Hallo Cosinus,
was willst Du mir damit konkret zu meinem Problem sagen? Bis auf die "Anti"-Programme setzte ich alle seit Jahren ein und bin zumindest bisher (unbemerkt?) virenfrei (und auch sonst problemlos) geblieben.
Und hier das zweite Protokoll: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-01-2021
durchgeführt von KR Admin (Administrator) auf KR5 (Micro-Star International Co., Ltd. MS-7B51) (31-01-2021 16:31:38)
Gestartet von D:\Allgemein\Downloads
Geladene Profile: KR Admin & KR
Platform: Windows 10 Pro Version 20H2 19042.746 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: "C:\Kommunikation\Firefox\firefox.exe" -osint -url "%1"
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
() [Datei ist nicht signiert] C:\Utility\Dateimanagement\Allway Sync\Bin\SyncService.exe
(Ascora GmbH -> ) C:\ProgramData\Abelssoft\AntiLogger\Program\AntiLogger.exe
(Ascora GmbH -> ) C:\ProgramData\Abelssoft\AntiRansomware\Program\AntiRansomware.exe
(Ascora GmbH -> ) C:\ProgramData\Abelssoft\AntiRansomware\Program\ARWWatcherService.exe
(Ascora GmbH -> ) C:\ProgramData\Abelssoft\HackCheck\Program\HackCheck.exe
(Botkind, Inc. -> ) C:\Utility\Dateimanagement\Allway Sync\Bin\syncappw.exe <2>
(cFos Software GmbH -> cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Utility\Sicherung\Todo Backup\bin\TodoBackupService.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) C:\Utility\Sicherung\Todo Backup\bin\Agent.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) C:\Utility\Sicherung\Todo Backup\bin\TrayProcess.exe
(Deutsche Telekom AG -> DEUTSCHE TELEKOM AG) C:\Program Files (x86)\Telekom\MagentaCloud\MagentaCloud.App.exe
(Deutsche Telekom AG -> Deutsche Telekom AG) C:\Program Files (x86)\Telekom\MagentaCloud\Updater\MaintenanceService.exe
(Deutsche Telekom AG -> The CefSharp Authors) C:\Program Files (x86)\Telekom\MagentaCloud\CefSharp.BrowserSubprocess.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\114.4.426\QtWebEngineProcess.exe <3>
(FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Utility\PDF\Foxit Reader\FoxitReaderUpdateService.exe
(geek software GmbH -> geek software GmbH) C:\Utility\PDF\PDF24\pdf24.exe <3>
(GN AUDIO A/S -> GN Audio A/S) C:\Program Files (x86)\Jabra\Direct4\jabra-direct.exe <8>
(GN AUDIO A/S -> GN Audio A/S) C:\Program Files (x86)\Jabra\Direct4\SoftphoneIntegrations.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.52\GoogleCrashHandler64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_3c43114c92103b1a\LMS.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\avp.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\avpui.exe <2>
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksde.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksdeui.exe <2>
(Logitech, Inc. -> ) C:\Kommunikation\LogitechKamera\LWS\Webcam Software\CameraHelperShell.exe <2>
(Logitech, Inc. -> Logitech Inc.) C:\Kommunikation\LogitechKamera\LWS\Webcam Software\LWS.exe <2>
(Lotus Development Corporation) [Datei ist nicht signiert] C:\Kommunikation\Lotus Organizer\easyclip6.exe <2>
(Malwarebytes Inc -> Malwarebytes) C:\Sicherheit\MBAM\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Sicherheit\MBAM\mbamtray.exe <2>
(Microsoft Corporation -> ) C:\Program Files (x86)\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft) C:\Program Files (x86)\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe <4>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.BingWeather_4.46.23383.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2012.21.0_x64__8wekyb3d8bbwe\Calculator.exe <2>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe <2>
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI.CentralServer.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDKeeper2.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\True Color\MSI.True Color.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControl_Service.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\One Dragon Center\CC_Engine_x64.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\MSI_Super_Charger_Service.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Kommunikation\Firefox\firefox.exe <10>
(ND_Apps -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_1408eaf9a25ed64f\Display.NvContainer\NVDisplay.Container.exe <3>
(Open Source Developer, Dominik Reichl -> Dominik Reichl) C:\Sicherheit\KeePass\KeePass.exe <2>
(Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World) C:\Utility\System\Diagnose\CrystalDiskInfo\DiskInfo64.exe
(Open-Shell) [Datei ist nicht signiert] C:\Utility\System\OpenShell\StartMenu.exe <2>
(PFU Limited) [Datei ist nicht signiert] C:\Utility\PFU\ScanSnap\Driver\PfuSsMon.exe <2>
(PFU LIMITED) [Datei ist nicht signiert] C:\Utility\PFU\ScanSnap\Driver\SSDriver\fi5110\SsWiaChecker.exe <2>
(PFU Limited) [Datei ist nicht signiert] C:\Utility\PFU\ScanSnap\Update\SsUWatcher.exe <2>
(PFU) [Datei ist nicht signiert] C:\Program Files (x86)\PFU\ScanSnapCloud\SSCloud\sCloudWatch.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_d87c47469b47c3f9\RtkAudUService64.exe <3>
(Reiner Kartengeraete GmbH und Co.KG -> REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe <2>
(Ruiware, LLC -> Ruiware) C:\Sicherheit\WinPatrol\WinPatrol.exe <2>
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Sicherheit\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Sicherheit\Spybot - Search & Destroy 2\SDTray.exe <2>
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Sicherheit\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Sicherheit\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Skymatic -> Skymatic UG (haftungsbeschränkt)) C:\Utility\Dateimanagement\Cryptomator\Cryptomator.exe <2>
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_d87c47469b47c3f9\RtkAudUService64.exe [1201448 2020-10-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [DiskMonitor] => C:\Utility\System\Active@ Disk Monitor\DiskMonitor.exe [1400864 2017-08-16] (LSoft Technologies Inc -> LSoft Technologies Inc)
HKLM\...\Run: [Eraser] => C:\Utility\Dateimanagement\Eraser\Eraser.exe [1068624 2020-10-11] (Heidi Computers Ltd -> The Eraser Project)
HKLM\...\Run: [PDF24] => C:\Utility\PDF\PDF24\pdf24.exe [558144 2020-12-15] (geek software GmbH -> geek software GmbH)
HKLM\...\Run: [Open-Shell Start Menu] => C:\Utility\System\OpenShell\StartMenu.exe [216576 2020-09-26] (Open-Shell) [Datei ist nicht signiert]
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Sicherheit\KeePass\KeePass.exe [3137728 2021-01-09] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Utility\System\Partition Master\bin\EpmNews.exe [2089056 2015-09-16] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [Datei ist nicht signiert]
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Utility\PFU\ScanSnap\Driver\SSDriver\fi5110\SsWiaChecker.exe [86016 2016-02-18] (PFU LIMITED) [Datei ist nicht signiert]
HKLM-x32\...\Run: [ScanSnap OnlineUpdate Watcher] => C:\Utility\PFU\ScanSnap\Update\SsUWatcher.exe [454144 2016-09-06] (PFU Limited) [Datei ist nicht signiert]
HKLM-x32\...\Run: [ScanSnap Cloud Watcher] => C:\Program Files (x86)\PFU\ScanSnapCloud\SSCloud\sCloudWatch.exe [114688 2017-04-26] (PFU) [Datei ist nicht signiert]
HKLM-x32\...\Run: [LWS] => C:\Kommunikation\LogitechKamera\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.)
HKLM-x32\...\Run: [TrayProcess] => C:\Utility\Sicherung\Todo Backup\bin\TrayProcess.exe [1410184 2020-12-04] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [Bonus.SSR.FR11] => C:\Utility\ABBYY FineReader 11\Bonus.ScreenshotReader.exe [933640 2012-01-19] (ABBYY SOLUTIONS LIMITED -> ABBYY.)
HKLM-x32\...\Run: [SDTray] => C:\Sicherheit\Spybot - Search & Destroy 2\SDTray.exe [6787856 2019-03-19] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7992336 2021-01-25] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Jabra Direct] => C:\Program Files (x86)\Jabra\Direct4\jabra-direct.exe [106801536 2021-01-19] (GN AUDIO A/S -> GN Audio A/S)
HKU\S-1-5-21-2482742227-2173708982-1626382641-1001\...\Run: [KeePass Password Safe 2] => C:\Sicherheit\KeePass\KeePass.exe [3137728 2021-01-09] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKU\S-1-5-21-2482742227-2173708982-1626382641-1001\...\Run: [Allway Sync] => C:\Utility\Dateimanagement\Allway Sync\Bin\syncappw.exe [52656 2020-12-08] (Botkind, Inc. -> )
HKU\S-1-5-21-2482742227-2173708982-1626382641-1001\...\Run: [WinPatrol] => C:\Sicherheit\WinPatrol\winpatrol.exe [1223560 2017-05-08] (Ruiware, LLC -> Ruiware)
HKU\S-1-5-21-2482742227-2173708982-1626382641-1002\...\Run: [KeePass Password Safe 2] => C:\Sicherheit\KeePass\KeePass.exe [3137728 2021-01-09] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKU\S-1-5-21-2482742227-2173708982-1626382641-1002\...\Run: [Allway Sync] => C:\Utility\Dateimanagement\Allway Sync\Bin\syncappw.exe [52656 2020-12-08] (Botkind, Inc. -> )
HKU\S-1-5-21-2482742227-2173708982-1626382641-1002\...\Run: [WinPatrol] => C:\Sicherheit\WinPatrol\winpatrol.exe [1223560 2017-05-08] (Ruiware, LLC -> Ruiware)
HKLM\...\Windows x64\Print Processors\Canon MP560 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDA0.DLL [28672 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP560 series: C:\Windows\system32\CNMLMA0.DLL [336896 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [252416 2012-08-30] (CANON INC.) [Datei ist nicht signiert]
HKLM\...\Print\Monitors\FRITZ!fax Color Port Monitor: C:\Windows\system32\FritzColorPort64.dll [20480 2006-02-23] () [Datei ist nicht signiert]
HKLM\...\Print\Monitors\FRITZ!fax Port Monitor: C:\Windows\system32\FritzPort64.dll [20480 2006-02-22] () [Datei ist nicht signiert]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\88.0.4324.104\Installer\chrmstp.exe [2021-01-29] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2020-12-23]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk [2020-11-22]
ShortcutTarget: Lotus Organizer EasyClip.lnk -> C:\kommunikation\lotus organizer\easyclip6.exe (Lotus Development Corporation) [Datei ist nicht signiert]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2020-11-28]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Utility\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU Limited) [Datei ist nicht signiert]
Startup: C:\Users\KR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2021-01-25]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\KR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_Verbinde_Cryptomator_KR.lnk [2020-12-28]
ShortcutTarget: _Verbinde_Cryptomator_KR.lnk -> C:\Utility\Batch\_Verbinde_Cryptomator_KR.bat () [Datei ist nicht signiert]
Startup: C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2020-12-29]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_Verbinde_Cryptomator_KRAd.lnk [2020-12-28]
ShortcutTarget: _Verbinde_Cryptomator_KRAd.lnk -> C:\Utility\Batch\_Verbinde_Cryptomator_KRAd.bat () [Datei ist nicht signiert]
GroupPolicyScripts: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0E06D743-940A-4129-8A4A-9E07354A0011} - System32\Tasks\Abelssoft\Abelssoft AntiRansomware_82 => C:\Sicherheit\AntiRansomware\AbLauncher.exe [19248 2021-01-08] (Ascora GmbH -> )
Task: {15C6A397-AC94-4244-B982-F25C8EEF8945} - System32\Tasks\MSI Task Host - LEDKeeper2_Host => C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDKeeper2.exe [1632016 2020-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {23E912BF-974F-4F63-9237-405F30A4A0AE} - System32\Tasks\KR\_Del Temp => C:\Utility\Batch\_del_temp_PCKR5.bat [626 2021-01-05] () [Datei ist nicht signiert]
Task: {248F9C6F-7195-4BA1-B610-1F4597A93B16} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-31] (Google LLC -> Google LLC)
Task: {2D6B6D3F-D4C5-4198-A153-B84F1EE84625} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2020-12-27] (Dropbox, Inc -> Dropbox, Inc.)
Task: {31A93C5D-588D-4429-AFD3-20B3BE9239DF} - System32\Tasks\KR\_Sichern F_Bildschnitt_Input-T aktualisieren => C:\Utility\Dateimanagement\FreeFileSync\FreeFileSync.exe [735792 2021-01-02] (Florian BAUER -> FreeFileSync.org) -> C:\Utility\Batch\F_Bildschnitt_Input-T_akt_SyncSettings.ffs_batch
Task: {340F0A65-FBF4-4D31-A273-4969E8BE477B} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [3047944 2020-10-12] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {3F45AEAC-D489-4C2F-A6A9-F79AE6D55217} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-12-31] (Google LLC -> Google LLC)
Task: {4340BA9A-35FA-4509-A7D8-25B109EDA6FC} - System32\Tasks\Abelssoft\AntiLogger_3 => C:\Sicherheit\AntiLogger\AbLauncher.exe [18736 2020-09-28] (Ascora GmbH -> )
Task: {45256A5F-7713-470C-9C59-278CAB3DCD0D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 56B267BE8061A30D => C:\Kommunikation\Firefox\default-browser-agent.exe do-task
Task: {4533271C-1574-43BC-AC1F-ABEB45312FB4} - System32\Tasks\KR\_Sichern F_Bildschnitt_Output-T spiegel => C:\Utility\Dateimanagement\FreeFileSync\FreeFileSync.exe [735792 2021-01-02] (Florian BAUER -> FreeFileSync.org) -> C:\Utility\Batch\F_Bildschnitt_Output-T_spieg_SyncSettings.ffs_batch
Task: {5021DEC0-3627-4E13-8297-32B9F38396E1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Sicherheit\Spybot - Search & Destroy 2\SDUpdate.exe [7177168 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {542B7CF1-B054-433F-9AC6-1885CC177AB7} - System32\Tasks\MSI Task Host - MSI.True Color => C:\Program Files (x86)\MSI\One Dragon Center\True Color\MSI.True Color.exe [44720 2020-05-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {56D2D2D4-618B-4332-8056-336C0F156861} - System32\Tasks\CCleaner Update => C:\Sicherheit\CCleaner\CCUpdate.exe [686384 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {5BC2A892-575E-4E92-A2FB-0F02139BE7B4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Sicherheit\Spybot - Search & Destroy 2\SDScan.exe [6189624 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {70670872-3D17-473D-AF2B-5B57DE2DE5B0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23563200 2020-12-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {7145747D-E3BD-4408-8175-10DA722917DC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1445840 2021-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {7CE706A7-3A18-43FB-82D5-758BF96F7407} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2020-12-27] (Dropbox, Inc -> Dropbox, Inc.)
Task: {87802523-93BE-44ED-8F0A-0B1888B0E2C9} - System32\Tasks\MSI Task Host - Detect_Monitor => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [74528 2020-09-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {8D89904A-6D27-4B7E-8629-85C4DD12026F} - System32\Tasks\KR\_Sichern Registry ERUNT => C:\Utility\Sicherung\ERUNT\AUTOBACK.EXE [38912 2005-10-20] () [Datei ist nicht signiert] -> T:\PCKR5\Weitere\#Date##Time# sysreg curuser otherusers /noconfirmdelete /noprogresswindow /days:7
Task: {8EB1D8CC-981E-4AFD-BAF4-F89E33F37100} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2282912 2021-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {91E627FE-E4F1-4C71-A109-96D6CD7C43D2} - System32\Tasks\CCleanerSkipUAC => C:\Sicherheit\CCleaner\CCleaner.exe [26896568 2020-12-08] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A2B2373E-8F38-43ED-BC3E-C06706BBF694} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23563200 2020-12-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {A5CEDFCE-6AC0-4A1F-9141-EBBBA5C93BF1} - System32\Tasks\KR\_Sichern F_Bildschnitt_Input-T spiegel => C:\Utility\Dateimanagement\FreeFileSync\FreeFileSync.exe [735792 2021-01-02] (Florian BAUER -> FreeFileSync.org) -> C:\Utility\Batch\F_Bildschnitt_Input-T_spieg_SyncSettings.ffs_batch
Task: {C01D835E-8EC2-4B39-86BC-0FFD9980DBD1} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1445840 2021-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C67DA212-27C1-406A-9DE8-E6A085F71B92} - System32\Tasks\Abelssoft\HackCheck_106 => C:\Sicherheit\HackCheck\AbLauncher.exe [19248 2020-11-19] (Ascora GmbH -> )
Task: {D131B2A2-CB96-4C08-BCAD-0EF93C90974D} - System32\Tasks\MSI Task Host - DisplayID => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [74528 2020-09-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {D68D81AA-B5E6-4A0F-A8CE-F54BCD823DE6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2282912 2021-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {ED26643A-9EEC-4946-BF44-5F4522873CD2} - System32\Tasks\KR\_Sichern F_Bildschnitt_Input-Y => C:\Utility\Dateimanagement\FreeFileSync\FreeFileSync.exe [735792 2021-01-02] (Florian BAUER -> FreeFileSync.org) -> C:\Utility\Batch\F_Bildschnitt_Input-Y_spieg_SyncSettings.ffs_batch
Task: {F1DA16A7-1504-4796-9D8E-487BC7F1F868} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Sicherheit\Spybot - Search & Destroy 2\SDImmunize.exe [5723640 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {F88101E8-05B4-48CA-AA06-6C203D594E1A} - System32\Tasks\KR\_Sichern Registry => C:\Utility\Sicherung\Registry Backup\TweakingRegistryBackup.exe [1471384 2016-11-18] (Tweaking LLC -> Tweaking.com)
Task: {FF595491-8935-40EE-9B57-4E6CF168F260} - System32\Tasks\CrystalDiskInfo => C:\Utility\System\Diagnose\CrystalDiskInfo\DiskInfo64.exe [2762352 2020-11-22] (Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\windows\explorer.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33d62ac7-4aad-4af3-a10f-a17be82967d1}: [DhcpNameServer] 192.168.178.1
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,192.168.178.22,1]
Edge:
=======
Edge Profile: C:\Users\KR Admin\AppData\Local\Microsoft\Edge\User Data\Default [2021-01-31]
Edge HKU\S-1-5-21-2482742227-2173708982-1626382641-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKU\S-1-5-21-2482742227-2173708982-1626382641-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
FireFox:
========
FF DefaultProfile: 4bebz82y.default
FF ProfilePath: C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4bebz82y.default [2021-01-28]
FF ProfilePath: C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\45091fq3.default-esr-1609489461695 [2021-01-01]
FF Homepage: Mozilla\Firefox\Profiles\45091fq3.default-esr-1609489461695 -> hxxp://www.t-online.de/
FF ProfilePath: C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1 [2021-01-31]
FF Homepage: Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1 -> hxxp://www.t-online.de/
FF Extension: (Disconnect) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\2.0@disconnect.me.xpi [2021-01-01]
FF Extension: (HTTPS Everywhere) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\https-everywhere@eff.org.xpi [2021-01-31]
FF Extension: (Auto-Sort Bookmarks) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\sortbookmarks@bouanto.xpi [2021-01-01]
FF Extension: (uBlock Origin) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\uBlock0@raymondhill.net.xpi [2021-01-05]
FF Extension: (NoScript) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-01-28]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\KR Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8gbe0b5j.default-esr-1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-01-31]
FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\FFExt\light_plugin_firefox\addon.xpi => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\FFExt\light_plugin_firefox\addon.xpi => nicht gefunden
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\UTILITY\PDF\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\UTILITY\PDF\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\UTILITY\PDF\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\UTILITY\PDF\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\UTILITY\PDF\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
StartMenuInternet: Firefox-56B267BE8061A30D - C:\Kommunikation\Firefox\firefox.exe
Chrome:
=======
CHR Profile: C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default [2021-01-01]
CHR Extension: (Präsentationen) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-12-31]
CHR Extension: (Docs) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-12-31]
CHR Extension: (Google Drive) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-12-31]
CHR Extension: (YouTube) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-12-31]
CHR Extension: (Kaspersky Protection) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\elhpdacimkjpccooodognopfhbdgnpbk [2020-12-31]
CHR Extension: (Tabellen) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-12-31]
CHR Extension: (Google Docs Offline) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-12-31]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-12-31]
CHR Extension: (Google Mail) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-12-31]
CHR Extension: (Chrome Media Router) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-31]
CHR Extension: (think-cell) - C:\Users\KR Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcdkdcafnbklehdngbhmhpidandcjke [2020-12-31]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ppcdkdcafnbklehdngbhmhpidandcjke]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 2C6YWNOUEFLYRNDJMHUNQS4XLSPTFCBV; C:\Program Files (x86)\think-cell\tcupdate.exe [3269704 2021-01-27] (think-cell Operations GmbH -> think-cell Operations GmbH)
R3 ARWWatcherService; C:\ProgramData\Abelssoft\AntiRansomware\Program\ARWWatcherService.exe [22320 2021-01-08] (Ascora GmbH -> )
R2 AVP21.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\avp.exe [381928 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 BotkindSyncService; C:\Utility\Dateimanagement\Allway Sync\Bin\SyncService.exe [264192 2020-12-08] () [Datei ist nicht signiert]
R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [623880 2020-11-07] (cFos Software GmbH -> cFos Software GmbH)
R2 cjpcsc; C:\windows\SysWOW64\cjpcsc.exe [619464 2020-07-27] (Reiner Kartengeraete GmbH und Co.KG -> REINER SCT)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9482688 2020-12-31] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2020-12-27] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2020-12-27] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [44064 2021-01-25] (Dropbox, Inc -> Dropbox, Inc.)
R2 EaseUS Agent; C:\Utility\Sicherung\Todo Backup\bin\Agent.exe [43656 2020-12-04] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
R2 FoxitReaderUpdateService; C:\UTILITY\PDF\FOXIT READER\FoxitReaderUpdateService.exe [2357936 2020-11-23] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S3 klvssbridge64_21.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.2\x64\vssbridge64.exe [467352 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 KSDE5.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.2\ksde.exe [644264 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 LightKeeperService; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe [86776 2020-11-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MagentaCLOUDMaintenanceService; C:\Program Files (x86)\Telekom\MagentaCloud\Updater\MaintenanceService.exe [947632 2020-09-08] (Deutsche Telekom AG -> Deutsche Telekom AG)
R2 MBAMService; C:\Sicherheit\MBAM\MBAMService.exe [7456464 2021-01-28] (Malwarebytes Inc -> Malwarebytes)
R2 MSI_Central_Service; C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe [147088 2020-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 MSI_Companion_Service; C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe [122616 2020-10-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI_Super_Charger_Service; C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\MSI_Super_Charger_Service.exe [31504 2020-09-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R2 Mystic_Light_Service; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe [35504 2020-07-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 PDF24; C:\Utility\PDF\PDF24\pdf24.exe [558144 2020-12-15] (geek software GmbH -> geek software GmbH)
R2 RtkAudioUniversalService; C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_d87c47469b47c3f9\RtkAudUService64.exe [1201448 2020-10-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 SandraAgentSrv; C:\Utility\System\Diagnose\SiSoftware Sandra Lite 2020\RpcAgentSrv.exe [137736 2020-12-06] (SiSoftware SPC -> SiSoftware) [Datei ist nicht signiert]
R2 SDScannerService; C:\Sicherheit\Spybot - Search & Destroy 2\SDFSSvc.exe [2747312 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Sicherheit\Spybot - Search & Destroy 2\SDUpdSvc.exe [4583240 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Sicherheit\Spybot - Search & Destroy 2\SDWSCSvc.exe [940976 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 TeamViewer; C:\Utility\System\Teamviewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 VoiceControlService; C:\Program Files (x86)\MSI\One Dragon Center\VoiceControl\VoiceControl_Service.exe [32400 2020-07-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R3 VssEaseusProvider; C:\windows\system32\dllhost.exe /Processid:{482A0AB7-22FE-41E8-80D7-8BB99B48BF43} [21312 2020-11-21] (Microsoft Windows -> Microsoft Corporation)
R3 VssEaseusProvider; C:\windows\system32\dllhost.exe /Processid:{482A0AB7-22FE-41E8-80D7-8BB99B48BF43} [21312 2020-11-21] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_1408eaf9a25ed64f\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvmd.inf_amd64_1408eaf9a25ed64f\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 cFosSpeed; C:\Windows\system32\DRIVERS\cfosspeed6.sys [1804072 2020-11-06] (cFos Software GmbH -> cFos Software GmbH)
R3 cjusb; C:\Windows\System32\drivers\cjusb.sys [43224 2017-03-28] (REINER Kartengeraete GmbH & Co. KG -> REINER SCT)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [251608 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 dokan1; C:\Windows\System32\DRIVERS\dokan1.sys [104752 2019-03-08] (D3L -> Dokan Project)
R1 EneTechIo; C:\Windows\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [Datei ist nicht signiert]
R0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [74296 2020-11-27] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EUBAKUP0; C:\windows\system32\drivers\EUBAKUP0.sys [74296 2020-11-27] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [53304 2020-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 EUBKMON0; C:\windows\system32\drivers\EUBKMON0.sys [53304 2020-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [22784 2020-02-24] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [341760 2020-02-24] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EUFDDISK0; C:\windows\system32\drivers\EUFDDISK0.sys [341760 2020-02-24] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EuFdMount; C:\Utility\Sicherung\Todo Backup\drv\EuFdMount.sys [22072 2020-10-30] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [Datei ist nicht signiert]
S3 JabraDFU; C:\Windows\System32\Drivers\JabraBcDfuX64.sys [54408 2018-03-20] (GN Netcom A/S -> QTI Ltd)
R1 klbackupdisk; C:\Windows\system32\DRIVERS\klbackupdisk.sys [110392 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [212280 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [127288 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [37496 2020-10-21] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\Windows\system32\DRIVERS\klflt.sys [523576 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [659768 2020-12-25] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1341232 2020-12-25] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.2\Bases\klids.sys [244784 2021-01-28] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1025336 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [95544 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [113464 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [113464 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [85288 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [97080 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\drivers\kltap.sys [55592 2020-10-21] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [257208 2020-12-23] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [99152 2020-12-23] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [310232 2021-01-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [116888 2021-01-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [207352 2020-12-23] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [153400 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [250168 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [300856 2020-10-21] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [220160 2021-01-31] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2021-01-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248992 2021-01-28] (Malwarebytes Inc -> Malwarebytes)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [18448 2019-10-17] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 NTIOLib_CC_COMM; C:\Program Files (x86)\MSI\One Dragon Center\Lib\SYS\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_CC_CPU; C:\Program Files (x86)\MSI\One Dragon Center\Super_Charger\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_MysticLight; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Lib\NTIOLib_X64.sys [14288 2017-07-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 SANDRA; C:\Utility\System\Diagnose\SiSoftware Sandra Lite 2020\WNt600x64\Sandra.sys [23112 2009-08-07] (SiSoftware Ltd -> SiSoftware)
S0 Spybot3ELAM; C:\Windows\System32\drivers\Spybot3ELAM.sys [19904 2019-06-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Windows (R) Win 7 DDK provider)
R1 UimBus; C:\Windows\System32\drivers\UimBus.sys [102664 2014-11-28] (Paragon Software GmbH -> )
R1 Uim_DEVIM; C:\Windows\System32\drivers\uim_devim.sys [25992 2014-11-28] (Paragon Software GmbH -> )
R1 Uim_IM; C:\Windows\System32\drivers\uim_im.sys [700424 2014-11-28] (Paragon Software GmbH -> )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2020-12-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2020-12-20] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-20] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-01-31 16:30 - 2021-01-31 16:31 - 000000000 ____D C:\FRST
2021-01-31 15:44 - 2021-01-31 15:44 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\IcoFX
2021-01-31 15:26 - 2021-01-31 15:26 - 000220160 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2021-01-31 14:14 - 2021-01-31 14:14 - 000000000 ____D C:\ProgramData\MagentaCloud
2021-01-31 14:14 - 2021-01-31 14:14 - 000000000 ____D C:\Program Files (x86)\Telekom
2021-01-30 18:52 - 2021-01-30 18:52 - 001333760 _____ C:\Windows\SysWOW64\TextInputMethodFormatter.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000729600 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2021-01-30 18:52 - 2021-01-30 18:52 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000581120 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2021-01-30 18:52 - 2021-01-30 18:52 - 000575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
2021-01-30 18:52 - 2021-01-30 18:52 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2021-01-30 18:52 - 2021-01-30 18:52 - 000469504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000467968 _____ C:\Windows\system32\AssignedAccessCsp.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000455680 _____ C:\Windows\SysWOW64\WindowManagementAPI.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000446976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000304128 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2021-01-30 18:52 - 2021-01-30 18:52 - 000234496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2021-01-30 18:52 - 2021-01-30 18:52 - 000178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2021-01-30 18:52 - 2021-01-30 18:52 - 000157184 _____ C:\Windows\system32\uwfcsp.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000138056 _____ C:\Windows\system32\HvsiManagementApi.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2021-01-30 18:52 - 2021-01-30 18:52 - 000101704 _____ C:\Windows\SysWOW64\HvsiManagementApi.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000095744 _____ C:\Windows\system32\VirtualMonitorManager.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2021-01-30 18:52 - 2021-01-30 18:52 - 000084992 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2021-01-30 18:52 - 2021-01-30 18:52 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2021-01-30 18:52 - 2021-01-30 18:52 - 000067072 _____ C:\Windows\system32\BWContextHandler.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000053760 _____ C:\Windows\SysWOW64\BWContextHandler.dll
2021-01-30 18:52 - 2021-01-30 18:52 - 000010894 _____ C:\Windows\system32\DrtmAuthTxt.wim
2021-01-30 18:51 - 2021-01-30 18:51 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 002254336 _____ C:\Windows\system32\dwmscene.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 001162240 _____ C:\Windows\system32\MBR2GPT.EXE
2021-01-30 18:51 - 2021-01-30 18:51 - 000643072 _____ C:\Windows\system32\WindowManagementAPI.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000562688 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2021-01-30 18:51 - 2021-01-30 18:51 - 000544768 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2021-01-30 18:51 - 2021-01-30 18:51 - 000455168 _____ C:\Windows\system32\ssdm.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000422912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2021-01-30 18:51 - 2021-01-30 18:51 - 000330752 _____ C:\Windows\SysWOW64\ssdm.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000306688 _____ C:\Windows\system32\HeatCore.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2021-01-30 18:51 - 2021-01-30 18:51 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2021-01-30 18:51 - 2021-01-30 18:51 - 000235520 _____ C:\Windows\SysWOW64\HeatCore.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000190976 _____ C:\Windows\system32\BthpanContextHandler.dll
2021-01-30 18:51 - 2021-01-30 18:51 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2021-01-30 18:51 - 2021-01-30 18:51 - 000165888 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2021-01-30 18:51 - 2021-01-30 18:51 - 000152064 _____ C:\Windows\system32\EoAExperiences.exe
2021-01-30 18:51 - 2021-01-30 18:51 - 000074240 _____ C:\Windows\system32\rdsxvmaudio.dll
2021-01-30 14:33 - 2021-01-30 14:34 - 000000000 ____D C:\Program Files (x86)\think-cell
2021-01-28 13:04 - 2021-01-28 13:04 - 000248992 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2021-01-28 13:04 - 2021-01-28 13:04 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2021-01-28 13:04 - 2021-01-28 13:04 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2021-01-25 17:12 - 2021-01-25 17:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2021-01-25 17:12 - 2021-01-25 17:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2021-01-25 17:12 - 2021-01-25 17:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2021-01-25 17:12 - 2021-01-25 17:12 - 000044064 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2021-01-24 12:37 - 2021-01-24 12:37 - 000115254 _____ C:\Users\Public\size_after.bmp
2021-01-21 14:06 - 2021-01-21 14:06 - 000310232 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2021-01-21 14:05 - 2021-01-21 14:05 - 000116888 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys
2021-01-12 09:21 - 2021-01-12 09:21 - 000000000 ___HD C:\Users\KR Admin\ zAnti Ransomeware Honeypot
2021-01-12 09:21 - 2021-01-12 09:21 - 000000000 ___HD C:\Users\KR Admin\AppData\Roaming\ zAnti Ransomeware Honeypot
2021-01-12 09:21 - 2021-01-12 09:21 - 000000000 ___HD C:\Users\KR Admin\AppData\Roaming\ ! Anti Ransomeware Honeypot
2021-01-12 09:21 - 2021-01-12 09:21 - 000000000 ___HD C:\Users\KR Admin\ ! Anti Ransomeware Honeypot
2021-01-11 18:48 - 2021-01-11 18:48 - 000000000 ____D C:\Users\KR\AppData\Roaming\Zoom
2021-01-09 15:19 - 2021-01-09 15:19 - 000000000 ____D C:\Users\KR\AppData\Roaming\WinRAR
2021-01-05 18:16 - 2021-01-31 14:20 - 000000000 ____D C:\ProgramData\AlfBanCo7
2021-01-05 18:16 - 2021-01-05 18:40 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\ALFBanCo7
2021-01-05 18:16 - 2016-11-12 20:32 - 000876504 _____ (Xceed Software Inc (450) 442-2626 support@xceedsoft.com www.xceedsoft.com) C:\Windows\SysWOW64\SmartUI2.ocx
2021-01-05 18:16 - 2002-09-27 17:47 - 000442368 _____ (ComponentOne) C:\Windows\SysWOW64\vsflex7l.ocx
2021-01-05 18:16 - 2001-02-07 15:17 - 001066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.1
2021-01-05 18:16 - 2000-10-01 23:00 - 000125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL
2021-01-05 18:16 - 2000-05-21 23:00 - 001066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2021-01-05 18:16 - 2000-05-21 23:00 - 000647872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2021-01-05 18:16 - 2000-05-21 23:00 - 000140488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2021-01-05 18:16 - 1998-07-05 23:00 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL
2021-01-05 18:16 - 1998-07-05 23:00 - 000033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CmDlgDE.dll
2021-01-05 18:16 - 1998-07-05 19:00 - 000158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL
2021-01-05 10:09 - 2021-01-31 11:40 - 000004096 ___SH C:\{CED5AD40-FF97-4E5E-873D-1F4CC6DBB435}.CBM
2021-01-05 10:02 - 2021-01-31 11:39 - 000359424 ___SH C:\EUMONBMP.SYS
2021-01-04 12:24 - 2021-01-01 09:29 - 000000912 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Firefox.lnk
2021-01-04 12:23 - 2020-12-26 15:43 - 000001111 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Allway Sync.lnk
2021-01-04 12:22 - 2020-11-22 07:27 - 000001910 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Cryptomator.lnk
2021-01-04 12:22 - 2019-12-07 10:08 - 000000407 _____ C:\ProgramData\Microsoft\Windows\Start Menu\File Explorer.lnk
2021-01-03 17:41 - 2020-12-02 05:25 - 001769688 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-03 17:41 - 2020-12-02 05:25 - 001769688 _____ C:\Windows\system32\vulkaninfo.exe
2021-01-03 17:41 - 2020-12-02 05:25 - 001370328 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-03 17:41 - 2020-12-02 05:25 - 001370328 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-01-03 17:41 - 2020-12-02 05:25 - 001054944 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-01-03 17:41 - 2020-12-02 05:25 - 001054944 _____ C:\Windows\system32\vulkan-1.dll
2021-01-03 17:41 - 2020-12-02 05:25 - 000917720 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-03 17:41 - 2020-12-02 05:25 - 000917720 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-01-03 17:41 - 2020-12-02 05:25 - 000456600 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-01-03 17:41 - 2020-12-02 05:25 - 000349936 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-01-03 17:41 - 2020-12-02 05:23 - 001027992 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2021-01-03 17:41 - 2020-12-02 05:23 - 000674712 _____ C:\Windows\system32\nvofapi64.dll
2021-01-03 17:41 - 2020-12-02 05:23 - 000543128 _____ C:\Windows\SysWOW64\nvofapi.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 002096880 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 001585560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 001507224 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 001159920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000816368 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000813464 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000670616 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000656112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000590576 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2021-01-03 17:41 - 2020-12-02 05:22 - 000556440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2021-01-03 17:41 - 2020-12-02 05:22 - 000047240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2021-01-03 17:41 - 2020-12-02 05:21 - 007706352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2021-01-03 17:41 - 2020-12-02 05:21 - 006860184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2021-01-03 17:41 - 2020-12-02 05:21 - 004175256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2021-01-03 17:41 - 2020-12-02 05:21 - 002508528 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2021-01-03 17:41 - 2020-12-02 05:21 - 000849648 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2021-01-03 17:41 - 2020-12-02 05:21 - 000445848 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2021-01-03 17:41 - 2020-12-02 04:52 - 000080930 _____ C:\Windows\system32\nvinfo.pb
2021-01-03 17:11 - 2021-01-03 17:11 - 000000239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2021-01-03 16:30 - 2021-01-03 16:30 - 000081354 _____ C:\Windows\cFosSpeed_Setup_Log.txt
2021-01-03 16:30 - 2021-01-03 16:30 - 000003216 _____ C:\Windows\system32\Tasks\MSI Task Host - MSI.True Color
2021-01-03 16:30 - 2021-01-03 16:30 - 000003190 _____ C:\Windows\system32\Tasks\MSI Task Host - LEDKeeper2_Host
2021-01-03 16:30 - 2021-01-03 16:30 - 000000000 ____D C:\Program Files\ENE
2021-01-03 16:30 - 2021-01-03 16:30 - 000000000 ____D C:\Program Files (x86)\ENE
2021-01-03 16:30 - 2021-01-03 16:30 - 000000000 ____D C:\MSI
2021-01-03 16:30 - 2020-11-06 17:43 - 001804072 _____ (cFos Software GmbH) C:\Windows\system32\Drivers\cfosspeed6.sys
2021-01-03 16:30 - 2020-05-12 01:28 - 000020992 _____ C:\Windows\system32\Drivers\ene.sys
2021-01-03 15:22 - 2021-01-31 15:26 - 000008192 ___SH C:\DumpStack.log.tmp
2021-01-01 16:59 - 2021-01-01 17:19 - 000000000 ___HD C:\$WINDOWS.~BT
2021-01-01 16:31 - 2021-01-01 17:19 - 000001908 _____ C:\Windows\diagwrn.xml
2021-01-01 16:31 - 2021-01-01 17:19 - 000001908 _____ C:\Windows\diagerr.xml
2021-01-01 15:33 - 2021-01-01 15:33 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\NVIDIA
2021-01-01 15:26 - 2020-12-05 01:57 - 019546112 _____ C:\Users\KR Admin\AppData\Roaming\Sandra.mdb
2021-01-01 12:51 - 2021-01-03 16:36 - 000000000 ___RD C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zubehör
2021-01-01 12:48 - 2021-01-01 12:50 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Utilities
2021-01-01 12:37 - 2021-01-28 09:50 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System
2021-01-01 12:34 - 2021-01-01 12:36 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sicherheit
2021-01-01 12:09 - 2021-01-01 14:26 - 000000000 _____ C:\Windows\BcdLog.txt
2021-01-01 09:29 - 2021-01-01 09:29 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-01-31 16:30 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Registration
2021-01-31 16:26 - 2020-12-26 18:00 - 000000000 ____D C:\Users\KR\AppData\Roaming\Jabra Direct
2021-01-31 16:26 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-31 16:03 - 2020-11-22 17:58 - 000000000 ____D C:\Users\KR Admin\AppData\LocalLow\Mozilla
2021-01-31 15:46 - 2020-12-26 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphik
2021-01-31 15:39 - 2020-12-22 20:12 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\XnView
2021-01-31 15:36 - 2020-11-29 16:54 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Jabra Direct
2021-01-31 15:35 - 2020-12-26 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multimedia
2021-01-31 15:35 - 2020-11-22 18:34 - 000000000 ____D C:\Windows\system32\Tasks\Abelssoft
2021-01-31 15:35 - 2020-11-22 07:28 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Cryptomator
2021-01-31 15:34 - 2020-11-21 14:29 - 000000000 ____D C:\ProgramData\NVIDIA
2021-01-31 15:33 - 2020-11-21 14:02 - 001723220 _____ C:\Windows\system32\PerfStringBackup.INI
2021-01-31 15:33 - 2019-12-07 15:51 - 000743818 _____ C:\Windows\system32\perfh007.dat
2021-01-31 15:33 - 2019-12-07 15:51 - 000150240 _____ C:\Windows\system32\perfc007.dat
2021-01-31 15:33 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2021-01-31 15:26 - 2020-12-27 14:43 - 000000000 ____D C:\Users\KR\AppData\Roaming\Cryptomator
2021-01-31 15:26 - 2020-09-27 08:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-01-31 15:25 - 2020-12-26 18:31 - 000000000 ____D C:\Users\KR\AppData\LocalLow\Mozilla
2021-01-31 15:25 - 2020-12-26 18:08 - 000000000 ____D C:\Users\KR\AppData\Roaming\KeePass
2021-01-31 15:25 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\system32\config\BBI
2021-01-31 13:19 - 2020-09-27 06:33 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-01-31 12:15 - 2020-11-21 15:10 - 000004154 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{74F517A4-A288-4B07-8A43-4DCBB7E60D0D}
2021-01-31 12:11 - 2020-09-27 06:33 - 000450320 _____ C:\Windows\system32\FNTCACHE.DAT
2021-01-31 12:11 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2021-01-31 12:10 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-01-31 12:10 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-01-31 12:10 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\UNP
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\F12
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\PrintDialog
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Sysprep
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\setup
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\oobe
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Dism
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\Com
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Provisioning
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\IME
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2021-01-31 12:10 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-01-31 12:08 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2021-01-31 11:39 - 2020-11-21 18:59 - 000000000 ____D C:\Windows\system32\config\regsave
2021-01-30 18:51 - 2020-09-27 08:35 - 002877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2021-01-30 11:48 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-29 17:44 - 2020-12-26 16:23 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System
2021-01-29 17:43 - 2020-12-26 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sicherheit
2021-01-29 17:26 - 2020-11-15 17:11 - 000000000 ____D C:\Kommunikation
2021-01-28 13:18 - 2019-12-07 10:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2021-01-28 13:07 - 2020-11-29 15:58 - 000000000 ____D C:\Users\KR Admin\AppData\LocalLow\IGDump
2021-01-28 13:04 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2021-01-28 13:03 - 2020-10-17 18:07 - 000000000 ____D C:\Sicherheit
2021-01-28 09:45 - 2020-11-29 16:53 - 000000000 ____D C:\Program Files (x86)\Jabra
2021-01-28 09:45 - 2020-11-21 17:06 - 000000000 ____D C:\ProgramData\Package Cache
2021-01-27 11:50 - 2020-12-27 16:55 - 000000000 ____D C:\Program Files (x86)\Dropbox
2021-01-22 16:06 - 2020-12-26 17:59 - 000000000 ____D C:\Users\KR
2021-01-22 14:58 - 2020-12-27 16:55 - 000001226 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2021-01-22 14:58 - 2020-12-27 16:55 - 000001222 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2021-01-22 09:08 - 2020-12-27 16:55 - 000004286 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineUA
2021-01-22 09:08 - 2020-12-27 16:55 - 000004054 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineCore
2021-01-22 09:08 - 2020-11-21 16:32 - 000799104 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2021-01-21 09:40 - 2020-12-26 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kommunikation
2021-01-21 09:35 - 2020-12-26 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS Office
2021-01-18 19:12 - 2020-12-10 20:01 - 000003700 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-01-18 19:12 - 2020-12-10 20:01 - 000003576 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-01-15 09:59 - 2020-11-21 22:49 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-01-15 09:54 - 2020-11-21 18:48 - 000000000 ____D C:\Windows\system32\MRT
2021-01-15 09:53 - 2020-11-21 18:48 - 135062968 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-01-14 10:42 - 2020-12-26 18:00 - 000000000 ____D C:\Users\KR\AppData\Roaming\PFU
2021-01-12 19:20 - 2020-11-22 18:39 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2021-01-12 19:20 - 2020-11-22 18:39 - 000000000 ____D C:\Program Files\Common Files\AV
2021-01-12 19:20 - 2020-11-22 18:39 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2021-01-12 19:19 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\LiveKernelReports
2021-01-12 09:21 - 2020-11-21 14:23 - 000000000 ____D C:\Users\KR Admin
2021-01-12 09:20 - 2020-11-22 18:34 - 000000000 ____D C:\ProgramData\Abelssoft
2021-01-11 11:05 - 2020-12-18 10:03 - 000000048 _____ C:\Windows\SysWOW64\EUTB.TODI
2021-01-09 15:10 - 2020-12-29 12:34 - 000000000 ____D C:\Users\KR\AppData\Roaming\Foxit Software
2021-01-05 17:57 - 2020-11-22 17:46 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\FreeFileSync
2021-01-04 13:03 - 2020-12-26 18:55 - 000000000 ____D C:\Users\KR\AppData\Roaming\IrfanView
2021-01-03 17:41 - 2020-11-21 14:29 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2021-01-03 16:52 - 2020-12-26 16:23 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zubehör
2021-01-03 16:30 - 2020-11-21 17:07 - 000000000 ____D C:\Program Files\cFosSpeed
2021-01-01 17:06 - 2020-11-21 13:54 - 000000000 ____D C:\Windows\Panther
2021-01-01 14:47 - 2020-11-21 18:38 - 000006656 _____ C:\Windows\system32\lpcio.dll
2021-01-01 14:30 - 2020-11-21 15:16 - 000002266 ____H C:\Windows\EPMBatch.ept
2021-01-01 13:23 - 2020-11-22 17:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-01-01 13:18 - 2019-12-07 10:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2021-01-01 12:50 - 2020-12-26 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
2021-01-01 10:28 - 2020-11-22 19:57 - 000000000 ____D C:\ProgramData\Foxit Software
2021-01-01 10:27 - 2020-11-22 19:57 - 000000000 ____D C:\Users\KR Admin\AppData\Roaming\Foxit Software
2021-01-01 09:25 - 2020-11-22 17:58 - 000000000 ____D C:\ProgramData\Mozilla
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2021-01-01 15:26 - 2020-12-05 01:57 - 019546112 _____ () C:\Users\KR Admin\AppData\Roaming\Sandra.mdb
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
LastRegBack: 2021-01-30 13:43
==================== Ende von FRST.txt ======================== |