Goldberg | 26.02.2021 12:38 | Hallo Matthias,
schon mal vielen Dank für Deine Hilfe!
Ja, ich gestehe, dass ich in Sachen PC-Hygiene sehr schlampig bin und es mir sicher viel zu oft zu einfach mache. Sicher verwunderlich, dass ich mir bisher nichts Schlimmeres eingefangen habe.
Die Anweisungen habe ich ausgeführt und im Folgenden die Logs....
Vielen Dank!
Michael Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 26.02.21
Scan-Zeit: 11:51
Protokolldatei: 88872f04-7820-11eb-8055-74d43585b2ed.json
-Softwaredaten-
Version: 4.3.0.98
Komponentenversion: 1.0.1173
Version des Aktualisierungspakets: 1.0.37509
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19042.804)
CPU: x64
Dateisystem: NTFS
Benutzer: Atelier_PC\AtelierNiederhein
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 343948
Erkannte Bedrohungen: 90
In die Quarantäne verschobene Bedrohungen: 90
Abgelaufene Zeit: 5 Min., 0 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 14
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}, In Quarantäne, 6916, 396863, , , , , ,
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startfenster-Replace.de, In Quarantäne, 8265, 350112, , , , , ,
PUP.Optional.GoodGame.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GoodGame.de, In Quarantäne, 8946, 401580, , , , , ,
PUP.Optional.StartPage, HKLM\SOFTWARE\Websuche, In Quarantäne, 571, 463409, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 8265, 350115, 1.0.37509, , ame, , ,
PUP.Optional.GimpUpdaterDe.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GIMP Updater, In Quarantäne, 13870, 728127, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\djhangopedggnlnicpbjklghlckmndge, In Quarantäne, 8265, 354303, 1.0.37509, , ame, , ,
PUP.Optional.GreatDealz, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\lobonlhedgiilkfmbbbfhkaoefacipgj, In Quarantäne, 8685, 466866, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 8265, 350115, 1.0.37509, , ame, , ,
PUP.Optional.QwebDe, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Qweb.de, In Quarantäne, 9667, 478742, , , , , ,
Adware.KeenValue, HKLM\SOFTWARE\WOW6432NODE\Updater, In Quarantäne, 3526, 212959, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Updater, In Quarantäne, 8265, 541219, , , , , ,
Registrierungswert: 10
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|FAVICONURL, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|URL, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|STARTFENSTER SYMBOL, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|STARTFENSTER-REPLACE, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,
PUP.Optional.GoodGame.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|GOODGAME, In Quarantäne, 8946, 401601, 1.0.37509, , ame, , ,
PUP.Optional.GimpUpdaterDe.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GIMP UPDATER, In Quarantäne, 13870, 728126, 1.0.37509, , ame, , ,
PUP.Optional.GreatDealz, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|LOBONLHEDGIILKFMBBBFHKAOEFACIPGJ, In Quarantäne, 8685, 466866, , , , , ,
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|FAVICONURL, In Quarantäne, 6916, 396862, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, In Quarantäne, 8265, 541219, , , , , ,
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|URL, In Quarantäne, 6916, 396862, 1.0.37509, , ame, , ,
Registrierungsdaten: 1
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 6916, 395422, 1.0.37509, , ame, , ,
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 12
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE, In Quarantäne, 8265, 350112, 1.0.37509, , ame, , ,
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAM FILES (X86)\GOODGAME, In Quarantäne, 8946, 401580, 1.0.37509, , ame, , ,
PUP.Optional.VLCUpdaterDE, C:\PROGRAM FILES (X86)\VLC UPDATER, In Quarantäne, 8336, 353751, 1.0.37509, , ame, , ,
PUP.Optional.GreatDealz, C:\PROGRAM FILES (X86)\GREATDEALZ, In Quarantäne, 8685, 388477, 1.0.37509, , ame, , ,
PUP.Optional.QwebDe, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\QWEB SYMBOL, In Quarantäne, 9667, 478741, 1.0.37509, , ame, , ,
PUP.Optional.QwebDe, C:\PROGRAM FILES (X86)\QWEB SYMBOL, In Quarantäne, 9667, 478742, 1.0.37509, , ame, , ,
Trojan.Banker, C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1968138750, In Quarantäne, 25, 506854, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, C:\PROGRAMDATA\UPDATER, In Quarantäne, 8265, 541219, 1.0.37509, , ame, , ,
PUP.Optional.QwebDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER, In Quarantäne, 11022, 728125, 1.0.37509, , ame, , ,
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,
Datei: 53
PUP.Optional.StartFenster.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\STARTFENSTER.LNK, In Quarantäne, 8259, 349853, 1.0.37509, , ame, , AF388855D2264546E3C332ADB25A22D9, 145F6A3FB58A8EB6392C59BD5BEE69E05A6D1E5AD49EC22AFB82D9BD04B9A1D0
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\STARTFENSTER SYMBOL.LNK, In Quarantäne, 8265, 350108, 1.0.37509, , ame, , 4335E2A9C86EAF6F50605D66F53C0CD5, 42B6DAAEAA4448DB13BAE495105AD122C368B30972E064A681220DAFC04BBE0C
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE\LOGO.ICO, In Quarantäne, 8265, 350112, 1.0.37509, , ame, , BDCF63C89B22A44CDF5B1BE184714A26, C333C15AC24C7820F8E613E6878F1823514E15618CBBFE16161405CDE5270A39
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\uninstall.exe, In Quarantäne, 8265, 350112, , , , , 453CD208DDE29DF341C2D8C3754D23BC, 12C1395B92058BF0EEE1375B5A7A8E71EC2EF0E1C20165AC367E05C4DDFA5B06
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAM FILES (X86)\GOODGAME\SETUP.ICO, In Quarantäne, 8946, 401580, 1.0.37509, , ame, , 58E4B64420F84EFA71F0CE29CD50429E, BA306550D41BE6E77BB836384504AC1979F467320295E6BE2A2F39433DF7A7A6
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\bigfarm.ico, In Quarantäne, 8946, 401580, , , , , 45B821EB95557B6B7E00289F22C1BA24, 4C02D9BF5497A4CCA25F054311C0C12E64495E9AC2EA235A6E8787029ED99CBF
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\empire.ico, In Quarantäne, 8946, 401580, , , , , 58A5323B66D3334572DA30572A369CE9, AE64EBDD1309C30F4778244330EEC7ED6EEEB96A363426586519E3C4356CC67A
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\uninstall.exe, In Quarantäne, 8946, 401580, , , , , 48FF80E435CDE88CE8640F836CBBA91D, 9BEB37DF3BD5974ABC51B7BF35F0A38D6B6F7C94026238F58815E95CCE55CBE4
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\GOODGAME.LNK, In Quarantäne, 8946, 401586, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\USERS\PUBLIC\DESKTOP\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401592, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\USERS\PUBLIC\DESKTOP\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401592, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401583, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401583, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401584, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401584, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401585, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401585, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.VLCUpdaterDE, C:\PROGRAM FILES (X86)\VLC UPDATER\SETUP.ICO, In Quarantäne, 8336, 353751, 1.0.37509, , ame, , 6F7E92FE7E6A62661AC2B41528A78FC6, FD9B5998B98EE0BA86ED7687F215A1CDDE90C00B0B1CD11DC83E3614389CB6AD
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\uninstall.exe, In Quarantäne, 8336, 353751, , , , , 8E387B02090DBCF119EA219AE9425C21, 28E1A7C4178970D87BA3790461B6E1E29C5E91B38C25D3EC6F1C977578ECA0EC
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc-updater.exe, In Quarantäne, 8336, 353751, , , , , 386112C1632557841499A65BA32165D3, 511E5FBBCE302C5A394E7EC41C230687117A382A788D15774325A75E94F886DE
PUP.Optional.GimpUpdaterDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER\UPDATER.EXE, In Quarantäne, 13870, 728126, , , , , 18774F18676445FA0B85BEC3037F9CF4, 9646873526A4F5C05267EDBA8D88D6651107B9E67DA6C45D0D3370C49A1E95BE
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\GOODGAME\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401581, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\GOODGAME\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401581, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401587, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C
PUP.Optional.GreatDealz, C:\Program Files (x86)\GreatDealz\lobonlhedgiilkfmbbbfhkaoefacipgj.crx, In Quarantäne, 8685, 388477, , , , , 318FDE27DCD8B40F85B0790DE1B84D98, 26529CDA5F955326AF2ABD49914FCFA50358A2A16ADB5CEB7AD7BE61452C7CB1
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401587, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478748, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.GreatDealz, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Ersetzt, 8685, 466866, , , , , C1F1EAA4B9D09A1EB82D48D486517766, 321F4C1C078AA4DC5ABC154D60A79B49A0268830F08AB58391A08C7F3310024E
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478749, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.QwebDe, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478744, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\QWEB SYMBOL.LNK, In Quarantäne, 9667, 496142, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.QwebDe, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qweb Symbol\ deinstallieren.lnk, In Quarantäne, 9667, 478741, , , , , 161228C0F0003C55D74FCCA07BC694BA, D75B2FC452B96255F38C8FDC8595049ED022E087C889CCE81B71F5669B9A410F
PUP.Optional.QwebDe, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qweb Symbol\Qweb Converter installieren.lnk, In Quarantäne, 9667, 478741, , , , , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478746, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933
PUP.Optional.QwebDe, C:\Program Files (x86)\Qweb Symbol\qweb.ico, In Quarantäne, 9667, 478742, , , , , 36D4D68344A3095BDFAB1FA5FE030795, ED9E540371968B4A63CE0705B31CAFA00AC8F5540413C4557F07C26C3D6CF0F2
PUP.Optional.QwebDe, C:\Program Files (x86)\Qweb Symbol\uninstall.exe, In Quarantäne, 9667, 478742, , , , , 364C38809CDD45188621EEE377B23FCF, DFE5A4739A068E39BB887FBB6FDCCE4A448E4751EBDFA9E326F5F609A66887BD
PUP.Optional.StartFenster, C:\PROGRAMDATA\UPDATER\CHECK-UPDATE.EXE, In Quarantäne, 8265, 541219, 1.0.37509, , ame, , 470F3664CB71A971177593422280713B, 2C1E83A4F17CE641878B4625BA7D46E9EA5C415D084A5D9161FADB619CAD4A6F
PUP.Optional.StartFenster, C:\ProgramData\Updater\setup.ico, In Quarantäne, 8265, 541219, , , , , A60B9AFB2DBC13DBFCFE4172325D1712, B2199B7933227655475B64C50AFE09E1DB10D511A248283DDD8EE88EF794A680
PUP.Optional.StartFenster, C:\ProgramData\Updater\uninstall.exe, In Quarantäne, 8265, 541219, , , , , 261B2499F1F5D36B46F3B730FFDB4996, 1D94DF3DB02E6067E936BFACC0D10FC27464DD635F6D8E0665721AE6D6F9A724
PUP.Optional.QwebDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER\GIMP.ICO, In Quarantäne, 11022, 728125, 1.0.37509, , ame, , 3A502781380607A40C507EB316BB5D96, 9165E8721AC00B0E2235F018181B2383F42BA1451B8365A918BDFC82F6E0B63E
PUP.Optional.QwebDe.ShrtCln, C:\Users\AtelierNiederhein\AppData\Roaming\GIMP Updater\uninst.exe, In Quarantäne, 11022, 728125, , , , , BA40B063B7C51AF1C254ED18B32DC86E, 18459F7E2F32D68075172F190E8B6F91D058A6DB225CE8E8C4392B5F6D0FDA85
PUP.Optional.ChipDe, C:\USERS\ATELIERNIEDERHEIN\DOWNLOADS\HIJACKTHIS - CHIP-INSTALLER VOM 24.02.2021 456E5770BF506EB7D7B3888D815AD1B5.EXE, In Quarantäne, 9554, 557991, 1.0.37509, C2BF7BCB91C3F9EDC4D26450, dds, 01133428, 5F5B877DFAC2A4EC5AF890F33D7801C6, 5C3022D3CEDD37473E7FA598742CA27DA5B07C1E658A801CC64686F2E1FCB729
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, In Quarantäne, 8265, 455286, , , , , 87A2838AE6CBF992A379B8A811786412, E42EDAEF21E97C70113290032164317E8F73F5C7C4BBC455643600B09C930E67
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000113.log, In Quarantäne, 8265, 455286, , , , , 8443299947279799FBB908AC4F7D0350, 841F10BA21C4B6EFA535919F95C12B5B5C197C8A2D966E2466B349E2768FFC6E
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000115.ldb, In Quarantäne, 8265, 455286, , , , , 165F91051B914EAA5BA0B0BA311792D4, 9F81BA32B14F907E69E9C01628F850E332E114F71AD4C7B4FE9780604AA4A733
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, In Quarantäne, 8265, 455286, , , , , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, In Quarantäne, 8265, 455286, , , , , ,
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, In Quarantäne, 8265, 455286, , , , , 90A43EDB8B2B2E50F1FD9EB008681DA5, 73A93845703D4E7594F4BE0695BF392CE798DE6847EB1597DF7F6157B3492CB0
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, In Quarantäne, 8265, 455286, , , , , 0A23996397857C10CD0C21EA62E3706B, D5EA8700EA252FBA80E4E04F442FF105401AE0B006928E6A183E00F0014438F3
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, In Quarantäne, 8265, 455286, , , , , 21E48FC9828C99A45F5D4927CAB9B16E, 65070D1C73DDEAF7B693D20B895C1DC96B87B132D9CF8E5C180541E3AE201844
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) Code:
# -------------------------------
# Malwarebytes AdwCleaner 8.1.0.0
# -------------------------------
# Build: 02-15-2021
# Database: 2021-01-26.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 02-26-2021
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 21
# Awaiting reboot:1
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files (x86)\VLC Plus Player
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoodGame
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Plus Player
Deleted C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC UPDATER
***** [ Files ] *****
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster.lnk
Deleted C:\Users\Public\Desktop\VLC Plus Player.lnk
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\GIMP Updater
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\SOFTWARE\Mozilla\NativeMessagingHosts\com.webcompanion.native
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.DellSupportAssistAgent Folder C:\ProgramData\SUPPORTASSIST\CLIENT\TECHNICIANTOOLKIT
Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA92FC08-40B9-4490-A1F6-CEEFCFD54526}
Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA92FC08-40B9-4490-A1F6-CEEFCFD54526}
Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dell SupportAssistAgent AutoUpdate
Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4015CD01-07AB-4354-9E43-E63DFAB5A6A2}
Deleted Preinstalled.DellSupportAssistAgent Task C:\Windows\System32\Tasks\DELL SUPPORTASSISTAGENT AUTOUPDATE
Needs Reboot Preinstalled.DellSupportAssistAgent Folder C:\Program Files\DELL\SUPPORTASSISTAGENT
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
***** Reboot Required to Complete *****
***** [ Folders ] *****
Cleaning failed C:\Program Files\DELL\SUPPORTASSISTAGENT
*************************
AdwCleaner[S00].txt - [3566 octets] - [26/02/2021 12:14:40]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 24-02-2021
durchgeführt von AtelierNiederhein (Administrator) auf ATELIER_PC (Gigabyte Technology Co., Ltd. G1.Sniper Z87) (26-02-2021 12:20:25)
Gestartet von C:\Users\AtelierNiederhein\Downloads
Geladene Profile: AtelierNiederhein
Platform: Windows 10 Home Version 20H2 19042.804 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <4>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_2.0.1.8_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Utility Toolbox\cnqtbapp.exe
(Canon INC.) [Datei ist nicht signiert] C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\116.4.368\QtWebEngineProcess.exe <3>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) [Datei ist nicht signiert] C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
(HP) [Datei ist nicht signiert] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Malwarebytes Inc -> Malwarebytes) C:\Users\AtelierNiederhein\Downloads\adwcleaner_8.1.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\AtelierNiederhein\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <6>
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Notepad++ -> Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(OpenJS Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(Synology Inc. -> ) [Datei ist nicht signiert] C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2095672 2020-10-09] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7992336 2021-02-14] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [270912 2015-06-17] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [CanonQuickToolbox] => C:\Program Files (x86)\Canon\Quick Utility Toolbox\cnqtbapp.exe [2340768 2018-05-09] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-02-05] (Adobe Inc. -> )
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [330176 2014-08-19] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [680720 2021-02-18] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3412696 2021-02-13] (Valve -> Valve Corporation)
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [TabletDriver] => C:\Huion Tablet\x64\TabletDriverCore.exe [334056 2019-12-28] (Shenzhen Huion Animation Technology Co.,LTD -> )
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [AusweisApp2] => C:\Program Files (x86)\AusweisApp2\AusweisApp2.exe [2405504 2020-11-30] (Governikus GmbH & Co. KG -> Governikus GmbH & Co. KG)
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [] => [X]
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\MountPoints2: {994bdb3c-1515-11eb-ab19-74d43585b2ed} - "E:\Autorun.exe"
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [4708328 2021-01-17] (Microsoft Windows -> Microsoft Corporation) <==== ACHTUNG
HKLM\...\Windows x64\Print Processors\Canon MB2700 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDD0.DLL [30720 2018-07-17] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\Canon MP640 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDA2.DLL [28672 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\hpcpp120: C:\Windows\System32\spool\prtprocs\x64\hpcpp120.DLL [342016 2012-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor MB2700 series: C:\WINDOWS\system32\CNCALD0.DLL [254464 2015-11-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MB2700 series: C:\WINDOWS\system32\CNMLMD0.DLL [436736 2018-07-17] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MB2700 series XPS: C:\WINDOWS\system32\CNMXLMD0.DLL [438784 2015-11-18] (CANON INC.) [Datei ist nicht signiert]
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\WINDOWS\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Datei ist nicht signiert]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\88.0.4324.190\Installer\chrmstp.exe [2021-02-26] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Huion Tablet.lnk [2020-12-27]
ShortcutTarget: Huion Tablet.lnk -> C:\Huion Tablet\Huion Tablet.exe (Shenzhen Huion Animation Technology Co.,LTD -> )
Startup: C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2017-10-15]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) [Datei ist nicht signiert]
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0BDFD991-F8B5-4BEE-8530-45660E0017B2} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-09] (Adobe Inc. -> Adobe)
Task: {10D8BCA2-0BE0-467B-9D4B-A897FCB0A99C} - System32\Tasks\BundleApplicationRepairToolLauncherTask => C:\Users\AtelierNiederhein\AppData\Roaming\PCDr\Repair\BundleApplicationRepairTool.exe [625024 2018-01-22] (PC-Doctor, Inc. -> )
Task: {12F6F9F7-2275-45BB-95E7-2114EA65FF67} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
Task: {1CFF7823-78EF-46B3-A9DC-7E09FBC06883} - System32\Tasks\Git for Windows Updater => C:\Program Files\Git\git-bash.exe [152128 2020-10-19] (Johannes Schindelin -> The Git Development Community)
Task: {1E1AA683-1EEF-4264-8968-7EA37A1A3969} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {1E8503BB-182C-4B7C-96D7-CA1396FDCF21} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-10-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2220FFED-725D-45AC-804A-B0D1840B9931} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {40963EC1-283A-4F9B-A04D-ADD40F8398D5} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {44130ECF-C77E-4F05-8443-7EDB691A4EB3} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5A31CF7F-82DF-4288-9EEC-00C0D39806B3} - System32\Tasks\AdobeAAMUpdater-1.0-Atelier_PC-AtelierNiederhein => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {5C4C9D73-63F6-40D1-B10A-51E01301ADEF} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {62A0F4F7-4327-4235-9042-94D34B32495B} - System32\Tasks\Red Giant Link => C:\Program [Argument = Files (x86)\Red Giant Link\Red Giant Link.exe]
Task: {64151D08-FB32-4417-B741-0119D3ECB8E1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {65323232-04B3-4D1B-A73A-60CCB8464652} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {661367E9-26A1-411C-B42B-F962A4C04EDB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-28] (Google Inc -> Google LLC)
Task: {781E23ED-CF39-4361-8B26-31C6AE6EA57D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {8B5250F2-E991-4F5D-9797-DFC5242918F3} - \Microsoft\Windows\UNP\RunCampaignManager -> Keine Datei <==== ACHTUNG
Task: {9E36B745-5CA5-4EAD-A9B9-9A080FD510EF} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {B1B91048-64C2-4F64-A07C-48DF270D5FB9} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [694752 2021-02-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {BF9DFB29-744A-44C4-B75A-36CDBD359B87} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {CCCB4A12-FE2E-4E47-9019-FC85F691113D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D2D4D365-8A40-48B8-848E-BFDA0B54BB7E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-28] (Google Inc -> Google LLC)
Task: {DB3F2604-FE62-482E-9851-B4ABC5799615} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {E8636D29-32DE-412D-A15D-971827532F7F} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [89840 2014-10-19] (Hewlett-Packard Company -> Hewlett Packard)
Task: {ECB9FE9C-C4C5-4722-A736-1903CFB243D0} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F6B38547-7C6F-4A89-AEA2-6D87DAF88FD7} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {F8BF1748-421D-4457-9146-E1B158630EE3} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4f89c9de-8a11-4370-a3fc-a9199241aa6a}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\AtelierNiederhein\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-26]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: xspktsq9.default-1575993033040
FF ProfilePath: C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 [2021-02-26]
FF Homepage: Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 -> www.google.de
FF Notifications: Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 -> hxxps://www.facebook.com
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> )
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-10-09] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> )
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll [2008-10-15] (CANON INC.) [Datei ist nicht signiert]
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\WINDOWS\system32\C2MP\npdivx32.dll [Keine Datei]
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.9.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @vlc.de/vlc,version=3.0.11 -> C:\Program Files (x86)\VLC Plus Player\npvlc.dll [Keine Datei]
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2021-02-15] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-10-09] (Adobe Inc. -> Adobe Systems)
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\AtelierNiederhein\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-03-09] (Unity Technologies SF -> Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: LWA64Plugin15.8 -> C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Plugins\npLWA64Plugin15.8.dll [2013-03-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: LWAPlugin15.8 -> C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll [2013-03-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\AtelierNiederhein\AppData\Roaming\mozilla\plugins\npLWA64Plugin15.8.dll [2018-05-25]
FF Plugin ProgramFiles/Appdata: C:\Users\AtelierNiederhein\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll [2018-05-25]
Chrome:
=======
CHR Profile: C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default [2021-02-25]
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.instagram.com
CHR StartupUrls: Default -> "hxxps://calendar.google.com/calendar/r?tab=wc"
CHR Extension: (Präsentationen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-28]
CHR Extension: (Docs) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-28]
CHR Extension: (Google Drive) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-28]
CHR Extension: (YouTube) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-28]
CHR Extension: (Adobe Acrobat) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-12-18]
CHR Extension: (Tabellen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-28]
CHR Extension: (Google Docs Offline) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-11]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-10]
CHR Extension: (Google Mail) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-28]
CHR Extension: (Chrome Media Router) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-02-10]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [852024 2020-10-09] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8404720 2019-11-09] (BattlEye Innovations e.K. -> )
R2 Cloud Station Drive VSS Service x64; C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe [287256 2018-05-18] (Synology Inc. -> ) [Datei ist nicht signiert]
R2 CtHdaSvc; C:\WINDOWS\sysWow64\CtHdaSvc.exe [113152 2016-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44064 2021-02-14] (Dropbox, Inc -> Dropbox, Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208760 2017-07-27] (Dell Inc -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294584 2017-07-27] (Dell Inc -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-07-27] (Dell Inc -> Dell Inc.)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-10-19] (NVIDIA Corporation -> NVIDIA)
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [Datei ist nicht signiert]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Datei ist nicht signiert]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [397256 2018-11-19] (Canon Inc. -> )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [41432 2017-11-30] (Dell Inc. -> Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10967832 2021-02-05] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-12-23] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
R3 cthda; C:\WINDOWS\system32\drivers\cthda.sys [1064968 2016-12-13] (Creative Technology Ltd -> Creative Technology Ltd)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2021-02-26] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220616 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-02-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198248 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [142416 2021-02-26] (Malwarebytes Inc -> Malwarebytes)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2016-09-05] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
R3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2018-03-16] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 wacomhidfilter; C:\WINDOWS\System32\drivers\wacomhidfilter.sys [12968 2008-08-27] (Wacom Technology Corp. -> Wacom Technology)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2021-02-10] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-02-26 12:17 - 2021-02-26 12:17 - 000003770 _____ C:\Users\AtelierNiederhein\Desktop\AdwCleaner[C00].txt
2021-02-26 12:16 - 2021-02-26 12:16 - 000198248 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-02-26 12:16 - 2021-02-26 12:16 - 000142416 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-02-26 12:16 - 2021-02-26 12:16 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-02-26 12:16 - 2021-02-26 12:16 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\IGDump
2021-02-26 12:13 - 2021-02-26 12:15 - 000000000 ____D C:\AdwCleaner
2021-02-26 12:10 - 2021-02-26 12:10 - 008463216 _____ (Malwarebytes) C:\Users\AtelierNiederhein\Downloads\adwcleaner_8.1.exe
2021-02-26 12:08 - 2021-02-26 12:08 - 000020274 _____ C:\Users\AtelierNiederhein\Desktop\malwareScan.txt
2021-02-26 11:58 - 2021-02-26 11:58 - 000000000 ____H C:\ProgramData\rebootpending.txt
2021-02-26 11:58 - 2021-02-26 11:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avira
2021-02-26 11:50 - 2021-02-26 11:50 - 000220616 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-02-26 11:50 - 2021-02-26 11:50 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-02-26 11:50 - 2021-02-26 11:50 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2021-02-26 11:49 - 2021-02-26 12:16 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-02-26 11:49 - 2021-02-26 11:49 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-02-26 11:49 - 2021-02-26 11:49 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-02-26 11:21 - 2021-02-26 11:21 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\mbam
2021-02-26 11:20 - 2021-02-26 11:20 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-02-26 11:18 - 2021-02-26 11:18 - 000000000 ____D C:\Program Files\Malwarebytes
2021-02-26 11:16 - 2021-02-26 11:16 - 002084016 _____ (Malwarebytes) C:\Users\AtelierNiederhein\Downloads\MBSetup.exe
2021-02-26 08:53 - 2021-02-26 08:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-02-26 07:38 - 2021-02-26 12:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2021-02-25 16:27 - 2021-02-25 16:28 - 000083593 _____ C:\Users\AtelierNiederhein\Downloads\Addition.txt
2021-02-25 16:25 - 2021-02-26 12:20 - 000033795 _____ C:\Users\AtelierNiederhein\Downloads\FRST.txt
2021-02-25 16:25 - 2021-02-26 12:20 - 000000000 ____D C:\FRST
2021-02-25 16:25 - 2021-02-25 16:25 - 002301440 _____ (Farbar) C:\Users\AtelierNiederhein\Downloads\FRST64.exe
2021-02-25 16:08 - 2021-02-25 16:08 - 000000000 ____D C:\WINDOWS\Panther
2021-02-24 18:02 - 2021-02-24 18:02 - 000022749 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_QTZQMX4WFQAB_1_Frau_Annette_Bohrloch.pdf
2021-02-24 15:10 - 2021-02-24 15:11 - 001029393 _____ C:\Users\AtelierNiederhein\Downloads\MWS_Integrators_ListingCreation_UK._V272404261_.pdf
2021-02-24 11:04 - 2021-02-24 11:04 - 005541016 _____ (Stanislav Polshyn & Trend Micro Inc.) C:\Users\AtelierNiederhein\Downloads\hijackthis.exe
2021-02-24 09:33 - 2021-02-24 09:34 - 001471893 _____ C:\Users\AtelierNiederhein\Downloads\f111-Vollmacht.pdf
2021-02-24 08:35 - 2021-02-25 15:50 - 000008046 _____ C:\WINDOWS\ntbtlog.txt
2021-02-24 08:25 - 2021-02-24 08:25 - 000000000 ____D C:\NPE
2021-02-24 08:24 - 2021-02-24 08:27 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\NPE
2021-02-24 08:24 - 2021-02-24 08:24 - 000000000 ____D C:\ProgramData\Norton
2021-02-24 08:23 - 2021-02-24 08:23 - 009645984 _____ (NortonLifeLock Inc.) C:\Users\AtelierNiederhein\Desktop\NPE.exe
2021-02-23 16:50 - 2021-02-23 16:50 - 000059863 _____ C:\Users\AtelierNiederhein\Documents\Liste_Zoll_v2.pdf
2021-02-22 16:53 - 2021-02-22 16:53 - 000022502 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_6VY63898CDB4_1_Herr_Thomas_Leonhardy.pdf
2021-02-22 16:38 - 2021-02-22 16:38 - 000191744 _____ C:\Users\AtelierNiederhein\Desktop\genexport (2).CSV
2021-02-20 14:04 - 2021-02-20 14:05 - 005228592 _____ C:\Users\AtelierNiederhein\Downloads\Deep_dive_on_Amazon_Neptune_DAT361.pdf
2021-02-19 15:30 - 2021-02-19 15:30 - 000693574 _____ C:\Users\AtelierNiederhein\Downloads\warum-2012.pdf
2021-02-19 09:31 - 2021-02-19 09:31 - 004310122 _____ C:\Users\AtelierNiederhein\Downloads\pkg_communitybuilder_2.5.0+build.2021.02.01.21.20.37.ae3d43f4e(1).zip
2021-02-19 09:30 - 2021-02-19 09:30 - 004310122 _____ C:\Users\AtelierNiederhein\Downloads\pkg_communitybuilder_2.5.0+build.2021.02.01.21.20.37.ae3d43f4e.zip
2021-02-18 10:32 - 2021-02-18 10:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2021-02-18 09:29 - 2021-02-18 09:29 - 000050434 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_M296EML5ZDZA_1_Frau_Petra_Rappo.pdf
2021-02-18 09:29 - 2021-02-18 09:29 - 000006556 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210218M296EML5ZDZA-0012191914.pdf
2021-02-16 17:13 - 2021-02-16 17:13 - 000024610 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_Y9P3XM464MRB_1_Frau_Sarah_Romaniw.pdf
2021-02-16 17:13 - 2021-02-16 17:13 - 000024457 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_Y9P3XM464MRB_2_Frau_Marina_Mudrytska.pdf
2021-02-15 12:26 - 2021-02-15 12:26 - 000818689 _____ C:\Users\AtelierNiederhein\Downloads\Justizkrimi_ROCO_Raiffeisen_Manager-Magazin_Maerz2018.pdf
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2021-02-14 04:12 - 2021-02-14 04:12 - 000044064 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2021-02-12 16:21 - 2021-02-12 16:21 - 007857864 _____ C:\Users\AtelierNiederhein\Downloads\X20001-136-CatalogueSennelierFR-DE-NL-2019-pagesinterieures-reduc.pdf
2021-02-12 16:08 - 2021-02-12 16:08 - 000024364 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_1_Sandra_Krug.pdf
2021-02-12 16:08 - 2021-02-12 16:08 - 000022479 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_2_Frau_Peggy_Stein.pdf
2021-02-12 16:08 - 2021-02-12 16:08 - 000022198 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_3_Frau_Nicole_Michaloudis.pdf
2021-02-12 12:45 - 2021-02-12 16:10 - 000004691 _____ C:\Users\AtelierNiederhein\.ganttproject
2021-02-12 12:44 - 2021-02-12 12:46 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\GanttProject
2021-02-12 12:44 - 2021-02-12 12:44 - 000002056 _____ C:\ProgramData\Desktop\GanttProject.lnk
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\Users\AtelierNiederhein\.ganttproject.d
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GanttProject
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\Program Files (x86)\GanttProject-3.0
2021-02-12 12:41 - 2021-02-12 12:44 - 114651200 _____ C:\Users\AtelierNiederhein\Downloads\ganttproject-3.0.3000.exe
2021-02-12 08:43 - 2021-02-12 08:43 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-02-12 08:43 - 2021-02-12 08:43 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-02-12 08:43 - 2021-02-12 08:43 - 001314112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-02-12 08:43 - 2021-02-12 08:43 - 000231232 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-02-12 08:43 - 2021-02-12 08:43 - 000010892 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-02-08 15:03 - 2021-02-08 15:03 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2020.lnk
2021-02-06 17:26 - 2021-02-06 17:26 - 000024381 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_4_Herr_Marc_Tenner.pdf
2021-02-06 17:26 - 2021-02-06 17:26 - 000022525 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_3_Andreas_Wäldele.pdf
2021-02-06 17:26 - 2021-02-06 17:26 - 000022499 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_5_Kristina_Neumann.pdf
2021-02-05 16:58 - 2021-02-05 16:58 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\Oracle
2021-02-05 16:39 - 2021-02-05 16:39 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AusweisApp2.lnk
2021-02-05 16:39 - 2021-02-05 16:39 - 000001134 _____ C:\ProgramData\Desktop\AusweisApp2.lnk
2021-02-05 16:39 - 2021-02-05 16:39 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\Governikus GmbH & Co. KG
2021-02-05 16:39 - 2021-02-05 16:39 - 000000000 ____D C:\Program Files (x86)\AusweisApp2
2021-02-05 16:38 - 2021-02-05 16:38 - 022896640 _____ C:\Users\AtelierNiederhein\Downloads\AusweisApp2-1.22.0.msi
2021-02-05 08:32 - 2021-02-05 08:32 - 000005689 _____ C:\Users\AtelierNiederhein\Documents\Snipping Tool Print Job.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000041458 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_3_Frau_petra_rappo.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000024538 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_2_Andreas_Wäldele.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000024529 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_1_Heiko_Herbst_.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000024289 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_6_Frau_Gudrun_Doege-Klein.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000022702 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_5_Herr_Matthias_Kindler.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000022531 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_4_Frau_Brigitte_Andritzke-Walter.pdf
2021-02-03 19:37 - 2021-02-03 19:37 - 000006899 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210203WNBT9UR88PC4-0011834233.pdf
2021-02-03 19:22 - 2021-02-03 19:22 - 000006659 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210203VFDKBKTSEB3M-0011833904.pdf
2021-02-03 19:17 - 2021-02-03 19:17 - 000244723 _____ C:\Users\AtelierNiederhein\Downloads\2kg_coupons_20210114.pdf
2021-02-03 13:45 - 2021-02-03 13:45 - 000001052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign 2021.lnk
2021-02-02 17:38 - 2021-02-02 17:38 - 000976969 _____ C:\Users\AtelierNiederhein\Downloads\Archive-2021-02-02-17-38-03.zip
2021-02-02 09:14 - 2021-02-02 09:38 - 000040076 _____ C:\Users\AtelierNiederhein\Downloads\oxarticles.csv
2021-02-01 14:08 - 2021-02-01 14:08 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2021.lnk
2021-02-01 13:19 - 2021-02-01 13:19 - 000115971 _____ C:\Users\AtelierNiederhein\Downloads\invoice_TC9927697177.pdf
2021-02-01 12:35 - 2021-02-01 12:36 - 001756565 _____ C:\Users\AtelierNiederhein\Downloads\Kontoeroeffnung_20210201_600170.pdf
2021-02-01 10:09 - 2021-02-01 09:29 - 000020020 _____ C:\Users\AtelierNiederhein\Documents\order_pastell-shop__Standard%20Pastels%20Order%20Spreadsheet-20210126.xls_0.ods
2021-01-29 12:20 - 2021-02-16 12:35 - 000000000 ____D C:\Users\AtelierNiederhein\Downloads\archiv
2021-01-27 15:01 - 2021-01-27 15:01 - 000000000 ____D C:\WINDOWS\SysWOW64\NV
2021-01-27 15:01 - 2021-01-27 15:01 - 000000000 ____D C:\WINDOWS\system32\NV
2021-01-27 14:59 - 2021-01-23 09:57 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-27 14:59 - 2021-01-23 09:57 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-01-27 14:59 - 2021-01-23 09:57 - 001453720 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-01-27 14:59 - 2021-01-23 09:57 - 001435872 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-27 14:59 - 2021-01-23 09:57 - 001435872 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-01-27 14:59 - 2021-01-23 09:57 - 001094872 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-01-27 14:59 - 2021-01-23 09:57 - 001094872 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-01-27 14:59 - 2021-01-23 09:57 - 000948960 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-27 14:59 - 2021-01-23 09:57 - 000948960 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-01-27 14:59 - 2021-01-23 09:56 - 001193112 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 001512104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 001164968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 000680088 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 000672936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 000558248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-01-27 14:59 - 2021-01-23 09:54 - 000547480 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 008262312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 007392920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 004611760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 002731184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 002103448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 001732264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446140.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 001589400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 001491608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446140.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 000813208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-01-27 14:59 - 2021-01-23 09:53 - 000657048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-01-27 14:59 - 2021-01-23 09:50 - 006070848 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2021-02-26 12:18 - 2017-07-12 17:41 - 000000000 ____D C:\ProgramData\NVIDIA
2021-02-26 12:18 - 2017-02-25 20:36 - 000000000 ____D C:\ProgramData\Mozilla
2021-02-26 12:17 - 2020-11-02 14:30 - 000000000 ____D C:\Program Files (x86)\Steam
2021-02-26 12:17 - 2017-02-25 17:41 - 000000000 ___RD C:\Users\AtelierNiederhein\Creative Cloud Files
2021-02-26 12:17 - 2016-11-20 16:10 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\Mozilla
2021-02-26 12:16 - 2020-09-25 18:05 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK
2021-02-26 12:16 - 2020-09-25 16:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-02-26 12:16 - 2020-09-25 16:09 - 000008192 ___SH C:\DumpStack.log.tmp
2021-02-26 12:16 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-02-26 12:16 - 2017-07-12 17:41 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-02-26 12:16 - 2015-12-20 08:54 - 000000000 ___RD C:\Users\AtelierNiederhein\OneDrive
2021-02-26 12:16 - 2015-12-19 17:36 - 000000000 __SHD C:\Users\AtelierNiederhein\IntelGraphicsProfiles
2021-02-26 12:15 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-02-26 12:09 - 2020-09-25 16:13 - 001590256 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-02-26 12:09 - 2019-12-07 15:50 - 000684966 _____ C:\WINDOWS\system32\perfh007.dat
2021-02-26 12:09 - 2019-12-07 15:50 - 000141424 _____ C:\WINDOWS\system32\perfc007.dat
2021-02-26 12:09 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2021-02-26 12:05 - 2020-09-25 16:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-02-26 12:05 - 2017-02-25 17:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-02-26 11:59 - 2017-02-25 16:39 - 000000000 ____D C:\ProgramData\Avira
2021-02-26 11:59 - 2017-02-25 16:39 - 000000000 ____D C:\Program Files (x86)\Avira
2021-02-26 11:58 - 2017-02-25 16:39 - 000000000 ____D C:\ProgramData\Package Cache
2021-02-26 11:57 - 2020-06-15 06:41 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-02-26 11:57 - 2020-06-15 06:41 - 000002274 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-02-26 11:57 - 2019-04-28 07:38 - 000002252 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-02-26 11:57 - 2017-02-25 20:40 - 000001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-02-26 11:49 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-02-26 09:17 - 2014-05-11 16:05 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\Steuerfälle
2021-02-26 08:32 - 2019-04-28 07:38 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-02-26 07:37 - 2019-11-06 05:57 - 000000000 ___HD C:\adobeTemp
2021-02-26 07:37 - 2017-02-25 17:40 - 000000000 ____D C:\Program Files\Common Files\Adobe
2021-02-25 14:15 - 2017-09-29 06:49 - 000001456 _____ C:\Users\AtelierNiederhein\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2021-02-24 09:38 - 2020-08-21 13:07 - 000000000 ____D C:\Projekte
2021-02-24 08:51 - 2017-04-25 04:57 - 000001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2021-02-24 08:51 - 2017-04-25 04:57 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-02-24 08:40 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-02-23 15:18 - 2017-02-25 16:21 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Adobe
2021-02-23 15:18 - 2014-07-10 19:50 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\Adobe
2021-02-23 09:08 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-02-22 16:48 - 2020-06-17 09:17 - 000007862 _____ C:\Users\AtelierNiederhein\Desktop\oxarticles.csv
2021-02-22 14:03 - 2020-08-21 10:35 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-02-22 09:16 - 2014-03-27 21:38 - 000000000 ___RD C:\Users\AtelierNiederhein\Dropbox
2021-02-22 08:14 - 2017-03-02 05:48 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\FileZilla
2021-02-20 13:51 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-02-18 14:13 - 2017-02-25 17:30 - 000000000 ____D C:\Program Files\Adobe
2021-02-18 14:07 - 2017-03-07 17:01 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\CrashDumps
2021-02-18 10:32 - 2017-02-26 08:22 - 000000000 ____D C:\Program Files (x86)\Dropbox
2021-02-17 15:47 - 2020-07-18 13:18 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Code
2021-02-17 09:58 - 2020-11-09 11:06 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\pyinstaller
2021-02-17 09:50 - 2020-07-18 13:57 - 000000000 ____D C:\Users\AtelierNiederhein\.pylint.d
2021-02-16 11:30 - 2014-04-03 17:47 - 000000000 ____D C:\Users\AtelierNiederhein\Desktop\tmp
2021-02-15 16:51 - 2017-02-26 10:14 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2021-02-15 16:51 - 2017-02-26 10:14 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2021-02-15 15:22 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-02-15 08:27 - 2020-09-25 16:18 - 000003392 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-962593549-1501595251-2753236537-1000
2021-02-15 08:27 - 2020-09-25 16:10 - 000002455 _____ C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-02-12 16:39 - 2020-09-25 16:09 - 010187680 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-02-12 16:38 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2021-02-12 16:10 - 2020-09-25 16:10 - 000000000 ____D C:\Users\AtelierNiederhein
2021-02-12 12:20 - 2020-07-18 13:18 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2021-02-12 08:38 - 2017-02-25 18:33 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-02-12 08:35 - 2017-02-25 18:33 - 130141752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-02-11 07:42 - 2020-09-25 16:18 - 000003700 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-02-11 07:42 - 2020-09-25 16:18 - 000003576 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-02-10 16:07 - 2018-12-16 11:38 - 000000600 _____ C:\Users\AtelierNiederhein\AppData\Local\PUTTY.RND
2021-02-10 09:22 - 2020-07-23 12:41 - 000000000 ____D C:\Program Files (x86)\PUBGLite
2021-02-10 08:59 - 2019-11-18 22:14 - 000074552 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys
2021-02-09 15:39 - 2020-09-25 16:18 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-02-06 12:20 - 2020-09-25 16:18 - 000003630 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-02-06 12:20 - 2020-09-25 16:18 - 000003506 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-02-05 20:04 - 2020-02-20 08:56 - 000734016 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2021-02-05 20:03 - 2020-08-21 10:35 - 000470848 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2021-02-02 10:35 - 2021-01-26 11:56 - 000002311 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteuerSparErklärung 2021.lnk
2021-02-02 10:35 - 2021-01-26 11:56 - 000002254 _____ C:\ProgramData\Desktop\SteuerSparErklärung 2021.lnk
2021-02-02 10:35 - 2021-01-26 11:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteuerSparErklärung 2021
2021-01-29 11:50 - 2017-02-26 08:22 - 000001258 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2021-01-29 11:50 - 2017-02-26 08:22 - 000001254 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2021-01-27 15:50 - 2017-06-30 09:28 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\NVIDIA
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2017-03-10 16:07 - 2018-10-21 11:41 - 000000033 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\AdobeWLCMCache.dat
2017-05-13 05:47 - 2020-11-07 16:23 - 000010120 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\ContactSheetII.log
2017-05-13 05:47 - 2020-11-07 16:23 - 000000709 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\Kontaktabzug II.xml
2021-01-02 17:16 - 2021-01-02 17:16 - 000000028 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\kulerdata.json
2017-09-29 06:49 - 2021-02-25 14:15 - 000001456 _____ () C:\Users\AtelierNiederhein\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2018-09-29 02:32 - 2018-09-29 02:32 - 000000000 _____ () C:\Users\AtelierNiederhein\AppData\Local\oobelibMkey.log
2018-12-16 11:38 - 2021-02-10 16:07 - 000000600 _____ () C:\Users\AtelierNiederhein\AppData\Local\PUTTY.RND
2020-08-23 12:04 - 2020-08-23 12:04 - 000008317 _____ () C:\Users\AtelierNiederhein\AppData\Local\recently-used.xbel
2018-08-16 16:14 - 2018-08-16 16:14 - 000007601 _____ () C:\Users\AtelierNiederhein\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== |