| johnny5709 | 05.08.2026 09:02 | Hoffe es dieses Mal richtig gemacht zu haben:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-08-2026 01
Ran by goofy (administrator) on DESKTOP-P4QE8KD (AZW SEi) (04-08-2026 17:35:38)
Running from C:\Users\goofy\Downloads\Neuer Ordner\FRST64 (08).exe
Loaded Profiles: goofy
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8973 (X64) Language: Deutsch (Deutschland)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(explorer.exe ->) () [File not signed] C:\Program Files\Rainlendar2\Rainlendar2.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2605.29.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(explorer.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(IObit Co., Ltd. -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\150.0.4078.105\msedgewebview2.exe <5>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <17>
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_23697451aa00e25a\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_733999112d65c1dd\Intel_PIE_Service.exe
(services.exe ->) (Lespeed Technology Co., Ltd -> WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\Intel(R) Audio Service\IntelAudioService.exe
(services.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.151.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Tweaking LLC -> Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
Failed to access process -> vmmemCmZygote
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
HKLM\...\Policies\Explorer: [NoThumbnailCache] 0
HKLM\...\Policies\Explorer: [DisableThumbnailCache] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [AllowDomainPINLogon] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26530552 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe [4232192 2025-11-21] () [File not signed]
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [NoThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\Policies\Explorer: [DisableThumbnailCache] 0
HKU\S-1-5-21-2474616372-3844271695-3557059434-1001\...\MountPoints2: {c5285fd3-bc9f-11ec-ba8c-3887d5b84f9c} - "F:\setup.exe"
HKU\S-1-5-21-2474616372-3844271695-3557059434-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
IFEO\CompatTelRunner.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\DeviceCensus.exe: [Debugger] C:\WINDOWS\System32\taskkill.exe
IFEO\eucloneserver.exe: [GlobalFlag]
BootExecute: autocheck autochk *
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {65871B34-40DD-4B84-9B4C-36481909297B} - System32\Tasks\CleanGenius => C:\Program Files\EaseUS\EaseUS Partition Master\ECG\CleanGeniusEPM.exe [726488 2026-06-18] (Chengdu Yiwo Tech Development Co., Ltd. -> )
Task: {17D68746-2E31-40BA-BEEB-1EFBE5B8C992} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\Scheduler.exe [164056 2026-04-16] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {C412CCD5-D50A-4DC8-A1DE-601B5A3DBB20} - System32\Tasks\Driver Booster SkipUAC (goofy) => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\DriverBooster.exe [8639696 2026-06-12] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {8CD636FC-F684-4131-BACD-903CA4D03C5B} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\13.5.0\AutoUpdate.exe [2537680 2026-06-12] (IObit CO., LTD -> IObit) <==== ATTENTION
Task: {B2E7DFB7-644F-4ED2-B89D-54B903BED13E} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {6449ACB8-AB62-489A-B6E5-1B87E8967CDF} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\goofy\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15205744 2025-12-07] (ESET, spol. s r.o. -> ESET)
Task: {A740AD63-A7E9-4A87-AED2-F32F9FDB518B} - System32\Tasks\IObit SUM2026Sale (One-time) => C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\sum26.exe [2888912 2026-07-26] (IObit CO., LTD -> IObit) -> C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\\/rpop <==== ATTENTION
Task: {D39270E8-21C6-4912-9B28-25CC92DED2EC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic\Tools\CodecTweakTool.exe [2401792 2026-07-20] () [File not signed]
Task: {FE7BAC05-0FC3-4442-8EC1-BE1FD4B65043} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1DAD7236-7EB3-470C-A338-44579225A44A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28616088 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {A07F1BC3-4949-4722-9792-F7A0A8F10184} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {158D0912-1DAB-4FA8-86E2-BEC17B49639C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [313624 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {4FD9E461-DE91-4FD9-A266-006255F58111} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [188184 2026-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {6B60C455-FDB2-4660-B9F2-FCFA0892EFB1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2474616372-3844271695-3557059434-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [704640 2026-07-29] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {9709E63F-D713-40D9-B8D1-1A6EF83B3042} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-29] (Mozilla Corporation -> Mozilla Foundation)
Task: {051BE515-FB31-4F7E-80C0-9BC944141BD2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {7173B6DA-C062-4B89-BA20-58E8CA884001} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File)
Task: {DB8AD0FE-07AF-4BFB-98DF-03934344A48F} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [220816 2019-09-30] (Tweaking LLC -> Tweaking.com)
Task: {EE6F8AFE-BA02-4989-B07C-047CD805BEB1} - System32\Tasks\Uninstaller_SkipUac_goofy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [10041280 2026-07-07] (IObit Co., Ltd. -> IObit) -> C:\Program Files (x86)\IObit\IObit Uninstaller\\/UninstallExplorer <==== ATTENTION
Task: {3EBEEA44-E7AD-47D6-934F-6CC33D439D0B} - System32\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [11172760 2026-01-22] (Lespeed Technology Co., Ltd -> WiseCleaner.com) -> C:\Program Files (x86)\Wise\Wise Care 365\-StartTray
Task: {DAAC4EBA-C7EE-48C6-AEE5-040FA89A7BA4} - System32\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [12417432 2026-01-05] (Lespeed Technology Co., Ltd -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9 18 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog5-x64 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5-x64 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9-x64 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9-x64 18 %windir%\system32\vsocklib.dll => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5de296e9-d9aa-419d-8c0b-536d1fc546ec}: [DhcpDomain] fritz.box
HKLM\System\...\Parameters\PersistentRoutes: [104.82.14.146,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.82.22.249,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.87.88.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [104.89.242.39,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [11.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.18.11,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [13.107.3.128,255.255.255.255,0.0.0.0,1]
PersistentRoutes: There are 1086 PersistentRoutes.
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: hu4eol42.default-release -> 1A202D4B41E895FC
FF DefaultProfile: 3syath58.default-release-1783881393319 -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release [2026-08-04]
FF Extension: (uBlock Origin) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-07-09]
FF Extension: (NoScript) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2026-07-21] [UpdateUrl:hxxps://dist.torproject.org/torbrowser/noscript/update-stable.json]
FF Extension: (Mullvad Browser Extension) - C:\Users\goofy\AppData\Roaming\Mullvad\MullvadBrowser\Profiles\hu4eol42.default-release\Extensions\{d19a89b9-76c1-4a61-bcd4-49e8de916403}.xpi [2026-04-17] [UpdateUrl:hxxps://cdn.mullvad.net/browser-extension/updates.json]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default [2026-02-13]
FF user.js: detected! => C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\m4wz3vgv.default\user.js [2025-12-01]
FF ProfilePath: C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 [2026-08-04]
FF Homepage: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> web.de
FF NewTabOverride: Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319 -> Enabled: mailcheck@web.de
FF Extension: (WEB.DE MailCheck) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\mailcheck@web.de.xpi [2026-07-14] [UpdateUrl:hxxps://dl.gmx.com/mailcheck/firefox/updates.json]
FF Extension: (New Tab) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\newtab@mozilla.org.xpi [2026-07-18]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\goofy\AppData\Roaming\Mozilla\Firefox\Profiles\3syath58.default-release-1783881393319\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2026-07-18]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2025-12-22] (VideoLAN) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=3 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [No File]
FF Plugin HKU\S-1-5-21-2474616372-3844271695-3557059434-1001: @update.avira.securebrowser.com/Avira Browser;version=9 -> C:\Users\goofy\AppData\Local\Avira\Browser\Update\1.8.1997.6\npAviraBrowserUpdate3.dll [No File]
Edge:
=======
Edge Profile: C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default [2026-07-31]
Edge Extension: (Google Docs Offline) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-07-26]
Edge Extension: (Edge relevant text changes) - C:\Users\goofy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-07-26]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [144784 2018-04-18] (Canon Inc. -> CANON INC.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14056848 2026-07-13] (Microsoft Corporation -> Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2272424 2026-01-23] (voidtools PTY LTD -> voidtools)
S3 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [888208 2025-11-16] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUMemfilesService; C:\Program Files (x86)\Glary Utilities\x64\MemfilesService.exe [416136 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
S3 GUPMService; C:\Program Files (x86)\Glary Utilities\GUPMService.exe [76688 2026-07-17] (Glarysoft Ltd -> Glarysoft Ltd)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460992 2025-04-18] (Canon Inc. -> )
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [193472 2025-08-18] (IObit Co., Ltd. -> IObit) <==== ATTENTION
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
S4 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-07-24] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 PCManager Service Store; C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.21.7.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe [162104 2026-06-17] (Microsoft Corporation -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-05-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\System32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
R2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [651216 2023-09-11] (Lespeed Technology Co., Ltd -> WiseCleaner.com)
S4 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 27\LiveTunerService.exe [288608 2024-10-28] (Ashampoo GmbH & Co. KG -> )
S3 Browser; %SystemRoot%\System32\browser.dll (No File)
S3 MozillaVPNBroker; "C:\Program Files\Mozilla\Mozilla VPN\Mozilla VPN.exe" windowsdaemon (No File)
S3 MozillaVPNProxy; "C:\Program Files\Mozilla\Mozilla VPN\socksproxy.exe" -p 8123 -s (No File)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Ahflt; C:\WINDOWS\System32\drivers\ahflt.sys [49552 2023-08-30] (Microsoft Corporation -> Microsoft Corporation)
R3 bhtsdhubdr; C:\WINDOWS\System32\drivers\bhtsdhubdr.sys [202456 2020-10-20] (BayHub Technology Inc. -> BayHubTech)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ebrntdrv; C:\WINDOWS\system32\ebrntdrv.sys [57512 2025-12-25] (CHENGDU YIWO Tech Development Co., Ltd. -> )
S3 epmdkdrv; C:\WINDOWS\system32\epmdkdrv.sys [57512 2025-05-26] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R0 EPMVolFl; C:\WINDOWS\System32\drivers\EPMVolFl.sys [30136 2022-12-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider)
S3 eprdtdrv; C:\WINDOWS\system32\eprdtdrv.sys [27728 2025-09-29] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 ESAuDriver; C:\WINDOWS\System32\drivers\ESAuDriver.sys [223208 2024-07-16] (苏州顺芯半导体有限公司 -> Everest Semiconducor Co., Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 EUDCPEPM; C:\WINDOWS\System32\drivers\EUDCPEPM.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EUDCPEPM0; C:\WINDOWS\system32\drivers\EUDCPEPM0.sys [77904 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R1 EUEDKEPM; C:\WINDOWS\System32\drivers\EUEDKEPM.sys [24656 2026-01-12] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S3 EuMrx; C:\WINDOWS\System32\DRIVERS\EuMrx.sys [215704 2025-09-29] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Win 7 DDK provider)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [230888 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 GSCAuxDriver; C:\WINDOWS\System32\DriverStore\FileRepository\gscauxdriver.inf_amd64_fe9355c6b52fb409\GSCAuxDriverx64.sys [71424 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSCx64; C:\WINDOWS\System32\DriverStore\FileRepository\gscheci.inf_amd64_e0a6bd87d5543f55\TeeDriverGSCW8x64.sys [243992 2021-05-28] (Intel(R) pGFX 2020 -> Intel Corporation)
S3 GSDriver; C:\WINDOWS\System32\drivers\GSDriver64.sys [55488 2022-09-01] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [23744 2026-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd)
S3 iaLPSS2_UART2_SYSTEM; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2.inf_amd64_fd889dfbe795f97b\iaLPSS2_UART2.sys [406488 2026-01-18] (Intel Corporation -> Intel Corporation)
R3 IntcSST; C:\WINDOWS\System32\drivers\IntcSST.sys [697728 2025-11-26] (Smart Sound Technology -> Intel(R) Corporation)
R3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [28240 2024-04-26] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [21712 2025-04-21] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [36552 2025-08-08] (Microsoft Windows Hardware Compatibility Publisher -> IObit)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-27] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [144880 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-07-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt11.sys [216680 2026-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [132712 2026-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-25] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-08-04] (Malwarebytes Inc -> Malwarebytes)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_05602848cd0003d3\rt68cx21x64.sys [941608 2026-07-07] (Realtek Semiconductor Corp. -> Realtek)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 vkrnlintvsc; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsc.inf_amd64_ae7c1fb85fc0224e\vkrnlintvsc.sys [79168 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
R3 vkrnlintvsp; C:\WINDOWS\System32\DriverStore\FileRepository\wvkrnlintvsp.inf_amd64_249e734e16ab4232\vkrnlintvsp.sys [87504 2026-07-29] (Microsoft Windows -> Microsoft Corporation)
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [283016 2026-02-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-11-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
U4 DiagTrack; no ImagePath
U4 dmwappushsvc; no ImagePath
S3 EuGdiDrv; \SystemRoot\system32\EuGdiDrv.sys (No File)
S2 MozillaVPNSplitTunnel; \??\C:\Program Files\Mozilla\Mozilla VPN\mullvad-split-tunnel.sys (No File)
S3 usbscan; \SystemRoot\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\usbscan.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-04 17:34 - 2026-08-04 17:35 - 000000000 ____D C:\FRST
2026-08-04 17:32 - 2026-08-04 17:32 - 000000784 _____ C:\Users\goofy\Desktop\FRST.txt
2026-08-04 16:33 - 2026-08-04 16:33 - 000730398 _____ C:\WINDOWS\system32\perfh007.dat
2026-08-04 16:33 - 2026-08-04 16:33 - 000255203 ____T C:\Users\goofy\test_trace.txt
2026-08-04 16:33 - 2026-08-04 16:33 - 000153228 _____ C:\WINDOWS\system32\perfc007.dat
2026-08-04 16:33 - 2026-08-04 16:33 - 000000171 ____T C:\Users\goofy\test_step1.txt
2026-08-04 16:29 - 2026-08-04 16:29 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-08-04 14:28 - 2026-08-04 14:28 - 000003322 _____ C:\WINDOWS\system32\Tasks\klcp_update
2026-08-04 14:28 - 2019-12-28 12:00 - 000784384 _____ C:\WINDOWS\system32\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000681984 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000310784 _____ C:\WINDOWS\system32\xvidvfw.dll
2026-08-04 14:28 - 2019-12-28 12:00 - 000284160 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003850240 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2026-08-04 14:28 - 2017-07-30 13:50 - 003799552 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2026-08-04 14:28 - 2012-07-21 13:55 - 000180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2026-08-04 14:28 - 2012-07-21 13:54 - 000122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2026-08-04 14:28 - 2011-12-07 20:37 - 000148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2026-08-04 14:28 - 2011-12-07 20:32 - 000216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2026-08-04 09:02 - 2026-08-04 09:02 - 012426276 _____ C:\Users\goofy\Downloads\F-Droid.apk
2026-08-04 08:44 - 2026-08-04 08:44 - 012426276 _____ C:\Users\goofy\Downloads\org.fdroid.fdroid_1023052.apk
2026-08-02 22:22 - 2026-08-02 22:22 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2026-08-02 22:22 - 2026-08-02 22:22 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2026-08-01 23:02 - 2026-08-01 23:02 - 000344472 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-07-30 07:26 - 2026-08-04 09:55 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-07-29 13:26 - 2026-07-29 13:26 - 000038723 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-07-28 08:48 - 2026-07-28 08:48 - 000132424 _____ C:\Users\goofy\Downloads\Account Statement FDA_124_114_752_806 - 2026-02-06 - 2026-07-28.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000149064 _____ C:\Users\goofy\Downloads\5187303_2026_Nr.006_Kontoauszug_vom_2026.07.01_20260728084308515.pdf
2026-07-28 08:43 - 2026-07-28 08:43 - 000118245 _____ C:\Users\goofy\Downloads\5187303_2026_Rechnungsabschluss_Geduldete Überziehung_vom_2026.07.01_20260728084320936.pdf
2026-07-26 13:51 - 2026-07-26 13:51 - 000000000 ____D C:\Users\goofy\AppData\Local\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-07-26 13:45 - 000000758 _____ C:\Users\Public\Desktop\Steuer 2025.lnk
2026-07-26 13:45 - 2026-07-26 13:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2025
2026-07-26 13:27 - 2026-07-26 13:27 - 547540784 _____ C:\Users\goofy\Downloads\Steuer2025.exe
2026-07-26 07:01 - 2026-07-26 07:01 - 000003378 _____ C:\WINDOWS\system32\Tasks\IObit SUM2026Sale (One-time)
2026-07-25 09:18 - 2026-07-25 09:18 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2026-07-25 09:05 - 2026-07-25 09:05 - 058118520 _____ (Tweaking.com) C:\Users\goofy\Downloads\tweaking.com_windows_repair_aio_setup.exe
2026-07-25 08:51 - 2026-07-25 08:51 - 000003782 _____ C:\WINDOWS\system32\Tasks\Tweaking.com - Windows Repair Tray Icon
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2026-07-25 08:51 - 2026-07-25 08:51 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2026-07-24 20:54 - 2026-08-04 17:35 - 000000000 ____D C:\Users\goofy\Downloads\Neuer Ordner
2026-07-24 13:27 - 2026-07-24 14:21 - 000000000 ____D C:\Program Files (x86)\iTop Data Recovery
2026-07-24 13:27 - 2026-07-24 13:27 - 000003144 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_goofy
2026-07-24 13:27 - 2026-07-24 13:27 - 000001442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2026-07-24 13:27 - 2026-07-24 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2026-07-24 13:27 - 2026-07-24 13:27 - 000000000 ____D C:\ProgramData\iTop
2026-07-24 13:25 - 2026-07-24 13:25 - 033257536 _____ (IObit ) C:\Users\goofy\Downloads\iobituninstaller.exe
2026-07-24 12:53 - 2026-07-24 12:53 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\MMC
2026-07-24 12:45 - 2026-07-24 12:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\Malwarebytes
2026-07-24 12:45 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Sentry
2026-07-24 09:38 - 2026-08-04 16:35 - 000000000 ____D C:\Users\goofy\AppData\Local\Malwarebytes
2026-07-24 09:38 - 2026-07-24 09:38 - 000002105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-24 09:37 - 2026-07-24 09:37 - 002862824 _____ (Malwarebytes) C:\Users\goofy\Downloads\MBSetup-8.8.exe
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-24 09:37 - 2026-07-24 09:37 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows
2026-07-24 08:50 - 2026-07-24 08:53 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\Packages
2026-07-24 08:50 - 2026-07-24 08:50 - 000000020 ___SH C:\Users\WsiAccount\ntuser.ini
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Vorlagen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Startmenü
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Netzwerkumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Lokale Einstellungen
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Eigene Dateien
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Druckumgebung
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Videos
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Musik
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Documents\Eigene Bilder
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Verlauf
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\AppData\Local\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 _SHDL C:\Users\WsiAccount\Anwendungsdaten
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\SystemCertificates
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Protect
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Crypto
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ___SD C:\Users\WsiAccount\AppData\Roaming\Microsoft\Credentials
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Vault
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Spelling
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\LocalLow\Intel
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\VirtualStore
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\D3DSCache
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount\AppData\Local\ConnectedDevicesPlatform
2026-07-24 08:50 - 2026-07-24 08:50 - 000000000 ____D C:\Users\WsiAccount
2026-07-24 08:50 - 2026-02-12 20:54 - 000000000 ____D C:\Users\WsiAccount\AppData\Roaming\Microsoft\Network
2026-07-24 08:50 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\WsiAccount\OneDrive
2026-07-23 23:18 - 2026-07-23 23:18 - 000000000 ____D C:\Users\Administrator\AppData\Local\PeerDistRepub
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Everything
2026-07-23 22:40 - 2026-07-24 12:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\Everything
2026-07-23 22:36 - 2026-07-23 22:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2026-07-23 22:06 - 2026-07-23 22:07 - 000000000 ____D C:\Users\Administrator\Desktop\Neuer Ordner
2026-07-23 22:06 - 2026-07-23 22:06 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003586 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2474616372-3844271695-3557059434-500
2026-07-23 22:06 - 2026-07-23 22:06 - 000002419 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Obsidium x64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ___HD C:\Users\Administrator\.obs64
2026-07-23 22:06 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\TeraCopy
2026-07-23 22:05 - 2026-07-23 22:20 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers
2026-07-23 22:05 - 2026-07-23 22:05 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2026-07-23 22:04 - 2026-07-24 12:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows
2026-07-23 22:04 - 2026-07-23 23:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Spelling
2026-07-23 22:04 - 2026-07-23 22:11 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache
2026-07-23 22:04 - 2026-07-23 22:06 - 000000000 ____D C:\Users\Administrator
2026-07-23 22:04 - 2026-07-23 22:04 - 000002346 _____ C:\Users\Administrator\Desktop\Microsoft Edge.lnk
2026-07-23 22:04 - 2026-07-23 22:04 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Vorlagen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Startmenü
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Eigene Dateien
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Druckumgebung
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Videos
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Protect
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Crypto
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ___SD C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Vault
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\Intel
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder
2026-07-23 22:04 - 2026-07-23 22:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2026-07-23 22:04 - 2026-02-12 20:54 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Network
2026-07-23 22:04 - 2025-11-25 20:12 - 000000000 ___RD C:\Users\Administrator\OneDrive
2026-07-22 08:09 - 2026-07-29 14:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell
2026-07-21 17:20 - 2026-07-21 17:20 - 000000000 ____D C:\Program Files\PowerShell
2026-07-18 09:53 - 2026-07-18 09:53 - 000056366 _____ C:\Users\goofy\Downloads\ernaehrungstagebuch102.pdf
2026-07-16 10:43 - 2026-07-25 09:25 - 000000000 ____D C:\Program Files\TeraCopy
2026-07-16 10:43 - 2026-07-16 11:04 - 000000000 ____D C:\Users\goofy\AppData\Roaming\TeraCopy
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\AppData\Roaming\Obsidium x64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ___HD C:\Users\goofy\.obs64
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Code Sector
2026-07-16 10:43 - 2026-07-16 10:43 - 000000000 ____D C:\ProgramData\Caphyon
2026-07-14 08:57 - 2026-07-14 08:57 - 000000000 ____D C:\Program Files\Microsoft Office 15
2026-07-13 22:12 - 2026-07-25 08:52 - 000010055 _____ C:\WINDOWS\system32\InstallMonitorLog.csv
2026-07-13 17:29 - 2026-07-23 22:10 - 000000000 ____D C:\WINDOWS\Panther
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagwrn.xml
2026-07-13 14:26 - 2026-07-23 22:08 - 000001890 _____ C:\WINDOWS\diagerr.xml
2026-07-12 23:18 - 2026-07-16 17:24 - 000000000 ____D C:\Users\goofy\AppData\Local\PlaceholderTileLogoFolder
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ___SD C:\WINDOWS\system32\containers
2026-07-12 21:12 - 2026-07-12 21:12 - 000000000 ____D C:\WINDOWS\system32\HvsiSettingsProviders
2026-07-11 10:46 - 2026-05-16 00:09 - 036362808 _____ C:\Users\goofy\Desktop\FRITZBOX - Tricks und Tipps Mai 2026.pdf
2026-07-09 12:10 - 2026-07-09 12:10 - 000000416 _____ C:\WINDOWS\BRWMARK.INI
2026-07-09 12:10 - 2026-07-09 12:10 - 000000034 _____ C:\WINDOWS\SysWOW64\BD5240.DAT
2026-07-09 10:02 - 2026-07-09 10:03 - 000000000 ____D C:\Users\goofy\Downloads\PVS
2026-07-07 09:02 - 2026-07-07 09:02 - 000002620 _____ C:\Users\goofy\Desktop\Raisin-Empfängerprüfung.txt
2026-07-07 08:53 - 2026-07-07 08:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2026-07-06 22:33 - 2026-07-06 22:33 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Media Player
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-08-04 17:09 - 2023-02-05 18:26 - 000000000 ____D C:\Users\goofy\.rainlendar2
2026-08-04 16:49 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-08-04 16:42 - 2026-01-24 11:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Mp3tag
2026-08-04 16:41 - 2025-12-24 20:47 - 000000000 ____D C:\Users\goofy\AppData\Roaming\vlc
2026-08-04 16:39 - 2023-09-17 10:49 - 000000000 ____D C:\Users\goofy\Desktop\YSD
2026-08-04 16:33 - 2026-02-12 20:56 - 001724020 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-08-04 16:33 - 2026-02-12 20:13 - 000000000 ____D C:\Users\goofy
2026-08-04 16:33 - 2025-11-30 12:03 - 000064520 _____ C:\Users\goofy\test.dat
2026-08-04 16:33 - 2025-11-30 12:02 - 000005397 _____ C:\Users\goofy\test.ini
2026-08-04 16:33 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-08-04 16:30 - 2026-03-02 11:44 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Wise Care 365
2026-08-04 16:29 - 2026-02-22 11:29 - 000012288 ___SH C:\DumpStack.log.tmp
2026-08-04 16:29 - 2026-02-12 20:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-08-04 16:29 - 2025-11-25 19:01 - 000142058 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-08-04 16:29 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-08-04 14:57 - 2026-01-14 12:03 - 000000000 ____D C:\Users\goofy\AppData\Local\Everything
2026-08-04 14:57 - 2026-01-14 11:15 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Everything
2026-08-04 14:57 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-08-04 14:57 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2026-08-04 14:28 - 2026-01-18 10:10 - 000000000 ____D C:\Program Files (x86)\K-Lite_Codec_Pack_1587_Basic
2026-08-04 11:26 - 2025-11-26 19:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\YouTubeSongDownloader
2026-08-04 11:12 - 2022-11-28 22:53 - 000000000 ____D C:\Users\goofy\.cache
2026-08-03 14:31 - 2025-11-26 10:44 - 000001334 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2026-08-03 09:57 - 2025-11-25 19:14 - 000000000 ____D C:\Users\goofy\AppData\Local\Packages
2026-08-03 09:14 - 2026-02-12 19:53 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2026-08-02 22:50 - 2026-04-17 11:41 - 000000000 ____D C:\Users\goofy\AppData\Local\deno
2026-08-02 22:50 - 2026-03-01 15:52 - 000000000 ____D C:\Users\goofy\AppData\Local\D3DSCache
2026-08-02 22:22 - 2025-12-07 14:05 - 000001398 _____ C:\Users\goofy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2026-08-02 08:23 - 2026-01-17 19:51 - 000000000 ____D C:\Users\goofy\AppData\Local\CrashDumps
2026-08-01 15:16 - 2025-11-26 18:04 - 000000000 ____D C:\Users\goofy\AppData\Local\JDownloader 2
2026-08-01 08:30 - 2025-11-26 22:34 - 000000000 ____D C:\Program Files (x86)\Glary Utilities
2026-07-31 20:47 - 2025-11-25 20:14 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Excel
2026-07-31 14:39 - 2026-06-27 11:40 - 000002812 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (goofy)
2026-07-31 14:39 - 2026-06-27 11:40 - 000002634 _____ C:\WINDOWS\system32\Tasks\Driver Booster Scheduler
2026-07-31 14:39 - 2026-06-27 11:40 - 000002620 _____ C:\WINDOWS\system32\Tasks\Driver Booster Update
2026-07-31 14:39 - 2026-02-12 20:54 - 000003742 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-07-31 14:39 - 2026-02-12 20:54 - 000003516 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-07-31 14:38 - 2025-11-26 22:54 - 000000000 ____D C:\ProgramData\ProductData3
2026-07-31 10:06 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2026-07-31 08:46 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-31 07:35 - 2026-02-12 20:35 - 000001607 _____ C:\WINDOWS\system32\config\VSMIDK
2026-07-30 14:16 - 2025-10-20 11:38 - 000000000 ____D C:\Users\goofy\Desktop\Steuer
2026-07-29 14:20 - 2025-11-25 22:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-07-29 14:16 - 2026-02-12 20:08 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-07-29 14:16 - 2024-04-01 18:37 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files (x86)\Windows Defender
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-plocm
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\qps-ploc
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\et-EE
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\es-MX
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\am-ET
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\DiagTrack
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-07-29 14:16 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-07-29 14:16 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-07-29 13:26 - 2026-02-12 20:46 - 003375104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-07-29 08:14 - 2025-11-25 19:01 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-07-29 08:11 - 2025-11-25 22:37 - 000001071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-07-26 15:30 - 2024-03-08 23:04 - 000000000 ____D C:\Users\goofy\Desktop\Kontoauszüge
2026-07-26 13:48 - 2026-01-10 13:30 - 000000000 ____D C:\ProgramData\Buhl Data Service GmbH
2026-07-26 13:45 - 2026-01-10 13:56 - 000000000 ____D C:\Program Files\Steuer 2025
2026-07-25 09:28 - 2022-04-14 03:14 - 000000000 ____D C:\WINDOWS\CSC
2026-07-25 09:24 - 2026-01-24 11:03 - 000000000 ____D C:\Program Files\Mp3tag
2026-07-25 09:12 - 2025-12-21 20:16 - 001729632 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2026-07-24 13:27 - 2025-11-26 22:53 - 000000908 _____ C:\ProgramData\pdinst.ini
2026-07-24 13:27 - 2025-11-26 22:53 - 000000000 ____D C:\Users\goofy\AppData\Roaming\IObit
2026-07-24 13:27 - 2025-11-26 22:53 - 000000000 ____D C:\ProgramData\IObit
2026-07-24 13:26 - 2025-11-26 22:54 - 000000000 ____D C:\Program Files (x86)\IObit
2026-07-24 11:22 - 2025-11-26 22:34 - 000001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities.lnk
2026-07-24 09:38 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-07-24 09:15 - 2023-02-06 16:17 - 000000000 ____D C:\Users\goofy\Desktop\Text-Dateien
2026-07-24 08:50 - 2026-03-05 09:03 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-07-23 22:20 - 2020-11-19 09:48 - 000000000 ____D C:\ProgramData\Packages
2026-07-23 22:15 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Registration
2026-07-23 22:04 - 2020-11-19 09:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2026-07-23 21:23 - 2026-04-29 11:55 - 000001292 _____ C:\Users\goofy\Desktop\ESET Online Scanner.lnk
2026-07-20 08:28 - 2025-12-07 19:52 - 002318240 _____ C:\Users\goofy\Desktop\Hochzeit Klaus2.jpeg
2026-07-19 17:38 - 2025-01-20 12:46 - 000000004 _____ C:\Users\goofy\Desktop\1990.txt
2026-07-17 15:31 - 2025-11-25 22:11 - 000000000 ____D C:\Program Files\Microsoft Office
2026-07-16 17:21 - 2025-12-14 11:21 - 000000000 ____D C:\WINDOWS\pss
2026-07-15 17:35 - 2024-04-01 18:36 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-07-15 17:35 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-07-15 15:04 - 2025-11-26 23:05 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-07-15 15:03 - 2025-11-26 23:05 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-07-15 14:36 - 2025-11-26 11:06 - 000000000 ____D C:\ProgramData\Package Cache
2026-07-15 14:35 - 2026-02-14 10:54 - 000000000 ____D C:\Program Files\dotnet
2026-07-14 18:56 - 2025-11-25 20:18 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\Word
2026-07-13 17:42 - 2020-11-19 09:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2026-07-13 13:37 - 2026-02-11 20:06 - 000499195 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_708
2026-07-12 20:36 - 2026-02-12 20:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-07-12 20:36 - 2025-11-25 22:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-07-11 15:25 - 2025-11-26 19:03 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Signal
2026-07-10 10:43 - 2023-03-29 21:51 - 000000000 ____D C:\Users\goofy\Desktop\Restaurants, Cafés
2026-07-09 17:13 - 2025-11-11 14:23 - 000000011 _____ C:\Users\goofy\Desktop\a.txt
2026-07-09 11:49 - 2025-11-25 21:57 - 000000000 ____D C:\Users\goofy\AppData\Roaming\Microsoft\MMC
2026-07-07 16:37 - 2025-11-26 17:40 - 000000000 ____D C:\Program Files\7-Zip
2026-07-06 16:03 - 2024-10-27 11:31 - 000000000 ____D C:\Users\goofy\Aiarty Output
2026-07-05 18:10 - 2025-09-23 10:49 - 000000000 ____D C:\Users\goofy\Desktop\Clio
==================== Files in the root of some directories ========
2022-10-06 13:03 - 2023-10-07 12:55 - 000000076 _____ () C:\Users\goofy\123.dat
2024-04-21 19:41 - 2025-11-25 10:14 - 000067918 _____ () C:\Users\goofy\bestof.dat
2025-11-11 18:10 - 2025-11-11 18:10 - 007300408 _____ (Microsoft Corporation) C:\Users\goofy\setup.exe
2025-11-12 20:13 - 2023-11-01 15:44 - 000000049 _____ () C:\Users\goofy\start.bat
2025-11-30 12:03 - 2026-08-04 16:33 - 000064520 _____ () C:\Users\goofy\test.dat
2025-11-25 20:08 - 2023-11-01 15:44 - 000000049 _____ () C:\Program Files\start.bat
2026-06-26 17:22 - 2026-06-26 17:22 - 000000059 _____ () C:\Users\goofy\AppData\Roaming\epm_user.ini
2025-12-05 19:53 - 2025-12-05 19:57 - 000097808 _____ () C:\Users\goofy\AppData\Local\dxdiag.log
2026-06-09 20:58 - 2026-06-09 20:58 - 000102541 _____ () C:\Users\goofy\AppData\Local\mozillavpn.log
2025-12-14 11:23 - 2025-12-14 11:23 - 000007629 _____ () C:\Users\goofy\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ======================== --- --- --- |