Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   PC ist seit Jahren Infiziert (https://www.trojaner-board.de/222064-pc-seit-jahren-infiziert.html)

anonym_20 02.10.2026 12:36

PC ist seit Jahren Infiziert
 
Seit Jahren wird mein PC, Fernseher(die haben irgendwas draufgespielt dass man sogar Netflix fest im Smart integriert ist gelöscht und wurde immer wieder von unbekannten mit Trojanern infiziert. Das Modem genauso. insgesamt sind mir 3 PCs ,Fernseher ,Laptop, Roboter Staubsauger die am anfang sehr gut funktionierte und dann nach 3 tagen plötzlich sich ständig ohne ein ziel überall angestossen ist. ich habe mehrmals die wohnungs-karte rausgeladen , die aber immer wieder manipulert wurde wie beim pc.

Dieses PC ist neu und hab es gekauft nachdem mir hier geraten wurde ein neues PC zu kaufen für 2000Euro. Und trotzdem hat es wieder macken. Schon nachdem ich Ihn einrichten wollte, und ich mich mit dem Internet verbunden habe, war es 3stunden lang nur warten. worauf? Keine Ahnung es hat gar nicht geupdadet. Die List war leer. Aber hier mal Security Checker.
Momentan hat es keine Probleme aber ich bin nicht sicher! Deshalb die LOGS von SecurityChecker und FRST:

Zitat:

SecurityCheck by glax24 & Severnyj v.1.4.0.58 [15.08.24]
WebSite: www.safezone.cc
DateLog: 02.10.2026 12:23:31
Path starting: C:\Users\*****\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: *****
VersionXML: 16.90is-01.10.2026
___________________________________________________________________________

Windows 11 Core (x64) Release: 26H2 (10.0.26300.9550) Lang: German(0407)
Installation date OS: 20.06.2026 00:36:33
LicenseStatus: Windows(R), Core edition The machine is permanently activated.
LicenseStatus: Office 21, Office21ProPlus2021MSDNR_Retail edition The machine is permanently activated.
LicenseStatus: Office 21, Office21ProPlus2021R_Grace edition Windows is in Notification mode
LicenseStatus: Office 16, Office16O365HomePremR_Grace edition Windows is in Notification mode
Boot Mode: Normal
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
SystemDrive: C: FS: [NTFS] Capacity: [897.4 Gb] Used: [289.8 Gb] Free: [607.6 Gb]
------------------------------- [ Windows ] -------------------------------
User Account Control enabled (Level 4)
Sicherheitscenter (wscsvc) - The service is running
Remoteregistrierung (RemoteRegistry) - The service has stopped
SSDP-Suche (SSDPSRV) - The service is running
Remotedesktopdienste (TermService) - The service is running
Windows-Remoteverwaltung (WS-Verwaltung) (WinRM) - The service has stopped
Background Intelligent Transfer Service (BITS) - The service has stopped
Übermittlungsoptimierung (DoSvc) - The service has stopped
Windows-Sicherheitsdienst (SecurityHealthService) - The service is running
Update Orchestrator Service (UsoSvc) - The service is running
WaaSMedicSvc (WaaSMedicSvc) - The service has stopped
Windows Update (wuauserv) - The service has stopped
---------------------------- [ Antivirus_WMI ] ----------------------------
Windows Defender (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Defender Firewall (mpssvc) - The service is running
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Avira Secure Browser v.152.0.35367.42
Avira Update Helper v.1.8.1997.6
-------------------------- [ SecurityUtilities ] --------------------------
LockHunter 3.4, 32/64 bit v.3.4.3.146
--------------------------- [ OtherUtilities ] ----------------------------
Microsoft 365 - de-de v.16.0.20430.20092 [+]
Microsoft Office Professional Plus 2021 - de-de v.16.0.20430.20092 [+]
NVIDIA App 11.0.9.251 v.11.0.9.251
Microsoft Edge WebView2-Laufzeit v.154.0.4258.48
Intel® Driver & Support Assistant v.26.2.0.7
Microsoft Visual C++ v14 Redistributable (x86) - 14.50.35719 v.14.50.35719.0 Warning! Download Update
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 v.14.50.35719.0 Warning! Download Update
------------------------------ [ ArchAndFM ] ------------------------------
WinRAR 7.23 (64-Bit) v.7.23.0
-------------------------------- [ Media ] --------------------------------
VLC media player v.3.0.23 Warning! Download Update
iTunes v.12.13.11.1
------------------------------- [ Browser ] -------------------------------
Mozilla Firefox (x64 de) v.157.0
Google Chrome v.154.0.8037.98 [+]
Microsoft Edge v.154.0.4258.48
------------------ [ AntivirusFirewallProcessServices ] -------------------
Microsoft Defender Core-Dienst (MDCoreSvc) - The service is running
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MpDefenderCoreService.exe v.4.18.26080.4
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\MsMpEng.exe v.4.18.26080.4
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0\NisSrv.exe v.4.18.26080.4
Microsoft Defender Antivirus-Dienst (WinDefend) - The service is running
Microsoft Defender Antivirus-Netzwerkinspektionsdienst (WdNisSvc) - The service is running
----------------------------- [ End of Log ] ------------------------------






FRST Additions Logfile:

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 01-10-2026
durchgeführt von ***** (02-10-2026 12:25:52)
Gestartet von C:\Users\*****\OneDrive\Desktop
Microsoft Windows 11 Home Version 26H2 26300.9550 (X64) (2026-06-20 00:36:33)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

Administrator (S-1-5-21-21875824-1833468012-1891651564-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-21875824-1833468012-1891651564-503 - 0 - Disabled)
Gast (S-1-5-21-21875824-1833468012-1891651564-501 - 0 - Disabled)
***** (DisplayName: G**** - *C)  (S-1-5-21-21875824-1833468012-1891651564-1007 - Administrators - Enabled) [MS Account] => C:\Users\*****
WDAGUtilityAccount (S-1-5-21-21875824-1833468012-1891651564-504 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Apple Mobile Device Support (HKLM\...\{A1147B7D-734A-49BD-A6CA-E41E2B4B7B8F}) (Version: 20.0.0.35 - Apple Inc.)
Avira Secure Browser (HKLM-x32\...\Avira Secure Browser) (Version: 152.0.35367.42 - Die Avira Secure Browser-Autoren)
Avira Update Helper (HKLM-x32\...\{25A7DD46-F34D-4979-9C3D-BFB147368DD6}) (Version: 1.8.1997.6 - Avira) Hidden
Documentation Manager (HKLM\...\{40C886AE-8BEE-49A9-A980-30CCC810B262}) (Version: 24.70.0.3 - Intel Corporation) Hidden
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.743.1.6250 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{bdbc521f-cb3d-4738-b6ac-90b33e222f8d}) (Version: 13.743.1.6250 - Electronic Arts)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 154.0.8037.98 - Google LLC)
HP EmailSMTP Plugin (HKLM\...\{EB8C0C19-AB72-4A10-AA2A-1E9A576C2D5E}) (Version: 56.0.529.0 - HP)
HP Enabling Services (HKLM\...\{EB4E9E57-5044-4FDB-913F-2BA903AC53B0}) (Version: 6.9.0.1017 - HP Inc.)
HP ENVY Inspire 7900 series - Grundlegende Software für das Gerät (HKLM\...\{1933D1B2-8E2B-46E4-B0F8-A1C36A3828CB}) (Version: 55.4.5082.2256 - HP Inc.)
HP Envy Photo 7900 series - Grundlegende Software für das Gerät (HKLM\...\{922FC23F-853F-48D6-8251-37E0ED7167FA}) (Version: 63.1.2123.25253 - HP Inc.)
HP FTP Plugin (HKLM\...\{703CEAD3-DC8D-4902-9DCF-CE45D912922A}) (Version: 56.0.480.0 - HP)
HP OCR (HKLM-x32\...\{04A83156-5855-4FB4-96A3-D8E95B6F3B74}) (Version: 1.0.1020.0 - HP Inc.)
HP PSDr NTService Component (HKLM\...\{7FF0066D-7114-4A27-8F1E-7C17CB4542D1}) (Version: 11.8.0.0 - HP Inc.)
HP Scan - Grundlegende Software für das Gerät (HKLM\...\{5A837DCB-4006-47BF-8094-CD4FC291BF67}) (Version: 63.8.6459.26156 - HP Inc.)
HP SFTP Plugin (HKLM\...\{F3997C1C-E4F4-4856-A045-BF4CD1EE46C3}) (Version: 56.0.529.0 - HP Inc.)
HP SharePoint Plugin (HKLM\...\{24A4DCC1-2DA3-446F-9455-ADF0ADCBBB19}) (Version: 56.0.529.0 - HP)
Intel Driver && Support Assistant (HKLM-x32\...\{2C633E0E-1F95-42CC-95D8-63C12DD9672F}) (Version: 26.2.0.7 - Intel) Hidden
Intel(R) Icls (HKLM\...\{5AC763E5-494E-410F-832D-450C41DEB63B}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2435.6.36.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{EAF1D7D8-7514-48F8-AAE6-49A6CBAA66BC}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{9D7BB5D9-5975-43F0-A31F-63589939A14D}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME WMI Provider (HKLM\...\{0B44BD9A-7327-4EA3-8C44-C4C7A4B1777E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) NPU Software & Drivers (HKLM\...\Intel(R) NPU Software & Drivers) (Version: 1.0.17.0 - Intel(R) Corporation)
Intel(R) Serial IO (HKLM\...\{49B19848-D806-4774-B5B4-C67C4E098E22}) (Version: 30.100.2419.23 - Intel Corporation) Hidden
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.2419.23 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000070-0240-1031-84C8-B8D95FA3C8C3}) (Version: 24.70.0.4 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{039CECE9-B083-4114-AFC7-5CDBA4321241}) (Version: 26.2.0.7 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{4152D055-4116-42A3-BC9E-86D0A17B35A5}) (Version: 25.4.36.6 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{C8093AA3-B113-4F81-9A87-B1C41929B346}) (Version: 26.1.0.2 - Intel)
Intel® Software Installer (HKLM\...\{55AFCB51-121C-4654-B9A3-6EADAA94CD2B}) (Version: 24.40.0.4 - Intel Corporation) Hidden
Intel® Software Installer (HKLM\...\{B80ACD63-2F12-4509-A6D9-A782A2642754}) (Version: 24.10.0.4 - Intel Corporation) Hidden
Intel® Software Installer (HKLM\...\{EB9FE660-9D60-40B6-9D16-5610C81513E5}) (Version: 24.70.0.3 - Intel Corporation) Hidden
IRIS Software Download Tool (HKLM-x32\...\{8F0E9102-8D90-419C-B42B-B2E48403A5C0}) (Version: 1.0.44.0 - HP Inc.)
iTunes (HKLM\...\{F7F4BCB2-0D0F-46DA-9896-303008DC6DBA}) (Version: 12.13.11.1 - Apple Inc.)
LockHunter 3.4, 32/64 bit (HKLM\...\LockHunter_is1) (Version: 3.4.3.146 - Crystal Rich Ltd)
Medion Service App (HKLM\...\{F1A17BC3-7C28-4F3D-8835-BF78282D11B7}) (Version: 3.0.0.0 - Medion)
Medion-Service (HKLM\...\{ED61C980-1719-427E-8522-78B239E8A9F9}) (Version: 1.0.44 - Medion AG)
Microsoft .NET 10.0 Templates 10.0.101 x64 (HKLM\...\{89689C38-93A6-4065-9783-47E96FC49A85}) (Version: 40.10.18029 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 10.0.1 (x64) (HKLM\...\{97247546-3F97-4F4F-A02F-4563A48CBD10}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host - 10.0.1 (x64) (HKLM\...\{9A3CDC3E-B643-4C13-8F8B-1E7F999A0C61}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.14 (x64) (HKLM\...\{04904762-A110-4E46-A728-7EF88DCCA1F1}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.14 (x86) (HKLM-x32\...\{CB771E25-82B7-435C-B8CF-1DAF85D9A373}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host - 9.0.3 (x64) (HKLM\...\{E29A8846-BD00-4830-8BDF-7CC3E81C5385}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 10.0.1 (x64) (HKLM\...\{12D4B30A-B8DE-496F-ABBA-8E355A7E2652}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.14 (x64) (HKLM\...\{B2E7F2C8-73CD-4269-B7BC-11B7D8BB7A37}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.14 (x86) (HKLM-x32\...\{455AA7CD-6D99-4039-95D2-FF1A437FD444}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 9.0.3 (x64) (HKLM\...\{0FD489DC-A3E9-4F57-9770-812CD1059FA5}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 10.0.1 (x64) (HKLM\...\{DD248F59-C0EC-48F9-B8DB-CB8268F9E028}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.14 (x64) (HKLM\...\{6C817CE3-32BC-4C6B-8B1A-E6F71EDAFFCC}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.14 (x86) (HKLM-x32\...\{6E39BE88-1272-4732-A962-9B34A31EE12C}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 9.0.3 (x64) (HKLM\...\{102DCD41-F00B-484D-9D6B-5D2919D8FCF8}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET SDK 10.0.101 (x64) (HKLM-x32\...\{F9366523-19F5-49F6-9F27-3F27B596471D}) (Version: 10.1.125.57005 - Microsoft Corporation)
Microsoft .NET Targeting Pack - 10.0.1 (x64) (HKLM\...\{010930C3-106A-4DD2-B08C-E93615935B26}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Toolset 10.0.101 (x64) (HKLM\...\{E6BC5C00-F9CA-4BCD-A6B6-B2938627B375}) (Version: 40.10.18029 - Microsoft Corporation) Hidden
Microsoft 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.20430.20092 - Microsoft Corporation)
Microsoft ASP.NET Core 8.0.14 Shared Framework (x86) (HKLM-x32\...\{BBD33465-6641-37D3-9444-5CCD7FE71A79}) (Version: 8.0.14.25112 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core Runtime - 10.0.1 (x64) (HKLM\...\{AB53B509-E973-4D79-896A-56D9ADBA7A01}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core Targeting Pack - 10.0.1 (x64) (HKLM\...\{58C0E442-C5F1-4028-B8BF-DFF5C82B4B70}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.48 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.48 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM\...\{C7B6BB76-07B4-48D4-B257-4511AB9E002A}) (Version: 3.5.270.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2021 - de-de (HKLM\...\ProPlus2021Retail - de-de) (Version: 16.0.20430.20092 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 (HKLM\...\{BBBE35B2-9349-3C48-BD3D-F574B17C7924}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.50.35719 (HKLM-x32\...\{773AD50D-AAE6-4BA1-AD01-B5A38874C840}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.50.35719 (HKLM-x32\...\{5A0DFA55-3851-45BC-8B20-95EA4BF5812D}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation)
Microsoft Visual C++ v14 Redistributable (x86) - 14.50.35719 (HKLM-x32\...\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}) (Version: 14.50.35719.0 - Microsoft Corporation)
Microsoft Windows Application Compatibility Fix Database (HKLM\...\{22221111-1111-1111-1111-111111111111}.sdb) (Version:  - )
Microsoft Windows Desktop Runtime - 10.0.1 (x64) (HKLM\...\{E83798A0-54B2-4BF4-AFD2-53F5FD087C95}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{F12CDBC1-172E-4413-829C-B5234E386262}) (Version: 64.56.29521 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 9.0.3 (x64) (HKLM\...\{E4F4C068-697F-4148-8CDA-738802A3A83A}) (Version: 72.12.29522 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 9.0.3 (x64) (HKLM-x32\...\{76b4f6b3-a516-4f73-a8f9-6b544f752f78}) (Version: 9.0.3.34613 - Microsoft Corporation)
Microsoft Windows Desktop Targeting Pack - 10.0.1 (x64) (HKLM\...\{22FF3E28-2020-4721-8C2D-353FFC90C1B5}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Android.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{280E75B9-118E-469A-8BF7-AD4708442FD8}) (Version: 32.0.40940 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.iOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{8608B9F2-2F29-4B17-AC80-C93B4DEBCBCF}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.MacCatalyst.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{DA1CD7F8-E2CE-4B32-907E-E0E061E0516B}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.macOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{69A66F43-AAC3-42E6-892E-ADB2AAF44ABE}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Maui.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{407911F5-7C04-4579-A280-D5C5339683F2}) (Version: 80.0.42184 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.tvOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{427BF3CD-23D1-4E9F-8DA8-F0C4F4A1E35C}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.Current.Manifest-10.0.100 (x64) (HKLM\...\{3D9990F6-184F-4DD8-8E74-F92648B703FC}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net6.Manifest-10.0.100 (x64) (HKLM\...\{0824EB00-71AC-43FD-9E94-546F9DFE1DC4}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net7.Manifest-10.0.100 (x64) (HKLM\...\{DF4D0FDE-976B-40B6-8101-B39F98931D26}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net8.Manifest-10.0.100 (x64) (HKLM\...\{58D2B598-B3A9-4B81-918B-67D545EEF340}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net9.Manifest-10.0.100 (x64) (HKLM\...\{642C8F96-EA9D-4BFD-AB4F-44CB225E1695}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest-10.0.100 (x64) (HKLM\...\{1105F4E4-6E34-4B2B-AFD8-93B6F2C7D00C}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest-10.0.100 (x64) (HKLM\...\{7F26C03D-1431-4683-9971-01473AF8CB89}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest-10.0.100 (x64) (HKLM\...\{4AF0C57C-7D5E-4BA7-934F-EAE70EAD90CF}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net8.Manifest-10.0.100 (x64) (HKLM\...\{49144E21-44CA-41E2-AE4C-AFD8303000C7}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net9.Manifest-10.0.100 (x64) (HKLM\...\{D44A8F17-7EC8-4FCF-9CBB-34822DE2EF1E}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 157.0 - Mozilla)
NVIDIA App 11.0.9.251 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.9.251 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.9.12728.38614306 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.9.12728.38614306 - NVIDIA Corporation)
NVIDIA Grafiktreiber 617.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 617.14 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.4.6.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.6.3 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.26.0703 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.26.0703 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.20430.20092 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.20326.20100 - Microsoft Corporation) Hidden
Red Dead Redemption 2 (HKLM-x32\...\Red Dead Redemption 2) (Version: 1.0.1491.50 - Rockstar Games)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.106.2879 - Rockstar Games)
Rockstar Games SDK (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.4.0.240 - Rockstar Games)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Windows Driver Package - Hewlett-Packard USB  (09/08/2015 1.0.0.1) (HKLM\...\C9EDF507DA1B23454B1BF10495C79A1C34ADD79F) (Version: 09/08/2015 1.0.0.1 - Hewlett-Packard)
WinRAR 7.23 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 7.23.0 - win.rar GmbH)
YI Home (HKLM-x32\...\YI Home) (Version: 1.0.0.0_202010211000 - XiaoYi)

Packages:
=========
Alaskan Landscapes by Kyle Waters -> C:\Program Files\WindowsApps\Microsoft.AlaskanLandscapesbyKyleWaters_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Australian Landscapes by Ian Johnson -> C:\Program Files\WindowsApps\Microsoft.AustralianLandscapesbyIanJohnson_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Bing Wallpaper -> C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.467.0_x86__8wekyb3d8bbwe [2026-09-29] (Microsoft Corporation) [Startup Task]
Community Showcase Natural Landscapes 2 -> C:\Program Files\WindowsApps\Microsoft.CommunityShowcaseNaturalLandscapes2_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Dolby Digital Plus decoder for PC OEMs -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyDigitalPlusDecoderOEM_1.2.591.0_x64__rz1tebttyb220 [2026-08-08] (Dolby Laboratories)
Erazer PC Control Center B860 -> C:\Program Files\WindowsApps\MEDION.ErazerPCControlCenterB860_1.1.3.0_x64__eqf9tz77ft5w8 [2026-08-15] (MEDION)
HP -> C:\Program Files\WindowsApps\AD2F1837.myHP_61.52637.14262.0_x64__v10z8vjag6ke6 [2026-09-26] (HP Inc.) [Startup Task]
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_3.3.2.0_x64__v10z8vjag6ke6 [2026-10-02] (HP Inc.) [Startup Task]
HP Print Support Application -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterDriver_2605.1.4767.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_166.2.1118.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.55.10.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
Islands in the Sun -> C:\Program Files\WindowsApps\Microsoft.IslandsintheSun_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Local AI Manager for Microsoft 365 -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2026-10-02] ()
Microsoft Mahjong Theme Collection -> C:\Program Files\WindowsApps\msstorefast.MicrosoftMahjongThemeCollection_1.0.1.0_neutral__fespsf2pqzq82 [2026-01-19] (Microsoft Studios)
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2026-10-02] ()
Mountain Dwellings -> C:\Program Files\WindowsApps\Microsoft.MountainDwellings_1.0.0.0_neutral__8wekyb3d8bbwe [2026-01-19] (Microsoft Corporation)
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2026-10-02] ()
Power Cam -> C:\Program Files\WindowsApps\2424AVASoft.PowerCam_4.3.2.0_x64__va7m5r7ggpxww [2026-09-29] (Waqas Hafeez)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.50.323.0_x64__dt26b99r8h8gj [2025-12-07] (Realtek Semiconductor Corp)
Warm Winter Nights -> C:\Program Files\WindowsApps\Microsoft.WarmWinterNights_1.0.0.0_neutral__8wekyb3d8bbwe [2025-12-07] (Microsoft Corporation)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8002.5.1.0_x64__8wekyb3d8bbwe [2026-09-25] (Microsoft Corp.)
WinRAR -> C:\Program Files\WinRAR [2026-07-01] (win.rar GmbH)
Wooden Walkways PREMIUM -> C:\Program Files\WindowsApps\Microsoft.WoodenWalkwaysPREMIUM_1.0.0.0_neutral__8wekyb3d8bbwe [2026-02-22] (Microsoft Corporation)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-21875824-1833468012-1891651564-1007_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
ContextMenuHandlers1: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei
ContextMenuHandlers1: [SXWEFileMenu12.1] -> {9F985FDB-B90C-4F4F-AAC3-77755DC8DCE9} => C:\Program Files (x86)\soft Xpansion\Perfect PDF 12\perfect-pdf-we-addin-x64.dll -> Keine Datei
ContextMenuHandlers2: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers2: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei
ContextMenuHandlers2: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei
ContextMenuHandlers4: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers5: [NvAppDesktopContext] -> {F2E8B4A1-9C7D-4F6E-B3A5-8D2C1F4E9B7A} => C:\Program Files\NVIDIA Corporation\NVIDIA App\NvCpl\nvui.dll [2026-08-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_da865124972e1f80\nvshext.dll [2026-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} =>  -> Keine Datei

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Web-Apps\Google.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "-taskbar-tab" "9afdf869-a8f4-41fb-a0b0-276b394815ab" "-new-window" "hxxps://www.google.com" "-profile" "C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\lp2q6z31.default-release-1789763782870" "-container" "0"
ShortcutWithArgument: C:\Users\*****\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "-taskbar-tab" "9afdf869-a8f4-41fb-a0b0-276b394815ab" "-new-window" "hxxps://www.google.com" "-profile" "C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\lp2q6z31.default-release-1789763782870" "-container" "0"

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============

2026-06-15 04:42 - 2026-09-19 16:03 - 000000000 ____L () [symlink -> C:\Program Files\NVIDIA Corporation\NVIDIA App\MessageBus\NvMessageBusBroadcast.dll] C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\NvMessageBusBroadcast.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============

SearchScopes: HKU\S-1-5-21-21875824-1833468012-1891651564-1007 -> DefaultScope {F03D6AFE-7372-4D2D-AD3E-F7B184D0C066} URL =
SearchScopes: HKU\S-1-5-21-21875824-1833468012-1891651564-1007 -> {F03D6AFE-7372-4D2D-AD3E-F7B184D0C066} URL =
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.microsoft.com -> hxxp://download.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.windowsupdate.com -> hxxp://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.windowsupdate.com -> hxxps://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\microsoft.com -> hxxp://ntservicepack.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ntservicepack.microsoft.com -> hxxp://ntservicepack.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\update.microsoft.com -> hxxp://update.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\update.microsoft.com -> hxxps://update.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windows.com -> hxxp://wustat.windows.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.com -> hxxp://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.com -> hxxps://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.microsoft.com -> hxxp://windowsupdate.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ws.microsoft.com -> hxxp://ws.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ws.microsoft.com -> hxxps://ws.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\wustat.windows.com -> hxxp://wustat.windows.com

==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2025-12-24 15:47 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2025-12-08 01:02 - 2026-03-30 11:47 - 000000440 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

DNS Servers: 192.168.178.1
 ist aktiviert.

==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-21875824-1833468012-1891651564-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\*****\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

HKLM\...\StartupApproved\Run: => "Ashampoo WinOptimizer Live-Tuner3"
HKLM\...\StartupApproved\Run: => "AnyTech365 IntelliGuard"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_794056B798E168129F1A28C1E6F646AA"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "AviraBrowserAutoLaunch_C8164B68A561FBDEFEDA7C0B69D93AE6"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "MicrosoftCopilotAutoLaunch_B27E74A70B3383C5564357D44A1D5D01"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{11AA026A-21C9-4478-8CB4-BFB94B504C36}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6898CDBB-4C02-4E12-9254-3C736A85EB56}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{35C2655C-949A-4037-8FE8-3519B102DC06}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{4A141E5A-308A-4B84-BD59-D0CF33DC7055}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{6C688787-443A-4C7F-A587-677268B99349}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{6586E741-17CD-4F2E-B7F3-735E1B27DC94}C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe] => (Block) C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe (Shanghai Xiaoyi Technology Co., Ltd. -> Shanghai Xiaoyi Technology Co., Ltd.)
FirewallRules: [UDP Query User{47FA9CEC-9296-4DA5-89DD-8990482134B9}C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe] => (Block) C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe (Shanghai Xiaoyi Technology Co., Ltd. -> Shanghai Xiaoyi Technology Co., Ltd.)
FirewallRules: [{61D1E0D7-D626-482B-B471-B52ECE8156E6}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{0F134FB0-6A45-4D5E-8EBE-CFD36754A10D}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{2EAF2AAD-61E0-41D7-A785-C260A2378945}] => (Allow) C:\Program Files\Avira\Browser\Application\AviraBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [TCP Query User{98C10373-02BA-4265-AF2F-E535E5B46EF6}C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe] => (Block) C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe => Keine Datei
FirewallRules: [UDP Query User{74EC454E-00DD-4E5A-942D-40AD23088A5B}C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe] => (Block) C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe => Keine Datei
FirewallRules: [{C0A9BA6D-ABC8-41B5-9BA1-F76A6A680FB7}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS69F3\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{481C02D1-A532-4433-AF22-5B4AF223C0AC}C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{92E6FABF-6D77-445B-BEA8-0222B89C25A8}C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{C358551E-1CC6-4155-95CD-CC24DB61B082}] => (Allow) C:\Program Files (x86)\HP\HP Scan\bin\HPScan.exe (HP Inc. -> HP Inc.)
FirewallRules: [{7D0F5B69-820B-4E84-A304-6DCCAEB90FB1}] => (Allow) C:\Program Files\HP\HP Scan\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9CD0FFE3-BEDB-4317-93BE-7D438E4D87DC}] => (Allow) LPort=5357
FirewallRules: [{3D1C70C0-B516-44F2-96D8-4FCD195B7811}] => (Allow) C:\Program Files\HP\HP Scan\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{235DF83F-4AAF-4DE2-99C8-DCC3CE64D625}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS1C39\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{9FF06ADA-7A7D-4F2D-9B06-1403280A9A6B}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS20E6\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{4CDD90F2-7BED-4949-AA52-CC1AC062544D}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS6BDB\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{9A60299C-E42A-4617-A7F7-F64300335129}C:\users\*****\appdata\local\temp\7zs7180\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs7180\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{DF7A0566-C5C6-4F88-A764-298E7ED482E0}C:\users\*****\appdata\local\temp\7zs7180\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs7180\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{29734E65-4CAB-45AC-B6A0-B34F68E06375}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS4FAF\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{7234A6DE-6F56-4B9E-88A8-C843B6EF2D03}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS117D\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{33FB03E7-1173-4B4B-B464-36537C647520}C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe] => (Block) C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{13624F04-30D2-4008-ABAC-F51BD7B0BEB6}C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe] => (Block) C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{AF4C70D8-28EF-4FD7-896B-6BF7599BC994}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS49FC\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{53F07BAF-2166-4A51-9E41-E7A45806791B}C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{79AF1D52-C694-42D4-B021-B597EE305FE7}C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{417D1252-1A3D-47DC-8172-51F41E46F5BE}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS0048\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{3466B863-A23A-4F6D-BD77-0DDB5645A59D}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS69FA\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{C7E19E1B-B2B5-43C4-A35A-BDEA3AE34996}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS3D74\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{B775F919-44A3-4B08-ABF2-F14E0E542D18}C:\users\****\appdata\local\temp\7zs74d2\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{45613CAB-4016-423F-89AF-9C67F1DB2DB4}                      C:\users\ *****\appdata\local\temp\7zs74d2\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{4C74B017-FCD8-4A4A-9AF7-9399F474EA0C}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS6415\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{224320CB-B9AB-4194-98A7-7D24A33A8214}] => (Allow) C:\Program Files\HP\HP Envy Photo 7900 series\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D54A6844-73AD-4E44-A1AA-F5335FDA5708}] => (Allow) C:\Program Files\HP\HP Envy Photo 7900 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{B9105D77-19FA-423B-90F5-A78BFB54009C}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS2CFD\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{BBCF78B5-0BF8-441B-BC5F-67AC518AF392}C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{6F079316-061C-4032-BEF1-DB27D8B01F94}C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{C1D00003-2FA0-446B-ADB6-AEBF2E6DD529}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS71FE\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{0C18D31A-C4F0-47EF-9B41-1A193F110D6C}C:\users\\appdata\local\temp\7zs46fa\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{BE0AD9BE-9B8E-40B8-B284-E8206D2E5A27}C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{801FAE07-D66F-479A-9FF4-9228D2530B3F}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS2BF8\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{DB99124D-9F4C-4D8A-8440-0B42F24C91AD}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS014A\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{5D4A4539-3332-45CB-B76F-18750B6580A1}] => (Allow) C:\Program Files\HP\HP ENVY Inspire 7900 series\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{A099DD6E-38CA-4EFC-A468-117F242191F5}] => (Allow) C:\Program Files\HP\HP ENVY Inspire 7900 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{81D19FC2-B746-40F0-82C7-72E716E1AABC}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS0DA7\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{094D4B07-E597-486B-AFF0-E571B403052C}C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{8728D513-A7A9-4E26-923C-2BE1A9B592DD}C:\users*****\appdata\local\temp\7zs51ed\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{BE96C4B3-90DB-48B8-AFC8-FFFD4502AF89}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS26A0\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{57408797-5896-484C-BCD7-D5E06AF6A1B7}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS70E1\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{1CC3EC0E-4D47-41D3-9EDE-174763D56A9D}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{C674C33C-5AEF-43C4-8F74-BC7985CD93ED}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{400C2462-0B74-4F45-BA04-3DC34CE63042}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6E6ACDD5-7E07-4758-AC6F-58A2B168882B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Wiederherstellungspunkte =========================

01-10-2026 09:02:40 Test
02-10-2026 04:04:35 Wiederherstellungsvorgang
02-10-2026 07:26:59 Installed iTunes

==================== Fehlerhafte Geräte im Gerätemanager ============

==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (10/02/2026 12:14:02 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: GAMING-PC)
Description: Die Anwendung oder der Dienst "Microsoft Office SDX Helper" konnte nicht heruntergefahren werden.

Error: (10/02/2026 09:11:07 AM) (Source: Application Error) (EventID: 1000) (User: NT-AUTORITÄT)
Description: Fehlerhafter Anwendungsname: DSAArcDetect64.exe, Version: 26.2.0.7, Zeitstempel: 0x6a060000
Fehlerhafter Modulname: KERNELBASE.dll, Version: 10.0.26100.9549, Zeitstempel: 0x4370855d
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00000000000c483a
Fehlerhafte Prozess-ID: 0xadc
Fehlerhafte Anwendungsstartzeit: 0x1dd523d318f1670
Fehlerhafter Anwendungspfad: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
Fehlerhafter Modulpfad: C:\WINDOWS\System32\KERNELBASE.dll
Berichts-ID: 79892efa-716b-47ca-af45-537bf3ece078
Vollständiger Name des fehlerhaften Pakets:
Fehlerhafte paketbezogene Anwendungs-ID:

Error: (10/02/2026 09:11:07 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: DSAArcDetect64.exe
CoreCLR Version: 8.0.1425.11118
.NET Version: 8.0.14
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException: Could not load file or assembly 'C:\Program Files (x86)\Intel\Driver and Support Assistant\DSACoreInterop64.dll'. Das angegebene Modul wurde nicht gefunden.
File name: 'C:\Program Files (x86)\Intel\Driver and Support Assistant\DSACoreInterop64.dll'
  at DSAArcDetect64.Models.AvailableDevices..ctor()
  at DSAArcDetect64.ResizableBarDetection.Detect(ArcOutput& output, String oemName)
  at DSAArcDetect64.Output.JsonOutput.RunDetection()
  at DSAArcDetect64.Program.Main(String[] args)

Error: (10/02/2026 07:26:57 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start.  Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 07:26:57 AM) (Source: MsiInstaller) (EventID: 1013) (User: GAMING-PC)
Description: Produkt: iTunes -- Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start.  Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:56 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start.  Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:56 AM) (Source: MsiInstaller) (EventID: 1013) (User: GAMING-PC)
Description: Produkt: iTunes -- Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start.  Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:15 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start.  Verify that you have sufficient privileges to start system services.


Systemfehler:
=============
Error: (10/02/2026 09:34:09 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.AppCaptureManager" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_57a1617" gewartet wurde.

Error: (10/02/2026 08:58:55 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.Internal.AppCaptureShell" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_1bbb9c" gewartet wurde.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{740FE937-01F7-4482-AA62-C83F0AD3D6D0}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{FD06603A-2BDF-4BB1-B7DF-5DC68F353601}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:21:11 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.AppCaptureManager" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_1bbb9c" gewartet wurde.


Windows Defender:
================

TimeCreated : 02.10.2026 06:52:37
Message    : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AndroidUnlocker!MTB&threatid=2147906596
&enterprise=0
Name: HackTool:Win32/AndroidUnlocker!MTB
ID: 2147906596
Schweregrad: Hoch
Kategorie: Tool
Pfad: file:_C:\Users\*****\AppData\Local\Temp\Rar$DRa18336.39281.rartemp\Imobie_AnyFix.exe
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:28:04
Message    : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:

ID: 2147714384
Schweregrad: Schwerwiegend



TimeCreated : 02.10.2026 06:27:14
Message    : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
r
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3


Weitere Informationen:
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3




Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\System32\OpenWith.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3


CodeIntegrity:
===============
Date: 2026-10-02 09:43:03
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Google\Chrome\Application\154.0.8037.98\libLiteRtWebGpuAccelerator.dll that did not meet the Microsoft signing level requirements.


==================== Speicherinformationen ===========================

BIOS: American Megatrends International, LLC. 860H8EMW0X.101 03/05/2025
Hauptplatine: ERAZER B860H8-EM
Prozessor: Intel(R) Core(TM) Ultra 7 265
Prozentuale Nutzung des RAM: 36%
Installierter physikalischer RAM: 32393.82 MB
Verfügbarer physikalischer RAM: 20487.97 MB
Summe virtueller Speicher: 34441.82 MB
Verfügbarer virtueller Speicher: 22097.14 MB

==================== Laufwerke ================================

Disk 0 - Drive c: (Boot) (Fixed) (Total:897.4 GB) (Free:607.15 GB) (Model: WD Blue SN5000 1TB) NTFS
Disk 0 - Drive d: (Recover) (Fixed) (Total:30 GB) (Free:6.1 GB) (Model: WD Blue SN5000 1TB) NTFS

Disk 0 - \\?\Volume{2af04c12-0f24-4bc5-85cf-4cf07e5c746e}\ (Recovery) (Fixed) (Total:4 GB) (Free:2.86 GB) NTFS
Disk 0 - \\?\Volume{d4e61ded-a6df-43e5-bff5-b9838129e2d1}\ (SYSTEM) (Fixed) (Total:96 MB) (Free:61.27 MB) FAT32

==================== MBR & Partitionstabelle ====================

============================================================
Disk: 0 (Size: 931.51 GB) (Disk ID: 8B120361)

Partitions:
===========
Partition Style : GPT
Partition Count : 5
Disk ID          : {2E4ADDD9-B50B-4BE1-B73B-5AE0A3D33D44}
Usable Offset    : 0.02 MB
Usable Length    : 931.51 GB
Max Partitions  : 128

Partition 1
  Type            : EFI System Partition
  Size            : 100 MB
  Offset          : 1 MB
  Type GUID        : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
  Partition GUID  : {D4E61DED-A6DF-43E5-BFF5-B9838129E2D1}
  GPT Name        : EFI system partition
  Attributes      : 0x0000000000000000
  Attribute Flags  : None
  Hidden          : Yes
  Platform Required: No
------------------------------------------------------------
Partition 2
  Type            : Microsoft Reserved (MSR)
  Size            : 16 MB
  Offset          : 101 MB
  Type GUID        : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
  Partition GUID  : {430534BF-2202-45BE-873F-319E2053B097}
  GPT Name        : Microsoft reserved partition
  Attributes      : 0x0000000000000000
  Attribute Flags  : None
  Hidden          : Yes
  Platform Required: No
------------------------------------------------------------
Partition 3
  Type            : Basic Data Partition
  Size            : 897.4 GB
  Offset          : 117 MB
  Type GUID        : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
  Partition GUID  : {87463F06-5EAE-4A99-9E6D-AE2C5A5B20FF}
  GPT Name        : Basic data partition
  Attributes      : 0x0000000000000000
  Attribute Flags  : None
  Hidden          : No
  Platform Required: No
------------------------------------------------------------
Partition 4
  Type            : Windows Recovery
  Size            : 4 GB
  Offset          : 919054 MB
  Type GUID        : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
  Partition GUID  : {2AF04C12-0F24-4BC5-85CF-4CF07E5C746E}
  GPT Name        : Basic data partition
  Attributes      : 0x8000000000000001
  Attribute Flags  : Platform Required, No Default Drive Letter
  Hidden          : Yes
  Platform Required: Yes
------------------------------------------------------------
Partition 5
  Type            : Basic Data Partition
  Size            : 30 GB
  Offset          : 923149 MB
  Type GUID        : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
  Partition GUID  : {1B1C1A37-7AB3-4E49-9816-9B3831A40469}
  GPT Name        : Basic data partition
  Attributes      : 0x0000000000000000
  Attribute Flags  : None
  Hidden          : No
  Platform Required: No
------------------------------------------------------------

============================================================

==================== Ende vom Addition.txt =======================

--- --- ---



Zitat:



Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 01-10-2026
durchgeführt von ***** (02-10-2026 12:25:52)
Gestartet von C:\Users\\*****\OneDrive\Desktop
Microsoft Windows 11 Home Version 26H2 26300.9550 (X64) (2026-06-20 00:36:33)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

Administrator (S-1-5-21-21875824-1833468012-1891651564-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-21875824-1833468012-1891651564-503 - 0 - Disabled)
Gast (S-1-5-21-21875824-1833468012-1891651564-501 - 0 - Disabled)
\***** (DisplayName: G**** - *C) (S-1-5-21-21875824-1833468012-1891651564-1007 - Administrators - Enabled) [MS Account] => C:\Users\\*****
WDAGUtilityAccount (S-1-5-21-21875824-1833468012-1891651564-504 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Apple Mobile Device Support (HKLM\...\{A1147B7D-734A-49BD-A6CA-E41E2B4B7B8F}) (Version: 20.0.0.35 - Apple Inc.)
Avira Secure Browser (HKLM-x32\...\Avira Secure Browser) (Version: 152.0.35367.42 - Die Avira Secure Browser-Autoren)
Avira Update Helper (HKLM-x32\...\{25A7DD46-F34D-4979-9C3D-BFB147368DD6}) (Version: 1.8.1997.6 - Avira) Hidden
Documentation Manager (HKLM\...\{40C886AE-8BEE-49A9-A980-30CCC810B262}) (Version: 24.70.0.3 - Intel Corporation) Hidden
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.743.1.6250 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{bdbc521f-cb3d-4738-b6ac-90b33e222f8d}) (Version: 13.743.1.6250 - Electronic Arts)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 154.0.8037.98 - Google LLC)
HP EmailSMTP Plugin (HKLM\...\{EB8C0C19-AB72-4A10-AA2A-1E9A576C2D5E}) (Version: 56.0.529.0 - HP)
HP Enabling Services (HKLM\...\{EB4E9E57-5044-4FDB-913F-2BA903AC53B0}) (Version: 6.9.0.1017 - HP Inc.)
HP ENVY Inspire 7900 series - Grundlegende Software für das Gerät (HKLM\...\{1933D1B2-8E2B-46E4-B0F8-A1C36A3828CB}) (Version: 55.4.5082.2256 - HP Inc.)
HP Envy Photo 7900 series - Grundlegende Software für das Gerät (HKLM\...\{922FC23F-853F-48D6-8251-37E0ED7167FA}) (Version: 63.1.2123.25253 - HP Inc.)
HP FTP Plugin (HKLM\...\{703CEAD3-DC8D-4902-9DCF-CE45D912922A}) (Version: 56.0.480.0 - HP)
HP OCR (HKLM-x32\...\{04A83156-5855-4FB4-96A3-D8E95B6F3B74}) (Version: 1.0.1020.0 - HP Inc.)
HP PSDr NTService Component (HKLM\...\{7FF0066D-7114-4A27-8F1E-7C17CB4542D1}) (Version: 11.8.0.0 - HP Inc.)
HP Scan - Grundlegende Software für das Gerät (HKLM\...\{5A837DCB-4006-47BF-8094-CD4FC291BF67}) (Version: 63.8.6459.26156 - HP Inc.)
HP SFTP Plugin (HKLM\...\{F3997C1C-E4F4-4856-A045-BF4CD1EE46C3}) (Version: 56.0.529.0 - HP Inc.)
HP SharePoint Plugin (HKLM\...\{24A4DCC1-2DA3-446F-9455-ADF0ADCBBB19}) (Version: 56.0.529.0 - HP)
Intel Driver && Support Assistant (HKLM-x32\...\{2C633E0E-1F95-42CC-95D8-63C12DD9672F}) (Version: 26.2.0.7 - Intel) Hidden
Intel(R) Icls (HKLM\...\{5AC763E5-494E-410F-832D-450C41DEB63B}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2435.6.36.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{EAF1D7D8-7514-48F8-AAE6-49A6CBAA66BC}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{9D7BB5D9-5975-43F0-A31F-63589939A14D}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) ME WMI Provider (HKLM\...\{0B44BD9A-7327-4EA3-8C44-C4C7A4B1777E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) NPU Software & Drivers (HKLM\...\Intel(R) NPU Software & Drivers) (Version: 1.0.17.0 - Intel(R) Corporation)
Intel(R) Serial IO (HKLM\...\{49B19848-D806-4774-B5B4-C67C4E098E22}) (Version: 30.100.2419.23 - Intel Corporation) Hidden
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.2419.23 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000070-0240-1031-84C8-B8D95FA3C8C3}) (Version: 24.70.0.4 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{039CECE9-B083-4114-AFC7-5CDBA4321241}) (Version: 26.2.0.7 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{4152D055-4116-42A3-BC9E-86D0A17B35A5}) (Version: 25.4.36.6 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{C8093AA3-B113-4F81-9A87-B1C41929B346}) (Version: 26.1.0.2 - Intel)
Intel® Software Installer (HKLM\...\{55AFCB51-121C-4654-B9A3-6EADAA94CD2B}) (Version: 24.40.0.4 - Intel Corporation) Hidden
Intel® Software Installer (HKLM\...\{B80ACD63-2F12-4509-A6D9-A782A2642754}) (Version: 24.10.0.4 - Intel Corporation) Hidden
Intel® Software Installer (HKLM\...\{EB9FE660-9D60-40B6-9D16-5610C81513E5}) (Version: 24.70.0.3 - Intel Corporation) Hidden
IRIS Software Download Tool (HKLM-x32\...\{8F0E9102-8D90-419C-B42B-B2E48403A5C0}) (Version: 1.0.44.0 - HP Inc.)
iTunes (HKLM\...\{F7F4BCB2-0D0F-46DA-9896-303008DC6DBA}) (Version: 12.13.11.1 - Apple Inc.)
LockHunter 3.4, 32/64 bit (HKLM\...\LockHunter_is1) (Version: 3.4.3.146 - Crystal Rich Ltd)
Medion Service App (HKLM\...\{F1A17BC3-7C28-4F3D-8835-BF78282D11B7}) (Version: 3.0.0.0 - Medion)
Medion-Service (HKLM\...\{ED61C980-1719-427E-8522-78B239E8A9F9}) (Version: 1.0.44 - Medion AG)
Microsoft .NET 10.0 Templates 10.0.101 x64 (HKLM\...\{89689C38-93A6-4065-9783-47E96FC49A85}) (Version: 40.10.18029 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 10.0.1 (x64) (HKLM\...\{97247546-3F97-4F4F-A02F-4563A48CBD10}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host - 10.0.1 (x64) (HKLM\...\{9A3CDC3E-B643-4C13-8F8B-1E7F999A0C61}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.14 (x64) (HKLM\...\{04904762-A110-4E46-A728-7EF88DCCA1F1}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.14 (x86) (HKLM-x32\...\{CB771E25-82B7-435C-B8CF-1DAF85D9A373}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host - 9.0.3 (x64) (HKLM\...\{E29A8846-BD00-4830-8BDF-7CC3E81C5385}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 10.0.1 (x64) (HKLM\...\{12D4B30A-B8DE-496F-ABBA-8E355A7E2652}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.14 (x64) (HKLM\...\{B2E7F2C8-73CD-4269-B7BC-11B7D8BB7A37}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.14 (x86) (HKLM-x32\...\{455AA7CD-6D99-4039-95D2-FF1A437FD444}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 9.0.3 (x64) (HKLM\...\{0FD489DC-A3E9-4F57-9770-812CD1059FA5}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 10.0.1 (x64) (HKLM\...\{DD248F59-C0EC-48F9-B8DB-CB8268F9E028}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.14 (x64) (HKLM\...\{6C817CE3-32BC-4C6B-8B1A-E6F71EDAFFCC}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.14 (x86) (HKLM-x32\...\{6E39BE88-1272-4732-A962-9B34A31EE12C}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 9.0.3 (x64) (HKLM\...\{102DCD41-F00B-484D-9D6B-5D2919D8FCF8}) (Version: 72.12.29501 - Microsoft Corporation) Hidden
Microsoft .NET SDK 10.0.101 (x64) (HKLM-x32\...\{F9366523-19F5-49F6-9F27-3F27B596471D}) (Version: 10.1.125.57005 - Microsoft Corporation)
Microsoft .NET Targeting Pack - 10.0.1 (x64) (HKLM\...\{010930C3-106A-4DD2-B08C-E93615935B26}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft .NET Toolset 10.0.101 (x64) (HKLM\...\{E6BC5C00-F9CA-4BCD-A6B6-B2938627B375}) (Version: 40.10.18029 - Microsoft Corporation) Hidden
Microsoft 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.20430.20092 - Microsoft Corporation)
Microsoft ASP.NET Core 8.0.14 Shared Framework (x86) (HKLM-x32\...\{BBD33465-6641-37D3-9444-5CCD7FE71A79}) (Version: 8.0.14.25112 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core Runtime - 10.0.1 (x64) (HKLM\...\{AB53B509-E973-4D79-896A-56D9ADBA7A01}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core Targeting Pack - 10.0.1 (x64) (HKLM\...\{58C0E442-C5F1-4028-B8BF-DFF5C82B4B70}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.48 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.48 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM\...\{C7B6BB76-07B4-48D4-B257-4511AB9E002A}) (Version: 3.5.270.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2021 - de-de (HKLM\...\ProPlus2021Retail - de-de) (Version: 16.0.20430.20092 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 (HKLM\...\{BBBE35B2-9349-3C48-BD3D-F574B17C7924}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.50.35719 (HKLM-x32\...\{773AD50D-AAE6-4BA1-AD01-B5A38874C840}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.50.35719 (HKLM-x32\...\{5A0DFA55-3851-45BC-8B20-95EA4BF5812D}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation)
Microsoft Visual C++ v14 Redistributable (x86) - 14.50.35719 (HKLM-x32\...\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}) (Version: 14.50.35719.0 - Microsoft Corporation)
Microsoft Windows Application Compatibility Fix Database (HKLM\...\{22221111-1111-1111-1111-111111111111}.sdb) (Version: - )
Microsoft Windows Desktop Runtime - 10.0.1 (x64) (HKLM\...\{E83798A0-54B2-4BF4-AFD2-53F5FD087C95}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{F12CDBC1-172E-4413-829C-B5234E386262}) (Version: 64.56.29521 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 9.0.3 (x64) (HKLM\...\{E4F4C068-697F-4148-8CDA-738802A3A83A}) (Version: 72.12.29522 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 9.0.3 (x64) (HKLM-x32\...\{76b4f6b3-a516-4f73-a8f9-6b544f752f78}) (Version: 9.0.3.34613 - Microsoft Corporation)
Microsoft Windows Desktop Targeting Pack - 10.0.1 (x64) (HKLM\...\{22FF3E28-2020-4721-8C2D-353FFC90C1B5}) (Version: 80.4.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Android.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{280E75B9-118E-469A-8BF7-AD4708442FD8}) (Version: 32.0.40940 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.iOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{8608B9F2-2F29-4B17-AC80-C93B4DEBCBCF}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.MacCatalyst.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{DA1CD7F8-E2CE-4B32-907E-E0E061E0516B}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.macOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{69A66F43-AAC3-42E6-892E-ADB2AAF44ABE}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Maui.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{407911F5-7C04-4579-A280-D5C5339683F2}) (Version: 80.0.42184 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.tvOS.Manifest-10.0.100-rc.2 (x64) (HKLM\...\{427BF3CD-23D1-4E9F-8DA8-F0C4F4A1E35C}) (Version: 251.104.40928 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.Current.Manifest-10.0.100 (x64) (HKLM\...\{3D9990F6-184F-4DD8-8E74-F92648B703FC}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net6.Manifest-10.0.100 (x64) (HKLM\...\{0824EB00-71AC-43FD-9E94-546F9DFE1DC4}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net7.Manifest-10.0.100 (x64) (HKLM\...\{DF4D0FDE-976B-40B6-8101-B39F98931D26}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net8.Manifest-10.0.100 (x64) (HKLM\...\{58D2B598-B3A9-4B81-918B-67D545EEF340}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net9.Manifest-10.0.100 (x64) (HKLM\...\{642C8F96-EA9D-4BFD-AB4F-44CB225E1695}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest-10.0.100 (x64) (HKLM\...\{1105F4E4-6E34-4B2B-AFD8-93B6F2C7D00C}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest-10.0.100 (x64) (HKLM\...\{7F26C03D-1431-4683-9971-01473AF8CB89}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest-10.0.100 (x64) (HKLM\...\{4AF0C57C-7D5E-4BA7-934F-EAE70EAD90CF}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net8.Manifest-10.0.100 (x64) (HKLM\...\{49144E21-44CA-41E2-AE4C-AFD8303000C7}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net9.Manifest-10.0.100 (x64) (HKLM\...\{D44A8F17-7EC8-4FCF-9CBB-34822DE2EF1E}) (Version: 81.148.44025 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox) (Version: 157.0 - Mozilla)
NVIDIA App 11.0.9.251 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.9.251 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.9.12728.38614306 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.9.12728.38614306 - NVIDIA Corporation)
NVIDIA Grafiktreiber 617.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 617.14 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.4.6.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.6.3 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.26.0703 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.26.0703 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.20430.20092 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.20326.20100 - Microsoft Corporation) Hidden
Red Dead Redemption 2 (HKLM-x32\...\Red Dead Redemption 2) (Version: 1.0.1491.50 - Rockstar Games)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.106.2879 - Rockstar Games)
Rockstar Games SDK (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.4.0.240 - Rockstar Games)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.23 - VideoLAN)
Windows Driver Package - Hewlett-Packard USB (09/08/2015 1.0.0.1) (HKLM\...\C9EDF507DA1B23454B1BF10495C79A1C34ADD79F) (Version: 09/08/2015 1.0.0.1 - Hewlett-Packard)
WinRAR 7.23 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 7.23.0 - win.rar GmbH)
YI Home (HKLM-x32\...\YI Home) (Version: 1.0.0.0_202010211000 - XiaoYi)

Packages:
=========
Alaskan Landscapes by Kyle Waters -> C:\Program Files\WindowsApps\Microsoft.AlaskanLandscapesbyKyleWaters_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Australian Landscapes by Ian Johnson -> C:\Program Files\WindowsApps\Microsoft.AustralianLandscapesbyIanJohnson_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Bing Wallpaper -> C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.467.0_x86__8wekyb3d8bbwe [2026-09-29] (Microsoft Corporation) [Startup Task]
Community Showcase Natural Landscapes 2 -> C:\Program Files\WindowsApps\Microsoft.CommunityShowcaseNaturalLandscapes2_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Dolby Digital Plus decoder for PC OEMs -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyDigitalPlusDecoderOEM_1.2.591.0_x64__rz1tebttyb220 [2026-08-08] (Dolby Laboratories)
Erazer PC Control Center B860 -> C:\Program Files\WindowsApps\MEDION.ErazerPCControlCenterB860_1.1.3.0_x64__eqf9tz77ft5w8 [2026-08-15] (MEDION)
HP -> C:\Program Files\WindowsApps\AD2F1837.myHP_61.52637.14262.0_x64__v10z8vjag6ke6 [2026-09-26] (HP Inc.) [Startup Task]
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_3.3.2.0_x64__v10z8vjag6ke6 [2026-10-02] (HP Inc.) [Startup Task]
HP Print Support Application -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterDriver_2605.1.4767.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_166.2.1118.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.55.10.0_x64__v10z8vjag6ke6 [2026-09-27] (HP Inc.)
Islands in the Sun -> C:\Program Files\WindowsApps\Microsoft.IslandsintheSun_1.0.0.0_neutral__8wekyb3d8bbwe [2026-08-19] (Microsoft Corporation)
Local AI Manager for Microsoft 365 -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2026-10-02] ()
Microsoft Mahjong Theme Collection -> C:\Program Files\WindowsApps\msstorefast.MicrosoftMahjongThemeCollection_1.0.1.0_neutral__fespsf2pqzq82 [2026-01-19] (Microsoft Studios)
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2026-10-02] ()
Mountain Dwellings -> C:\Program Files\WindowsApps\Microsoft.MountainDwellings_1.0.0.0_neutral__8wekyb3d8bbwe [2026-01-19] (Microsoft Corporation)
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2026-10-02] ()
Power Cam -> C:\Program Files\WindowsApps\2424AVASoft.PowerCam_4.3.2.0_x64__va7m5r7ggpxww [2026-09-29] (Waqas Hafeez)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.50.323.0_x64__dt26b99r8h8gj [2025-12-07] (Realtek Semiconductor Corp)
Warm Winter Nights -> C:\Program Files\WindowsApps\Microsoft.WarmWinterNights_1.0.0.0_neutral__8wekyb3d8bbwe [2025-12-07] (Microsoft Corporation)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8002.5.1.0_x64__8wekyb3d8bbwe [2026-09-25] (Microsoft Corp.)
WinRAR -> C:\Program Files\WinRAR [2026-07-01] (win.rar GmbH)
Wooden Walkways PREMIUM -> C:\Program Files\WindowsApps\Microsoft.WoodenWalkwaysPREMIUM_1.0.0.0_neutral__8wekyb3d8bbwe [2026-02-22] (Microsoft Corporation)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-21875824-1833468012-1891651564-1007_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Keine Datei
ContextMenuHandlers1: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei
ContextMenuHandlers1: [SXWEFileMenu12.1] -> {9F985FDB-B90C-4F4F-AAC3-77755DC8DCE9} => C:\Program Files (x86)\soft Xpansion\Perfect PDF 12\perfect-pdf-we-addin-x64.dll -> Keine Datei
ContextMenuHandlers2: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers2: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei
ContextMenuHandlers2: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei
ContextMenuHandlers4: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2021-06-24] (Crystal Rich Ltd -> Crystal Rich Ltd)
ContextMenuHandlers5: [NvAppDesktopContext] -> {F2E8B4A1-9C7D-4F6E-B3A5-8D2C1F4E9B7A} => C:\Program Files\NVIDIA Corporation\NVIDIA App\NvCpl\nvui.dll [2026-08-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_da865124972e1f80\nvshext.dll [2026-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => -> Keine Datei

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Web-Apps\Google.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "-taskbar-tab" "9afdf869-a8f4-41fb-a0b0-276b394815ab" "-new-window" "hxxps://www.google.com" "-profile" "C:\Users\\*****\AppData\Roaming\Mozilla\Firefox\Profiles\lp2q6z31.default-release-1789763782870" "-container" "0"
ShortcutWithArgument: C:\Users\*****\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "-taskbar-tab" "9afdf869-a8f4-41fb-a0b0-276b394815ab" "-new-window" "hxxps://www.google.com" "-profile" "C:\Users\\*****\AppData\Roaming\Mozilla\Firefox\Profiles\lp2q6z31.default-release-1789763782870" "-container" "0"

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============

2026-06-15 04:42 - 2026-09-19 16:03 - 000000000 ____L () [symlink -> C:\Program Files\NVIDIA Corporation\NVIDIA App\MessageBus\NvMessageBusBroadcast.dll] C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\NvMessageBusBroadcast.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer (Nicht auf der Ausnahmeliste) =============

SearchScopes: HKU\S-1-5-21-21875824-1833468012-1891651564-1007 -> DefaultScope {F03D6AFE-7372-4D2D-AD3E-F7B184D0C066} URL =
SearchScopes: HKU\S-1-5-21-21875824-1833468012-1891651564-1007 -> {F03D6AFE-7372-4D2D-AD3E-F7B184D0C066} URL =
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-10-01] (Microsoft Corporation -> Microsoft Corporation)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.microsoft.com -> hxxp://download.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.windowsupdate.com -> hxxp://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\download.windowsupdate.com -> hxxps://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\microsoft.com -> hxxp://ntservicepack.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ntservicepack.microsoft.com -> hxxp://ntservicepack.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\update.microsoft.com -> hxxp://update.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\update.microsoft.com -> hxxps://update.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windows.com -> hxxp://wustat.windows.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.com -> hxxp://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.com -> hxxps://download.windowsupdate.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\windowsupdate.microsoft.com -> hxxp://windowsupdate.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ws.microsoft.com -> hxxp://ws.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\ws.microsoft.com -> hxxps://ws.microsoft.com
IE trusted site: HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\wustat.windows.com -> hxxp://wustat.windows.com

==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2025-12-24 15:47 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2025-12-08 01:02 - 2026-03-30 11:47 - 000000440 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Network ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

DNS Servers: 192.168.178.1
ist aktiviert.

==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-21875824-1833468012-1891651564-1007\Control Panel\Desktop\\Wallpaper -> C:\Users\\*****\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

HKLM\...\StartupApproved\Run: => "Ashampoo WinOptimizer Live-Tuner3"
HKLM\...\StartupApproved\Run: => "AnyTech365 IntelliGuard"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_794056B798E168129F1A28C1E6F646AA"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "AviraBrowserAutoLaunch_C8164B68A561FBDEFEDA7C0B69D93AE6"
HKU\S-1-5-21-21875824-1833468012-1891651564-1007\...\StartupApproved\Run: => "MicrosoftCopilotAutoLaunch_B27E74A70B3383C5564357D44A1D5D01"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{11AA026A-21C9-4478-8CB4-BFB94B504C36}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6898CDBB-4C02-4E12-9254-3C736A85EB56}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{35C2655C-949A-4037-8FE8-3519B102DC06}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{4A141E5A-308A-4B84-BD59-D0CF33DC7055}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{6C688787-443A-4C7F-A587-677268B99349}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{6586E741-17CD-4F2E-B7F3-735E1B27DC94}C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe] => (Block) C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe (Shanghai Xiaoyi Technology Co., Ltd. -> Shanghai Xiaoyi Technology Co., Ltd.)
FirewallRules: [UDP Query User{47FA9CEC-9296-4DA5-89DD-8990482134B9}C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe] => (Block) C:\program files (x86)\yihomepcclientintl\yihomepcclientintl.exe (Shanghai Xiaoyi Technology Co., Ltd. -> Shanghai Xiaoyi Technology Co., Ltd.)
FirewallRules: [{61D1E0D7-D626-482B-B471-B52ECE8156E6}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{0F134FB0-6A45-4D5E-8EBE-CFD36754A10D}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{2EAF2AAD-61E0-41D7-A785-C260A2378945}] => (Allow) C:\Program Files\Avira\Browser\Application\AviraBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)
FirewallRules: [TCP Query User{98C10373-02BA-4265-AF2F-E535E5B46EF6}C:\users\\*****\appdata\local\jdownloader 2\jdownloader2.exe] => (Block) C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe => Keine Datei
FirewallRules: [UDP Query User{74EC454E-00DD-4E5A-942D-40AD23088A5B}C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe] => (Block) C:\users\*****\appdata\local\jdownloader 2\jdownloader2.exe => Keine Datei
FirewallRules: [{C0A9BA6D-ABC8-41B5-9BA1-F76A6A680FB7}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS69F3\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{481C02D1-A532-4433-AF22-5B4AF223C0AC}C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{92E6FABF-6D77-445B-BEA8-0222B89C25A8}C:\users\*****\appdata\local\temp\7zs55ac\enterprisedu.exe] => (Allow) C:\users\\*****\appdata\local\temp\7zs55ac\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{C358551E-1CC6-4155-95CD-CC24DB61B082}] => (Allow) C:\Program Files (x86)\HP\HP Scan\bin\HPScan.exe (HP Inc. -> HP Inc.)
FirewallRules: [{7D0F5B69-820B-4E84-A304-6DCCAEB90FB1}] => (Allow) C:\Program Files\HP\HP Scan\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9CD0FFE3-BEDB-4317-93BE-7D438E4D87DC}] => (Allow) LPort=5357
FirewallRules: [{3D1C70C0-B516-44F2-96D8-4FCD195B7811}] => (Allow) C:\Program Files\HP\HP Scan\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{235DF83F-4AAF-4DE2-99C8-DCC3CE64D625}] => (Allow) C:\Users\\*****\AppData\Local\Temp\7zS1C39\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{9FF06ADA-7A7D-4F2D-9B06-1403280A9A6B}] => (Allow) C:\Users\\*****AppData\Local\Temp\7zS20E6\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{4CDD90F2-7BED-4949-AA52-CC1AC062544D}] => (Allow) C:\Users\\*****\AppData\Local\Temp\7zS6BDB\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{9A60299C-E42A-4617-A7F7-F64300335129}C:\users\\*****\appdata\local\temp\7zs7180\enterprisedu.exe] => (Allow) C:\users\\*****\appdata\local\temp\7zs7180\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{DF7A0566-C5C6-4F88-A764-298E7ED482E0}C:\users\*****appdata\local\temp\7zs7180\enterprisedu.exe] => (Allow) C:\users\\*****\appdata\local\temp\7zs7180\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{29734E65-4CAB-45AC-B6A0-B34F68E06375}] => (Allow) C:\Users\\*****\AppData\Local\Temp\7zS4FAF\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{7234A6DE-6F56-4B9E-88A8-C843B6EF2D03}] => (Allow) C:\Users\\*****\AppData\Local\Temp\7zS117D\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{33FB03E7-1173-4B4B-B464-36537C647520}C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe] => (Block) C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{13624F04-30D2-4008-ABAC-F51BD7B0BEB6}C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe] => (Block) C:\users\*****\appdata\local\temp\7zs7a03\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{AF4C70D8-28EF-4FD7-896B-6BF7599BC994}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS49FC\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{53F07BAF-2166-4A51-9E41-E7A45806791B}C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{79AF1D52-C694-42D4-B021-B597EE305FE7}C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs700c\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{417D1252-1A3D-47DC-8172-51F41E46F5BE}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS0048\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{3466B863-A23A-4F6D-BD77-0DDB5645A59D}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS69FA\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{C7E19E1B-B2B5-43C4-A35A-BDEA3AE34996}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS3D74\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{B775F919-44A3-4B08-ABF2-F14E0E542D18}C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{45613CAB-4016-423F-89AF-9C67F1DB2DB4}C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs74d2\enterprisedu.exe (HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{4C74B017-FCD8-4A4A-9AF7-9399F474EA0C}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS6415\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{224320CB-B9AB-4194-98A7-7D24A33A8214}] => (Allow) C:\Program Files\HP\HP Envy Photo 7900 series\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D54A6844-73AD-4E44-A1AA-F5335FDA5708}] => (Allow) C:\Program Files\HP\HP Envy Photo 7900 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{B9105D77-19FA-423B-90F5-A78BFB54009C}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS2CFD\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{BBCF78B5-0BF8-441B-BC5F-67AC518AF392}C:\users\*****k\appdata\local\temp\7zs0797\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{6F079316-061C-4032-BEF1-DB27D8B01F94}C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs0797\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{C1D00003-2FA0-446B-ADB6-AEBF2E6DD529}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS71FE\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{0C18D31A-C4F0-47EF-9B41-1A193F110D6C}C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{BE0AD9BE-9B8E-40B8-B284-E8206D2E5A27}C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs46fa\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{801FAE07-D66F-479A-9FF4-9228D2530B3F}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS2BF8\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{DB99124D-9F4C-4D8A-8440-0B42F24C91AD}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS014A\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{5D4A4539-3332-45CB-B76F-18750B6580A1}] => (Allow) C:\Program Files\HP\HP ENVY Inspire 7900 series\Bin\DeviceSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{A099DD6E-38CA-4EFC-A468-117F242191F5}] => (Allow) C:\Program Files\HP\HP ENVY Inspire 7900 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{81D19FC2-B746-40F0-82C7-72E716E1AABC}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS0DA7\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [TCP Query User{094D4B07-E597-486B-AFF0-E571B403052C}C:\users\*****k\appdata\local\temp\7zs51ed\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{8728D513-A7A9-4E26-923C-2BE1A9B592DD}C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe] => (Allow) C:\users\*****\appdata\local\temp\7zs51ed\enterprisedu.exe (VistaName -> HP Inc.) [Datei ist nicht signiert]
FirewallRules: [{BE96C4B3-90DB-48B8-AFC8-FFFD4502AF89}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS26A0\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{57408797-5896-484C-BCD7-D5E06AF6A1B7}] => (Allow) C:\Users\*****\AppData\Local\Temp\7zS70E1\HPEasyStart\HP.EasyStart.exe (HP Inc. -> HP)
FirewallRules: [{1CC3EC0E-4D47-41D3-9EDE-174763D56A9D}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{C674C33C-5AEF-43C4-8F74-BC7985CD93ED}] => (Allow) C:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{400C2462-0B74-4F45-BA04-3DC34CE63042}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6E6ACDD5-7E07-4758-AC6F-58A2B168882B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Wiederherstellungspunkte =========================

01-10-2026 09:02:40 Test
02-10-2026 04:04:35 Wiederherstellungsvorgang
02-10-2026 07:26:59 Installed iTunes

==================== Fehlerhafte Geräte im Gerätemanager ============

==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (10/02/2026 12:14:02 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: GAMING-PC)
Description: Die Anwendung oder der Dienst "Microsoft Office SDX Helper" konnte nicht heruntergefahren werden.

Error: (10/02/2026 09:11:07 AM) (Source: Application Error) (EventID: 1000) (User: NT-AUTORITÄT)
Description: Fehlerhafter Anwendungsname: DSAArcDetect64.exe, Version: 26.2.0.7, Zeitstempel: 0x6a060000
Fehlerhafter Modulname: KERNELBASE.dll, Version: 10.0.26100.9549, Zeitstempel: 0x4370855d
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00000000000c483a
Fehlerhafte Prozess-ID: 0xadc
Fehlerhafte Anwendungsstartzeit: 0x1dd523d318f1670
Fehlerhafter Anwendungspfad: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
Fehlerhafter Modulpfad: C:\WINDOWS\System32\KERNELBASE.dll
Berichts-ID: 79892efa-716b-47ca-af45-537bf3ece078
Vollständiger Name des fehlerhaften Pakets:
Fehlerhafte paketbezogene Anwendungs-ID:

Error: (10/02/2026 09:11:07 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: DSAArcDetect64.exe
CoreCLR Version: 8.0.1425.11118
.NET Version: 8.0.14
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException: Could not load file or assembly 'C:\Program Files (x86)\Intel\Driver and Support Assistant\DSACoreInterop64.dll'. Das angegebene Modul wurde nicht gefunden.
File name: 'C:\Program Files (x86)\Intel\Driver and Support Assistant\DSACoreInterop64.dll'
at DSAArcDetect64.Models.AvailableDevices..ctor()
at DSAArcDetect64.ResizableBarDetection.Detect(ArcOutput& output, String oemName)
at DSAArcDetect64.Output.JsonOutput.RunDetection()
at DSAArcDetect64.Program.Main(String[] args)

Error: (10/02/2026 07:26:57 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start. Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 07:26:57 AM) (Source: MsiInstaller) (EventID: 1013) (User: GAMING-PC)
Description: Produkt: iTunes -- Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start. Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:56 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start. Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:56 AM) (Source: MsiInstaller) (EventID: 1013) (User: GAMING-PC)
Description: Produkt: iTunes -- Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start. Verify that you have sufficient privileges to start system services.

Error: (10/02/2026 06:51:15 AM) (Source: MsiInstaller) (EventID: 11920) (User: GAMING-PC)
Description: Product: Apple Mobile Device Support -- Error 1920. Service 'Apple Mobile Device Service' (Apple Mobile Device Service) failed to start. Verify that you have sufficient privileges to start system services.


Systemfehler:
=============
Error: (10/02/2026 09:34:09 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.AppCaptureManager" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_57a1617" gewartet wurde.

Error: (10/02/2026 08:58:55 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.Internal.AppCaptureShell" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_1bbb9c" gewartet wurde.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{740FE937-01F7-4482-AA62-C83F0AD3D6D0}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{FD06603A-2BDF-4BB1-B7DF-5DC68F353601}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:23:08 AM) (Source: DCOM) (EventID: 10010) (User: GAMING-PC)
Description: Der Server "{6FA05A24-B1DF-4155-909E-7B424F2D2BB5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/02/2026 08:21:11 AM) (Source: DCOM) (EventID: 10029) (User: GAMING-PC)
Description: Das Zeitlimit für die Aktivierung der CLSID "Windows.Media.Capture.AppCaptureManager" wurde überschritten, während auf das Beenden von Dienst "BcastDVRUserService_1bbb9c" gewartet wurde.


Windows Defender:
================

TimeCreated : 02.10.2026 06:52:37
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AndroidUnlocker!MTB&threatid=2147906596
&enterprise=0
Name: HackTool:Win32/AndroidUnlocker!MTB
ID: 2147906596
Schweregrad: Hoch
Kategorie: Tool
Pfad: file:_C:\Users\*****\AppData\Local\Temp\Rar$DRa18336.39281.rartemp\Imobie_AnyFix.exe
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:28:04
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Vigorf.A&threatid=2147714384&enterprise=0
Name: Trojan:Win32/Vigorf.A
ID: 2147714384

SSystemRecovery1.rar
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz

Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:28:01
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Vigorf.A&threatid=2147714384&enterprise=0
Name: Trojan:Win32/Vigorf.A
ID: 2147714384

SSystemRecovery1.rar
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:27:49
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:



Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3




Pfad: file:_C:\Users\*****\OneDrive\Desktop\AMPED.rar
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3



Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:27:08
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Vigorf.A&threatid=2147714384&enterprise=0
Name: Trojan:Win32/Vigorf.A
ID: 2147714384
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\*****\OneDrive\Desktop\AMPED.rar
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\explorer.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3

TimeCreated : 02.10.2026 06:25:32
Message : Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Vigorf.A&threatid=2147714384&enterprise=0
Name: Trojan:Win32/Vigorf.A
ID: 2147714384

Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Echtzeitschutz
Benutzer: Gaming-PC\*****
Prozessname: C:\Windows\System32\OpenWith.exe
Sicherheitsversion: AV: 1.459.510.0, AS: 1.459.510.0, NIS: 1.459.510.0
Modulversion: AM: 1.1.26080.3, NIS: 1.1.26080.3


CodeIntegrity:
===============
Date: 2026-10-02 09:43:03
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Google\Chrome\Application\154.0.8037.98\libLiteRtWebGpuAccelerator.dll that did not meet the Microsoft signing level requirements.


==================== Speicherinformationen ===========================

BIOS: American Megatrends International, LLC. 860H8EMW0X.101 03/05/2025
Hauptplatine: ERAZER B860H8-EM
Prozessor: Intel(R) Core(TM) Ultra 7 265
Prozentuale Nutzung des RAM: 36%
Installierter physikalischer RAM: 32393.82 MB
Verfügbarer physikalischer RAM: 20487.97 MB
Summe virtueller Speicher: 34441.82 MB
Verfügbarer virtueller Speicher: 22097.14 MB

==================== Laufwerke ================================

Disk 0 - Drive c: (Boot) (Fixed) (Total:897.4 GB) (Free:607.15 GB) (Model: WD Blue SN5000 1TB) NTFS
Disk 0 - Drive d: (Recover) (Fixed) (Total:30 GB) (Free:6.1 GB) (Model: WD Blue SN5000 1TB) NTFS

Disk 0 - \\?\Volume{2af04c12-0f24-4bc5-85cf-4cf07e5c746e}\ (Recovery) (Fixed) (Total:4 GB) (Free:2.86 GB) NTFS
Disk 0 - \\?\Volume{d4e61ded-a6df-43e5-bff5-b9838129e2d1}\ (SYSTEM) (Fixed) (Total:96 MB) (Free:61.27 MB) FAT32

==================== MBR & Partitionstabelle ====================

============================================================
Disk: 0 (Size: 931.51 GB) (Disk ID: 8B120361)

Partitions:
===========
Partition Style : GPT
Partition Count : 5
Disk ID : {2E4ADDD9-B50B-4BE1-B73B-5AE0A3D33D44}
Usable Offset : 0.02 MB
Usable Length : 931.51 GB
Max Partitions : 128

Partition 1
Type : EFI System Partition
Size : 100 MB
Offset : 1 MB
Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
Partition GUID : {D4E61DED-A6DF-43E5-BFF5-B9838129E2D1}
GPT Name : EFI system partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Microsoft Reserved (MSR)
Size : 16 MB
Offset : 101 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {430534BF-2202-45BE-873F-319E2053B097}
GPT Name : Microsoft reserved partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 3
Type : Basic Data Partition
Size : 897.4 GB
Offset : 117 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {87463F06-5EAE-4A99-9E6D-AE2C5A5B20FF}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------
Partition 4
Type : Windows Recovery
Size : 4 GB
Offset : 919054 MB
Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
Partition GUID : {2AF04C12-0F24-4BC5-85CF-4CF07E5C746E}
GPT Name : Basic data partition
Attributes : 0x8000000000000001
Attribute Flags : Platform Required, No Default Drive Letter
Hidden : Yes
Platform Required: Yes
------------------------------------------------------------
Partition 5
Type : Basic Data Partition
Size : 30 GB
Offset : 923149 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {1B1C1A37-7AB3-4E49-9816-9B3831A40469}
GPT Name : Basic data partition
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------

============================================================

==================== Ende vom Addition.txt =======================[/CODE]
--- --- ---










Kann mir bitte jemand helfen? Ich danke euch!

PS:

PC's CD rom öffnet sich von selbst und schliesst.
Elektronik geräte öffnen sich von selber, Android Box oder Fernseher. (alle an internet anggeschlossen)
Das ganze lauft nun schon seit etwa 9 Jahren so. Ich weiss echt nicht mehr weiter!

cosinus 02.10.2026 14:18

Kommst du jetzt alle drei Jahre mit einem Bullshitinfektionsthread an??! :balla:

https://www.trojaner-board.de/207445...e-gehackt.html

Und auf deine Nachfrage damals wurde doch alles erklärt. :kaffee:

anonym_20 02.10.2026 15:45

du warst doch der jenige der gesagt ich soll mir ein neues PC kaufen:

PS: ich will nicht dass du in mein Threads antwortest.
Kurz gesagt, du störst.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:17 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133