![]() |
| |||||||
Log-Analyse und Auswertung: WIN 11 - Malwarebytes unterbindet Verbindung zu riskanter WebseiteWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #1 |
![]() ![]() | WIN 11 - Malwarebytes unterbindet Verbindung zu riskanter Webseite Hallo. Ich hatte in letzter Zeit immer irgendwie das Gefühl, dass mein Laptop von einem Virus befallen ist. Es hat auf einmal im Hintergrund mehr gearbeitet. Habe dann Malwarebytes ausgeführt. Funde es es keine gegeben. Was jedoch hinterher regelmässig kommt, ist ein Fenster, in dem mir mitgeteilt wird, dass Malwarebytes eine ristkante Verbindung zu einer Webseite unterbindet. Die Domäne ist cdn77.aj1985.online. Die Verbindung will er immer über Firefox machen. Das Zweite ist, dass bei fast jedem Start ein Popup aufgeht mit der Meldung "Unhandled exception in script". Dieses kann ich schliessen und es scheint alles zu funkionieren. Danke schonmal für Hilfe Hier noch die Logs FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2026
durchgeführt von joerg (Administrator) auf HOME (GIGABYTE GIGABYTE GAMING A16 CMH) (26-09-2026 07:57:48)
Gestartet von C:\Users\joerg\Desktop\FRST64.exe
Geladene Profile: joerg
Plattform: Microsoft Windows 11 Home Version 25H2 26200.9457 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Edge
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files (x86)\Epson Software\Epson Printer Connection Checker\EPPCCMON.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\GIGABYTE\Control Center\GCC.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\OSDwindow.exe
(C:\Program Files\GIGABYTE\Control Center\GCC.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\PgSvc\Gbt.GpuPowerGear.Proxy.exe
(C:\Program Files\GIGABYTE\Control Center\GimateServiceHelper.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> AudioCaptureService) C:\Program Files\GIGABYTE\AudioCaptureService\AudioCaptureService.exe
(C:\Program Files\GIGABYTE\GiMATE_ai\GiMATE_ai.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\DefenderSessionHelper.exe
(cmd.exe ->) (Giga-byte Technology Co., Ltd. -> ) C:\Program Files\GIGABYTE\GiMATE_ai\GiMATE_llm.exe
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_6c19a4caad42dde0\DAX3API.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~3.INF\DAX3API.exe
(DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_helper.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e49e9d8e54adc7ca\RtkAudUService64.exe
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\Epson Software\Epson Printer Connection Checker\EPPCCMON.EXE
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E1YATIBEE.EXE <2>
(Giga-byte Technology Co., Ltd. -> ) C:\Program Files\GIGABYTE\GiMATE_ai\GiMATE_ai.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\153.0.4234.48\msedgewebview2.exe <5>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvgb.inf_amd64_764b7a45580616a0\Display.NvContainer\NVDisplay.Container.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_6c19a4caad42dde0\DAX3API.exe
(services.exe ->) (FOR TESTING ONLY - IPF_PreProd_Cert -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dtt_sw.inf_amd64_8edcf6be1c4ddd78\ipfsvc.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\GprocSrvc.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\PgSvc\Gbt.GpuPowerGear.Service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_80dcb7b409148fed\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_91b5ed43a9896c4a\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_11590576de308f2a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_58a0ea2de06916f7\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_ee1169deb7ec6a42\Intel_PIE_Service.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_1af5af61f22f9a64\AS\IAS\IntelAudioService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.168.0830.0006\FileSyncHelper.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvgb.inf_amd64_764b7a45580616a0\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e49e9d8e54adc7ca\RtkAudUService64.exe
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\GCC.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\GimateServiceHelper.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\Lib\AIVisual\AIVisualPIPESvr.exe
(svchost.exe ->) (Giga-byte Technology Co., Ltd. -> ) C:\Program Files\GIGABYTE\GiMATE_ai\GiMATE_ai.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.380.2.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e49e9d8e54adc7ca\RtkAudUService64.exe [2790336 2025-05-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [466760 2026-02-16] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2770680 2025-09-19] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [1003792 2026-02-18] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [1327376 2026-02-18] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [GCCOSD] => C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\OSDwindow.exe [8347184 2026-06-17] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM-x32\...\Run: [GbtPgOSD] => C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\PgSvc\Gbt.GpuPowerGear.Proxy.exe [322608 2026-05-28] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM\...\RunOnce: [autobuildf9] => C:\Windows\system32\buildf9.exe [65272 2023-03-13] (Giga-byte Technology Co., Ltd. -> )
HKLM\...\RunOnce: [msedge_cleanup_{C50565E9-CCCF-44B4-BA15-5AC5C6569197}] => C:\Program Files (x86)\Microsoft\Copilot\Application\154.0.4258.37\Installer\setup.exe [5957960 2026-09-25] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4274421120-2470223001-163059934-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4756840 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4274421120-2470223001-163059934-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E1YATIBEE.EXE [484712 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-4274421120-2470223001-163059934-1001\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E1YATIBEE.EXE [484712 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EPSON PC-FAX Driver2 64Monitor: C:\Windows\system32\EFXLM16A.DLL [217432 2026-03-11] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EPSON WF-2950 Series 64MonitorBE: C:\Windows\system32\E1YLMBBEE.DLL [247976 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [3182776 2025-02-20] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Startup: C:\Users\joerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2025-12-05]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {A93388D8-F184-4906-8F92-41E1D16844E3} - System32\Tasks\AI => C:\Program Files\GIGABYTE\GiMATE_ai\GiMATE_ai.exe [60526968 2025-06-04] (Giga-byte Technology Co., Ltd. -> )
Task: {14CD74E4-5932-4E9F-9B7E-21F7E47B5A57} - System32\Tasks\aivisual => C:\Program Files\GIGABYTE\Control Center\Lib\AIVisual\AiVisualPipeSvr.exe [63144 2026-06-16] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
Task: {656B3687-4899-4642-8C5A-CC5C33492CC9} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [3389784 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {87F637BD-CD01-402D-841B-F16E9196E63F} - System32\Tasks\EPSON WF-2950 Series Update {9E7E8B5C-0F61-402A-99DF-41804D1CD318} => C:\Windows\System32\spool\drivers\x64\3\E1YTSBEE.EXE [680440 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {A4B291C6-7E56-4A2C-A570-5E9B4060A2A3} - System32\Tasks\EPSON WF-2950 Series Update {EDACAED1-8603-4850-B4AB-199CD264A28C} => C:\Windows\System32\spool\drivers\x64\3\E1YTSBEE.EXE [680440 2025-06-24] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {23DE4DF0-2B53-4D2F-9D24-3EA249D47A62} - System32\Tasks\GiMATE Service => C:\Program Files\GIGABYTE\Control Center\GCC.exe [35346088 2025-12-16] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) -> C:\Program Files\GIGABYTE\Control Center\\-h
Task: {E5C0AC8F-5B5E-4687-BB5C-6CCF5DABF960} - System32\Tasks\GimateServiceHelper => C:\Program Files\GIGABYTE\Control Center\GimateServiceHelper.exe [39592 2026-04-30] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
Task: {E06DA310-807D-4891-8A76-11F1F3754547} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16470400 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3857D140-84A7-40A3-AFBD-E92F464DF4C3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28440976 2026-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B71B701E-2FD3-4640-B92D-DD1663F9369B} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [69984 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {22B5DA96-D4F6-4F36-80D2-4044899A3276} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28440976 2026-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {0736FE22-8529-4BB4-81CA-39A5DC5E6BAB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [426352 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {2F9F741B-181E-4D55-8A86-EAE0C165CE3D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [426352 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {B3BA962A-9C30-4BF7-A032-16C28568A689} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1328920 2026-08-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C498650D-01CF-422B-BA10-D2F5F15E1622} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16470400 2026-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Keine Datei)
Task: {921BFAA7-6207-4962-83CC-139794E32738} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-4274421120-2470223001-163059934-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [1079424 2026-09-22] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {9DD34A82-FCF2-4003-8A18-1C091AAEF8FD} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [44160 2026-09-22] (Mozilla Corporation -> Mozilla Foundation)
Task: {F1C5748C-3A42-4359-922F-A7D9D0DC6C9A} - System32\Tasks\NvBroadcast_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\NVIDIA Broadcast UI.exe [11011624 2024-08-04] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\-minimized
Task: {AC9CBC18-9967-49DB-A0C0-5BA05425D605} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1277480 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {A6606CD4-52C4-4F2E-A180-69C6CC12B45F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3347496 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3F06C431-DE02-4AD3-BE98-595986CA2930} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646696 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {79BBA7E5-C148-406D-86FF-D6681B619FF2} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F676400F-9C5A-4658-AE64-408A405EFE7C} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0CF4095C-9ACC-4578-BF5C-885FA8F081E0} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9B25F045-74B5-48A9-9D7B-FE284BD46AE8} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A9B91AAD-E23C-469F-B137-0D091F8C25FC} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4409744 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {A138D3B7-0CA1-48A7-A15A-8DE4B70485DA} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-4274421120-2470223001-163059934-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4409744 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {7652AB28-6655-4148-96B4-D9AAA9E0833A} - System32\Tasks\OneDrive Startup Task-S-1-5-21-4274421120-2470223001-163059934-1001 => C:\Program Files\Microsoft OneDrive\26.168.0830.0006\OneDriveLauncher.exe [866192 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {58A5CBC0-5696-4A24-B36D-0D1B424F2347} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-4274421120-2470223001-163059934-1001 => C:\Users\joerg\AppData\Roaming\Zoom\bin\Zoom.exe [500168 2026-09-25] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\Windows\Tasks\EPSON WF-2950 Series Update {9E7E8B5C-0F61-402A-99DF-41804D1CD318}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E1YTSBEE.EXE:/EXE:{9E7E8B5C-0F61-402A-99DF-41804D1CD318} /F:UpdateWORKGROUP\HOME$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON WF-2950 Series Update {EDACAED1-8603-4850-B4AB-199CD264A28C}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E1YTSBEE.EXE:/EXE:{EDACAED1-8603-4850-B4AB-199CD264A28C} /F:UpdateWORKGROUP\HOME$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.51
Tcpip\..\Interfaces\{7a1f18f7-3614-4927-9e68-6802d11855dc}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{7a1f18f7-3614-4927-9e68-6802d11855dc}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}: [DhcpNameServer] 192.168.178.51
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\64259445A51224F6870273639303029545: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\64259445A51224F6870273639303029545: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\A59647479637D255E6966756273757D6: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\A59647479637D255E6966756273757D6: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\A596474796D255E6966756273757D6: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{f3acc241-b1ec-47d2-ae3f-ab945c892407}\A596474796D255E6966756273757D6: [DhcpDomain] fritz.box
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: dlnktlrv.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\joerg\AppData\Roaming\Mozilla\Firefox\Profiles\qiapksnk.default [2026-09-15]
FF ProfilePath: C:\Users\joerg\AppData\Roaming\Mozilla\Firefox\Profiles\dlnktlrv.default-release [2026-09-26]
FF Extension: (New Tab) - C:\Users\joerg\AppData\Roaming\Mozilla\Firefox\Profiles\dlnktlrv.default-release\Extensions\newtab@mozilla.org.xpi [2026-09-24]
FF Extension: (MetaMask) - C:\Users\joerg\AppData\Roaming\Mozilla\Firefox\Profiles\dlnktlrv.default-release\Extensions\webextension@metamask.io.xpi [2026-08-17]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-08-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-08-22] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\joerg\AppData\Local\Microsoft\Edge\User Data\Default [2026-09-15]
Edge Extension: (Google Docs Offline) - C:\Users\joerg\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-29]
Edge Extension: (Edge relevant text changes) - C:\Users\joerg\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-12-03]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13372816 2026-09-15] (Microsoft Corporation -> Microsoft Corporation)
S3 CorsairDeviceControlService; C:\Program Files\Corsair\Corsair Device Control Service\bin\CorsairDeviceControlService.exe [2415144 2024-08-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 DolbyDAXAPI; C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_6c19a4caad42dde0\DAX3API.exe [2770000 2025-03-06] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 dptftcs; C:\Windows\System32\DriverStore\FileRepository\dtt_sw.inf_amd64_8edcf6be1c4ddd78\ipfsvc.exe [562040 2024-09-12] (FOR TESTING ONLY - IPF_PreProd_Cert -> Intel Corporation)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [222768 2025-04-08] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.168.0830.0006\FileSyncHelper.exe [3800424 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
R2 Gbt.GpuPowerGear.Service; C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\PgSvc\Gbt.GpuPowerGear.Service.exe [319536 2026-05-28] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 GprocSrvc; C:\Program Files\GIGABYTE\Control Center\Lib\GBT_NbSrv\GprocSrvc.exe [31280 2026-06-17] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S2 Intel(R) Platform License Manager Service; C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_740dc8aba9846dbb\lib\PlatformLicenseManagerService.exe [741600 2024-08-02] (Intel Corporation -> Intel(R) Corporation)
R2 IntelAudioService; C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_1af5af61f22f9a64\AS\IAS\IntelAudioService.exe [532944 2025-05-09] (Intel Corporation -> Intel)
R2 ipfsvc; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_uf.exe [3084992 2024-08-02] (Intel Corporation -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11667704 2026-09-15] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-09-15] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe [2307776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvgb.inf_amd64_764b7a45580616a0\Display.NvContainer\NVDisplay.Container.exe [1275624 2025-11-05] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.168.0830.0006\OneDriveUpdaterService.exe [4098960 2026-09-24] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe [5311776 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe [291360 2026-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AirplaneModeController; C:\Windows\System32\drivers\vhidmini.sys [44880 2024-09-05] (Giga-byte Technology Co., Ltd. -> Windows (R) Win 7 DDK provider)
S3 CtaChildDriver; C:\Windows\System32\drivers\CtaChildDriver.sys [60392 2024-12-16] (Intel Corporation -> Intel Corporation)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [176976 2026-04-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae.sys [159296 2026-09-15] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 fse; C:\Windows\System32\drivers\fse.sys [230888 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
R3 gdrv3; \??\C:\Windows\system32\drivers\gdrv3.sys [58768 2026-07-26] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
S3 GSCAuxDriver; C:\Windows\System32\DriverStore\FileRepository\gscauxdriver.inf_amd64_b7ea2b267b9226f0\GSCAuxDriverx64.sys [112616 2024-12-16] (Intel Corporation -> Intel Corporation)
S3 GSCx64; C:\Windows\System32\DriverStore\FileRepository\gscheci.inf_amd64_985d88058166e9cc\TeeDriverGSCW8x64.sys [286720 2024-12-16] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_GPIO2_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_6f8ae740d22247ce\iaLPSS2_GPIO2_ADL.sys [141288 2024-08-02] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_563fbcd35feb69a6\iaLPSS2_I2C_ADL.sys [211432 2024-08-02] (Intel Corporation -> Intel Corporation)
S3 iaLPSS2_SPI_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_spi_adl.inf_amd64_bdfb46f9ce8fefd9\iaLPSS2_SPI_ADL.sys [162792 2024-08-02] (Intel Corporation -> Intel Corporation)
S3 iaLPSS2_UART2_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_uart2_adl.inf_amd64_cf101fc7906bfd11\iaLPSS2_UART2_ADL.sys [317016 2024-08-02] (Intel Corporation -> Intel Corporation)
R0 iaStorVD; C:\Windows\System32\drivers\iaStorVD.sys [1617096 2024-08-02] (Intel Corporation -> Intel Corporation)
S3 IntcSdwBus; C:\Windows\System32\DriverStore\FileRepository\intcsdwbus.inf_amd64_83b00d30ddce5c3a\IntcSdwBus.sys [525800 2024-07-22] (Intel Corporation -> Intel(R) Corporation)
R3 IntcUSB; C:\Windows\System32\DriverStore\FileRepository\intcusb.inf_amd64_597fa055d37ffe1e\IntcUSB.sys [941008 2025-05-09] (Intel Corporation -> Intel(R) Corporation)
R3 IntelGNA; C:\Windows\System32\DriverStore\FileRepository\gna.inf_amd64_8e2f374849f1eba9\gna.sys [90304 2024-08-02] (Intel Corporation -> Intel Corporation)
S3 Intel_NF_I2C; C:\Windows\System32\DriverStore\FileRepository\intel_nf_i2c_child.inf_amd64_395bbbb88694dc77\Intel_NF_I2C.sys [228456 2024-12-16] (Intel Corporation -> Intel Corporation)
R3 ipf_acpi; C:\Windows\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_c4581e5c36b81f6c\ipf_acpi.sys [88656 2024-08-02] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_cpu.sys [88144 2024-08-02] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2967a6eb0d3a7d\ipf_lf.sys [499392 2024-08-02] (Intel Corporation -> Intel Corporation)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [83008 2026-09-03] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\Windows\System32\drivers\l1vhlwf.sys [144864 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
S3 LT6911Au; C:\Windows\System32\DriverStore\FileRepository\lt6911au.inf_amd64_5808b19b30ac2a8b\LT6911Au.sys [67048 2024-07-22] (Intel Corporation -> Intel(R) Corporation)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [235624 2026-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-09-15] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\Drivers\farflt11.sys [217192 2026-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\Drivers\mbam.sys [132712 2026-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [246376 2026-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; \??\C:\Windows\system32\DRIVERS\mwac.sys [190096 2026-09-15] (Malwarebytes Inc -> )
R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [47240 2024-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvpcf; C:\Windows\System32\drivers\nvpcf.sys [302840 2025-11-05] (NVIDIA Corporation -> NVIDIA Corporation)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 rtucx21x64; C:\Windows\System32\DriverStore\FileRepository\rtucx21x64.inf_amd64_286645bc82b2f9fb\rtucx21x64.sys [1359360 2024-04-01] (Microsoft Windows -> Realtek Corporation)
R3 rtucx22x64; C:\Windows\System32\DriverStore\FileRepository\rtucx22x64sta.inf_amd64_3825a182b3f5dd79\rtucx22x64.sys [1846248 2025-06-27] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174416 2026-04-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 vmbusproxy; C:\Windows\system32\drivers\vmbusproxy.sys [98304 2025-12-03] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\Windows\System32\drivers\wd\WdAiNisDrv.sys [51264 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21632 2026-09-18] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [664592 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [137240 2026-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 WiManHu; C:\Windows\System32\DriverStore\FileRepository\wiman.inf_amd64_9fa510ad56b2f401\WiManHu\WiManHu.sys [216120 2024-08-02] (Intel Corporation -> Intel Corporation)
S3 WSDPrintDevice; C:\Windows\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-09-06] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; \SystemRoot\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys (Keine Datei)
==================== SvcHost (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-09-26 07:57 - 2026-09-26 07:57 - 000000000 ____D C:\Users\joerg\Desktop\FRST-OlderVersion
2026-09-25 14:31 - 2026-09-25 14:31 - 000002264 _____ C:\Users\joerg\AppData\LocalLow\DeviceId=A7A8_DeviceRevisionId=0004_DevicePciAddr=0.2.0_AppName=msedgewebview2=olk.exe_ApiClient=D3D12
2026-09-25 14:13 - 2026-09-25 14:13 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2026-09-23 18:28 - 2026-09-25 19:09 - 000000000 ____D C:\Windows\CbsTemp
2026-09-20 17:13 - 2026-09-20 17:13 - 000748376 _____ C:\Windows\system32\perfh007.dat
2026-09-20 17:13 - 2026-09-20 17:13 - 000159426 _____ C:\Windows\system32\perfc007.dat
2026-09-20 12:51 - 2026-04-21 06:07 - 000174416 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys
2026-09-15 16:32 - 2026-09-26 07:35 - 000000000 ____D C:\Windows\SystemTemp
2026-09-15 16:30 - 2026-09-15 16:30 - 000190096 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2026-09-15 16:01 - 2026-09-15 16:02 - 000000000 ____D C:\AdwCleaner
2026-09-15 16:01 - 2026-09-15 16:01 - 009630992 _____ (Malwarebytes) C:\Users\joerg\Downloads\adwcleaner.exe
2026-09-15 16:00 - 2026-09-15 16:00 - 002900520 _____ (Malwarebytes) C:\Users\joerg\Downloads\MBSetup-7.7(1).exe
2026-09-15 15:44 - 2026-09-26 07:45 - 000000000 ____D C:\Users\joerg\AppData\Local\Malwarebytes
2026-09-15 15:44 - 2026-09-15 15:44 - 000002100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-09-15 15:44 - 2026-09-15 15:44 - 000002088 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-09-15 15:44 - 2026-09-15 15:44 - 000000000 ____D C:\Users\joerg\AppData\Local\Sentry
2026-09-15 15:40 - 2026-09-15 15:40 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-09-15 15:40 - 2026-09-15 15:40 - 000000000 ____D C:\Program Files\Malwarebytes
2026-09-15 15:39 - 2026-09-15 15:39 - 002900520 _____ (Malwarebytes) C:\Users\joerg\Downloads\MBSetup-7.7.exe
2026-09-12 11:39 - 2026-09-12 11:39 - 000000000 ____D C:\Users\joerg\AppData\LocalLow\Shield
2026-09-11 10:48 - 2026-09-11 10:48 - 000081310 _____ C:\Users\joerg\Downloads\4544_2904_ABRECHNUNG_2026-09-05_Zitlau_Joerg.PDF
2026-09-09 18:53 - 2026-09-09 18:53 - 000004646 _____ C:\Windows\system32\ResPriUHMImageList
2026-09-09 18:53 - 2026-09-09 18:53 - 000004646 _____ C:\Windows\system32\ResPriLMImageList
2026-09-09 18:53 - 2026-09-09 18:53 - 000004646 _____ C:\Windows\system32\ResPriImageList
2026-09-09 18:53 - 2026-09-09 18:53 - 000004646 _____ C:\Windows\system32\ResPriHMImageList
2026-09-09 18:53 - 2026-09-09 18:53 - 000004555 _____ C:\Windows\system32\ResPriImageListLowCost
2026-09-09 18:53 - 2026-09-09 18:53 - 000004555 _____ C:\Windows\system32\ResPriHMImageListLowCost
2026-09-09 18:52 - 2026-09-09 18:52 - 000039215 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-09-09 18:52 - 2026-09-09 18:52 - 000039215 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2026-09-09 18:52 - 2026-09-09 18:52 - 000014689 _____ C:\Windows\system32\ecoscore_config.json
2026-09-08 18:12 - 2026-09-08 18:12 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Proof
2026-09-04 20:15 - 2026-09-22 18:09 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-08-29 10:52 - 2026-08-29 10:52 - 000081321 _____ C:\Users\joerg\Downloads\4544_2904_ABRECHNUNG_2026-08-05_Zitlau_Joerg-1.PDF
2026-08-29 10:46 - 2026-08-29 10:46 - 000081321 _____ C:\Users\joerg\Downloads\4544_2904_ABRECHNUNG_2026-08-05_Zitlau_Joerg.PDF
2026-08-29 07:29 - 2026-08-29 07:29 - 000000000 ____D C:\Users\joerg\AppData\Local\WindowsOobeAppHost
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-09-26 07:58 - 2025-12-07 16:33 - 000000000 ____D C:\FRST
2026-09-26 07:57 - 2025-12-07 16:32 - 002455552 _____ (Farbar) C:\Users\joerg\Desktop\FRST64.exe
2026-09-26 07:57 - 2025-12-07 16:20 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-09-26 07:44 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-09-26 07:32 - 2026-01-31 11:36 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Zoom
2026-09-26 07:25 - 2026-07-26 12:50 - 000000000 ____D C:\Users\joerg\AppData\Local\GbtFusionData
2026-09-26 07:25 - 2025-12-03 18:35 - 000000000 ___RD C:\Users\joerg\OneDrive
2026-09-26 07:25 - 2025-06-15 07:20 - 000003666 _____ C:\Windows\system32\Tasks\GiMATE Service
2026-09-26 07:25 - 2025-06-15 07:12 - 000000000 ____D C:\ProgramData\NVIDIA
2026-09-26 07:25 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-09-26 07:25 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\AppReadiness
2026-09-25 19:32 - 2025-12-13 12:42 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Telegram Desktop
2026-09-25 14:31 - 2025-12-05 19:21 - 000000298 _____ C:\Users\joerg\AppData\LocalLow\3fb547855fb3d3c7cb2c06aca33a9c3f354a22a4517aeb6e3c4558bfccca078a
2026-09-25 14:31 - 2025-12-03 18:19 - 000000000 ____D C:\Users\joerg\AppData\Local\D3DSCache
2026-09-25 14:29 - 2025-12-05 19:21 - 000375307 _____ C:\Users\joerg\AppData\LocalLow\3790edf8c43600d5e37b8382e3c0e71798c796e70c306d7b8f4ecf2fb4451cb5
2026-09-25 14:28 - 2026-01-13 15:57 - 000000130 _____ C:\Users\joerg\AppData\LocalLow\3a320a53e298c65994944589b86f741f340445dd273095332097e58569de6ed3
2026-09-25 14:13 - 2026-01-31 11:36 - 000004248 _____ C:\Windows\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-4274421120-2470223001-163059934-1001
2026-09-24 20:22 - 2025-12-03 18:36 - 000000130 _____ C:\Users\joerg\AppData\LocalLow\fc18fb27e101ce15521508b9f0ffba6ed4c603de490a2eca8b1bed3acfb3658d
2026-09-24 19:49 - 2025-12-07 15:45 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-09-24 19:49 - 2025-12-05 18:34 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-09-24 19:49 - 2025-12-05 18:34 - 000002046 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-09-24 19:49 - 2025-12-03 18:38 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-4274421120-2470223001-163059934-1001
2026-09-24 19:49 - 2025-12-03 18:35 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4274421120-2470223001-163059934-1001
2026-09-22 18:58 - 2025-06-15 06:11 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-09-22 18:09 - 2026-08-19 19:18 - 000002132 _____ C:\Users\joerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-09-22 18:09 - 2026-05-27 19:06 - 000402048 _____ (Mozilla Foundation) C:\Users\joerg\Desktop\Firefox.exe
2026-09-22 18:09 - 2025-12-07 16:20 - 000001072 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-09-22 18:00 - 2025-06-15 06:23 - 000000000 ____D C:\Program Files\Microsoft Office
2026-09-21 17:28 - 2025-12-21 16:18 - 000000000 ____D C:\Users\joerg\Downloads\Telegram Desktop
2026-09-20 17:13 - 2025-06-15 06:27 - 001729504 _____ C:\Windows\system32\PerfStringBackup.INI
2026-09-20 17:13 - 2024-04-01 09:24 - 000000000 ____D C:\Windows\INF
2026-09-20 11:14 - 2025-06-15 06:12 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-09-20 11:14 - 2025-06-15 06:12 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-09-20 11:07 - 2025-06-15 06:12 - 000003830 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{38264092-CF0F-458D-A6C5-65850D75C80D}
2026-09-20 11:07 - 2025-06-15 06:12 - 000003758 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{53B6A564-24D5-48E8-BABD-4B401FD9C55A}
2026-09-19 19:38 - 2026-01-21 20:38 - 000000130 _____ C:\Users\joerg\AppData\LocalLow\c128e33a9d0746f9675aa6bfa95c9e8ed1e9dd7821e0d9f8303aee95d2127b63
2026-09-19 19:38 - 2025-12-07 16:36 - 000000130 _____ C:\Users\joerg\AppData\LocalLow\1200a7146be44de5d7e4933bba92fbf62e200cae64fc37f56462371d1d9f7ebc
2026-09-18 15:02 - 2025-06-15 06:12 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-09-16 22:56 - 2025-12-27 18:09 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Sky Go
2026-09-16 10:01 - 2025-12-07 16:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-09-15 16:32 - 2025-12-03 18:16 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Windows
2026-09-15 16:30 - 2025-12-04 09:04 - 000016060 _____ C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-09-15 16:30 - 2025-06-15 06:12 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-09-15 16:30 - 2025-06-15 06:11 - 000012288 ___SH C:\DumpStack.log.tmp
2026-09-15 16:30 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ServiceState
2026-09-15 16:29 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2026-09-15 16:29 - 2024-04-01 09:21 - 000786432 _____ C:\Windows\system32\config\BBI
2026-09-15 16:28 - 2024-04-01 09:26 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2026-09-15 16:23 - 2025-12-07 16:36 - 000178751 _____ C:\Users\joerg\AppData\LocalLow\dbb17a6be212ef685ba97fbba526dd2acf51c2e342e255cd4905a3ef0d0cc239
2026-09-15 16:12 - 2025-06-15 06:11 - 000001623 _____ C:\Windows\system32\config\VSMIDK
2026-09-15 16:11 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\bcastdvr
2026-09-15 15:44 - 2025-12-03 18:19 - 000000000 ____D C:\Users\joerg\AppData\Local\Packages
2026-09-15 15:44 - 2025-06-15 06:23 - 000000000 ____D C:\ProgramData\Packages
2026-09-15 15:44 - 2024-04-01 09:26 - 000000000 ___HD C:\Windows\ELAMBKUP
2026-09-15 14:41 - 2025-06-15 06:14 - 003381760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2026-09-13 09:50 - 2025-12-05 19:01 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Word
2026-09-13 09:45 - 2025-06-15 07:23 - 000000000 ____D C:\Windows\Minidump
2026-09-13 09:45 - 2025-06-15 06:11 - 007263134 ____N C:\Windows\Minidump\091326-12468-01.dmp
2026-09-12 11:39 - 2025-12-27 18:08 - 000001049 _____ C:\Users\joerg\Desktop\Sky Go.lnk
2026-09-12 11:39 - 2025-12-27 18:08 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sky
2026-09-12 10:24 - 2025-12-05 18:50 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\Excel
2026-09-12 07:19 - 2025-06-15 06:11 - 007078874 ____N C:\Windows\Minidump\091226-11765-01.dmp
2026-09-11 15:13 - 2025-12-07 15:44 - 000000130 _____ C:\Users\joerg\AppData\LocalLow\d8656072743725704677e48c4998f1086ef6607a0d0c69c6d85c0259f88b6355
2026-09-09 20:13 - 2025-06-15 06:11 - 000653832 _____ C:\Windows\system32\FNTCACHE.DAT
2026-09-09 20:12 - 2025-12-18 20:12 - 000000000 ____D C:\Windows\system32\NarratorMCAT
2026-09-09 20:12 - 2025-12-05 19:23 - 000000000 ____D C:\Windows\system32\ruxim
2026-09-09 20:12 - 2024-09-06 06:10 - 000000000 ____D C:\Windows\InboxApps
2026-09-09 20:12 - 2024-04-01 10:08 - 000000000 ____D C:\Windows\system32\OpenSSH
2026-09-09 20:12 - 2024-04-01 10:08 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\system32\F12
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\UUS
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\setup
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\oobe
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\InstallShield
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\Dism
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemResources
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinMetadata
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Sysprep
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ShellExperiences
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\setup
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\oobe
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\migwiz
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Dism
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\appraiser
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellExperiences
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellComponents
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\Provisioning
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\L2Schemas
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\BrowserCore
2026-09-09 20:12 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-09-09 20:12 - 2024-04-01 09:21 - 000000000 ____D C:\Windows\servicing
2026-09-09 19:45 - 2025-12-03 21:57 - 000000000 ____D C:\Windows\system32\MRT
2026-09-09 19:41 - 2025-12-03 21:57 - 230964456 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-09-08 18:16 - 2025-12-05 19:00 - 000000000 ____D C:\Users\joerg\AppData\Roaming\Microsoft\UProof
2026-09-08 18:11 - 2026-02-01 11:15 - 000163695 _____ C:\Users\joerg\AppData\LocalLow\897f03072020ffe6a861429e41e5228659e097df2818ea8037a4c5bd8426ccb5
2026-09-08 18:11 - 2026-02-01 11:15 - 000000298 _____ C:\Users\joerg\AppData\LocalLow\2d80f582381c44c865fd9e8e27ac844e6c7b00b0d3c0e9b69a55b369e1853383
2026-08-27 17:42 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\appcompat
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ========================
|
| Themen zu WIN 11 - Malwarebytes unterbindet Verbindung zu riskanter Webseite |
| administrator, defender, desktop, firefox, geforce, google, home, internet, mozilla, nvidia, performance, popup, port, prozesse, realtek, registry, scan, server, services.exe, software, svchost.exe, system, updates, virus, windows |