Danke für die Rückmeldung !
Mache ich.
Bis dann
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11.06.2024
durchgeführt von (Administrator) auf DESKTOP-JIUD8FD (FUJITSU LIFEBOOK E751) (12-06-2024 14:57:36)
Gestartet von C:\Users\\Downloads\FRST64.exe
Geladene Profile:
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.4529 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Users\\Downloads\adwcleaner.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.AlwaysOnTop.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.Awake.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.ColorPickerUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.CropAndLock.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.FancyZones.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseJumpUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.PowerLauncher.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.PowerOCR.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\WinUI3Apps\PowerToys.Peek.UI.exe
(C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseWithoutBordersHelper.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MiniTool Software Limited -> ) C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <16>
(Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World) C:\Program Files\CrystalDiskInfo\DiskInfo64.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(services.exe ->) (TomTom) [Datei ist nicht signiert] C:\Program Files\TomTom HOME\TTHOMEService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16680192 2016-06-30] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
HKLM-x32\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKLM-x32\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM-x32\...\Run: [FjBatteryLimitter] => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterRun.exe [364448 2021-01-27] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [MicrosoftEdgeAutoLaunch_761B5E3B796A47561624C9533E0596CC] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4136912 2024-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [org.whispersystems.signal-desktop] => C:\Users\\AppData\Local\Programs\signal-desktop\Signal.exe [163723200 2023-12-07] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [Opera Stable] => C:\Users\\AppData\Local\Programs\Opera\opera.exe [1610144 2024-05-31] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\\AppData\Local\Microsoft\Teams\Update.exe [2593752 2024-04-15] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [TomTomHOME.exe] => C:\Program Files\TomTom HOME\TTHOMERunner.exe [902656 2024-02-01] (TomTom) [Datei ist nicht signiert]
HKLM\...\Windows x64\Print Processors\ssj1MPC: C:\Windows\System32\spool\prtprocs\x64\ssj1mpc.dll [41984 2014-09-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\ssj1M Langmon: C:\WINDOWS\system32\ssj1mlm.dll [34304 2014-09-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\125.0.6422.113\Installer\chrmstp.exe [2024-05-31] (Google LLC -> Google LLC)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {562CEC1A-4B75-45AB-AEA6-9FEF5D35ABDB} - System32\Tasks\CrystalDiskInfo => C:\Program Files\CrystalDiskInfo\DiskInfo64.exe [2826784 2023-01-21] (Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World)
Task: {6D90EE18-BE6C-4EC8-ABF9-6A4B36E66A33} - System32\Tasks\Fujitsu\FjBatteryLimitter\Limit => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterBatu.exe [154528 2020-12-24] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {9CE998AF-C86D-4B87-B37D-5E7DC9331F21} - System32\Tasks\Fujitsu\FjBatteryLimitter\Notify => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterNotify.exe [184736 2020-12-22] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {A2FC685D-FE2C-4E0A-9388-47407CA99DF5} - System32\Tasks\Fujitsu\FjBatteryLimitter\Unlimit => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterBatu.exe [154528 2020-12-24] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {FC874D58-B481-43C6-8BD3-5F3A10C048C7} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem127.0.6490.0{5EB9DC0D-5EFB-4D9F-8E1E-5258D1DE9CC9} => C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
Task: {2D22DF16-23BD-4F35-801B-70C5227541C6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\System32\MRT.exe [199048176 2024-06-12] (Microsoft Windows -> Microsoft Corporation) -> C:\WINDOWS\system32\/EHB /HeartbeatFailure "SubmitHeartbeatReportData" /HeartbeatError "0x80072ee7"
Task: {CD4F6C8B-9511-4707-98F8-7F7B6BCF7897} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE04CD40-7B3E-4904-900D-262FD33F26BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E6A2C6D5-E66A-453D-95FE-FACE7F7FB304} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CCFC2C2D-0323-4717-B889-D598BE384EB6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C4A79E98-CD29-4557-BED6-C45065E074BC} - System32\Tasks\MiniToolPartitionWizard => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
Task: {60FBB232-B751-4684-B596-6007D9124FA8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {D38CD21E-FFAB-41BE-AB3A-72B5695CF0ED} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-4142085759-758095809-663797801-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {B4778B5F-4ADE-4BB7-A908-12B750D7B473} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33696 2024-06-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {FBEAD6B8-04CF-4381-AA9A-610E31B87C7F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 9274DBA75F807560 => C:\Users\\AppData\Local\Mozilla Firefox\default-browser-agent.exe [35232 2024-01-08] (Mozilla Corporation -> Mozilla Foundation)
Task: {AC7F0668-B350-423B-B144-3495BD3B31E4} - System32\Tasks\Opera scheduled Autoupdate 1677170401 => C:\Users\\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5728672 2024-05-28] (Opera Norway AS -> Opera Software)
Task: {9D7535CC-443E-42D9-B0D3-B70314F2834B} - System32\Tasks\PowerToys\Autorun for => C:\Program Files\PowerToys\PowerToys.exe [1191976 2024-04-03] (Microsoft Corporation -> Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{2b8f04b4-4d19-4b0d-9c56-28c0ef27cde5}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{2b8f04b4-4d19-4b0d-9c56-28c0ef27cde5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{3031a7d0-5eab-4720-8228-12f02fa3cf90}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{a0a194ea-d745-416b-9b60-c2fa6d4eeb80}: [DhcpNameServer] 192.168.182.150
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E666475726560274163747A7577616E676: [DhcpNameServer] 192.168.179.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D207C65737: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D207C65737: [DhcpDomain] jwlogin
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D22374625374: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D22374625374: [DhcpDomain] JOOWIN
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\64259445A51224F6870273539303025444: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\64259445A51224F6870273539303025444: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\65F6461666F6E6560284F6473707F647: [DhcpNameServer] 10.79.179.130 10.79.181.130
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\A4F4F47594E4D2142464447344: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\A4F4F47594E4D2142464447344: [DhcpDomain] jwlogin
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default [2024-06-12]
Edge Extension: (Google Docs Offline) - C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-21]
Edge Extension: (Edge relevant text changes) - C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-31]
FireFox:
========
FF DefaultProfile: kcmq5dj6.default
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\kyuvi6wc.default-release-1 [2024-01-21]
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\kcmq5dj6.default [2022-11-30]
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release [2024-06-12]
FF Notifications: Mozilla\Firefox\Profiles\4cdmdtmw.default-release -> hxxps://www.handyhase.de; hxxps://cpkldfu071bc739g04bg.baseauthenticity.co.in; hxxps://euuzetoh7vt7bc.baseauthenticity.co.in; hxxps://ws6eytqr72gjbx.baseauthenticity.co.in
FF Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\@setupvpncom.xpi [2024-03-31]
FF Extension: (Microsoft Bing-Suchmaschine) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\bingwallpaperdse@microsoft.com.xpi [2023-02-22] [UpdateUrl:hxxps://bingwallpaper.microsoft.com/FirefoxExtn/updateextension.json]
FF Extension: (Ghostery Tracker- & Werbeblocker | AdBlocker) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\firefox@ghostery.com.xpi [2024-05-31]
FF Extension: (Innovator – Balanced) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\innovator-balanced-colorway@mozilla.org.xpi [2023-03-19]
FF Extension: (Mate Translate – Übersetzer, Wörterbuch) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\jid1-TMndP6cdKgxLcQ@jetpack.xpi [2023-02-28]
FF Extension: (Firefox Relay) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\private-relay@firefox.com.xpi [2023-12-08]
FF Extension: (Show me the password!) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\showmethepassword@alejandrobrizuela.com.ar.xpi [2023-12-18]
FF Extension: (Swisscows) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\swisscows@swisscows.ch.xpi [2024-02-08]
FF Extension: (uBlock Origin) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\uBlock0@raymondhill.net.xpi [2024-05-24]
FF Extension: (Chameleon) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{3579f63b-d8ee-424f-bbb6-6d0ce3285e6a}.xpi [2024-05-31]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2023-02-28]
FF Extension: (Disable WebRTC) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{64f73088-5156-43ae-94db-5a4701089ba3}.xpi [2024-04-26]
FF Extension: (Youtube Downloader) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{a7847979-429e-4a40-8651-1a50fd8382ce}.xpi [2024-05-15]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2024-05-02]
FF Extension: (Unpaywall) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{f209234a-76f0-4735-9920-eb62507a54cd}.xpi [2023-06-03]
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\\AppData\Local\Google\Chrome\User Data\Default [2023-08-22]
CHR Extension: (Google Docs Offline) - C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-07-25]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-07-25]
Opera:
=======
OPR DefaultProfile: Default
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 Fuj02e3DriverUtilityService; C:\WINDOWS\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1c41b5ae1124caab\fuj02e3-utility.exe [146536 2018-05-16] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
S4 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [72848 2016-09-20] (FUJITSU LIMITED -> FUJITSU LIMITED)
S2 GoogleUpdaterInternalService127.0.6490.0; C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
S2 GoogleUpdaterService127.0.6490.0; C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8895072 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [3073888 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [732992 2023-04-12] (MiniTool Software Limited -> )
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [225088 2023-04-12] (MiniTool Software Limited -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522200 2024-04-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TTHOMEService; C:\Program Files\TomTom HOME\TTHOMEService.exe [437248 2024-02-01] (TomTom) [Datei ist nicht signiert]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 FUJ02B1; C:\WINDOWS\system32\DRIVERS\FUJ02B1.sys [68536 2018-09-06] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 fuj02e3; C:\WINDOWS\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1c41b5ae1124caab\fuj02e3.sys [42592 2018-05-16] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
R3 guardian2; C:\WINDOWS\System32\Drivers\oz776x64.sys [108456 2019-06-04] (BayHub Technology Inc. -> O2Micro)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [221136 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-06-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [201280 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [78400 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [188784 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
R3 SNP2UVCW10; C:\WINDOWS\system32\DRIVERS\snp2uvcW10.sys [1819240 2016-08-02] (Sonix Technology CO., LTD -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2024-06-12 14:57 - 2024-06-12 14:58 - 000025424 _____ C:\Users\
\Downloads\FRST.txt
2024-06-12 14:57 - 2024-06-12 14:58 - 000000000 ____D C:\FRST
2024-06-12 14:56 - 2024-06-12 14:56 - 002395136 _____ (Farbar) C:\Users\\Downloads\FRST64.exe
2024-06-12 14:48 - 2024-06-12 14:49 - 000000000 ____D C:\AdwCleaner
2024-06-12 14:48 - 2024-06-12 14:48 - 008790880 _____ (Malwarebytes) C:\Users\\Downloads\adwcleaner.exe
2024-06-12 14:24 - 2024-06-12 14:24 - 000001428 _____ C:\Users\\Desktop\Malwarebytes Scan-Bericht 2024-06-12 121807.txt
2024-06-12 14:17 - 2024-06-12 14:17 - 000188784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2024-06-12 14:14 - 2024-06-12 14:57 - 000000000 ____D C:\Users\\AppData\Local\Malwarebytes
2024-06-12 14:13 - 2024-06-12 14:17 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2024-06-12 14:13 - 2024-06-12 14:17 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2024-06-12 14:12 - 2024-06-12 14:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2024-06-12 14:12 - 2024-06-12 14:15 - 000000000 ____D C:\Program Files\Malwarebytes
2024-06-12 14:09 - 2024-06-12 14:09 - 002591712 _____ (Malwarebytes) C:\Users\\Downloads\MBSetup.exe
2024-06-12 13:36 - 2024-06-12 13:36 - 000000000 ___HD C:\$WinREAgent
2024-06-12 13:20 - 2024-06-12 13:59 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2024-06-12 13:17 - 2024-06-12 13:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-06-04 16:56 - 2024-06-04 16:56 - 000000000 ___HD C:\OneDriveTemp
2024-05-24 20:22 - 2024-05-24 20:22 - 000000000 ____D C:\Program Files\dotnet
2024-05-24 20:18 - 2024-05-24 20:18 - 000178237 _____ (OFGB) C:\Users\\Downloads\OFGB.exe
2024-05-23 19:10 - 2024-05-23 19:11 - 362471424 _____ C:\Users\\Downloads\LibreOffice_7.6.7_Win_x86-64(1).msi
2024-05-23 14:12 - 2024-05-23 14:12 - 000000000 ____D C:\Users\Public\Documents\sun
2024-05-17 19:39 - 2024-05-17 19:39 - 006970144 _____ (VS Revo Group ) C:\Users\\Downloads\revosetup.exe
2024-05-16 08:41 - 2024-05-16 08:41 - 000001153 _____ C:\Users\Public\Desktop\LibreOffice 7.6.lnk
2024-05-16 08:41 - 2024-05-16 08:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.6
2024-05-16 08:33 - 2024-05-16 08:34 - 362471424 _____ C:\Users\\Downloads\LibreOffice_7.6.7_Win_x86-64.msi
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2024-06-12 14:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-06-12 14:17 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-06-12 14:13 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-06-12 14:09 - 2022-11-30 20:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-06-12 14:06 - 2023-10-20 13:40 - 000000000 ___HD C:\Users\\Downloads\.opera
2024-06-12 14:06 - 2023-10-20 13:40 - 000000000 ___HD C:\Users\\.opera
2024-06-12 14:04 - 2023-04-24 12:59 - 001632020 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-06-12 14:04 - 2023-04-24 12:38 - 000000000 ____D C:\Users\
2024-06-12 14:04 - 2019-12-07 16:51 - 000707136 _____ C:\WINDOWS\system32\perfh007.dat
2024-06-12 14:04 - 2019-12-07 16:51 - 000142394 _____ C:\WINDOWS\system32\perfc007.dat
2024-06-12 14:01 - 2024-04-11 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\PowerToys
2024-06-12 14:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-06-12 14:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-06-12 14:00 - 2023-04-24 12:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-06-12 14:00 - 2023-04-24 12:49 - 000430088 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-06-12 13:59 - 2022-11-30 20:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-06-12 13:59 - 2022-11-30 18:54 - 000008192 ___SH C:\DumpStack.log.tmp
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-06-12 13:59 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-06-12 13:52 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-06-12 13:46 - 2022-11-30 18:52 - 000416976 __RSH C:\bootmgr
2024-06-12 13:45 - 2023-04-24 12:54 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-06-12 13:37 - 2023-02-09 18:27 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-06-12 13:32 - 2023-01-16 18:47 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-06-12 13:32 - 2022-11-30 18:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-06-12 13:24 - 2023-04-24 12:54 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-06-12 13:24 - 2023-04-24 12:54 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-06-12 13:24 - 2023-04-24 12:54 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4142085759-758095809-663797801-1001
2024-06-12 13:24 - 2023-04-24 12:54 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4142085759-758095809-663797801-1001
2024-06-12 13:24 - 2023-04-24 12:38 - 000002398 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-06-12 13:23 - 2022-11-30 18:47 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-06-12 13:19 - 2023-04-24 12:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-06-12 13:19 - 2022-11-30 20:38 - 000001276 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-06-12 13:19 - 2022-11-30 20:38 - 000000907 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-06-12 13:19 - 2022-11-30 18:47 - 199048176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-06-12 13:17 - 2023-10-04 15:58 - 000000000 ____D C:\Program Files\RUXIM
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ___SD C:\WINDOWS\system32\AppV
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Portable Devices
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2024-06-12 13:12 - 2019-12-07 16:52 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2024-06-12 13:12 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\de
2024-06-12 13:12 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\de
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 __RSD C:\WINDOWS\Media
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\icsxml
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\downlevel
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Com
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\IME
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2024-06-12 13:12 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2024-06-12 13:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2024-06-12 13:08 - 2023-10-20 20:20 - 000000000 ____D C:\Users\\AppData\Roaming\vlc
2024-06-12 13:08 - 2023-03-19 20:39 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2024-06-12 13:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Containers
2024-06-12 13:05 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2024-06-12 12:57 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\registration
2024-06-12 12:55 - 2023-04-24 12:35 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-06-12 12:39 - 2022-11-30 19:20 - 000000000 ___RD C:\Users\\OneDrive
2024-06-12 12:27 - 2023-04-24 12:49 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-06-11 23:33 - 2023-12-21 14:23 - 000000000 ____D C:\Users\\.mediathek3
2024-06-10 17:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-06-06 19:43 - 2024-01-29 10:47 - 000016431 _____ C:\Users\\Desktop\MaWa V L aktuell.odt
2024-06-05 21:39 - 2022-11-30 18:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-06-02 15:16 - 2023-02-23 18:13 - 000000000 ____D C:\Users\\AppData\Local\ElevatedDiagnostics
2024-05-31 22:02 - 2023-04-24 12:54 - 000004296 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1677170401
2024-05-31 22:02 - 2023-02-23 18:40 - 000001389 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk
2024-05-31 21:58 - 2023-07-25 14:55 - 000002239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-05-31 21:58 - 2023-07-25 14:55 - 000002198 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-05-26 00:01 - 2023-03-03 18:41 - 000001904 _____ C:\Users\\Desktop\Reset Windows Update Tool.lnk
2024-05-24 20:22 - 2023-03-12 19:00 - 000000000 ____D C:\ProgramData\Package Cache
2024-05-16 08:40 - 2023-12-12 11:50 - 000000000 ____D C:\Program Files\LibreOffice
2024-05-15 20:22 - 2022-11-30 19:16 - 000000000 ____D C:\ProgramData\Packages
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== --- --- ---
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11.06.2024
durchgeführt von (Administrator) auf DESKTOP-JIUD8FD (FUJITSU LIFEBOOK E751) (12-06-2024 14:57:36)
Gestartet von C:\Users\\Downloads\FRST64.exe
Geladene Profile:
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.4529 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Users\\Downloads\adwcleaner.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.AlwaysOnTop.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.Awake.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.ColorPickerUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.CropAndLock.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.FancyZones.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseJumpUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.PowerLauncher.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.PowerOCR.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\WinUI3Apps\PowerToys.Peek.UI.exe
(C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.MouseWithoutBordersHelper.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <3>
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MiniTool Software Limited -> ) C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <16>
(Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World) C:\Program Files\CrystalDiskInfo\DiskInfo64.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(services.exe ->) (TomTom) [Datei ist nicht signiert] C:\Program Files\TomTom HOME\TTHOMEService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16680192 2016-06-30] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
HKLM-x32\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKLM-x32\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM-x32\...\Run: [FjBatteryLimitter] => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterRun.exe [364448 2021-01-27] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [MicrosoftEdgeAutoLaunch_761B5E3B796A47561624C9533E0596CC] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4136912 2024-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [org.whispersystems.signal-desktop] => C:\Users\\AppData\Local\Programs\signal-desktop\Signal.exe [163723200 2023-12-07] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [Opera Stable] => C:\Users\\AppData\Local\Programs\Opera\opera.exe [1610144 2024-05-31] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\\AppData\Local\Microsoft\Teams\Update.exe [2593752 2024-04-15] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\...\Run: [TomTomHOME.exe] => C:\Program Files\TomTom HOME\TTHOMERunner.exe [902656 2024-02-01] (TomTom) [Datei ist nicht signiert]
HKLM\...\Windows x64\Print Processors\ssj1MPC: C:\Windows\System32\spool\prtprocs\x64\ssj1mpc.dll [41984 2014-09-24] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\...\Print\Monitors\ssj1M Langmon: C:\WINDOWS\system32\ssj1mlm.dll [34304 2014-09-24] (Microsoft Windows Hardware Compatibility Publisher -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\125.0.6422.113\Installer\chrmstp.exe [2024-05-31] (Google LLC -> Google LLC)
HKU\S-1-5-21-4142085759-758095809-663797801-1001\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {562CEC1A-4B75-45AB-AEA6-9FEF5D35ABDB} - System32\Tasks\CrystalDiskInfo => C:\Program Files\CrystalDiskInfo\DiskInfo64.exe [2826784 2023-01-21] (Open Source Developer, Noriyuki Miyazaki -> Crystal Dew World)
Task: {6D90EE18-BE6C-4EC8-ABF9-6A4B36E66A33} - System32\Tasks\Fujitsu\FjBatteryLimitter\Limit => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterBatu.exe [154528 2020-12-24] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {9CE998AF-C86D-4B87-B37D-5E7DC9331F21} - System32\Tasks\Fujitsu\FjBatteryLimitter\Notify => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterNotify.exe [184736 2020-12-22] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {A2FC685D-FE2C-4E0A-9388-47407CA99DF5} - System32\Tasks\Fujitsu\FjBatteryLimitter\Unlimit => C:\Program Files (x86)\Fujitsu\FjBatteryLimitter\FjBatteryLimitterBatu.exe [154528 2020-12-24] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
Task: {FC874D58-B481-43C6-8BD3-5F3A10C048C7} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem127.0.6490.0{5EB9DC0D-5EFB-4D9F-8E1E-5258D1DE9CC9} => C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
Task: {2D22DF16-23BD-4F35-801B-70C5227541C6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\System32\MRT.exe [199048176 2024-06-12] (Microsoft Windows -> Microsoft Corporation) -> C:\WINDOWS\system32\/EHB /HeartbeatFailure "SubmitHeartbeatReportData" /HeartbeatError "0x80072ee7"
Task: {CD4F6C8B-9511-4707-98F8-7F7B6BCF7897} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE04CD40-7B3E-4904-900D-262FD33F26BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E6A2C6D5-E66A-453D-95FE-FACE7F7FB304} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CCFC2C2D-0323-4717-B889-D598BE384EB6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpCmdRun.exe [1678960 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C4A79E98-CD29-4557-BED6-C45065E074BC} - System32\Tasks\MiniToolPartitionWizard => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
Task: {60FBB232-B751-4684-B596-6007D9124FA8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {D38CD21E-FFAB-41BE-AB3A-72B5695CF0ED} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-4142085759-758095809-663797801-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675744 2024-06-12] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (Der Dateneintrag hat 6 weitere Zeichen).
Task: {B4778B5F-4ADE-4BB7-A908-12B750D7B473} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33696 2024-06-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {FBEAD6B8-04CF-4381-AA9A-610E31B87C7F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 9274DBA75F807560 => C:\Users\\AppData\Local\Mozilla Firefox\default-browser-agent.exe [35232 2024-01-08] (Mozilla Corporation -> Mozilla Foundation)
Task: {AC7F0668-B350-423B-B144-3495BD3B31E4} - System32\Tasks\Opera scheduled Autoupdate 1677170401 => C:\Users\\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5728672 2024-05-28] (Opera Norway AS -> Opera Software)
Task: {9D7535CC-443E-42D9-B0D3-B70314F2834B} - System32\Tasks\PowerToys\Autorun for => C:\Program Files\PowerToys\PowerToys.exe [1191976 2024-04-03] (Microsoft Corporation -> Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{2b8f04b4-4d19-4b0d-9c56-28c0ef27cde5}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{2b8f04b4-4d19-4b0d-9c56-28c0ef27cde5}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{3031a7d0-5eab-4720-8228-12f02fa3cf90}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{a0a194ea-d745-416b-9b60-c2fa6d4eeb80}: [DhcpNameServer] 192.168.182.150
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E666475726560274163747A7577616E676: [DhcpNameServer] 192.168.179.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D207C65737: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D207C65737: [DhcpDomain] jwlogin
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D22374625374: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\3556E66647572656D22374625374: [DhcpDomain] JOOWIN
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\64259445A51224F6870273539303025444: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\64259445A51224F6870273539303025444: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\65F6461666F6E6560284F6473707F647: [DhcpNameServer] 10.79.179.130 10.79.181.130
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\A4F4F47594E4D2142464447344: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{aa13d0d3-d258-448e-b3f4-f5b92ad18b21}\A4F4F47594E4D2142464447344: [DhcpDomain] jwlogin
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default [2024-06-12]
Edge Extension: (Google Docs Offline) - C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-21]
Edge Extension: (Edge relevant text changes) - C:\Users\\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-31]
FireFox:
========
FF DefaultProfile: kcmq5dj6.default
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\kyuvi6wc.default-release-1 [2024-01-21]
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\kcmq5dj6.default [2022-11-30]
FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release [2024-06-12]
FF Notifications: Mozilla\Firefox\Profiles\4cdmdtmw.default-release -> hxxps://www.handyhase.de; hxxps://cpkldfu071bc739g04bg.baseauthenticity.co.in; hxxps://euuzetoh7vt7bc.baseauthenticity.co.in; hxxps://ws6eytqr72gjbx.baseauthenticity.co.in
FF Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\@setupvpncom.xpi [2024-03-31]
FF Extension: (Microsoft Bing-Suchmaschine) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\bingwallpaperdse@microsoft.com.xpi [2023-02-22] [UpdateUrl:hxxps://bingwallpaper.microsoft.com/FirefoxExtn/updateextension.json]
FF Extension: (Ghostery Tracker- & Werbeblocker | AdBlocker) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\firefox@ghostery.com.xpi [2024-05-31]
FF Extension: (Innovator – Balanced) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\innovator-balanced-colorway@mozilla.org.xpi [2023-03-19]
FF Extension: (Mate Translate – Übersetzer, Wörterbuch) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\jid1-TMndP6cdKgxLcQ@jetpack.xpi [2023-02-28]
FF Extension: (Firefox Relay) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\private-relay@firefox.com.xpi [2023-12-08]
FF Extension: (Show me the password!) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\showmethepassword@alejandrobrizuela.com.ar.xpi [2023-12-18]
FF Extension: (Swisscows) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\swisscows@swisscows.ch.xpi [2024-02-08]
FF Extension: (uBlock Origin) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\uBlock0@raymondhill.net.xpi [2024-05-24]
FF Extension: (Chameleon) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{3579f63b-d8ee-424f-bbb6-6d0ce3285e6a}.xpi [2024-05-31]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2023-02-28]
FF Extension: (Disable WebRTC) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{64f73088-5156-43ae-94db-5a4701089ba3}.xpi [2024-04-26]
FF Extension: (Youtube Downloader) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{a7847979-429e-4a40-8651-1a50fd8382ce}.xpi [2024-05-15]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2024-05-02]
FF Extension: (Unpaywall) - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\4cdmdtmw.default-release\Extensions\{f209234a-76f0-4735-9920-eb62507a54cd}.xpi [2023-06-03]
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\\AppData\Local\Google\Chrome\User Data\Default [2023-08-22]
CHR Extension: (Google Docs Offline) - C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-07-25]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-07-25]
Opera:
=======
OPR DefaultProfile: Default
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 Fuj02e3DriverUtilityService; C:\WINDOWS\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1c41b5ae1124caab\fuj02e3-utility.exe [146536 2018-05-16] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
S4 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [72848 2016-09-20] (FUJITSU LIMITED -> FUJITSU LIMITED)
S2 GoogleUpdaterInternalService127.0.6490.0; C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
S2 GoogleUpdaterService127.0.6490.0; C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe [4785440 2024-05-20] (Google LLC -> Google LLC)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8895072 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [3073888 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MpDefenderCoreService.exe [1505416 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [732992 2023-04-12] (MiniTool Software Limited -> )
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [225088 2023-04-12] (MiniTool Software Limited -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522200 2024-04-24] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TTHOMEService; C:\Program Files\TomTom HOME\TTHOMEService.exe [437248 2024-02-01] (TomTom) [Datei ist nicht signiert]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe [3236728 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe [133704 2024-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 FUJ02B1; C:\WINDOWS\system32\DRIVERS\FUJ02B1.sys [68536 2018-09-06] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 fuj02e3; C:\WINDOWS\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1c41b5ae1124caab\fuj02e3.sys [42592 2018-05-16] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
R3 guardian2; C:\WINDOWS\System32\Drivers\oz776x64.sys [108456 2019-06-04] (BayHub Technology Inc. -> O2Micro)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [221136 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-06-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [201280 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [78400 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-06-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [188784 2024-06-12] (Malwarebytes Inc. -> Malwarebytes)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
R3 SNP2UVCW10; C:\WINDOWS\system32\DRIVERS\snp2uvcW10.sys [1819240 2016-08-02] (Sonix Technology CO., LTD -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2024-06-12 14:57 - 2024-06-12 14:58 - 000025424 _____ C:\Users\
\Downloads\FRST.txt
2024-06-12 14:57 - 2024-06-12 14:58 - 000000000 ____D C:\FRST
2024-06-12 14:56 - 2024-06-12 14:56 - 002395136 _____ (Farbar) C:\Users\\Downloads\FRST64.exe
2024-06-12 14:48 - 2024-06-12 14:49 - 000000000 ____D C:\AdwCleaner
2024-06-12 14:48 - 2024-06-12 14:48 - 008790880 _____ (Malwarebytes) C:\Users\\Downloads\adwcleaner.exe
2024-06-12 14:24 - 2024-06-12 14:24 - 000001428 _____ C:\Users\\Desktop\Malwarebytes Scan-Bericht 2024-06-12 121807.txt
2024-06-12 14:17 - 2024-06-12 14:17 - 000188784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2024-06-12 14:14 - 2024-06-12 14:57 - 000000000 ____D C:\Users\\AppData\Local\Malwarebytes
2024-06-12 14:13 - 2024-06-12 14:17 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2024-06-12 14:13 - 2024-06-12 14:17 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2024-06-12 14:12 - 2024-06-12 14:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2024-06-12 14:12 - 2024-06-12 14:15 - 000000000 ____D C:\Program Files\Malwarebytes
2024-06-12 14:09 - 2024-06-12 14:09 - 002591712 _____ (Malwarebytes) C:\Users\\Downloads\MBSetup.exe
2024-06-12 13:36 - 2024-06-12 13:36 - 000000000 ___HD C:\$WinREAgent
2024-06-12 13:20 - 2024-06-12 13:59 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2024-06-12 13:17 - 2024-06-12 13:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-06-04 16:56 - 2024-06-04 16:56 - 000000000 ___HD C:\OneDriveTemp
2024-05-24 20:22 - 2024-05-24 20:22 - 000000000 ____D C:\Program Files\dotnet
2024-05-24 20:18 - 2024-05-24 20:18 - 000178237 _____ (OFGB) C:\Users\\Downloads\OFGB.exe
2024-05-23 19:10 - 2024-05-23 19:11 - 362471424 _____ C:\Users\\Downloads\LibreOffice_7.6.7_Win_x86-64(1).msi
2024-05-23 14:12 - 2024-05-23 14:12 - 000000000 ____D C:\Users\Public\Documents\sun
2024-05-17 19:39 - 2024-05-17 19:39 - 006970144 _____ (VS Revo Group ) C:\Users\\Downloads\revosetup.exe
2024-05-16 08:41 - 2024-05-16 08:41 - 000001153 _____ C:\Users\Public\Desktop\LibreOffice 7.6.lnk
2024-05-16 08:41 - 2024-05-16 08:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.6
2024-05-16 08:33 - 2024-05-16 08:34 - 362471424 _____ C:\Users\\Downloads\LibreOffice_7.6.7_Win_x86-64.msi
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2024-06-12 14:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-06-12 14:17 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2024-06-12 14:13 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-06-12 14:09 - 2022-11-30 20:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-06-12 14:06 - 2023-10-20 13:40 - 000000000 ___HD C:\Users\\Downloads\.opera
2024-06-12 14:06 - 2023-10-20 13:40 - 000000000 ___HD C:\Users\\.opera
2024-06-12 14:04 - 2023-04-24 12:59 - 001632020 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-06-12 14:04 - 2023-04-24 12:38 - 000000000 ____D C:\Users\
2024-06-12 14:04 - 2019-12-07 16:51 - 000707136 _____ C:\WINDOWS\system32\perfh007.dat
2024-06-12 14:04 - 2019-12-07 16:51 - 000142394 _____ C:\WINDOWS\system32\perfc007.dat
2024-06-12 14:01 - 2024-04-11 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\PowerToys
2024-06-12 14:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-06-12 14:01 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-06-12 14:00 - 2023-04-24 12:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-06-12 14:00 - 2023-04-24 12:49 - 000430088 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-06-12 13:59 - 2022-11-30 20:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-06-12 13:59 - 2022-11-30 18:54 - 000008192 ___SH C:\DumpStack.log.tmp
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-06-12 13:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-06-12 13:59 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-06-12 13:52 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-06-12 13:46 - 2022-11-30 18:52 - 000416976 __RSH C:\bootmgr
2024-06-12 13:45 - 2023-04-24 12:54 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-06-12 13:37 - 2023-02-09 18:27 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-06-12 13:32 - 2023-01-16 18:47 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-06-12 13:32 - 2022-11-30 18:58 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-06-12 13:24 - 2023-04-24 12:54 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-06-12 13:24 - 2023-04-24 12:54 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-06-12 13:24 - 2023-04-24 12:54 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4142085759-758095809-663797801-1001
2024-06-12 13:24 - 2023-04-24 12:54 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4142085759-758095809-663797801-1001
2024-06-12 13:24 - 2023-04-24 12:38 - 000002398 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-06-12 13:23 - 2022-11-30 18:47 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-06-12 13:19 - 2023-04-24 12:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-06-12 13:19 - 2022-11-30 20:38 - 000001276 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-06-12 13:19 - 2022-11-30 20:38 - 000000907 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-06-12 13:19 - 2022-11-30 18:47 - 199048176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-06-12 13:17 - 2023-10-04 15:58 - 000000000 ____D C:\Program Files\RUXIM
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ___SD C:\WINDOWS\system32\AppV
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Portable Devices
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-06-12 13:12 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2024-06-12 13:12 - 2019-12-07 16:52 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2024-06-12 13:12 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\de
2024-06-12 13:12 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\de
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 __RSD C:\WINDOWS\Media
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\icsxml
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\downlevel
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Com
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\IME
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2024-06-12 13:12 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2024-06-12 13:12 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2024-06-12 13:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2024-06-12 13:08 - 2023-10-20 20:20 - 000000000 ____D C:\Users\\AppData\Roaming\vlc
2024-06-12 13:08 - 2023-03-19 20:39 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2024-06-12 13:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Containers
2024-06-12 13:05 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2024-06-12 12:57 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\registration
2024-06-12 12:55 - 2023-04-24 12:35 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-06-12 12:39 - 2022-11-30 19:20 - 000000000 ___RD C:\Users\\OneDrive
2024-06-12 12:27 - 2023-04-24 12:49 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-06-11 23:33 - 2023-12-21 14:23 - 000000000 ____D C:\Users\\.mediathek3
2024-06-10 17:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-06-06 19:43 - 2024-01-29 10:47 - 000016431 _____ C:\Users\\Desktop\MaWa V L aktuell.odt
2024-06-05 21:39 - 2022-11-30 18:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-06-02 15:16 - 2023-02-23 18:13 - 000000000 ____D C:\Users\\AppData\Local\ElevatedDiagnostics
2024-05-31 22:02 - 2023-04-24 12:54 - 000004296 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1677170401
2024-05-31 22:02 - 2023-02-23 18:40 - 000001389 _____ C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk
2024-05-31 21:58 - 2023-07-25 14:55 - 000002239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-05-31 21:58 - 2023-07-25 14:55 - 000002198 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-05-26 00:01 - 2023-03-03 18:41 - 000001904 _____ C:\Users\\Desktop\Reset Windows Update Tool.lnk
2024-05-24 20:22 - 2023-03-12 19:00 - 000000000 ____D C:\ProgramData\Package Cache
2024-05-16 08:40 - 2023-12-12 11:50 - 000000000 ____D C:\Program Files\LibreOffice
2024-05-15 20:22 - 2022-11-30 19:16 - 000000000 ____D C:\ProgramData\Packages
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== --- --- --- |