Individuum | 26.08.2021 19:11 | Verdacht auf befall von Trojanern allo Liebe Community,
des öfteren bin ich schon hier gelandet wenn ich mir eine Malware oder sonstiges eingefangen hatte und konnte bisher immer etwas daraus ziehen. Nun sind mir in letzter Zeit immerwieder konten von spotify, mojang, gmail, microsoft durch dubiose ip adressen oder aus komischen Ländern abhanden gekommen, die ich dann recovern musste. Ich habe nun meine E-mail konten zwei faktor gesichert, knapp 150 PW geändert, eine neue e-mail bei der ich mir sicher bin das sie clean ist angelegt und bin nun an meiner Hardware und meinen Lokalen daten angelangt, Malwarebytes scan habe ich im vorfeld schon durchgeführt, Malwarebytes hat 26 Bedrohungen gefunden und in die Quarantäne verschoben, unter anderem Trojaner usw. Hier die Log dateien auch aus FRST.exe wie in der Anleitung beschrieben. Könnt Ihr mir helfen ? bin ich nun wieder befreit von datenlecks ? Ich hatte wohl auf meiner haupt email auch einen datenbruch der schon bis 2018 zurückliegt, kann das noch etwas damit zu tun gehabt haben Um Hilfe wäre ich sehr Dankbar da doch schon eineiges an Wert auf meinem Kasten liegt...
Liebe Grüße
Individuum Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 26.08.21
Scan-Zeit: 18:51
Protokolldatei: d12be10e-068d-11ec-869c-704d7b2db4bc.json
-Softwaredaten-
Version: 4.4.5.130
Komponentenversion: 1.0.1430
Version des Aktualisierungspakets: 1.0.44396
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19043.1165)
CPU: x64
Dateisystem: NTFS
Benutzer: MisterSun\termi
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 396398
Erkannte Bedrohungen: 26
In die Quarantäne verschobene Bedrohungen: 26
Abgelaufene Zeit: 3 Min., 2 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 3
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Microsoft\Windows\Application Experience\StartupCheckLibrary, In Quarantäne, 511, 735770, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C50DFF3E-8F20-4749-A24E-AA59C96107F1}, In Quarantäne, 511, 735770, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{C50DFF3E-8F20-4749-A24E-AA59C96107F1}, In Quarantäne, 511, 735770, , , , , ,
Registrierungswert: 1
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C50DFF3E-8F20-4749-A24E-AA59C96107F1}|PATH, In Quarantäne, 511, 782993, 1.0.44396, , ame, , ,
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 4
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 201, 838845, , , , , ,
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 201, 838845, , , , , ,
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 201, 838845, , , , , ,
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 201, 838845, , , , , ,
Datei: 18
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\APPLICATION EXPERIENCE\STARTUPCHECKLIBRARY, In Quarantäne, 511, 735770, 1.0.44396, , ame, , FACF73072EAFE24D954582146EBC25B6, B89F446D662E4FA1D4536684EA547705E593289BE8790B5F260FA7322444706A
Legit.MisusedLegit, C:\USERS\TERMI\APPDATA\LOCALLOW\pF2qC1gG7yH8hI1o\mozglue.dll, In Quarantäne, 3838, 965519, 1.0.44396, , ame, , EAE9273F8CDCF9321C6C37C244773139, A0C6630D4012AE0311FF40F4F06911BCF1A23F7A4762CE219B8DFFA012D188CC
Legit.MisusedLegit, C:\USERS\TERMI\APPDATA\LOCALLOW\pF2qC1gG7yH8hI1o\nss3.dll, In Quarantäne, 3838, 965520, 1.0.44396, , ame, , 02CC7B8EE30056D5912DE54F1BDFC219, 1989526553FD1E1E49B0FEA8036822CA062D3D39C4CAB4A37846173D0F1753D5
Malware.AI.1144860452, C:\WINDOWS\SYSTEM32\SERVICEINSTALLER.EXE, In Quarantäne, 1000000, 0, 1.0.44396, 79BBCFD409ED690A443D2F24, dds, 01394704, 9EB407C77C44D6D7876244CF35C0D4AA, FFED5BEA3B2367946ECCF950A55BC160477E2FECFB0D8D5093818377DDDE9D46
PUP.Optional.GameHack, C:\PROGRAM FILES\CHEAT ENGINE 7.2\STANDALONEPHASE1.DAT, In Quarantäne, 8232, 393793, 1.0.44396, , ame, , EB339EECEC8AA8C0FD3B08D39799D4D8, 88BB94C3CE727DB13B77ABDBDB75A4C878E91D651692F3618178DEC5BBB7080C
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, In Quarantäne, 201, 838845, , , , , A46D9C897799D5ED54492B0359FF945E, 42851A1D8751AB9C3D385A74B20658F878249359090CC6D2175C5FDA26C48B75
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\001137.ldb, In Quarantäne, 201, 838845, , , , , FB155396408472111190DBA065DD36E0, 927752FE4F5724B163BD1F1969302F1F26AD203EBCD3DFBF454E4BBC53CA33AE
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\001139.log, In Quarantäne, 201, 838845, , , , , D91A6C9B09A5C62F6B931336B985235A, DDF18834F1F7D3D80397FBEFB15C96853BF86FC70A1B41F33A6BEDF1469B3D73
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\001140.ldb, In Quarantäne, 201, 838845, , , , , 3E8EC8DBEA26347E7E8FCBBC58D4BAF3, 3B7260307D0FFBF694762EB9947A143E98114DCF6A767088AB7A5D635FEA8F0D
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, In Quarantäne, 201, 838845, , , , , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, In Quarantäne, 201, 838845, , , , , ,
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, In Quarantäne, 201, 838845, , , , , E09D468E77E3BA96B408163DA8B421A5, 904D4015142B9CF0D2B715E783E089BFD853D4B4A1A1BD43321EC49E89AA5FC2
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, In Quarantäne, 201, 838845, , , , , 419BBB23864293240D83BE9EC61AAEAC, 489B8658A820D941535F9BF367A07D9646A9F65180E9CF8FC35C93BAE9E33BC4
PUP.Optional.PushNotifications.Generic, C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, In Quarantäne, 201, 838845, , , , , BF5017FBE7ED2C4B6A789667F1E408BD, 437B11DF4FB31D1B130C24D6E9B2A959A421F12ACD8586CA15A4A94A4A2F7D2A
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 201, 838845, 1.0.44396, , ame, , BF4751B30B48DEAC1E90EC20EB51DB0B, 41A8F8BAD3B7203EFC32FFFA114A4C1F2B3400B5A98D4AC233B70919E91B559B
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 201, 838845, 1.0.44396, , ame, , BF4751B30B48DEAC1E90EC20EB51DB0B, 41A8F8BAD3B7203EFC32FFFA114A4C1F2B3400B5A98D4AC233B70919E91B559B
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 201, 838845, 1.0.44396, , ame, , BF4751B30B48DEAC1E90EC20EB51DB0B, 41A8F8BAD3B7203EFC32FFFA114A4C1F2B3400B5A98D4AC233B70919E91B559B
PUP.Optional.PushNotifications.Generic, C:\USERS\TERMI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 201, 838845, 1.0.44396, , ame, , BF4751B30B48DEAC1E90EC20EB51DB0B, 41A8F8BAD3B7203EFC32FFFA114A4C1F2B3400B5A98D4AC233B70919E91B559B
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) [CODE]FRST:
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2021
durchgeführt von termi (Administrator) auf MISTERSUN (26-08-2021 19:44:58)
Gestartet von C:\Users\termi\Desktop
Geladene Profile: termi
Platform: Windows 10 Home Version 21H1 19043.1165 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Opera
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avscan.exe <2>
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\protectedservice.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.UI.Application.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(Comfort Software Group -> Comfort Software Group) C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler64.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a086f01cc7be643a\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a086f01cc7be643a\IntelCpHeciSvc.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\NVDisplay.Container.exe <2>
(Opera Software AS -> Opera Software) C:\Users\termi\AppData\Local\Programs\Opera GX\78.0.4093.153\opera.exe <57>
(Opera Software AS -> Opera Software) C:\Users\termi\AppData\Local\Programs\Opera GX\78.0.4093.153\opera_crashreporter.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(Swift Media Entertainment, Inc. -> Blitz, Inc.) C:\Users\termi\AppData\Local\Programs\Blitz\Blitz.exe <8>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Unified Intents AB -> Unified Intents AB) C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [835136 2018-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-12-09] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [114824 2020-09-14] (Adobe Inc. -> )
HKLM-x32\...\Run: [Avira Security startup helper] => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [255968 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [330440 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Discord] => C:\Users\termi\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4110568 2021-07-21] (Valve -> Valve Corporation)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [408920 2021-04-21] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [vibranceGUI] => "C:\Users\termi\AppData\Local\Temp\Rar$EXa3644.19640\vibranceGUI.exe" -minimized <==== ACHTUNG
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1806680 2021-08-12] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\termi\AppData\Local\Microsoft\Teams\Update.exe [2455264 2021-08-26] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Spotify] => C:\Users\termi\AppData\Roaming\Spotify\Spotify.exe [24731784 2021-08-24] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Update Plus Player] => R:\VLC Plus Player\vlc.exe [157808 2021-05-26] (Aller Media e.K. -> VideoLAN) <==== ACHTUNG
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [Unified Remote V3] => C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe [3243784 2021-02-22] (Unified Intents AB -> Unified Intents AB)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\Run: [com.blitz.app] => C:\Users\termi\AppData\Local\Programs\Blitz\Blitz.exe [122577672 2021-08-24] (Swift Media Entertainment, Inc. -> Blitz, Inc.)
HKU\S-1-5-21-3983815968-458737157-1999859390-1001\...\MountPoints2: {80388fa7-1736-11e7-8a88-704d7b2db4bc} - "G:\setup.exe"
HKLM\...\Windows x64\Print Processors\Canon PIXMA iP4000 Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD64.DLL [31744 2005-09-01] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [52568 2009-08-19] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ Language Monitor PIXMA iP4000: C:\WINDOWS\system32\CNMLM64.DLL [245248 2005-09-01] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\92.0.4515.159\Installer\chrmstp.exe [2021-08-17] (Google LLC -> Google LLC)
AppInit_DLLs: acaptuser64.dll => C:\WINDOWS\system32\acaptuser64.dll [119160 2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
AppInit_DLLs-x32: acaptuser32.dll => C:\Windows\SysWOW64\acaptuser32.dll [114280 2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
GroupPolicy: Beschränkung ? <==== ACHTUNG
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {05A2FEC2-1C2C-4773-AA3B-286113F6B073} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2483032 2021-08-12] (Overwolf Ltd -> Overwolf LTD)
Task: {0D109579-AB28-483A-985A-579FA7C0C240} - System32\Tasks\Opera GX scheduled Autoupdate 1619790436 => C:\Users\termi\AppData\Local\Programs\Opera GX\launcher.exe [41841360 2021-08-12] (Opera Software AS -> Opera Software)
Task: {2D026C1D-5797-4C35-A441-F62D093A7024} - System32\Tasks\Avira\System Speedup\Delayed Startup\termi\1 => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [255968 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) -> LaunchApp "C:\Users\termi\AppData\Local\Avira\Security\Delay Load for Current\ShareX.lnk" -silent
Task: {31C65895-E4B6-4C69-B3E6-E76C03651221} - System32\Tasks\Avira_Security_Service_SCM_Watchdog => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [255968 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {53B0BADD-D56A-41BE-8B48-D8D82D6CD51A} - System32\Tasks\Avira\System Speedup\Delayed Startup\termi\3 => C:\Users\termi\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
Task: {5B2EBBF5-585C-4F1D-8324-84CED127CECC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {5CBBA1E9-FE5D-46A7-839E-3E6D9FDD5F3D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114048 2021-08-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D428151-ADD0-4928-9671-B53C9F3DDE1E} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {699A37EB-0B9C-49FE-B6F1-7008A4CB3959} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {6AAC3308-1706-4DE5-BD25-6F4DB5A651C5} - System32\Tasks\Avira\System Speedup\SecurityTestScheduler => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [255968 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {6CABE442-4B11-497F-AF46-25B4B91A4022} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23253888 2021-08-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {78772080-6D06-4E28-BDCE-184DE907ED35} - System32\Tasks\Microsoft\Windows\Maintenance\InstallWinSAT => Maintenance.vbs
Task: {790EE0F4-2DDC-4660-BEA6-68E75EF4698B} - System32\Tasks\Avira_Security_Systray => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe [1503840 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {79714970-3FA9-4706-9C99-C4C9EB1AC1BD} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1621345670 => C:\Users\termi\AppData\Local\Programs\Opera GX\launcher.exe [41841360 2021-08-12] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\termi\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {8557749A-35AD-4AC9-8403-1D2ADE4B865F} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {880A8237-7692-492D-A102-607F82FC5DEE} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8980E3BC-3724-4DF9-968E-06A757235055} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8B3FC8C4-24FF-44B1-8ABF-BB2F6D37409F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114048 2021-08-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {8D2A07C3-B4D3-4167-B794-CAF2E8A2DB41} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23253888 2021-08-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {8E292CB0-CED4-4CBC-B18E-7A0DBF2711A5} - System32\Tasks\Avira\System Speedup\Delayed Startup\termi\2 => C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe [8514512 2021-03-30] (Comfort Software Group -> Comfort Software Group)
Task: {918DE258-52A7-47DD-86A1-15D2087AE07B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4282280 2021-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {97418155-1665-434C-8D24-16EF744E4ECF} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {97D8E99F-8F55-45E2-8E2F-7A7D059E5FF7} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NoUACCheck
Task: {A97D8EF9-EF12-48DD-95CE-4178E0D88E07} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [330440 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {C38D0722-274B-40EF-B450-3949F636E3BC} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\1 => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Task: {CCC9DA24-2791-42CB-BC0A-7670923CFCC7} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-06-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CF31B2BF-4704-45FE-A305-D904A65A3442} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D056125D-B444-4A2D-ABBB-BBC49CC1CBC8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4282280 2021-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {D0624FDE-6C9E-473D-B112-4F135F7E5A85} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [29868432 2021-08-26] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {D2E96B03-1C26-4399-84B7-8FCEE7E53263} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-03-23] (Google LLC -> Google LLC)
Task: {E63809FB-5626-4307-A9DA-CF3E1F3D78D9} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2651056 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {EE4E1910-DD8D-4FCF-94DE-4BDFA8441F59} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\2 => C:\Program Files\Riot Vanguard\vgtray.exe [3180256 2021-08-17] (Riot Games, Inc. -> Riot Games, Inc.)
Task: {EFE662EC-FC81-4A6A-B78F-33D3F6D6A5D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-03-23] (Google LLC -> Google LLC)
Task: {F025EBEE-545C-4AA4-953C-B464E42C7F1D} - System32\Tasks\Avira_Security_Update => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Common.Updater.exe [273784 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {F69C8215-5B1F-44A5-ACB3-D040277B8B8D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 217.147.55.3 217.147.60.5
Tcpip\..\Interfaces\{fe70adbd-29a4-48d7-9244-369e6eea9ff0}: [DhcpNameServer] 217.147.55.3 217.147.60.5
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <==== ACHTUNG
Edge:
=======
Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden]
Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden]
Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden]
Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden]
Edge DefaultProfile: Default
Edge Profile: C:\Users\termi\AppData\Local\Microsoft\Edge\User Data\Default [2021-08-26]
Edge HomePage: Default -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
Edge Extension: (Outlook) - C:\Users\termi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2021-04-03]
Edge Extension: (Word) - C:\Users\termi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2021-04-03]
Edge Extension: (Excel) - C:\Users\termi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm [2021-04-03]
Edge Extension: (PowerPoint) - C:\Users\termi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2021-04-03]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.281.2 -> C:\Program Files\Java\jre1.8.0_281\bin\dtplugin\npDeployJava1.dll [2021-04-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.281.2 -> C:\Program Files\Java\jre1.8.0_281\bin\plugin2\npjp2.dll [2021-04-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @vlc.de/vlc,version=3.0.14 -> R:\VLC Plus Player\npvlc.dll [2021-05-26] (Aller Media e.K. -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-05-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default [2021-07-26]
CHR Notifications: Default -> hxxps://www6.todhamilton.pro
CHR Extension: (Präsentationen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-03-23]
CHR Extension: (Docs) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-03-23]
CHR Extension: (Google Drive) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-03-23]
CHR Extension: (Earth View from Google Earth) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2021-03-23]
CHR Extension: (James White) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm [2021-03-23]
CHR Extension: (YouTube) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-03-23]
CHR Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-05-20]
CHR Extension: (Adblock für Youtube™) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2021-05-20]
CHR Extension: (Tabellen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-03-23]
CHR Extension: (Google Docs Offline) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-03]
CHR Extension: (AdBlock*– der beste Ad-Blocker) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-07-03]
CHR Extension: (Tinder) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejiihbkifllpgdfndalmghiodgkefan [2021-03-23]
CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcnanddlhb [2021-03-23]
CHR Extension: (Chrometana - Redirect Bing Somewhere Better) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaicbfmipfpfpjmlbpejaoaflfdnabnc [2021-03-23]
CHR Extension: (Fair AdBlocker) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgblnfidahcdcjddiepkckcfdhpknnjh [2021-03-23]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-23]
CHR Extension: (Hover Zoom+) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pccckmaobkjjboncdfnnofkonhgpceea [2021-07-26]
CHR Extension: (Google Mail) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-03-23]
CHR Extension: (Chrome Media Router) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-11]
CHR Profile: C:\Users\termi\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-07-26]
CHR Profile: C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-07-14]
CHR Extension: (Präsentationen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-03-23]
CHR Extension: (Docs) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2021-03-23]
CHR Extension: (Google Drive) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-03-23]
CHR Extension: (YouTube) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-03-23]
CHR Extension: (Tabellen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-03-23]
CHR Extension: (Google Docs Offline) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-14]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-23]
CHR Extension: (Google Mail) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-03-23]
CHR Extension: (Chrome Media Router) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-07-14]
CHR Profile: C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2 [2021-07-14]
CHR Extension: (Präsentationen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-07-14]
CHR Extension: (Docs) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2021-07-14]
CHR Extension: (Google Drive) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-07-14]
CHR Extension: (YouTube) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-07-14]
CHR Extension: (Tabellen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-07-14]
CHR Extension: (Google Docs Offline) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-14]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-07-14]
CHR Extension: (Google Mail) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-07-14]
CHR Extension: (Chrome Media Router) - C:\Users\termi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-07-14]
CHR Profile: C:\Users\termi\AppData\Local\Google\Chrome\User Data\System Profile [2021-07-26]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-3983815968-458737157-1999859390-1001) Opera GXStable - "C:\Users\termi\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1206648 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntivirProtectedService; C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe [538000 2021-06-25] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [485048 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [485048 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [574672 2021-07-06] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2989160 2021-07-02] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [384480 2021-08-19] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraSecurity; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe [271560 2021-07-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [159080 2021-04-13] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8895512 2021-05-11] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9142128 2021-08-05] (Microsoft Corporation -> Microsoft Corporation)
S4 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2018-02-16] (Digital Wave Ltd -> Digital Wave Ltd.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4816728 2021-04-21] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2021-03-06] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 EQU8_19; C:\ProgramData\EQU8\Totally Accurate Battlegrounds\bin\anticheat.x64.equ8.exe [5673048 2021-04-02] (Int3 Software AB -> Int3 Software AB)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2021-04-16] (Macrovision Corporation -> Macrovision Europe Ltd.) [Datei ist nicht signiert]
S3 GoogleChromeElevationService1d77db0b98e2a40; C:\Program Files\Google\Chrome\Application\92.0.4515.159\elevation_service.exe [1460568 2021-08-13] (Google LLC -> Google LLC)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7497336 2021-08-26] (Malwarebytes Inc -> Malwarebytes)
S3 MicrosoftEdgeElevationService1d77dbb2c5be210; C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.78\elevation_service.exe [1640336 2021-08-19] (Microsoft Corporation -> Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2483032 2021-08-12] (Overwolf Ltd -> Overwolf LTD)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-06-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [14676264 2021-07-01] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [10112672 2021-08-17] (Riot Games, Inc. -> Riot Games, Inc.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\NisSrv.exe [2727416 2021-07-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpEng.exe [136656 2021-07-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 GoogleChromeElevationService; "C:\Program Files\Google\Chrome\Application\91.0.4472.124\elevation_service.exe" [X]
S3 MicrosoftEdgeElevationService; "C:\Program Files (x86)\Microsoft\Edge\Application\91.0.864.70\elevation_service.exe" [X]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AsusVBus; C:\WINDOWS\System32\drivers\AsusVBus.sys [39704 2017-01-09] (ASUSTeK Computer Inc. -> Windows (R) Win 7 DDK provider)
S3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [84472 2017-01-09] (ASUSTeK Computer Inc. -> ASUS Corporation)
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [78936 2019-06-07] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S0 avelam; C:\WINDOWS\System32\drivers\avelam.sys [22848 2021-06-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [207864 2021-07-30] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [199312 2021-02-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [46704 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [89736 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [45472 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S3 BrSerIb; C:\WINDOWS\System32\drivers\BrSerIb.sys [95344 2014-10-23] (Brother Industries, Ltd. -> Brother Industries Ltd.)
S3 BrUsbSIb; C:\WINDOWS\System32\drivers\BrUsbSIb.sys [21872 2014-10-23] (Brother Industries, Ltd. -> Brother Industries Ltd.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2020-12-14] (Microsoft Corporation) [Datei ist nicht signiert]
S3 Bulk; C:\WINDOWS\System32\Drivers\HDJBulk.sys [354824 2018-12-21] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2018. All rights reserved.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 dot4; C:\WINDOWS\System32\drivers\Dot4.sys [146856 2015-03-10] (BoiseTest -> Windows (R) Win 7 DDK provider)
S3 dot4usb; C:\WINDOWS\System32\drivers\dot4usb.sys [43944 2015-03-10] (BoiseTest -> Microsoft Corporation)
R3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [32240 2020-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Dev47Apps)
R3 DroidCamVideo; C:\WINDOWS\System32\DriverStore\FileRepository\droidcamvideo.inf_amd64_47e18363cbf3dfe0\droidcamvideo.sys [33784 2021-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2021-04-21] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2021-04-21] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EQU8_HELPER_19; C:\WINDOWS\system32\DRIVERS\EQU8_HELPER_19.sys [38032 2021-04-12] (Int3 Software AB -> )
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [160176 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 HDJAsioK; C:\WINDOWS\System32\Drivers\HDJAsioK.sys [334344 2018-12-21] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2018. All rights reserved.)
S3 HDJCtrl; C:\WINDOWS\System32\Drivers\HDJCtrl.sys [72712 2018-12-21] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2017. All rights reserved.)
S3 HDJMidi; C:\WINDOWS\system32\DRIVERS\HDJMidi.sys [287240 2018-12-21] (Microsoft Windows Hardware Compatibility Publisher -> © Guillemot R&D, 2018. All rights reserved.)
R1 hideFirewall; C:\WINDOWS\System32\drivers\hideFirewall.sys [99824 2021-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [40960 2021-07-21] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 HWHandSet; C:\WINDOWS\System32\drivers\hw_quusbmdm.sys [226560 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hwusb_cdcacm; C:\WINDOWS\System32\drivers\hw_cdcacm.sys [127360 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hw_usbdev; C:\WINDOWS\System32\drivers\hw_usbdev.sys [116864 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 MAUSBMIDI; C:\WINDOWS\System32\drivers\MAudioUSBMIDI.sys [200200 2010-04-13] (M-Audio -> M-Audio)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210344 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-08-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198888 2021-08-26] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [68528 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-08-26] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [149424 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 NDivert; C:\WINDOWS\System32\drivers\NDivert.sys [105184 2021-03-28] (TEFINCOM S.A. -> )
S3 niks4m2usb; C:\WINDOWS\System32\drivers\niks4m2usb.sys [104304 2015-09-04] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH)
S3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [39360 2021-05-13] (TEFINCOM S.A. -> WireGuard LLC)
R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [38608 2020-12-14] (TEFINCOM S.A. -> TEFINCOM S.A.)
R3 RDID1117; C:\WINDOWS\system32\Drivers\RDWM1117.SYS [309888 2015-07-22] (Microsoft Windows Hardware Compatibility Publisher -> Roland Corporation)
S3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64880 2020-11-11] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [43376 2020-06-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-06-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2020-06-09] (TEFINCOM S.A. -> The OpenVPN Project)
R3 uvhid; C:\WINDOWS\System32\drivers\uvhid.sys [28128 2020-04-21] (Unified Intents AB -> Windows (R) Win 7 DDK provider)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [8232160 2021-08-17] (Riot Games, Inc. -> Riot Games, Inc.)
S3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2019-03-04] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49568 2021-07-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [434424 2021-07-23] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [78072 2021-07-23] (Microsoft Windows -> Microsoft Corporation)
R3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [38176 2021-05-13] (WireGuard LLC -> WireGuard LLC)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-08-26 19:44 - 2021-08-26 19:45 - 000043795 ____C C:\Users\termi\Desktop\FRST.txt
2021-08-26 19:44 - 2021-08-26 19:45 - 000000000 ____D C:\FRST
2021-08-26 19:44 - 2021-08-26 19:44 - 002300928 _____ (Farbar) C:\Users\termi\Desktop\FRST64.exe
2021-08-26 19:27 - 2021-08-26 19:27 - 000068528 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-08-26 19:26 - 2021-08-26 19:26 - 000198888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-08-26 19:26 - 2021-08-26 19:26 - 000149424 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-08-26 18:50 - 2021-08-26 18:50 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-08-26 18:50 - 2021-08-26 18:50 - 000210344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-08-26 18:50 - 2021-08-26 18:50 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-08-26 18:50 - 2021-08-26 18:50 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-08-26 18:50 - 2021-08-26 18:50 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-08-26 18:50 - 2021-08-26 18:50 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-08-26 18:50 - 2021-08-26 18:50 - 000000000 ____D C:\Users\termi\AppData\Local\mbam
2021-08-26 18:50 - 2021-08-26 18:50 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-08-26 18:50 - 2021-08-26 18:50 - 000000000 ____D C:\Program Files\Malwarebytes
2021-08-26 18:49 - 2021-08-26 18:49 - 002120496 _____ (Malwarebytes) C:\Users\termi\Downloads\MBSetup.exe
2021-08-26 18:35 - 2021-08-26 18:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avira
2021-08-26 18:14 - 2021-08-26 18:14 - 000000000 ____D C:\WINDOWS\system32\Tasks\Ivanti
2021-08-26 18:10 - 2021-08-26 19:27 - 000000000 ____D C:\Users\Public\Security Sessions
2021-08-26 17:59 - 2021-08-26 17:59 - 000003374 _____ C:\WINDOWS\system32\Tasks\Avira_Antivirus_Systray
2021-08-26 17:59 - 2021-08-26 17:59 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2021-08-26 17:59 - 2021-07-30 23:17 - 000207864 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2021-08-26 17:59 - 2021-06-25 14:59 - 000022848 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avelam.sys
2021-08-26 17:59 - 2021-02-09 19:03 - 000199312 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2021-08-26 17:59 - 2019-06-07 15:09 - 000078936 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avdevprot.sys
2021-08-26 17:59 - 2019-03-20 19:50 - 000089736 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2021-08-26 17:59 - 2019-03-20 19:50 - 000046704 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2021-08-26 17:59 - 2019-03-20 19:50 - 000045472 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2021-08-26 17:58 - 2021-08-26 19:27 - 000000000 ____D C:\Users\Public\Speedup Sessions
2021-08-26 17:58 - 2021-08-26 18:37 - 000002960 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Systray
2021-08-26 17:58 - 2021-08-26 18:10 - 000000000 ____D C:\Users\termi\AppData\Local\Avira
2021-08-26 17:58 - 2021-08-26 18:10 - 000000000 ____D C:\ProgramData\Avira
2021-08-26 17:58 - 2021-08-26 17:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2021-08-26 17:58 - 2021-08-26 17:59 - 000000000 ____D C:\Program Files (x86)\Avira
2021-08-26 17:58 - 2021-08-26 17:58 - 005901768 _____ (Avira Operations GmbH & Co. KG) C:\Users\termi\Downloads\avira_de_sptl1_1654573332-1629993478__adwg-spotlightprcupdate1-new2.exe
2021-08-26 17:58 - 2021-08-26 17:58 - 000003768 _____ C:\WINDOWS\system32\Tasks\AviraSystemSpeedupUpdate
2021-08-26 17:58 - 2021-08-26 17:58 - 000003696 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Update
2021-08-26 17:58 - 2021-08-26 17:58 - 000003428 _____ C:\WINDOWS\system32\Tasks\Avira_Security_Service_SCM_Watchdog
2021-08-26 17:58 - 2021-08-26 17:58 - 000001157 _____ C:\Users\Public\Desktop\Avira.lnk
2021-08-26 00:20 - 2021-08-26 00:20 - 034499456 _____ (TeamViewer Germany GmbH) C:\Users\termi\Downloads\TeamViewer_Setup_x64.exe
2021-08-24 16:00 - 2021-08-24 16:00 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2021-08-20 18:50 - 2021-08-26 19:38 - 000000000 ____D C:\Users\termi\AppData\Roaming\Blitz
2021-08-20 18:50 - 2021-08-24 23:01 - 000000000 ____D C:\Users\termi\AppData\Local\blitz-updater
2021-08-20 18:49 - 2021-08-20 18:49 - 076770248 _____ (Blitz, Inc.) C:\Users\termi\Downloads\Blitz-1.15.32.exe
2021-08-19 17:09 - 2021-08-19 17:09 - 000000222 ____C C:\Users\termi\Desktop\The Forest.url
2021-08-18 03:00 - 2021-08-18 03:00 - 000000000 ___DC C:\Users\termi\Documents\u-he
2021-08-16 09:20 - 2021-08-16 09:20 - 000044775 _____ C:\Users\termi\Downloads\ACFrOgBSMEuoyDAfOx97hvj2vD_EvhaZTeghQaTzxERCgiyQSDH2IHCJf0eSIJX5lV3pnJPruJjZA_I4Gkyy4dQSttBm59AF1nvAUWRIMzuaKkLTju_8NDnZHsLI8EQ=.pdf
2021-08-15 20:13 - 2021-08-22 00:08 - 000000000 ___DC C:\Users\termi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2021-08-15 20:13 - 2021-08-15 21:14 - 000000000 ____D C:\Users\termi\AppData\Local\Roblox
2021-08-15 20:13 - 2021-08-15 20:25 - 000000256 ____C C:\Users\termi\AppData\LocalLow\rbxcsettings.rbx
2021-08-15 20:13 - 2021-08-15 20:13 - 001666008 _____ (Roblox Corporation) C:\Users\termi\Downloads\RobloxPlayerLauncher.exe
2021-08-14 00:22 - 2021-08-14 00:22 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-08-14 00:22 - 2021-08-14 00:22 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-08-14 00:22 - 2021-08-14 00:22 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-08-14 00:22 - 2021-08-14 00:22 - 000011347 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-08-14 00:21 - 2021-08-14 00:21 - 001823280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-08-14 00:21 - 2021-08-14 00:21 - 001393480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-08-14 00:21 - 2021-08-14 00:21 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2021-08-14 00:16 - 2021-08-14 00:16 - 000000000 ___HD C:\$WinREAgent
2021-08-12 08:15 - 2021-08-12 08:26 - 000000000 ___DC C:\Users\termi\Desktop\Dokumente
2021-08-09 08:55 - 2021-08-09 08:57 - 000000000 ___DC C:\Users\termi\Desktop\Schulfremdenprüfung Leony
2021-08-05 15:37 - 2021-08-05 15:37 - 000000000 ___DC C:\Users\termi\Desktop\efi
2021-07-31 07:38 - 2021-08-14 15:20 - 000000000 ___DC C:\Users\termi\Desktop\Bilder von Mir
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-08-26 19:33 - 2021-03-23 19:29 - 000000000 ____D C:\Program Files\WinRAR
2021-08-26 19:33 - 2017-03-03 03:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-08-26 19:32 - 2021-03-23 18:19 - 001722788 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-08-26 19:32 - 2021-03-23 17:53 - 000743546 _____ C:\WINDOWS\system32\perfh007.dat
2021-08-26 19:32 - 2021-03-23 17:53 - 000149968 _____ C:\WINDOWS\system32\perfc007.dat
2021-08-26 19:32 - 2021-03-23 17:51 - 000000000 ____D C:\WINDOWS\INF
2021-08-26 19:30 - 2021-03-23 18:03 - 000000000 ____D C:\ProgramData\NVIDIA
2021-08-26 19:29 - 2021-04-20 22:59 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2021-08-26 19:29 - 2021-03-23 18:29 - 000000000 ____D C:\Program Files (x86)\Google
2021-08-26 19:29 - 2021-03-23 17:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-08-26 19:27 - 2021-05-18 12:51 - 000000032 _____ C:\Users\termi\AppData\Roaming\.machineId
2021-08-26 19:26 - 2021-07-07 12:34 - 000000000 ____D C:\Program Files\TeamViewer
2021-08-26 19:26 - 2021-03-23 18:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-08-26 19:26 - 2021-03-23 17:47 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-08-26 19:26 - 2020-12-14 14:23 - 000008192 ___SH C:\DumpStack.log.tmp
2021-08-26 19:26 - 2017-03-02 15:47 - 000000000 __SHD C:\Users\termi\IntelGraphicsProfiles
2021-08-26 19:26 - 2017-03-02 15:44 - 000000000 ___DC C:\Intel
2021-08-26 19:19 - 2021-04-14 16:33 - 000000000 ____D C:\Program Files\Cheat Engine 7.2
2021-08-26 19:19 - 2021-03-23 18:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-08-26 19:19 - 2021-01-06 08:40 - 000000000 ___DC C:\Users\termi\AppData\LocalLow\pF2qC1gG7yH8hI1o
2021-08-26 19:06 - 2019-03-08 10:08 - 002092776 _____ C:\UkLog.dat
2021-08-26 18:56 - 2021-03-23 17:52 - 000000000 ___HD C:\Program Files\WindowsApps
2021-08-26 18:56 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-08-26 18:50 - 2021-03-23 17:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-08-26 18:39 - 2021-03-23 18:02 - 000446632 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-08-26 18:38 - 2021-03-23 18:49 - 000000000 ____D C:\Program Files (x86)\Steam
2021-08-26 18:37 - 2021-04-03 11:16 - 000004422 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-08-26 18:37 - 2021-03-25 22:56 - 000004192 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-26 18:37 - 2021-03-25 22:56 - 000004072 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-26 18:37 - 2021-03-25 22:56 - 000003740 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-08-26 18:37 - 2021-03-23 18:44 - 000000000 ____D C:\Users\termi\AppData\Roaming\discord
2021-08-26 18:37 - 2021-03-23 18:29 - 000004354 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-08-26 18:37 - 2020-06-13 22:10 - 000000000 ___DC C:\Users\termi\Documents\ShareX
2021-08-26 18:35 - 2021-05-12 22:34 - 000000000 ____D C:\Users\termi\AppData\Roaming\TeamViewer
2021-08-26 17:11 - 2021-06-09 14:17 - 000000000 ____D C:\Users\termi\AppData\Roaming\Spotify
2021-08-26 14:42 - 2021-03-23 18:49 - 000000000 ____D C:\ProgramData\Riot Games
2021-08-26 13:37 - 2021-06-09 14:17 - 000000000 ____D C:\Users\termi\AppData\Local\Spotify
2021-08-26 01:07 - 2021-05-27 15:05 - 000002371 ____C C:\Users\termi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-08-26 00:16 - 2021-04-30 14:00 - 000000000 ____D C:\Users\termi\AppData\Roaming\TS3Client
2021-08-26 00:05 - 2021-04-05 13:29 - 000000000 ____D C:\Users\termi\AppData\Local\CrashDumps
2021-08-25 23:21 - 2021-05-12 00:37 - 000000000 ____D C:\ProgramData\Unified Remote
2021-08-25 14:04 - 2021-05-04 18:04 - 000000000 ____D C:\Program Files (x86)\Overwolf
2021-08-25 02:33 - 2021-03-23 18:44 - 000000000 ____D C:\Users\termi\AppData\Local\Discord
2021-08-23 06:25 - 2021-03-23 18:26 - 000003366 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3983815968-458737157-1999859390-1001
2021-08-23 06:25 - 2021-03-23 18:10 - 000002402 ____C C:\Users\termi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-08-21 20:44 - 2021-03-23 18:03 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-08-21 20:42 - 2021-05-06 11:14 - 000000000 ____D C:\Users\termi\AppData\Local\ElevatedDiagnostics
2021-08-21 09:11 - 2020-06-28 11:22 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-08-20 22:41 - 2021-04-17 21:26 - 000000000 ____D C:\Users\termi\AppData\Roaming\.minecraft
2021-08-20 21:48 - 2021-04-17 21:26 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
2021-08-20 19:56 - 2021-03-23 19:25 - 000000000 ____D C:\Users\termi\AppData\Local\D3DSCache
2021-08-20 19:54 - 2021-04-20 22:55 - 000000000 ____D C:\Program Files\Riot Vanguard
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\SystemResources
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-08-20 19:53 - 2021-03-23 17:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-08-20 19:53 - 2021-03-23 17:47 - 000000000 ____D C:\WINDOWS\servicing
2021-08-20 18:50 - 2021-05-18 12:51 - 000002244 ____C C:\Users\termi\Desktop\Blitz.lnk
2021-08-20 18:50 - 2021-03-23 18:51 - 000002252 ____C C:\Users\termi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blitz.lnk
2021-08-18 03:01 - 2018-02-27 16:54 - 000000000 ____D C:\Users\Public\Documents\NI Resources
2021-08-18 03:00 - 2021-06-19 23:53 - 000000000 ____D C:\Program Files\Common Files\VST3
2021-08-17 21:58 - 2021-03-23 18:30 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-08-17 21:28 - 2021-04-30 15:47 - 000004204 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1619790436
2021-08-17 21:28 - 2021-04-30 15:47 - 000001441 ____C C:\Users\termi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Opera GX.lnk
2021-08-16 00:08 - 2021-03-25 22:48 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-08-14 15:23 - 2021-05-01 22:14 - 000000000 ___DC C:\Users\termi\Desktop\minecraft
2021-08-14 09:14 - 2021-04-15 19:24 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-08-14 00:24 - 2021-03-23 17:48 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-08-14 00:15 - 2021-03-25 22:46 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-08-14 00:12 - 2021-03-25 22:46 - 133215968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-08-13 08:06 - 2021-04-03 11:16 - 000003700 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-08-12 18:33 - 2021-03-23 18:24 - 000000000 ____D C:\Users\termi\AppData\Local\Packages
2021-08-09 10:06 - 2021-03-23 18:26 - 000000000 ____D C:\Users\termi\AppData\Local\PlaceholderTileLogoFolder
2021-08-09 04:37 - 2017-03-02 15:40 - 000000000 ___RD C:\Users\termi\OneDrive
2021-08-03 02:51 - 2021-03-23 18:29 - 000003632 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-08-01 14:59 - 2021-05-04 18:03 - 000000000 ____D C:\Users\termi\AppData\Local\Overwolf
2021-07-29 14:59 - 2021-07-16 21:33 - 000000000 ____D C:\Users\termi\AppData\Roaming\vlc
2021-07-27 02:34 - 2021-03-23 21:13 - 000000306 __RSH C:\ProgramData\ntuser.pol
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2021-01-17 16:04 - 2021-01-17 16:04 - 001408808 _____ (Microsoft Corporation) C:\Users\termi\vs_community__1087382636.1580554586.exe
2021-05-18 12:51 - 2021-08-26 19:27 - 000000032 _____ () C:\Users\termi\AppData\Roaming\.machineId
2021-04-30 16:27 - 2021-04-30 16:28 - 000002400 _____ () C:\Users\termi\AppData\Roaming\vibranceGUI.log
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== --- --- --- |