Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2026
durchgeführt von De***** (Administrator) auf OPFER (Gigabyte Technology Co., Ltd. B550 GAMING X V2) (06-07-2026 05:54:47)
Gestartet von C:\Users\De*****\Desktop\FRST64.exe
Geladene Profile: De*****
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser nicht gefunden!
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\150.0.4078.48\identity_helper.exe
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Elgato\StreamDeck\StreamDeck.exe ->) (Corsair Memory, Inc. -> ) C:\Program Files\Elgato\StreamDeck\crashpad_handler.exe
(C:\Program Files\Elgato\StreamDeck\StreamDeck.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Users\De*****\AppData\Roaming\Elgato\StreamDeck\Plugins\com.elgato.discord.sdPlugin\ESDDiscord.exe
(C:\Program Files\Elgato\StreamDeck\StreamDeck.exe ->) (OpenJS Foundation -> Node.js) C:\Users\De*****\AppData\Roaming\Elgato\StreamDeck\NodeJS\20.20.0\node.exe <3>
(C:\Program Files\Elgato\StreamDeck\StreamDeck.exe ->) (The Qt Company Oy -> The Qt Company Ltd.) C:\Program Files\Elgato\StreamDeck\QtWebEngineProcess.exe <4>
(C:\Program Files\Elgato\Volume Controller\ElgatoAudioControlServerWatcher.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Elgato\Volume Controller\ElgatoAudioControlServer.exe
(C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <4>
(C:\Program Files\GIGABYTE\Control Center\GCC.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\Dll\GvFPS.exe
(C:\Program Files\GIGABYTE\Control Center\GCC.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\Dll\GvFvSDKCSharp.exe
(C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\Dll\GvFPS.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\Dll\PresentMon\Gv.PresentMon.exe
(C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\Dll\GvFvSDKCSharp.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
(C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\FrameViewSDK\FvContainer\FvContainer.exe
(C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\FrameViewSDK\FvContainer\FvContainer.System.exe
(C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe
(C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe
(C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.98\msedgewebview2.exe
(cmd.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Epic Games Inc. -> Node.js) C:\Program Files (x86)\Epic Games\Epic Online Services\EpicOnlineServicesUserHelper.exe
(explorer.exe ->) (Corsair Memory, Inc. -> ) C:\Program Files\Elgato\Volume Controller\ElgatoAudioControlServerWatcher.exe
(explorer.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Elgato\ControlCenter\ControlCenter.exe
(explorer.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Elgato\StreamDeck\StreamDeck.exe
(explorer.exe ->) (Last.fm) [Datei ist nicht signiert] C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe
(explorer.exe ->) (Open-Shell) [Datei ist nicht signiert] C:\Program Files\Open-Shell\StartMenu.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <6>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.98\msedgewebview2.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_67995ceab8993b08\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (GIGA-BYTE Technology Co., Ltd. -> ) C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\AorusLcdService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_67995ceab8993b08\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2605.9.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Epic Games Inc. -> Node.js) C:\Program Files (x86)\Epic Games\Epic Online Services\EpicOnlineServicesUserHelper.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files\GIGABYTE\Control Center\GCC.exe
(svchost.exe ->) (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.6465_none_7e0fb53c7c8be091\TiWorker.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [1090784 2020-07-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [Open-Shell Start Menu] => C:\Program Files\Open-Shell\StartMenu.exe [267776 2025-05-08] (Open-Shell) [Datei ist nicht signiert]
HKLM\...\Run: [Control Center] => C:\Program Files\Elgato\ControlCenter\ControlCenter.exe [2128536 2025-11-04] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Beschränkung <==== ACHTUNG
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [LGHUB] => C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe [26469016 2026-07-01] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [Discord] => C:\Users\De*****\AppData\Local\Discord\Update.exe [1596344 2026-05-11] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [Stream Deck] => C:\Program Files\Elgato\StreamDeck\StreamDeck.exe [26921672 2026-05-11] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [Volume Controller SD plugin] => C:\Program Files\Elgato\Volume Controller\ElgatoAudioControlServerWatcher.exe [336264 2025-05-20] (Corsair Memory, Inc. -> )
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [EpicGamesLauncher] => C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [51866552 2026-07-02] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [5773976 2026-06-25] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [VoicemodV3] => C:\Program Files\Voicemod V3\Voicemod.exe [6781896 2026-05-18] (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod Inc.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Run: [MicrosoftEdgeAutoLaunch_A734CDB21F65BACD27474256D84E27D6] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-02] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon TS5300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDFO.DLL [509952 2019-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS5300 series: C:\Windows\system32\CNMLMFO.DLL [940032 2019-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
Startup: C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AORUS ENGINE.lnk [2026-05-15]
ShortcutTarget: AORUS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\autorun.exe () [Datei ist nicht signiert]
Startup: C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Last.fm Desktop Scrobbler.lnk [2026-05-24]
ShortcutTarget: Last.fm Desktop Scrobbler.lnk -> C:\Users\De*****\AppData\Roaming\Microsoft\Installer\{B13709CB-85AE-4F45-BFF9-2CB2B7A78F83}\_19B259572BFCF696C10AAD.exe () [Datei ist nicht signiert]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {94A41645-9B05-4C8F-8C71-ABDA73456BEE} - System32\Tasks\GCC => C:\Program Files\GIGABYTE\Control Center\GCC.exe [35425448 2025-09-12] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) -> C:\Program Files\GIGABYTE\Control Center\\-b
Task: {A382BFDA-B03B-4FD4-A277-285834C4DB1E} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe [34677248 2025-12-22] (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert]
Task: {9448382A-FF23-41CB-8F49-7407AC3C827C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23564224 2023-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {4831E84F-3573-4DE4-990F-8F28FF6F2093} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23564224 2023-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {D2AF46AF-E06E-471C-A29D-191838163BFC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1446864 2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {C3804A93-91AF-42FA-942A-4FC40E60D79D} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1446864 2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {C6DE697E-F78D-4826-B8F8-11420388A363} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2283984 2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {FF2FBDF0-FF40-40A4-8167-A2A5093071D6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2283984 2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {781E25E5-8065-4FC3-98C3-0D9D3B7D0EDC} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3346544 2026-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {794FAC6B-7EC5-41FA-994F-D660CE6A2864} - System32\Tasks\PinnacleStudio26Notifier => C:\Program Files\Pinnacle\Studio 26\programs\PinnacleNotifierWrapper.exe [12560 2023-09-07] (Corel Corporation -> Pinnacle)
Task: {B95AED71-1BFC-4ECC-B212-585D0EC712ED} - System32\Tasks\PinnacleStudio26Updater => C:\Program Files\Pinnacle\Studio 26\programs\PSNotification.exe [560448 2023-09-05] (Corel Corporation -> )
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{92f7a2f7-2616-4dd9-bc56-75d2e543c925}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{92f7a2f7-2616-4dd9-bc56-75d2e543c925}: [DhcpDomain] home
FireFox:
========
FF DefaultProfile: iwlc3x28.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\errvuaqj.default [2026-05-01]
FF ProfilePath: C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release [2026-07-05]
FF Session Restore: Mozilla\Firefox\Profiles\iwlc3x28.default-release -> ist aktiviert.
FF Extension: (BetterTTV) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\firefox@betterttv.net.xpi [2026-07-02]
FF Extension: (I don't care about cookies) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\jid1-KKzOGWgsW3Ao4Q@jetpack.xpi [2026-05-01]
FF Extension: (7TV) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\moz-addon-prod@7tv.app.xpi [2026-06-24]
FF Extension: (New Tab) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\newtab@mozilla.org.xpi [2026-06-27]
FF Extension: (uBlock Origin) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-07-03]
FF Extension: (YTMusic Scrobbler → Last.FM) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\ytmusic-scrobbler@addon.xpi [2026-05-24]
FF Extension: (Dark space - The best dynamic theme) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2026-05-21]
FF Extension: (Last.fm Scrobbler for YouTube™) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{4e09fe4d-835f-4d58-a7ec-0bbc19f0aeab}.xpi [2026-05-24]
FF Extension: (Return YouTube Dislike) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{762f9885-5a13-4abd-9c77-433dcd38b8fd}.xpi [2026-05-21]
FF Extension: (Last of us) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{7f42afdf-5e55-4f2c-882f-20d8fa4782d5}.xpi [2026-05-21]
FF Extension: (Shorts für YouTube™ ausblenden) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{88ebde3a-4581-4c6b-8019-2a05a9e3e938}.xpi [2026-05-24]
FF Extension: (Briked LastFM YoutubeMusic Scrobbler) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{db4d3665-83be-478f-8ff0-4d17052b465a}.xpi [2026-05-24]
FF Extension: (DocsAfterDark) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\Extensions\{e8ffc3db-2875-4c7f-af38-d03e7f7f8ab9}.xpi [2026-05-14]
FF Extension: (IPP Activator) - C:\Users\De*****\AppData\Roaming\Mozilla\Firefox\Profiles\iwlc3x28.default-release\features\{08036fea-d89d-4965-88a5-38c8a8c425ff}\ipp-activator@mozilla.com.xpi [2026-06-24]
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\De*****\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-06]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\De*****\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2026-07-05]
Edge Extension: (Google Docs Offline) - C:\Users\De*****\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-05]
Edge Extension: (Edge relevant text changes) - C:\Users\De*****\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-04-30]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AorusLcdService; C:\Program Files\GIGABYTE\Control Center\Lib\De*****\Service\AorusLcdService.exe [60000 2025-10-22] (GIGA-BYTE Technology Co., Ltd. -> )
S2 CdRomArbiterService; C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.2.0_x64.exe [9728 2026-06-12] (GuinpinSoft inc) [Datei ist nicht signiert]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9491904 2023-07-31] (Microsoft Corporation -> Microsoft Corporation)
S3 CorsairDeviceControlService; C:\Program Files\Corsair\Corsair Device Control Service\bin\CorsairDeviceControlService.exe [2937496 2025-12-02] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S3 DiscordSystemHelper; C:\Program Files\Common Files\Discord\Discord\DiscordSystemHelper.exe [2241408 2026-06-18] (discord-code-sign-windows-admin -> Discord Inc.)
R2 EasyTuneEngineService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [159912 2025-12-31] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 EpicGamesUpdater; C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3408312 2026-07-02] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [2606520 2026-06-23] (Epic Games Inc. -> Epic Games, Inc.)
S2 GBTECService; C:\Program Files (x86)\GIGABYTE\GBTECService\OLEDDisplayService.exe [21160 2025-09-25] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [20985496 2026-07-01] (Logitech Inc -> Logitech, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11514232 2026-07-04] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-04] (Malwarebytes Inc -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpDefenderCoreService.exe [2150144 2026-06-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_67995ceab8993b08\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-04-23] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1523832 2026-05-25] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2026-04-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\NisSrv.exe [4608640 2026-06-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MsMpEng.exe [290744 2026-06-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 GigabyteUpdateService; C:\Windows\system32\GigabyteUpdateService.exe [898808 2026-07-05] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [77240 2022-07-18] (Advanced Micro Devices Inc. -> AMD)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R1 CTIIO; C:\Windows\system32\drivers\CtiIo64.sys [39672 2026-05-15] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [159296 2026-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 FvKMDSvc; C:\Windows\system32\VRFCAT-Plugins\FrameViewKM_x64.sys [29248 2026-02-27] (NVIDIA Corporation -> )
R3 gdrv3; C:\Windows\System32\drivers\gdrv3.sys [52440 2026-05-15] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 iriuna0; C:\Windows\System32\DriverStore\FileRepository\iriunaud.inf_amd64_03929b79d4508491\iriuna0.sys [41096 2025-08-18] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82312 2026-05-23] (Microsoft Windows -> Microsoft Corporation)
R3 logi_joy_bus_enum; C:\Windows\System32\drivers\logi_joy_bus_enum.x64.sys [45448 2026-05-13] (Logitech Inc -> Logitech)
R3 logi_joy_vir_hid; C:\Windows\System32\drivers\logi_joy_vir_hid.x64.sys [32648 2026-05-13] (Logitech Inc -> Logitech)
R3 logi_joy_xlcore; C:\Windows\System32\drivers\logi_joy_xlcore.x64.sys [74632 2026-05-13] (Logitech Inc -> Logitech)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [235624 2026-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-07-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\Drivers\farflt.sys [215656 2026-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\Drivers\mbam.sys [132712 2026-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [246376 2026-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [190096 2026-07-04] (Malwarebytes Inc -> Malwarebytes)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [19672 2026-05-15] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 voicemodvad; C:\Windows\System32\DriverStore\FileRepository\voicemodvad.inf_amd64_b1314f88d7831d1d\voicemodvad.sys [93352 2025-10-24] (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod S.L.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [21888 2026-06-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [646536 2026-06-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [115120 2026-06-10] (Microsoft Windows -> Microsoft Corporation)
U2 DriverUpdSvc.exe; kein ImagePath
U2 TuneupSvc.exe; kein ImagePath
==================== SvcHost (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-06 05:54 - 2026-07-06 05:55 - 000026821 _____ C:\Users\De*****\Desktop\FRST.txt
2026-07-05 21:30 - 2026-07-05 21:31 - 000000000 ____D C:\AdwCleaner
2026-07-05 21:30 - 2026-07-05 21:30 - 009630992 _____ (Malwarebytes) C:\Users\De*****\Desktop\adwcleaner.exe
2026-07-05 08:58 - 2026-07-05 08:58 - 000030776 _____ C:\Users\De*****\Downloads\CRR6678303_ReturnDocument.pdf
2026-07-04 23:43 - 2026-07-04 23:43 - 000190096 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2026-07-04 23:14 - 2026-07-04 23:14 - 000001643 _____ C:\Users\De*****\Desktop\Malwarebytes Bedrohungsscan-Bericht 2026-07-04 231220.txt
2026-07-04 23:11 - 2026-07-06 05:53 - 000000000 ____D C:\Users\De*****\AppData\Local\Malwarebytes
2026-07-04 23:11 - 2026-07-04 23:11 - 000002059 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-04 23:11 - 2026-07-04 23:11 - 000002047 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-07-04 23:11 - 2026-07-04 23:11 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-04 23:11 - 2026-07-04 23:11 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-04 23:10 - 2026-07-04 23:10 - 002862824 _____ (Malwarebytes) C:\Users\De*****\Downloads\MBSetup-3.3.exe
2026-07-04 22:54 - 2026-07-04 22:54 - 000000144 _____ C:\Users\De*****\AppData\Local\Support.ini
2026-07-04 22:53 - 2026-07-04 22:54 - 000000000 ____D C:\Users\De*****\AppData\Local\NortonSupport
2026-07-04 22:53 - 2026-07-04 22:53 - 011461344 _____ (Gen Digital Inc.) C:\Users\De*****\Downloads\nortonsupport.exe
2026-07-04 21:14 - 2026-07-04 23:20 - 000062814 _____ C:\Users\De*****\Downloads\Addition.txt
2026-07-04 21:14 - 2026-07-04 21:14 - 000040954 _____ C:\Users\De*****\Downloads\Shortcut.txt
2026-07-04 21:13 - 2026-07-04 23:38 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Avast Software
2026-07-04 21:13 - 2026-07-04 23:38 - 000000000 ____D C:\Users\De*****\AppData\Local\Avast Software
2026-07-04 21:13 - 2026-07-04 23:38 - 000000000 ____D C:\ProgramData\Avast Software
2026-07-04 21:12 - 2026-07-04 21:12 - 001737448 _____ (Gen Digital Inc.) C:\Users\De*****\Downloads\avast_one_free_antivirus.exe
2026-07-04 21:12 - 2026-07-04 21:12 - 000000000 ____D C:\Users\De*****\AppData\Roaming\xpdf
2026-07-04 21:11 - 2026-07-06 05:55 - 000000000 ____D C:\FRST
2026-07-04 21:11 - 2026-07-04 21:27 - 000094725 _____ C:\Users\De*****\Downloads\FRST.txt
2026-07-04 21:11 - 2026-07-04 21:11 - 002448896 _____ (Farbar) C:\Users\De*****\Desktop\FRST64.exe
2026-07-04 21:10 - 2026-07-04 21:12 - 000000000 ____D C:\Users\De*****\AppData\Local\Norton
2026-07-04 21:09 - 2026-07-05 14:45 - 000000000 ____D C:\ProgramData\Norton
2026-07-04 21:09 - 2026-07-04 21:09 - 001999912 _____ (Gen Digital Inc.) C:\Users\De*****\Downloads\norton_360_online_setup.exe
2026-07-04 21:09 - 2026-07-04 21:09 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Norton
2026-07-04 20:54 - 2026-07-04 20:54 - 000000799 _____ C:\Users\De*****\Documents\Videos - Verknüpfung.lnk
2026-07-03 22:54 - 2026-07-03 22:55 - 2080374784 _____ C:\Users\De*****\Downloads\negoziodifoto267rt.part4.rar
2026-07-03 22:54 - 2026-07-03 22:55 - 2080374784 _____ C:\Users\De*****\Downloads\negoziodifoto267rt.part3.rar
2026-07-03 22:54 - 2026-07-03 22:55 - 2080374784 _____ C:\Users\De*****\Downloads\negoziodifoto267rt.part2.rar
2026-07-03 22:54 - 2026-07-03 22:55 - 2047096756 _____ C:\Users\De*****\Downloads\negoziodifoto267rt.part5.rar
2026-07-03 22:53 - 2026-07-03 22:53 - 2080374784 _____ C:\Users\De*****\Downloads\negoziodifoto267rt.part1.rar
2026-07-03 22:52 - 2026-07-03 22:52 - 272629760 _____ C:\Users\De*****\Downloads\negoziodifoto25gpai8.part1(1).rar
2026-07-03 09:00 - 2026-07-03 09:00 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Adobe
2026-07-02 18:08 - 2026-07-02 18:08 - 004895711 _____ C:\Users\De*****\Downloads\folders.3.1.9.zip
2026-07-02 17:52 - 2026-07-02 17:52 - 000082705 _____ C:\Users\De*****\Downloads\responsive-slider-gallery.1.5.4.zip
2026-07-02 08:01 - 2026-07-02 08:01 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\QuickStyles
2026-07-02 07:56 - 2026-07-02 07:56 - 000000856 _____ C:\Users\Public\Desktop\Logitech G HUB.lnk
2026-07-02 07:56 - 2026-07-02 07:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2026-07-02 07:56 - 2026-07-02 07:56 - 000000000 ____D C:\Program Files\LGHUB
2026-07-02 07:55 - 2026-07-02 07:55 - 000000000 ____D C:\ProgramData\Logi
2026-06-30 22:28 - 2026-07-02 09:37 - 000000000 ____D C:\Users\De*****\AppData\Local\VoicemodV3
2026-06-30 22:28 - 2026-06-30 22:28 - 000001841 _____ C:\Users\Public\Desktop\Voicemod V3.lnk
2026-06-30 22:28 - 2026-06-30 22:28 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Voicemod.exe
2026-06-30 22:28 - 2026-06-30 22:28 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Voicemod
2026-06-30 22:28 - 2026-06-30 22:28 - 000000000 ____D C:\ProgramData\Voicemod
2026-06-30 22:28 - 2026-06-30 22:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voicemod V3
2026-06-30 22:28 - 2026-06-30 22:28 - 000000000 ____D C:\Program Files\Voicemod V3
2026-06-30 22:27 - 2026-06-30 22:27 - 006396696 _____ (Voicemod Inc., Sucursal en España ) C:\Users\De*****\Downloads\VoicemodInstaller_1.6.13-tigkb3.exe
2026-06-28 02:09 - 2026-06-28 02:09 - 000383694 _____ C:\Users\De*****\Downloads\Spotify-Font.zip
2026-06-28 01:46 - 2026-06-28 02:53 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Notepad++
2026-06-28 01:46 - 2026-06-28 01:46 - 006899264 _____ (Don HO don.h@free.fr) C:\Users\De*****\Downloads\npp.8.9.6.4.Installer.x64.exe
2026-06-28 01:46 - 2026-06-28 01:46 - 000000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
2026-06-28 01:46 - 2026-06-28 01:46 - 000000000 ____D C:\Program Files\Notepad++
2026-06-28 01:41 - 2026-06-28 01:41 - 025594304 _____ (NowPlayingToFile) C:\Users\De*****\Downloads\NowPlayingToFile.exe
2026-06-28 01:26 - 2026-06-28 01:26 - 007980050 _____ C:\Users\De*****\Downloads\201736-916310642(1).mp4
2026-06-28 01:07 - 2026-06-28 01:07 - 000088330 _____ C:\Users\De*****\Downloads\Snip-v8.0.2.zip
2026-06-28 01:03 - 2026-06-28 01:49 - 000000000 ____D C:\Users\De*****\Desktop\Snip
2026-06-25 21:24 - 2026-06-25 21:34 - 000000000 ____D C:\Users\De*****\AppData\Roaming\YouTube Music Desktop App
2026-06-25 21:24 - 2026-06-25 21:24 - 109704704 _____ (NovusTheory) C:\Users\De*****\Downloads\2.0.5.exe
2026-06-25 21:24 - 2026-06-25 21:24 - 000002649 _____ C:\Users\De*****\Desktop\YouTube Music Desktop App.lnk
2026-06-25 21:24 - 2026-06-25 21:24 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NovusTheory
2026-06-25 21:24 - 2026-06-25 21:24 - 000000000 ____D C:\Users\De*****\AppData\Local\youtube_music_desktop_app
2026-06-25 21:19 - 2026-06-25 21:19 - 000000109 _____ C:\Users\De*****\Downloads\instructions.url.download
2026-06-25 21:13 - 2026-06-25 21:13 - 000000000 ____D C:\Users\De*****\.android
2026-06-25 21:12 - 2026-06-25 21:12 - 002686736 _____ C:\Users\De*****\Downloads\IriunWebcam-2.9.6.exe
2026-06-25 21:12 - 2026-06-25 21:12 - 000001127 _____ C:\Users\De*****\Desktop\Iriun Webcam.lnk
2026-06-25 21:12 - 2026-06-25 21:12 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Iriun Webcam
2026-06-25 21:12 - 2026-06-25 21:12 - 000000000 ____D C:\Program Files (x86)\Iriun Webcam
2026-06-25 21:12 - 2026-06-25 21:12 - 000000000 ____D C:\Program Files (x86)\dotnet
2026-06-19 18:19 - 2026-06-19 18:19 - 000000000 ____D C:\Users\De*****\AppData\Local\Chameleon
2026-06-19 18:16 - 2026-06-19 18:16 - 000000223 _____ C:\Users\De*****\Desktop\MECCHA CHAMELEON.url
2026-06-13 22:53 - 2026-06-13 22:54 - 000000000 ____D C:\Users\De*****\Downloads\Presets
2026-06-12 14:16 - 2026-06-12 14:16 - 000002142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 5 64-Bit.lnk
2026-06-12 14:16 - 2026-06-12 14:16 - 000002122 _____ C:\Users\Public\Desktop\Lightroom 5 64-Bit.lnk
2026-06-12 14:16 - 2026-06-12 14:16 - 000000000 ____D C:\Program Files\Common Files\Adobe
2026-06-12 14:15 - 2026-06-12 14:15 - 000000000 ____D C:\Program Files\Adobe
2026-06-12 09:44 - 2026-06-12 09:44 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV
2026-06-12 09:44 - 2026-06-12 09:44 - 000000000 ____D C:\Program Files (x86)\MakeMKV
2026-06-12 09:43 - 2026-06-12 09:43 - 016347143 _____ (GuinpinSoft inc) C:\Users\De*****\Downloads\Setup_MakeMKV_v1.18.3(1).exe
2026-06-12 09:43 - 2026-06-12 09:43 - 000000000 ____D C:\Users\De*****\.MakeMKV
2026-06-12 09:42 - 2026-06-12 09:44 - 000001066 _____ C:\Users\De*****\Desktop\MakeMKV.lnk
2026-06-12 09:42 - 2026-06-12 09:42 - 000000000 ____D C:\Program Files\Common Files\cdarbsvc
2026-06-11 20:51 - 2026-06-11 20:51 - 000000039 _____ C:\Users\De*****\AppData\Local\kritadisplayrc
2026-06-11 20:22 - 2026-06-11 20:22 - 272629760 _____ C:\Users\De*****\Downloads\negoziodifoto25gpai8.part1.rar
2026-06-11 20:19 - 2026-06-11 21:00 - 017954611 _____ C:\Users\De*****\Downloads\Blaetter.psd
2026-06-11 20:18 - 2026-06-11 20:18 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part6.rar
2026-06-11 20:18 - 2026-06-11 20:18 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part5.rar
2026-06-11 20:18 - 2026-06-11 20:18 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part4.rar
2026-06-11 20:18 - 2026-06-11 20:18 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part3.rar
2026-06-11 20:18 - 2026-06-11 20:18 - 170926090 _____ C:\Users\De*****\Downloads\negoziodifoto267.part7.rar
2026-06-11 20:17 - 2026-06-11 20:17 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part2.rar
2026-06-11 20:17 - 2026-06-11 20:17 - 581959680 _____ C:\Users\De*****\Downloads\negoziodifoto267.part1.rar
2026-06-11 20:11 - 2026-06-11 20:11 - 000000000 ____D C:\Users\De*****\AppData\Local\krita
2026-06-11 20:10 - 2026-06-11 20:51 - 000003213 _____ C:\Users\De*****\AppData\Local\kritarc
2026-06-11 20:10 - 2026-06-11 20:51 - 000000000 ____D C:\Users\De*****\AppData\Roaming\krita
2026-06-11 20:10 - 2026-06-11 20:10 - 000000000 ____D C:\Users\De*****\AppData\Local\fontconfig
2026-06-11 20:09 - 2026-06-11 20:09 - 164092376 _____ (Krita Foundation) C:\Users\De*****\Downloads\krita-x64-5.3.2.1-setup.exe
2026-06-11 17:35 - 2026-06-11 17:35 - 000130944 _____ C:\Users\De*****\Downloads\il_fullxfull.783482168_nce9.jpeg
2026-06-11 13:58 - 2026-06-11 13:58 - 000010466 _____ C:\Users\De*****\Downloads\ash.zip
2026-06-10 22:21 - 2026-06-10 22:21 - 000995553 _____ C:\Users\De*****\Downloads\Farntattoo mit Farn
2026-06-10 22:16 - 2026-06-10 22:16 - 000995553 _____ C:\Users\De*****\Downloads\downloaded_photo(8).jpeg
2026-06-10 19:40 - 2026-06-19 18:16 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2026-06-10 19:40 - 2026-06-10 19:40 - 000000223 _____ C:\Users\De*****\Desktop\The Walking Dead The Telltale Definitive Series.url
2026-06-10 19:40 - 2026-06-10 19:40 - 000000222 _____ C:\Users\De*****\Desktop\Life is Strange 2.url
2026-06-10 19:40 - 2026-06-10 19:40 - 000000000 ____D C:\Users\De*****\AppData\Local\Dontnod
2026-06-10 14:02 - 2026-06-10 14:03 - 1510591777 _____ C:\Users\De*****\Downloads\Mixed-20260610T120132Z-3-001.zip
2026-06-10 14:02 - 2026-06-10 14:03 - 1389048167 _____ C:\Users\De*****\Downloads\Left Behind-20260610T120131Z-3-001.zip
2026-06-10 14:02 - 2026-06-10 14:03 - 1221712215 _____ C:\Users\De*****\Downloads\Pittsburgh-20260610T120132Z-3-001.zip
2026-06-10 14:02 - 2026-06-10 14:03 - 1047567441 _____ C:\Users\De*****\Downloads\Bus Depot-20260610T120128Z-3-001.zip
2026-06-10 14:01 - 2026-06-10 14:02 - 957405611 _____ C:\Users\De*****\Downloads\Lakeside Resort -20260610T120130Z-3-001.zip
2026-06-10 14:01 - 2026-06-10 14:02 - 537997910 _____ C:\Users\De*****\Downloads\The University -20260610T120137Z-3-001.zip
2026-06-10 14:01 - 2026-06-10 14:02 - 1233344112 _____ C:\Users\De*****\Downloads\Bill's Town-20260610T120125Z-3-001.zip
2026-06-10 14:01 - 2026-06-10 14:01 - 228039412 _____ C:\Users\De*****\Downloads\Hometown-20260610T120129Z-3-001.zip
2026-06-10 14:01 - 2026-06-10 14:01 - 206546538 _____ C:\Users\De*****\Downloads\Jackson-20260610T120129Z-3-001.zip
2026-06-10 09:06 - 2026-06-10 09:07 - 001407658 _____ C:\Users\De*****\Downloads\downloaded_photo(3).jpeg
2026-06-10 09:06 - 2026-06-10 09:07 - 001103142 _____ C:\Users\De*****\Downloads\downloaded_photo(4).jpeg
2026-06-10 09:06 - 2026-06-10 09:07 - 001072101 _____ C:\Users\De*****\Downloads\downloaded_photo(5).jpeg
2026-06-10 09:06 - 2026-06-10 09:07 - 000952869 _____ C:\Users\De*****\Downloads\downloaded_photo(6).jpeg
2026-06-10 09:06 - 2026-06-10 09:06 - 000996769 _____ C:\Users\De*****\Downloads\downloaded_photo(7).jpeg
2026-06-10 09:06 - 2026-06-10 09:06 - 000663240 _____ C:\Users\De*****\Downloads\downloaded_photo(2).jpeg
2026-06-10 08:52 - 2026-06-10 08:52 - 000601566 _____ C:\Users\De*****\Downloads\downloaded_photo.jpeg
2026-06-10 08:52 - 2026-06-10 08:52 - 000454672 _____ C:\Users\De*****\Downloads\downloaded_photo(1).jpeg
2026-06-10 08:07 - 2026-06-10 08:07 - 000299739 _____ C:\Users\De*****\Downloads\WhatsApp Image 2026-06-09 at 10.42.02.jpeg
2026-06-10 08:07 - 2026-06-10 08:07 - 000145064 _____ C:\Users\De*****\Downloads\WhatsApp Image 2026-06-08 at 15.28.27.jpeg
2026-06-09 20:57 - 2023-10-16 09:54 - 000000154 _____ C:\Users\De*****\Desktop\fernfox.txt
2026-06-09 20:20 - 2026-06-28 02:52 - 000000000 ____D C:\Users\De*****\AppData\Roaming\vlc
2026-06-09 20:20 - 2026-06-09 20:20 - 045948080 _____ C:\Users\De*****\Downloads\vlc-3.0.23-win64.exe
2026-06-09 20:20 - 2026-06-09 20:20 - 000000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2026-06-09 20:20 - 2026-06-09 20:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2026-06-09 20:20 - 2026-06-09 20:20 - 000000000 ____D C:\Program Files\VideoLAN
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2026-07-06 05:54 - 2026-05-25 20:01 - 000000000 ____D C:\Program Files (x86)\Steam
2026-07-06 05:53 - 2026-05-15 19:55 - 000003452 _____ C:\Windows\system32\Tasks\GCC
2026-07-06 05:53 - 2026-05-15 16:56 - 000000000 ____D C:\Users\De*****\AppData\Local\CrashDumps
2026-07-06 05:53 - 2026-05-11 20:40 - 000000000 ____D C:\Users\De*****\AppData\Local\OpenShell
2026-07-05 21:47 - 2026-04-30 08:11 - 000000000 ____D C:\Users\De*****
2026-07-05 21:47 - 2026-04-27 12:15 - 000000000 ____D C:\ProgramData\NVIDIA
2026-07-05 21:43 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-05 21:34 - 2026-04-27 12:16 - 001622274 _____ C:\Windows\system32\PerfStringBackup.INI
2026-07-05 21:34 - 2019-12-07 16:51 - 000701762 _____ C:\Windows\system32\perfh007.dat
2026-07-05 21:34 - 2019-12-07 16:51 - 000141266 _____ C:\Windows\system32\perfc007.dat
2026-07-05 21:34 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2026-07-05 21:33 - 2023-12-04 04:56 - 000000000 ____D C:\Windows\SystemTemp
2026-07-05 21:28 - 2026-04-27 15:54 - 000109304 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\system32\GigabyteDownloadAssistant.exe
2026-07-05 21:28 - 2026-04-27 12:09 - 000926512 _____ C:\Windows\system32\wpbbin.exe
2026-07-05 21:28 - 2026-04-27 12:09 - 000898808 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\system32\GigabyteUpdateService.exe
2026-07-05 21:28 - 2026-04-27 12:09 - 000008192 ___SH C:\DumpStack.log.tmp
2026-07-05 21:28 - 2026-04-27 12:09 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-07-05 21:28 - 2026-04-27 12:09 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-07-05 21:28 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2026-07-05 13:23 - 2026-05-01 14:58 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-05 09:51 - 2026-04-30 08:11 - 000000000 ____D C:\Users\De*****\AppData\Local\D3DSCache
2026-07-05 08:59 - 2026-05-11 20:56 - 000000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2026-07-04 23:42 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2026-07-04 23:11 - 2026-05-13 21:39 - 000000000 ____D C:\Users\De*****\AppData\Local\Sentry
2026-07-04 23:11 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2026-07-04 21:48 - 2026-04-30 08:11 - 000000000 ____D C:\Users\De*****\AppData\Local\Packages
2026-07-04 21:48 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-04 21:48 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2026-07-04 21:07 - 2026-04-27 12:09 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-02 22:00 - 2026-05-12 21:31 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\UProof
2026-07-02 09:37 - 2026-05-13 21:40 - 000000000 ____D C:\Users\De*****\AppData\Roaming\G HUB
2026-07-02 08:03 - 2026-05-12 21:31 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Word
2026-07-02 08:00 - 2026-05-12 21:31 - 000000000 ____D C:\Users\De*****\AppData\Roaming\Microsoft\Office
2026-07-02 07:56 - 2026-05-13 21:40 - 000000000 ____D C:\Users\De*****\AppData\Roaming\lghub
2026-07-02 07:56 - 2026-05-13 21:40 - 000000000 ____D C:\Users\De*****\AppData\Local\LGHUB
2026-06-30 21:06 - 2026-05-01 14:59 - 000003594 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3912185912-3826206352-237317771-1004
2026-06-30 21:06 - 2026-04-30 08:12 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3912185912-3826206352-237317771-1004
2026-06-30 21:06 - 2026-04-30 08:11 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3912185912-3826206352-237317771-1004
2026-06-30 21:06 - 2026-04-30 08:11 - 000002421 _____ C:\Users\De*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-06-28 02:54 - 2026-05-16 18:39 - 000000000 ____D C:\Users\De*****\AppData\Roaming\discord
2026-06-28 02:52 - 2026-05-11 21:59 - 000000000 ____D C:\Users\De*****\AppData\Roaming\obs-studio
2026-06-27 21:52 - 2026-05-16 18:38 - 000000000 ____D C:\Users\De*****\AppData\Local\Discord
2026-06-25 21:24 - 2026-05-16 18:38 - 000000000 ____D C:\Users\De*****\AppData\Local\SquirrelTemp
2026-06-25 21:12 - 2026-04-30 08:27 - 000000000 ____D C:\ProgramData\Package Cache
2026-06-20 20:34 - 2026-04-27 12:09 - 000003756 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-06-20 20:34 - 2026-04-27 12:09 - 000003630 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-06-19 18:19 - 2026-05-24 00:26 - 000000000 ____D C:\Users\De*****\AppData\Local\UnrealEngine
2026-06-19 17:34 - 2026-05-16 18:39 - 000002309 _____ C:\Users\De*****\Desktop\Discord.lnk
2026-06-12 00:41 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2026-06-11 20:14 - 2026-05-17 10:33 - 000000000 ____D C:\Users\De*****\AppData\Local\JDownloader 2
2026-06-10 09:51 - 2026-04-30 08:15 - 000000000 ____D C:\Windows\system32\MRT
2026-06-10 09:50 - 2026-04-30 08:15 - 222431176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-06-10 07:54 - 2026-04-27 12:09 - 000000000 ____D C:\Windows\system32\Drivers\wd
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2026-05-11 21:22 - 2026-05-11 21:22 - 000000199 _____ () C:\Users\De*****\AppData\Roaming\DESKTOP-7N9OIEK.MTBF.txt
2026-06-11 20:10 - 2026-06-11 20:11 - 000008300 _____ () C:\Users\De*****\AppData\Local\krita-sysinfo.log
2026-06-11 20:10 - 2026-06-11 20:51 - 000000868 _____ () C:\Users\De*****\AppData\Local\krita.log
2026-06-11 20:51 - 2026-06-11 20:51 - 000000039 _____ () C:\Users\De*****\AppData\Local\kritadisplayrc
2026-06-11 20:10 - 2026-06-11 20:51 - 000003213 _____ () C:\Users\De*****\AppData\Local\kritarc
2026-05-17 10:49 - 2026-05-17 10:49 - 000001565 _____ () C:\Users\De*****\AppData\Local\recently-used.xbel
2026-07-04 22:54 - 2026-07-04 22:54 - 000000144 _____ () C:\Users\De*****\AppData\Local\Support.ini
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 02-07-2026
durchgeführt von De***** (06-07-2026 05:56:08)
Gestartet von C:\Users\De*****\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) (2026-04-27 10:10:37)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
Administrator (S-1-5-21-3912185912-3826206352-237317771-500 - Administrators - Disabled)
claud (S-1-5-21-3912185912-3826206352-237317771-1003 - Limited - Disabled)
De***** (S-1-5-21-3912185912-3826206352-237317771-1004 - Administrators - Enabled) => C:\Users\De*****
DefaultAccount (S-1-5-21-3912185912-3826206352-237317771-503 - Limited - Disabled)
Gast (S-1-5-21-3912185912-3826206352-237317771-501 - Limited - Disabled)
selin (S-1-5-21-3912185912-3826206352-237317771-1002 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3912185912-3826206352-237317771-504 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Photoshop Lightroom 5 64-bit (HKLM\...\{6C1A010F-9108-4162-A26F-9FEC4AC0F0F0}) (Version: 5.0.1 - Adobe)
AORUS ENGINE (HKLM-x32\...\AORUS ENGINE_is1) (Version: 2.3.1.0 - GIGABYTE Technology Co.,Inc.)
Corsair Device Control Service (HKLM\...\{7DABA693-C23D-4B86-B506-3B941CEDF1FF}) (Version: 1.9.9 - Corsair) Hidden
Corsair Device Control Service Bundle (HKLM-x32\...\{dffe1772-7f42-4dd2-ae7c-f07b34d720be}) (Version: 1.9.9 - Corsair)
Dazzle Video Capture DVC100 X64 Driver 1.09 (HKLM-x32\...\{FB4B9EB9-68B2-4C42-8C38-B65F8FE5A5CA}) (Version: 1.09.0000 - Pinnacle) Hidden
DazzleBDAX64 (HKLM-x32\...\{F28AD4BC-AE49-4735-9E50-64212BD2083B}) (Version: 1.06.0000 - Corel) Hidden
Discord (HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\Discord) (Version: 1.0.9243 - Discord Inc.)
Elgato Control Center (HKLM\...\{7C4F166A-6F89-4E48-851E-F7983793C7A1}) (Version: 1.8.2.714 - Corsair Memory, Inc.)
Elgato Stream Deck (HKLM\...\{C7AF453E-819C-487D-AD09-CDD3FF83BCB7}) (Version: 7.4.2.22730 - Corsair Memory, Inc.)
ENE Video Capture Box HAL (HKLM\...\{A096611D-BA11-4A1A-8D09-0A0462D7C8F2}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE Video Capture Box HAL (HKLM-x32\...\{974259bf-3ed1-4cd6-9ed1-40c7f601a786}) (Version: 1.0.5.15 - Ene Tech.) Hidden
ENE_AIC_Marvell_HAL (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_AIC_Marvell_HAL (HKLM-x32\...\{887e18fb-6bc3-4cd4-b34e-32d9ff71bbae}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden
ENE_DRAM_RGB_AIO (HKLM\...\{DFAD06E0-C5FC-4154-8F95-65871D5AB5BF}) (Version: 1.0.23.1 - Ene Tech.) Hidden
ENE_DRAM_RGB_AIO (HKLM-x32\...\{3a0741bc-3391-41cd-81aa-0122796a0648}) (Version: 1.0.23.1 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.17.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{6a0e18d7-c33b-4c8c-aa31-4beedf5956c6}) (Version: 1.0.17.0 - ENE TECHNOLOGY INC.) Hidden
ENE_External_Device_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_External_Device_HAL (HKLM-x32\...\{a7b1cf47-d8f0-423d-9494-568195f1c864}) (Version: 1.0.12.7 - ENE Tech) Hidden
ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.1.8 - ENE TECHNOLOGY INC.) Hidden
ENE_MousePad_HAL (HKLM-x32\...\{bf256b46-8ff7-48be-ab7f-5661e9a0651f}) (Version: 1.0.1.8 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
ENE_X_AIC_HAL (HKLM-x32\...\{c662a481-d76a-4188-95d2-6eb4ffd55542}) (Version: 1.0.6.3 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM\...\{49A4D983-CF26-4648-ABA6-B389B878E763}) (Version: 1.3.176.0 - Epic Games, Inc.)
Epic Online Services (HKLM-x32\...\{E8B44A12-7A40-43A7-928E-8DA376AFA1B7}) (Version: 5.2.0 - Epic Games, Inc.)
GBT_MB_Update (HKLM\...\GBT_MB_Update) (Version: 26.01.14.01 - GIGABYTE)
GBT_RGB_Sync_Control 26.03.25.01 (HKLM\...\GBT_RGB_Sync_Control) (Version: 26.03.25.01 - GIGABYTE)
GBT_rgbMotherboard_UC 25.12.23.01 (HKLM\...\GBT_rgbMotherboard_UC) (Version: 25.12.23.01 - GIGABYTE)
GBT_VGA 26.03.10.01 (HKLM\...\GBT_VGA) (Version: 26.03.10.01 - GIGABYTE)
GIGABYTE Control Center 26.03.26.01 (HKLM\...\GIGABYTE Control Center) (Version: 26.03.26.01 - GIGABYTE)
GIGABYTE Performance Library (HKLM\...\MBEasyTune) (Version: 26.03.19.01 - GIGABYTE)
GIGABYTE Storage Library (HKLM\...\MBStorage) (Version: 26.03.30.01 - GIGABYTE)
GIMP 3.2.4 (HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\GIMP-3_is1) (Version: 3.2.4.0 - The GIMP Team)
Hue Sync (HKLM\...\{C6402782-99C2-4495-B853-CD3A4976D582}) (Version: 1.13.1.83 - Signify Netherlands B.V.)
Iriun Webcam (HKLM-x32\...\IriunWebcam_is1) (Version: - )
JDownloader 2 (HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\jdownloader2) (Version: 2.0.260331 - AppWork GmbH)
Last.fm Desktop Scrobbler (HKLM-x32\...\{B13709CB-85AE-4F45-BFF9-2CB2B7A78F83}) (Version: 3.1.29 - Last.fm)
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: 2026.4.919028 - Logitech)
MakeMKV v1.18.3 (HKLM-x32\...\MakeMKV) (Version: v1.18.3 - GuinpinSoft inc)
Malwarebytes version 5.6.1.257 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.1.257 - Malwarebytes)
Microsoft .NET Host - 10.0.8 (x86) (HKLM-x32\...\{0F9FB11C-AD3C-4F55-B657-364489CAC99F}) (Version: 80.32.52183 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 10.0.8 (x86) (HKLM-x32\...\{0D5C8AE5-439B-4D3F-82CE-A0D14D9C4EF7}) (Version: 80.32.52183 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 10.0.8 (x86) (HKLM-x32\...\{CAE576AC-3499-4735-B4F8-D82B2D670BA1}) (Version: 80.32.52183 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.48 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 149.0.4022.98 - Microsoft Corporation) Hidden
Microsoft Office Standard 2019 - de-de (HKLM\...\Standard2019Volume - de-de) (Version: 16.0.10401.20025 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\OneDriveSetup.exe) (Version: 26.106.0603.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 10.0.8 (x86) (HKLM-x32\...\{B0AD693F-9836-4CEF-B4FD-CFEACD8290B5}) (Version: 80.32.52183 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime 10.0.8 (x86) (HKLM-x32\...\{DA4D6331-BCC8-4AEC-9120-498589CB7983}) (Version: 10.0.8.50000 - Microsoft Corporation)
MultiCam Capture 2.0 Lite (HKLM\...\{8F281193-9234-4F08-9624-42B1AF08B999}) (Version: 2.1.0.138 - Corel Corporation) Hidden
MyDVD Content Pack 1 (HKLM-x32\...\{ADCF7AE3-8E36-4B80-9460-66B74B56927F}) (Version: 1.00.0000 - Corel Corporation)
MyDVD Content Pack 2 (HKLM-x32\...\{B9987701-F119-46FA-BFF1-A8B593BFAF9E}) (Version: 1.00.0000 - Corel Corporation)
Norton Update Helper (HKLM-x32\...\{469D3039-E8BB-40CB-9989-158443EEA4EB}) (Version: 1.8.1994.6 - Norton LifeLock) Hidden
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.9.6.4 - Notepad++ Team)
NVIDIA App 11.0.7.237 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.7.237 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.7.12227.37421622 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.7.12227.37421622 - NVIDIA Corporation)
NVIDIA Grafiktreiber 596.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 596.36 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.4.5.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.7 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 32.1.2 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10401.20025 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10401.20025 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10401.20025 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0407-0000-0000000FF1CE}) (Version: 16.0.10401.20025 - Microsoft Corporation) Hidden
Open-Shell (HKLM\...\{828B8D4B-7BC6-47C7-81CD-9B5CC579C447}) (Version: 4.4.196 - The Open-Shell Team)
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{6e0eff60-c502-43bb-8f56-360ca07e73d9}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Pinnacle 3D Title Editor (HKLM\...\{7A863778-80BD-420B-B50B-BF3DD62DBC8A}) (Version: 1.0.10.302 - Corel Corporation) Hidden
Pinnacle Creative Pack Volume 1 (HKLM\...\{9E0ADCB8-A77F-43FD-A723-6A22BDDE7742}) (Version: 11.0 - Corel Corporation)
Pinnacle Hollywood FX Volumes 1-3 (HKLM\...\{BAF923F8-84EF-48D6-BB4F-5497D39D9EB3}) (Version: 10.0 - Corel Corporation)
Pinnacle MyDVD (HKLM\...\{C8F119D0-8BB5-4121-83CE-C13FC63B86CA}) (Version: 3.0.304.0 - Ihr Firmenname) Hidden
Pinnacle MyDVD (HKLM-x32\...\{A11758A5-E546-4B9D-906A-92F58BD32506}) (Version: 3.0 - Corel) Hidden
Pinnacle Premium Pack Volumes 1-2 (HKLM-x32\...\{AD9FEAC6-2C4D-45F9-968B-EA79DC7FBB29}) (Version: 10.0 - Corel Corporation)
Pinnacle ScoreFitter Volumes 1-2 (HKLM\...\{3627D5D2-A197-4059-AAF7-333D3E345B32}) (Version: 10.0 - Corel Corporation)
Pinnacle Studio - Standard Content Pack (HKLM\...\{B17FBF94-EF8A-4CA2-8281-EB0A729EB75C}) (Version: 26 - Corel Corporation)
Pinnacle Studio 26 (HKLM\...\{CB208FA7-D241-45B2-83E0-DD119C9FCAC5}) (Version: 26.2.0.298 - Corel Corporation)
Pinnacle Title Extreme (HKLM\...\{3C993EC4-A1EC-4B38-8D3F-96E089FB6182}) (Version: 10.0 - Corel Corporation)
RGB Fusion (HKLM-x32\...\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.24.1202.1 - Gigabyte)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.106.2879 - Rockstar Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
Verbatim_SureFireGaming_Product (HKLM\...\{35CB65C6-A7E3-4EE7-AD40-738D70A72164}) (Version: 1.0.3.11 - Verbatim) Hidden
Verbatim_SureFireGaming_Product (HKLM-x32\...\{d601832a-0d94-46ce-9b19-78e8a5887313}) (Version: 1.0.3.11 - Verbatim) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Voicemod (HKLM\...\{FE519A29-8B15-47C4-BCD6-A513277DC26F}_is1) (Version: 1.6.13 - Voicemod Inc., Sucursal en España)
WD P40 Game Drive (HKLM\...\{EE55DBAE-ECDD-4ADD-AAB5-23DE848B0996}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden
WD P40 Game Drive (HKLM-x32\...\{72b1a866-fc31-4381-bff3-fa6cd8823777}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden
WinRAR 7.22 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 7.22.0 - win.rar GmbH)
YouTube Music Desktop App (HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\youtube_music_desktop_app) (Version: 2.0.11 - NovusTheory)
Packages:
=========
Hue Sync -> C:\Program Files\Hue Sync [2026-05-11] (Signify Netherlands B.V.) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2026-04-30] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2026-04-30] (Realtek Semiconductor Corp)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-3912185912-3826206352-237317771-1004_Classes\CLSID\{e13cc75c-3ffc-4561-9482-33bbaa8b710c}\localserver32 -> C:\Program Files\Elgato\ControlCenter\ControlCenter.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Open-Shell\ClassicExplorer64.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Open-Shell\ClassicExplorer64.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2026-05-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2026-05-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-04] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers5: [NvAppDesktopContext] -> {F2E8B4A1-9C7D-4F6E-B3A5-8D2C1F4E9B7A} => C:\Program Files\NVIDIA Corporation\NVIDIA App\NvCpl\nvui.dll [2026-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_67995ceab8993b08\nvshext.dll [2026-04-23] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-07-04] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\Windows\system32\StartMenuHelper64.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2026-05-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2026-05-01] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Drivers32: [vidc.mjpg] => pvmjpgx40.dll
HKLM\...\Drivers32: [vidc.pDAD] => C:\Windows\SysWOW64\prodad-codec.dll [506312 2021-04-12] (proDAD GmbH -> proDAD GmbH)
==================== Verknüpfungen & WMI ========================
==================== Geladene Module (Nicht auf der Ausnahmeliste) =============
2026-05-15 19:48 - 2019-08-05 13:26 - 000025088 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\BSL430.dll
2026-05-15 19:48 - 2019-08-05 13:26 - 000225792 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvFireware.dll
2026-05-15 19:48 - 2022-04-01 15:48 - 000045056 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvIntelI2C.dll
2026-05-15 19:48 - 2021-05-04 11:39 - 000185344 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\ITEDriver.dll
2026-05-11 21:27 - 2026-03-17 12:44 - 000086016 ____N () [Datei ist nicht signiert] C:\Users\De*****\AppData\Roaming\Elgato\StreamDeck\Plugins\com.elgato.discord.sdPlugin\z.dll
2026-05-11 21:06 - 2026-05-11 21:06 - 000049664 _____ () [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_64\ControlCentdba37129#\10ea5854cafa7b86c0c4d8e1623957d0\ControlCenter.XmlSerializers.ni.dll
2026-05-11 21:06 - 2026-05-11 21:06 - 002301952 _____ (deniszykov) [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_64\deniszykov.615d72e4#\28a429c507507671a8efbfb516c74769\deniszykov.WebSocketListener.ni.dll
2026-05-15 19:48 - 2021-12-22 15:15 - 000732672 _____ (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvComW.dll
2026-05-15 19:48 - 2019-08-05 13:26 - 000013312 _____ (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvCrypt.dll
2026-05-15 19:48 - 2022-06-23 10:13 - 000524800 _____ (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GVDisplay.dll
2026-05-15 19:48 - 2020-11-05 14:16 - 000268800 _____ (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvIllumLib.dll
2026-05-15 19:48 - 2019-08-05 13:26 - 000218112 _____ (GIGABYTE Technology Co.,Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvOrderLib.dll
2026-05-11 21:00 - 2026-05-11 21:00 - 001093120 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL
2026-05-11 21:00 - 2026-05-11 21:00 - 000065536 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80DEU.DLL
2025-05-08 08:22 - 2025-05-08 08:22 - 000994304 _____ (Open-Shell) [Datei ist nicht signiert] C:\Program Files\Open-Shell\ClassicExplorer64.dll
2025-05-08 08:21 - 2025-05-08 08:21 - 002777600 _____ (Open-Shell) [Datei ist nicht signiert] C:\Program Files\Open-Shell\StartMenuDLL.dll
2025-05-08 08:22 - 2025-05-08 08:22 - 000438272 _____ (Open-Shell) [Datei ist nicht signiert] C:\Windows\system32\StartMenuHelper64.dll
2026-05-15 19:48 - 2019-08-27 13:22 - 000224256 _____ (TODO: <Company name>) [Datei ist nicht signiert] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvAutoUpdate.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\Users\De*****\Desktop\adwcleaner.exe:MBAM.Zone.Identifier [141]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================
==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Open-Shell\ClassicExplorer64.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Open-Shell\ClassicExplorer32.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Open-Shell\ClassicExplorer64.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Open-Shell\ClassicExplorer32.dll [2025-05-08] (Open-Shell) [Datei ist nicht signiert]
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-05-12] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts Inhalt: =========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2019-12-07 11:14 - 2019-12-07 11:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Network ===========================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
DNS Servers: 192.168.1.1
ist aktiviert.
Network Binding:
=============
Bluetooth-Netzwerkverbindung: Bluetooth Device (Personal Area Network) -> bthpan.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
==================== Andere Bereiche ===========================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\De*****\Pictures\yotei_wallpaper.png
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 5) (TamperProtectionSource: )
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_A734CDB21F65BACD27474256D84E27D6"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "Opera GX Stable"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "Opera GX Browser Assistant"
HKU\S-1-5-21-3912185912-3826206352-237317771-1004\...\StartupApproved\Run: => "VoicemodV3"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{BEF85657-E578-4D5F-852D-C07BD2870558}] => (Allow) C:\Program Files\Elgato\ControlCenter\ControlCenter.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
FirewallRules: [TCP Query User{7BC350D1-1823-4394-8D05-B90806DEBCB1}C:\program files\hue sync\huesync.exe] => (Allow) C:\program files\hue sync\huesync.exe (Signify Netherlands B.V. -> Signify Netherlands B.V.)
FirewallRules: [UDP Query User{311D4903-ABC2-47A2-BBE4-EFA8940578D7}C:\program files\hue sync\huesync.exe] => (Allow) C:\program files\hue sync\huesync.exe (Signify Netherlands B.V. -> Signify Netherlands B.V.)
FirewallRules: [{9C3F5053-CD7E-4FAD-B110-83B5CC23D1A8}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\RM.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{CEFDD12B-7FAE-4917-B486-792F514FF6CB}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\RM.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{8A1F47D8-ACE6-40E6-8D39-1A04463A057B}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\NGStudio.exe () <==== ACHTUNG [Null Byte Datei/Ordner]
FirewallRules: [{2DEA488B-589C-438B-A2F3-59B0273D5DA8}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\NGStudio.exe () <==== ACHTUNG [Null Byte Datei/Ordner]
FirewallRules: [{12C38129-15A3-4FC9-AE25-0F50F32A069B}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\UMI.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{A8834EFF-522C-46C8-BCF4-9091665DF3C3}] => (Allow) C:\Program Files\Pinnacle\Studio 26\programs\UMI.exe (Corel Corporation -> Pinnacle)
FirewallRules: [TCP Query User{E6E5DDDE-E6CC-4DB5-ADA0-37E054B87AE8}C:\program files\obs-studio\obs-plugins\64bit\obs-browser-page.exe] => (Allow) C:\program files\obs-studio\obs-plugins\64bit\obs-browser-page.exe (OBS Project, LLC -> )
FirewallRules: [UDP Query User{DFABD219-5C9E-4CB4-97DF-D51AACEABCDF}C:\program files\obs-studio\obs-plugins\64bit\obs-browser-page.exe] => (Allow) C:\program files\obs-studio\obs-plugins\64bit\obs-browser-page.exe (OBS Project, LLC -> )
FirewallRules: [{741FB140-61E0-4296-B075-924A343866C7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{ADDC789D-3361-40F0-AA77-EC8D94A3941D}] => (Allow) C:\Program Files\GIGABYTE\Control Center\GCC.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{364F069F-117C-44F8-BBC6-25F8D64001BE}] => (Allow) C:\Program Files\Elgato\Volume Controller\ElgatoAudioControlServer.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
FirewallRules: [{2971C988-59E6-4121-BA5C-699736C85BC3}] => (Allow) C:\Program Files\obs-studio\bin\64bit\obs64.exe (OBS Project, LLC -> OBS)
FirewallRules: [{3F8F98B2-F135-41CF-A159-2B1D1D39A237}] => (Allow) C:\Program Files\Elgato\StreamDeck\StreamDeck.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
FirewallRules: [TCP Query User{B6401BCA-6D56-49D8-AC1B-8CA5495E2045}C:\users\De*****\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\De*****\appdata\local\programs\opera gx\opera.exe => Keine Datei
FirewallRules: [UDP Query User{EE7B8624-FF25-4C03-993B-F90F4C435EBE}C:\users\De*****\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\De*****\appdata\local\programs\opera gx\opera.exe => Keine Datei
FirewallRules: [TCP Query User{AF58695F-7EF0-41D7-81A0-6CEA9FC2C1F6}C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{47E70EC5-20A4-4E07-A12D-915973EB8631}C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{D29C7FDA-1F90-4852-AA2B-714075E89E6A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F977251F-E3B0-496A-AE2A-26A298448AD7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F8FAFADB-05D3-4F5A-BE38-743C7F7BD09C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B909EECD-E7AC-4222-8A93-0AAC0D5DC972}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5AB89A66-A2EA-49D9-871D-1A0E44A5F0AC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Walking Dead The Telltale Definitive Series\WDC.exe (Telltale Games) [Datei ist nicht signiert]
FirewallRules: [{6F562F79-4433-4C29-8065-6FDA5544120A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Walking Dead The Telltale Definitive Series\WDC.exe (Telltale Games) [Datei ist nicht signiert]
FirewallRules: [{2FDDBF44-01BA-4366-97D1-7264667C8B0F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\lis2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [Datei ist nicht signiert]
FirewallRules: [{A3A1F8F8-B780-49FE-B6AF-095EE248201C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\lis2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [Datei ist nicht signiert]
FirewallRules: [{D156EF6A-6DA5-405E-B830-6BF518FCAB82}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MECCHA CHAMELEON\PenguinHotel.exe (Error3: CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [{14783131-3FB1-4D74-BA03-9500E69E85AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MECCHA CHAMELEON\PenguinHotel.exe (Error3: CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [TCP Query User{DDC6F3DD-1A64-4F9B-80A7-03404A052360}C:\program files (x86)\steam\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe (Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{6CB66F7D-93FF-488B-AB7B-786D8918334E}C:\program files (x86)\steam\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe (Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [{64544FBE-4500-4236-A5FA-08A4ED80C739}] => (Allow) C:\Program Files (x86)\Iriun Webcam\IriunWebcam.exe (IriunWebcam) [Datei ist nicht signiert]
FirewallRules: [TCP Query User{4215F917-9B59-4C2B-B46A-D7417C5ADC35}C:\users\De*****\appdata\local\youtube_music_desktop_app\app-2.0.11\youtube-music-desktop-app.exe] => (Allow) C:\users\De*****\appdata\local\youtube_music_desktop_app\app-2.0.11\youtube-music-desktop-app.exe (NovusTheory) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{DD3569A7-F58C-438F-B87B-CC6943F273ED}C:\users\De*****\appdata\local\youtube_music_desktop_app\app-2.0.11\youtube-music-desktop-app.exe] => (Allow) C:\users\De*****\appdata\local\youtube_music_desktop_app\app-2.0.11\youtube-music-desktop-app.exe (NovusTheory) [Datei ist nicht signiert]
FirewallRules: [{D2B9EA81-077C-4C20-B83B-5557A88832A0}] => (Allow) C:\Program Files\Voicemod V3\Voicemod.exe (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod Inc.)
FirewallRules: [{31E8F000-B014-40F4-B04C-34C95C28BF1C}] => (Allow) C:\Users\De*****\AppData\Local\VoicemodV3\app\last\Voicemod.exe (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod Inc., Sucursal en España)
FirewallRules: [{3338592C-679F-45BC-8C1C-38AF996CBF5A}] => (Allow) C:\Program Files\Voicemod V3\Voicemod.exe (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod Inc.)
FirewallRules: [{665905E3-B126-4E82-9769-BB94257A38E7}] => (Allow) C:\Users\De*****\AppData\Local\VoicemodV3\app\last\Voicemod.exe (VOICEMOD, INC. SUCURSAL EN ESPAÑA -> Voicemod Inc., Sucursal en España)
FirewallRules: [{7826FC77-363E-4FFA-BF88-F91B59214130}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B9AAF61D-2343-4EBD-9988-AFB3ADEED071}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AD1B509C-5E1A-4C6A-81FB-61ED039263D3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{41109D83-F279-4889-BFA0-3453C02CFC72}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2606.60031.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{253A814C-2BB8-4271-BDD3-4874D6900D66}C:\program files\gigabyte\control center\gcc.exe] => (Allow) C:\program files\gigabyte\control center\gcc.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [UDP Query User{C6AC78AA-6416-4EF6-9E61-1348749CD672}C:\program files\gigabyte\control center\gcc.exe] => (Allow) C:\program files\gigabyte\control center\gcc.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [TCP Query User{26D02E39-7B99-4D68-A6AA-3D884346F9EA}C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{B395CFB2-C4C3-45A7-9F06-39C21595EAD2}C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
==================== Wiederherstellungspunkte =========================
28-06-2026 15:40:27 Geplanter Prüfpunkt
05-07-2026 21:33:36 AdwCleaner_BeforeCleaning_05/07/2026_21:33:35
==================== Fehlerhafte Geräte im Gerätemanager ============
==================== Fehlereinträge in der Ereignisanzeige: ========================
Applikationsfehler:
==================
Error: (07/06/2026 05:53:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Last.fm Desktop Scrobbler.exe, Version: 3.1.29.1, Zeitstempel: 0x5be9c779
Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.19041.6093, Zeitstempel: 0xcff64e29
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0011f2ed
ID des fehlerhaften Prozesses: 0x5194
Startzeit der fehlerhaften Anwendung: 0x01dd0cfb0cfb6ca9
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
Pfad des fehlerhaften Moduls: C:\Windows\system32\wmp.dll
Berichtskennung: 634d0ed6-7911-4151-8c30-f993932aad32
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/05/2026 09:30:52 PM) (Source: GigabyteOLEDDisplayService) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. Das Handle ist ungültig
Error: (07/05/2026 09:29:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Last.fm Desktop Scrobbler.exe, Version: 3.1.29.1, Zeitstempel: 0x5be9c779
Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.19041.6093, Zeitstempel: 0xcff64e29
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0011f2ed
ID des fehlerhaften Prozesses: 0x4adc
Startzeit der fehlerhaften Anwendung: 0x01dd0cb496a5762c
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
Pfad des fehlerhaften Moduls: C:\Windows\system32\wmp.dll
Berichtskennung: 70b042c1-944b-4ea2-9377-2c193e09d511
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/05/2026 02:45:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Last.fm Desktop Scrobbler.exe, Version: 3.1.29.1, Zeitstempel: 0x5be9c779
Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.19041.6093, Zeitstempel: 0xcff64e29
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0011f2ed
ID des fehlerhaften Prozesses: 0xe0c
Startzeit der fehlerhaften Anwendung: 0x01dd0c7c37df07d6
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
Pfad des fehlerhaften Moduls: C:\Windows\system32\wmp.dll
Berichtskennung: 53599caf-111b-49f7-95c2-51e237b1d0f5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/05/2026 08:22:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Last.fm Desktop Scrobbler.exe, Version: 3.1.29.1, Zeitstempel: 0x5be9c779
Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.19041.6093, Zeitstempel: 0xcff64e29
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0011f2ed
ID des fehlerhaften Prozesses: 0x302c
Startzeit der fehlerhaften Anwendung: 0x01dd0c469dd8aa44
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
Pfad des fehlerhaften Moduls: C:\Windows\system32\wmp.dll
Berichtskennung: 2a54f263-7ecd-407e-8314-3dfe0d51c480
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/04/2026 11:45:42 PM) (Source: GigabyteOLEDDisplayService) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. Das Handle ist ungültig
Error: (07/04/2026 11:44:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Last.fm Desktop Scrobbler.exe, Version: 3.1.29.1, Zeitstempel: 0x5be9c779
Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.19041.6093, Zeitstempel: 0xcff64e29
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0011f2ed
ID des fehlerhaften Prozesses: 0xba0
Startzeit der fehlerhaften Anwendung: 0x01dd0bfe3d80e06c
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Last.fm\Last.fm Desktop Scrobbler\Last.fm Desktop Scrobbler.exe
Pfad des fehlerhaften Moduls: C:\Windows\system32\wmp.dll
Berichtskennung: 6910ccdc-71e0-45cc-b86c-6665de86b5b5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (07/04/2026 11:42:43 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007045b, Der Computer wird heruntergefahren..
Systemfehler:
=============
Error: (07/05/2026 09:34:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "EasyTune Engine Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/05/2026 09:34:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "GIGABYTE AORUS LCD Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/05/2026 09:34:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (07/05/2026 09:34:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "FrameView SDK service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/05/2026 09:34:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "NVIDIA Display Container LS" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 6000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (07/05/2026 09:34:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "LGHUB Updater Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (07/05/2026 09:34:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Realtek Audio Universal Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (07/05/2026 09:34:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "GIGABYTE Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Windows Defender:
================
Date: 2026-07-03 22:45:34
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.EN.A!ml&threatid=2147810995&enterprise=0
Name: Trojan:Script/Sabsik.EN.A!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\Generative\python37.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: OPFER\De*****
Prozessname: C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\Generative\Setup.exe
Sicherheitsversion: AV: 1.453.410.0, AS: 1.453.410.0, NIS: 1.453.410.0
Modulversion: AM: 1.1.26050.11, NIS: 1.1.26050.11
Date: 2026-07-03 22:41:24
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.EN.A!ml&threatid=2147810995&enterprise=0
Name: Trojan:Script/Sabsik.EN.A!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\python37.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: OPFER\De*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.453.410.0, AS: 1.453.410.0, NIS: 1.453.410.0
Modulversion: AM: 1.1.26050.11, NIS: 1.1.26050.11
Date: 2026-07-03 22:41:16
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.EN.A!ml&threatid=2147810995&enterprise=0
Name: Trojan:Script/Sabsik.EN.A!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\python37.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: OPFER\De*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.453.410.0, AS: 1.453.410.0, NIS: 1.453.410.0
Modulversion: AM: 1.1.26050.11, NIS: 1.1.26050.11
Date: 2026-07-03 22:39:56
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.EN.A!ml&threatid=2147810995&enterprise=0
Name: Trojan:Script/Sabsik.EN.A!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\python37.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: OPFER\De*****
Prozessname: C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\Setup.exe
Sicherheitsversion: AV: 1.453.410.0, AS: 1.453.410.0, NIS: 1.453.410.0
Modulversion: AM: 1.1.26050.11, NIS: 1.1.26050.11
Date: 2026-07-03 22:37:39
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.EN.A!ml&threatid=2147810995&enterprise=0
Name: Trojan:Script/Sabsik.EN.A!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\python37.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: OPFER\De*****
Prozessname: C:\Users\De*****\Desktop\Adobe Photoshop 2026 v27.7 Portable\Sandbox\Adobe Photoshop 2026\roaming\modified\@PROGRAMFILES@\Adobe\Adobe Photoshop 2026\Plug-ins\Setup.exe
Sicherheitsversion: AV: 1.453.410.0, AS: 1.453.410.0, NIS: 1.453.410.0
Modulversion: AM: 1.1.26050.11, NIS: 1.1.26050.11
Event[0]:
Date: 2026-07-04 23:42:43
Description:
Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Security Intelligence aufgetreten. Es wird versucht, zu einer vorherigen Version zurückzukehren.
Security Intelligence versucht: Aktuell
Fehlercode: 0x80501102
Fehlerbeschreibung: Unerwartetes Problem. Installieren Sie bei Bedarf verfügbare Updates, und starten Sie das Programm dann erneut. Informationen zum Installieren von Updates finden Sie unter "Hilfe und Support".
Security Intelligence-Version: 1.453.410.0;1.453.410.0
Modulversion: 1.1.26050.11
Date: 2026-07-04 20:59:43
Description:
Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.453.410.0
Update Source: Microsoft Update-Server
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.26050.11
Fehlercode: 0x8024402c
Fehlerbeschreibung: Unerwartetes Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates oder zur Problembehandlung finden Sie unter "Hilfe und Support".
Date: 2026-04-30 08:07:36
Description:
Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.303.25.0
Update Source: Microsoft Center zum Schutz vor Schadsoftware
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\Netzwerkdienst
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.16400.2
Fehlercode: 0x80072ee7
Fehlerbeschreibung: Der Servername oder die Serveradresse konnte nicht verarbeitet werden.
Date: 2026-04-30 08:07:36
Description:
Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.303.25.0
Update Source: Microsoft Center zum Schutz vor Schadsoftware
Sicherheitstyp: AntiSpyware
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\Netzwerkdienst
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.16400.2
Fehlercode: 0x80072ee7
Fehlerbeschreibung: Der Servername oder die Serveradresse konnte nicht verarbeitet werden.
Date: 2026-04-30 08:07:36
Description:
Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.303.25.0
Update Source: Microsoft Center zum Schutz vor Schadsoftware
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\Netzwerkdienst
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.16400.2
Fehlercode: 0x80072ee7
Fehlerbeschreibung: Der Servername oder die Serveradresse konnte nicht verarbeitet werden.
CodeIntegrity:
===============
Date: 2026-07-05 21:31:53
Description:
Code Integrity determined that a process (\Device\HarddiskVolume7\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume7\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements.
Date: 2026-07-05 21:30:54
Description:
Code Integrity determined that a process (\Device\HarddiskVolume7\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
==================== Speicherinformationen ===========================
BIOS: American Megatrends International, LLC. FC 06/08/2023
Hauptplatine: Gigabyte Technology Co., Ltd. B550 GAMING X V2
Prozessor: AMD Ryzen 7 5700X 8-Core Processor
Prozentuale Nutzung des RAM: 22%
Installierter physikalischer RAM: 32688.33 MB
Verfügbarer physikalischer RAM: 25441.99 MB
Summe virtueller Speicher: 64688.33 MB
Verfügbarer virtueller Speicher: 56523.6 MB
==================== Laufwerke ================================
Drive c: (System) (Fixed) (Total:1862.35 GB) (Free:1592.32 GB) (Model: WD_BLACK SN7100 2TB) NTFS
Drive d: (System ALT) (Fixed) (Total:930.85 GB) (Free:106.12 GB) (Model: WD_BLACK SN750 SE NVMe 1TB) NTFS
\\?\Volume{c57d8c83-53af-4995-942e-9f7cfbf3a066}\ () (Fixed) (Total:0.55 GB) (Free:0.07 GB) NTFS
\\?\Volume{00d0777e-346e-47a2-8901-83d7a35a08e0}\ () (Fixed) (Total:0.55 GB) (Free:0.08 GB) NTFS
\\?\Volume{edcb1fc1-59a0-42b4-8a72-3b72ea5eac54}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
\\?\Volume{940704ec-8f6c-4c7d-af09-c59c244c4c87}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partitionstabelle ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT.
==================== Ende von Addition.txt ======================= |