| Goldberg |  26.02.2021 12:38 |        Hallo Matthias,  
schon mal vielen Dank für Deine Hilfe!  
Ja, ich gestehe, dass ich in Sachen PC-Hygiene sehr schlampig bin und es mir sicher viel zu oft zu einfach mache. Sicher verwunderlich, dass ich mir bisher nichts Schlimmeres eingefangen habe.  
Die Anweisungen habe ich ausgeführt und im Folgenden die Logs....  
Vielen Dank! 
Michael    Code:  
 Malwarebytes 
www.malwarebytes.com   
-Protokolldetails- 
Scan-Datum: 26.02.21 
Scan-Zeit: 11:51 
Protokolldatei: 88872f04-7820-11eb-8055-74d43585b2ed.json   
-Softwaredaten- 
Version: 4.3.0.98 
Komponentenversion: 1.0.1173 
Version des Aktualisierungspakets: 1.0.37509 
Lizenz: Testversion   
-Systemdaten- 
Betriebssystem: Windows 10 (Build 19042.804) 
CPU: x64 
Dateisystem: NTFS 
Benutzer: Atelier_PC\AtelierNiederhein   
-Scan-Übersicht- 
Scan-Typ: Bedrohungs-Scan 
Scan gestartet von: Manuell 
Ergebnis: Abgeschlossen 
Gescannte Objekte: 343948 
Erkannte Bedrohungen: 90 
In die Quarantäne verschobene Bedrohungen: 90 
Abgelaufene Zeit: 5 Min., 0 Sek.   
-Scan-Optionen- 
Speicher: Aktiviert 
Start: Aktiviert 
Dateisystem: Aktiviert 
Archive: Aktiviert 
Rootkits: Aktiviert 
Heuristik: Aktiviert 
PUP: Erkennung 
PUM: Erkennung   
-Scan-Details- 
Prozess: 0 
(keine bösartigen Elemente erkannt)   
Modul: 0 
(keine bösartigen Elemente erkannt)   
Registrierungsschlüssel: 14 
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}, In Quarantäne, 6916, 396863, , , , , ,  
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startfenster-Replace.de, In Quarantäne, 8265, 350112, , , , , ,  
PUP.Optional.GoodGame.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GoodGame.de, In Quarantäne, 8946, 401580, , , , , ,  
PUP.Optional.StartPage, HKLM\SOFTWARE\Websuche, In Quarantäne, 571, 463409, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 8265, 350115, 1.0.37509, , ame, , ,  
PUP.Optional.GimpUpdaterDe.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GIMP Updater, In Quarantäne, 13870, 728127, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\djhangopedggnlnicpbjklghlckmndge, In Quarantäne, 8265, 354303, 1.0.37509, , ame, , ,  
PUP.Optional.GreatDealz, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\lobonlhedgiilkfmbbbfhkaoefacipgj, In Quarantäne, 8685, 466866, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 8265, 350115, 1.0.37509, , ame, , ,  
PUP.Optional.QwebDe, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Qweb.de, In Quarantäne, 9667, 478742, , , , , ,  
Adware.KeenValue, HKLM\SOFTWARE\WOW6432NODE\Updater, In Quarantäne, 3526, 212959, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Updater, In Quarantäne, 8265, 541219, , , , , ,    
Registrierungswert: 10 
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|FAVICONURL, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,  
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|URL, In Quarantäne, 6916, 396863, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|STARTFENSTER SYMBOL, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|STARTFENSTER-REPLACE, In Quarantäne, 8259, 401432, 1.0.37509, , ame, , ,  
PUP.Optional.GoodGame.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\AM|GOODGAME, In Quarantäne, 8946, 401601, 1.0.37509, , ame, , ,  
PUP.Optional.GimpUpdaterDe.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GIMP UPDATER, In Quarantäne, 13870, 728126, 1.0.37509, , ame, , ,  
PUP.Optional.GreatDealz, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|LOBONLHEDGIILKFMBBBFHKAOEFACIPGJ, In Quarantäne, 8685, 466866, , , , , ,  
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|FAVICONURL, In Quarantäne, 6916, 396862, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, In Quarantäne, 8265, 541219, , , , , ,  
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CDFB2166-DF6D-4054-BD68-4FDEEDA24BFA}|URL, In Quarantäne, 6916, 396862, 1.0.37509, , ame, , ,    
Registrierungsdaten: 1 
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-962593549-1501595251-2753236537-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 6916, 395422, 1.0.37509, , ame, , ,    
Daten-Stream: 0 
(keine bösartigen Elemente erkannt)   
Ordner: 12 
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE, In Quarantäne, 8265, 350112, 1.0.37509, , ame, , ,  
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAM FILES (X86)\GOODGAME, In Quarantäne, 8946, 401580, 1.0.37509, , ame, , ,  
PUP.Optional.VLCUpdaterDE, C:\PROGRAM FILES (X86)\VLC UPDATER, In Quarantäne, 8336, 353751, 1.0.37509, , ame, , ,  
PUP.Optional.GreatDealz, C:\PROGRAM FILES (X86)\GREATDEALZ, In Quarantäne, 8685, 388477, 1.0.37509, , ame, , ,  
PUP.Optional.QwebDe, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\QWEB SYMBOL, In Quarantäne, 9667, 478741, 1.0.37509, , ame, , ,  
PUP.Optional.QwebDe, C:\PROGRAM FILES (X86)\QWEB SYMBOL, In Quarantäne, 9667, 478742, 1.0.37509, , ame, , ,  
Trojan.Banker, C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1968138750, In Quarantäne, 25, 506854, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, C:\PROGRAMDATA\UPDATER, In Quarantäne, 8265, 541219, 1.0.37509, , ame, , ,  
PUP.Optional.QwebDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER, In Quarantäne, 11022, 728125, 1.0.37509, , ame, , ,  
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,  
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,  
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, In Quarantäne, 8265, 455286, , , , , ,    
Datei: 53 
PUP.Optional.StartFenster.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\STARTFENSTER.LNK, In Quarantäne, 8259, 349853, 1.0.37509, , ame, , AF388855D2264546E3C332ADB25A22D9, 145F6A3FB58A8EB6392C59BD5BEE69E05A6D1E5AD49EC22AFB82D9BD04B9A1D0 
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\STARTFENSTER SYMBOL.LNK, In Quarantäne, 8265, 350108, 1.0.37509, , ame, , 4335E2A9C86EAF6F50605D66F53C0CD5, 42B6DAAEAA4448DB13BAE495105AD122C368B30972E064A681220DAFC04BBE0C 
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE\LOGO.ICO, In Quarantäne, 8265, 350112, 1.0.37509, , ame, , BDCF63C89B22A44CDF5B1BE184714A26, C333C15AC24C7820F8E613E6878F1823514E15618CBBFE16161405CDE5270A39 
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\uninstall.exe, In Quarantäne, 8265, 350112, , , , , 453CD208DDE29DF341C2D8C3754D23BC, 12C1395B92058BF0EEE1375B5A7A8E71EC2EF0E1C20165AC367E05C4DDFA5B06 
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAM FILES (X86)\GOODGAME\SETUP.ICO, In Quarantäne, 8946, 401580, 1.0.37509, , ame, , 58E4B64420F84EFA71F0CE29CD50429E, BA306550D41BE6E77BB836384504AC1979F467320295E6BE2A2F39433DF7A7A6 
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\bigfarm.ico, In Quarantäne, 8946, 401580, , , , , 45B821EB95557B6B7E00289F22C1BA24, 4C02D9BF5497A4CCA25F054311C0C12E64495E9AC2EA235A6E8787029ED99CBF 
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\empire.ico, In Quarantäne, 8946, 401580, , , , , 58A5323B66D3334572DA30572A369CE9, AE64EBDD1309C30F4778244330EEC7ED6EEEB96A363426586519E3C4356CC67A 
PUP.Optional.GoodGame.ShrtCln, C:\Program Files (x86)\GoodGame\uninstall.exe, In Quarantäne, 8946, 401580, , , , , 48FF80E435CDE88CE8640F836CBBA91D, 9BEB37DF3BD5974ABC51B7BF35F0A38D6B6F7C94026238F58815E95CCE55CBE4 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\GOODGAME.LNK, In Quarantäne, 8946, 401586, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\PUBLIC\DESKTOP\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401592, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\PUBLIC\DESKTOP\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401592, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401583, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401583, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401584, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401584, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401585, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401585, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.VLCUpdaterDE, C:\PROGRAM FILES (X86)\VLC UPDATER\SETUP.ICO, In Quarantäne, 8336, 353751, 1.0.37509, , ame, , 6F7E92FE7E6A62661AC2B41528A78FC6, FD9B5998B98EE0BA86ED7687F215A1CDDE90C00B0B1CD11DC83E3614389CB6AD 
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\uninstall.exe, In Quarantäne, 8336, 353751, , , , , 8E387B02090DBCF119EA219AE9425C21, 28E1A7C4178970D87BA3790461B6E1E29C5E91B38C25D3EC6F1C977578ECA0EC 
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc-updater.exe, In Quarantäne, 8336, 353751, , , , , 386112C1632557841499A65BA32165D3, 511E5FBBCE302C5A394E7EC41C230687117A382A788D15774325A75E94F886DE 
PUP.Optional.GimpUpdaterDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER\UPDATER.EXE, In Quarantäne, 13870, 728126, , , , , 18774F18676445FA0B85BEC3037F9CF4, 9646873526A4F5C05267EDBA8D88D6651107B9E67DA6C45D0D3370C49A1E95BE 
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\GOODGAME\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401581, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\GOODGAME\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401581, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\GoodGame BigFarm spielen.lnk, In Quarantäne, 8946, 401587, 1.0.37509, , ame, , EA120EBBF3C266CAC8EFD91C524A74E1, CF72108120A7831F4210E149C6973D8C0343D286A4391693FFAC9094A8CC6C9C 
PUP.Optional.GreatDealz, C:\Program Files (x86)\GreatDealz\lobonlhedgiilkfmbbbfhkaoefacipgj.crx, In Quarantäne, 8685, 388477, , , , , 318FDE27DCD8B40F85B0790DE1B84D98, 26529CDA5F955326AF2ABD49914FCFA50358A2A16ADB5CEB7AD7BE61452C7CB1 
PUP.Optional.GoodGame.ShrtCln, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\GoodGame Empire spielen.lnk, In Quarantäne, 8946, 401587, 1.0.37509, , ame, , 30D7D37DA3C02E97A295E72191EEBFBE, 354D9C3E0CD86706FA59045EE6441CF57A97B7A413FE2D80C40CB4063814E63E 
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478748, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.GreatDealz, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Ersetzt, 8685, 466866, , , , , C1F1EAA4B9D09A1EB82D48D486517766, 321F4C1C078AA4DC5ABC154D60A79B49A0268830F08AB58391A08C7F3310024E 
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\FAVORITES\LINKS\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478749, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.QwebDe, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478744, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\QWEB SYMBOL.LNK, In Quarantäne, 9667, 496142, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.QwebDe, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qweb Symbol\ deinstallieren.lnk, In Quarantäne, 9667, 478741, , , , , 161228C0F0003C55D74FCCA07BC694BA, D75B2FC452B96255F38C8FDC8595049ED022E087C889CCE81B71F5669B9A410F 
PUP.Optional.QwebDe, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qweb Symbol\Qweb Converter installieren.lnk, In Quarantäne, 9667, 478741, , , , , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.QwebDe, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\QWEB CONVERTER INSTALLIEREN.LNK, In Quarantäne, 9667, 478746, 1.0.37509, , ame, , 3E9DADC7A69FF007E90069FF81161A96, E207F82B2A0477132651D1B9020035EF9BA2D2FC2ED5236A9CF4728FA3B38933 
PUP.Optional.QwebDe, C:\Program Files (x86)\Qweb Symbol\qweb.ico, In Quarantäne, 9667, 478742, , , , , 36D4D68344A3095BDFAB1FA5FE030795, ED9E540371968B4A63CE0705B31CAFA00AC8F5540413C4557F07C26C3D6CF0F2 
PUP.Optional.QwebDe, C:\Program Files (x86)\Qweb Symbol\uninstall.exe, In Quarantäne, 9667, 478742, , , , , 364C38809CDD45188621EEE377B23FCF, DFE5A4739A068E39BB887FBB6FDCCE4A448E4751EBDFA9E326F5F609A66887BD 
PUP.Optional.StartFenster, C:\PROGRAMDATA\UPDATER\CHECK-UPDATE.EXE, In Quarantäne, 8265, 541219, 1.0.37509, , ame, , 470F3664CB71A971177593422280713B, 2C1E83A4F17CE641878B4625BA7D46E9EA5C415D084A5D9161FADB619CAD4A6F 
PUP.Optional.StartFenster, C:\ProgramData\Updater\setup.ico, In Quarantäne, 8265, 541219, , , , , A60B9AFB2DBC13DBFCFE4172325D1712, B2199B7933227655475B64C50AFE09E1DB10D511A248283DDD8EE88EF794A680 
PUP.Optional.StartFenster, C:\ProgramData\Updater\uninstall.exe, In Quarantäne, 8265, 541219, , , , , 261B2499F1F5D36B46F3B730FFDB4996, 1D94DF3DB02E6067E936BFACC0D10FC27464DD635F6D8E0665721AE6D6F9A724 
PUP.Optional.QwebDe.ShrtCln, C:\USERS\ATELIERNIEDERHEIN\APPDATA\ROAMING\GIMP UPDATER\GIMP.ICO, In Quarantäne, 11022, 728125, 1.0.37509, , ame, , 3A502781380607A40C507EB316BB5D96, 9165E8721AC00B0E2235F018181B2383F42BA1451B8365A918BDFC82F6E0B63E 
PUP.Optional.QwebDe.ShrtCln, C:\Users\AtelierNiederhein\AppData\Roaming\GIMP Updater\uninst.exe, In Quarantäne, 11022, 728125, , , , , BA40B063B7C51AF1C254ED18B32DC86E, 18459F7E2F32D68075172F190E8B6F91D058A6DB225CE8E8C4392B5F6D0FDA85 
PUP.Optional.ChipDe, C:\USERS\ATELIERNIEDERHEIN\DOWNLOADS\HIJACKTHIS - CHIP-INSTALLER VOM 24.02.2021 456E5770BF506EB7D7B3888D815AD1B5.EXE, In Quarantäne, 9554, 557991, 1.0.37509, C2BF7BCB91C3F9EDC4D26450, dds, 01133428, 5F5B877DFAC2A4EC5AF890F33D7801C6, 5C3022D3CEDD37473E7FA598742CA27DA5B07C1E658A801CC64686F2E1FCB729 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, In Quarantäne, 8265, 455286, , , , , 87A2838AE6CBF992A379B8A811786412, E42EDAEF21E97C70113290032164317E8F73F5C7C4BBC455643600B09C930E67 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000113.log, In Quarantäne, 8265, 455286, , , , , 8443299947279799FBB908AC4F7D0350, 841F10BA21C4B6EFA535919F95C12B5B5C197C8A2D966E2466B349E2768FFC6E 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000115.ldb, In Quarantäne, 8265, 455286, , , , , 165F91051B914EAA5BA0B0BA311792D4, 9F81BA32B14F907E69E9C01628F850E332E114F71AD4C7B4FE9780604AA4A733 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, In Quarantäne, 8265, 455286, , , , , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, In Quarantäne, 8265, 455286, , , , , ,  
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, In Quarantäne, 8265, 455286, , , , , 90A43EDB8B2B2E50F1FD9EB008681DA5, 73A93845703D4E7594F4BE0695BF392CE798DE6847EB1597DF7F6157B3492CB0 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, In Quarantäne, 8265, 455286, , , , , 0A23996397857C10CD0C21EA62E3706B, D5EA8700EA252FBA80E4E04F442FF105401AE0B006928E6A183E00F0014438F3 
PUP.Optional.StartFenster, C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, In Quarantäne, 8265, 455286, , , , , 21E48FC9828C99A45F5D4927CAB9B16E, 65070D1C73DDEAF7B693D20B895C1DC96B87B132D9CF8E5C180541E3AE201844 
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B 
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B 
PUP.Optional.StartFenster, C:\USERS\ATELIERNIEDERHEIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Ersetzt, 8265, 455286, 1.0.37509, , ame, , 5883D038EAF12922D81DEC733D7C5BC7, 223DDF01FE0A2CD3A5444966A88B985B963FB526A7EA9A2ADF877CDF67DCCC3B   
Physischer Sektor: 0 
(keine bösartigen Elemente erkannt)   
WMI: 0 
(keine bösartigen Elemente erkannt)     
(end)    Code:  
 # ------------------------------- 
# Malwarebytes AdwCleaner 8.1.0.0 
# ------------------------------- 
# Build:    02-15-2021 
# Database: 2021-01-26.1 (Cloud) 
# Support:  https://www.malwarebytes.com/support 
# 
# ------------------------------- 
# Mode: Clean 
# ------------------------------- 
# Start:    02-26-2021 
# Duration: 00:00:01 
# OS:       Windows 10 Home 
# Cleaned:  21 
# Awaiting reboot:1 
# Failed:   0     
***** [ Services ] *****   
No malicious services cleaned.   
***** [ Folders ] *****   
Deleted       C:\Program Files (x86)\VLC Plus Player 
Deleted       C:\ProgramData\Application Data\Lavasoft\Web Companion 
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoodGame 
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Plus Player 
Deleted       C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC UPDATER   
***** [ Files ] *****   
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster.lnk 
Deleted       C:\Users\Public\Desktop\VLC Plus Player.lnk   
***** [ DLL ] *****   
No malicious DLLs cleaned.   
***** [ WMI ] *****   
No malicious WMI cleaned.   
***** [ Shortcuts ] *****   
No malicious shortcuts cleaned.   
***** [ Tasks ] *****   
No malicious tasks cleaned.   
***** [ Registry ] *****   
Deleted       HKCU\Software\GIMP Updater 
Deleted       HKCU\Software\Lavasoft\Web Companion 
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion 
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com 
Deleted       HKLM\Software\Wow6432Node\Lavasoft\Web Companion 
Deleted       HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native 
Deleted       HKU\S-1-5-18\SOFTWARE\Mozilla\NativeMessagingHosts\com.webcompanion.native   
***** [ Chromium (and derivatives) ] *****   
No malicious Chromium entries cleaned.   
***** [ Chromium URLs ] *****   
No malicious Chromium URLs cleaned.   
***** [ Firefox (and derivatives) ] *****   
No malicious Firefox entries cleaned.   
***** [ Firefox URLs ] *****   
No malicious Firefox URLs cleaned.   
***** [ Hosts File Entries ] *****   
No malicious hosts file entries cleaned.   
***** [ Preinstalled Software ] *****   
Deleted       Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\SUPPORTASSIST\CLIENT\TECHNICIANTOOLKIT 
Deleted       Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA92FC08-40B9-4490-A1F6-CEEFCFD54526}  
Deleted       Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA92FC08-40B9-4490-A1F6-CEEFCFD54526}  
Deleted       Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dell SupportAssistAgent AutoUpdate 
Deleted       Preinstalled.DellSupportAssistAgent   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4015CD01-07AB-4354-9E43-E63DFAB5A6A2} 
Deleted       Preinstalled.DellSupportAssistAgent   Task   C:\Windows\System32\Tasks\DELL SUPPORTASSISTAGENT AUTOUPDATE 
Needs Reboot  Preinstalled.DellSupportAssistAgent   Folder   C:\Program Files\DELL\SUPPORTASSISTAGENT     
*************************   
[+] Delete Tracing Keys 
[+] Reset Winsock   
*************************   
***** Reboot Required to Complete *****     
***** [ Folders ] *****   
Cleaning failed   C:\Program Files\DELL\SUPPORTASSISTAGENT   
*************************   
AdwCleaner[S00].txt - [3566 octets] - [26/02/2021 12:14:40]   
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########    Code:  
 Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 24-02-2021 
durchgeführt von AtelierNiederhein (Administrator) auf ATELIER_PC (Gigabyte Technology Co., Ltd. G1.Sniper Z87) (26-02-2021 12:20:25) 
Gestartet von C:\Users\AtelierNiederhein\Downloads 
Geladene Profile: AtelierNiederhein 
Platform: Windows 10 Home Version 20H2 19042.804 (X64) Sprache: Deutsch (Deutschland) 
Standard-Browser: FF 
Start-Modus: Normal   
==================== Prozesse (Nicht auf der Ausnahmeliste) =================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)   
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe 
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe 
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <4> 
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe 
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe 
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe 
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe 
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_2.0.1.8_x86__enpm4xejd91yc\AdobeNotificationClient.exe 
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe 
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe 
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Utility Toolbox\cnqtbapp.exe 
(Canon INC.) [Datei ist nicht signiert] C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe 
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe 
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe 
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe 
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe 
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3> 
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe 
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe 
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\116.4.368\QtWebEngineProcess.exe <3> 
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe 
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe 
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe 
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe 
(Hewlett-Packard Company) [Datei ist nicht signiert] C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe 
(HP) [Datei ist nicht signiert] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe 
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe 
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe 
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe 
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe 
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe 
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe 
(Malwarebytes Inc -> Malwarebytes) C:\Users\AtelierNiederhein\Downloads\adwcleaner_8.1.exe 
(Microsoft Corporation -> Microsoft Corporation) C:\Users\AtelierNiederhein\AppData\Local\Microsoft\OneDrive\OneDrive.exe 
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe 
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe 
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe 
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe 
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe 
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe 
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe 
(Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe 
(Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe 
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <6> 
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe 
(Notepad++ -> Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe 
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe 
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> 
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2> 
(OpenJS Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe 
(Synology Inc. -> ) [Datei ist nicht signiert] C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe 
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe 
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe 
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe 
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe   
==================== Registry (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)   
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) 
HKLM\...\Run: [] => [X] 
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2095672 2020-10-09] (Adobe Inc. -> Adobe Inc.) 
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7992336 2021-02-14] (Dropbox, Inc -> Dropbox, Inc.) 
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [270912 2015-06-17] (Canon Inc. -> CANON INC.) 
HKLM-x32\...\Run: [CanonQuickToolbox] => C:\Program Files (x86)\Canon\Quick Utility Toolbox\cnqtbapp.exe [2340768 2018-05-09] (Canon Inc. -> CANON INC.) 
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-02-05] (Adobe Inc. -> ) 
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) 
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [330176 2014-08-19] (Hewlett-Packard Company -> Hewlett-Packard Company) 
HKLM-x32\...\Run: [] => [X] 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [680720 2021-02-18] (Adobe Inc. -> Adobe Systems Incorporated) 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3412696 2021-02-13] (Valve -> Valve Corporation) 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [TabletDriver] => C:\Huion Tablet\x64\TabletDriverCore.exe [334056 2019-12-28] (Shenzhen Huion Animation Technology Co.,LTD -> ) 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [AdobeBridge] => [X] 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [AusweisApp2] => C:\Program Files (x86)\AusweisApp2\AusweisApp2.exe [2405504 2020-11-30] (Governikus GmbH & Co. KG -> Governikus GmbH & Co. KG) 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Run: [] => [X] 
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\MountPoints2: {994bdb3c-1515-11eb-ab19-74d43585b2ed} - "E:\Autorun.exe"  
HKU\S-1-5-21-962593549-1501595251-2753236537-1000\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [4708328 2021-01-17] (Microsoft Windows -> Microsoft Corporation) <==== ACHTUNG 
HKLM\...\Windows x64\Print Processors\Canon MB2700 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDD0.DLL [30720 2018-07-17] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) 
HKLM\...\Windows x64\Print Processors\Canon MP640 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDA2.DLL [28672 2010-04-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) 
HKLM\...\Windows x64\Print Processors\hpcpp120: C:\Windows\System32\spool\prtprocs\x64\hpcpp120.DLL [342016 2012-01-27] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) 
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc) 
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor MB2700 series: C:\WINDOWS\system32\CNCALD0.DLL [254464 2015-11-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) 
HKLM\...\Print\Monitors\Canon BJ Language Monitor MB2700 series: C:\WINDOWS\system32\CNMLMD0.DLL [436736 2018-07-17] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) 
HKLM\...\Print\Monitors\Canon BJ Language Monitor MB2700 series XPS: C:\WINDOWS\system32\CNMXLMD0.DLL [438784 2015-11-18] (CANON INC.) [Datei ist nicht signiert] 
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\WINDOWS\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Datei ist nicht signiert] 
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\88.0.4324.190\Installer\chrmstp.exe [2021-02-26] (Google LLC -> Google LLC) 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Huion Tablet.lnk [2020-12-27] 
ShortcutTarget: Huion Tablet.lnk -> C:\Huion Tablet\Huion Tablet.exe (Shenzhen Huion Animation Technology Co.,LTD -> ) 
Startup: C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2017-10-15] 
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) [Datei ist nicht signiert]   
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
Task: {0BDFD991-F8B5-4BEE-8530-45660E0017B2} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-09] (Adobe Inc. -> Adobe) 
Task: {10D8BCA2-0BE0-467B-9D4B-A897FCB0A99C} - System32\Tasks\BundleApplicationRepairToolLauncherTask => C:\Users\AtelierNiederhein\AppData\Roaming\PCDr\Repair\BundleApplicationRepairTool.exe [625024 2018-01-22] (PC-Doctor, Inc. -> ) 
Task: {12F6F9F7-2275-45BB-95E7-2114EA65FF67} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe) 
Task: {1CFF7823-78EF-46B3-A9DC-7E09FBC06883} - System32\Tasks\Git for Windows Updater => C:\Program Files\Git\git-bash.exe [152128 2020-10-19] (Johannes Schindelin -> The Git Development Community) 
Task: {1E1AA683-1EEF-4264-8968-7EA37A1A3969} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.) 
Task: {1E8503BB-182C-4B7C-96D7-CA1396FDCF21} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-10-20] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {2220FFED-725D-45AC-804A-B0D1840B9931} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK 
Task: {40963EC1-283A-4F9B-A04D-ADD40F8398D5} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {44130ECF-C77E-4F05-8443-7EDB691A4EB3} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {5A31CF7F-82DF-4288-9EEC-00C0D39806B3} - System32\Tasks\AdobeAAMUpdater-1.0-Atelier_PC-AtelierNiederhein => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) 
Task: {5C4C9D73-63F6-40D1-B10A-51E01301ADEF} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {62A0F4F7-4327-4235-9042-94D34B32495B} - System32\Tasks\Red Giant Link => C:\Program [Argument = Files (x86)\Red Giant Link\Red Giant Link.exe] 
Task: {64151D08-FB32-4417-B741-0119D3ECB8E1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} 
Task: {65323232-04B3-4D1B-A73A-60CCB8464652} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {661367E9-26A1-411C-B42B-F962A4C04EDB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-28] (Google Inc -> Google LLC) 
Task: {781E23ED-CF39-4361-8B26-31C6AE6EA57D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) 
Task: {8B5250F2-E991-4F5D-9797-DFC5242918F3} - \Microsoft\Windows\UNP\RunCampaignManager -> Keine Datei <==== ACHTUNG 
Task: {9E36B745-5CA5-4EAD-A9B9-9A080FD510EF} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log 
Task: {B1B91048-64C2-4F64-A07C-48DF270D5FB9} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [694752 2021-02-26] (Mozilla Corporation -> Mozilla Foundation) 
Task: {BF9DFB29-744A-44C4-B75A-36CDBD359B87} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log 
Task: {CCCB4A12-FE2E-4E47-9019-FC85F691113D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {D2D4D365-8A40-48B8-848E-BFDA0B54BB7E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-28] (Google Inc -> Google LLC) 
Task: {DB3F2604-FE62-482E-9851-B4ABC5799615} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) 
Task: {E8636D29-32DE-412D-A15D-971827532F7F} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [89840 2014-10-19] (Hewlett-Packard Company -> Hewlett Packard) 
Task: {ECB9FE9C-C4C5-4722-A736-1903CFB243D0} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation) 
Task: {F6B38547-7C6F-4A89-AEA2-6D87DAF88FD7} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.) 
Task: {F8BF1748-421D-4457-9146-E1B158630EE3} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)   
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe   
==================== Internet (Nicht auf der Ausnahmeliste) ====================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)   
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 
Tcpip\..\Interfaces\{4f89c9de-8a11-4370-a3fc-a9199241aa6a}: [DhcpNameServer] 192.168.1.1   
Edge:  
======= 
Edge DefaultProfile: Default 
Edge Profile: C:\Users\AtelierNiederhein\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-26] 
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]   
FireFox: 
======== 
FF DefaultProfile: xspktsq9.default-1575993033040 
FF ProfilePath: C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 [2021-02-26] 
FF Homepage: Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 -> www.google.de 
FF Notifications: Mozilla\Firefox\Profiles\xspktsq9.default-1575993033040 -> hxxps://www.facebook.com 
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi 
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02] 
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi 
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> ) 
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-10-09] (Adobe Inc. -> Adobe Systems) 
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> ) 
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll [2008-10-15] (CANON INC.) [Datei ist nicht signiert] 
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\WINDOWS\system32\C2MP\npdivx32.dll [Keine Datei] 
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) 
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @videolan.org/vlc,version=3.0.9.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) 
FF Plugin-x32: @vlc.de/vlc,version=3.0.11 -> C:\Program Files (x86)\VLC Plus Player\npvlc.dll [Keine Datei] 
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2021-02-15] (Adobe Inc. -> Adobe Systems Inc.) 
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-10-09] (Adobe Inc. -> Adobe Systems) 
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\AtelierNiederhein\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-03-09] (Unity Technologies SF -> Unity Technologies ApS) 
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: LWA64Plugin15.8 -> C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Plugins\npLWA64Plugin15.8.dll [2013-03-13] (Microsoft Corporation -> Microsoft Corporation) 
FF Plugin HKU\S-1-5-21-962593549-1501595251-2753236537-1000: LWAPlugin15.8 -> C:\Users\AtelierNiederhein\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll [2013-03-13] (Microsoft Corporation -> Microsoft Corporation) 
FF Plugin ProgramFiles/Appdata: C:\Users\AtelierNiederhein\AppData\Roaming\mozilla\plugins\npLWA64Plugin15.8.dll [2018-05-25] 
FF Plugin ProgramFiles/Appdata: C:\Users\AtelierNiederhein\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll [2018-05-25]   
Chrome:  
======= 
CHR Profile: C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default [2021-02-25] 
CHR Notifications: Default -> hxxps://www.facebook.com; hxxps://www.instagram.com 
CHR StartupUrls: Default -> "hxxps://calendar.google.com/calendar/r?tab=wc" 
CHR Extension: (Präsentationen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-28] 
CHR Extension: (Docs) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-28] 
CHR Extension: (Google Drive) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-28] 
CHR Extension: (YouTube) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-28] 
CHR Extension: (Adobe Acrobat) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-12-18] 
CHR Extension: (Tabellen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-28] 
CHR Extension: (Google Docs Offline) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-11] 
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-10] 
CHR Extension: (Google Mail) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-28] 
CHR Extension: (Chrome Media Router) - C:\Users\AtelierNiederhein\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-02-10] 
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] 
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]   
==================== Dienste (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) 
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe) 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [852024 2020-10-09] (Adobe Inc. -> Adobe Inc.) 
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) 
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) 
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8404720 2019-11-09] (BattlEye Innovations e.K. -> ) 
R2 Cloud Station Drive VSS Service x64; C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe [287256 2018-05-18] (Synology Inc. -> ) [Datei ist nicht signiert] 
R2 CtHdaSvc; C:\WINDOWS\sysWow64\CtHdaSvc.exe [113152 2016-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd) 
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.) 
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-26] (Dropbox, Inc -> Dropbox, Inc.) 
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44064 2021-02-14] (Dropbox, Inc -> Dropbox, Inc.) 
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208760 2017-07-27] (Dell Inc -> Dell Inc.) 
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294584 2017-07-27] (Dell Inc -> Dell Inc.) 
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-07-27] (Dell Inc -> Dell Inc.) 
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-10-19] (NVIDIA Corporation -> NVIDIA) 
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [Datei ist nicht signiert] 
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Datei ist nicht signiert] 
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [397256 2018-11-19] (Canon Inc. -> ) 
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] 
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] 
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [41432 2017-11-30] (Dell Inc. -> Dell Inc.) 
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10967832 2021-02-05] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) 
S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-12-23] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) 
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) 
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)   
===================== Treiber (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)   
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert] 
R3 cthda; C:\WINDOWS\system32\drivers\cthda.sys [1064968 2016-12-13] (Creative Technology Ltd -> Creative Technology Ltd) 
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) 
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2021-02-26] (Malwarebytes Corporation -> Malwarebytes) 
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220616 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-02-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) 
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198248 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [142416 2021-02-26] (Malwarebytes Inc -> Malwarebytes) 
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) 
S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) 
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) 
S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) 
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2016-09-05] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated) 
S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.) 
S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) 
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.) 
R3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2018-03-16] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) 
S3 wacomhidfilter; C:\WINDOWS\System32\drivers\wacomhidfilter.sys [12968 2008-08-27] (Wacom Technology Corp. -> Wacom Technology) 
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) 
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation) 
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation) 
S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2021-02-10] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)   
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)     
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)   
2021-02-26 12:17 - 2021-02-26 12:17 - 000003770 _____ C:\Users\AtelierNiederhein\Desktop\AdwCleaner[C00].txt 
2021-02-26 12:16 - 2021-02-26 12:16 - 000198248 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 
2021-02-26 12:16 - 2021-02-26 12:16 - 000142416 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 
2021-02-26 12:16 - 2021-02-26 12:16 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 
2021-02-26 12:16 - 2021-02-26 12:16 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\IGDump 
2021-02-26 12:13 - 2021-02-26 12:15 - 000000000 ____D C:\AdwCleaner 
2021-02-26 12:10 - 2021-02-26 12:10 - 008463216 _____ (Malwarebytes) C:\Users\AtelierNiederhein\Downloads\adwcleaner_8.1.exe 
2021-02-26 12:08 - 2021-02-26 12:08 - 000020274 _____ C:\Users\AtelierNiederhein\Desktop\malwareScan.txt 
2021-02-26 11:58 - 2021-02-26 11:58 - 000000000 ____H C:\ProgramData\rebootpending.txt 
2021-02-26 11:58 - 2021-02-26 11:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avira 
2021-02-26 11:50 - 2021-02-26 11:50 - 000220616 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 
2021-02-26 11:50 - 2021-02-26 11:50 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 
2021-02-26 11:50 - 2021-02-26 11:50 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 
2021-02-26 11:49 - 2021-02-26 12:16 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 
2021-02-26 11:49 - 2021-02-26 11:49 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 
2021-02-26 11:49 - 2021-02-26 11:49 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 
2021-02-26 11:21 - 2021-02-26 11:21 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\mbam 
2021-02-26 11:20 - 2021-02-26 11:20 - 000000000 ____D C:\ProgramData\Malwarebytes 
2021-02-26 11:18 - 2021-02-26 11:18 - 000000000 ____D C:\Program Files\Malwarebytes 
2021-02-26 11:16 - 2021-02-26 11:16 - 002084016 _____ (Malwarebytes) C:\Users\AtelierNiederhein\Downloads\MBSetup.exe 
2021-02-26 08:53 - 2021-02-26 08:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 
2021-02-26 07:38 - 2021-02-26 12:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 
2021-02-25 16:27 - 2021-02-25 16:28 - 000083593 _____ C:\Users\AtelierNiederhein\Downloads\Addition.txt 
2021-02-25 16:25 - 2021-02-26 12:20 - 000033795 _____ C:\Users\AtelierNiederhein\Downloads\FRST.txt 
2021-02-25 16:25 - 2021-02-26 12:20 - 000000000 ____D C:\FRST 
2021-02-25 16:25 - 2021-02-25 16:25 - 002301440 _____ (Farbar) C:\Users\AtelierNiederhein\Downloads\FRST64.exe 
2021-02-25 16:08 - 2021-02-25 16:08 - 000000000 ____D C:\WINDOWS\Panther 
2021-02-24 18:02 - 2021-02-24 18:02 - 000022749 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_QTZQMX4WFQAB_1_Frau_Annette_Bohrloch.pdf 
2021-02-24 15:10 - 2021-02-24 15:11 - 001029393 _____ C:\Users\AtelierNiederhein\Downloads\MWS_Integrators_ListingCreation_UK._V272404261_.pdf 
2021-02-24 11:04 - 2021-02-24 11:04 - 005541016 _____ (Stanislav Polshyn & Trend Micro Inc.) C:\Users\AtelierNiederhein\Downloads\hijackthis.exe 
2021-02-24 09:33 - 2021-02-24 09:34 - 001471893 _____ C:\Users\AtelierNiederhein\Downloads\f111-Vollmacht.pdf 
2021-02-24 08:35 - 2021-02-25 15:50 - 000008046 _____ C:\WINDOWS\ntbtlog.txt 
2021-02-24 08:25 - 2021-02-24 08:25 - 000000000 ____D C:\NPE 
2021-02-24 08:24 - 2021-02-24 08:27 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\NPE 
2021-02-24 08:24 - 2021-02-24 08:24 - 000000000 ____D C:\ProgramData\Norton 
2021-02-24 08:23 - 2021-02-24 08:23 - 009645984 _____ (NortonLifeLock Inc.) C:\Users\AtelierNiederhein\Desktop\NPE.exe 
2021-02-23 16:50 - 2021-02-23 16:50 - 000059863 _____ C:\Users\AtelierNiederhein\Documents\Liste_Zoll_v2.pdf 
2021-02-22 16:53 - 2021-02-22 16:53 - 000022502 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_6VY63898CDB4_1_Herr_Thomas_Leonhardy.pdf 
2021-02-22 16:38 - 2021-02-22 16:38 - 000191744 _____ C:\Users\AtelierNiederhein\Desktop\genexport (2).CSV 
2021-02-20 14:04 - 2021-02-20 14:05 - 005228592 _____ C:\Users\AtelierNiederhein\Downloads\Deep_dive_on_Amazon_Neptune_DAT361.pdf 
2021-02-19 15:30 - 2021-02-19 15:30 - 000693574 _____ C:\Users\AtelierNiederhein\Downloads\warum-2012.pdf 
2021-02-19 09:31 - 2021-02-19 09:31 - 004310122 _____ C:\Users\AtelierNiederhein\Downloads\pkg_communitybuilder_2.5.0+build.2021.02.01.21.20.37.ae3d43f4e(1).zip 
2021-02-19 09:30 - 2021-02-19 09:30 - 004310122 _____ C:\Users\AtelierNiederhein\Downloads\pkg_communitybuilder_2.5.0+build.2021.02.01.21.20.37.ae3d43f4e.zip 
2021-02-18 10:32 - 2021-02-18 10:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 
2021-02-18 09:29 - 2021-02-18 09:29 - 000050434 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_M296EML5ZDZA_1_Frau_Petra_Rappo.pdf 
2021-02-18 09:29 - 2021-02-18 09:29 - 000006556 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210218M296EML5ZDZA-0012191914.pdf 
2021-02-16 17:13 - 2021-02-16 17:13 - 000024610 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_Y9P3XM464MRB_1_Frau_Sarah_Romaniw.pdf 
2021-02-16 17:13 - 2021-02-16 17:13 - 000024457 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_Y9P3XM464MRB_2_Frau_Marina_Mudrytska.pdf 
2021-02-15 12:26 - 2021-02-15 12:26 - 000818689 _____ C:\Users\AtelierNiederhein\Downloads\Justizkrimi_ROCO_Raiffeisen_Manager-Magazin_Maerz2018.pdf 
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 
2021-02-14 04:12 - 2021-02-14 04:12 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 
2021-02-14 04:12 - 2021-02-14 04:12 - 000044064 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 
2021-02-12 16:21 - 2021-02-12 16:21 - 007857864 _____ C:\Users\AtelierNiederhein\Downloads\X20001-136-CatalogueSennelierFR-DE-NL-2019-pagesinterieures-reduc.pdf 
2021-02-12 16:08 - 2021-02-12 16:08 - 000024364 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_1_Sandra_Krug.pdf 
2021-02-12 16:08 - 2021-02-12 16:08 - 000022479 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_2_Frau_Peggy_Stein.pdf 
2021-02-12 16:08 - 2021-02-12 16:08 - 000022198 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_C39FCNPD4G73_3_Frau_Nicole_Michaloudis.pdf 
2021-02-12 12:45 - 2021-02-12 16:10 - 000004691 _____ C:\Users\AtelierNiederhein\.ganttproject 
2021-02-12 12:44 - 2021-02-12 12:46 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\GanttProject 
2021-02-12 12:44 - 2021-02-12 12:44 - 000002056 _____ C:\ProgramData\Desktop\GanttProject.lnk 
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\Users\AtelierNiederhein\.ganttproject.d 
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GanttProject 
2021-02-12 12:44 - 2021-02-12 12:44 - 000000000 ____D C:\Program Files (x86)\GanttProject-3.0 
2021-02-12 12:41 - 2021-02-12 12:44 - 114651200 _____ C:\Users\AtelierNiederhein\Downloads\ganttproject-3.0.3000.exe 
2021-02-12 08:43 - 2021-02-12 08:43 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 
2021-02-12 08:43 - 2021-02-12 08:43 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 
2021-02-12 08:43 - 2021-02-12 08:43 - 001314112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 
2021-02-12 08:43 - 2021-02-12 08:43 - 000231232 _____ C:\WINDOWS\system32\containerdevicemanagement.dll 
2021-02-12 08:43 - 2021-02-12 08:43 - 000010892 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 
2021-02-08 15:03 - 2021-02-08 15:03 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2020.lnk 
2021-02-06 17:26 - 2021-02-06 17:26 - 000024381 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_4_Herr_Marc_Tenner.pdf 
2021-02-06 17:26 - 2021-02-06 17:26 - 000022525 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_3_Andreas_Wäldele.pdf 
2021-02-06 17:26 - 2021-02-06 17:26 - 000022499 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_LUKHCAQPXPEN_5_Kristina_Neumann.pdf 
2021-02-05 16:58 - 2021-02-05 16:58 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\Oracle 
2021-02-05 16:39 - 2021-02-05 16:39 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AusweisApp2.lnk 
2021-02-05 16:39 - 2021-02-05 16:39 - 000001134 _____ C:\ProgramData\Desktop\AusweisApp2.lnk 
2021-02-05 16:39 - 2021-02-05 16:39 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\Governikus GmbH & Co. KG 
2021-02-05 16:39 - 2021-02-05 16:39 - 000000000 ____D C:\Program Files (x86)\AusweisApp2 
2021-02-05 16:38 - 2021-02-05 16:38 - 022896640 _____ C:\Users\AtelierNiederhein\Downloads\AusweisApp2-1.22.0.msi 
2021-02-05 08:32 - 2021-02-05 08:32 - 000005689 _____ C:\Users\AtelierNiederhein\Documents\Snipping Tool Print Job.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000041458 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_3_Frau_petra_rappo.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000024538 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_2_Andreas_Wäldele.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000024529 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_1_Heiko_Herbst_.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000024289 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_6_Frau_Gudrun_Doege-Klein.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000022702 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_5_Herr_Matthias_Kindler.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000022531 _____ C:\Users\AtelierNiederhein\Downloads\DHL-Paketmarke_WNBT9UR88PC4_4_Frau_Brigitte_Andritzke-Walter.pdf 
2021-02-03 19:37 - 2021-02-03 19:37 - 000006899 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210203WNBT9UR88PC4-0011834233.pdf 
2021-02-03 19:22 - 2021-02-03 19:22 - 000006659 _____ C:\Users\AtelierNiederhein\Downloads\DOF-210203VFDKBKTSEB3M-0011833904.pdf 
2021-02-03 19:17 - 2021-02-03 19:17 - 000244723 _____ C:\Users\AtelierNiederhein\Downloads\2kg_coupons_20210114.pdf 
2021-02-03 13:45 - 2021-02-03 13:45 - 000001052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign 2021.lnk 
2021-02-02 17:38 - 2021-02-02 17:38 - 000976969 _____ C:\Users\AtelierNiederhein\Downloads\Archive-2021-02-02-17-38-03.zip 
2021-02-02 09:14 - 2021-02-02 09:38 - 000040076 _____ C:\Users\AtelierNiederhein\Downloads\oxarticles.csv 
2021-02-01 14:08 - 2021-02-01 14:08 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2021.lnk 
2021-02-01 13:19 - 2021-02-01 13:19 - 000115971 _____ C:\Users\AtelierNiederhein\Downloads\invoice_TC9927697177.pdf 
2021-02-01 12:35 - 2021-02-01 12:36 - 001756565 _____ C:\Users\AtelierNiederhein\Downloads\Kontoeroeffnung_20210201_600170.pdf 
2021-02-01 10:09 - 2021-02-01 09:29 - 000020020 _____ C:\Users\AtelierNiederhein\Documents\order_pastell-shop__Standard%20Pastels%20Order%20Spreadsheet-20210126.xls_0.ods 
2021-01-29 12:20 - 2021-02-16 12:35 - 000000000 ____D C:\Users\AtelierNiederhein\Downloads\archiv 
2021-01-27 15:01 - 2021-01-27 15:01 - 000000000 ____D C:\WINDOWS\SysWOW64\NV 
2021-01-27 15:01 - 2021-01-27 15:01 - 000000000 ____D C:\WINDOWS\system32\NV 
2021-01-27 14:59 - 2021-01-23 09:57 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 
2021-01-27 14:59 - 2021-01-23 09:57 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe 
2021-01-27 14:59 - 2021-01-23 09:57 - 001453720 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 
2021-01-27 14:59 - 2021-01-23 09:57 - 001435872 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 
2021-01-27 14:59 - 2021-01-23 09:57 - 001435872 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 
2021-01-27 14:59 - 2021-01-23 09:57 - 001094872 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 
2021-01-27 14:59 - 2021-01-23 09:57 - 001094872 _____ C:\WINDOWS\system32\vulkan-1.dll 
2021-01-27 14:59 - 2021-01-23 09:57 - 000948960 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 
2021-01-27 14:59 - 2021-01-23 09:57 - 000948960 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 
2021-01-27 14:59 - 2021-01-23 09:56 - 001193112 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 001512104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 001164968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 000680088 _____ C:\WINDOWS\system32\nvofapi64.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 000672936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 000558248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 
2021-01-27 14:59 - 2021-01-23 09:54 - 000547480 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 008262312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 007392920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 004611760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 002731184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 002103448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 001732264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446140.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 001589400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 001491608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446140.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 000813208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 
2021-01-27 14:59 - 2021-01-23 09:53 - 000657048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 
2021-01-27 14:59 - 2021-01-23 09:50 - 006070848 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll   
==================== Ein Monat (geänderte) ==================   
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)   
2021-02-26 12:18 - 2017-07-12 17:41 - 000000000 ____D C:\ProgramData\NVIDIA 
2021-02-26 12:18 - 2017-02-25 20:36 - 000000000 ____D C:\ProgramData\Mozilla 
2021-02-26 12:17 - 2020-11-02 14:30 - 000000000 ____D C:\Program Files (x86)\Steam 
2021-02-26 12:17 - 2017-02-25 17:41 - 000000000 ___RD C:\Users\AtelierNiederhein\Creative Cloud Files 
2021-02-26 12:17 - 2016-11-20 16:10 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\LocalLow\Mozilla 
2021-02-26 12:16 - 2020-09-25 18:05 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK 
2021-02-26 12:16 - 2020-09-25 16:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 
2021-02-26 12:16 - 2020-09-25 16:09 - 000008192 ___SH C:\DumpStack.log.tmp 
2021-02-26 12:16 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 
2021-02-26 12:16 - 2017-07-12 17:41 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 
2021-02-26 12:16 - 2015-12-20 08:54 - 000000000 ___RD C:\Users\AtelierNiederhein\OneDrive 
2021-02-26 12:16 - 2015-12-19 17:36 - 000000000 __SHD C:\Users\AtelierNiederhein\IntelGraphicsProfiles 
2021-02-26 12:15 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 
2021-02-26 12:09 - 2020-09-25 16:13 - 001590256 _____ C:\WINDOWS\system32\PerfStringBackup.INI 
2021-02-26 12:09 - 2019-12-07 15:50 - 000684966 _____ C:\WINDOWS\system32\perfh007.dat 
2021-02-26 12:09 - 2019-12-07 15:50 - 000141424 _____ C:\WINDOWS\system32\perfc007.dat 
2021-02-26 12:09 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 
2021-02-26 12:05 - 2020-09-25 16:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 
2021-02-26 12:05 - 2017-02-25 17:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 
2021-02-26 11:59 - 2017-02-25 16:39 - 000000000 ____D C:\ProgramData\Avira 
2021-02-26 11:59 - 2017-02-25 16:39 - 000000000 ____D C:\Program Files (x86)\Avira 
2021-02-26 11:58 - 2017-02-25 16:39 - 000000000 ____D C:\ProgramData\Package Cache 
2021-02-26 11:57 - 2020-06-15 06:41 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 
2021-02-26 11:57 - 2020-06-15 06:41 - 000002274 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk 
2021-02-26 11:57 - 2019-04-28 07:38 - 000002252 _____ C:\ProgramData\Desktop\Google Chrome.lnk 
2021-02-26 11:57 - 2017-02-25 20:40 - 000001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 
2021-02-26 11:49 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 
2021-02-26 09:17 - 2014-05-11 16:05 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\Steuerfälle 
2021-02-26 08:32 - 2019-04-28 07:38 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 
2021-02-26 07:37 - 2019-11-06 05:57 - 000000000 ___HD C:\adobeTemp 
2021-02-26 07:37 - 2017-02-25 17:40 - 000000000 ____D C:\Program Files\Common Files\Adobe 
2021-02-25 14:15 - 2017-09-29 06:49 - 000001456 _____ C:\Users\AtelierNiederhein\AppData\Local\Adobe Für Web speichern 13.0 Prefs 
2021-02-24 09:38 - 2020-08-21 13:07 - 000000000 ____D C:\Projekte 
2021-02-24 08:51 - 2017-04-25 04:57 - 000001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 
2021-02-24 08:51 - 2017-04-25 04:57 - 000000000 ____D C:\Program Files (x86)\TeamViewer 
2021-02-24 08:40 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 
2021-02-23 15:18 - 2017-02-25 16:21 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Adobe 
2021-02-23 15:18 - 2014-07-10 19:50 - 000000000 ____D C:\Users\AtelierNiederhein\Documents\Adobe 
2021-02-23 09:08 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 
2021-02-22 16:48 - 2020-06-17 09:17 - 000007862 _____ C:\Users\AtelierNiederhein\Desktop\oxarticles.csv 
2021-02-22 14:03 - 2020-08-21 10:35 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 
2021-02-22 09:16 - 2014-03-27 21:38 - 000000000 ___RD C:\Users\AtelierNiederhein\Dropbox 
2021-02-22 08:14 - 2017-03-02 05:48 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\FileZilla 
2021-02-20 13:51 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 
2021-02-18 14:13 - 2017-02-25 17:30 - 000000000 ____D C:\Program Files\Adobe 
2021-02-18 14:07 - 2017-03-07 17:01 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\CrashDumps 
2021-02-18 10:32 - 2017-02-26 08:22 - 000000000 ____D C:\Program Files (x86)\Dropbox 
2021-02-17 15:47 - 2020-07-18 13:18 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Code 
2021-02-17 09:58 - 2020-11-09 11:06 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\pyinstaller 
2021-02-17 09:50 - 2020-07-18 13:57 - 000000000 ____D C:\Users\AtelierNiederhein\.pylint.d 
2021-02-16 11:30 - 2014-04-03 17:47 - 000000000 ____D C:\Users\AtelierNiederhein\Desktop\tmp 
2021-02-15 16:51 - 2017-02-26 10:14 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk 
2021-02-15 16:51 - 2017-02-26 10:14 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 
2021-02-15 15:22 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 
2021-02-15 08:27 - 2020-09-25 16:18 - 000003392 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-962593549-1501595251-2753236537-1000 
2021-02-15 08:27 - 2020-09-25 16:10 - 000002455 _____ C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 
2021-02-12 16:39 - 2020-09-25 16:09 - 010187680 _____ C:\WINDOWS\system32\FNTCACHE.DAT 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Keywords 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr 
2021-02-12 16:38 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System 
2021-02-12 16:38 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing 
2021-02-12 16:10 - 2020-09-25 16:10 - 000000000 ____D C:\Users\AtelierNiederhein 
2021-02-12 12:20 - 2020-07-18 13:18 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code 
2021-02-12 08:38 - 2017-02-25 18:33 - 000000000 ____D C:\WINDOWS\system32\MRT 
2021-02-12 08:35 - 2017-02-25 18:33 - 130141752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 
2021-02-11 07:42 - 2020-09-25 16:18 - 000003700 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 
2021-02-11 07:42 - 2020-09-25 16:18 - 000003576 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 
2021-02-10 16:07 - 2018-12-16 11:38 - 000000600 _____ C:\Users\AtelierNiederhein\AppData\Local\PUTTY.RND 
2021-02-10 09:22 - 2020-07-23 12:41 - 000000000 ____D C:\Program Files (x86)\PUBGLite 
2021-02-10 08:59 - 2019-11-18 22:14 - 000074552 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys 
2021-02-09 15:39 - 2020-09-25 16:18 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 
2021-02-06 12:20 - 2020-09-25 16:18 - 000003630 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 
2021-02-06 12:20 - 2020-09-25 16:18 - 000003506 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 
2021-02-05 20:04 - 2020-02-20 08:56 - 000734016 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll 
2021-02-05 20:03 - 2020-08-21 10:35 - 000470848 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll 
2021-02-02 10:35 - 2021-01-26 11:56 - 000002311 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteuerSparErklärung 2021.lnk 
2021-02-02 10:35 - 2021-01-26 11:56 - 000002254 _____ C:\ProgramData\Desktop\SteuerSparErklärung 2021.lnk 
2021-02-02 10:35 - 2021-01-26 11:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteuerSparErklärung 2021 
2021-01-29 11:50 - 2017-02-26 08:22 - 000001258 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 
2021-01-29 11:50 - 2017-02-26 08:22 - 000001254 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 
2021-01-27 15:50 - 2017-06-30 09:28 - 000000000 ____D C:\Users\AtelierNiederhein\AppData\Local\NVIDIA   
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========   
2017-03-10 16:07 - 2018-10-21 11:41 - 000000033 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\AdobeWLCMCache.dat 
2017-05-13 05:47 - 2020-11-07 16:23 - 000010120 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\ContactSheetII.log 
2017-05-13 05:47 - 2020-11-07 16:23 - 000000709 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\Kontaktabzug II.xml 
2021-01-02 17:16 - 2021-01-02 17:16 - 000000028 _____ () C:\Users\AtelierNiederhein\AppData\Roaming\kulerdata.json 
2017-09-29 06:49 - 2021-02-25 14:15 - 000001456 _____ () C:\Users\AtelierNiederhein\AppData\Local\Adobe Für Web speichern 13.0 Prefs 
2018-09-29 02:32 - 2018-09-29 02:32 - 000000000 _____ () C:\Users\AtelierNiederhein\AppData\Local\oobelibMkey.log 
2018-12-16 11:38 - 2021-02-10 16:07 - 000000600 _____ () C:\Users\AtelierNiederhein\AppData\Local\PUTTY.RND 
2020-08-23 12:04 - 2020-08-23 12:04 - 000008317 _____ () C:\Users\AtelierNiederhein\AppData\Local\recently-used.xbel 
2018-08-16 16:14 - 2018-08-16 16:14 - 000007601 _____ () C:\Users\AtelierNiederhein\AppData\Local\Resmon.ResmonCfg   
==================== SigCheck ============================   
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)   
==================== Ende von FRST.txt ========================      |