![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Langsamer WIN-StartWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| | #1 |
| | Langsamer WIN-Start OS: WIN 11 Pro x64 Version: 10.0.26200 Build 26200 BIOS: UEFI Gebietsschema: Vereinigte Staaten Zeitzone: Mitteleuropäische Sommerzeit Es dauert gut 3 Min., bevor der eigentl. Startvorgang von Windows beginnt (rotierender Kreis), welcher dann nach rd. 45 Sec. abgeschlossen ist. Defender, Malwarebytes, Eset-Onlinescanner, SFC und DISM ohne Befund. Die log-Datei (FRST_04-08-2026 17.37.28.txt) kann ich nicht senden. Alle Einträge lauten: PHP User Warning: is_dir(): open_basedir restriction in effect. File(/) is not within the allowed path(s): (/var/www/vhosts/trojaner-board.de/:/tmp/) in ..../includes/functions_file.php on line 60 Letzter Eintrag: Fatal error: Allowed memory size of 268435456 bytes exhausted (tried to allocate 130968 bytes) in /var/www/vhosts/trojaner-board.de/httpdocs/includes/class_core.php on line 60 |
| | #2 | |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-StartZitat:
Posten in CODE-TagsDie Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
| | #3 |
| | Langsamer WIN-Start Hoffe es dieses Mal richtig gemacht zu haben:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-08-2026 01
Ran by goofy (administrator) on DESKTOP-P4QE8KD (AZW SEi) (04-08-2026 17:35:38)
Running from C:\Users\goofy\Downloads\Neuer Ordner\FRST64 (08).exe
Loaded Profiles: goofy
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8973 (X64) Language: Deutsch (Deutschland)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(explorer.exe ->) () [File not signed] C:\Program Files\Rainlendar2\Rainlendar2.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2605.29.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(explorer.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(IObit Co., Ltd. -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe <5>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <17>
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_733999112d65c1dd\Intel_PIE_Service.exe
(services.exe ->) (Lespeed Technology Co., Ltd -> WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
(services.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.151.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Tweaking LLC -> Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
Failed to access process -> vmmemCmZygote
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
HKLM\...\Policies\Explorer: [NoThumbnailCache] 0
HKLM\...\Policies\Explorer: [DisableThumbnailCache] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [AllowDomainPINLogon] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26530552 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe [4232192 2025-11-21] () [File not signed]
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [DisableThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\MountPoints2: {c5285fd3-bc9f-11ec-ba8c-3887d5b84f9c} - "F:\setup.exe"
HKU\S-1-5-21-2474616372-3844271695-3557059434-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
IFEO\CompatTelRunner.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\DeviceCensus.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\eucloneserver.exe: [GlobalFlag]
BootExecute: autocheck autochk *
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {65871B34-40DD-4B84-9B4C-36481909297B} - System32\Tasks\CleanGenius => C:\Program Files\EaseUS\EaseUS Partition Master\ECG\CleanGeniusEPM.exe [726488 2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> )
Task: {17D68746-2E31-40BA-BEEB-1EFBE5B8C992} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\Scheduler.exe [164056 2026-04-16] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {C412CCD5-D50A-4DC8-A1DE-601B5A3DBB20} - System32\Tasks\Driver Booster SkipUAC (goofy) => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\DriverBooster.exe [8639696 2026-06-12] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {8CD636FC-F684-4131-BACD-903CA4D03C5B} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\AutoUpdate.exe [2537680 2026-06-12] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {B2E7DFB7-644F-4ED2-B89D-54B903BED13E} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {6449ACB8-AB62-489A-B6E5-1B87E8967CDF} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {A740AD63-A7E9-4A87-AED2-F32F9FDB518B} - System32\Tasks\IObit SUM2026Sale (One-time) => C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\sum26.exe [2888912 2026-07-26] (IObit CO., LTD -> IObit) -> C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\\/rpop <==== ATTENTION
Task: {D39270E8-21C6-4912-9B28-25CC92DED2EC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\CodecTweakTool.exe [2401792 2026-07-20] () [File not signed]
Task: {FE7BAC05-0FC3-4442-8EC1-BE1FD4B65043} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1DAD7236-7EB3-470C-A338-44579225A44A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {A07F1BC3-4949-4722-9792-F7A0A8F10184} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {158D0912-1DAB-4FA8-86E2-BEC17B49639C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {4FD9E461-DE91-4FD9-A266-006255F58111} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [188184 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {6B60C455-FDB2-4660-B9F2-FCFA0892EFB1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2474616372-3844271695-3557059434-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-29] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {9709E63F-D713-40D9-B8D1-1A6EF83B3042} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-29] (Mozilla Corporation -> Mozilla Foundation)
Task: {051BE515-FB31-4F7E-80C0-9BC944141BD2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {7173B6DA-C062-4B89-BA20-58E8CA884001} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File)
Task: {DB8AD0FE-07AF-4BFB-98DF-03934344A48F} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [220816 2019-09-30] (Tweaking LLC -> Tweaking.com)
Task: {EE6F8AFE-BA02-4989-B07C-047CD805BEB1} - System32\Tasks\Uninstaller_SkipUac_goofy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [10041280 2026-07-07] (IObit Co., Ltd. -> IObit) -> C:\Program Files (x86)\IObit\IObit Uninstaller\\/UninstallExplorer <==== ATTENTION
Task: {3EBEEA44-E7AD-47D6-934F-6CC33D439D0B} - System32\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [11172760 2026-01-22] (Lespeed Technology Co., Ltd -> WiseCleaner.com) -> C:\Program Files (x86)\Wise\Wise Care 365\-StartTray
Task: {DAAC4EBA-C7EE-48C6-AEE5-040FA89A7BA4} - System32\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [12417432 2026-01-05] (Lespeed Technology Co., Ltd -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9 18 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog5-x64 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5-x64 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9-x64 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9-x64 18 %windir%\system32\vsocklib.dll => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpDomain] fritz.box
HKLM\System\...\Parameters\PersistentRoutes: [104.82.14.146,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.82.22.249,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.87.88.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.89.242.39,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [11.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.18.11,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.3.128,255.255.255.255,0.0.0.0,1]
PersistentRoutes: There are 1086 PersistentRoutes.
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: hu4eol42.default-release -> 1A202D4B41E895FC
FF DefaultProfile: 3syath58.default-release-1783881393319 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release [2026-08-04]
FF Extension: (uBlock Origin) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-07-09]
FF Extension: (NoScript) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2026-07-21] [UpdateUrl:hxxps://dist.torproject.org/torbrowser/noscript/update-stable.json]
FF Extension: (Mullvad Browser Extension) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{d19a89b9-76c1-4a61-bcd4-49e8de916403}.xpi [2026-04-17] [UpdateUrl:hxxps://cdn.mullvad.net/browser-extension/updates.json]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default [2026-02-13]
FF user.js: detected! => C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default\user.js [2025-12-01]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 [2026-08-04]
FF Homepage: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> web.de
FF NewTabOverride: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> Enabled: mailcheck@web.de
FF Extension: (WEB.DE MailCheck) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\mailcheck@web.de.xpi [2026-07-14] [UpdateUrl:hxxps://dl.gmx.com/mailcheck/firefox/updates.json]
FF Extension: (New Tab) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\newtab@mozilla.org.xpi [2026-07-18]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2026-07-18]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-22] (VideoLAN) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=3 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [No File]
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=9 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [No File]
Edge:
=======
Edge Profile: C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-31]
Edge Extension: (Google Docs Offline) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-26]
Edge Extension: (Edge relevant text changes) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-07-26]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [144784 2018-04-18] (Canon Inc. -> CANON INC.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14056848 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
S3 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [888208 2025-11-16] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUMemfilesService; C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe [416136 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUPMService; C:\Program Files (x86)\Glary Utilities\GUPMService.exe [76688 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460992 2025-04-18] (Canon Inc. -> )
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [193472 2025-08-18] (IObit Co., Ltd. -> IObit) <==== ATTENTION
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
S4 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 PCManager Service Store; C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe [162104 2026-06-17] (Microsoft Corporation -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\System32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
R2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [651216 2023-09-11] (Lespeed Technology Co., Ltd -> WiseCleaner.com)
S4 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 27\LiveTunerService.exe [288608 2024-10-28] (Ashampoo GmbH & Co. KG -> )
S3 Browser; %SystemRoot%\System32\browser.dll (No File)
S3 MozillaVPNBroker; "C:\Program Files\Mozilla\Mozilla VPN\Mozilla VPN.exe" windowsdaemon (No File)
S3 MozillaVPNProxy; "C:\Program Files\Mozilla\Mozilla VPN\socksproxy.exe" -p 8123 -s (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Ahflt; C:\WINDOWS\System32\drivers\ahflt.sys [49552 2023-08-30] (Microsoft Corporation -> Microsoft Corporation)
R3 bhtsdhubdr; C:\WINDOWS\System32\drivers\bhtsdhubdr.sys [202456 2020-10-20] (BayHub Technology Inc. -> BayHubTech)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ebrntdrv; C:\WINDOWS\system32\ebrntdrv.sys [57512 2025-12-25] (CHENGDU YIWO Tech Development Co., Ltd. -> )
S3 epmdkdrv; C:\WINDOWS\system32\epmdkdrv.sys [57512 2025-05-26] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R0 EPMVolFl; C:\WINDOWS\System32\drivers\EPMVolFl.sys [30136 2022-12-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider)
S3 eprdtdrv; C:\WINDOWS\system32\eprdtdrv.sys [27728 2025-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 ESAuDriver; C:\WINDOWS\System32\drivers\ESAuDriver.sys [223208 2024-07-16] (苏州顺芯半导体有限公司 -> Everest Semiconducor Co., Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 EUDCPEPM; C:\WINDOWS\System32\drivers\EUDCPEPM.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EUDCPEPM0; C:\WINDOWS\system32\drivers\EUDCPEPM0.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R1 EUEDKEPM; C:\WINDOWS\System32\drivers\EUEDKEPM.sys [24656 2026-01-12] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EuMrx; C:\WINDOWS\System32\DRIVERS\EuMrx.sys [215704 2025-09-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Win 7 DDK provider)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [230888 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 GSCAuxDriver; C:\WINDOWS\System32\DriverStore\FileRepository\gscauxdriver.inf_amd64_fe9355c6b52fb409\GSCAuxDriverx64.sys [71424 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSCx64; C:\WINDOWS\System32\DriverStore\FileRepository\gscheci.inf_amd64_e0a6bd87d5543f55\TeeDriverGSCW8x64.sys [243992 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSDriver; C:\WINDOWS\System32\drivers\GSDriver64.sys [55488 2022-09-01] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [23744 2026-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd)
S3 iaLPSS2_UART2_SYSTEM; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2.inf_amd64_fd889dfbe795f97b\iaLPSS2_UART2.sys [406488 2026-01-18] (Intel Corporation -> Intel Corporation)
R3 IntcSST; C:\WINDOWS\System32\drivers\IntcSST.sys [697728 2025-11-26] (Smart Sound Technology -> Intel(R) Corporation)
R3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [28240 2024-04-26] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [21712 2025-04-21] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [36552 2025-08-08] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-27] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144880 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-07-24] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt11.sys [216680 2026-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-25] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-08-04] (Malwarebytes Inc -> Malwarebytes)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_05602848cd0003d3\rt68cx21x64.sys [941608 2026-07-07] (Realtek Semiconductor Corp. -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 vkrnlintvsc; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsc.inf_amd64_ae7c1fb85fc0224e\vkrnlintvsc.sys [79168 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
R3 vkrnlintvsp; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsp.inf_amd64_249e734e16ab4232\vkrnlintvsp.sys [87504 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-13] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [283016 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-11-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
U4 DiagTrack; no ImagePath
U4 dmwappushsvc; no ImagePath
S3 EuGdiDrv; \SystemRoot\system32\EuGdiDrv.sys (No File)
S2 MozillaVPNSplitTunnel; \??\C:\Program Files\Mozilla\Mozilla VPN\mullvad-split-tunnel.sys (No File)
S3 usbscan; \SystemRoot\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\usbscan.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-04 17:34 - 2026-08-04 17:35 - 000000000 ____D C:\FRST
2026-08-04 17:32 - 2026-08-04 17:32 - 000000784 _____ C:\Users\goofy\Desktop\FRST.txt
2026-08-04 16:33 - 2026-08-04 16:33 - 000730398 _____ C:\WINDOWS\system32\perfh007.dat
2026-08-04 16:33 - 2026-08-04 16:33 - 000255203 ____T C:\Users\goofy\test_trace.txt
2026-08-04 16:33 - 2026-08-04 16:33 - 000153228 _____ C:\WINDOWS\system32\perfc007.dat
2026-08-04 16:33 - 2026-08-04 16:33 - 000000171 ____T C:\Users\goofy\test_step1.txt
2026-08-04 16:29 - 2026-08-04 16:29 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-08-04 14:28 - 2026-08-04 14:28 - 000003322 _____ C:\WINDOWS\system32\Tasks\klcp_update
2026-08-04 14:28 - 2019-12-28 12:00 - 000784384 _____ C:\WINDOWS\system32\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000681984 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000310784 _____ C:\WINDOWS\system32\xvidvfw.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000284160 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003850240 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003799552 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2026-08-04 14:28 - 2012-07-21 13:55 - 000180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2026-08-04 14:28 - 2012-07-21 13:54 - 000122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2026-08-04 14:28 - 2011-12-07 20:37 - 000148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2026-08-04 14:28 - 2011-12-07 20:32 - 000216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2026-08-04 09:02 - 2026-08-04 09:02 - 012426276 _____ C:\Users\goofy\Downloads\F-Droid.apk
2026-08-04 08:44 - 2026-08-04 08:44 - 012426276 _____ C:\Users\goofy\Downloads\org.fdroid.fdroid_1023052.apk
2026-08-02 22:22 - 2026-08-02 22:22 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2026-08-02 22:22 - 2026-08-02 22:22 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2026-08-01 23:02 - 2026-08-01 23:02 - 000344472 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-07-30 07:26 - 2026-08-04 09:55 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-07-28 08:48 - 2026-07-28 08:48 - 000132424 _____ C:\Users\goofy\Downloads\Account Statement FDA_124_114_752_806 - 2026-02-06 - 2026-07-28.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000149064 _____ C:\Users\goofy\Downloads\5187303_2026_Nr.006_Kontoauszug_vom_2026.07.01_20260728084308515.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000118245 _____ C:\Users\goofy\Downloads\5187303_2026_Rechnungsabschluss_Geduldete Überziehung_vom_2026.07.01_20260728084320936.pdf
2026-07-26 13:51 - 2026-07-26 13:51 - 000000000 ____D C:\Users\goofy\AppData\Local\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-07-26 13:45 - 000000758 _____ C:\Users\Public\Desktop\Steuer 2025.lnk
2026-07-26 13:45 - 2026-07-26 13:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2025
2026-07-26 13:27 - 2026-07-26 13:27 - 547540784 _____ C:\Users\goofy\Downloads\Steuer2025.exe
2026-07-26 07:01 - 2026-07-26 07:01 - 000003378 _____ C:\WINDOWS\system32\Tasks\IObit SUM2026Sale (One-time)
2026-07-25 09:18 - 2026-07-25 09:18 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2026-07-25 09:05 - 2026-07-25 09:05 - 058118520 _____ (Tweaking.com) C:\Users\goofy\Downloads\tweaking.com_windows_repair_aio_setup.exe
2026-07-25 08:51 - 2026-07-25 08:51 - 000003782 _____ C:\WINDOWS\system32\Tasks\Tweaking.com - Windows Repair Tray Icon
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2026-07-24 20:54 - 2026-08-04 17:35 - 000000000 ____D C:\Users\goofy\Downloads\Neuer Ordner
2026-07-24 13:27 - 2026-07-24 14:21 - 000000000 ____D C:\Program Files (x86)\iTop Data Recovery
2026-07-24 13:27 - 2026-07-24 13:27 - 000003144 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_goofy
2026-07-24 13:27 - 2026-07-24 13:27 - 000001442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2026-07-24 13:27 - 2026-07-24 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2026-07-24 13:27 - 2026-07-24 13:27 - 000000000 ____D C:\ProgramData\iTop
2026-07-24 13:25 - 2026-07-24 13:25 - 033257536 _____ (IObit ) C:\Users\goofy\Downloads\iobituninstaller.exe
2026-07-24 12:53 - 2026-07-24 12:53 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\MMC
2026-07-24 12:45 - 2026-07-24 12:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\Malwarebytes
2026-07-24 12:45 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Sentry
2026-07-24 09:38 - 2026-08-04 16:35 - 000000000 ____D C:\Users\goofy\AppData\Local\Malwarebytes
2026-07-24 09:38 - 2026-07-24 09:38 - 000002105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-24 09:37 - 2026-07-24 09:37 - 002862824 _____ (Malwarebytes) C:\Users\goofy\Downloads\MBSetup-8.8.exe
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\Packages
2026-07-24 08:50 - 2026-07-24 08:50 - 000000020 ___SH C:\Users\WsiAccount\ntuser.ini
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Vorlagen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Startmenü
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Netzwerkumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Lokale Einstellungen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Eigene Dateien
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Druckumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Videos
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Musik
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Bilder
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Verlauf
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\SystemCertificates
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Protect
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Crypto
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Credentials
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Vault
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Spelling
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\LocalLow\Intel
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\VirtualStore
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\D3DSCache
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\ConnectedDevicesPlatform
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount
2026-07-24 08:50 - 2026-02-12 20:54 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Network
2026-07-24 08:50 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\WsiAccount\OneDrive
2026-07-23 23:18 - 2026-07-23 23:18 - 000000000 ____D C:\Users\Administrator\AppData\Local\PeerDistRepub
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Everything
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\Everything
2026-07-23 22:36 - 2026-07-23 22:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2026-07-23 22:06 - 2026-07-23 22:07 - 000000000 ____D C:\Users\Administrator\Desktop\Neuer Ordner
2026-07-23 22:06 - 2026-07-23 22:06 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003586 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000002419 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Obsidium x64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\.obs64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\TeraCopy
2026-07-23 22:05 - 2026-07-23 22:20 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers
2026-07-23 22:05 - 2026-07-23 22:05 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2026-07-23 22:04 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Spelling
2026-07-23 22:04 - 2026-07-23 22:11 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache
2026-07-23 22:04 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator
2026-07-23 22:04 - 2026-07-23 22:04 - 000002346 _____ C:\Users\Administrator\Desktop\Microsoft Edge.lnk
2026-07-23 22:04 - 2026-07-23 22:04 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Vorlagen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Startmenü
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Eigene Dateien
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Druckumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Videos
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Protect
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Crypto
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Vault
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Intel
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2026-07-23 22:04 - 2026-02-12 20:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Network
2026-07-23 22:04 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\Administrator\OneDrive
2026-07-22 08:09 - 2026-07-29 14:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\Program Files\PowerShell
2026-07-18 09:53 - 2026-07-18 09:53 - 000056366 _____ C:\Users\goofy\Downloads\ernaehrungstagebuch102.pdf
2026-07-16 10:43 - 2026-07-25 09:25 - 000000000 ____D C:\Program Files\TeraCopy
2026-07-16 10:43 - 2026-07-16 11:04 - 000000000 ____D C:\Users\goofy\AppData\Roaming\TeraCopy
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\AppData\Roaming\Obsidium x64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\.obs64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Code Sector
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Caphyon
2026-07-14 08:57 - 2026-07-14 08:57 - 000000000 ____D C:\Program Files\Microsoft Office 15
2026-07-13 22:12 - 2026-07-25 08:52 - 000010055 _____ C:\WINDOWS\system32\InstallMonitorLog.csv
2026-07-13 17:29 - 2026-07-23 22:10 - 000000000 ____D C:\WINDOWS\Panther
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagwrn.xml
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagerr.xml
2026-07-12 23:18 - 2026-07-16 17:24 - 000000000 ____D C:\Users\goofy\AppData\Local\PlaceholderTileLogoFolder
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ___SD C:\WINDOWS\system32\containers
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ____D C:\WINDOWS\system32\HvsiSettingsProviders
2026-07-11 10:46 - 2026-05-16 00:09 - 036362808 _____ C:\Users\goofy\Desktop\FRITZBOX - Tricks und Tipps Mai 2026.pdf
2026-07-09 12:10 - 2026-07-09 12:10 - 000000416 _____ C:\WINDOWS\BRWMARK.INI
2026-07-09 12:10 - 2026-07-09 12:10 - 000000034 _____ C:\WINDOWS\SysWOW64\BD5240.DAT
2026-07-09 10:02 - 2026-07-09 10:03 - 000000000 ____D C:\Users\goofy\Downloads\PVS
2026-07-07 09:02 - 2026-07-07 09:02 - 000002620 _____ C:\Users\goofy\Desktop\Raisin-Empfängerprüfung.txt
2026-07-07 08:53 - 2026-07-07 08:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2026-07-06 22:33 - 2026-07-06 22:33 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Media Player
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-04 17:09 - 2023-02-05 18:26 - 000000000 ____D C:\Users\goofy\.rainlendar2
2026-08-04 16:49 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-08-04 16:42 - 2026-01-24 11:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Mp3tag
2026-08-04 16:41 - 2025-12-24 20:47 - 000000000 ____D C:\Users\goofy\AppData\Roaming\vlc
2026-08-04 16:39 - 2023-09-17 10:49 - 000000000 ____D C:\Users\goofy\Desktop\YSD
2026-08-04 16:33 - 2026-02-12 20:56 - 001724020 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-08-04 16:33 - 2026-02-12 20:13 - 000000000 ____D C:\Users\goofy
2026-08-04 16:33 - 2025-11-30 12:03 - 000064520 _____ C:\Users\goofy\test.dat
2026-08-04 16:33 - 2025-11-30 12:02 - 000005397 _____ C:\Users\goofy\test.ini
2026-08-04 16:33 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-08-04 16:30 - 2026-03-02 11:44 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Wise Care 365
2026-08-04 16:29 - 2026-02-22 11:29 - 000012288 ___SH C:\DumpStack.log.tmp
2026-08-04 16:29 - 2026-02-12 20:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-08-04 16:29 - 2025-11-25 19:01 - 000142058 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-08-04 16:29 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-08-04 14:57 - 2026-01-14 12:03 - 000000000 ____D C:\Users\goofy\AppData\Local\Everything
2026-08-04 14:57 - 2026-01-14 11:15 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Everything
2026-08-04 14:57 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-08-04 14:57 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic
2026-08-04 11:26 - 2025-11-26 19:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\YouTubeSongDownloader
2026-08-04 11:12 - 2022-11-28 22:53 - 000000000 ____D C:\Users\goofy\.cache
2026-08-03 14:31 - 2025-11-26 10:44 - 000001334 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2026-08-03 09:57 - 2025-11-25 19:14 - 000000000 ____D C:\Users\goofy\AppData\Local\Packages
2026-08-03 09:14 - 2026-02-12 19:53 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2026-08-02 22:50 - 2026-04-17 11:41 - 000000000 ____D C:\Users\goofy\AppData\Local\deno
2026-08-02 22:50 - 2026-03-01 15:52 - 000000000 ____D C:\Users\goofy\AppData\Local\D3DSCache
2026-08-02 22:22 - 2025-12-07 14:05 - 000001398 _____ C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2026-08-02 08:23 - 2026-01-17 19:51 - 000000000 ____D C:\Users\goofy\AppData\Local\CrashDumps
2026-08-01 15:16 - 2025-11-26 18:04 - 000000000 ____D C:\Users\goofy\AppData\Local\JDownloader 2
2026-08-01 08:30 - 2025-11-26 22:34 - 000000000 ____D C:\Program Files (x86)\Glary Utilities
2026-07-31 20:47 - 2025-11-25 20:14 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Excel
2026-07-31 14:39 - 2026-06-27 11:40 - 000002812 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (goofy)
2026-07-31 14:39 - 2026-06-27 11:40 - 000002634 _____ C:\WINDOWS\system32\Tasks\Driver Booster Scheduler
2026-07-31 14:39 - 2026-06-27 11:40 - 000002620 _____ C:\WINDOWS\system32\Tasks\Driver Booster Update
2026-07-31 14:39 - 2026-02-12 20:54 - 000003742 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-31 14:39 - 2026-02-12 20:54 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-31 14:38 - 2025-11-26 22:54 - 000000000 ____D C:\ProgramData\ProductData3
2026-07-31 10:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2026-07-31 08:46 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-31 07:35 - 2026-02-12 20:35 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2026-07-30 14:16 - 2025-10-20 11:38 - 000000000 ____D C:\Users\goofy\Desktop\Steuer
2026-07-29 14:20 - 2025-11-25 22:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-07-29 14:16 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\DiagTrack
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-07-29 14:16 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-07-29 13:26 - 2026-02-12 20:46 - 003375104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-07-29 08:14 - 2025-11-25 19:01 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-29 08:11 - 2025-11-25 22:37 - 000001071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 15:30 - 2024-03-08 23:04 - 000000000 ____D C:\Users\goofy\Desktop\Kontoauszüge
2026-07-26 13:48 - 2026-01-10 13:30 - 000000000 ____D C:\ProgramData\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-01-10 13:56 - 000000000 ____D C:\Program Files\Steuer 2025
2026-07-25 09:28 - 2022-04-14 03:14 - 000000000 ____D C:\WINDOWS\CSC
2026-07-25 09:24 - 2026-01-24 11:03 - 000000000 ____D C:\Program Files\Mp3tag
2026-07-25 09:12 - 2025-12-21 20:16 - 001729632 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2026-07-24 13:27 - 2025-11-26 22:53 - 000000908 _____ C:\ProgramData\pdinst.ini
2026-07-24 13:27 - 2025-11-26 22:53 - 000000000 ____D C:\Users\goofy\AppData\Roaming\IObit
2026-07-24 13:27 - 2025-11-26 22:53 - 000000000 ____D C:\ProgramData\IObit
2026-07-24 13:26 - 2025-11-26 22:54 - 000000000 ____D C:\Program Files (x86)\IObit
2026-07-24 11:22 - 2025-11-26 22:34 - 000001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities.lnk
2026-07-24 09:38 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-07-24 09:15 - 2023-02-06 16:17 - 000000000 ____D C:\Users\goofy\Desktop\Text-Dateien
2026-07-24 08:50 - 2026-03-05 09:03 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-07-23 22:20 - 2020-11-19 09:48 - 000000000 ____D C:\ProgramData\Packages
2026-07-23 22:15 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Registration
2026-07-23 22:04 - 2020-11-19 09:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2026-07-23 21:23 - 2026-04-29 11:55 - 000001292 _____ C:\Users\goofy\Desktop\ESET Online Scanner.lnk
2026-07-20 08:28 - 2025-12-07 19:52 - 002318240 _____ C:\Users\goofy\Desktop\Hochzeit Klaus2.jpeg
2026-07-19 17:38 - 2025-01-20 12:46 - 000000004 _____ C:\Users\goofy\Desktop\1990.txt
2026-07-17 15:31 - 2025-11-25 22:11 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-16 17:21 - 2025-12-14 11:21 - 000000000 ____D C:\WINDOWS\pss
2026-07-15 17:35 - 2024-04-01 18:36 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-07-15 17:35 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-07-15 15:04 - 2025-11-26 23:05 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-15 15:03 - 2025-11-26 23:05 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-15 14:36 - 2025-11-26 11:06 - 000000000 ____D C:\ProgramData\Package Cache
2026-07-15 14:35 - 2026-02-14 10:54 - 000000000 ____D C:\Program Files\dotnet
2026-07-14 18:56 - 2025-11-25 20:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Word
2026-07-13 17:42 - 2020-11-19 09:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-07-13 13:37 - 2026-02-11 20:06 - 000499195 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_708
2026-07-12 20:36 - 2026-02-12 20:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-12 20:36 - 2025-11-25 22:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-11 15:25 - 2025-11-26 19:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Signal
2026-07-10 10:43 - 2023-03-29 21:51 - 000000000 ____D C:\Users\goofy\Desktop\Restaurants, Cafés
2026-07-09 17:13 - 2025-11-11 14:23 - 000000011 _____ C:\Users\goofy\Desktop\a.txt
2026-07-09 11:49 - 2025-11-25 21:57 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\MMC
2026-07-07 16:37 - 2025-11-26 17:40 - 000000000 ____D C:\Program Files\7-Zip
2026-07-06 16:03 - 2024-10-27 11:31 - 000000000 ____D C:\Users\goofy\Aiarty Output
2026-07-05 18:10 - 2025-09-23 10:49 - 000000000 ____D C:\Users\goofy\Desktop\Clio
==================== Files in the root of some directories ========
2022-10-06 13:03 - 2023-10-07 12:55 - 000000076 _____ () C:\Users\goofy\123.dat
2024-04-21 19:41 - 2025-11-25 10:14 - 000067918 _____ () C:\Users\goofy\bestof.dat
2025-11-11 18:10 - 2025-11-11 18:10 - 007300408 _____ (Microsoft Corporation) C:\Users\goofy\setup.exe
2025-11-12 20:13 - 2023-11-01 15:44 - 000000049 _____ () C:\Users\goofy\start.bat
2025-11-30 12:03 - 2026-08-04 16:33 - 000064520 _____ () C:\Users\goofy\test.dat
2025-11-25 20:08 - 2023-11-01 15:44 - 000000049 _____ () C:\Program Files\start.bat
2026-06-26 17:22 - 2026-06-26 17:22 - 000000059 _____ () C:\Users\goofy\AppData\Roaming\epm_user.ini
2025-12-05 19:53 - 2025-12-05 19:57 - 000097808 _____ () C:\Users\goofy\AppData\Local\dxdiag.log
2026-06-09 20:58 - 2026-06-09 20:58 - 000102541 _____ () C:\Users\goofy\AppData\Local\mozillavpn.log
2025-12-14 11:23 - 2025-12-14 11:23 - 000007629 _____ () C:\Users\goofy\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
|
| | #4 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-Start Das Addition-Log fehlt.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #5 |
| | Langsamer WIN-Start Sorry! Hier die Datei: Code:
ATTFilter [Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-08-2026 01
Ran by goofy (04-08-2026 17:37:28)
Running from C:\Users\goofy\Downloads\Neuer Ordner
Microsoft Windows 11 Pro Version 25H2 26200.8973 (X64) (2026-02-12 18:55:13)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2474616372-3844271695-3557059434-500 - Administrators - Disabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-2474616372-3844271695-3557059434-503 - Limited - Disabled)
Gast (S-1-5-21-2474616372-3844271695-3557059434-501 - Limited - Disabled)
goofy (DisplayName: ) (S-1-5-21-2474616372-3844271695-3557059434-1001 - Administrators - Enabled) => C:\Users\goofy
WDAGUtilityAccount (S-1-5-21-2474616372-3844271695-3557059434-504 - Limited - Disabled)
WsiAccount (DisplayName: ) (S-1-5-21-2474616372-3844271695-3557059434-1005 - Limited - Disabled) => C:\Users\WsiAccount
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 26.02 (x64) (HKLM\...\7-Zip) (Version: 26.02 - Igor Pavlov)
AI Photo Restoration Software for Old Photos 13.0 (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\AI Photo Restoration Software for Old Photos_is1) (Version: 13.0 - SoftOrbits)
Aiarty Image Enhancer (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Aiarty Image Enhancer) (Version: 3.1 - Digiarty, Inc.)
Appman Auto Sequencer (HKLM-x32\...\{8F3C758F-4251-FBF2-C0DC-A3D6530FA966}) (Version: 10.1.28000.1 - Microsoft) Hidden
Appman Sequencer on amd64 (HKLM\...\{BCBE4F1F-7F40-C8F7-AF60-7EDC73727C04}) (Version: 10.1.28000.1 - Microsoft) Hidden
Ashampoo WinOptimizer 27 (HKLM-x32\...\{4209F371-B009-83C0-55A2-B0904D2A6CF6}_is1) (Version: 27.00.05 - Ashampoo GmbH & Co. KG)
BCD and Boot (HKLM-x32\...\{E5D99374-E8C2-155F-7806-D967CE096401}) (Version: 10.1.28000.1 - Microsoft) Hidden
BLACK WHITE projects 6 professional (64-Bit) (HKLM\...\SILVER_PROJECTS_6_3_28B15F1D_is1) (Version: 6.63 - Franzis Verlag GmbH)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.5.0.69 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.7.0 - Canon Inc.)
CanoScan LiDE 400 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4813S) (Version: 1.00 - Canon Inc.)
Chip Bankingbrowser 2026 (HKLM-x32\...\{DF19E964-BD8F-4BD1-963E-60D058CC2901}_is1) (Version: 8 - Abelssoft)
CrystalDiskInfo 9.9.1 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.9.1 - Crystal Dew World)
Driver Booster 13 (HKLM-x32\...\Driver Booster_is1) (Version: 13.5.0 - IObit)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
EaseUS Partition Master (HKLM\...\EaseUS Partition Master_is1) (Version: 20.3 - EaseUS)
Everything 1.4.1.1032 (x64) (HKLM\...\Everything) (Version: 1.4.1.1032 - voidtools)
Free ISO Creator version 1.0 (HKLM-x32\...\{FBEF93EA-D52F-45B5-91D3-ABEACE4C7615}_is1) (Version: 1.0 - freeisocreator.com)
Glary Utilities PRO 6.45 (HKLM-x32\...\Glary Utilities) (Version: 6.45.0.49 - Glarysoft Ltd)
Imaging And Configuration Designer (DesktopEditions) (HKLM-x32\...\{A65BDB59-35E2-5A02-9CF3-A22FFDF29A88}) (Version: 10.1.28000.1 - Microsoft) Hidden
Imaging And Configuration Designer (OnecoreUAP) (HKLM-x32\...\{CB7C9DA0-441C-07DF-2AD9-54129394A57E}) (Version: 10.1.28000.1 - Microsoft) Hidden
Imaging Designer (DesktopEditions) (HKLM-x32\...\{329E262C-6F7E-C520-7B2E-26BDE336E321}) (Version: 10.1.28000.1 - Microsoft) Hidden
Imaging Designer (OnecoreUAP) (HKLM-x32\...\{8BBCE85C-0C0B-A282-737E-41E21BE57A58}) (Version: 10.1.28000.1 - Microsoft) Hidden
Imaging Tools Support (DesktopEditions) (HKLM-x32\...\{4C3D8452-762F-AE7F-8E42-4A329FF221DA}) (Version: 10.1.28000.1 - Microsoft) Hidden
Imaging Tools Support (OnecoreUAP) (HKLM-x32\...\{1F2EEE8C-1BEA-A331-0C28-9B81AB246449}) (Version: 10.1.28000.1 - Microsoft) Hidden
IObit Uninstaller 15 (HKLM-x32\...\IObitUninstall) (Version: 15.5.0.11 - IObit)
iReaShare Android Manager (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\iReaShare Android Manager) (Version: 1.0.12 - iReaShare)
ISO to USB (HKLM-x32\...\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1) (Version: - isotousb.com)
JDownloader 2 (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\jdownloader2) (Version: 2.0.240220 - AppWork GmbH)
Kingston SSD Manager x64 1.5.6.5 (HKLM-x32\...\{53F657CD-C4FC-4DCD-826E-6862917532AC}_is1) (Version: 1.5.6.5 - @2021 Kingston Digital, Inc.)
Kits Configuration Installer (HKLM-x32\...\{B417962A-C373-E8A3-40A6-D393D048E09F}) (Version: 10.1.28000.1 - Microsoft) Hidden
K-Lite Mega Codec Pack 19.8.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 19.8.5 - KLCP)
Malwarebytes version 5.6.3.284 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.3.284 - Malwarebytes)
Microsoft .NET Host - 8.0.29 (x64) (HKLM\...\{DC3A1841-0E03-4FF1-A0EA-ED67C23AE5B9}) (Version: 64.116.55299 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.29 (x64) (HKLM\...\{AB48661D-072A-4D25-82C0-B15A271B3B3A}) (Version: 64.116.55299 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.29 (x64) (HKLM\...\{008A60AE-D44F-4260-8190-AD1BED94E5DF}) (Version: 64.116.55299 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.105 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.105 - Microsoft Corporation) Hidden
Microsoft Office LTSC Professional Plus 2024 - de-de (HKLM\...\ProPlus2024Volume - de-de) (Version: 16.0.17932.20884 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2474616372-3844271695-3557059434-500\...\OneDriveSetup.exe) (Version: 25.087.0506.0001 - Microsoft Corporation)
Microsoft Support and Recovery Assistant (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\ef788e60295adac3) (Version: 17.1.2465.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.51.36247 (HKLM\...\{6FA797CF-6B76-4B6D-87EE-768F92008720}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.51.36247 (HKLM\...\{931A2CF0-2404-45EA-82F5-345735AE6A90}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.51.36247 (HKLM-x32\...\{582BA719-E6F1-4651-A873-049E6A0DDDAF}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.51.36247 (HKLM-x32\...\{4BF7CE18-E151-449F-9190-6CDBED0BB4A2}) (Version: 14.51.36247 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.51.36247 (HKLM-x32\...\{0e3bb569-69d6-4c34-bff9-c2f81db5e5f0}) (Version: 14.51.36247.0 - Microsoft Corporation)
Microsoft Visual C++ v14 Redistributable (x86) - 14.51.36247 (HKLM-x32\...\{9a6ce18d-11c0-4452-aa35-9f2b8437c686}) (Version: 14.51.36247.0 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.29 (x64) (HKLM\...\{F7A0E757-A368-44E4-A62B-C1A1954375AE}) (Version: 64.116.55314 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.29 (x64) (HKLM-x32\...\{9f2d26b2-8ee6-4466-ae8b-0a84b0ab083e}) (Version: 8.0.29.36225 - Microsoft Corporation)
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 153.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 151.0.2 - Mozilla)
Mp3tag v3.35.1 (HKLM\...\Mp3tag) (Version: 3.35.1 - Florian Heidenreich)
Mullvad Browser (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\MullvadBrowserRelease) (Version: 15.0.19 - Mullvad VPN)
NetSkat (HKLM-x32\...\{3BA463F1-3B1E-44E1-BBB7-AEB7070CD48E}) (Version: 7.9.21 - CuteSoft)
OA3Tool (HKLM-x32\...\{49E464F0-A7DA-67DE-4430-A0EFCF366D4C}) (Version: 10.1.28000.1 - Microsoft) Hidden
OACheck (HKLM-x32\...\{6661AA14-067A-DAFD-F183-624CD5A83873}) (Version: 10.1.28000.1 - Microsoft) Hidden
OATool (HKLM-x32\...\{769E5F0E-6BD2-BC8D-6E50-1736DC9D36A1}) (Version: 10.1.28000.1 - Microsoft) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.17928.20216 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.17932.20884 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.17928.20216 - Microsoft Corporation) Hidden
Oscdimg (DesktopEditions) (HKLM-x32\...\{E507E7D8-0675-91F2-DE68-1B9802B60867}) (Version: 10.1.28000.1 - Microsoft) Hidden
Oscdimg (OnecoreUAP) (HKLM-x32\...\{13A298DC-77E9-C62D-6C35-9F9F905EF66C}) (Version: 10.1.28000.1 - Microsoft) Hidden
PowerShell 7-x64 (HKLM\...\{92D9A5DC-8C64-40D5-B1BC-98DB9C7FDB7F}) (Version: 7.6.4.0 - Microsoft Corporation)
Privacy Protector for Windows 11 13.0 (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Privacy Protector for Windows 11_is1) (Version: 13.0 - SoftOrbits)
Q-Dir (HKLM\...\Q-Dir) (Version: 12.69 - SoftwareOK.com Nenad Hrg)
Rainlendar2 (remove only) (HKLM-x32\...\Rainlendar2) (Version: 2.23.0 - Rainy)
Signal 8.18.0 (HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\7d96caee-06e6-597c-9f2f-c7bb2e0948b4) (Version: 8.18.0 - Signal Messenger, LLC)
SoftOrbits Version 1.2 (HKLM-x32\...\SoftOrbits_is1) (Version: 1.2 - SoftOrbits)
Steuer 2025 (HKLM\...\{D79918A9-BF47-47CB-987C-4A2155A39F34}) (Version: 33.09.3580 - Buhl Data Service GmbH)
Supply Chain Trust Tools ADK (HKLM-x32\...\{3E5CF411-0849-BCE6-6232-2B28F6D53949}) (Version: 10.1.28000.1 - Microsoft) Hidden
TeraCopy (HKLM\...\{573E992C-480B-4636-9966-49162BC24D42}) (Version: 4.0.3.2 - Code Sector)
Text to MP3 Converter (HKLM-x32\...\Text to MP3 Converter_is1) (Version: 4.5.0.0 - VOVSOFT)
Toolkit Documentation (HKLM-x32\...\{7DFB81FC-F66B-EAAE-50A7-04FB0CEABB93}) (Version: 10.1.28000.1 - Microsoft) Hidden
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.14.0 - Tweaking.com)
UEV Tools on amd64 (HKLM\...\{81C8E18F-C051-6052-BE84-1176F283D75B}) (Version: 10.1.28000.1 - Microsoft) Hidden
Unknown Device Identifier 9.01 (HKLM\...\Unknown Device Identifier_is1) (Version: 9.01 - Huntersoft)
User State Migration Tool (ClientCore) (HKLM-x32\...\{53F0EE3A-E614-6F55-5647-2ACCEE303FF1}) (Version: 10.1.28000.1 - Microsoft) Hidden
User State Migration Tool (DesktopEditions) (HKLM-x32\...\{52411147-1F91-A90A-AB16-EDD7DE1843A4}) (Version: 10.1.28000.1 - Microsoft) Hidden
User State Migration Tool (OnecoreUAP) (HKLM-x32\...\{74E8813F-0A6B-0684-8327-DC43D9551D8F}) (Version: 10.1.28000.1 - Microsoft) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Win11PrivacyFix 2026 (HKLM-x32\...\fb89d336-fbea-44d5-b40b-af72d5d93c6a_is1) (Version: 5.02 - Abelssoft)
Windows Assessment and Deployment Kit (HKLM-x32\...\{d702f722-3d72-487e-9d7b-a2be862530f6}) (Version: 10.1.28000.1 - Microsoft Corporation)
Windows Deployment Customizations (HKLM-x32\...\{FF71AE91-4613-06F9-70FC-D9DB7B18AA08}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Deployment Image Servicing and Management - Headers and Libraries (HKLM-x32\...\{C1ED1F7E-6C3F-184C-AE14-5BA04F28A885}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Deployment Image Servicing and Management Tools (DesktopEditions) (HKLM-x32\...\{CFCFBA80-5781-D896-54B1-6D3ABE395CA3}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Deployment Image Servicing and Management Tools (OnecoreUAP) (HKLM-x32\...\{9A35E47A-5770-CB7E-47DF-5B516A9E79CC}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Deployment Tools (HKLM-x32\...\{69D5815B-35D6-1C05-D1BB-9332FE9D1758}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Deployment Tools Environment (HKLM-x32\...\{EB1FE64B-E60B-F462-C7CF-C874DBFB2EAA}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Setup Files (ClientCore) (HKLM-x32\...\{CF45B69D-BF23-9312-6F54-54F94F18EA5C}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Setup Files (DesktopEditions) (HKLM-x32\...\{38E6FDBF-4F3E-2091-D4E7-8FE321C8A85E}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Setup Files (OnecoreUAP) (HKLM-x32\...\{E3D54104-33AA-E4FE-315E-14F504AC11DD}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows Setup Files (ShellCommon) (HKLM-x32\...\{D34A9AEF-CA5C-64DB-F8E7-189DBB73B666}) (Version: 10.1.28000.1 - Microsoft) Hidden
Windows System Image Manager (HKLM-x32\...\{5896F2EE-50E5-E19F-9BF0-B3ADE69E4237}) (Version: 10.1.28000.1 - Microsoft) Hidden
WinSetView (HKLM-x32\...\{C91B741C-99CD-458D-B952-8E37E9503EF2}_is1) (Version: 3.1.8 - LesFerch)
Winxvideo AI (HKLM-x32\...\Winxvideo AI) (Version: 3.2 - Digiarty, Inc.)
Wise Care 365 (HKLM-x32\...\Wise Care 365_is1) (Version: 7.3.4 - Lespeed Technology Co., Ltd.)
WordPad for Windows 11 (HKLM\...\WordPad for Windows 11_is1) (Version: 2.0 - Winaero)
WPT Redistributables (HKLM-x32\...\{8C19B706-2ABF-9540-053A-6FCB96ADE5D4}) (Version: 10.1.28000.1 - Microsoft) Hidden
WPTx64 (DesktopEditions) (HKLM-x32\...\{4EFB22C5-0461-D2C4-F712-B4542FAB7F0E}) (Version: 10.1.28000.1 - Microsoft) Hidden
WPTx64 (OnecoreUAP) (HKLM-x32\...\{4268C9A1-6F72-B943-CD23-8D1A2CD45BF5}) (Version: 10.1.28000.1 - Microsoft) Hidden
wxMP3gain 4.2 (HKLM-x32\...\{A8DA0F4D-7A25-4FB1-91ED-D6481CB7CD35}_is1) (Version: 4.2 - Cristiano Fraga G. Nunes)
YouTube Song Downloader 2026 (HKLM-x32\...\55_is1) (Version: 26.12 - Abelssoft)
Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2026-01-14] (INTEL CORP) [Startup Task]
Diagnostic Data Viewer -> C:\Program Files\WindowsApps\Microsoft.DiagnosticDataViewer_4.2209.41991.0_x64__8wekyb3d8bbwe [2026-07-16] (Microsoft Corporation)
Ink.Handwriting.de-DE.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.de-DE.1.0_0.1082.2350.0_x64__8wekyb3d8bbwe [2026-01-14] (Microsoft Corporation)
Ink.Handwriting.de-DE.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.de-DE.1.0_0.1082.2350.0_x86__8wekyb3d8bbwe [2026-01-14] (Microsoft Corporation)
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-08-01] ()
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2026-01-14] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2026-01-14] (Microsoft Corporation) [MS Ad]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_55.20610.576.0_x64__8wekyb3d8bbwe [2026-01-14] (Microsoft Corporation)
Mp3tag -> C:\Program Files\Mp3tag [2026-07-25] (Florian Heidenreich)
PC Manager -> C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe [2026-06-17] (Microsoft Corporation) [Startup Task]
TeraCopy Shell Extension -> C:\Program Files\TeraCopy [2026-07-25] (Code Sector)
Windows Sandbox -> C:\Program Files\WindowsApps\MicrosoftWindows.WindowsSandbox_0.5.3.0_x64__cw5n1h2txyewy [2026-07-12] (Microsoft Windows)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001_Classes\CLSID\{1e9ea9b3-b691-859f-156f-90e5a1475c42}\localserver32 -> "C:\Program Files\Ashampoo\Ashampoo App\launcher\AshampooLauncher.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001_Classes\CLSID\{6a27a1a9-7be8-1491-04ca-ee68a211c258}\localserver32 -> "C:\Program Files\Google\Play Games\current\service\Service.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001_Classes\CLSID\{86CA1AA0-34AA-4E8B-A509-50C905BAE2A2}\InprocServer32 -> => No File
ContextMenuHandlers1: [1XdShellExt] -> {B4E15CD0-F916-4C8E-830A-15E3E9D01A1B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-06-25] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [EpmRightMenu] -> {a5354344-b5da-4901-afd1-f0adc1d0b8bd} => C:\Program Files\EaseUS\RightMenu\epmright.dll [2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> TODO: <Company name>)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-11-16] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers1: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2025-08-18] (IObit Co., Ltd. -> IObit)
ContextMenuHandlers2: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers2: [EpmRightMenu] -> {a5354344-b5da-4901-afd1-f0adc1d0b8bd} => C:\Program Files\EaseUS\RightMenu\epmright.dll [2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> TODO: <Company name>)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-11-16] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers3: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-24] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-06-25] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [EpmRightMenu] -> {a5354344-b5da-4901-afd1-f0adc1d0b8bd} => C:\Program Files\EaseUS\RightMenu\epmright.dll [2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> TODO: <Company name>)
ContextMenuHandlers4: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2025-08-18] (IObit Co., Ltd. -> IObit)
ContextMenuHandlers4: [WorkFolders] -> {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} => -> No File
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers5: [EpmRightMenu] -> {a5354344-b5da-4901-afd1-f0adc1d0b8bd} => C:\Program Files\EaseUS\RightMenu\epmright.dll [2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> TODO: <Company name>)
ContextMenuHandlers5: [WorkFolders] -> {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} => -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-06-25] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities\x64\ContextHandler.dll [2025-11-16] (Glarysoft Ltd -> Glarysoft Ltd)
ContextMenuHandlers6: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2025-08-18] (IObit Co., Ltd. -> IObit)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-24] (Malwarebytes Inc -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [VIDC.X264] => C:\WINDOWS\system32\x264vfw64.dll [3799552 2017-07-30] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\WINDOWS\system32\lagarith.dll [148992 2011-12-07] () [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\WINDOWS\system32\xvidvfw.dll [310784 2019-12-28] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] () [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [284160 2019-12-28] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed]
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2025-02-07 11:18 - 2025-02-07 11:18 - 000019968 _____ () [File not signed] C:\Program Files\Rainlendar2\lfs.dll
2025-02-07 12:36 - 2025-02-07 12:36 - 000364544 _____ () [File not signed] C:\Program Files\Rainlendar2\libical.dll
2025-02-07 12:36 - 2025-02-07 12:36 - 000063488 _____ () [File not signed] C:\Program Files\Rainlendar2\libicalss.dll
2025-02-07 11:18 - 2025-02-07 11:18 - 000392192 _____ () [File not signed] C:\Program Files\Rainlendar2\lua54.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000212992 _____ () [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\libEGL.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 005431296 _____ () [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\libGLESv2.dll
2026-07-07 08:43 - 2026-06-25 12:00 - 000101888 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000964096 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\freebl3.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 009238528 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\gkcodecs.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000352768 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\lgpllibs.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 004298752 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\mozavcodec.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000605696 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\mozavutil.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000998912 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\mozglue.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 002712064 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\nss3.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 000288256 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\softokn3.dll
2026-07-24 08:10 - 2026-07-24 08:10 - 169520640 _____ (Mullvad VPN AB) [File not signed] C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\xul.dll
2025-02-07 11:14 - 2025-02-07 11:14 - 000571392 _____ (The curl library, hxxps://curl.se/) [File not signed] C:\Program Files\Rainlendar2\libcurl.dll
2025-02-07 10:16 - 2025-02-07 10:16 - 004837376 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files\Rainlendar2\libcrypto-3-x64.dll
2025-02-07 11:13 - 2025-02-07 11:13 - 001247232 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files\Rainlendar2\libssl-3-x64.dll
2025-02-07 11:29 - 2025-02-07 11:29 - 003009024 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxbase32u_vc_rny.dll
2025-02-07 11:34 - 2025-02-07 11:34 - 000186880 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxbase32u_xml_vc_rny.dll
2025-02-07 11:33 - 2025-02-07 11:33 - 007418880 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxmsw32u_core_vc_rny.dll
2025-02-07 11:34 - 2025-02-07 11:34 - 000709120 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxmsw32u_html_vc_rny.dll
2025-02-07 11:59 - 2025-02-07 11:59 - 000790528 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxmsw32u_propgrid_vc_rny.dll
2025-02-07 11:35 - 2025-02-07 11:35 - 000878080 _____ (wxWidgets development team) [File not signed] C:\Program Files\Rainlendar2\wxmsw32u_xrc_vc_rny.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\goofy\Desktop\Dynamikum in Pirmasens.png:shield [154]
AlternateDataStreams: C:\Users\goofy\Desktop\fake-Rufnummern.png:shield [181]
AlternateDataStreams: C:\Users\goofy\Desktop\Powerline AV.pdf:shield [171]
AlternateDataStreams: C:\Users\goofy\Desktop\Powerline AV2.pdf:shield [142]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2025-08-18] (IObit Co., Ltd. -> IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
There are 7942 more sites.
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\123simsen.com -> www.123simsen.com
There are 7942 more sites.
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2026-07-25 09:17 - 2026-07-25 09:17 - 000000855 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
2025-11-26 10:44 - 2026-08-03 14:31 - 000001334 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
172.27.246.194 46e5a09d-794a-4dcb-967b-cbae450cfa15.mshome.net # 2026 8 2 4 11 1 18 370
172.19.119.187 7ef4a8a9-8b4d-4a21-81bb-035a3115961c.mshome.net # 2026 8 5 7 10 48 48 542
172.28.96.1 DESKTOP-P4QE8KD.mshome.net # 2031 8 6 2 12 31 40 661
172.28.108.14 ed05b32d-f004-4789-9a33-a40090fda691.mshome.net # 2026 8 1 10 7 14 35 320
320
47 58
10 0 28 492
172.25.119.31 c77dd4bb-61dc-41d3-a33f-872bc38cf0a9.mshome.net # 2026 7 1 13 8 49 18 352
172.27.31.43 d416e4f6-3c9b-454b-90cd-c2289547fa86.mshome.net # 2026 7 3 8 18 51 15 418
172.29.243.53 db052cb7-19bf-4210-824f-76ce893e98dd.mshome.net # 2026 7 5 10 6 19 49 188
172.25.112.1 DESKTOP-P4QE8KD.mshome.net # 2031 7 6 5 8 49 18 352
172.31.87.200 df9be588-d99b-4e23-80bb-af4fb457745c.mshome.net # 2026 7 0 12 7 17 1 618
45 835
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.178.1
Windows Firewall is enabled.
Network Binding:
=============
vms_vsf: Erweiterungsfilter für virtuellen Hyper-V-Switch
ms_l1vhlwf: Geschachtelte Netzwerkvirtualisierung
vms_vsp: Extension-Protokoll für virtuellen Hyper-V-Switch
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-2474616372-3844271695-3557059434-1005\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2474616372-3844271695-3557059434-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_2.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 0)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\SOFTWARE\Microsoft\Windows Security Health\State => (AppAndBrowser_StoreAppsSmartScreenOff: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\Services: MBVpnTunnelService => 3
MSCONFIG\Services: RstMwService => 2
MSCONFIG\Services: WO_LiveService2 => 2
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\StartupApproved\Run: => "AviraBrowserAutoLaunch_FD9D8C6A34614A635E4238D6F2EDAA67"
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_4034F5E9CB1F0186CE71883A938CD3EE"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{44760ECD-DCF7-43A0-B6F5-BA23FA02DE3A}] => (Block) C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe (Ascora GmbH -> The CefSharp Authors)
FirewallRules: [{E9E5DE7D-4A4C-42F1-BCF6-ED2379351795}] => (Block) C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe (Ascora GmbH -> The CefSharp Authors)
FirewallRules: [UDP Query User{719502A9-2D80-446F-B7C1-05CB11299D37}C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe] => (Allow) C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe (Ascora GmbH -> The CefSharp Authors)
FirewallRules: [TCP Query User{570D49C8-E5F9-4B00-8063-4A74817097B4}C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe] => (Allow) C:\program files (x86)\chip bankingbrowser\program\cefsharp.browsersubprocess.exe (Ascora GmbH -> The CefSharp Authors)
FirewallRules: [{0D5F240A-18B0-489E-A9AD-69B999DF0132}] => (Allow) C:\Program Files (x86)\Donemax\Donemax Data Eraser\DMDE.exe => No File
FirewallRules: [{CBE7F882-F0DC-4B3D-AF06-1EE515D6334B}] => (Allow) C:\Program Files (x86)\Donemax\Donemax Data Eraser\DMDE.exe => No File
FirewallRules: [{ED7D77C0-7D85-40B2-9911-DEB1C2DAC801}] => (Allow) C:\Program Files (x86)\Donemax\Donemax Data Eraser\DMDE.exe => No File
FirewallRules: [UDP Query User{56262E3E-0C2B-4917-B28F-B1A23D5EDB22}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN) [File not signed]
FirewallRules: [TCP Query User{0A136397-2A04-4916-A759-B799412CA71D}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN) [File not signed]
FirewallRules: [{D9130E2B-1BF1-471C-ADB9-5C182476E581}] => (Allow) C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{F03A9C7F-40A4-4D46-8000-8A5C72DAC29D}] => (Allow) C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{D132D7A1-DD99-437F-A2D1-DD297C2AEC60}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F2233B2A-CFF5-48FF-8D8C-1F5385510190}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AC582C83-B7C2-45B7-A89E-11BEC77E7FDD}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BE6E81A5-434F-493C-9F53-CE7AFE143E12}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{70CF51DD-930A-48B9-B0D3-0B4C6CAECDCD}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6677187D-7ADC-488F-A24F-2F5959F1D09B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{42680933-D4E6-4C2B-90AD-6D599CC59AE6}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1F198561-ECBE-4F9B-B733-7EC383DB1EA2}] => (Allow) C:\Program Files\WindowsApps\microsoftteams_23275.702.2421.2406_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E4AC64F4-61FB-462F-B212-421706CBCA98}] => (Allow) C:\Program Files\WindowsApps\microsoftteams_23275.702.2421.2406_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BA72D89D-8AAB-4C92-8C3D-E5826DE601AB}] => (Allow) LPort=12972
FirewallRules: [{460DD12C-D6FC-483B-9689-BE0CF80D96AC}] => (Allow) LPort=14714
FirewallRules: [{D3644945-91F2-44A4-BDB7-7026B2779EB3}] => (Allow) LPort=31931
FirewallRules: [{3FA2E1D3-DEEF-4724-81BB-F75A54002590}] => (Allow) C:\Program Files (x86)\Donemax\Donemax Data Eraser\DMDE.exe => No File
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{42645240-6352-4CDF-81CD-0362C938DE28}C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe] => (Allow) C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe (Google LLC -> )
FirewallRules: [UDP Query User{60C4B5A4-5F95-479B-8283-6AE25761150B}C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe] => (Allow) C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe (Google LLC -> )
FirewallRules: [{12B1B353-2B3E-450E-AE6D-FECCD82129D4}] => (Block) C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe (Google LLC -> )
FirewallRules: [{46883FD6-A4AE-4DE8-98B6-7C519CFE2A17}] => (Block) C:\users\goofy\downloads\scrcpy-win64-v4.0\adb.exe (Google LLC -> )
FirewallRules: [{D03073F4-7644-49B9-9D67-B9781FBF580B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{28000B34-7BF2-474D-9D5D-A15578AE25B1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{F2F668F5-7DD7-4809-8282-B637488776F7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{0648CB0F-B5CC-4C12-A3F0-3581F5704FF3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{B2860D58-2015-49D3-8683-993CD30B91C8}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21253.510.996.1465_x64__8wekyb3d8bbwe\msteams.exe => No File
FirewallRules: [{17EFE77D-9BB4-4BE7-A785-BE5AADA9B675}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21253.510.996.1465_x64__8wekyb3d8bbwe\msteams.exe => No File
FirewallRules: [{8E19E3EE-CE55-4E8F-AF88-2BB17592D589}] => (Allow) C:\Program Files\Steuer 2025\wmain26.dll (Buhl-Data-Service GmbH -> )
FirewallRules: [{48DA8AAC-298D-4595-AE61-04D5FE70240A}] => (Allow) C:\Program Files\Steuer 2025\wmain26.dll (Buhl-Data-Service GmbH -> )
FirewallRules: [{C4A2AD07-6CD0-4B7F-86CD-3DD5147B5497}] => (Allow) C:\Program Files\Steuer 2025\wmain26.dll (Buhl-Data-Service GmbH -> )
FirewallRules: [{7F25B74A-A153-4C31-A024-174651678C17}] => (Allow) C:\Program Files\Steuer 2025\wmain26.dll (Buhl-Data-Service GmbH -> )
==================== Restore Points =========================
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (08/02/2026 08:23:25 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-P4QE8KD)
Description: Fehlerhafter Anwendungsname: wxmp3gain.exe, Version: 0.0.0.0, Zeitstempel: 0x663450cb
Fehlerhafter Modulname: wxmsw32u_core_gcc810.dll, Version: 3.2.4.0, Zeitstempel: 0x654b4d56
Ausnahmecode: 0xc0000005
Fehleroffset: 0x001dac85
Fehlerhafte Prozess-ID: 0x44c
Fehlerhafte Anwendungsstartzeit: 0x1dd224766ecdd38
Fehlerhafter Anwendungspfad: C:\Program Files (x86)\wxMP3gain\wxmp3gain.exe
Fehlerhafter Modulpfad: C:\Program Files (x86)\wxMP3gain\wxmsw32u_core_gcc810.dll
Berichts-ID: 1e03ba08-e875-468b-a251-3aed0481cd77
Vollständiger Name des fehlerhaften Pakets:
Fehlerhafte paketbezogene Anwendungs-ID:
Error: (08/02/2026 07:58:37 AM) (Source: System Restore) (EventID: 8211) (User: )
Description: Der geplante Wiederherstellungspunkt konnte nicht erstellt werden. Zusätzliche Informationen: (0x80042302).
Error: (08/02/2026 07:58:37 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\WINDOWS\system32\srtasks.exe ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Fehler = 0x80042302).
Error: (08/02/2026 07:58:37 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007041d, Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung..
Vorgang:
Sicherung abbrechen
Kontext:
Ausführungskontext: Requestor
Aktueller Status: SnapshotSetCreated
Error: (08/02/2026 07:58:37 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {faf53cc4-bd73-4e36-83f1-2b23f46e513e} und dem Namen "VSSEvent" kann nicht gestartet werden. [0x8007041d, Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.]
Vorgang:
Sicherung abbrechen
Kontext:
Ausführungskontext: Requestor
Aktueller Status: SnapshotSetCreated
Error: (08/02/2026 07:56:56 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x80040154, Klasse nicht registriert.
Vorgang:
Generatordaten werden gesammelt
Asynchroner Vorgang wird ausgeführt
Kontext:
Ausführungskontext: Requestor
Aktueller Status: GatherWriterMetadata
Error: (08/02/2026 07:56:56 AM) (Source: VSS) (EventID: 22) (User: )
Description: Fehler im Volumenschattenkopie-Dienst: Eine vom Volumenschattenkopie-Dienst benötigte kritische Komponente ist nicht registriert.
Dies kann geschehen, wenn bei der Windows-Installation oder bei der Installation eines Schattenkopieanbieters ein Fehler aufgetreten ist.
Der von CoCreateInstance für die Klasse mit CLSID "{faf53cc4-bd73-4e36-83f1-2b23f46e513e}" und dem Namen "VSSEvent" zurückgegebene Fehler ist [0x80040154, Klasse nicht registriert
].
Vorgang:
Generatordaten werden gesammelt
Asynchroner Vorgang wird ausgeführt
Kontext:
Ausführungskontext: Requestor
Aktueller Status: GatherWriterMetadata
Error: (08/01/2026 11:02:24 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhostw (7300,R,98,0) WebCacheLocal: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Users\goofy\AppData\Local\Microsoft\Windows\WebCache\V0100002.log.
System errors:
=============
Error: (08/04/2026 05:38:59 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: Fehler "1053" in DCOM, als der Dienst "EventSystem" mit den Argumenten "Nicht verfügbar" gestartet wurde, um den folgenden Server zu verwenden:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (08/04/2026 05:38:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "COM+-Ereignissystem" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/04/2026 05:38:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst COM+-Ereignissystem erreicht.
Error: (08/04/2026 05:38:52 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: Fehler "1053" in DCOM, als der Dienst "EventSystem" mit den Argumenten "Nicht verfügbar" gestartet wurde, um den folgenden Server zu verwenden:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (08/04/2026 05:38:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "COM+-Ereignissystem" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/04/2026 05:38:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst COM+-Ereignissystem erreicht.
Error: (08/04/2026 05:38:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
Error: (08/04/2026 05:38:48 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst WinHTTP-Web Proxy Auto-Discovery-Dienst erreicht.
Windows Defender:
================
TimeCreated : 30.07.2026 14:20:18
(Message : Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Security Intelligence ) (aufgetreten. Es wird versucht, zu einer vorherigen Version zurückzukehren.) (Security Intelligence versucht: Aktuell) (Fehlercode: 0x80501102) (Fehlerbeschreibung: Unerwartetes Problem. Installieren Sie bei Bedarf verfügbare Updates, und starten ) (Sie das Programm dann erneut. Informationen zum Installieren von Updates finden Sie unter "Hilfe und ) (Support". ) (Security Intelligence-Version: 1.455.364.0;1.455.364.0) (Modulversion: 1.1.26060.3008)
TimeCreated : 24.07.2026 14:43:43
(Message : Microsoft Defender Antivirus Dienst scheint beim Herunterfahren nicht reagiert zu sein.) (Timout (Sekunden): 120) (Komponente: ShutdownSpyNetManager) (Selbstbeendigend: 0)
TimeCreated : 23.07.2026 21:25:36
(Message : Fehler des Microsoft Defender Antivirus-Echtzeitschutz-Features.) (Feature: Bei Zugriff) (Fehlercode: 0x8007043c) (Fehlerbeschreibung: Der Dienst kann nicht im abgesicherten Modus gestartet werden. ) (Ursache: Die Antischadsoft-Sicherheitsfunktion wurde aus unbekanntem Grund beendet. Möglicherweise ) (kann das Problem durch einen Neustart des Diensts behoben werden.)
TimeCreated : 23.07.2026 21:23:16
(Message : Fehler des Microsoft Defender Antivirus-Echtzeitschutz-Features.) (Feature: Bei Zugriff) (Fehlercode: 0x8007043c) (Fehlerbeschreibung: Der Dienst kann nicht im abgesicherten Modus gestartet werden. ) (Ursache: Die Antischadsoft-Sicherheitsfunktion wurde aus unbekanntem Grund beendet. Möglicherweise ) (kann das Problem durch einen Neustart des Diensts behoben werden.)
TimeCreated : 22.07.2026 08:06:58
(Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.) (Weitere Informationen:) (https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threati) (d=14994&enterprise=0) (Name: SettingsModifier:Win32/PossibleHostsFileHijack) (ID: 14994) (Schweregrad: Mittel) (Kategorie: Einstellungsveränderer) (Pfad: file:_C:\Windows\System32\drivers\etc\hosts) (Erkennungsursprung: Lokaler Computer) (Erkennungstype: Konkret) (Erkennungsquelle: System) (Benutzer: NT-AUTORITÄT\SYSTEM) (Prozessname: Unknown) (Sicherheitsversion: AV: 1.455.256.0, AS: 1.455.256.0, NIS: 1.455.256.0) (Modulversion: AM: 1.1.26060.3008, NIS: 1.1.26060.3008)
TimeCreated : 21.07.2026 20:26:17
(Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.) (Weitere Informationen:) (https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threati) (d=14994&enterprise=0) (Name: SettingsModifier:Win32/PossibleHostsFileHijack) (ID: 14994) (Schweregrad: Mittel) (Kategorie: Einstellungsveränderer) (Pfad: file:_C:\Windows\System32\drivers\etc\hosts) (Erkennungsursprung: Lokaler Computer) (Erkennungstype: Konkret) (Erkennungsquelle: System) (Benutzer: NT-AUTORITÄT\SYSTEM) (Prozessname: Unknown) (Sicherheitsversion: AV: 1.455.254.0, AS: 1.455.254.0, NIS: 1.455.254.0) (Modulversion: AM: 1.1.26060.3008, NIS: 1.1.26060.3008)
TimeCreated : 21.07.2026 17:04:06
(Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.) (Weitere Informationen:) (https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threati) (d=14994&enterprise=0) (Name: SettingsModifier:Win32/PossibleHostsFileHijack) (ID: 14994) (Schweregrad: Mittel) (Kategorie: Einstellungsveränderer) (Pfad: file:_C:\Windows\System32\drivers\etc\hosts) (Erkennungsursprung: Lokaler Computer) (Erkennungstype: Konkret) (Erkennungsquelle: System) (Benutzer: NT-AUTORITÄT\SYSTEM) (Prozessname: Unknown) (Sicherheitsversion: AV: 1.455.252.0, AS: 1.455.252.0, NIS: 1.455.252.0) (Modulversion: AM: 1.1.26060.3008, NIS: 1.1.26060.3008)
TimeCreated : 21.07.2026 14:04:20
(Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.) (Weitere Informationen:) (https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threati) (d=14994&enterprise=0) (Name: SettingsModifier:Win32/PossibleHostsFileHijack) (ID: 14994) (Schweregrad: Mittel) (Kategorie: Einstellungsveränderer) (Pfad: file:_C:\Windows\System32\drivers\etc\hosts) (Erkennungsursprung: Lokaler Computer) (Erkennungstype: Konkret) (Erkennungsquelle: System) (Benutzer: NT-AUTORITÄT\SYSTEM) (Prozessname: Unknown) (Sicherheitsversion: AV: 1.455.249.0, AS: 1.455.249.0, NIS: 1.455.249.0) (Modulversion: AM: 1.1.26060.3008, NIS: 1.1.26060.3008)
CodeIntegrity:
===============
Date: 2026-08-04 16:59:02
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: INSYDE Corp. CB1D_FV106 08/25/2021
Motherboard: AZW SEi
Processor: Intel(R) Core(TM) i5-8279U CPU @ 2.40GHz
Percentage of memory in use: 50%
Total physical RAM: 16225.93 MB
Available physical RAM: 8055.62 MB
Total Virtual: 17249.93 MB
Available Virtual: 8834.16 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:149.75 GB) (Free:56.41 GB) (Model: KINGSTON OM8PDP3512B-A01) NTFS
Drive d: () (Fixed) (Total:325.94 GB) (Free:205.46 GB) (Model: KINGSTON OM8PDP3512B-A01) NTFS
Drive e: (VOLUME) (Fixed) (Total:0 GB) (Free:0 GB) (Model: KINGSTON OM8PDP3512B-A01) FAT
Drive j: (Musik1) (Fixed) (Total:3725.9 GB) (Free:1243.09 GB) (Model: TOSHIBA EXTERNAL_USB USB Device) NTFS
Drive k: (Volume) (Fixed) (Total:3010.67 GB) (Free:1840.03 GB) (Model: TOSHIBA EXTERNAL_USB USB Device) NTFS
Drive l: (Volume) (Fixed) (Total:715.34 GB) (Free:361.78 GB) (Model: TOSHIBA EXTERNAL_USB USB Device) NTFS
\\?\Volume{62c94196-794a-403b-8a01-6e424d41a339}\ () (Fixed) (Total:1.02 GB) (Free:0.08 GB) NTFS
\\?\Volume{71483c23-053b-4b20-9236-d7c7e2f0ad0a}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: BF8D40C0)
Partition: GPT.
==========================================================
Disk: 1 (Size: 3726 GB) (Disk ID: 4E95CC91)
Partition: GPT.
==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 3726 GB) (Disk ID: 05FF671D)
Partition: GPT.
==================== End of Addition.txt =======================
Geändert von cosinus (Gestern um 14:31 Uhr) Grund: code tags |
| | #6 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-Start Störende, veraltete oder unnötige Programme deinstallieren Bitte über Programme und Features (appwiz.cpl) deinstallieren:
__________________ --> Langsamer WIN-Start |
| | #7 |
| | Langsamer WIN-Start Danke! Alle 5 Programme ohne Probleme deinstalliert. Startverhalten unverändert. Mir ist aufgefallen, dass sich 2 Versionen von Powershell auf meinem Rechner befinden: C:\Program Files\PowerShell\7\pwsh.exe" (Version 7.6.4.500) C:\Program Files\WindowsPowerShell> (Version 7.6.3.500) Beide funktionieren. In der Systemsteuerung/Programme ist nur ein Eintrag (Version wird nicht angezeigt) aufgeführt, so dass ich nicht weiß, ob ich die alte oder neue Version deinstallieren würde. |
| | #8 | |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-StartZitat:
adwCleaner Führe AdwCleaner gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei in CODE-Tags. adwcleaner zwecks Kontrolle bitte wiederholen, falls es Funde gab.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #9 |
| | Langsamer WIN-Start Der Hinweis auf das unveränderte Startverhalten war nicht als Kritik gemeint, sondern lediglich als sachliche Info. Tut mir leid, wenn das anders angekommen ist. Hier die logs von adwCleaner: Code:
ATTFilter # -------------------------------
# Malwarebytes AdwCleaner 8.8.1.639
# -------------------------------
# Build: 05-13-2026
# Database: 2026-05-07.3 (Cloud)
# Support: https://help.malwarebytes.com/
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 08-05-2026
# Duration: 00:00:01
# OS: Windows 11 (Build 26200.8973)
# Cleaned: 7
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Users\goofy\AppData\Roaming\IObit\Advanced SystemCare
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2233 octets] - [05/08/2026 22:09:59]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Code:
ATTFilter # -------------------------------
# Malwarebytes AdwCleaner 8.8.1.639
# -------------------------------
# Build: 05-13-2026
# Database: 2026-05-07.3 (Cloud)
# Support: https://help.malwarebytes.com/
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 08-05-2026
# Duration: 00:00:10
# OS: Windows 11 (Build 26200.8973)
# Scanned: 32079
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
|
| | #10 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-Start Meine Information war auch nur prophylaktisch gemeint ![]() adwCleaner hat jedenfalls erstaunlich wenig gefunden. Bitte neue FRST-Logs.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #11 |
| | Langsamer WIN-StartFRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 05-08-2026
durchgeführt von goofy (Administrator) auf DESKTOP-P4QE8KD (AZW SEi) (06-08-2026 09:47:29)
Gestartet von C:\Users\goofy\Downloads\FRST\FRST64 (08).exe
Geladene Profile: goofy & WsiAccount & Administrator
Plattform: Microsoft Windows 11 Pro Version 25H2 26200.8973 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(explorer.exe ->) () [Datei ist nicht signiert] C:\Program Files\Rainlendar2\Rainlendar2.exe
(explorer.exe ->) (Florian Heidenreich -> Florian Heidenreich) C:\Program Files\Mp3tag\Mp3tag.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2605.29.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(explorer.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe <5>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13>
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_733999112d65c1dd\Intel_PIE_Service.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
(services.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.151.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Tweaking LLC -> Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
konnte nicht auf den Prozess zugreifen -> vmmemCmZygote
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
HKLM\...\Policies\Explorer: [NoThumbnailCache] 0
HKLM\...\Policies\Explorer: [DisableThumbnailCache] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Microsoft\MRT: Beschränkung <==== ACHTUNG
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 <==== ACHTUNG
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [AllowDomainPINLogon] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26530552 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe [4232192 2025-11-21] () [Datei ist nicht signiert]
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [DisableThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\MountPoints2: {c5285fd3-bc9f-11ec-ba8c-3887d5b84f9c} - "F:\setup.exe"
HKU\S-1-5-21-2474616372-3844271695-3557059434-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
IFEO\CompatTelRunner.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\DeviceCensus.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\eucloneserver.exe: [GlobalFlag]
GroupPolicy: Beschränkung ? <==== ACHTUNG
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {65871B34-40DD-4B84-9B4C-36481909297B} - System32\Tasks\CleanGenius => C:\Program Files\EaseUS\EaseUS Partition Master\ECG\CleanGeniusEPM.exe [726488 2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> )
Task: {B2E7DFB7-644F-4ED2-B89D-54B903BED13E} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {6449ACB8-AB62-489A-B6E5-1B87E8967CDF} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {A740AD63-A7E9-4A87-AED2-F32F9FDB518B} - System32\Tasks\IObit SUM2026Sale (One-time) => "C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\sum26.exe" -> C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\\/rpop <==== ACHTUNG
Task: {D39270E8-21C6-4912-9B28-25CC92DED2EC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\CodecTweakTool.exe [2401792 2026-07-20] () [Datei ist nicht signiert]
Task: {FE7BAC05-0FC3-4442-8EC1-BE1FD4B65043} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1DAD7236-7EB3-470C-A338-44579225A44A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {A07F1BC3-4949-4722-9792-F7A0A8F10184} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {158D0912-1DAB-4FA8-86E2-BEC17B49639C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {4FD9E461-DE91-4FD9-A266-006255F58111} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [188184 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {6B60C455-FDB2-4660-B9F2-FCFA0892EFB1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2474616372-3844271695-3557059434-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-29] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {9709E63F-D713-40D9-B8D1-1A6EF83B3042} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-29] (Mozilla Corporation -> Mozilla Foundation)
Task: {051BE515-FB31-4F7E-80C0-9BC944141BD2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (Keine Datei)
Task: {7173B6DA-C062-4B89-BA20-58E8CA884001} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Keine Datei)
Task: {DB8AD0FE-07AF-4BFB-98DF-03934344A48F} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [220816 2019-09-30] (Tweaking LLC -> Tweaking.com)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Winsock: Catalog5 02 %SystemRoot%\system32\pnrpnsp.dll => Keine Datei
Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => Keine Datei
Winsock: Catalog5-x64 02 %SystemRoot%\system32\pnrpnsp.dll => Keine Datei
Winsock: Catalog5-x64 03 %SystemRoot%\system32\pnrpnsp.dll => Keine Datei
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpDomain] fritz.box
HKLM\System\...\Parameters\PersistentRoutes: [104.82.14.146,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.82.22.249,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.87.88.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.89.242.39,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [11.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.18.11,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.3.128,255.255.255.255,0.0.0.0,1]
PersistentRoutes: Da befinden sich 1086 PersistentRoutes.
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: hu4eol42.default-release -> 1A202D4B41E895FC
FF DefaultProfile: 3syath58.default-release-1783881393319 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release [2026-08-05]
FF Extension: (uBlock Origin) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-07-09]
FF Extension: (NoScript) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2026-07-21] [UpdateUrl:hxxps://dist.torproject.org/torbrowser/noscript/update-stable.json]
FF Extension: (Mullvad Browser Extension) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{d19a89b9-76c1-4a61-bcd4-49e8de916403}.xpi [2026-04-17] [UpdateUrl:hxxps://cdn.mullvad.net/browser-extension/updates.json]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default [2026-02-13]
FF user.js: detected! => C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default\user.js [2025-12-01]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 [2026-08-06]
FF Homepage: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> web.de
FF NewTabOverride: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> Enabled: mailcheck@web.de
FF Extension: (WEB.DE MailCheck) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\mailcheck@web.de.xpi [2026-07-14] [UpdateUrl:hxxps://dl.gmx.com/mailcheck/firefox/updates.json]
FF Extension: (New Tab) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\newtab@mozilla.org.xpi [2026-07-18]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2026-07-18]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-22] (VideoLAN) [Datei ist nicht signiert]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=3 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=9 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [Keine Datei]
Edge:
=======
Edge Profile: C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-31]
Edge Extension: (Google Docs Offline) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-26]
Edge Extension: (Edge relevant text changes) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-07-26]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [144784 2018-04-18] (Canon Inc. -> CANON INC.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14056848 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460992 2025-04-18] (Canon Inc. -> )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
S4 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 PCManager Service Store; C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe [162104 2026-06-17] (Microsoft Corporation -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\System32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S3 Browser; %SystemRoot%\System32\browser.dll (Keine Datei)
S3 MozillaVPNBroker; "C:\Program Files\Mozilla\Mozilla VPN\Mozilla VPN.exe" windowsdaemon (Keine Datei)
S3 MozillaVPNProxy; "C:\Program Files\Mozilla\Mozilla VPN\socksproxy.exe" -p 8123 -s (Keine Datei)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 Ahflt; C:\WINDOWS\System32\drivers\ahflt.sys [49552 2023-08-30] (Microsoft Corporation -> Microsoft Corporation)
R3 bhtsdhubdr; C:\WINDOWS\System32\drivers\bhtsdhubdr.sys [202456 2020-10-20] (BayHub Technology Inc. -> BayHubTech)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ebrntdrv; C:\WINDOWS\system32\ebrntdrv.sys [57512 2025-12-25] (CHENGDU YIWO Tech Development Co., Ltd. -> )
S3 epmdkdrv; C:\WINDOWS\system32\epmdkdrv.sys [57512 2025-05-26] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R0 EPMVolFl; C:\WINDOWS\System32\drivers\EPMVolFl.sys [30136 2022-12-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider)
S3 eprdtdrv; C:\WINDOWS\system32\eprdtdrv.sys [27728 2025-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 ESAuDriver; C:\WINDOWS\System32\drivers\ESAuDriver.sys [223208 2024-07-16] (苏州顺芯半导体有限公司 -> Everest Semiconducor Co., Ltd)
R1 ESProtectionDriver; \??\C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-07-24] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 EUDCPEPM; C:\WINDOWS\System32\drivers\EUDCPEPM.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EUDCPEPM0; \??\C:\WINDOWS\system32\drivers\EUDCPEPM0.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 EUEDKEPM; C:\WINDOWS\System32\drivers\EUEDKEPM.sys [24656 2026-01-12] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EuMrx; C:\WINDOWS\System32\DRIVERS\EuMrx.sys [215704 2025-09-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Win 7 DDK provider)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [230888 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 GSCAuxDriver; C:\WINDOWS\System32\DriverStore\FileRepository\gscauxdriver.inf_amd64_fe9355c6b52fb409\GSCAuxDriverx64.sys [71424 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSCx64; C:\WINDOWS\System32\DriverStore\FileRepository\gscheci.inf_amd64_e0a6bd87d5543f55\TeeDriverGSCW8x64.sys [243992 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSDriver; C:\WINDOWS\System32\drivers\GSDriver64.sys [55488 2022-09-01] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 iaLPSS2_UART2_SYSTEM; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2.inf_amd64_fd889dfbe795f97b\iaLPSS2_UART2.sys [406488 2026-01-18] (Intel Corporation -> Intel Corporation)
R3 IntcSST; C:\WINDOWS\System32\drivers\IntcSST.sys [697728 2025-11-26] (Smart Sound Technology -> Intel(R) Corporation)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-27] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144880 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-07-24] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt11.sys [216680 2026-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-08-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; \??\C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-08-06] (Malwarebytes Inc -> )
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_05602848cd0003d3\rt68cx21x64.sys [941608 2026-07-07] (Realtek Semiconductor Corp. -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 vkrnlintvsc; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsc.inf_amd64_ae7c1fb85fc0224e\vkrnlintvsc.sys [79168 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
R3 vkrnlintvsp; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsp.inf_amd64_249e734e16ab4232\vkrnlintvsp.sys [87504 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-13] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [283016 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-11-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
U4 DiagTrack; kein ImagePath
U4 dmwappushsvc; kein ImagePath
S3 EuGdiDrv; \SystemRoot\system32\EuGdiDrv.sys (Keine Datei)
S4 IUFileFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys (Keine Datei)
S3 IUProcessFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys (Keine Datei)
S3 IURegistryFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys (Keine Datei)
S2 MozillaVPNSplitTunnel; \??\C:\Program Files\Mozilla\Mozilla VPN\mullvad-split-tunnel.sys (Keine Datei)
S3 usbscan; \SystemRoot\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\usbscan.sys (Keine Datei)
==================== SvcHost (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-08-06 09:29 - 2026-08-06 09:29 - 000337501 ____T C:\Users\goofy\test_trace.txt
2026-08-06 09:29 - 2026-08-06 09:29 - 000000171 ____T C:\Users\goofy\test_step1.txt
2026-08-06 08:07 - 2026-08-06 08:07 - 000730438 _____ C:\WINDOWS\system32\perfh007.dat
2026-08-06 08:07 - 2026-08-06 08:07 - 000153232 _____ C:\WINDOWS\system32\perfc007.dat
2026-08-06 08:03 - 2026-08-06 08:03 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-08-05 22:09 - 2026-08-05 22:09 - 009630992 _____ (Malwarebytes) C:\Users\goofy\Downloads\adwcleaner.exe
2026-08-05 21:38 - 2026-08-05 21:38 - 000000000 ____D C:\Users\goofy\Downloads\Ville de Sarralbe - Uploads from Ville de Sarralbe
2026-08-05 21:23 - 2026-08-05 21:23 - 008610419 _____ C:\Users\goofy\Downloads\2026-08-06_Regionalverband_Saarbruecken_-_06-08-2026.pdf
2026-08-05 17:08 - 2026-08-05 17:08 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2026-08-05 10:47 - 2026-08-06 09:41 - 000000000 ____D C:\Users\goofy\Downloads\Neuer Ordner
2026-08-05 09:27 - 2026-08-05 09:27 - 000000000 ____D C:\Users\goofy\AppData\Roaming\MPC-HC
2026-08-04 19:07 - 2026-08-04 19:07 - 000001505 _____ C:\Users\goofy\Desktop\Bedarf (slow reduction).txt
2026-08-04 19:07 - 2026-08-04 19:07 - 000001160 _____ C:\Users\goofy\Desktop\Wenn Sie Ihren Computer wirklich ko.txt
2026-08-04 19:07 - 2026-08-04 19:07 - 000000324 _____ C:\Users\goofy\Desktop\GoldHändler.txt
2026-08-04 19:06 - 2026-08-04 19:06 - 000003631 _____ C:\Users\goofy\Desktop\Tropfentest.txt
2026-08-04 19:06 - 2026-08-04 19:06 - 000000788 _____ C:\Users\goofy\Desktop\Das modernere Werkzeug im Vergleich.txt
2026-08-04 19:06 - 2026-08-04 19:06 - 000000729 _____ C:\Users\goofy\Desktop\Windows-Suche.txt
2026-08-04 19:06 - 2026-08-04 19:06 - 000000388 _____ C:\Users\goofy\Desktop\Um Edge vollständig aus Autostart.txt
2026-08-04 19:06 - 2026-08-04 19:06 - 000000016 _____ C:\Users\goofy\Desktop\Y815544687GDE4M2.txt
2026-08-04 19:05 - 2026-08-04 19:05 - 000000578 _____ C:\Users\goofy\Desktop\Gudrun Kilburg geb. Niederländ.txt
2026-08-04 19:05 - 2026-08-04 19:05 - 000000197 _____ C:\Users\goofy\Desktop\Novalgin-Warnsignale.txt
2026-08-04 19:04 - 2026-08-04 19:04 - 000000507 _____ C:\Users\goofy\Desktop\10 positive Sätze, die dein Kind ei.txt
2026-08-04 18:59 - 2026-08-04 18:59 - 000001104 _____ C:\Users\goofy\Desktop\Bolognese-Rezept.txt
2026-08-04 18:58 - 2026-08-04 18:58 - 000000174 _____ C:\Users\goofy\Desktop\Ökotest 08.2026, Seite 27.txt
2026-08-04 18:53 - 2026-08-04 18:53 - 000083281 _____ C:\Users\goofy\Desktop\Users shortcut scan result (x64).txt
2026-08-04 17:34 - 2026-08-06 09:47 - 000000000 ____D C:\FRST
2026-08-04 17:32 - 2026-08-04 17:32 - 000000784 _____ C:\Users\goofy\Desktop\FRST.txt
2026-08-04 14:28 - 2026-08-04 14:28 - 000003322 _____ C:\WINDOWS\system32\Tasks\klcp_update
2026-08-04 14:28 - 2019-12-28 12:00 - 000784384 _____ C:\WINDOWS\system32\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000681984 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000310784 _____ C:\WINDOWS\system32\xvidvfw.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000284160 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003850240 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003799552 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2026-08-04 14:28 - 2012-07-21 13:55 - 000180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2026-08-04 14:28 - 2012-07-21 13:54 - 000122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2026-08-04 14:28 - 2011-12-07 20:37 - 000148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2026-08-04 14:28 - 2011-12-07 20:32 - 000216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2026-08-02 22:22 - 2026-08-02 22:22 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2026-08-02 22:22 - 2026-08-02 22:22 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2026-08-01 23:02 - 2026-08-05 17:08 - 000344624 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-07-30 07:26 - 2026-08-05 16:57 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-07-28 08:48 - 2026-07-28 08:48 - 000132424 _____ C:\Users\goofy\Downloads\Account Statement FDA_124_114_752_806 - 2026-02-06 - 2026-07-28.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000149064 _____ C:\Users\goofy\Downloads\5187303_2026_Nr.006_Kontoauszug_vom_2026.07.01_20260728084308515.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000118245 _____ C:\Users\goofy\Downloads\5187303_2026_Rechnungsabschluss_Geduldete Überziehung_vom_2026.07.01_20260728084320936.pdf
2026-07-26 13:51 - 2026-07-26 13:51 - 000000000 ____D C:\Users\goofy\AppData\Local\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-07-26 13:45 - 000000758 _____ C:\Users\Public\Desktop\Steuer 2025.lnk
2026-07-26 13:45 - 2026-07-26 13:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2025
2026-07-26 13:27 - 2026-07-26 13:27 - 547540784 _____ C:\Users\goofy\Downloads\Steuer2025.exe
2026-07-26 07:01 - 2026-07-26 07:01 - 000003378 _____ C:\WINDOWS\system32\Tasks\IObit SUM2026Sale (One-time)
2026-07-25 09:05 - 2026-07-25 09:05 - 058118520 _____ (Tweaking.com) C:\Users\goofy\Downloads\tweaking.com_windows_repair_aio_setup.exe
2026-07-25 08:51 - 2026-07-25 08:51 - 000003782 _____ C:\WINDOWS\system32\Tasks\Tweaking.com - Windows Repair Tray Icon
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2026-07-24 20:54 - 2026-08-06 09:44 - 000000000 ____D C:\Users\goofy\Downloads\FRST
2026-07-24 13:27 - 2026-07-24 14:21 - 000000000 ____D C:\Program Files (x86)\iTop Data Recovery
2026-07-24 13:27 - 2026-07-24 13:27 - 000000000 ____D C:\ProgramData\iTop
2026-07-24 13:25 - 2026-07-24 13:25 - 033257536 _____ (IObit ) C:\Users\goofy\Downloads\iobituninstaller.exe
2026-07-24 12:53 - 2026-07-24 12:53 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\MMC
2026-07-24 12:45 - 2026-07-24 12:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\Malwarebytes
2026-07-24 12:45 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Sentry
2026-07-24 09:38 - 2026-08-06 08:08 - 000000000 ____D C:\Users\goofy\AppData\Local\Malwarebytes
2026-07-24 09:38 - 2026-07-24 09:38 - 000002105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-24 09:37 - 2026-07-24 09:37 - 002862824 _____ (Malwarebytes) C:\Users\goofy\Downloads\MBSetup-8.8.exe
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\Packages
2026-07-24 08:50 - 2026-07-24 08:50 - 000000020 ___SH C:\Users\WsiAccount\ntuser.ini
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Vorlagen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Startmenü
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Netzwerkumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Lokale Einstellungen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Eigene Dateien
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Druckumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Videos
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Musik
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Bilder
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Verlauf
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\SystemCertificates
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Protect
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Crypto
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Credentials
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Vault
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Spelling
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\LocalLow\Intel
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\VirtualStore
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\D3DSCache
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\ConnectedDevicesPlatform
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount
2026-07-24 08:50 - 2026-02-12 20:54 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Network
2026-07-24 08:50 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\WsiAccount\OneDrive
2026-07-23 23:18 - 2026-07-23 23:18 - 000000000 ____D C:\Users\Administrator\AppData\Local\PeerDistRepub
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Everything
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\Everything
2026-07-23 22:36 - 2026-07-23 22:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2026-07-23 22:06 - 2026-07-23 22:07 - 000000000 ____D C:\Users\Administrator\Desktop\Neuer Ordner
2026-07-23 22:06 - 2026-07-23 22:06 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003586 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000002419 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Obsidium x64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\.obs64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\TeraCopy
2026-07-23 22:05 - 2026-07-23 22:20 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers
2026-07-23 22:05 - 2026-07-23 22:05 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2026-07-23 22:04 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Spelling
2026-07-23 22:04 - 2026-07-23 22:11 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache
2026-07-23 22:04 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator
2026-07-23 22:04 - 2026-07-23 22:04 - 000002346 _____ C:\Users\Administrator\Desktop\Microsoft Edge.lnk
2026-07-23 22:04 - 2026-07-23 22:04 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Vorlagen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Startmenü
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Eigene Dateien
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Druckumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Videos
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Protect
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Crypto
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Vault
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Intel
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2026-07-23 22:04 - 2026-02-12 20:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Network
2026-07-23 22:04 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\Administrator\OneDrive
2026-07-22 08:09 - 2026-07-29 14:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\Program Files\PowerShell
2026-07-18 09:53 - 2026-07-18 09:53 - 000056366 _____ C:\Users\goofy\Downloads\ernaehrungstagebuch102.pdf
2026-07-16 10:43 - 2026-07-25 09:25 - 000000000 ____D C:\Program Files\TeraCopy
2026-07-16 10:43 - 2026-07-16 11:04 - 000000000 ____D C:\Users\goofy\AppData\Roaming\TeraCopy
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\AppData\Roaming\Obsidium x64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\.obs64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Code Sector
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Caphyon
2026-07-14 08:57 - 2026-07-14 08:57 - 000000000 ____D C:\Program Files\Microsoft Office 15
2026-07-13 22:12 - 2026-07-25 08:52 - 000010055 _____ C:\WINDOWS\system32\InstallMonitorLog.csv
2026-07-13 17:29 - 2026-07-23 22:10 - 000000000 ____D C:\WINDOWS\Panther
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagwrn.xml
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagerr.xml
2026-07-12 23:18 - 2026-07-16 17:24 - 000000000 ____D C:\Users\goofy\AppData\Local\PlaceholderTileLogoFolder
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ___SD C:\WINDOWS\system32\containers
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ____D C:\WINDOWS\system32\HvsiSettingsProviders
2026-07-11 10:46 - 2026-05-16 00:09 - 036362808 _____ C:\Users\goofy\Desktop\FRITZBOX - Tricks und Tipps Mai 2026.pdf
2026-07-09 12:10 - 2026-07-09 12:10 - 000000416 _____ C:\WINDOWS\BRWMARK.INI
2026-07-09 12:10 - 2026-07-09 12:10 - 000000034 _____ C:\WINDOWS\SysWOW64\BD5240.DAT
2026-07-09 10:02 - 2026-07-09 10:03 - 000000000 ____D C:\Users\goofy\Downloads\PVS
2026-07-07 09:02 - 2026-07-07 09:02 - 000002620 _____ C:\Users\goofy\Desktop\Raisin-Empfängerprüfung.txt
2026-07-07 08:53 - 2026-07-07 08:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-08-06 09:40 - 2025-12-24 20:47 - 000000000 ____D C:\Users\goofy\AppData\Roaming\vlc
2026-08-06 09:37 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-08-06 09:36 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-08-06 09:33 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-08-06 09:29 - 2026-02-12 20:13 - 000000000 ____D C:\Users\goofy
2026-08-06 09:29 - 2025-11-30 12:03 - 000164673 _____ C:\Users\goofy\test.dat
2026-08-06 09:29 - 2025-11-30 12:02 - 000005397 _____ C:\Users\goofy\test.ini
2026-08-06 09:29 - 2023-09-17 10:49 - 000000000 ____D C:\Users\goofy\Desktop\YSD
2026-08-06 08:07 - 2026-02-12 20:56 - 001724020 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-08-06 08:07 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-08-06 08:03 - 2026-02-22 11:29 - 000012288 ___SH C:\DumpStack.log.tmp
2026-08-06 08:03 - 2026-02-12 20:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-08-06 08:03 - 2025-11-25 19:01 - 000143664 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-08-06 08:03 - 2023-02-05 18:26 - 000000000 ____D C:\Users\goofy\.rainlendar2
2026-08-05 22:58 - 2026-01-14 12:03 - 000000000 ____D C:\Users\goofy\AppData\Local\Everything
2026-08-05 22:58 - 2026-01-14 11:15 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Everything
2026-08-05 22:58 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-08-05 22:11 - 2025-11-26 22:53 - 000000000 ____D C:\Users\goofy\AppData\Roaming\IObit
2026-08-05 22:02 - 2025-11-26 18:04 - 000000000 ____D C:\Users\goofy\AppData\Local\JDownloader 2
2026-08-05 21:53 - 2026-01-24 11:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Mp3tag
2026-08-05 17:25 - 2026-02-12 20:35 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2026-08-05 16:58 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-08-05 16:37 - 2025-11-26 22:54 - 000000000 ____D C:\Program Files (x86)\IObit
2026-08-05 16:34 - 2025-11-27 10:02 - 000000000 ____D C:\Program Files (x86)\Wise
2026-08-05 16:33 - 2025-11-26 22:53 - 000001008 _____ C:\ProgramData\pdinst.ini
2026-08-05 16:31 - 2025-12-25 13:19 - 000000000 ____D C:\Program Files (x86)\Ashampoo
2026-08-05 16:31 - 2025-11-26 22:54 - 000000000 ____D C:\ProgramData\ProductData3
2026-08-05 15:11 - 2025-11-26 19:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\YouTubeSongDownloader
2026-08-05 15:11 - 2025-11-26 10:44 - 000001334 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2026-08-05 12:44 - 2025-11-25 19:14 - 000000000 ____D C:\Users\goofy\AppData\Local\Packages
2026-08-05 10:28 - 2026-02-12 19:53 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2026-08-04 19:08 - 2025-09-20 16:50 - 000000958 _____ C:\Users\goofy\Desktop\pornvideos.txt
2026-08-04 19:07 - 2026-04-01 13:00 - 000000134 _____ C:\Users\goofy\Desktop\fakemail.txt
2026-08-04 19:07 - 2025-09-02 17:07 - 000000399 _____ C:\Users\goofy\Desktop\Telefonnummern.txt
2026-08-04 19:06 - 2026-05-06 13:11 - 000000676 _____ C:\Users\goofy\Desktop\Ladekabel.txt
2026-08-04 19:06 - 2025-11-11 23:39 - 000003457 _____ C:\Users\goofy\Desktop\winget upgrade.txt
2026-08-04 19:00 - 2025-11-25 20:14 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Excel
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic
2026-08-04 11:12 - 2022-11-28 22:53 - 000000000 ____D C:\Users\goofy\.cache
2026-08-02 22:50 - 2026-04-17 11:41 - 000000000 ____D C:\Users\goofy\AppData\Local\deno
2026-08-02 22:50 - 2026-03-01 15:52 - 000000000 ____D C:\Users\goofy\AppData\Local\D3DSCache
2026-08-02 22:22 - 2025-12-07 14:05 - 000001398 _____ C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2026-08-02 08:23 - 2026-01-17 19:51 - 000000000 ____D C:\Users\goofy\AppData\Local\CrashDumps
2026-07-31 14:39 - 2026-02-12 20:54 - 000003742 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-31 14:39 - 2026-02-12 20:54 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-31 10:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2026-07-30 14:16 - 2025-10-20 11:38 - 000000000 ____D C:\Users\goofy\Desktop\Steuer
2026-07-29 14:20 - 2025-11-25 22:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-07-29 14:16 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\DiagTrack
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-07-29 14:16 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-07-29 13:26 - 2026-02-12 20:46 - 003375104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-07-29 08:14 - 2025-11-25 19:01 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-29 08:11 - 2025-11-25 22:37 - 000001071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 15:30 - 2024-03-08 23:04 - 000000000 ____D C:\Users\goofy\Desktop\Kontoauszüge
2026-07-26 13:48 - 2026-01-10 13:30 - 000000000 ____D C:\ProgramData\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-01-10 13:56 - 000000000 ____D C:\Program Files\Steuer 2025
2026-07-25 09:28 - 2022-04-14 03:14 - 000000000 ____D C:\WINDOWS\CSC
2026-07-25 09:24 - 2026-01-24 11:03 - 000000000 ____D C:\Program Files\Mp3tag
2026-07-25 09:12 - 2025-12-21 20:16 - 001729632 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2026-07-24 09:38 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-07-24 09:15 - 2023-02-06 16:17 - 000000000 ____D C:\Users\goofy\Desktop\Text-Dateien
2026-07-24 08:50 - 2026-03-05 09:03 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-07-23 22:20 - 2020-11-19 09:48 - 000000000 ____D C:\ProgramData\Packages
2026-07-23 22:15 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Registration
2026-07-23 22:04 - 2020-11-19 09:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2026-07-23 21:23 - 2026-04-29 11:55 - 000001292 _____ C:\Users\goofy\Desktop\ESET Online Scanner.lnk
2026-07-20 08:28 - 2025-12-07 19:52 - 002318240 _____ C:\Users\goofy\Desktop\Hochzeit Klaus2.jpeg
2026-07-19 17:38 - 2025-01-20 12:46 - 000000004 _____ C:\Users\goofy\Desktop\1990.txt
2026-07-17 15:31 - 2025-11-25 22:11 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-16 17:21 - 2025-12-14 11:21 - 000000000 ____D C:\WINDOWS\pss
2026-07-15 17:35 - 2024-04-01 18:36 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-07-15 17:35 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-07-15 15:04 - 2025-11-26 23:05 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-15 15:03 - 2025-11-26 23:05 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-15 14:36 - 2025-11-26 11:06 - 000000000 ____D C:\ProgramData\Package Cache
2026-07-15 14:35 - 2026-02-14 10:54 - 000000000 ____D C:\Program Files\dotnet
2026-07-14 18:56 - 2025-11-25 20:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Word
2026-07-13 17:42 - 2020-11-19 09:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-07-13 13:37 - 2026-02-11 20:06 - 000499195 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_708
2026-07-12 20:36 - 2026-02-12 20:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-12 20:36 - 2025-11-25 22:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-11 15:25 - 2025-11-26 19:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Signal
2026-07-10 10:43 - 2023-03-29 21:51 - 000000000 ____D C:\Users\goofy\Desktop\Restaurants, Cafés
2026-07-09 17:13 - 2025-11-11 14:23 - 000000011 _____ C:\Users\goofy\Desktop\a.txt
2026-07-09 11:49 - 2025-11-25 21:57 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\MMC
2026-07-07 16:37 - 2025-11-26 17:40 - 000000000 ____D C:\Program Files\7-Zip
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2022-10-06 13:03 - 2023-10-07 12:55 - 000000076 _____ () C:\Users\goofy\123.dat
2024-04-21 19:41 - 2025-11-25 10:14 - 000067918 _____ () C:\Users\goofy\bestof.dat
2025-11-11 18:10 - 2025-11-11 18:10 - 007300408 _____ (Microsoft Corporation) C:\Users\goofy\setup.exe
2025-11-12 20:13 - 2023-11-01 15:44 - 000000049 _____ () C:\Users\goofy\start.bat
2025-11-30 12:03 - 2026-08-06 09:29 - 000164673 _____ () C:\Users\goofy\test.dat
2025-11-25 20:08 - 2023-11-01 15:44 - 000000049 _____ () C:\Program Files\start.bat
2026-06-26 17:22 - 2026-06-26 17:22 - 000000059 _____ () C:\Users\goofy\AppData\Roaming\epm_user.ini
2025-12-05 19:53 - 2025-12-05 19:57 - 000097808 _____ () C:\Users\goofy\AppData\Local\dxdiag.log
2026-06-09 20:58 - 2026-06-09 20:58 - 000102541 _____ () C:\Users\goofy\AppData\Local\mozillavpn.log
2025-12-14 11:23 - 2025-12-14 11:23 - 000007629 _____ () C:\Users\goofy\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ========================
|
| | #12 |
| | Langsamer WIN-StartCode:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 05-08-2026
durchgeführt von goofy (06-08-2026 09:58:58)
Gestartet von C:\Users\goofy\Downloads\FRST
Start-Modus: Normal
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
Shortcut: C:\Users\Administrator\Links\Desktop.lnk -> C:\Users\goofy\Desktop ()
Shortcut: C:\Users\Administrator\Links\Downloads.lnk -> C:\Users\goofy\Downloads ()
Shortcut: C:\Users\Administrator\Desktop\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\goofy\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Keine Datei)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Q-Dir.lnk -> C:\Program Files\Q-Dir\Q-Dir.exe (Nenad Hrg (SoftwareOK.com))
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Everything.lnk -> C:\Program Files\Everything\Everything.exe (voidtools)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Privater Modus.lnk -> C:\Program Files\Mozilla Firefox\private_browsing.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe (Malwarebytes)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetSkat.lnk -> C:\Windows\Installer\{3BA463F1-3B1E-44E1-BBB7-AEB7070CD48E}\_E48AE1C817CF814BCC1F1B.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk -> C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk -> C:\Program Files\Microsoft Office\root\Office16\lync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Sandbox.lnk -> C:\Windows\System32\WindowsSandbox.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSetView.lnk -> C:\Program Files (x86)\WinSetView\WinSetView.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Song Downloader\YouTube Song Downloader.lnk -> C:\Program Files (x86)\YouTube Song Downloader\YouTube Song Downloader.exe (Abelssoft)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\Changelog.lnk -> C:\Program Files (x86)\wxMP3gain\Changelog.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\License.lnk -> C:\Program Files (x86)\wxMP3gain\License.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\Readme.lnk -> C:\Program Files (x86)\wxMP3gain\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\wxMP3gain entfernen.lnk -> C:\Program Files (x86)\wxMP3gain\unins000.exe (Cristiano Fraga G. Nunes )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\wxMP3gain.lnk -> C:\Program Files (x86)\wxMP3gain\wxmp3gain.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winxvideo AI\Deinstallieren Winxvideo AI.lnk -> C:\Program Files (x86)\Digiarty\Winxvideo AI\uninst.exe (Digiarty, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winxvideo AI\Winxvideo AI.lnk -> C:\Program Files (x86)\Digiarty\Winxvideo AI\Winxvideo AI.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows Performance Toolkit\GPUView.lnk -> C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\gpuview\GPUView.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows Performance Toolkit\Windows Performance Analyzer.lnk -> C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\wpa.exe (wpa)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows Performance Toolkit\Windows Performance Recorder.lnk -> C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\WPRUI.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows ADK\Microsoft Application Virtualization (App-V) Sequencer Tool.lnk -> C:\Program Files (x86)\Windows Kits\10\Microsoft Application Virtualization\Sequencer\Sequencer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows ADK\Microsoft User Experience Virtualization (UE-V) Template Generator.lnk -> C:\Program Files (x86)\Windows Kits\10\Microsoft User Experience Virtualization\Management\Generator.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows ADK\Windows Imaging and Configuration Designer.lnk -> C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Imaging and Configuration Designer\x86\ICD.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows ADK\Windows System Image Manager.lnk -> C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\WSIM\x86\imgmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win11PrivacyFix\Win11PrivacyFix.lnk -> C:\Program Files (x86)\Win11PrivacyFix\AbLauncher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOVSOFT\Text to MP3 Converter\Text to MP3 Converter entfernen.lnk -> C:\Program Files (x86)\VOVSOFT\Text to MP3 Converter\unins000.exe (VOVSOFT )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOVSOFT\Text to MP3 Converter\Text to MP3 Converter.lnk -> C:\Program Files (x86)\VOVSOFT\Text to MP3 Converter\texttomp3.exe (VOVSOFT)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files\VideoLAN\VLC\Documentation.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files\VideoLAN\VLC\NEWS.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files\VideoLAN\VLC\VideoLAN Website.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 9.01\License.lnk -> C:\Program Files\Unknown Device Identifier\License.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 9.01\Read Me.lnk -> C:\Program Files\Unknown Device Identifier\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 9.01\Uninstall.lnk -> C:\Program Files\Unknown Device Identifier\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 9.01\Unknown Device Identifier on the Web.lnk -> C:\Program Files\Unknown Device Identifier\UnknownDeviceIdentifier.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 9.01\Unknown Device Identifier.lnk -> C:\Program Files\Unknown Device Identifier\UnknownDeviceIdentifier.exe (Huntersoft)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Open Windows Repair (WR) Tray Icon.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Registry Backup.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\registry_backup_tool\TweakingRegistryBackup.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Windows Repair.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2025\Steuer 2025.lnk -> C:\Program Files\Steuer 2025\stman2026.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2\Rainlendar2.lnk -> C:\Program Files\Rainlendar2\Rainlendar2.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2\Remove Rainlendar2.lnk -> C:\Program Files\Rainlendar2\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Q-Dir\Q-Dir.lnk -> C:\Program Files\Q-Dir\Q-Dir.exe (Nenad Hrg (SoftwareOK.com))
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag\Mp3tag.lnk -> C:\Program Files\Mp3tag\Mp3tag.exe (Florian Heidenreich)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office-Spracheinstellungen.lnk -> C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Skype for Business-Aufzeichnungs-Manager.lnk -> C:\Program Files\Microsoft Office\root\Office16\OcPubMgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingston SSD Manager x64\Kingston SSD Manager x64.lnk -> C:\Program Files\Kingston_SSD_Manager\KSM_Gen15.exe (Kingston Digital, Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\CodecTweakTool.exe ( )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Media Player Classic.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\mpc-hc64.exe (MPC-HC Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\unins000.exe (KLCP )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext (x64).lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\GraphStudioNext64.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\GraphStudioNext.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\mediainfo.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB\ISO to USB.lnk -> C:\Program Files (x86)\ISO to USB\isotousb.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB\Uninstall ISO to USB.lnk -> C:\Program Files (x86)\ISO to USB\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free ISO Creator\Free ISO Creator.lnk -> C:\Program Files (x86)\Free ISO Creator\FreeISOCreator.exe (Hewlett-Packard)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free ISO Creator\Uninstall Free ISO Creator.lnk -> C:\Program Files (x86)\Free ISO Creator\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis\BLACK WHITE projects 6 professional\BLACK WHITE projects 6 professional (64-Bit).lnk -> C:\Program Files\Franzis\BLACK WHITE projects 6 professional\BLACK WHITE projects 6 professional.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master\EaseUS Partition Master.lnk -> C:\Program Files\EaseUS\EaseUS Partition Master\bin\EPMUI.exe (EaseUS)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard\EaseUS Data Recovery Wizard entfernen.lnk -> C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard\easeus data recovery wizard.lnk -> C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe (CHENGDU YIWO Tech Development Co., Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo\CrystalDiskInfo.lnk -> C:\Program Files\CrystalDiskInfo\DiskInfo64.exe (Crystal Dew World)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chip Bankingbrowser\Chip Bankingbrowser.lnk -> C:\Program Files (x86)\Chip Bankingbrowser\AbLauncher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\IJ Scan Utility\IJ Scan Utility.lnk -> C:\Program Files (x86)\Canon\IJ Scan Utility\SCANUTILITY.exe (CANON INC.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiarty Image Enhancer\Aiarty Image Enhancer.lnk -> C:\Program Files (x86)\Aiarty\ImageEnhancer\Aiarty Image Enhancer.exe (Digiarty)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiarty Image Enhancer\Deinstallieren Aiarty Image Enhancer.lnk -> C:\Program Files (x86)\Aiarty\ImageEnhancer\uninst.exe (Digiarty, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk -> C:\Windows\regedit.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1 (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1 (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1 (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell 5.1.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\Links\Desktop.lnk -> C:\Users\goofy\Desktop ()
Shortcut: C:\Users\goofy\Links\Downloads.lnk -> C:\Users\goofy\Downloads ()
Shortcut: C:\Users\goofy\Desktop\AI Photo Restoration Software for Old Photos.lnk -> C:\Users\goofy\AppData\Roaming\SoftOrbits\AI Photo Restoration Software for Old Photos\PhotoRetoucher.exe ()
Shortcut: C:\Users\goofy\Desktop\Aiarty Output.lnk -> C:\Users\goofy\Aiarty Output ()
Shortcut: C:\Users\goofy\Desktop\ESET Online Scanner.lnk -> C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe (ESET)
Shortcut: C:\Users\goofy\Desktop\iReaShare Android Manager.lnk -> C:\Program Files (x86)\iReaShare\iReaShare Android Manager\1.0.12\Bin\iReaShare Android Manager.exe ()
Shortcut: C:\Users\goofy\Desktop\Mühle 6.0.lnk -> C:\ProgramData\JMMG Communications\Muehle\Muehle.exe (JMMG Communications, Jochen Moschko)
Shortcut: C:\Users\goofy\Desktop\Mullvad Browser\Mullvad Browser.lnk -> C:\Users\goofy\Desktop\Mullvad Browser\Browser\mullvadbrowser.exe (Mullvad VPN AB)
Shortcut: C:\Users\goofy\Desktop\Beenden und Neustart\Papierkorb.lnk -> [LFx@_dP/Nr1SPS0%G`)Papierkorb-Systemordner1SPSjc(=Oe)::{645FF040-5081-101B-9F08-00AA002F954E}]
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk -> C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe (ESET)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mullvad Browser.lnk -> C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\mullvadbrowser.exe (Mullvad VPN AB)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk -> [LFx@_dP/N1SPSU(Ly9K-e)::{645FF040-5081-101B-9F08-00AA002F954E}]
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Signal.lnk -> C:\Users\goofy\AppData\Local\Programs\signal-desktop\Signal.exe (Signal Messenger, LLC)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mühle\Mühle 6.0.lnk -> C:\ProgramData\JMMG Communications\Muehle\Muehle.exe (JMMG Communications, Jochen Moschko)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader 2 Uninstaller.lnk -> C:\Users\goofy\AppData\Local\JDownloader 2\Uninstall JDownloader.exe (AppWork GmbH)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader 2.lnk -> C:\Users\goofy\AppData\Local\JDownloader 2\JDownloader2.exe (AppWork GmbH)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iReaShare\iReaShare Android Manager\iReaShare Android Manager.lnk -> C:\Program Files (x86)\iReaShare\iReaShare Android Manager\1.0.12\Bin\iReaShare Android Manager.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iReaShare\iReaShare Android Manager\Uninstall iReaShare Android Manager.lnk -> C:\Program Files (x86)\iReaShare\iReaShare Android Manager\1.0.12\uninst.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\SendTo\Media Player Classic.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\mpc-hc64.exe (MPC-HC Team)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\SendTo\MediaInfo.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\mediainfo.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\EaseUS Partition Master.lnk -> C:\Program Files\EaseUS\EaseUS Partition Master\bin\EPMUI.exe (EaseUS)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Everything.lnk -> C:\Program Files\Everything\Everything.exe (voidtools)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Q-Dir.lnk -> C:\Program Files\Q-Dir\Q-Dir.exe (Nenad Hrg (SoftwareOK.com))
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chip Bankingbrowser.lnk -> C:\Program Files (x86)\Chip Bankingbrowser\AbLauncher.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Everything.lnk -> C:\Program Files\Everything\Everything.exe (voidtools)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\JDownloader 2.lnk -> C:\Users\goofy\AppData\Local\JDownloader 2\JDownloader2.exe (AppWork GmbH)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MP3Diags.lnk -> D:\MP3 Diags\MP3Diags.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mp3tag.lnk -> C:\Program Files\Mp3tag\Mp3tag.exe (Florian Heidenreich)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mullvad Browser.lnk -> C:\Users\goofy\AppData\Local\Mullvad\MullvadBrowser\Release\mullvadbrowser.exe (Mullvad VPN AB)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\NetSkat.lnk -> C:\Windows\Installer\{3BA463F1-3B1E-44E1-BBB7-AEB7070CD48E}\_E48AE1C817CF814BCC1F1B.exe ()
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PowerShell 7.lnk -> C:\Program Files\WindowsPowerShell\pwsh.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Q-Dir.lnk -> C:\Program Files\Q-Dir\Q-Dir.exe (Nenad Hrg (SoftwareOK.com))
Shortcut: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\wxMP3gain.lnk -> C:\Program Files (x86)\wxMP3gain\wxmp3gain.exe ()
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Steuer 2025.lnk -> C:\Program Files\Steuer 2025\stman2026.exe ()
Shortcut: C:\Users\Public\Desktop\Winxvideo AI.lnk -> C:\Program Files (x86)\Digiarty\Winxvideo AI\Winxvideo AI.exe ()
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk -> C:\Windows\System32\LiveCaptions.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk -> C:\Windows\System32\voiceaccess.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows ADK\Deployment and Imaging Tools Environment.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\DandISetEnv.bat"
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits\Windows Software Development Kit\Windows Software Development Kit.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Windows Kits\10\"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN) -> -Iskins
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Uninstall Tweaking.com - Windows Repair.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\uninstall.exe (Indigo Rose Corporation) -> "/U:C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Uninstall\uninstall.xml"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2\Rainlendar2 Options.lnk -> C:\Program Files\Rainlendar2\Rainlendar2.exe () -> -e Global_ShowOptionsDialog()
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell\PowerShell 7 (x64).lnk -> C:\Program Files\PowerShell\7\pwsh.exe (Microsoft Corporation) -> -WorkingDirectory ~
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk -> C:\Program Files\Microsoft Office\root\Client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Office16\DCF\SPREADSHEETCOMPARE.EXE"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Filters\DirectVobSub64\vsfilter.dll",DirectVobSub
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio (MPC-HC internal).lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\mpc-hc64.exe (MPC-HC Team) -> /configlavaudio
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\LAVFilters64\lavaudio.ax",OpenConfiguration
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter (MPC-HC internal).lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\mpc-hc64.exe (MPC-HC Team) -> /configlavsplitter
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\LAVFilters64\lavsplitter.ax",OpenConfiguration
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video (MPC-HC internal).lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\mpc-hc64.exe (MPC-HC Team) -> /configlavvideo
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\LAVFilters64\lavvideo.ax",OpenConfiguration
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\madVR.lnk -> C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Filters\madVR\madHcCtrl.exe (madshi.net) -> editLocalSettingsDontWait
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\MPC Video Renderer.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\MPC-HC64\MPCVR\MpcVideoRenderer64.ax",OpenConfiguration
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\system32\x264vfw64.dll",Configure
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x86).lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\SysWOW64\x264vfw.dll",Configure
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid VFW.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\system32\xvidvfw.dll",Configure
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debugging Tools for Windows (x86)\Uninstall Debugging Tools for Windows (x86).lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /x {48F95CE7-69D9-4967-81F7-D763CABFBD53}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player Legacy.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerUser\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Containers\Layers\141c4c32-ddd0-43a0-b320-826f69a1eecd\Files\Users\ContainerAdministrator\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Abmelden.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -l -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Erweiterte Startoptionen.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -r -o -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Herunterfahren.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -s -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Neustart komplett.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -g -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Neustart.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -r -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Ruhezustand.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -h
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Safe Mode Exit.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c bcdedit /deletevalue safeboot & shutdown -r -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\Safe Mode.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /C C:\Windows\System32\bcdedit.exe /set safeboot minimal & shutdown -r -t 0
ShortcutWithArgument: C:\Users\goofy\Desktop\Beenden und Neustart\UEFI Boot.lnk -> C:\Windows\System32\shutdown.exe (Microsoft Corporation) -> -r -fw -t 0
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Should I Remove It\Uninstall.lnk -> C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) -> /x {4E62123C-4C0D-4123-A8A2-C0103B92D7EA}
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mühle\Bedienungsanleitung.lnk -> C:\ProgramData\JMMG Communications\Muehle\Muehle.exe (JMMG Communications, Jochen Moschko) -> /manual
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mühle\Mühle deinstallieren.lnk -> C:\ProgramData\JMMG Communications\Muehle\Muehle.exe (JMMG Communications, Jochen Moschko) -> /uninst
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\goofy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PowerShell 7 (x64).lnk -> C:\Program Files\PowerShell\7\pwsh.exe (Microsoft Corporation) -> -WorkingDirectory ~
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\goofy\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAbout
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\WsiAccount\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
InternetURL: C:\Users\Administrator\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\MP3gain Website.url -> URL: hxxp://mp3gain.sourceforge.net/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxMP3gain\wxMP3gain Website.url -> URL: hxxps://github.com/cfgnunes/wxmp3gain
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOVSOFT\Text to MP3 Converter\Text to MP3 Converter im Internet.url -> URL: hxxps://vovsoft.com
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2025\Hilfen\Steuer 2025 Online-Hilfe.url -> URL: hxxp://www.buhl.de/go/333
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag\Mp3tag Hilfe.url -> URL: hxxps://docs.mp3tag.de
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag\Mp3tag Website.url -> URL: hxxps://www.mp3tag.de/en/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag\Neu in dieser Version.url -> URL: hxxps://docs.mp3tag.de/getting-started/release-notes
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Help\Online Codec Help.url -> URL: hxxp://www.codecguide.com/help.htm
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hasleo WinToUSB\Hasleo WinToUSB im Internet.url -> URL: hxxps://www.hasleo.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis\BLACK WHITE projects 6 professional\Webseite - BLACK WHITE projects 6 professional.url -> URL: hxxp://www.franzis.de/blackwhite-projects
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master\Besuchen Sie EaseUS.url -> URL: hxxps://www.easeus.de/partition-manager/index.html
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master\EaseUS Partition Master Help.url -> URL: hxxps://www.easeus.de/bedienungsanleitung/partition-master-free-nutzer-anleitung.html
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard\EaseUS besuchen.url -> URL: hxxps://www.easeus.de
InternetURL: C:\Users\goofy\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Corporation\Microsoft Support and Recovery Assistant Onlineunterstützung.url -> BASEURL: hxxps://aka.ms/SaRA_Home URL: hxxps://aka.ms/SaRA_Home
InternetURL: C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box\FRITZ!Box USB-Fernanschluss Onlineunterstützung.url -> BASEURL: hxxps://avm.de/ URL: hxxps://avm.de/
==================== Ende vom Shortcut.txt =============================
|
| | #13 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Langsamer WIN-Start Man könnte jetzt was fixen, aber das wäre wenn überhaupt nur Kosmetik. Die genaue Ursache für den langsamen Startprozes herauszufinden kann sehr aufwändig bis unmöglich sein. Malware ist hier jedenfalls nicht die Ursache. Es ist bekannt, dass Windows 11 große Qualitäts- und Resourcenprobleme hat. Brauchst du denn unbedingt Windows? Wenn nein, dann wechsel zu Linux. Das OS ist deutlich performanter.
__________________ Logfiles bitte immer in CODE-Tags posten |
![]() |
| Themen zu Langsamer WIN-Start |
| abgeschlossen, beginnt, build, dauert, eintrag, einträge, error, escan, file, kreis, langsamer, langsamer programmstart, log-datei, malwarebytes, memory, nicht, not, sende, träge, vorgang, warning, win, win 11, windows, zone |