - Disabled)
ich (DisplayName: ) (S-1-5-21-2554665034-2769250351-2666445128-1001 - Administrators - Enabled) => C:\Users\ich
WDAGUtilityAccount (S-1-5-21-2554665034-2769250351-2666445128-504 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" knnen in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
5KPlayer (HKLM-x32\...\5KPlayer) (Version: 6.3 - DearMob, Inc.)
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.116 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.11.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 5.0.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 21.6.1 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{72ADA61A-C86E-4954-8B2B-1CDDC30D2F88}) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.)
ATTO Disk Benchmark (HKLM-x32\...\{B483E952-8CDD-4EDA-9CD1-956FA1DF3846}) (Version: 4.010.4001 - ATTO Technology)
Branding64 (HKLM\...\{C871FC62-0186-40ED-BAEA-7C65BE367755}) (Version: 1.00.0006 - Advanced Micro Devices, Inc.) Hidden
DRmare Spotify Music Converter 2.9.2.470 (HKLM-x32\...\DRmare Spotify Music Converter_is1) (Version: - DRmare Studio.)
FinanzmanagerV8 (HKLM-x32\...\{78E2401D-39D5-4023-B0BF-7FA96F3FD425}_is1) (Version: 12.1.1.2 - Ackisoft)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.105 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Volume - de-de) (Version: 16.0.10417.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\OneDriveSetup.exe) (Version: 26.123.0628.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 (HKLM-x32\...\{855e31d2-9031-46e1-b06d-c9d7777deefb}) (Version: 14.28.29913.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 (HKLM-x32\...\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 (HKLM-x32\...\{6F0267F3-7467-350D-A8C8-33B72E3658D8}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 (HKLM-x32\...\{7753EC39-3039-3629-98BE-447C5D869C09}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 (HKLM\...\{620A7633-7A09-42A8-8580-076A4483C4B0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 (HKLM\...\{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 153.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.6.0 - Mozilla)
Mozilla Thunderbird ESR (x64 de) (HKLM\...\Mozilla Thunderbird 140.13.0 ESR (x64 de)) (Version: 140.13.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8710.1 - Realtek Semiconductor Corp.)
RyzenMasterSDK (HKLM\...\{22DFF94E-1F6F-463F-9F14-425610714166}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Spotify (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Spotify) (Version: 1.2.67.560.g46a15f6b - Spotify AB)
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.13.6 - TeamViewer)
Telegram Desktop (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.10 - Telegram FZ-LLC)
Trader Workstation (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\5889-6375-8446-2021) (Version: latest (10.39.1d) 20250729 16:04:39 - Interactive Brokers LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
VLC Plus Player Updater (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\AM VLC Plus Player Updater) (Version: 1.2.231101 - ) <==== ACHTUNG
Windows-PC-Integrittsprfung (HKLM\...\{63EFBDB5-01B0-4614-BE9F-7F1908E42275}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows-PC-Integrittsprfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Zoom Workplace (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)
Packages:
=========
Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-09-22] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_165.4.1108.0_x64__v10z8vjag6ke6 [2026-07-14] (HP Inc.)
Media Engine-Add-On fr Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-09-18] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
PDF X -> C:\Program Files\WindowsApps\6760NGPDFLab.PDFX_1.4.26.0_x64__sbe4t8mqwq93a [2026-04-27] (NG PDF Lab)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2020-02-24] (Realtek Semiconductor Corp)
TradingView -> C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj [2026-07-17] (TradingView, Inc.) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2607.106.0_x64__cv1g1gvanyjgm [2026-04-01] (WhatsApp Inc.) [Startup Task]
XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.9.0_x86__xpfg3f7e9an52 [2026-05-23] (New Work SE)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{2C72ECAC-94DB-4B5A-9A7B-DFBB8F91600D}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{c0ad642c-00c1-4a64-9231-64a029585d50}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> Keine Datei
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
==================== Codecs (Nicht auf der Ausnahmeliste) ====================
==================== Verknpfungen & WMI ========================
==================== Geladene Module (Nicht auf der Ausnahmeliste) =============
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 003567616 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 000912896 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 003109888 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000575488 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Device.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000048640 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Platform.dll
2020-10-13 14:34 - 2019-02-21 18:00 - 000078336 _____ (Igor Pavlov) [Datei ist nicht signiert] C:\Program Files\7-Zip\7-zip.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000039424 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000414720 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000025088 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000024576 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000023552 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000532992 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001441792 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001189888 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000134656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006184448 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006867456 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000735232 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Multimedia.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000120832 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5MultimediaQuick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001104896 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000325120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 003668480 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000517120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlModels.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000051712 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlWorkerScript.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 004228608 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000171008 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001085440 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000480256 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5RemoteObjects.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000205824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000329728 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000127488 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000390656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 095598080 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 005587968 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000462848 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000188928 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 002878464 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000055808 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000059392 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000262144 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtMultimedia\declarative_multimedia.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQml\qmlplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000284160 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000333824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000136704 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000090112 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000313856 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000091648 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================
==================== Verknpfungen (Nicht auf der Ausnahmeliste) =================
==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts Inhalt: =========================
(Wenn bentigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurckzusetzen.)
2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Aktuell gibt es keinen automatisierten Fix fr diesen Bereich.)
DNS Servers: 192.168.178.1
ist aktiviert.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Andere Bereiche ===========================
(Aktuell gibt es keinen automatisierten Fix fr diesen Bereich.)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ich\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\1823424666669546968\134296975926575021.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER Deaktivierte Eintrge ==
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{61DAA257-E0C3-4F25-910C-565F1BDD5E19}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{44552941-A547-419B-AC9A-4FAF93919AA4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E3AA84FE-6205-4252-90DD-A762CF95E430}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{18EF6F25-1412-4775-A9F9-25B9D8FC2677}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{45B79D01-1582-45CB-8EF4-B68F2698C36A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04B6C09F-8A95-4A1D-A8C0-D4FFFCD172AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3B1FA3A1-C9DF-4F04-B816-5BBC85DCE4B4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D267263A-8AAD-44BB-8631-5E3FA416F0EB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{374EA369-A884-4DCC-A03F-22F8A88C6DFA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{36C32310-F6A8-4642-A399-FCDAE182241A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E867D3D0-A4E7-454A-BBA7-317EF443BE51}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{927AB9BB-26EE-4E53-9E51-BFEDF15EF318}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{76EF7034-F429-4CB1-9B18-7FCDB7CEB806}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [{9D80857B-3AB5-437A-8D60-1FEBD0BD3E9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{74B3FD42-45BD-4A9B-AD42-ADBC6D52F56A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{79E1FF7C-5958-43B7-914D-38BB35A903D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0FC30D72-008B-465F-A3F4-003A3D09303F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{598FC530-827C-435E-A0ED-4845AD284CF1}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{822C11B3-B37F-4DD7-9828-38EB47660BF6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AA1F03BE-7545-4453-8473-F5EB37BD3031}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{87EEB120-96CB-49BC-BEB6-A4C31D654E60}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{61D1FF96-53A5-4C23-B2E6-0DC6E02AC31F}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{DE9743AE-5721-4EBB-ABE0-A85296D8D925}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{76719E5A-8201-4551-AA76-089599D2AA01}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56823129-AA6B-4BA5-8697-5F90CDCC2CC4}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{B93C0938-E753-418F-8FF9-882A4A0AE3C5}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [TCP Query User{EB4FC249-39F8-4AE0-B8D3-D2CDD8F77B6A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{C59548F9-4A18-48AA-A17F-465B4B3AFC61}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{733EC7B5-130F-4EB0-945C-27417A924A57}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{61890F17-7742-4040-961E-6F72946863CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{76EC9F12-C838-402A-85DC-130235097AB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3DD5003D-EEC0-4B76-8AD1-CFC2CD17D253}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:100.59 GB) (Free:30.69 GB) (31%)
==================== Fehlerhafte Gerte im Gertemanager ============
==================== Fehlereintrge in der Ereignisanzeige: ========================
Applikationsfehler:
==================
Error: (04/12/2026 09:32:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x14e4
Startzeit der fehlerhaften Anwendung: 0x01dcc2071af365ef
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 4e7b1853-af90-4211-8701-9198bf15de72
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/01/2026 08:41:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 01 Apr 2026 18:41:31 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d47307eb-d44b-4fc1-8e6f-7b73a64a57f3
Methode: GET(734ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/13/2026 10:58:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x1254
Startzeit der fehlerhaften Anwendung: 0x01dcae30e59bf607
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 60b38bb2-e4c1-4c39-b9e5-572064572a80
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/07/2026 02:50:35 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sat, 07 Mar 2026 12:50:36 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8adcde60-a460-4738-b6f3-760a6307c300
Methode: GET(328ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/05/2026 10:55:25 AM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Thu, 05 Mar 2026 08:55:24 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: fd264e2e-0cdf-4351-b129-4d42eb912658
Methode: GET(453ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/02/2026 10:52:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Das Programm AISprite.exe Version 0.0.0.0 hat die Interaktion mit Windows beendet und wurde geschlossen. berprfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1ca0
Startzeit: 01dcaa8645c4c42b
Beendigungszeit: 167
Anwendungspfad: C:\Program Files\EaseUS\EaseUS Partition Master\bin\AISprite.exe
Bericht-ID: 3af370b9-136f-45b2-b388-ea2c66b29163
Vollstndiger Name des fehlerhaften Pakets:
Relative Anwendungs-ID des fehlerhaften Pakets:
Absturztyp: Unknown
Error: (03/02/2026 10:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: dwm.exe, Version: 10.0.19041.4355, Zeitstempel: 0x6564cf4e
Name des fehlerhaften Moduls: dwmcore.dll, Version: 10.0.19041.6456, Zeitstempel: 0x071e2bd4
Ausnahmecode: 0xc00001ad
Fehleroffset: 0x0000000000216f2f
ID des fehlerhaften Prozesses: 0x624
Startzeit der fehlerhaften Anwendung: 0x01dc902026ae90ff
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\dwm.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\dwmcore.dll
Berichtskennung: 887e0236-f9c6-474e-94dc-24c44b43acda
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (02/27/2026 03:49:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: msedge.exe, Version: 144.0.3719.115, Zeitstempel: 0x6983cd0b
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.19041.6280, Zeitstempel: 0x56511854
Ausnahmecode: 0xe0000008
Fehleroffset: 0x0000000000025369
ID des fehlerhaften Prozesses: 0x20b8
Startzeit der fehlerhaften Anwendung: 0x01dc9aa654e409ed
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\KERNELBASE.dll
Berichtskennung: 697e523a-7bbf-42c9-89c2-94af170e001f
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (07/29/2026 10:46:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop
Error: (07/29/2026 10:46:10 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/28/2026 07:25:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/27/2026 03:52:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop
Error: (07/27/2026 03:38:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/26/2026 08:41:53 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/25/2026 06:23:01 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop
Error: (07/25/2026 06:03:54 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Windows Defender:
================
TimeCreated : 28.07.2026 22:56:36 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{F4838B2A-8F1C-4208-A563-A4F0E8D5B5B6}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 27.07.2026 22:41:05 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{97CCA619-B1D6-40F6-B049-4D8485303A5E}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 27.07.2026 15:52:56 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{0F5ECE31-8205-4EC4-BC6E-C1B3AF0E667E}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 25.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{58D50D97-2BA7-4DCA-B98E-FDA1FC876235}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 24.07.2026 22:58:44 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{F1E3ED12-ADA8-43AC-8FE6-285FF5EB5EF6}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 22.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{F005FCA6-B5F5-4BB2-9B45-F060534EFFAD}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 21.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{46A80609-5805-4BF8-9C5F-E019B177665C}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
TimeCreated : 20.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus şсãπ ĥаś вëĕñ ѕτøрφèδ вěƒοŗе ċǿmρℓėťîōи.%п %τŞсåй ) (ÌĎ:%ъ{EEC40400-621D-43AB-9DE8-60E0B84D1041}%ŋ %ţŚĉãи Тỳрε:%ъAntimalware%ņ %тŞčал ) (*άřαmёť*ŕś:%ьSchnellüberprüfung%л %ŧЦŝєґ:%вNT-AUTORITÄT\SYSTEM%ή %ŧŞţøφ Γěăѕøή:%в*сĥēδūŀ℮δ ś¢āń щäš ) (šκ*рρ℮δ ъ*čáűşэ ťћé ℓáśŧ šц¢сęśѕƒüł ѕċдή шǻş ŵìţħιй ţђē ℓǻŝŧ 7 δäÿş)
CodeIntegrity:
===============
Date: 2023-11-15 22:38:04
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-11-04 12:40:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-09-14 14:38:27
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-08-15 17:01:02
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-08-10 00:12:03
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
BIOS: American Megatrends Inc. P3.50 05/15/2019
Hauptplatine: ASRock A300M-STX
Prozessor: AMD Athlon 200GE with Radeon Vega Graphics
Prozentuale Nutzung des RAM: 66%
Installierter physikalischer RAM: 14269.9 MB
Verfgbarer physikalischer RAM: 4730.62 MB
Summe virtueller Speicher: 32701.9 MB
Verfgbarer virtueller Speicher: 14076.85 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:100.59 GB) (Free:30.69 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
Drive d: (Daten) (Fixed) (Total:263.96 GB) (Free:160.77 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
\\?\Volume{2588bb51-4ecb-4703-927e-87241e53487c}\ (Wiederherstellung) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{2e77b4c7-e5c8-462c-995d-caa9d9a39aa9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partitionstabelle ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0833C066)
Partition: GPT.
==================== Ende von Addition.txt =======================
Karsten |
| | #2 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das?![]() Mein Name ist Matthias und ich werde dir bei der Analyse und Bereinigung deines Systems helfen. Ja, das ist alles bekannt. Das ist zu 100% eine Fake-Email. Alle Informationen darin sind gelogen. ![]() Du kannst ganz locker bleiben, was das angeht. Bitte die betroffenen Mails einfach als Spam markieren und lschen (lassen). Zuknftige Mails dieser Art sollten dann automatisch abgefangen werden. Unabhngig von den Spam-Mails sehe ich etwas PUP auf deinem System. Das sollten wir entfernen. Bist du bereit dafr? |
| | #3 | |
| /// Winkelfunktion /// TB-Sch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Das ist Spam. Ignorieren und lschen. Dein weitaus greres Problem lautet Windows 10!
__________________Zitat:
Der Rechner insbesondere die CPU ist nicht gerade neuwertig...ich wrde an deiner Stelle mal einen neuen PC einplanen. Alternativen: a) Alle Daten sichern und dann mit einem neu installierten Linux weitermachen. b) Bei Windows 10 bleiben und und versuchen die ESU-Updates zu aktivieren. Geht nur mit Microsoft-Konto. Und nur bei privaten Kisten, die kein Domnenmitglied sein drfen. Variante (b) ist keine echte Lsung, da sie das Unvermeidliche nur fr ein Jahr hinauszgert.
__________________ |
| | #4 |
![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Hi Matthias, wow, schnelle Antwort und ich bin schonmal entspannt, dass ich keine Infektion hab! Ich frage mich aber schon, wo das Kennwort herkommt, das in der mail bei "xxxxxx" steht. Das war mein Kennwort fr das Telekom-Kundencenter (webmailing). Ansonsten, Code:
ATTFilter Unabhngig von den Spam-Mails sehe ich etwas PUP auf deinem System.
Das sollten wir entfernen.
Bist du bereit dafr?
Code:
ATTFilter Updatestand von November 2025. Also fast ein Jahr alt.
Der Rechner insbesondere die CPU ist nicht gerade neuwertig...ich wrde an deiner Stelle mal einen neuen PC einplanen.
|
| | #5 | |
| /// Winkelfunktion /// TB-Sch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das?Zitat:
Und die Angreifer wissen genau, dass viele Menschen faul sind und sich nicht viele Passwrter merken wollen. Die gehen davon aus, dass viele ein einziges Standardpasswort haben, dass sie berall nutzen. On Top kommen die vielen mittlerweile monatealten Sicherheitslcken in deinem Windows 10 da ja der Updatestand von November 2025 ist.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #6 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Ok, lass uns anfangen. Schritt 1 Die folgenden Programme sind veraltet, stren die Bereinigung oder es handelt sich um Werbesoftware (Adware) bzw. Potentiell Unerwnschte Programme (PUP) und mssen entfernt werden.
Schritt 2 Fhre AdwCleaner gem der bebilderten Anleitung aus und poste abschlieend die Logdatei. Schritt 3 Fhre Malwarebytes' AntiMalware (MBAM) gem der bebilderten Anleitung aus und poste abschlieend die Logdatei. |
| | #7 |
![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? 29.07.: Luft. VLC ist deinstalliert. AdwCleaner: Code:
ATTFilter # -------------------------------
# Malwarebytes AdwCleaner 8.8.1.639
# -------------------------------
# Build: 05-13-2026
# Database: 2026-04-29.3 (Local)
# Support: https://help.malwarebytes.com/
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 07-29-2026
# Duration: 00:00:17
# OS: Windows 10 (Build 19045.6466)
# Scanned: 32087
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
In MBAM finde ich nichts, um den Bericht aufzurufen. Ich kann auch keinen screenshot hier einfgen. 30.07.: Moin, nach dem automatischen scan der MBAM Testversion von eben konnte ich einen Bericht aufrufen: Code:
ATTFilter Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 30.07.2026
Scan-Zeit: 09:33
Protokolldatei: ff704362-8be8-11f1-a8b9-7085c2fb617c.json
-Softwaredaten-
Version: 5.6.3.277
Komponentenversion: 161.0.5685
Version des Aktualisierungspakets: 1.0.112698
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19045.6466)
CPU: x64
Dateisystem: NTFS
Benutzer: System
-Scan-bersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Zeitplaner
Ergebnis: Abgeschlossen
Gescannte Objekte: 187.459
Erkannte Bedrohungen: 0
In die Quarantne verschobene Bedrohungen: 0
Scandauer: 1 Min., 14 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bsartigen Elemente erkannt)
Modul: 0
(keine bsartigen Elemente erkannt)
Registrierungsschlssel: 0
(keine bsartigen Elemente erkannt)
Registrierungswert: 0
(keine bsartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bsartigen Elemente erkannt)
Daten-Stream: 0
(keine bsartigen Elemente erkannt)
Ordner: 0
(keine bsartigen Elemente erkannt)
Datei: 0
(keine bsartigen Elemente erkannt)
Physischer Sektor: 0
(keine bsartigen Elemente erkannt)
WMI: 0
(keine bsartigen Elemente erkannt)
(end)
|
| | #8 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Gut gemacht. FRST-Scan
|
| | #9 | |
![]() | Laut e-mails wurde ein RAT installiert. Stimmt das?Zitat:
Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 29-07-2026
durchgefhrt von ich (Administrator) auf MINIKISTE (30-07-2026 15:52:24)
Gestartet von C:\Users\ich\Desktop\FRST64.exe
Geladene Profile: ich
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe
(DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atieclxx.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <20>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\atiesrxx.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2605.9.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(svchost.exe ->) (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\ich\AppData\Local\Microsoft\OneDrive\26.129.0706.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurckgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [878584 2020-02-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Beschrnkung <==== ACHTUNG
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Beschrnkung <==== ACHTUNG
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [MicrosoftEdgeAutoLaunch_751C59213C62DD7EB8DB14A3F1AC059D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
IFEO\eucloneserver.exe: [GlobalFlag]
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {1C78BB52-D722-4176-9808-8042632697F8} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {148BF502-EBE0-4840-A89D-529297418C7F} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1715672 2021-06-18] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {AC27279C-89A1-4D48-9A6A-ABE2307D4BE1} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {A35FC8BE-A762-4580-8F3F-169579B3EEC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {C31F4F16-1598-4CF6-AC7F-E3F71929F506} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23571824 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {9161EDBC-D5DC-430D-AF8B-9B1809BE10CF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {E07A43E3-4BC0-431A-988C-4E2964CED342} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2209672 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {5E528E4C-8E64-4DAB-8DAB-F37E97A1E71B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D62085FB-4AE8-44EA-ABEB-A7F82CAF653A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3514712 2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {4BFDD6AC-F72E-43AC-A2F1-2F9A123102B5} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {EE9F17DF-2969-4532-8F12-AF68198FEF75} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2554665034-2769250351-2666445128-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-23] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {4D777CA7-B499-4232-85EB-BFFC65C9281B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {E99244D7-9235-4B43-9515-62E8897C0AC6} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [622040 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
Task: {09BAA0E5-10B4-4424-8E70-0544213E7D5A} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {51C54EF4-49F1-4345-85A9-C704CE822DA4} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {85CB1741-D3B6-4B7C-95A5-E44C56527E48} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {0A7B7829-72E1-4435-A3F8-F9FBD38107C9} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001 => C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurckgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpNameServer] 192.168.111.15
Tcpip\..\Interfaces\{33867303-0351-4723-912a-464f8a5c93b5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5c6c3cd9-4aaf-41cd-a8c0-ea8acbf27ab9}: [DhcpDomain] fritz.box
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: jz7hsqat.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\fp3qcvzs.default [0]
FF ProfilePath: C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release [0]
FF Session Restore: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
FF Extension: (Lush – Balanced) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\lush-balanced-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (New Tab) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\newtab@mozilla.org.xpi [2026-07-28]
FF Extension: (Visionary – Bold) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\visionary-bold-colorway@mozilla.org.xpi [2023-04-04]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2026-07-29]
FF Extension: (Snowflake) - C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\jz7hsqat.default-release\Extensions\{b11bea1f-a888-4332-8d8a-cec2be7d24b9}.xpi [2026-06-16]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default [0]
Edge DefaultSearchURL: Default -> hxxps://www.ecosia.org/search?q={searchTerms}&addon=opensearch
Edge DefaultSearchKeyword: Default -> ecosia.org
Edge DefaultSuggestURL: Default -> hxxps://ac.ecosia.org/autocomplete?q={searchTerms}&type=list
Edge Extension: (Google Docs Offline) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [0]
Edge Extension: (Edge relevant text changes) - C:\Users\ich\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [0]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [510936 2021-06-17] (Advanced Micro Devices Inc. -> AMD)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9514352 2026-07-05] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_8e2568524f674315\amdsafd.sys [100768 2021-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [62056 2020-07-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-07-29] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt.sys [215656 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-29] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-07-29] (Malwarebytes Inc -> Malwarebytes)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2026-07-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [616880 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-09] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
==================== SvcHost (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-30 15:52 - 2026-07-30 15:53 - 000020403 _____ C:\Users\ich\Desktop\FRST.txt
2026-07-30 15:50 - 2026-07-30 15:50 - 002449408 _____ (Farbar) C:\Users\ich\Desktop\FRST64.exe
2026-07-30 09:43 - 2026-07-30 09:43 - 000001412 _____ C:\Users\ich\Desktop\Malwarebytes Bedrohungsscan-Bericht 2026-07-30 093345.txt
2026-07-29 22:10 - 2026-07-29 22:10 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-07-29 22:08 - 2026-07-30 09:47 - 000000000 ____D C:\Users\ich\AppData\Local\Malwarebytes
2026-07-29 22:08 - 2026-07-29 22:08 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-29 22:08 - 2026-07-29 22:08 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-07-29 22:08 - 2026-07-29 22:08 - 000000000 ____D C:\Users\ich\AppData\Local\Sentry
2026-07-29 22:07 - 2026-07-29 22:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-29 22:07 - 2026-07-29 22:07 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-29 22:03 - 2026-07-29 22:03 - 000000000 ____D C:\AdwCleaner
2026-07-29 21:51 - 2026-07-29 21:51 - 002862824 _____ (Malwarebytes) C:\Users\ich\Desktop\MBSetup-7.7.exe
2026-07-29 21:50 - 2026-07-29 21:50 - 009630992 _____ (Malwarebytes) C:\Users\ich\Desktop\adwcleaner.exe
2026-07-29 19:32 - 2026-07-29 19:32 - 000002163 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive Photos.lnk
2026-07-29 19:22 - 2026-07-29 19:22 - 000000000 ___HD C:\$Windows.~WS
2026-07-29 11:57 - 2026-07-30 15:52 - 000000000 ____D C:\FRST
2026-07-26 16:53 - 2026-07-29 22:00 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-07-26 16:53 - 2026-07-26 16:53 - 004162299 _____ C:\Users\ich\Downloads\Bauplne Igelburgen Stand 23.04.2025(1).pdf
2026-07-26 16:52 - 2026-07-26 16:52 - 000393984 _____ C:\Users\ich\Downloads\Geeignetes Nassfutter fr Igel.pdf
2026-07-26 16:51 - 2026-07-26 16:51 - 000201064 _____ C:\Users\ich\Downloads\Geeignetes Trockenfutter fr Igel.pdf
2026-07-25 18:02 - 2026-07-25 18:02 - 002082252 _____ C:\Users\ich\Downloads\ein_schlafhaus_fuer_igel_selber_bauen.pdf
2026-07-24 17:30 - 2026-07-24 17:30 - 000222611 _____ C:\Users\ich\Downloads\OS_FS-40 test-1.pdf
2026-07-24 15:52 - 2026-07-24 15:52 - 002000904 _____ C:\Users\ich\Downloads\4T_Leitfaden_02a-1.pdf
2026-07-23 21:54 - 2026-07-30 15:26 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 23:33 - 2026-07-21 23:33 - 000229156 _____ C:\Users\ich\Downloads\modellbautool.zip
2026-07-21 10:53 - 2026-07-21 10:53 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
==================== Ein Monat (genderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-30 15:39 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-30 15:32 - 2020-07-14 19:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-30 10:05 - 2021-12-18 15:18 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-29 22:29 - 2022-02-11 18:23 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-29 22:09 - 2020-07-14 19:28 - 001632088 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-07-29 22:09 - 2019-12-07 16:51 - 000706062 _____ C:\WINDOWS\system32\perfh007.dat
2026-07-29 22:09 - 2019-12-07 16:51 - 000142356 _____ C:\WINDOWS\system32\perfc007.dat
2026-07-29 22:09 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2026-07-29 22:08 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-07-29 22:03 - 2020-02-24 18:17 - 000000000 ____D C:\Users\ich\AppData\Local\D3DSCache
2026-07-29 22:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-29 22:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-29 22:00 - 2020-07-14 19:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-07-29 22:00 - 2020-03-20 13:51 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2026-07-29 22:00 - 2020-02-24 18:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-07-29 22:00 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-07-29 19:42 - 2024-08-13 23:54 - 000000000 ____D C:\WINDOWS\Panther
2026-07-29 19:42 - 2021-01-22 13:19 - 000000000 ____D C:\ESD
2026-07-29 19:32 - 2025-01-29 23:08 - 000003572 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2021-12-11 13:22 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2020-07-14 19:24 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-29 19:32 - 2020-07-14 19:05 - 000002377 _____ C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-29 19:21 - 2020-07-14 19:05 - 000000000 ____D C:\Users\ich
2026-07-29 10:44 - 2020-06-17 19:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-28 16:51 - 2024-12-19 12:01 - 000004250 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2554665034-2769250351-2666445128-1001
2026-07-28 11:15 - 2021-10-20 14:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-28 11:15 - 2020-02-24 18:46 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 22:46 - 2020-03-08 18:45 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-07-23 10:24 - 2021-02-02 13:28 - 000000000 ____D C:\Users\ich\AppData\Roaming\Microsoft\Excel
2026-07-22 10:24 - 2020-07-14 19:24 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-22 10:24 - 2020-07-14 19:24 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-21 10:53 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2026-07-21 10:52 - 2020-03-04 11:51 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-17 15:38 - 2020-02-24 15:51 - 000000000 ____D C:\Users\ich\AppData\Local\Packages
2026-07-16 20:11 - 2020-02-24 18:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-16 20:08 - 2020-02-24 18:39 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-09 21:01 - 2020-02-24 15:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2026-03-02 22:50 - 2026-03-02 22:50 - 000000028 _____ () C:\Users\ich\AppData\Roaming\epm_user.ini
2023-11-26 17:26 - 2023-11-26 17:26 - 000000036 _____ () C:\Users\ich\AppData\Local\_LOCAL_GUID
==================== SigCheck ============================
(Es ist kein automatischer Fix fr Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ========================
Code:
ATTFilter Zustzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 29-07-2026
durchgefhrt von ich (30-07-2026 15:53:52)
Gestartet von C:\Users\ich\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) (2020-07-14 17:24:24)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
Administrator (S-1-5-21-2554665034-2769250351-2666445128-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2554665034-2769250351-2666445128-503 - Limited - Disabled)
Gast (S-1-5-21-2554665034-2769250351-2666445128-501 - Limited - Disabled)
ich (DisplayName: ) (S-1-5-21-2554665034-2769250351-2666445128-1001 - Administrators - Enabled) => C:\Users\ich
WDAGUtilityAccount (S-1-5-21-2554665034-2769250351-2666445128-504 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" knnen in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
5KPlayer (HKLM-x32\...\5KPlayer) (Version: 6.3 - DearMob, Inc.)
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.116 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.11.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 5.0.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 21.6.1 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{72ADA61A-C86E-4954-8B2B-1CDDC30D2F88}) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.01.15.2138 - Advanced Micro Devices, Inc.)
ATTO Disk Benchmark (HKLM-x32\...\{B483E952-8CDD-4EDA-9CD1-956FA1DF3846}) (Version: 4.010.4001 - ATTO Technology)
Branding64 (HKLM\...\{C871FC62-0186-40ED-BAEA-7C65BE367755}) (Version: 1.00.0006 - Advanced Micro Devices, Inc.) Hidden
DRmare Spotify Music Converter 2.9.2.470 (HKLM-x32\...\DRmare Spotify Music Converter_is1) (Version: - DRmare Studio.)
FinanzmanagerV8 (HKLM-x32\...\{78E2401D-39D5-4023-B0BF-7FA96F3FD425}_is1) (Version: 12.1.1.2 - Ackisoft)
Malwarebytes version 5.6.3.277 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.3.277 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.105 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Volume - de-de) (Version: 16.0.10417.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\OneDriveSetup.exe) (Version: 26.129.0706.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 (HKLM-x32\...\{855e31d2-9031-46e1-b06d-c9d7777deefb}) (Version: 14.28.29913.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26429 (HKLM-x32\...\{2019b6a0-8533-4a04-ac0e-b2c10bdb9841}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.14.26429 (HKLM-x32\...\{6F0267F3-7467-350D-A8C8-33B72E3658D8}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.14.26429 (HKLM-x32\...\{7753EC39-3039-3629-98BE-447C5D869C09}) (Version: 14.14.26429 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 (HKLM\...\{620A7633-7A09-42A8-8580-076A4483C4B0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 (HKLM\...\{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}) (Version: 14.28.29913 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 153.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.6.0 - Mozilla)
Mozilla Thunderbird ESR (x64 de) (HKLM\...\Mozilla Thunderbird 140.13.0 ESR (x64 de)) (Version: 140.13.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.10417.20176 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8710.1 - Realtek Semiconductor Corp.)
RyzenMasterSDK (HKLM\...\{22DFF94E-1F6F-463F-9F14-425610714166}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Spotify (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Spotify) (Version: 1.2.67.560.g46a15f6b - Spotify AB)
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.13.6 - TeamViewer)
Telegram Desktop (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.10 - Telegram FZ-LLC)
Trader Workstation (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\5889-6375-8446-2021) (Version: latest (10.39.1d) 20250729 16:04:39 - Interactive Brokers LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Windows-PC-Integrittsprfung (HKLM\...\{63EFBDB5-01B0-4614-BE9F-7F1908E42275}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows-PC-Integrittsprfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Zoom Workplace (HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)
Packages:
=========
Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-09-22] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_165.4.1108.0_x64__v10z8vjag6ke6 [2026-07-14] (HP Inc.)
Media Engine-Add-On fr Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-02-15] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation) [MS Ad]
PDF X -> C:\Program Files\WindowsApps\6760NGPDFLab.PDFX_1.4.26.0_x64__sbe4t8mqwq93a [2026-04-27] (NG PDF Lab)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2020-02-24] (Realtek Semiconductor Corp)
TradingView -> C:\Program Files\WindowsApps\TradingView.Desktop_3.3.0.7992_x64__n534cwy3pjxzj [2026-07-17] (TradingView, Inc.) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm [2026-07-24] (WhatsApp Inc.) [Startup Task]
XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.9.0_x86__xpfg3f7e9an52 [2021-06-12] (New Work SE)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{2C72ECAC-94DB-4B5A-9A7B-DFBB8F91600D}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{c0ad642c-00c1-4a64-9231-64a029585d50}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-29] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> Keine Datei
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-29] (Malwarebytes Inc -> Malwarebytes)
==================== Codecs (Nicht auf der Ausnahmeliste) ====================
==================== Verknpfungen & WMI ========================
==================== Geladene Module (Nicht auf der Ausnahmeliste) =============
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 003567616 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2021-03-12 06:18 - 2021-03-12 06:18 - 000756736 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AODDevice.dll
2021-03-12 06:18 - 2021-03-12 06:18 - 023854080 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\AODPlatform.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 000912896 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2020-03-19 06:40 - 2020-03-19 06:40 - 003109888 _____ () [Datei ist nicht signiert] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000575488 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Device.dll
2021-04-15 07:01 - 2021-04-15 07:01 - 000048640 _____ (Advanced Micro Devices) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Platform.dll
2020-10-13 14:34 - 2019-02-21 18:00 - 000078336 _____ (Igor Pavlov) [Datei ist nicht signiert] C:\Program Files\7-Zip\7-zip.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000039424 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000031744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000414720 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000025088 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000024576 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000023552 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000532992 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001441792 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 001189888 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000134656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006184448 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 006867456 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000735232 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Multimedia.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000120832 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5MultimediaQuick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001104896 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000325120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 003668480 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000517120 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlModels.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000051712 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QmlWorkerScript.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 004228608 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000171008 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 001085440 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000480256 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5RemoteObjects.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000205824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000329728 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000127488 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2021-01-06 12:25 - 2021-01-06 12:25 - 000390656 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 095598080 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 005587968 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000462848 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000188928 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 002878464 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000055808 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000059392 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000262144 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtMultimedia\declarative_multimedia.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQml\qmlplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000284160 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000333824 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000136704 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000090112 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000313856 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000017920 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2021-01-06 12:26 - 2021-01-06 12:26 - 000091648 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\Users\ich\Desktop\FRST64.exe:MBAM.Zone.Identifier [225]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknpfungen (Nicht auf der Ausnahmeliste) =================
==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-21] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts Inhalt: =========================
(Wenn bentigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurckzusetzen.)
2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Aktuell gibt es keinen automatisierten Fix fr diesen Bereich.)
DNS Servers: 192.168.178.1
ist aktiviert.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Andere Bereiche ===========================
(Aktuell gibt es keinen automatisierten Fix fr diesen Bereich.)
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ich\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\1823424666669546968\134298008784579201.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER Deaktivierte Eintrge ==
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{61DAA257-E0C3-4F25-910C-565F1BDD5E19}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{44552941-A547-419B-AC9A-4FAF93919AA4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E3AA84FE-6205-4252-90DD-A762CF95E430}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{18EF6F25-1412-4775-A9F9-25B9D8FC2677}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{45B79D01-1582-45CB-8EF4-B68F2698C36A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04B6C09F-8A95-4A1D-A8C0-D4FFFCD172AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3B1FA3A1-C9DF-4F04-B816-5BBC85DCE4B4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D267263A-8AAD-44BB-8631-5E3FA416F0EB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{374EA369-A884-4DCC-A03F-22F8A88C6DFA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{36C32310-F6A8-4642-A399-FCDAE182241A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E867D3D0-A4E7-454A-BBA7-317EF443BE51}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{927AB9BB-26EE-4E53-9E51-BFEDF15EF318}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{76EF7034-F429-4CB1-9B18-7FCDB7CEB806}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [{9D80857B-3AB5-437A-8D60-1FEBD0BD3E9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{74B3FD42-45BD-4A9B-AD42-ADBC6D52F56A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{79E1FF7C-5958-43B7-914D-38BB35A903D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0FC30D72-008B-465F-A3F4-003A3D09303F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{598FC530-827C-435E-A0ED-4845AD284CF1}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{822C11B3-B37F-4DD7-9828-38EB47660BF6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AA1F03BE-7545-4453-8473-F5EB37BD3031}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
FirewallRules: [{87EEB120-96CB-49BC-BEB6-A4C31D654E60}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{61D1FF96-53A5-4C23-B2E6-0DC6E02AC31F}] => (Allow) C:\Users\ich\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{DE9743AE-5721-4EBB-ABE0-A85296D8D925}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{76719E5A-8201-4551-AA76-089599D2AA01}C:\users\ich\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ich\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56823129-AA6B-4BA5-8697-5F90CDCC2CC4}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [UDP Query User{B93C0938-E753-418F-8FF9-882A4A0AE3C5}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob)
FirewallRules: [TCP Query User{EB4FC249-39F8-4AE0-B8D3-D2CDD8F77B6A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{C59548F9-4A18-48AA-A17F-465B4B3AFC61}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{733EC7B5-130F-4EB0-945C-27417A924A57}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{61890F17-7742-4040-961E-6F72946863CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{76EC9F12-C838-402A-85DC-130235097AB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3DD5003D-EEC0-4B76-8AD1-CFC2CD17D253}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.54031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:100.59 GB) (Free:31.73 GB) (32%)
==================== Fehlerhafte Gerte im Gertemanager ============
==================== Fehlereintrge in der Ereignisanzeige: ========================
Applikationsfehler:
==================
Error: (07/29/2026 10:00:44 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 29 Jul 2026 20:00:45 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8b42e0f9-c0c4-4e33-840e-6b17d2c7b24f
Methode: GET(422ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (04/12/2026 09:32:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x14e4
Startzeit der fehlerhaften Anwendung: 0x01dcc2071af365ef
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 4e7b1853-af90-4211-8701-9198bf15de72
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/01/2026 08:41:28 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 01 Apr 2026 18:41:31 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d47307eb-d44b-4fc1-8e6f-7b73a64a57f3
Methode: GET(734ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/13/2026 10:58:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUEPMaster.exe, Version: 2120.1.14.617, Zeitstempel: 0x60cbdd34
Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.19041.3636, Zeitstempel: 0x81cf5d89
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000000000007286e
ID des fehlerhaften Prozesses: 0x1254
Startzeit der fehlerhaften Anwendung: 0x01dcae30e59bf607
Pfad der fehlerhaften Anwendung: C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\ucrtbase.dll
Berichtskennung: 60b38bb2-e4c1-4c39-b9e5-572064572a80
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (03/07/2026 02:50:35 PM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sat, 07 Mar 2026 12:50:36 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 8adcde60-a460-4738-b6f3-760a6307c300
Methode: GET(328ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/05/2026 10:55:25 AM) (Source: CertEnroll) (EventID: 86) (User: NT-AUTORITT)
Description: Fehler bei der Initialisierung der SCEP-Zertifikatregistrierung fr WORKGROUP\MINIKISTE$ ber https://AMD-KeyId-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net/templates/Aik/scep:
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-8a0578cf56146fea399af903fb5b0ac36eb2786a.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Thu, 05 Mar 2026 08:55:24 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: fd264e2e-0cdf-4351-b129-4d42eb912658
Methode: GET(453ms)
Phase: GetCACaps
Nicht gefunden (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
Error: (03/02/2026 10:52:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Das Programm AISprite.exe Version 0.0.0.0 hat die Interaktion mit Windows beendet und wurde geschlossen. berprfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1ca0
Startzeit: 01dcaa8645c4c42b
Beendigungszeit: 167
Anwendungspfad: C:\Program Files\EaseUS\EaseUS Partition Master\bin\AISprite.exe
Bericht-ID: 3af370b9-136f-45b2-b388-ea2c66b29163
Vollstndiger Name des fehlerhaften Pakets:
Relative Anwendungs-ID des fehlerhaften Pakets:
Absturztyp: Unknown
Error: (03/02/2026 10:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: dwm.exe, Version: 10.0.19041.4355, Zeitstempel: 0x6564cf4e
Name des fehlerhaften Moduls: dwmcore.dll, Version: 10.0.19041.6456, Zeitstempel: 0x071e2bd4
Ausnahmecode: 0xc00001ad
Fehleroffset: 0x0000000000216f2f
ID des fehlerhaften Prozesses: 0x624
Startzeit der fehlerhaften Anwendung: 0x01dc902026ae90ff
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\dwm.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\dwmcore.dll
Berichtskennung: 887e0236-f9c6-474e-94dc-24c44b43acda
Vollstndiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (07/30/2026 09:25:44 AM) (Source: DCOM) (EventID: 10001) (User: MINIKISTE)
Description: Ein DCOM-Server konnte nicht gestartet werden: {F4DF18B4-A2CF-4B0A-8D62-954CD6AD2E33} als Nicht verfgbar/Nicht verfgbar. Fehler:
"2147942593"
Aufgetreten beim Start dieses Befehls:
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_22606.1401.10.0_x64__8wekyb3d8bbwe\StoreDesktopExtension.exe" -Embedding
Error: (07/29/2026 10:05:26 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT-AUTORITT)
Description: Die Zertifizierungsstelle/Schlssel fr den sicheren Start mssen aktualisiert werden. Diese Gertesignaturinformationen sind hier enthalten.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:P3.50;OEMModelNumber:To Be Filled By O.E.M.;OEMModelBaseBoard:A300M-STX;OEMModelSystemFamily:To Be Filled By O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By O.E.M.;OSArchitecture:amd64;
BucketId: af6804523f69fa8ba945f8732703d84288a7fece0e3e2b352e10b0e5b86891c3
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Error: (07/29/2026 10:00:25 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 29.07.2026 um 21:54:19 unerwartet heruntergefahren.
Error: (07/29/2026 10:46:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop
Error: (07/29/2026 10:46:10 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/28/2026 07:25:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Error: (07/27/2026 03:52:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop
Error: (07/27/2026 03:38:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80073d02 fehlgeschlagen: 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller
Windows Defender:
================
TimeCreated : 28.07.2026 22:56:36 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{F4838B2A-8F1C-4208-A563-A4F0E8D5B5B6}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 27.07.2026 22:41:05 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{97CCA619-B1D6-40F6-B049-4D8485303A5E}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 27.07.2026 15:52:56 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{0F5ECE31-8205-4EC4-BC6E-C1B3AF0E667E}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 25.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{58D50D97-2BA7-4DCA-B98E-FDA1FC876235}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 24.07.2026 22:58:44 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{F1E3ED12-ADA8-43AC-8FE6-285FF5EB5EF6}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 22.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{F005FCA6-B5F5-4BB2-9B45-F060534EFFAD}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 21.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{46A80609-5805-4BF8-9C5F-E019B177665C}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
TimeCreated : 20.07.2026 22:41:10 Uhr
(Message : Microsoft Defender Antivirus Ÿс〠ĥа› вë•ñ •„ø€†èδ в›’ο—е ‹ǿmρ„“—ťîōи.%п %„žсåй ) (ŒŽ:%Š{EEC40400-621D-43AB-9DE8-60E0B84D1041}%‹ %ţš‰ãи Тỳ€ε:%ŠAntimalware%† %‚žčал ) (*ά™αm‘ť*•›:%ŒSchnellüberprüfung%л %ŧЦŝ”‘:%вNT-AUTORIT„T\SYSTEM%ή %ŧžţø† “›ƒ•øή:%в*сĥ“δū€„δ ›¢ā„ ‰äš ) (šκ*€ρ„δ Š*čáűŸэ ť›é „“á›ŧ š†¢с™›•’ü‚ •‹дή ˆǻŸ ŵìţħιй ţ’“ „“ǻŝŧ 7 δäÿŸ)
CodeIntegrity:
===============
Date: 2026-07-29 22:12:59
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
Date: 2023-11-15 22:38:04
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-11-04 12:40:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
BIOS: American Megatrends Inc. P3.50 05/15/2019
Hauptplatine: ASRock A300M-STX
Prozessor: AMD Athlon 200GE with Radeon Vega Graphics
Prozentuale Nutzung des RAM: 57%
Installierter physikalischer RAM: 14269.9 MB
Verfgbarer physikalischer RAM: 5996.85 MB
Summe virtueller Speicher: 30653.9 MB
Verfgbarer virtueller Speicher: 18109.14 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:100.59 GB) (Free:31.73 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
Drive d: (Daten) (Fixed) (Total:263.96 GB) (Free:158.08 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS
\\?\Volume{2588bb51-4ecb-4703-927e-87241e53487c}\ (Wiederherstellung) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{2e77b4c7-e5c8-462c-995d-caa9d9a39aa9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partitionstabelle ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0833C066)
Partition: GPT.
==================== Ende von Addition.txt =======================
|
| | #10 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Wir entfernen ein paar verwaiste Eintrge und kontrollieren die Systemdateien auf Fehler. Wir fhren eine Reparatur mit FRST durch. Dabei werden schdliche und verwaiste Eintrge entfernt sowie temporren Dateien und der Papierkorb geleert. Auerdem werden die Systemdateien auf Fehler berprft. Bitte gedulde dich, sobald du die Reparatur gestartet hast. Je nach Art und Umfang der notwendigen Reparaturen kann dies einige Minuten dauern. Eventuell erhltst du whrend der Reparatur auch die Information "keine Rckmeldung" von FRST. Das ist normal, du musst nichts weiter tun, nur abwarten. Reparatur mit FRST HINWEIS AN ALLE MITLESER: Dieses FRST-Skript ist ausschlielich fr diesen Nutzer gedacht und sollte niemals 1:1 fr ein anderes System verwendet werden!
|
| | #11 |
![]() | Laut e-mails wurde ein RAT installiert. Stimmt das?Code:
ATTFilter Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 29-07-2026
durchgefhrt von ich (30-07-2026 17:03:00) Run:1
Gestartet von C:\Users\ich\Desktop
Geladene Profile: ich
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Keine Datei)
IFEO\eucloneserver.exe: [GlobalFlag]
FF Notifications: Mozilla\Firefox\Profiles\jz7hsqat.default-release -> hxxps://www.quoka.de; hxxps://www.clientam.com; hxxps://de.tradingview.com; hxxps://www.facebook.com
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
CustomCLSID: HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
AlternateDataStreams: C:\Users\ich\Desktop\FRST64.exe:MBAM.Zone.Identifier [225]
CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv
CMD: netsh winsock reset
CMD: netsh int ip reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winhttp reset proxy
RemoveProxy:
CMD: Winmgmt /salvagerepository
CMD: Winmgmt /verifyrepository
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: Winmgmt /resyncperf
CMD: reg query "HKLM\System\CurrentControlSet\Control\Session Manager\Environment" /S
CMD: reg query "HKCU\Environment" /S
CMD: sfc /scannow
Hosts:
EmptyEventLogs:
EmptyTemp:
End::
*****************
Wiederherstellungspunkt wurde erfolgreich erstellt.
Prozesse erfolgreich geschlossen.
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Acrobat Synchronizer" => erfolgreich entfernt
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\eucloneserver.exe => erfolgreich entfernt
"FF Notifications:" => erfolgreich entfernt
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000} => erfolgreich entfernt
HKU\S-1-5-21-2554665034-2769250351-2666445128-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000} => erfolgreich entfernt
C:\Users\ich\Desktop\FRST64.exe => ":MBAM.Zone.Identifier" ADS erfolgreich entfernt
========= cscript /nologo %systemroot%\System32\slmgr.vbs /dlv =========
Softwarelizenzierungsdienst-Version: 10.0.19041.6456
Name: Windows(R), Professional edition
Beschreibung: Windows(R) Operating System, RETAIL channel
Aktivierungs-ID: 4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Anwendungs-ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Erweiterte PID: 03612-03308-000-000000-00-1031-19041.0000-1962020
Product Key-Kanal: Retail
Installations-ID: 040596417152700085086813238177281342063154884582129214249674564
Lizenz-URL verwenden: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
URL fr die šberprfung: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx
Teil-Product Key: 3V66T
Lizenzstatus: Lizenziert
Verbleibende Windows Rearm-Anzahl: 1001
Verbleibende SKU Rearm-Anzahl: 1001
Vertrauenswrdige Zeit: 30.07.2026 17:03:20
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieen.
========= Ende von CMD: =========
========= netsh int ip reset =========
Depotweiterleitung wird zurckgesetzt... OK
Depot wird zurckgesetzt... OK
Steuerungsprotokoll wird zurckgesetzt... OK
Echosequenzanforderung wird zurckgesetzt... OK
Global wird zurckgesetzt... OK
Schnittstelle wird zurckgesetzt... OK
Anycastadresse wird zurckgesetzt... OK
Multicastadresse wird zurckgesetzt... OK
Unicastadresse wird zurckgesetzt... OK
Nachbar wird zurckgesetzt... OK
Pfad wird zurckgesetzt... OK
Potentiell wird zurckgesetzt... OK
Pr„fixrichtlinie wird zurckgesetzt... OK
Proxynachbar wird zurckgesetzt... OK
Route wird zurckgesetzt... OK
Standordpr„fix wird zurckgesetzt... OK
Unterschnittstelle wird zurckgesetzt... OK
Reaktivierungsmuster wird zurckgesetzt... OK
Nachbar aufl”sen wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... Fehler
Zugriff verweigert
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
wird zurckgesetzt... OK
Starten Sie den Computer neu, um die Aktion abzuschlieen.
========= Ende von CMD: =========
========= netsh advfirewall reset =========
OK.
========= Ende von CMD: =========
========= netsh advfirewall set allprofiles state ON =========
OK.
========= Ende von CMD: =========
========= netsh winhttp reset proxy =========
Aktuelle WinHTTP-Proxyeinstellungen:
DirectAccess (kein Proxyserver).
========= Ende von CMD: =========
========= RemoveProxy: =========
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt
"HKU\S-1-5-21-2554665034-2769250351-2666445128-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= Winmgmt /salvagerepository =========
Das WMI-Repository ist konsistent.
========= Ende von CMD: =========
========= Winmgmt /verifyrepository =========
Das WMI-Repository ist konsistent.
========= Ende von CMD: =========
========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.
========= Ende von CMD: =========
========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.
========= Ende von CMD: =========
========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.
========= Ende von CMD: =========
========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.
========= Ende von CMD: =========
========= Winmgmt /resyncperf =========
0
========= Ende von CMD: =========
========= reg query "HKLM\System\CurrentControlSet\Control\Session Manager\Environment" /S =========
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
DriverData REG_SZ C:\Windows\System32\Drivers\DriverData
OS REG_SZ Windows_NT
Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE REG_SZ AMD64
PSModulePath REG_EXPAND_SZ %ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules
TEMP REG_EXPAND_SZ %SystemRoot%\TEMP
TMP REG_EXPAND_SZ %SystemRoot%\TEMP
USERNAME REG_SZ SYSTEM
windir REG_EXPAND_SZ %SystemRoot%
NUMBER_OF_PROCESSORS REG_SZ 4
PROCESSOR_LEVEL REG_SZ 23
PROCESSOR_IDENTIFIER REG_SZ AMD64 Family 23 Model 17 Stepping 0, AuthenticAMD
PROCESSOR_REVISION REG_SZ 1100
========= Ende von CMD: =========
========= reg query "HKCU\Environment" /S =========
HKEY_CURRENT_USER\Environment
Path REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;
TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
OneDrive REG_EXPAND_SZ C:\Users\ich\OneDrive
========= Ende von CMD: =========
========= sfc /scannow =========
Systemsuche wird gestartet. Dieser Vorgang kann einige Zeit dauern.
berprfungsphase der Systemsuche wird gestartet.
berprfung 0 % abgeschlossen.
berprfung 1 % abgeschlossen.
berprfung 1 % abgeschlossen.
berprfung 2 % abgeschlossen.
berprfung 3 % abgeschlossen.
berprfung 3 % abgeschlossen.
berprfung 4 % abgeschlossen.
berprfung 4 % abgeschlossen.
berprfung 5 % abgeschlossen.
berprfung 6 % abgeschlossen.
berprfung 6 % abgeschlossen.
berprfung 7 % abgeschlossen.
berprfung 7 % abgeschlossen.
berprfung 8 % abgeschlossen.
berprfung 9 % abgeschlossen.
berprfung 9 % abgeschlossen.
berprfung 10 % abgeschlossen.
berprfung 11 % abgeschlossen.
berprfung 11 % abgeschlossen.
berprfung 12 % abgeschlossen.
berprfung 12 % abgeschlossen.
berprfung 13 % abgeschlossen.
berprfung 14 % abgeschlossen.
berprfung 14 % abgeschlossen.
berprfung 15 % abgeschlossen.
berprfung 15 % abgeschlossen.
berprfung 16 % abgeschlossen.
berprfung 17 % abgeschlossen.
berprfung 17 % abgeschlossen.
berprfung 18 % abgeschlossen.
berprfung 18 % abgeschlossen.
berprfung 19 % abgeschlossen.
berprfung 20 % abgeschlossen.
berprfung 20 % abgeschlossen.
berprfung 21 % abgeschlossen.
berprfung 22 % abgeschlossen.
berprfung 22 % abgeschlossen.
berprfung 23 % abgeschlossen.
berprfung 23 % abgeschlossen.
berprfung 24 % abgeschlossen.
berprfung 25 % abgeschlossen.
berprfung 25 % abgeschlossen.
berprfung 26 % abgeschlossen.
berprfung 26 % abgeschlossen.
berprfung 27 % abgeschlossen.
berprfung 28 % abgeschlossen.
berprfung 28 % abgeschlossen.
berprfung 29 % abgeschlossen.
berprfung 30 % abgeschlossen.
berprfung 30 % abgeschlossen.
berprfung 31 % abgeschlossen.
berprfung 31 % abgeschlossen.
berprfung 32 % abgeschlossen.
berprfung 33 % abgeschlossen.
berprfung 33 % abgeschlossen.
berprfung 34 % abgeschlossen.
berprfung 34 % abgeschlossen.
berprfung 35 % abgeschlossen.
berprfung 36 % abgeschlossen.
berprfung 36 % abgeschlossen.
berprfung 37 % abgeschlossen.
berprfung 37 % abgeschlossen.
berprfung 38 % abgeschlossen.
berprfung 39 % abgeschlossen.
berprfung 39 % abgeschlossen.
berprfung 40 % abgeschlossen.
berprfung 41 % abgeschlossen.
berprfung 41 % abgeschlossen.
berprfung 42 % abgeschlossen.
berprfung 42 % abgeschlossen.
berprfung 43 % abgeschlossen.
berprfung 44 % abgeschlossen.
berprfung 44 % abgeschlossen.
berprfung 45 % abgeschlossen.
berprfung 45 % abgeschlossen.
berprfung 46 % abgeschlossen.
berprfung 47 % abgeschlossen.
berprfung 47 % abgeschlossen.
berprfung 48 % abgeschlossen.
berprfung 48 % abgeschlossen.
berprfung 49 % abgeschlossen.
berprfung 50 % abgeschlossen.
berprfung 50 % abgeschlossen.
berprfung 51 % abgeschlossen.
berprfung 52 % abgeschlossen.
berprfung 52 % abgeschlossen.
berprfung 53 % abgeschlossen.
berprfung 53 % abgeschlossen.
berprfung 54 % abgeschlossen.
berprfung 55 % abgeschlossen.
berprfung 55 % abgeschlossen.
berprfung 56 % abgeschlossen.
berprfung 56 % abgeschlossen.
berprfung 57 % abgeschlossen.
berprfung 58 % abgeschlossen.
berprfung 58 % abgeschlossen.
berprfung 59 % abgeschlossen.
berprfung 60 % abgeschlossen.
berprfung 60 % abgeschlossen.
berprfung 61 % abgeschlossen.
berprfung 61 % abgeschlossen.
berprfung 62 % abgeschlossen.
berprfung 63 % abgeschlossen.
berprfung 63 % abgeschlossen.
berprfung 64 % abgeschlossen.
berprfung 64 % abgeschlossen.
berprfung 65 % abgeschlossen.
berprfung 66 % abgeschlossen.
berprfung 66 % abgeschlossen.
berprfung 67 % abgeschlossen.
berprfung 67 % abgeschlossen.
berprfung 68 % abgeschlossen.
berprfung 69 % abgeschlossen.
berprfung 69 % abgeschlossen.
berprfung 70 % abgeschlossen.
berprfung 71 % abgeschlossen.
berprfung 71 % abgeschlossen.
berprfung 72 % abgeschlossen.
berprfung 72 % abgeschlossen.
berprfung 73 % abgeschlossen.
berprfung 74 % abgeschlossen.
berprfung 74 % abgeschlossen.
berprfung 75 % abgeschlossen.
berprfung 75 % abgeschlossen.
berprfung 76 % abgeschlossen.
berprfung 77 % abgeschlossen.
berprfung 77 % abgeschlossen.
berprfung 78 % abgeschlossen.
berprfung 79 % abgeschlossen.
berprfung 79 % abgeschlossen.
berprfung 80 % abgeschlossen.
berprfung 80 % abgeschlossen.
berprfung 81 % abgeschlossen.
berprfung 82 % abgeschlossen.
berprfung 82 % abgeschlossen.
berprfung 83 % abgeschlossen.
berprfung 83 % abgeschlossen.
berprfung 84 % abgeschlossen.
berprfung 85 % abgeschlossen.
berprfung 85 % abgeschlossen.
berprfung 86 % abgeschlossen.
berprfung 86 % abgeschlossen.
berprfung 87 % abgeschlossen.
berprfung 88 % abgeschlossen.
berprfung 88 % abgeschlossen.
berprfung 89 % abgeschlossen.
berprfung 90 % abgeschlossen.
berprfung 90 % abgeschlossen.
berprfung 91 % abgeschlossen.
berprfung 91 % abgeschlossen.
berprfung 92 % abgeschlossen.
berprfung 93 % abgeschlossen.
berprfung 93 % abgeschlossen.
berprfung 94 % abgeschlossen.
berprfung 94 % abgeschlossen.
berprfung 95 % abgeschlossen.
berprfung 96 % abgeschlossen.
berprfung 96 % abgeschlossen.
berprfung 97 % abgeschlossen.
berprfung 97 % abgeschlossen.
berprfung 98 % abgeschlossen.
berprfung 99 % abgeschlossen.
berprfung 99 % abgeschlossen.
berprfung 100 % abgeschlossen.
Der Windows-Ressourcenschutz hat beschdigte Dateien gefunden und erfolgreich repariert.
Bei Onlinereparaturen finden Sie Details in der CBS-Protokolldatei unter
windir\Logs\CBS\CBS.log. Beispiel C:\Windows\Logs\CBS\CBS.log. Bei Offlinereparaturen
finden Sie Details in der durch das /OFFLOGFILE-Kennzeichen angegebenen Protokolldatei.
========= Ende von CMD: =========
C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.
=========== EmptyEventLogs: ==========
1181 Event logs cleared.
================================
=========== EmptyTemp: ==========
FlushDNS => abgeschlossen
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 217677519 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 12103675 B
Edge => 885744113 B
Firefox => 2236687804 B
Opera => 0 B
Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
Default => 3 B
ProgramData => 0 B
Public => 0 B
systemprofile => 452317 B
systemprofile32 => 0 B
LocalService => 4301 B
NetworkService => 1726675 B
ich => 344113511 B
RecycleBin => 0 B
EmptyTemp: => 3.4 GB temporre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 17:12:20 ====
Fr die Mitleser: Microsoft bietet fr diese Hardware kein W11 an. Man kann aber registry-Eintrge machen, so dass es geht. Das Verfahren ist von MS dokumentiert. Die Anleitung hab ich aus der c't 5/2025. |
| | #12 |
| /// Winkelfunktion /// TB-Sch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Laut e-mails wurde ein RAT installiert. Stimmt das? Wir kennen das. Da raten wir aber von ab, weil Microsoft derart alte Hardware nicht mehr testet - und man somit mit noch mehr Fehlern unter Windows 11 rechnen muss als es ohnehin schon gibt. Ob du mit der langsamen CPU unter Windows 11 zufrieden sein wirst, wird sich auch noch zeigen. Und du wirst jedes Jahr manuellen Aufwand haben, weil sich solche Installation nicht auf das aktuelle Release hochziehen wie zB 26H2, das in ein paar Monaten erscheinen wird.
__________________ Logfiles bitte immer in CODE-Tags posten |
![]() |
| Themen zu Laut e-mails wurde ein RAT installiert. Stimmt das? |
| antivirus, converter, defender, desktop, email, firefox, google, internet, internet explorer, malware, mozilla, performance, prozesse, realtek, registry, rundll, scan, server, services.exe, svchost.exe, system, trojan, udp, updates, windows |