|
Plagegeister aller Art und deren Bekämpfung: Trojan.Generic.17748374Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.08.2016, 16:00 | #1 |
| Trojan.Generic.17748374 Liebes Board, bei einem Routinescan meines PCs mit G Data Internet Security wurde obiger Trojan.Generic entdeckt und in die Quarantäne verschoben. Ein Scan mit Malwarebytes Anti-Malware ein oder zwei Tage vorher hatte den Virus (noch) nicht erkannt. Auswirkungen des Trojan.Generics auf den PC habe ich bisher nicht festgestellt. FRST habe ich schon über den Rechner laufen lassen. FRST.txt und Addition.txt füge ich bei. Das Protokoll von G Data mit dem Fund wird nachgeliefert. Ist erkennbar, ob der Tojan.Generic auf dem PC etwas angestellt hat? Wie kann das bereinigt werden? Wer kann mir helfen? Vielen Dank im Voraus. Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-08-2016 durchgeführt von Jordan BUH2 (Administrator) auf JORDANBUH-PC (18-08-2016 11:33:13) Gestartet von C:\Users\Jordan BUH2\Downloads Geladene Profile: Jordan BUH2 (Verfügbare Profile: Jordan BUH2 & DefaultAppPool) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avanquest Software) C:\Users\Jordan BUH2\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe (Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Avanquest Software) C:\Program Files (x86)\Avanquest\AutoSaveEssentials\AutoSave Essentials.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe (G DATA Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe (eM Client s.r.o.) C:\Program Files (x86)\eM Client\MailClient.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation) HKLM\...\Run: [LXBSCATS] => rundll32 C:\Windows\system32\spool\DRIVERS\x64\3\LXBStime.dll,RunDLLEntry HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.) HKLM-x32\...\Run: [vspdfprsrv.exe] => C:\Program Files (x86)\Avanquest\PDF Experte 8 Ultimate\vspdfprsrv.exe [6420992 2013-04-15] (Visagesoft) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-07-05] (Apple Inc.) HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AutoSave] => C:\Program Files (x86)\Avanquest\AutoSaveEssentials\Autosave Essentials.exe [1934592 2010-12-03] (Avanquest Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-07-08] (Apple Inc.) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [VLC Updater] => C:\Program Files (x86)\VLC Updater\vlc-updater.exe [370128 2016-06-29] () HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [Avanquest Message] => C:\Users\Jordan BUH2\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [435944 2016-06-22] (Avanquest Software) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64" IFEO\backitup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\neroexpress.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Control Center.lnk [2015-01-17] ShortcutTarget: Control Center.lnk -> C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe (Funkwerk Enterprise Communications GmbH) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-11-30] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-13] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-01-21] ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Jordan BUH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8610.lnk [2016-03-01] ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8610.lnk -> C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP) Startup: C:\Users\Jordan BUH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verbatim GREEN BUTTON.lnk [2013-12-10] ShortcutTarget: Verbatim GREEN BUTTON.lnk -> C:\Program Files (x86)\Verbatim GREEN BUTTON\GREEN BUTTON.exe () ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: 0.0.0.1 mssplus.mcafee.com Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{0c4641db-fde4-4ecc-b629-28035eadc701}: [DhcpNameServer] 192.168.1.250 Tcpip\..\Interfaces\{f4e7f8d3-7e08-4745-94fd-cd77276900a5}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-07-20] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-23] (Hewlett-Packard Co.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-23] (Hewlett-Packard Co.) FireFox: ======== FF ProfilePath: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default FF DefaultSearchEngine: Startpage (SSL) FF Homepage: hxxps://www.ing-diba.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-13] () FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-20] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-13] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-20] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-29] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-29] (NVIDIA Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\user.js [2016-04-28] FF SearchPlugin: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\searchplugins\ixquick-https.xml [2016-03-18] FF SearchPlugin: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\searchplugins\startpage-ssl.xml [2016-03-18] FF Extension: WOT - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2016-03-22] FF Extension: DownThemAll! - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-04-15] FF Extension: Bitdefender QuickScan - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2016-04-27] FF Extension: Trafficlight - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\trafficlight@bitdefender.com.xpi [2016-04-27] FF Extension: ImTranslator - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2016-07-20] FF Extension: NoScript - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-10] FF Extension: anonymoX - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\client@anonymox.net.xpi [2016-03-22] FF Extension: Ghostery - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\firefox@ghostery.com.xpi [2016-08-12] FF Extension: Trusted Shops Add-On - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2016-05-04] FF Extension: PAYBACK Internet Assistant - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\toolbar-ff@payback.de-sh.xpi [2016-08-12] FF Extension: Adblock Plus - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-30] [ist nicht signiert] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2790368 2016-02-18] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe [970872 2016-02-11] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe [4068592 2016-02-18] (G Data Software AG) S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-12-09] (Freemake) [Datei ist nicht signiert] R3 GDFwSvc; C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe [3219872 2016-03-04] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [791160 2016-02-18] (G Data Software AG) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [4764304 2016-07-27] (SurfRight B.V.) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-23] (Hewlett-Packard Co.) [Datei ist nicht signiert] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-23] (Hewlett-Packard Co.) [Datei ist nicht signiert] S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [327944 2016-07-19] (McAfee, Inc.) S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation) S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2015-06-25] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AutoSave; C:\Windows\System32\DRIVERS\AutoSave.sys [36896 2009-08-13] (Avanquest) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [160768 2016-03-18] (G Data Software AG) S0 GDElam; C:\Windows\System32\DRIVERS\GDElam.sys [117904 2015-01-08] (G Data Software AG) R1 GDKBB; C:\Windows\system32\drivers\GDKBB64.sys [37400 2016-03-18] (G Data Software AG) R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [29720 2016-03-18] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [246272 2016-03-18] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [92160 2016-03-18] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [77848 2016-03-18] (G DATA Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2015-12-28] (G Data Software) S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [46960 2016-05-31] () R3 hmpalert; C:\WINDOWS\system32\drivers\hmpalert.sys [245288 2016-07-27] (SurfRight B.V.) R3 hmpnet; C:\WINDOWS\system32\drivers\hmpnet.sys [78256 2016-07-27] (SurfRight B.V.) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [134656 2016-03-18] (G Data Software AG) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [31144 2015-06-04] (TuneUp Software) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-08-18 11:33 - 2016-08-18 11:34 - 00021770 _____ C:\Users\Jordan BUH2\Downloads\FRST.txt 2016-08-18 11:32 - 2016-08-18 11:33 - 00000000 ____D C:\FRST 2016-08-18 11:28 - 2016-08-18 11:32 - 02394624 _____ (Farbar) C:\Users\Jordan BUH2\Downloads\FRST64.exe 2016-08-15 13:05 - 2016-08-15 13:05 - 00001924 _____ C:\Users\Public\Desktop\IrfanView 64 Thumbnails.lnk 2016-08-15 13:05 - 2016-08-15 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView 2016-08-15 13:04 - 2016-08-15 13:05 - 00000000 ____D C:\Program Files\IrfanView 2016-08-13 11:39 - 2016-08-13 11:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2016-08-10 18:01 - 2016-08-03 12:22 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-08-10 18:01 - 2016-08-03 12:21 - 00566112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-08-10 18:01 - 2016-08-03 12:19 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-08-10 18:01 - 2016-08-03 12:19 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2016-08-10 18:01 - 2016-08-03 11:51 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-08-10 18:01 - 2016-08-03 11:44 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2016-08-10 18:01 - 2016-08-03 11:40 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2016-08-10 18:01 - 2016-08-03 11:31 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe 2016-08-10 18:01 - 2016-08-03 11:29 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-08-10 18:01 - 2016-08-03 11:18 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-08-10 18:01 - 2016-08-03 11:18 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-08-10 18:01 - 2016-08-03 11:16 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2016-08-10 18:01 - 2016-08-03 11:11 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-08-10 18:01 - 2016-08-03 07:34 - 00501592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-08-10 18:01 - 2016-08-03 07:34 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-08-10 18:01 - 2016-08-03 07:33 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-08-10 18:01 - 2016-08-03 06:32 - 12585984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-08-10 18:01 - 2016-08-03 06:32 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2016-08-10 18:01 - 2016-08-03 06:25 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2016-08-10 18:01 - 2016-08-03 06:19 - 02180096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 01505984 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 00050368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-08-10 18:00 - 2016-08-03 12:36 - 07469408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-08-10 18:00 - 2016-08-03 12:36 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2016-08-10 18:00 - 2016-08-03 12:36 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2016-08-10 18:00 - 2016-08-03 12:30 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-08-10 18:00 - 2016-08-03 12:23 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-08-10 18:00 - 2016-08-03 12:23 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-08-10 18:00 - 2016-08-03 12:22 - 01322760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-08-10 18:00 - 2016-08-03 12:22 - 00465248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2016-08-10 18:00 - 2016-08-03 12:22 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-08-10 18:00 - 2016-08-03 12:22 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-08-10 18:00 - 2016-08-03 12:20 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-08-10 18:00 - 2016-08-03 12:20 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-08-10 18:00 - 2016-08-03 12:13 - 01988448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-08-10 18:00 - 2016-08-03 12:13 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-08-10 18:00 - 2016-08-03 12:13 - 00393056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-08-10 18:00 - 2016-08-03 12:11 - 00422744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-08-10 18:00 - 2016-08-03 11:51 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe 2016-08-10 18:00 - 2016-08-03 11:46 - 22384128 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-08-10 18:00 - 2016-08-03 11:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll 2016-08-10 18:00 - 2016-08-03 11:44 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2016-08-10 18:00 - 2016-08-03 11:43 - 16985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-08-10 18:00 - 2016-08-03 11:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-08-10 18:00 - 2016-08-03 11:41 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2016-08-10 18:00 - 2016-08-03 11:39 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-08-10 18:00 - 2016-08-03 11:39 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll 2016-08-10 18:00 - 2016-08-03 11:38 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-08-10 18:00 - 2016-08-03 11:38 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-08-10 18:00 - 2016-08-03 11:37 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-08-10 18:00 - 2016-08-03 11:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-08-10 18:00 - 2016-08-03 11:36 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-08-10 18:00 - 2016-08-03 11:36 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2016-08-10 18:00 - 2016-08-03 11:35 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-08-10 18:00 - 2016-08-03 11:35 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll 2016-08-10 18:00 - 2016-08-03 11:34 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-08-10 18:00 - 2016-08-03 11:33 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2016-08-10 18:00 - 2016-08-03 11:33 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-08-10 18:00 - 2016-08-03 11:31 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-08-10 18:00 - 2016-08-03 11:31 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 24613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 11:29 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-08-10 18:00 - 2016-08-03 11:29 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2016-08-10 18:00 - 2016-08-03 11:29 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-08-10 18:00 - 2016-08-03 11:29 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 07536640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 01717760 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-08-10 18:00 - 2016-08-03 11:20 - 13390336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-08-10 18:00 - 2016-08-03 11:18 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-08-10 18:00 - 2016-08-03 11:17 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-08-10 18:00 - 2016-08-03 11:16 - 03589120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-08-10 18:00 - 2016-08-03 11:16 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-08-10 18:00 - 2016-08-03 11:16 - 01732096 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-08-10 18:00 - 2016-08-03 11:15 - 07833088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-08-10 18:00 - 2016-08-03 11:14 - 04895232 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-08-10 18:00 - 2016-08-03 11:14 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 11:13 - 03025920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-08-10 18:00 - 2016-08-03 11:13 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-08-10 18:00 - 2016-08-03 11:12 - 02746368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-08-10 18:00 - 2016-08-03 07:52 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 02921368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-08-10 18:00 - 2016-08-03 07:30 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-08-10 18:00 - 2016-08-03 07:30 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-08-10 18:00 - 2016-08-03 07:30 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-08-10 18:00 - 2016-08-03 06:57 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe 2016-08-10 18:00 - 2016-08-03 06:48 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll 2016-08-10 18:00 - 2016-08-03 06:47 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-08-10 18:00 - 2016-08-03 06:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-08-10 18:00 - 2016-08-03 06:44 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll 2016-08-10 18:00 - 2016-08-03 06:42 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll 2016-08-10 18:00 - 2016-08-03 06:40 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll 2016-08-10 18:00 - 2016-08-03 06:39 - 19351040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-08-10 18:00 - 2016-08-03 06:37 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-08-10 18:00 - 2016-08-03 06:37 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-08-10 18:00 - 2016-08-03 06:35 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2016-08-10 18:00 - 2016-08-03 06:35 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe 2016-08-10 18:00 - 2016-08-03 06:34 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-08-10 18:00 - 2016-08-03 06:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 06:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-08-10 18:00 - 2016-08-03 06:33 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-08-10 18:00 - 2016-08-03 06:33 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-08-10 18:00 - 2016-08-03 06:32 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-08-10 18:00 - 2016-08-03 06:32 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-08-10 18:00 - 2016-08-03 06:31 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-08-10 18:00 - 2016-08-03 06:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2016-08-10 18:00 - 2016-08-03 06:29 - 12133376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-08-10 18:00 - 2016-08-03 06:28 - 03663360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-08-10 18:00 - 2016-08-03 06:25 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-08-10 18:00 - 2016-08-03 06:23 - 05660672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-08-10 18:00 - 2016-08-03 06:23 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-08-10 18:00 - 2016-08-03 06:22 - 02501120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-08-10 18:00 - 2016-08-03 06:22 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-08-10 18:00 - 2016-08-03 06:21 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-08-08 18:24 - 2016-08-08 18:24 - 00001829 _____ C:\Users\Public\Desktop\iTunes.lnk 2016-08-08 18:24 - 2016-08-08 18:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-08-08 18:23 - 2016-08-08 18:23 - 00000000 ____D C:\Program Files (x86)\iTunes 2016-08-08 18:22 - 2016-08-08 18:24 - 00000000 ____D C:\Program Files\iTunes 2016-08-08 18:22 - 2016-08-08 18:22 - 00000000 ____D C:\Program Files\iPod 2016-07-30 10:39 - 2016-07-30 10:41 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Driver Genius (Driver-Soft) 2016-07-30 10:23 - 2016-07-30 10:23 - 00003368 _____ C:\WINDOWS\System32\Tasks\Driver Genius Scheduler 2016-07-30 10:23 - 2016-07-30 10:23 - 00003022 _____ C:\WINDOWS\System32\Tasks\Driver Genius Skip UAC 2016-07-30 10:23 - 2016-07-30 10:23 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\Avanquest Software 2016-07-30 10:22 - 2016-07-30 10:22 - 00001287 _____ C:\Users\Jordan BUH2\Desktop\Driver Genius.lnk 2016-07-30 10:22 - 2016-07-30 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius 2016-07-30 10:22 - 2016-07-30 10:22 - 00000000 ____D C:\Program Files (x86)\Driver-Soft 2016-07-27 17:27 - 2016-07-27 17:27 - 00000424 _____ C:\Users\Jordan BUH2\Desktop\Dieser PC - Verknüpfung.lnk 2016-07-26 10:26 - 2016-07-26 10:26 - 00028466 _____ C:\Users\Jordan BUH2\Desktop\Ihre Spende wurde gesendet - PayPal.htm 2016-07-26 10:26 - 2016-07-26 10:26 - 00000000 ____D C:\Users\Jordan BUH2\Desktop\Ihre Spende wurde gesendet - PayPal-Dateien 2016-07-25 10:30 - 2016-07-25 10:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2016-07-23 10:51 - 2016-07-23 10:51 - 00009702 _____ C:\Users\Jordan BUH2\Desktop\GEORGs DIP MIX.tmd 2016-07-20 18:07 - 2016-07-20 18:05 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-08-18 11:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-08-18 10:51 - 2015-02-10 14:05 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-08-18 10:50 - 2016-01-05 17:36 - 00998344 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-08-18 10:50 - 2015-10-30 20:35 - 03503128 _____ C:\WINDOWS\system32\perfh007.dat 2016-08-18 10:50 - 2015-10-30 20:35 - 00961866 _____ C:\WINDOWS\system32\perfc007.dat 2016-08-18 10:16 - 2014-07-23 16:34 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-08-18 10:09 - 2016-03-17 19:54 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\eM Client 2016-08-18 10:05 - 2016-03-16 19:27 - 00000000 ____D C:\Users\Jordan BUH2 2016-08-17 21:18 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-08-17 18:18 - 2016-03-18 17:35 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Downloads - Medion 2016-08-17 17:36 - 2015-11-13 19:22 - 00000000 ____D C:\ProgramData\SoftMaker 2016-08-17 15:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-08-17 14:48 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-08-17 14:48 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-08-17 14:44 - 2016-03-18 17:33 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\CCleaner 2016-08-17 14:29 - 2016-03-17 14:42 - 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-08-17 14:20 - 2014-05-18 20:13 - 00000000 ____D C:\Users\Jordan BUH2\Documents\VBR Roki 2016-08-17 14:13 - 2013-12-28 15:43 - 00000000 ____D C:\Program Files\Lx_cats 2016-08-17 14:11 - 2016-01-05 18:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-08-17 14:11 - 2016-01-05 17:33 - 00000000 ____D C:\ProgramData\NVIDIA 2016-08-16 18:08 - 2016-03-23 17:21 - 00000000 ____D C:\Onlineüberweisungen 2016-08-16 15:23 - 2016-05-24 11:29 - 00000000 ____D C:\Diakonie Michaelshoven 2016-08-15 17:08 - 2016-01-10 18:55 - 00000000 ____D C:\Café Fuga - WiSü 2016-08-15 14:12 - 2016-03-18 16:11 - 00000000 ____D C:\Users\Jordan BUH2\Desktop\Selten genutzte Desktopverknüpfungen 2016-08-15 13:59 - 2016-03-18 18:15 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Irfan View 2016-08-15 13:05 - 2016-03-30 10:50 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\IrfanView 2016-08-15 12:03 - 2015-10-30 08:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-08-13 11:39 - 2015-10-03 11:19 - 00000000 ____D C:\Program Files\McAfee Security Scan 2016-08-13 11:39 - 2014-06-12 11:19 - 00002016 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2016-08-12 17:24 - 2013-12-06 17:50 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Texte 2016-08-12 13:50 - 2016-06-01 10:34 - 00050032 _____ C:\Users\Jordan BUH2\AppData\Local\GDIPFONTCACHEV1.DAT 2016-08-11 18:01 - 2016-01-05 18:12 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-08-11 17:55 - 2015-10-30 20:47 - 00000000 ____D C:\Program Files\Windows Journal 2016-08-11 17:55 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-08-11 17:55 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-08-11 16:47 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2016-08-11 16:47 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-08-11 16:47 - 2013-11-14 23:39 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-08-11 16:36 - 2013-04-29 11:44 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-08-11 11:42 - 2016-06-01 14:31 - 00258200 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-08-10 18:30 - 2016-03-22 13:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-10 18:05 - 2013-12-06 18:36 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Form 2016-08-10 17:16 - 2016-05-09 14:06 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Softmaker freefont 2016-08-10 17:15 - 2016-03-18 18:13 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Schriften 2016-08-08 18:22 - 2013-12-28 16:26 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-08-04 11:32 - 2015-10-17 15:13 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-07-30 11:11 - 2013-12-06 17:51 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Bilderprint + f. Mails 2016-07-30 10:28 - 2013-12-27 11:47 - 00000000 ____D C:\ProgramData\DriverGenius 2016-07-30 10:22 - 2016-03-16 19:30 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Local\Avanquest 2016-07-28 10:26 - 2013-12-27 14:44 - 00000000 ____D C:\ProgramData\HitmanPro.Alert 2016-07-28 10:24 - 2016-03-22 19:28 - 00000000 ____D C:\Program Files (x86)\HitmanPro.Alert 2016-07-27 14:55 - 2016-03-18 16:22 - 00011465 _____ C:\Users\Jordan BUH2\Desktop\Heizungszähler Mildred 8.xlsx 2016-07-27 11:11 - 2016-03-22 19:28 - 00863888 _____ (SurfRight B.V.) C:\WINDOWS\system32\hmpalert.dll 2016-07-27 11:11 - 2016-03-22 19:28 - 00789136 _____ (SurfRight B.V.) C:\WINDOWS\SysWOW64\hmpalert.dll 2016-07-27 11:11 - 2016-03-22 19:28 - 00245288 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpalert.sys 2016-07-27 11:11 - 2016-03-22 19:28 - 00078256 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpnet.sys 2016-07-25 18:04 - 2016-03-16 19:27 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\Apple Computer 2016-07-20 18:08 - 2014-07-09 14:12 - 00000000 ____D C:\ProgramData\Oracle 2016-07-20 18:07 - 2016-02-05 02:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-07-20 18:07 - 2014-09-12 11:37 - 00000000 ____D C:\Program Files\Java 2016-07-20 18:07 - 2014-03-06 18:03 - 00000000 ____D C:\Program Files (x86)\Java 2016-07-20 18:06 - 2016-03-24 10:36 - 00000000 ____D C:\Users\Jordan BUH2\.oracle_jre_usage 2016-07-20 18:05 - 2016-04-22 11:22 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-07-20 18:04 - 2016-02-05 02:54 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-03-06 13:26 - 2015-03-06 13:26 - 0000057 _____ () C:\ProgramData\Ament.ini 2013-11-30 18:02 - 2015-02-10 17:57 - 0006986 _____ () C:\ProgramData\hpzinstall.log Einige Dateien in TEMP: ==================== C:\Users\Jordan BUH\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\Jordan BUH\AppData\Local\Temp\sqlite3.dll C:\Users\Jordan BUH2\AppData\Local\Temp\HitmanPro_x64.exe C:\Users\Jordan BUH2\AppData\Local\Temp\iv_uninstall.exe C:\Users\Jordan BUH2\AppData\Local\Temp\jre-8u101-windows-au.exe C:\Users\Jordan BUH2\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Jordan BUH2\AppData\Local\Temp\rk.exe C:\Users\Jordan BUH2\AppData\Local\Temp\vlc-2.2.4-win64.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-08-11 16:19 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 17-08-2016 durchgeführt von Jordan BUH2 (18-08-2016 11:35:31) Gestartet von C:\Users\Jordan BUH2\Downloads Windows 10 Pro Version 1511 (X64) (2016-01-05 16:11:40) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-510940551-968253352-1311968580-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-510940551-968253352-1311968580-503 - Limited - Disabled) Gast (S-1-5-21-510940551-968253352-1311968580-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-510940551-968253352-1311968580-1003 - Limited - Enabled) Jordan BUH2 (S-1-5-21-510940551-968253352-1311968580-1005 - Administrator - Enabled) => C:\Users\Jordan BUH2 ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: G DATA INTERNET SECURITY (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: G DATA INTERNET SECURITY (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: G*DATA Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 16.00 (x64) (HKLM\...\7-Zip) (Version: 16.00 - Igor Pavlov) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Apple Application Support (32-Bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) AutoSave Essentials (HKLM-x32\...\{5B59928C-B074-41E0-92CD-FEE1B826369E}) (Version: 3.52.0001 - Avanquest) Avanquest Message (HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\{20573C69-4A68-4BEF-A23D-365CB66924CE}) (Version: 2.05.0 - Avanquest Software) Avanquest update (HKLM-x32\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.34 - Avanquest Software) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.21 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Driver Genius (HKLM-x32\...\Driver Genius_is1) (Version: 16.0 - Driver-Soft Inc.) eM Client (HKLM-x32\...\{7B35918E-43E4-45AF-8F1B-C15D86CA919D}) (Version: 6.0.24928.0 - eM Client Inc.) E-Mail Converter (HKLM-x32\...\E-Mail Converter_is1) (Version: Aktuelle Version - IN MEDIA KG) Eumex RNDIS64 Treiber V1.02 (HKLM\...\{293C4FDD-FB80-48F8-8B40-F085392FDAA1}) (Version: 1.02.0000 - Deutsche Telekom) Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Freemake Video Converter Version 4.1.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.2 - Ellora Assets Corporation) funkwerk Eumex 401 WIN-Tools V1.00 (HKLM-x32\...\InstallShield_{F1C6C824-FF4F-4CD6-9B25-E40F750FC2E8}) (Version: 1.00.0000 - Funkwerk Enterprise Communications GmbH) funkwerk Eumex 401 WIN-Tools V1.00 (x32 Version: 1.00.0000 - Funkwerk Enterprise Communications GmbH) Hidden G DATA INTERNET SECURITY (HKLM-x32\...\{AC68D2FF-1674-4C16-A536-A69FC11BBD82}) (Version: 25.1.0.12 - G DATA Software AG) Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Google+ Auto Backup (HKLM-x32\...\{D1D4D7EA-62B8-4665-9FF7-02A91B925CC9}) (Version: 1.0.18.74 - Google) Hewlett-Packard ACLM.NET v1.1.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HitmanPro.Alert 3 (HKLM\...\HitmanPro.Alert) (Version: 3.5.0.546 - SurfRight B.V.) HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet Pro 8610 - Grundlegende Software für das Gerät (HKLM\...\{C1586445-E3CA-45F0-A754-E6C2784CDDB7}) (Version: 32.3.198.49673 - Hewlett-Packard Co.) HP Officejet Pro 8610 Hilfe (HKLM-x32\...\{2466D8D5-4856-4492-BDEF-48A640F58866}) (Version: 32.0.0 - Hewlett Packard) HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP) HP Product Detection (HKLM-x32\...\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP) HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP) HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) iCloud (HKLM\...\{724A887F-2B55-4306-B6F9-8F0E7A04B1B5}) (Version: 5.2.2.87 - Apple Inc.) IrfanView 64 (remove only) (HKLM\...\IrfanView64) (Version: 4.42 - Irfan Skiljan) iTunes (HKLM\...\{955524E7-79EB-4CA9-BA4D-FD2DF587651B}) (Version: 12.4.3.1 - Apple Inc.) Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation) Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation) K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - ) Lexmark 810 Series (HKLM\...\Lexmark 810 Series) (Version: - Lexmark International, Inc.) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Outlook 2007 (HKLM-x32\...\OUTLOOKR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 48.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 48.0 (x86 de)) (Version: 48.0 - Mozilla) MPC-HC 1.7.0 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.0.7858 - MPC-HC Team) Nero BackItUp (HKLM-x32\...\{0420F95C-11FF-4E02-B967-6CC22B188F9F}) (Version: 5.2.22001 - Nero AG) Nero BackItUp and Burn (HKLM-x32\...\{E08CC458-41FB-4BB5-9B08-2C83DB55A5B9}) (Version: 1.2.0031 - Nero AG) Nero BurnRights (HKLM-x32\...\{397516AE-7DFE-4F90-84E0-BD616D559434}) (Version: 3.6.26001 - Nero AG) Nero Express (HKLM-x32\...\{6C3CF7AC-5AB0-42D9-93C0-68166A57AFB6}) (Version: 9.6.16000 - Nero AG) Nero RescueAgent (HKLM-x32\...\{51E2F9B3-A972-4F58-B4EF-4D9676D9F5D1}) (Version: 2.6.26000 - Nero AG) NVIDIA 3D Vision Controller-Treiber 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 341.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.95 - NVIDIA Corporation) NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation) NVIDIA Grafiktreiber 341.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.95 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) PDF Experte 8 Ultimate (HKLM-x32\...\{FC279721-37A6-4777-AFD8-7A56681EBA14}) (Version: 8.40.1030.10 - Avanquest Software) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Print Gallery 3 (HKLM-x32\...\Print Gallery 3) (Version: - ) Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia) Serif PhotoPlus 10 (HKLM-x32\...\{37598694-FDF5-47BA-9433-AC8416BAD384}) (Version: 10.1.0.20 - Serif (Europe) Ltd) SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden SoftMaker Office 2016 (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB05}) (Version: 16.0.3729 - SoftMaker Software GmbH) SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.5491 - Analog Devices) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden Stellar Phoenix Windows Data Recovery - Professional (HKLM-x32\...\Stellar Phoenix Windows Data Recovery - Professional_is1) (Version: 6.0.0.1 - Stellar Information Technology Pvt Ltd.) Steuer-Spar-Erklärung 2011 (HKLM-x32\...\{9F5FD796-86F0-4360-85F8-D54C0F5411EB}) (Version: 16.19.11 - Akademische Arbeitsgemeinschaft Verlag) Steuer-Spar-Erklärung 2012 (HKLM-x32\...\{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}) (Version: 17.15.11 - Wolters Kluwer Deutschland GmbH) Steuer-Spar-Erklärung 2013 (HKLM-x32\...\{AEB61F7A-4BBA-4292-A096-7893E09034A4}) (Version: 18.11.11 - Wolters Kluwer Deutschland GmbH) SteuerSparErklärung 2014 (HKLM-x32\...\{A463EB06-22A6-47F5-9593-E52B291EF13E}) (Version: 19.14.99 - Akademische Arbeitsgemeinschaft) SteuerSparErklärung 2015 (HKLM-x32\...\{312C0E08-8F94-4536-AAF6-3413F784AC5F}) (Version: 20.38.173 - Akademische Arbeitsgemeinschaft) SteuerSparErklärung 2016 (HKLM-x32\...\{D331D50C-C578-423B-8BC7-94D3133CE315}) (Version: 21.36.103 - Akademische Arbeitsgemeinschaft) Studie zur Verbesserung von HP Officejet Pro 8500 A910 Produkten (HKLM\...\{D7B11BA7-15D3-4E84-8974-20258D4A1701}) (Version: 22.50.231.0 - Hewlett-Packard Co.) Studie zur Verbesserung von HP Officejet Pro 8610 (HKLM\...\{C597CC7C-D465-4761-8516-274F3713FE85}) (Version: 32.3.198.49673 - Hewlett-Packard Co.) TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.354 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.354 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.354 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.171 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_OUTLOOKR_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Verbatim GREEN BUTTON 1.52 (HKLM-x32\...\Verbatim GREEN BUTTON_is1) (Version: - Verbatim) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows-Treiberpaket - T-Home Net (06/30/2010 6.0.6000.16384) (HKLM\...\7B73EBFEF26F2C40D3AA9D389F5CF2C77121106C) (Version: 06/30/2010 6.0.6000.16384 - T-Home) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-510940551-968253352-1311968580-1005_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02F0EB19-31A6-4F30-BFAF-8700F3132C73} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {033C0748-13B5-49F6-88AE-94BDAE38C0DF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {09706E15-D7EE-4524-8453-761ED2BDDFDD} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {0DF43B5F-B86F-4287-9634-A0D2801B5878} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {0F03E94F-8323-430F-8B82-B6FB22332AA5} - System32\Tasks\{BD81C126-4441-479C-87E6-2FCD638656DA} => pcalua.exe -a D:\Setup.EXE -d D:\ Task: {0F5E83A3-007E-4FB7-A2BD-625F420A2C3A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-05] (Piriform Ltd) Task: {12E9D80D-4762-491E-BF80-6AE90A27A748} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2015-06-25] (TuneUp Software) Task: {1878DB26-E0D0-4101-827C-9BB73BB14766} - System32\Tasks\{49772CC1-8E42-4FB7-A3BF-4B25D0933878} => pcalua.exe -a "C:\Users\Jordan BUH\AppData\Local\Temp\NERO02000168\setup.exe" -d C:\Windows\SysWOW64 -c /embed"{117269C3-294D-4B7E-95EB-0792456E38A4}" /hide_splash /hide_progress /runprerequisites"BackItUp,BurnRights,Express,RescueAgent,Common" /l1031 <==== ACHTUNG Task: {1F5FA19E-DE5C-49A7-BA5B-4AD01A75AB59} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {21437EBD-4A26-4C8D-9930-85CE336B947A} - System32\Tasks\{7AB87B53-9FAA-4A20-8435-719089585D1E} => pcalua.exe -a D:\setup.exe -d D:\ Task: {2504409A-B208-4860-A659-3DA22C18EB4C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {2D76E890-492E-4CD8-91E1-D83FD1FE6107} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {3083C145-5766-4151-BAF4-4B2107B0425E} - System32\Tasks\Jordan BUH NBAgent => C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [2010-03-14] (Nero AG) Task: {30F93B05-C5E5-4180-972C-FA3A878E3CED} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {3445288B-BB70-4CE1-9D09-1D73BCC97258} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {4068E13D-31E1-4042-A02D-3005F80D2548} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-06-22] (Oracle Corporation) Task: {44E17834-C883-4A03-BA5A-FD87C20EB3FD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {496F03FC-818E-484D-AF24-12D89D4B99EC} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {54FC9274-ADF7-4AC2-8F18-14D69B861E56} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {58DAB692-D302-4385-8917-47041870D803} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {61F79395-89D8-46B3-BDC7-4F5E6D3757DB} - System32\Tasks\HPCustParticipation HP Officejet Pro 8500 A910 => C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.) Task: {6924130A-89A7-45A8-96A2-7EEAD1ABD365} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-11] (Microsoft Corporation) Task: {694D983B-9598-4D0A-987C-5C2F6F6445CF} - System32\Tasks\HPCustParticipation HP Officejet Pro 8610 => C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP) Task: {6D320FF4-4E5E-4EF3-9245-9511D5499752} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-13] (Adobe Systems Incorporated) Task: {6FD00B60-28B9-499E-91DB-A471939E74A6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {6FF16CC8-EDA7-402A-AA2B-DCA640ECEEB5} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {7E4EFAC3-22A2-4841-8218-12E5BD77F6FB} - System32\Tasks\HP AR Program Upload - 8f76a56ba6ed43aab88b8f0a47e8a3e2d0941de0f8fd4096960aee122c0a193f => C:\Program Files\HP\HP Officejet Pro 8610\bin\HPRewards.exe [2014-07-21] (TODO: <Company name>) Task: {8069DE98-16CA-40F3-AC54-5CF5585BEFFE} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2016-07-08] (Apple Inc.) Task: {8322B41D-1605-4E92-AC46-0806667D8213} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {8755646F-821B-4040-AC81-4543FCFA7F89} - System32\Tasks\Driver Genius Skip UAC => C:\Program Files (x86)\Driver-Soft\DriverGenius\DriverGenius.exe [2016-07-08] (Driver-Soft Inc.) Task: {893B2CEA-D25E-4F56-8FB6-22BE268EA9D3} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {8FA61C5B-9623-4C7C-8F93-D5BAD857C141} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {91E3C423-67B9-4F6C-AA5A-89ABA06F81F0} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {93B9BE18-51D9-4DEA-9772-ED7B4D784838} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {96164F84-5049-411F-B1CB-FAC00A680483} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {9C695646-0AEB-4E65-B6AD-8845AD6AF3C2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {A1A1A548-C840-4D0A-B414-142E9F9343D4} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe Task: {A8F92935-6697-48BF-987B-DA1A037CFE99} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG Task: {B65C5BC2-DA97-4FB7-A6A7-BF811F67C840} - System32\Tasks\HP AR Program Upload - fed3784a90694dd79bb205e4294d28e017bf3843315047da87271e7d90b5b6cc => C:\Program Files\HP\HP Officejet Pro 8610\bin\HPRewards.exe [2014-07-21] (TODO: <Company name>) Task: {B673086B-21B1-451D-9522-6A4414094339} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {B81DF791-95EB-4704-8B25-0DDA3AFFA518} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {B9704044-B377-4DC7-9D45-0195C9628600} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-10-28] (Hewlett-Packard) Task: {BB7789B9-3DD3-442F-8619-F9604388AF91} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {C074218E-68ED-4D3A-B53A-605D7E0CF663} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {C11D20FA-B7E5-46DE-9042-1C0DD9FF7425} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {C3DCBB65-0F99-4DB1-A017-CFF903EB4D7E} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {C5CC9CC1-6C85-4CD0-B3C4-4C7C12878FB9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {C8000DBE-129F-49C0-B5F5-0A1ED90F73B7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {CBC9EF50-1F2A-4A0B-97A4-53B66F918112} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {D43BF3BE-C09E-4C6F-A540-714FB7110927} - System32\Tasks\{199D21ED-B1B8-4D17-86C0-B29B9AC23969} => pcalua.exe -a "C:\Program Files (x86)\XSManager\Uninstaller.exe" Task: {D4CCB735-F0AE-4834-BBA0-5D2B88BD66B0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {D9EC7B73-2E20-4715-AD2B-34E00339B43C} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {DC946FF1-84EC-409A-9C89-AD12F69B0D4A} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {E3F4CD12-4EB5-43D3-996E-F098E26AE135} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe Task: {E4C16DC2-6E86-44A5-88E3-01958EEDD895} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {EEC1443B-DB01-40BE-8864-AC1D55F6D5F3} - System32\Tasks\Driver Genius Scheduler => C:\Program Files (x86)\Driver-Soft\DriverGenius\DriverGenius.exe [2016-07-08] (Driver-Soft Inc.) Task: {F00FDFD0-BF52-43E3-AAE0-48FC9AE55AD1} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {FCC8D11A-7A91-4BBC-916F-7384C358760B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:17 - 2015-10-30 09:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-07-05 15:23 - 2016-07-05 15:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-06-25 07:53 - 2015-06-25 07:53 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2016-02-11 05:43 - 2016-02-11 05:43 - 00387704 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-01-05 17:33 - 2016-01-29 12:49 - 00135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-07-13 14:31 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-07-13 14:31 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-24 11:27 - 2016-05-24 11:27 - 00959168 _____ () C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-01-05 17:13 - 2016-01-05 17:13 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-13 14:32 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-07-13 14:31 - 2016-07-01 05:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-07-13 14:31 - 2016-07-01 05:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-07-13 14:31 - 2016-07-01 05:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-07-13 14:31 - 2016-07-01 05:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-08-05 18:52 - 2016-08-05 18:52 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2016-04-19 11:08 - 2016-04-19 11:16 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-03-30 18:18 - 2015-10-12 05:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-05-24 11:27 - 2016-05-24 11:27 - 00679624 _____ () C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll 2008-09-17 09:40 - 2008-09-17 09:40 - 01725696 _____ () C:\Program Files (x86)\Avanquest\AutoSaveEssentials\BCGPStyle2007Silver.dll 2010-08-06 15:00 - 2010-08-06 15:00 - 00058744 _____ () C:\Program Files (x86)\Avanquest\AutoSaveEssentials\VerifyLicense.dll 2016-05-31 22:01 - 2016-05-31 22:01 - 00134656 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\MailClient.1d52ed9e#\e96243324a7c4382e757f7088088df2b\MailClient.Collections.ni.dll 2016-05-31 22:01 - 2016-05-31 22:01 - 00491520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\MailClient.Mail\0287751dbfb4a91eb5d96e37b50cd420\MailClient.Mail.ni.dll 2016-05-31 22:02 - 2016-05-31 22:02 - 00934400 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\HTMLEditorControl\a21dc3cc036a8ceaa4a5f7772e3b9d8d\HTMLEditorControl.ni.dll 2016-05-31 22:01 - 2016-05-31 22:01 - 00552960 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\LinqBridge\355c9d0ca4c9560daf1d96415fc141b9\LinqBridge.ni.dll 2016-05-31 22:02 - 2016-05-31 22:02 - 00020992 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\MailClient.Interop\4600e088566adcb15be2425cd8eb257c\MailClient.Interop.ni.dll 2016-05-31 22:02 - 2016-05-31 22:02 - 00580096 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\MailClient.Common.UI\aa025cda2f377b8f7506078d3d0a08dc\MailClient.Common.UI.ni.dll 2015-09-23 15:19 - 2015-09-23 15:19 - 00642016 _____ () C:\Program Files (x86)\eM Client\SQLite\x86\sqlite3.dll 2016-05-31 22:02 - 2016-05-31 22:02 - 00097280 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\MailClient.Sasl\71735f4b8ec19e93562b9a06c1ebca9f\MailClient.Sasl.ni.dll 2016-05-31 22:02 - 2016-05-31 22:02 - 00639488 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\HtmlInterop\5e2279927258c98e1c440dd5df1e42f7\HtmlInterop.ni.dll 2016-05-31 22:01 - 2016-05-31 22:01 - 00083456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SystemCoreTimeZone\6489a39434c98cfcfd60baaa04cb01fc\SystemCoreTimeZone.ni.dll 2016-05-31 22:03 - 2016-05-31 22:03 - 01570816 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsAPICodePack\bd93e48d6d3588e0365c9517fdca1def\WindowsAPICodePack.ni.dll 2014-01-07 13:03 - 2011-02-28 10:00 - 03668992 _____ () C:\Program Files (x86)\K-Lite Codec Pack\ffdshow\ffdshow.ax 2009-02-26 13:46 - 2009-02-26 13:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 11:46 - 2011-06-22 11:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2016-04-19 11:08 - 2016-04-19 11:16 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 11:08 - 2016-04-19 11:16 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\TEMP:D5FBE8F9 [181] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2016-08-13 11:39 - 00000871 ____A C:\WINDOWS\system32\Drivers\etc\hosts 0.0.0.1 mssplus.mcafee.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-510940551-968253352-1311968580-1005\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\...\StartupApproved\StartupFolder: => "Control Center.lnk" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "vspdfprsrv.exe" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{A47DA60B-3122-4DC3-A670-6D880A77CDD0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{11E5CB5C-1AAD-4CE9-A932-B9DD6537AFDF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B6BCE8F8-F848-48F0-9F9C-65161088C72C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{ED2E8DF3-79B3-4D90-A9B4-13F9C08C2D15}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0F7DD1CC-1033-4AC9-A40C-BB069771C922}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9711B62B-C816-40A8-A1C0-70EBAD05F99C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{6945A128-E605-44E4-85BB-C03B8A3159AE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{C99C231B-1C99-4778-85D7-AA3B3A0D8924}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{5561FF6D-4F51-4930-A2CF-6A4C1644C997}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{945B701E-AB2D-42E3-85B1-4680C8E78B7D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{BDD75971-22C3-4C14-9A96-73187F6C82B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{5FE59737-84DC-4CAD-B5D8-3C222142C6B9}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{B977729F-F203-4A09-B37E-C8174E4E713A}] => (Allow) LPort=5357 FirewallRules: [{1215FA15-F53F-4379-BDAA-C1AB848620B6}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\Bin\DeviceSetup.exe FirewallRules: [{22DF2118-EC1D-4CF2-987A-4D9AC69E6A04}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\SendAFax.exe FirewallRules: [{BE9C8437-D5D3-4AFC-B5C0-BF3DCD76DA88}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\DigitalWizards.exe FirewallRules: [{DDF90D7D-1A2E-4FF1-9F99-809AEB8E398B}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\FaxApplications.exe FirewallRules: [{B38EC3CD-94F8-4216-94FE-B72FEF5F5D58}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6645A87F-8F1F-4CE1-B57F-4A7D938A8204}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{559073AE-3979-45C6-89CB-F79B84994859}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxbspswx.exe FirewallRules: [{0E6595E9-7888-4428-AAF0-A985B115B2E5}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxbspswx.exe FirewallRules: [{752C24B3-35F3-4EBA-AA86-D04CA20F73A4}] => (Allow) C:\Windows\System32\lxbscoms.exe FirewallRules: [{E709868D-7834-46DF-857C-11814B341279}] => (Allow) C:\Windows\System32\lxbscoms.exe FirewallRules: [{9FBEED3F-415A-4986-87F4-8E90F3D77B2D}] => (Allow) C:\Windows\SysWOW64\lxbscoms.exe FirewallRules: [{73B174D9-1B1A-4D24-BAC5-16D2ED361DBE}] => (Allow) C:\Windows\SysWOW64\lxbscoms.exe FirewallRules: [{9B06B25F-A257-4EBD-AB8A-5908349DF272}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{CFDCA81C-52ED-4009-B091-BB8D8ABC1932}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{B98804FC-C551-4732-A9C1-54ED95431884}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{B84B0494-39AD-4744-94DA-9DF4D8A5C00B}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{0A714B82-6102-4FAB-B807-710D4FD7CE98}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{C71DC4EA-AE1C-479B-8BD1-D4F08FD4A78F}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{E6027A1A-7E32-4C8A-87A2-45E6D196A72B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{2F550B28-846A-4C2C-80C0-3F85DBE8E0B1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{259AE222-BDB6-4624-BCFD-747DF1EAA001}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{0D619857-DF30-48AF-B584-43D66D71EE71}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{B66DD5DB-DC48-4E6B-B39A-9F8BA4AE0E21}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{482BF70C-1DC0-4DBC-A48F-D7D7ED79BDF1}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{02281DC0-7081-4A6C-8BD8-9B37863D6D6C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{E0723386-642C-41DF-A93F-35BD927486E9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{00D7BC25-5ECD-4537-B062-0883F331E88B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{FC13AA84-24DF-4B52-B19F-9C24CBFCCEFD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{9136226F-D5D7-4E50-9A08-15CB67ABB37A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{B8AD818E-CE6A-4EFF-B999-89309EA916C8}] => (Allow) C:\Users\Jordan BUH\AppData\Local\Temp\7zS2870\HPDiagnosticCoreUI.exe FirewallRules: [{C8B285CC-A0FB-4A8D-844E-281977CFFAC1}] => (Allow) C:\Users\Jordan BUH\AppData\Local\Temp\7zS2870\HPDiagnosticCoreUI.exe FirewallRules: [{71C2C069-1A55-4722-A594-3A1A4C7A8F0F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{CA7513E3-40E7-4EF4-B9D7-4CD2167A3E93}] => (Allow) LPort=2869 FirewallRules: [{BC9B82C7-87F4-436D-A877-8AC891E68466}] => (Allow) LPort=1900 FirewallRules: [{D7943FF4-78FB-424F-BAF2-875EC95C34C1}] => (Allow) C:\Users\Jordan BUH2\AppData\Local\Temp\7zS3E62\HPDiagnosticCoreUI.exe FirewallRules: [{6833A69B-C73E-41AA-96BC-93FE0D46665C}] => (Allow) C:\Users\Jordan BUH2\AppData\Local\Temp\7zS3E62\HPDiagnosticCoreUI.exe FirewallRules: [{6EDDD73D-6368-4927-BEEC-3F5FE790ECA8}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Wiederherstellungspunkte ========================= 12-08-2016 13:25:46 Windows-Sicherung 13-08-2016 11:37:37 Windows-Sicherung 15-08-2016 11:46:22 Windows-Sicherung 16-08-2016 14:45:38 Windows-Sicherung 17-08-2016 14:22:34 Windows-Sicherung 18-08-2016 10:08:55 Windows-Sicherung ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (08/18/2016 10:50:55 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/18/2016 10:50:55 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/18/2016 10:50:55 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/18/2016 10:47:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (08/18/2016 10:47:02 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-510940551-968253352-1311968580-1001.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig. . Vorgang: OnIdentify-Ereignis Generatordaten werden gesammelt Kontext: Ausführungskontext: Shadow Copy Optimization Writer Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Generatorname: Shadow Copy Optimization Writer Generatorinstanz-ID: {43ab7c0a-6bc3-4a75-baca-e8b4ddbfee2e} Error: (08/18/2016 10:40:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/18/2016 10:40:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/18/2016 10:40:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/18/2016 10:34:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (08/18/2016 10:34:28 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-510940551-968253352-1311968580-1001.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig. . Vorgang: OnIdentify-Ereignis Generatordaten werden gesammelt Kontext: Ausführungskontext: Shadow Copy Optimization Writer Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Generatorname: Shadow Copy Optimization Writer Generatorinstanz-ID: {43ab7c0a-6bc3-4a75-baca-e8b4ddbfee2e} Systemfehler: ============= Error: (08/18/2016 07:36:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_35dbd" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/18/2016 07:36:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _35dbd" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/18/2016 07:36:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_35dbd" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/18/2016 07:36:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_35dbd" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/17/2016 02:17:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "G DATA Dateisystem Wächter" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (08/17/2016 02:17:19 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (08/17/2016 02:12:54 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (08/17/2016 02:12:50 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (08/17/2016 02:11:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Freemake Improver" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 = Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (08/17/2016 02:11:48 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Freemake Improver erreicht. CodeIntegrity: =================================== Date: 2016-08-11 18:00:54.453 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-26 13:07:01.483 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:07:01.142 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:07:01.035 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:07:00.809 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:07:00.715 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:07:00.646 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:06:57.286 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 13:06:56.160 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2016-07-26 12:46:28.601 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz Prozentuale Nutzung des RAM: 69% Installierter physikalischer RAM: 3965.61 MB Verfügbarer physikalischer RAM: 1215.75 MB Summe virtueller Speicher: 7933.61 MB Verfügbarer virtueller Speicher: 4379.08 MB ==================== Laufwerke ================================ Drive c: (Windows) (Fixed) (Total:691.8 GB) (Free:552.99 GB) NTFS Drive e: (VERBATIM HD) (Fixed) (Total:1863.01 GB) (Free:801.26 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E1452038) Partition 1: (Active) - (Size=6.8 GB) - (Type=27) Partition 2: (Not Active) - (Size=691.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 1863 GB) (Disk ID: CE5B010A) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
18.08.2016, 16:13 | #2 |
| Trojan.Generic.17748374 Hallo,
__________________hier noch das Protokoll von G Data. Code:
ATTFilter Virenprüfung mit G DATA INTERNET SECURITY Version 25.1.0.12 (12.02.2016) Virensignaturen vom 16.08.2016 Startzeit: 17.08.2016 14:15:49 Engine(s): Engine A (AVA 25.7911), Engine B (GD 25.7515) Heuristik: Ein Archive: Ein Systembereiche: Ein RootKits prüfen: Ein Prüfung der Systembereiche... Prüfung aller im Speicher befindlichen Prozesse und Verweise im Autostart... Prüfung aller lokalen Festplatten... Analyse vollständig durchgeführt: 18.08.2016 02:28:28 1032520 Dateien überprüft 1 infizierte Dateien gefunden 0 verdächtige Dateien gefunden Archiv: setup.msi Pfad: C:\Users\Jordan BUH\AppData\Local\Temp\0hoequ3p.i4i Status: Datei in Quarantäne verschoben Virus: Trojan.Generic.17748374 (Engine A) Objekt: (Embedded CAB)=>MicrosoftExchangeWebServicesDataFile In Archiv: C:\Users\Jordan BUH\AppData\Local\Temp\0hoequ3p.i4i\setup.msi Status: Virus gefunden Virus: Trojan.Generic.17748374 Der Zugriff auf die folgenden Dateien wurde verweigert: C:\WINDOWS\CSC\v2.0.6\pq C:\WINDOWS\CSC\v2.0.6\temp\ea-{7d2540ad-4d5f-11e3-bcc0-00219b5e62b7} C:\WINDOWS\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTDiagtrack-Listener.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTWFP-IPsec Diagnostics.etl C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG1 C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG2 C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat{f5cc2126-4d68-11e3-aa81-00219b5e62b7}.TM.blf C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat{f5cc2126-4d68-11e3-aa81-00219b5e62b7}.TMContainer00000000000000000001.regtrans-ms C:\WINDOWS\System32\Microsoft\Protect\Recovery\Recovery.dat{f5cc2126-4d68-11e3-aa81-00219b5e62b7}.TMContainer00000000000000000002.regtrans-ms C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\00aecd79aaaa820cec3d1c23060ff6cc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\00b1c00dd400e62299bb1e4d9c08b734_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\00cbb0947faecc2c7409a7dd512ff397_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\091c69903cf589d9d539d0caf7f0bd2f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0fb202d0bcee4fdcdf5a9c259f7ac954_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10321ce1fd6a2206766546a6a2caa8e7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1068a369574389f078433184fc73314c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1076b357f264b0a82dddcdbebc820ad4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\108f1496ffff7e76aa9a581ffb5ba31c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10f4684b414bf0d58d83aac8d7d36f36_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\114b7d8c1bb7747aa3a368cade3fcde9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1166bb4162bae07d7bfcdb2a938771df_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\119dca948d2b7ede569c1fa06414ac38_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\11f75ee1927ac8850aa9482df61cad60_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\121a31daa1a3a37dd9f762f977585d3d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\122b7a95164811633540afc6b74c8d85_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\123354b3d63cecb32280bea30ccbe014_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\133a47490183ad6df27a213577920dbe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13460fbeed76198b9706ec3912de2efe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\134fd665bf4663b959ab994383fd0c09_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\136e73aff63fb437776e40c5d15989e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13a1faec7f264ffac3a5e5efedae5807_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13aeb23037bf2f7b7e12a0df5f681485_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13c5ef0a891d7c106d176936c692b71b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13ed6e64e74a0a5c062f69651014ae36_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\140a3e516e3e30ac0593fae715019876_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1439461c8871fa268548a33285ed3340_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1472ae3ff7e8594cb437fc87a71f738c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\148cebe2f46e28586034e1f70599585c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\14bb51c610605b7e23092b3af096b6e0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\14de7f52fc75780bf0917fb9bbf4b119_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\152fbc166ee7baa24bef25f2436abeec_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\155b35fe4ac51e5d54001778f4b5d9cc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\16027887822e1b42a2196e3b14409f7d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\16e0e54f0a2515dd807604438c62ca65_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\16f16255fdf1b8ebd155780d9542a682_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1716c1d35393820905d6d29db6595b3a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1754c4d7b5f6b02f6c398668fcdb2007_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1766c5a8cd7ac187015adef9d07c2db7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\177293756fe7e0ad1b268a082dd58771_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1792e733f36760d19570b47dcf1be1fc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\17af97bc6fd01a88282fd287f6592887_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\17e83195d438c9e1805bb8b6f5ee9696_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\180a867de27d67677c3c540d2e164331_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a7767c34e0018c108f59e080619d636_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a7e5f01204133676809ede4323102ea_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a80a7331ba150c39df3ca3e1cd2f8e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1b291b809720586f576372fc7bfbb18e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1b293a023e79ec16a3204746ae3ae04f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1ba83859ffb7b5c14e101748ee557b84_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1ba938873c5b1720d70f652689b39ebc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2068c590b9496b961ec9ebd74cc66d65_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2068c9f3f25ec31fe989d302415be2e4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\20eb2fb5347705c5b6c524a9663211ed_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2122f06583824975a6d6754c80d45788_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\218168808ea204e240d6290f51407f13_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\21d6d1244065ce58fdea84667ec489dc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\21fa2b9a3b1f3ff2da1282f78e2fb7bd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2247a34cefaaf4ef16b142a36e7fa233_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22ccd05a990a9bfb9b9885ef7c3fb908_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22e9e8aff3d13e052fec7cccd06a4047_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\23515011433a10f71b673b2a5bce45be_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\237f79917b8520b69843384755648b35_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2397538abeb53b14931d67c3751174f5_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\23c50c0c3f140e1473dc38bf72ed2a5a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\23ebd29f3a0640bf707133e16e4677f1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\24307b7f26c6ebd83b8809a808f5875a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2eb78f0710eabae0b1ce4fd2240a7a9e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ec2477091cd4054fa43a4e897cd4f9f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ee547fae2f7c01f4ddf1839d54222d3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ef6304cbad7e7d22ac9abde3d31607c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f3d8ee060f7ffb4f6a20f0f68e4bb80_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f4236633b3e2b842b8c1e93fd90d874_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f8b74caef39fe1bafa51a86a43a6363_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2fa961d8ba561bce7badebd3ecd3216d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2fc81eb4755b7986cad84198fc64b017_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2fdafe280086eb093fd2fab59fd5c076_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2fde8d48bcd0fc8fbdf4b2e5f6397e69_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2feca81a773ebe17c2ff55dcfc3647cb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\300fa2a0dd2ed502d84e1d6692ff8fe7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\308753014a9486843b032b7f8b8f7e67_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30c01d0bef1a50408d5295916808e9e1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3642494f9935f4435c528f986d828eed_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3648d65d5cb93183275d0d1a63639c6c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3653c5444b19c5cfe091c6894cb5d1d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3654bbb358568e8efae0836ff0cc421e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\365a50072ef5a224ea104f023f6e597e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3eec04873950a2d30aa25c51643170b6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f11ee2008aa86fe84a57a7ba60f8d2a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f28db417922175b8edb92643102a882_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f5a9bda2388ee0ef8d053498c539000_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f984a8c956469e908d11dfe1eb52257_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3fa2272b7dec0cdd1d6ed7896d645a1f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4252f0637efab5582e8a031e4e86c7e6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\428cb6dbe7535f7d54989380496f9e7f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\43d0d2da024b811819d6073c3312a454_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\43f73e776b5a5a694b023cbe3f85d7a6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\440181a652f7defdec617c6fde917f3a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4431e7648ef2f38d54be310efbe1d4f0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4438ca64b517856aa246624726d87ef2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\447368e8e4808f3b38ed594359f468ca_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4484d01ef6c940caa0f82798a90a7d32_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\450b9c2d17f2f1cdfda6417821a94cf5_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45229a4c6868bb321eb24f498c421df4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4529b0dfd216aa95a245239ffbf3b1df_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4538040edd1d6baab40a6cc905345e67_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\453d1dd0ef59c78e6a31cefa01aa3d51_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\456ed855656a08c670b226ca67f0e515_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45727b0296921d84ade5c67bbbfc103d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4575bd27577cda8113a6331432c6246f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45869aa1230e7647688050f296de9f7c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\458d83bc3cf7ac75625d2f4570e317da_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45998a69703e7cd3d10ad33e69b677ad_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\459cf083615061b714f366b593017718_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\462ce77708ac4279ec708c8d2a864c21_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\466406c55a274a9e225db0708e07a606_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46950f00c262828e51cfa9061f2ecccc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46983cf34a04e70c325e222bc92499ee_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\470df3a9361934fb7c2f7f5fd4bdc23a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4714e2c0f8f0ac9fc5ddbd90d48d6540_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4716e29c5fd5a3b9b9ea92c1bcb6c138_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\479dd6b1524263c09da36f9c48dda99a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\47a81f916c37457878841e8cc61ade4a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\47ad5be87816fbc3db33370c1cd775f7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\47c1c56f326b4aa0df07db24d16e640f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\485ea47ba7cc047c81d7c5d7189e99fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4872d257d832bda8028f78c187cd6456_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4878e924bf7cdf09edb8d07f5522a3e9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4891fd003fd731d25b03ae2ce5aa94f6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48c0d9caf54ceb5e4dc72651897a3a4c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48c56ad4658766d16d9fb9551ef025bf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48cc5a4166e5a5e97e5622701137cd08_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48e770137477e0009c39a7e740e9f922_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\490694136be8d3ba7e7c01d9381868c7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4917af40dbfdd15d5f607a55fbbaf6d0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\49274b151532230fe4200ed63d31be60_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\493a44cdb646e791a58e26be92002e0e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\493c36e7e4306ced1d3840c7d1a54daf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\494e84bb9e1669718fef172ad2fdcc96_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\498f80146d5de3d62c5ba44ff135bca9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\49c5353b1762ff6dd5d65554cf738f80_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\49e83007d314993d3a87a89dc874d908_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\49fdf7e465ea4313fae2719edd589f20_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a1935606abd185bfe417559f9b58db0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a1bf7ccb113777e80ce463505259945_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4d4c65473c02b6f0f0dd06cdf4ec23e1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4d6ee8b085b22b79d544d2ce04b8f150_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4d81fc30a2fbfe5c2126e24d618a78ab_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4db08a77ea652e75505828dd8854ff8a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4dde64c3771089f50da5d0f3dd1a4920_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4ebb1c8e2478a427a84f442485ba261e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4ed33bc69477c550c485fc8c012c52fb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4eed1b5fdede0e3453d6210a8d24895f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4eefff08f76d75ddce52f51561b54d5d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f034a33d7bd3f95e533ab9d86928a80_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f182a9930271adaab7b2af566fb051f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f4c4c5f72424426dd0a0db3b8127430_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4fb5cf5b175377067c46365193e7081d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4fe801d3c88c2550388197473da2e159_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5001872be1758d07eb7f92448c7d7d9a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\500ca5f271f2bec0075645c059df87f9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\504c42464bae4f3014128e9faf08eedd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\507a71e27708eb15a3ff57baac452bd8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50a1580a7c19debff06f5cef27519782_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50ea34095b5cca83966c0d31646ec0bf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50ea472e8275b29a91ec6b8e1ce75202_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50fe02ce787f24694e0d8d3d9e368ec4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5150b0496778d9fc867518aa698dbf89_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5180b030c3f02793e0a096a5b12203cf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\51ccbdd7cb257e5165f9b8233bd5a2cf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\51dd5b3276d2760485c9913a99057b44_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5287c8b587e367ed77e669cbe36dbd7e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\52a5d8ce622c858a57dc51d323d1a3b3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\52b2f0831ec4a908633f8f87c21e51b1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\52bf2fa146f3a7347d220f160e16e508_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\530bd6bd83ff0c8d9825d0a4df9434d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\53addb2dedb23792778115e8951c41d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\543006db32ac74744d5911ea392fa7d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\544805180f1a36646169e494bb977cdf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\544f6a2e724479f36622deafc648ed58_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\545f49b4818abbc82461ed2306205ff4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5470de05840c0ed07055a713bb916ffd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\54f1fdb2e434ab2ab7e73bba6efd8c9c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\54ff86794529a47405b1c2469bf370ce_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\56431cac629fdc90e3b518930c5827d2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\566e11b4b6cce793bda783feb7289e54_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\568eb45d90cbfe05a66b5247c4b985ee_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5740da6d46ed8dde69d8c932a7d810f8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\576795cd76ecf6e80a8a305511f3d424_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\576c63b26920a236eee4197b1a1dfc15_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\577403cf3548ca027be5e9d0a7c88a49_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\579b0d3c9096a01cd922d66a65fcbd7f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\57a92e0c7291c0798a3cb40fa3e993cf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\57eab7bc0d6682f95b27093cba7b7726_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\580ee4d5ede291f2c523ef09c0ae81f2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5828193d1c3546e053ad4a2f3f92ef62_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5831276a71c501c78eab9fb5af34d778_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\584c47908df6408b432f1aa97bf53588_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\588634c37cbf9c34c46e9db6ef232a03_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\597b5c4953a1fc3e565eebcb0598b72d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\597e85c7fda8346437d308d5bf7e3a42_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\59bc6ea889c709177c4cec5fc3753181_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\59eed887b88f574a3b95935fd805ff3e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a24ebf6ed8ee12e167b9093a430ea0a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a86757ed95aa7c4d61db45a48e17515_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a9237ee7e947a7d530e2bba8e15d71c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5ae6f6fb87a657d6f56610109a1c5eda_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5afd73e7f4336f7f25a40a330d9a1244_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5b4edbff8f332d5ec9ed38adfa1ccf9e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5b90eeb682e2e13aeaea58b36df40431_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5bbdd907b5d3c7eeec1ef2f94476c04f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5bc775ffd869b918dc25563b86d6199c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5bd25423db65ddd61811ed1dfc20da97_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5bedbae121a862404d33c976f82670d6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5c1d7c97151e44adceda175351c1e57b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5c22842d1e9349fe26a50b5f8b156aea_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5d5bdb68138c56145bf86d0f3c01600b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5d6b3130b933541638963bcba9a1d92a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5dd60364e731a27c18ef2e0ac54d353d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e0e70531e4281d85cd3ed4dab75886e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e2c0013fd5d03a1460c038f2696d972_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e3a98d4eb24067ea02d4cb62dd36e85_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e45711c19c1a47e3fc5a6248a40dbc3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e6fd59c346a46fc55b31513c04c2586_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5ed98f57ceee7b94705ac00c3115ed64_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5ef778a39d88ceb72f8be42287d03423_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5f4a473513de6d47c138992c8f33278e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5f4c748fe97e99c626be9f9676434814_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5f6e41a1f836ee3474a563db2ca88bc3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5f976097344f846b5e04aa3d77104b0f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5ff6a24da8ca94d32ccd46859eeecee1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\601a40090a79ca80c9a52c0f664d099e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\607ac196ac813ab1c9d425a1de3d170f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\60a169c1a35d6e41625bcff31a8aa0dd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\60a9d5f98eb60b3cd031072d219e6141_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\66292920860008f0ee72fdfab6209963_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\664c3749d2a4ba37be0374b3d8ffecac_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6686bd15a05dbf06f8e4ee6ccbbd81e1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\66d0714c1e21f7b1f8561ac00c689c85_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6739da09abe6fee3dd957ad4b1788168_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\674f66509eacc70297859770a2c6fe15_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\677766e6c4fc7d3009e3f66d6577b682_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\67a84eb3dc1af660a93e00f0c1c3ec95_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\67b58f45d4ba31f2bc91bb3247eace5a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\681e34f7aacba8f2f9b616056bc13cbb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\683e91c639637ac9eec592a752e45d78_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\68684a17e2dc0012f4ad77923a14ab78_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\687a4067102fcd3cf550e57cf8ac3c6d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\689897d55536805480315f34ec558d44_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\68a61bc4275272bd68ea22ead178024f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\690b2e668669f2b572480a50de296028_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6cfbe0f38795940c3db53cadfd4d8ac6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6cfd17bffee47dd31f5dab7376154d19_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6d76b87517b916ed3e0b7a29f7ed5250_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\74be9014c7f64fa05c5994e9e63f0919_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\74bfe23c3948b5d14b06defe74252d52_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\751c73443454022bde99e19c97d70c9c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7552cd5bd9d99dd1f128e8988d961386_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7612d1763d3ef16e58b719e2fd747a98_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\775c62d8e6f5abe2eacb9076f008c6d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\77906da9e541b18dee91a459dac7c2c8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\77e02508ff582734d4c29e055a031fd4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\77e3e58219b3901cde44a521cbdd4ada_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78092965b9ca47a037b3acfd9148fea3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78122b6461914b777c101abdcb7d1b52_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\784d8b277118889669ab5fa68bf25fd6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\788292773b7081c3ff0e37421ea3f2cb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78bbc53e8f848776c3a7170e42763b80_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78e67b7a10424328b8a6236a6e549f6b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7999827a2f56e036abcbd4bb8f44b4a7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a013561b4378b74daf2c2f1cf3e3d3e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a07be2cff45dd2a452cadb2ad1e712e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a3676c20cc01a05bf0c1f94cd54b634_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a84f26106b3000e7e38096cec1505ac_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a8d1a176d68253ccab4484562e747f7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a941e17245df38761018a33d92800ae_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a95de2dcd066d4595785455d4189837_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a9748ece9bb78387d6154a16c202680_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7ad6411882c4628e77d685aedc4d8c0b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7afb181a6e5988ca3a3fd17475061fe0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b00b17ce13ea0cd8f74c0603cb4bc6d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b10daaeb4c428f4940a1bdc63402608_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b359862eb24cb495f3cbd4bb3fa8c78_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b41038586da52c126ec8df71a3f2c9e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7f2f987d03759e6cb93e07923fc69be0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7f96f375b1c17634c6b9904684910888_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7fa7f395a5e17b8ab2d0bfc282610cad_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80676f406c6792457e97009152f31d43_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072478187479463bdcb44fef8988a0e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\808e95884b472b3ac4dfe7417b9eb201_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80c75e2a6d0ce327b5af196914be85e8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\810e733f7da7238c01ec7aad20398dc7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8129ff1278d1244e5b3a3e33508d4f72_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8152b80163b11f757e316e4265c54b0c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8241d822e715f1a62667e3efff513f8a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\825ccab62cc09ed69d0b769eeb633fdc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\825cf424727ef2002c694e08bf99846c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8300be8a37ba103aca48e295c6c48ab8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8304f6bd2c39e5166ccf7969b6119ca2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\831d822318023470d614f6e5d24223b4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\83332898d0a284c8c2c1beefb63ba20d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8335e4d8575a2cce4809613bff9672b3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8360e4e498d5a2b4c3485baea147df37_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8390219da859a50b25701e080c9bdfcb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\83cb2144f55eda4afa7268122ff98065_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8445d1bd237285b7d32ee121fa7b98e9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\84655d727fa5c856ef9afd19fcd91a6f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\846d14664469efb599f6073b0dbb5566_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8470593556d25e57b542d6a27366bcb5_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8476ce41e5158bfb240265f186253a3e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\84a3bbb68de6908a25cc84474ec26d70_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\891c635e23ee3a509c1e9b13b8038bb5_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8db485d01ee42445b7a55eb31df2b083_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8e133666455f80b76fe0c0a8b2fd9e16_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8e253c1e04bcbca3a954079c8d17f7da_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8eb2febcb712ef2e86243065c245173c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8ed65cdb26c7fb6b0136a74779d0d0e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\91cb9e35cc5bfe707139fd9352e8b436_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\91d226e68dad4fcd3b3d2632e29481a1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\91e4e7ea1276f7bdf350de2128a5056c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\91f8afcce6990d4dfdae0d123792be7c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9209bc36886800a54fa3dafd93feb47f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\920ac55af49098fb9bcdda501a7c5be9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92136d1c49a825b0e3a9cc02b905cb37_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92364710ce449efa8b46b9bbf6b720aa_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\924b05bc7e99c51e9f6b1e5ecc0c3e23_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\926b7cd867c1752717150f967bf83542_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92cd5223d5db01a9d6275cb82cfb104c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92f25d5ff9372ae6a46ffe76561fa553_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92fba55d6145444d4d1e5251608e83ce_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\933673035cbd9d1d0b80ddd200d06ada_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9366362f0ab9a3e81aaabc7ee11a6141_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9388439d0091ac04a828f455f272626f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93a93fdf97752e43d552c1fed90fc310_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93a9f67210190f0774bef87a491dfdf3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93b0361b24853061ea267c1a2fd3fbbb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93d24bb9bf254f67c18c312538d2c632_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93df25e6356dc92a852969c1ad4dbe87_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93f49742fb29301a5a51ccd4d8aee8f6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\942fe063fd06d5be66182101f82abbd7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\94372585225aa855b1229c4311b0bf2e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9473818b69e5996da0957c4bbf1de49e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\949c836c051d04da31eb5da3782efd02_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\954520aae0a16c662b71218b3a658daa_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\954e6b129367f1f8c699d4ca9849ddcf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\963dbd68be6a3379e79754907def5a85_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\964d145aa34438aaf7c69e9bc1f39ad8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\96a88e126ab3cca4b8b528ed1a504869_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\96bb27af90a7c55af20f59bf06f2b144_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\96c5e03f1b67af393c2ceaa39f64d9ef_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\96dcfc6fe7b98361fdb9467d9f27e695_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9701c00ac21a65a2db3527bff7c48fb0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\986075e25647f6e9be1b0de06cafffd2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\987da22a311260b6b03ad2f37cc59a33_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\987f707ae70d8032ab6a5c8155500a96_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\989933ac84c60a9a20773b62f14a4893_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\994495551d81a71e16afb1bb7380b48e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\994d645c4cb73a940e55bce4c5d894db_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\99ddb0b05e0e4d3999043f8876095a63_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9a0975039d174aa3e29ff19f2374f24f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9a11fb6249282e78fc0fee772d4414b9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9a4e42b8f89841a76f04dfa399709ee1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9a6e876f69c92ae3c5fef0988a74ae06_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9a707ec3e5240dbddff06e4849569e0a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9b4f7a9e6cb658d258f66c795fa8d6a8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9b6d2c33ceddc394c643a8b297506333_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9bb276a2d7a26a9e8fb5b3f2ef8f1e93_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9be11c9ca8fa9680380539964593c033_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c05a22f39a844837e1cfe943b8e273f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c252d5b96828cafe7f8d57af4bd12ff_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c2d57eedf1f682778db5f5f93969f59_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c2f977ed8aae5daa96bbc43f6899515_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a06455f98a67f7a9ac477ced586e86e6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a092537d70c4774c33ac3559f705b750_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a19307a891cad2553b0fd339520329c4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a19d14a643ec92974c7ead787cd8a308_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a1c77c86e3e7a7863f86d6d6ead4462d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a1ca89da119925ff4773796705573749_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a1d85d8fb187479cf60c91d1d7367ff2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a24b71d2b2093760caa1e12da5f17327_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a28fbfbaa95c1e333480524167cd76fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a34919db345d23b3230e728e20a64484_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a35100360fa00187c27a9032ef263ae2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a39a0255154ffa1d2818aa654413e1eb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a43cb9e2a4d2f9d52af326c308e9d1e1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a43cba8d3dd3210c8719ca50bda34311_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a48c4a15a3cd36f55da1997fa31654b3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a4933b2071dd0b789cc58c82de055b23_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a4bd2720b117eb820ffeebc84687e7e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a4f00f3f7f61aa96384d62e1cfcd65a2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a529982a55ac96e4403e80f8d4f85ba8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a52cb1918b2610e7b82fb4b7039c7e44_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a5d97c05c1851f9ebff1e023bf8c2281_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a656e610d73527f6d2c6504111d416c0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a65ac8bc3b1e3571d0bebde8e792e12f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a66bf37e0353171917fc32e3cf10d827_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a694e5d2a00e64fd0f55fd5f3a31a748_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7a7b9fb2e54d86250a16374802023cf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7acde2cc4d1c34135f2a256e1daccb2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7f913235b624e3d40b7dd30a0bd538e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7fcd1c718f11feb89e59a1e8fd6a5fc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7ff1e949707c8402267c7fb3d7ddc51_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8413c8b5fdff895746e7f985235241e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a84e23a2fe8c0924e209e0aa43c3ae75_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a877996887cc8f1fb38fe7eb1734092e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a88d5eedfe221fb645e06b8c8c7c5967_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8ce6fa5d5203a688521fd88a7289766_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8d5b27406866a9ab45aae7f68ef562f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8dc484c02a255047da889184d04434b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8ffac8324b156f881f139d600ef038b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a9d043428b7fa423c90b94961112c5e7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a9e0bc078a1221309fdac0a10415dc95_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa3ec272adba47bc149a738208a0bc30_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa541e786fedb1a362f6ecfe3781ea0f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa567eaa584e2ac060ff45973fd0ea30_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa66be4314d9b1b8826b474efcb94abe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa86d432317cdb3a3351341aa8d4d07c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa8eed849e14087a4485b9ab8eefa896_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa9e6f75a7050c93986633131a091b54_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aaa3b02de41c12004195ad63cbfd2e6f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aab4f1b07816b2e666c14fc8e31165f2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aaea0b617816cdf090401b4c0c924850_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aaeab81874e4f596f7416087c1a8cf9b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab6bad26b9af21b9e7d0dd386da16ff9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab6d8ddfbcb262228fdf85504d1b88df_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\abbcf7da83a37c0be4eda6c3170724c8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\abcc44ab83b5f09e1655097e06a8ed74_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac03c721ead078fb53d7d796e8350fcb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac4c5c6aea06fde08280055c35aa7e9c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac5f65856d2ff7a713a964b550682f19_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\acb94fc2dd33776fcce1a196163b16e6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\acca1bb9b8a482d8d43a6a0acc8d48f6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\acd3226e5bd2d9bc897170ce6600de27_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ad53cfeb939720d6222086e0a0458505_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ad662bb4f22e3d465b52475089b58d70_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\adaace15975ceff197cadbb745d1d6a8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ade02519ced8a7f01f39924d673cf2bf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\adfe55524f2d89a7af0159d249d189ea_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae562cbf82124ba041cfe086dcecf432_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae6ba9edd39b2a90d2364f85b6c3eaa3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae8ddf87967b05d2a79f21cac36c6fdc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aeb5c2e4d089a3e706ea4e5c995ba8ca_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aedfd2f9e7b3cddf905dcdacebb4170c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aeea861d0044cdfdb01caef2c0113932_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aef5ae07df30c21e46e9add6fe680ca5_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af1e30fec6688e09c3f05179086f1ad3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af3cea0150638f3c8f04998f6ebbb842_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af813cbfde3ce89180a4cc68f311f78e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\afab573ffba16118066b464a8af13fa9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\afbd1c0193ce451b25e641aa43e1e9a2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\afd1559c3845d14e45ac60aef5c8ac2d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0119441427b903e48157459f0ac6812_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b095edf5c7cdaef2cba270af23bc6bea_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0a76af6c22f37bdf0041f76bea0df30_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0e064df2e83e99130cc4d56daf5c2d1_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0ed88b3597339b1779ee7c2712ffd36_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0f12d748e58477b371c47c12113c8de_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1628157554d40ebfdf18e195790f83b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b17c2e4d6b2681ae0680180206646e65_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b19254dc98a0352332c7791a0e35b6e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1a07776e4bf3cd4f92799cb47044018_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1de2f3470033322ee7454f4840e2fef_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1dff0432aecfb596a605e6ae8d156fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b232e42eb9d359aa8209155da30aa855_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b236ccb7f9d157540ca100635472fca9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b2bb92590067649e7f656a6e84465d7e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b2c290e026c2e5de2e03e59a1236e411_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b3068d218673facd9e59c5ad10aa46eb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b356a9d61d532da6e204e35878104dc8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b38dfa7568023ce85221c33c55222b9f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b3d6e7f5790a30240290331764d20fa3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b423cdbebeb77e2cf17c37312c9dc07e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b482a79faa34e3edf36aea72e6a7e605_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b4b4f90e2ffc2ce03e5379b0a6bdb57a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b4c74ae3ef1c567c11dafdfde38983f7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b4fbc848970e7eaaca906072742637db_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5316c3ff3755e33ab5c503ae3bfd81b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b562c991acde3d0c69186c8becb822fd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5e81b1f34f942041e8e4c152d8e6fd3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b66d3863186171e338d35a40fdb1f945_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b6aa82621564a5381a16896360818671_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b6b597d78e338c4de117487dcc37934f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b6f05f4ce4bc4e10cf407bbc3ed8b227_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b72334762cebc395012bb656add7c3e3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b78fa410d413f8aa0a70af319ac8344f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b7b19bc5f7c495639ad4f08568b64945_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b7c656500ea795daf57106bcfa505ea4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b7cc5309aff6ba780886223ce482befc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b94202d7f67d512d3dc94290b5ae6ce7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b94cc30f3d36555ee8ef7aa02a83cb80_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b95cd56cca6e59b3091cf1598d735896_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b96594d66959b193fe4b4c313a755dce_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b97d5a0c7136426128ceb889a7c7d956_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b998470a22b6c32a8aadf6d73a779718_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b9d48aac3c0f9a26b614a45b83ad198f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ba1c6a74072e48f3a0c8e91e33dedd23_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ba4fd2673a0d2e93979428bdf94f19ce_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ba5d9f5f94fdb064b1f723c794f37939_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ba6451e9e7d785672acbe39d905f5b11_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bae19e5796b0851619ece3a83282f42e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c75048cef90bac0c81abb5252c2cb43b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c78fbdf2b647407d1f13dc781fafde6d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c7fe34a9cbe2894d90fdac58e90e37d9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c9f443113b239e6a638cffab2460df1b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c9fbd3750659aa74084dd486c695722f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ca2e9fb0eaa883fa470d87abb25920ed_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ca39a620e9cdc43d59065c386107b9cb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cac09e44f2b230ceccfeec46c5e1716a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cadc9ac86d6a877cfc56e39799b06d6d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cb086720e16ac1dbadb8bfb4a36b99e2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cb2536774078330dccac8f1856a20862_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cbaefeeca2c5ccfc9c7491409c65ce87_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cbedb7aeca72a548ba492f9b8d637e58_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cc03ecf1e9024b3bfcfaac850d4b6e62_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cc5b96135c0217d2c99cc5e53f69c68c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd1914d491d49e65a9392f5ef2a4f23c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd3ad1c36a2c9704aeb013caeb4e2678_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd3c40fa979714d786dbc1e556e92649_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd4608b25c60ac95bc8d7b8e06a923b7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd5288cb4aaed3591a9e8c44f8c4631c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd70fd877c05dc57655b521154016d5f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd799c8b972cc2b0a1f99e8902690eb9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd7e20afe9740ec7f549770de107fc9c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cded4b6651c2371a951e313a0df02442_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cdf236284f2142baf4f1ecd1ae8014e3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cdfd9d3c733fa3331253cb222e368c2d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ce0991242d97948c0100b3d0cb9edacb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ce1c044f48446ec760c4b6dcb1e3d2dc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ce788507a53de772fd001f5a32f3753b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cf386d2e0ab2ff6e18730f5307d5b53a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cf47a07d59257564e99f460114bdbae2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cf5e40592d1ee86a07cfe6c520765eae_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cfe3796cc864dc4581cf78c807c73287_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d7f82088097d417f1a54e543f53a8056_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d888dfc5d89695ebcb2f331c2e98f66f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d8a9417660ec7db457939b98c4a79374_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d8ee85faf4f55d4a8c274d1ad2efcd63_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d9272d564a98016b1083d8c69772fb4d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d934351028e75a7d61058091ae18a5d4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d9677a4ea7390ef0048e550dea3bf057_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d9f95c3bbd411721451f8718f378c01a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da316cba926151cb2287f289213d34e7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da3327b2ae485f82f54ca06b2171428b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da3db17a5c866fca7e936a260061ac78_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da55dc7077f0bcbb2d8d270324f611fc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da671c029f9b0db0d9de48f1e6763502_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dac698b813af11d0ddeeea99e5cf2589_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dad7dcfa4080b381fff285b20d2f888e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\daddabadd8ae581b82cd268a499dd182_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\db351e458f0419c2f72029bdf2ba2f1b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\db4289307519d7b7e3fc8a47020c553a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dc5a48245b11673725f14b8ac50d2370_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dc9385c84dae6469ee0902a0f60b4d3b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dcad9f7873b1865c769581ca85d61052_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de0da90b47af970705f39f222900eee3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de22dffd30049b374dbbf13f2dd7cf2f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de44aac759cd94a2ba0c2d0fa7fff471_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de77bb30407e8dbfba314a8eab5d4fa8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de84f17885df353df4b1b03b08cfadc0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dea5fd90e1be927132de79f572dd382d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\deadde9ab7f43a88fe9ce84671917133_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ded432146ef57f72969e836c36cf78cb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\deeb0cdb607abd4d7d1dbcefb7a56fb7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\defbfb4877acd496643f9baf30d5bcd3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df1d7a859efbecd8ab893a5a424659a4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df3d7997b7c4af27e38d7d66402af7e7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df3ec9da2f16e34a0be46d115557472c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df4e3a70c827119ddbe169298805b076_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e77a782d602a89f1170f85654433ee9e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e79e653817271a3ca244b8e2e509ff66_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e7a0263a2232e3a7afe8a6d1eba189b0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e7b4d68a60309c396a0da3e7cdfd2751_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e816541846f20a75b2acb9cc76e62197_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e83ddef675600a0ff44fdbc60cf4aa42_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8707df1382bc1345311ef3d6febd072_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8a6fdb69e38c09bde1a173921b61beb_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8c3a49da95a4bb322510c575f72eb5d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e914cb62ee8f468f76219afa858e6fd9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e9bb9c0ba32cd97f468161d2ad822611_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ea237d89ebd5457729dcef67d9b86320_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ea6789a036677959ec326e8e50f0128c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb0a0866e6af41fee02274845cf9a757_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb48882ab53e3448d278eb7de32e86a0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb67cfe152dcbfd5576f5e204e8c25fa_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb878a425c0977ac6960fed6a2c777cf_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ebfd422395f736e76b0e44be88694a4a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec062de46de8e7f6366c9627db08a4e4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec511c9c327f5a54ae8a1a1f142a2490_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec99a9fc9a8fb63602d69063a2984bd4_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ecb182c1a9d06bbca8194ce0065b8e21_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ecba96c0dac2321844e989515d2ed9b9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ecd46a08330a1a48bbb2af6b078d8c3f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ece7d2589ca3adf5287fbef6ade72c2b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed0bd58234387dadc66e7bbaeea56b2d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed2584cce366a6e5adbc191f471af5fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed2a70fe90ce60abdd5898daaf24b941_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed60a847c41910886731262d96e4df16_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed70fa45f85fb6b2dba3568293f73aa0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed83cc092c330230e7de97281a7dcbbc_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed8bba5717a209d6a7ee5a32f081756a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed943d4ebf365ef0ec84f3ad5cfb0a84_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edb310fbded2027629671a1b8339cecd_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edced3ac1ba465db09c9c07668f08005_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edd8cd41db749a766a16a0c913e6dc1c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\edea28dd6024e3c7f2d7127e850da9d6_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee1c4abd12b5f9c05d8f2d06b7217e56_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee30c2d95eb4f858b1b48a0082ad3a7f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee51092d4d2563a4c7f693f2f4f7e18c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee6bcbbae4f9f305bcb02ebe0531b3d3_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee90102ff4741ed34dea28a98b9916d2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee96db2efbd95532e8734220953604fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eea46b11f2a37b3a1a283a809ff80151_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ef2d55fbea646c254c543d4a70acdc0c_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ef79a4f1082077e77ce6846cd97d7c6f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\efaa0287905e71fe827fbd70ba11dc4f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eff2466e562ccc8a85878571019b77c9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f0007267fa3f4e027e9f2fe4e49f649f_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f00782c463a7dcc9d9fd69da0323f26d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f01bad0f4bb834590ac0dd4e76d28206_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f0228df192b2e947b4b531321292618e_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f0293a535ec5246693f6c3ac5496a7b0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f04fde4681ee36b85cf015908db4cb1d_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f0cead698cdd800a806a1b2d64a535e7_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1371de69b436457afe6003b13e50162_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f18ce97d40d2b7ce2119175989e0a6fe_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f19ceb585b9c741861d554f455881089_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f19fd974ce2b33bf1055e89424d554d8_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1ac134ce076b8d9942fe6af1378e836_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1e9aba07f69086519125d1e904df4ca_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f259f59dd4abd7535508b7920292384b_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2952e82821ede9741cd8ee2f83a5d25_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2a19588a114e25decb26872b6544b1a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2b0319c92dbf16d776ca67a9f2e0a6a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f364acf197484976a3b07e12458abd3a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f3a53a4ee92d409dca23ea2444d63fa2_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f3ee6490f937cc9135dc25a029a991e0_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f421d1f37337068e037d7a20fd59a9db_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f48fead5f29af8e38aebee859947640a_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f4f0bb31125f5aed223a683dc074bfa9_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f5157ef1666998f39ef5fd5fc36f5062_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ffceb224fb0a4ca0b7e82189acb7bb61_3658fe8a-5728-45d9-80ce-de50582c3d28 C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.PERFTRACKESCALATIONS.xml C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.PERFTRACKPOINTDATA.xml C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.SIUF.xml C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.UIF.xml C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json C:\ProgramData\Microsoft\Diagnosis\SoftLanding\03c64315-0452-4ee7-bf62-1ece46c41f07_withdraw.xml C:\ProgramData\Microsoft\Diagnosis\SoftLanding\084c17b6-bc57-45ad-b172-3071389209a5_show.xml C:\ProgramData\Microsoft\Diagnosis\SoftLanding\084c17b6-bc57-45ad-b172-3071389209a5_withdraw.xml C:\ProgramData\Microsoft\Windows\SystemData\S-1-5-18\ReadOnly\LockScreen_Z\LockScreen___1280_1024_notdimmed.jpg C:\ProgramData\Microsoft\Windows\SystemData\S-1-5-18\ReadOnly\LockScreen_Z\LockScreen___1920_1080_notdimmed.jpg C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\MpScanCache-0.bin C:\System Volume Information\Syscache.hve C:\System Volume Information\Syscache.hve.LOG1 C:\System Volume Information\Syscache.hve.LOG2 C:\System Volume Information\WPSettings.dat C:\System Volume Information\WindowsImageBackup\Catalog\BackupGlobalCatalog C:\System Volume Information\WindowsImageBackup\Catalog\GlobalCatalog C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{03788017-4c49-4beb-9879-41ed2ab022f6} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{07ff8f7d-4d96-4265-a712-72c89e5bddf6} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{1274507c-6e98-45f9-8c96-56ce8906639c} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{12b6f76f-7238-4413-aaa8-18990583a3f3} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{134185b4-7b6d-4047-b68d-67dc7ffa79a4} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{18c9c678-2efb-4c24-b7fe-e8d32db0af5b} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{1e556f82-4f72-41b1-b912-7f7b4433aefe} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{1e558ed4-f258-43bf-a0f8-618f35626041} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{1ea2998a-6fde-41b1-9e6b-67eb04b1da17} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{1fed094d-b247-4fcd-81a7-90de7926aa67} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{2030685c-e4fe-4a89-b461-1ec410b37a7f} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{22c4daf1-21b9-4863-8df2-5dcdf945ca84} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{42ba5e76-826a-4a13-b9cc-95830ccca761} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{4352ff44-33e6-4e0a-a8f7-028585d14a2d} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{4626bef1-54c4-4d3e-bdc8-c1270fd67972} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{468f3669-1f6d-4f38-b096-c15a153bd81d} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{47f8f673-a79a-479b-8e89-c021aad2569c} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{5302a07e-3a34-44d4-b996-52af42155562} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{53366325-ad5d-4376-906b-f4faccf8b143} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{586109f5-7785-452f-8ab2-af05a774b6bf} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{599c84b1-c0eb-429b-90fa-8426c765416b} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{5ee59c03-7684-4b32-9acc-f6b0cf259f35} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{63092b2b-a63d-4f11-af98-f7fac5a10155} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{64b4ce8f-a64c-4549-a07e-b230b121dd83} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{6e67f350-d98d-4ba9-b80b-218570515433} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{77d6b11f-1741-4125-a07a-f31ce6d766d1} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{798ae3eb-db92-4cac-8fbe-7e23246db4a1} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{7f232793-7674-442d-b44a-aa8bdac0d739} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{7f531767-a63e-489e-b0f4-b659cc7c639e} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{80b0a420-ba95-417c-8d1b-aa8b93fb0da7} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{8788634a-bc12-4479-bd2a-a00b5ef1901d} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{8b6c0471-c826-4d5f-b001-24ef61a8f8e9} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{969aa473-9a47-43b8-ab4d-3ea9412ba7ff} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{a0cf9c77-debd-47c5-935b-e79c4c636f95} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{a128daa3-5501-4015-b8e8-5e9b8fa4d7f0} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{a38dc29d-b9e0-49f9-86af-6886e2d823fa} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{b09f082f-f96b-44b1-ab83-abffef25a145} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{b0b50cd0-95f3-444f-8fc9-e0b605ad6178} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{bec7534b-8eab-4b82-879e-3a13d0d2fd05} C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{bf94dfa8-9559-4cd2-bc6a-19dadd096e31} Die folgenden Dateien sind Passwortgeschützt: E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer14x32au_mssd_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer15x32au_mssa_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer16x32au_mssd_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer16x32_mssd_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH\Downloads\install_flashplayer17x32au_mssd_aaa_aih.exe E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH2\Documents\Steuertipps\130129 Steuertipps Ihre Anfrage 1301-2459.msg E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH2\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage 1301-2459.msg E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Jordan BUH2\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage Mail Nr. 2 1301-2459.msg E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Public\Documents\Steuertipps\130129 Steuertipps Ihre Anfrage 1301-2459.msg E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage 1301-2459.msg E:\AutoSave-C-Prog-Benutzer-Win\Latest\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage Mail Nr. 2 1301-2459.msg C:\Users\Jordan BUH\AppData\Local\Mozilla\Firefox\Profiles\zqxi3h73.default\cache2\entries\DA0DC62E4BF31FAE22A3DD9D8FF424E3D08AE419 C:\Users\Jordan BUH\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer14x32au_mssd_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer15x32au_mssa_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer16x32au_mssd_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer16x32_mssd_aaa_aih.exe C:\Users\Jordan BUH\Downloads\install_flashplayer17x32au_mssd_aaa_aih.exe E:\FileHistory\Jordan BUH\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130129 Steuertipps Ihre Anfrage 1301-2459 (2016_02_24 14_47_06 UTC).msg E:\FileHistory\Jordan BUH\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage 1301-2459 (2016_02_24 14_47_06 UTC).msg E:\FileHistory\Jordan BUH\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage Mail Nr. 2 1301-2459 (2016_02_24 14_47_06 UTC).msg E:\FileHistory\Jordan BUH2\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130129 Steuertipps Ihre Anfrage 1301-2459 (2016_04_11 09_11_32 UTC).msg E:\FileHistory\Jordan BUH2\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage Mail Nr. 2 1301-2459 (2016_04_11 09_11_32 UTC).msg E:\FileHistory\Jordan BUH2\JORDANBUH-PC\Data\C\Users\Public\Documents\Steuertipps\130131 Steuertipps Ihre Anfrage 1301-2459 (2016_04_11 09_11_32 UTC).msg E:\JORDANBUH-PC\Backup Set 2016-04-09 202129\Backup Files 2016-04-09 202129\Backup files 15.zip E:\JORDANBUH-PC\Backup Set 2016-04-09 202129\Backup Files 2016-04-15 104407\Backup files 2.zip E:\JORDANBUH-PC\Backup Set 2016-06-20 100325\Backup Files 2016-06-20 100325\Backup files 4.zip E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\Backup\JAN\X0\D\Privat\ESt\2007 - 2009 DATEV\EI-Kanzlei-Rechnungswesen 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\Backup\JAN\X0\D\Privat\ESt\2010\2010_Datev\Deine Unterlagen 2010\Bestand\EI-Kanzlei-Rechnungswesen 327243-10-2010 30102011 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\C\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig\GER\Data1.cab E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\C\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig\GER_\Data1.cab E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\C\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig\GER__\Data1.cab E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\C\Programme\Adobe\Acrobat 7.0\Setup Files\RdrBig707\DEU\Data1.cab E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Outlook\Outlook.pst E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2005\EI-Kanzlei-Rechnungswesen 56563-33333-2005 16092006 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2005\EI-Sicherung von ESt Mandanten-Daten 16092006 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\AV_2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\BILGES2007.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\PN_2007_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\PN_2007_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\Auswertungen 2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\FA 2007\2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\FA 2007\2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\FA 2007\2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007\FA 2007\2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\Bestände Restauswertungen.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\EI-ANLAG 327243-10 25122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\EI-Kanzlei-Rechnungswesen 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von ESt Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von GewSt Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von UStE Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\AV_2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\BILGES2008.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\ESt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\GewSt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\PN_2008_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\PN_2008_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\Auswertungen 2008\UStE Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\FA 2008\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\FA 2008\ESt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\FA 2008\GewSt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2008\FA 2008\UStE Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\AV_2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\BILGES2009.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\ESt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\GewSt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\PN_2009_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\PN_2009_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\Auswertungen 2009\UStE Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\FA 2009\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\FA 2009\ESt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\FA 2009\GewSt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2009\FA 2009\UStE Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2010\2010_Datev\Deine Unterlagen 2010\Bestand\EI-ANLAG 327243-10 30102011 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\ESt\2010\2010_Datev\Deine Unterlagen 2010\Bestand\EI-Kanzlei-Rechnungswesen 327243-10-2010 30102011 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\train it\DATEV\Datev\DESY\EI-DESY-NESY DATEN 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\train it\DATEV\Datev\DESY\EI-DESY-NESY MANDANT 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\train it\ReWe\DATEV\Datev\DESY\EI-DESY-NESY DATEN 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\D\Privat\train it\ReWe\DATEV\Datev\DESY\EI-DESY-NESY MANDANT 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\Desktop\Outlook\Outlook.pst E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2005\EI-Kanzlei-Rechnungswesen 56563-33333-2005 16092006 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2005\EI-Sicherung von ESt Mandanten-Daten 16092006 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\AV_2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\BILGES2007.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\PN_2007_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\PN_2007_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\Auswertungen 2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\FA 2007\2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\FA 2007\2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\FA 2007\2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007\FA 2007\2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\Bestände Restauswertungen.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\EI-ANLAG 327243-10 25122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\EI-Kanzlei-Rechnungswesen 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von ESt Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von GewSt Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2007 - 2009 DATEV\EI-Sicherung von UStE Mandanten-Daten 19122010 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\AV_2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\BILGES2008.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\ESt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\GewSt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\PN_2008_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\PN_2008_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\Auswertungen 2008\UStE Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\FA 2008\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\FA 2008\ESt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\FA 2008\GewSt Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2008\FA 2008\UStE Jordan, Susanne 2008.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\AV_2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\BILGES2009.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\ESt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\GewSt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\PN_2009_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\PN_2009_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\Auswertungen 2009\UStE Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\FA 2009\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\FA 2009\ESt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\FA 2009\GewSt Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2009\FA 2009\UStE Jordan, Susanne 2009.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2010\2010_Datev\Deine Unterlagen 2010\Bestand\EI-ANLAG 327243-10 30102011 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\ESt\2010\2010_Datev\Deine Unterlagen 2010\Bestand\EI-Kanzlei-Rechnungswesen 327243-10-2010 30102011 001.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\train it\DATEV\Datev\DESY\EI-DESY-NESY DATEN 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\train it\DATEV\Datev\DESY\EI-DESY-NESY MANDANT 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\train it\ReWe\DATEV\Datev\DESY\EI-DESY-NESY DATEN 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\Privat\train it\ReWe\DATEV\Datev\DESY\EI-DESY-NESY MANDANT 07012005 005.Z E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\SayO\FA Formulare\USt 2007\Auswertungen 2007\AV_2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\SayO\FA Formulare\USt 2007\Auswertungen 2007\BILGES2007.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\SayO\FA Formulare\USt 2007\Auswertungen 2007\PN_2007_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\D\SayO\FA Formulare\USt 2007\Auswertungen 2007\PN_2007_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\AV_2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\BILGES2007.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\PN_2007_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\PN_2007_02.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\Auswertungen 2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\FA 2007\2007\AW Bescheide ESt + USt 2007.msg E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\FA 2007\2007\GewSt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\FA 2007\2007\ESt Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\PC\USB Sticks Kopien\CORSAIR\ESt u. sayo\FA 2007\2007\UStE Jordan, Susanne 2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\SayO\FA Formulare\USt 2007\Auswertungen 2007\AV_2007.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\SayO\FA Formulare\USt 2007\Auswertungen 2007\BILGES2007.PDF E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\SayO\FA Formulare\USt 2007\Auswertungen 2007\PN_2007_01.pdf E:\Papierkorb C Prog\Sus PC u. Sicherungen\VERBATIM\SayO\FA Formulare\USt 2007\Auswertungen 2007\PN_2007_02.pdf E:\PC DiBurh alt\Datenträger D\Steuertipps\130129 Steuertipps Ihre Anfrage 1301-2459.msg E:\PC DiBurh alt\Datenträger D\Steuertipps\130131 Steuertipps Ihre Anfrage 1301-2459.msg E:\PC DiBurh alt\Datenträger D\Steuertipps\130131 Steuertipps Ihre Anfrage Mail Nr. 2 1301-2459.msg |
19.08.2016, 09:49 | #3 |
/// Malwareteam | Trojan.Generic.17748374Mein Name ist Dennis und ich werde dir bei der Bereinigung helfen. Bitte beachte, dass es ein paar Regeln gibt:
Sollte ich nicht innerhalb von 48h antworten, schreibe mir eine PM! Posten in CODE-Tags Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Los gehts! Ist das ganze Zeugs von Nero lizensiert? Von TuneUp Programmen rate ich ab: https://blog.malwarebytes.com/cyberc...tal-snake-oil/ Schritt # 1: AdwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt # 2: FRST Bitte noch ein frisches FRST-Log. Schritt # 3: Bitte Posten
__________________ |
20.08.2016, 10:57 | #4 |
| Trojan.Generic.17748374 Hallo Dennis, danke für die schnelle Reaktion. Mit AdwCleaner habe ich ein Problem, deshalb habe ich nach dem Suchlauf auch nicht gelöscht. Nach dem Start ist eine Zustimmung zu den Nutzungsbedingungen nicht erforderlich. Die dargestellten Optionen können weder vor noch nach dem Suchlauf gesetzt werden. Was soll ich tun? Hallo, Dass ich den Nutzungsbestimmungen nicht zustimmen musste, lag daran, dass ich nach einer früheren Anwendung den AdwCleaner nicht deinstalliert hatte. Die Oberfläche des aktuellen AdwCleaners (6.000) ist anders gestaltet. Optionen befinden sich nur unter Werkzeuge und da sind unter Löschung nur drei Optionen, nämlich „Tracing Schlüssel“ (hat Häkchen), „Image File Execution Options Schlüssel“ und „Prefetch Dateien“ (beide ohne Häkchen), ansonsten sind nur Wiederherstellungsoptionen vorhanden. Die Bedrohung in der Registrierungsdatenbank wurde gelöscht. Code:
ATTFilter # AdwCleaner v6.000 - Bericht erstellt am 19/08/2016 um 16:04:22 # Aktualisiert am 12/08/2016 von ToolsLib # Datenbank : 2016-08-19.1 [Server] # Betriebssystem : Windows 10 Pro (X64) # Benutzername : Jordan BUH2 - JORDANBUH-PC # Gestartet von : C:\Users\Jordan BUH2\Downloads\AdwCleaner\AdwCleaner_6.000.exe # Modus: Löschen # Unterstützung : https://toolslib.net/forum ***** [ Dienste ] ***** ***** [ Ordner ] ***** ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9} ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [918 Bytes] - [19/08/2016 16:04:22] C:\AdwCleaner\AdwCleaner[S0].txt - [1372 Bytes] - [19/08/2016 16:01:07] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1063 Bytes] ########## Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-08-2016 durchgeführt von Jordan BUH2 (Administrator) auf JORDANBUH-PC (19-08-2016 16:16:46) Gestartet von C:\Users\Jordan BUH2\Downloads\FRST Geladene Profile: Jordan BUH2 (Verfügbare Profile: Jordan BUH2 & DefaultAppPool) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Driver-Soft Inc.) C:\Program Files (x86)\Driver-Soft\DriverGenius\DriverGenius.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avanquest Software) C:\Users\Jordan BUH2\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe (Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Avanquest Software) C:\Program Files (x86)\Avanquest\AutoSaveEssentials\AutoSave Essentials.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe (G DATA Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (SoftMaker Software GmbH) C:\Program Files (x86)\SoftMaker Office 2016\TextMaker.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.486_none_7640e086266ea227\TiWorker.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation) HKLM\...\Run: [LXBSCATS] => rundll32 C:\Windows\system32\spool\DRIVERS\x64\3\LXBStime.dll,RunDLLEntry HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.) HKLM-x32\...\Run: [vspdfprsrv.exe] => C:\Program Files (x86)\Avanquest\PDF Experte 8 Ultimate\vspdfprsrv.exe [6420992 2013-04-15] (Visagesoft) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-07-05] (Apple Inc.) HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AutoSave] => C:\Program Files (x86)\Avanquest\AutoSaveEssentials\Autosave Essentials.exe [1934592 2010-12-03] (Avanquest Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-07-08] (Apple Inc.) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [VLC Updater] => C:\Program Files (x86)\VLC Updater\vlc-updater.exe [370128 2016-06-29] () HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\Run: [Avanquest Message] => C:\Users\Jordan BUH2\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [435944 2016-06-22] (Avanquest Software) HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64" HKU\S-1-5-21-510940551-968253352-1311968580-1005\...\RunOnce: [Uninstall C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jordan BUH2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64" IFEO\backitup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\neroexpress.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Control Center.lnk [2015-01-17] ShortcutTarget: Control Center.lnk -> C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe (Funkwerk Enterprise Communications GmbH) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-11-30] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-13] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-01-21] ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Jordan BUH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8610.lnk [2016-03-01] ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8610.lnk -> C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP) Startup: C:\Users\Jordan BUH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verbatim GREEN BUTTON.lnk [2013-12-10] ShortcutTarget: Verbatim GREEN BUTTON.lnk -> C:\Program Files (x86)\Verbatim GREEN BUTTON\GREEN BUTTON.exe () ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: 0.0.0.1 mssplus.mcafee.com Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{0c4641db-fde4-4ecc-b629-28035eadc701}: [DhcpNameServer] 192.168.1.250 Tcpip\..\Interfaces\{f4e7f8d3-7e08-4745-94fd-cd77276900a5}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-07-20] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-23] (Hewlett-Packard Co.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-20] (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-23] (Hewlett-Packard Co.) FireFox: ======== FF ProfilePath: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default FF DefaultSearchEngine: Startpage (SSL) FF Homepage: hxxps://www.ing-diba.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-13] () FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-20] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-13] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-20] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-29] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-29] (NVIDIA Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\user.js [2016-04-28] FF SearchPlugin: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\searchplugins\ixquick-https.xml [2016-03-18] FF SearchPlugin: C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\searchplugins\startpage-ssl.xml [2016-03-18] FF Extension: WOT - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2016-03-22] FF Extension: DownThemAll! - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-04-15] FF Extension: Bitdefender QuickScan - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2016-04-27] FF Extension: Trafficlight - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\trafficlight@bitdefender.com.xpi [2016-04-27] FF Extension: ImTranslator - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2016-07-20] FF Extension: NoScript - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-10] FF Extension: anonymoX - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\client@anonymox.net.xpi [2016-03-22] FF Extension: Ghostery - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\firefox@ghostery.com.xpi [2016-08-12] FF Extension: Trusted Shops Add-On - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\jid1-PBNne26X1Kn6hQ@jetpack.xpi [2016-05-04] FF Extension: PAYBACK Internet Assistant - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\toolbar-ff@payback.de-sh.xpi [2016-08-12] FF Extension: Adblock Plus - C:\Users\Jordan BUH2\AppData\Roaming\Mozilla\Firefox\Profiles\9lbok5l5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-30] [ist nicht signiert] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2790368 2016-02-18] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe [970872 2016-02-11] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe [4068592 2016-02-18] (G Data Software AG) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-12-09] (Freemake) [Datei ist nicht signiert] R3 GDFwSvc; C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe [3219872 2016-03-04] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [791160 2016-02-18] (G Data Software AG) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [4764304 2016-07-27] (SurfRight B.V.) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-23] (Hewlett-Packard Co.) [Datei ist nicht signiert] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-23] (Hewlett-Packard Co.) [Datei ist nicht signiert] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [327944 2016-07-19] (McAfee, Inc.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2015-06-25] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AutoSave; C:\Windows\System32\DRIVERS\AutoSave.sys [36896 2009-08-13] (Avanquest) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [160768 2016-03-18] (G Data Software AG) S0 GDElam; C:\Windows\System32\DRIVERS\GDElam.sys [117904 2015-01-08] (G Data Software AG) R1 GDKBB; C:\Windows\system32\drivers\GDKBB64.sys [37400 2016-03-18] (G Data Software AG) R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [29720 2016-03-18] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [246272 2016-03-18] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [92160 2016-03-18] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [77848 2016-03-18] (G DATA Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2015-12-28] (G Data Software) S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [46960 2016-05-31] () R3 hmpalert; C:\WINDOWS\system32\drivers\hmpalert.sys [245288 2016-07-27] (SurfRight B.V.) R3 hmpnet; C:\WINDOWS\system32\drivers\hmpnet.sys [78256 2016-07-27] (SurfRight B.V.) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [134656 2016-03-18] (G Data Software AG) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [31144 2015-06-04] (TuneUp Software) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) U3 idsvc; kein ImagePath U3 wpcsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-08-19 15:56 - 2016-08-19 16:04 - 00000000 ____D C:\AdwCleaner 2016-08-18 16:04 - 2016-08-18 16:04 - 736161906 _____ C:\WINDOWS\MEMORY.DMP 2016-08-18 16:04 - 2016-08-18 16:04 - 00296676 _____ C:\WINDOWS\Minidump\081816-29687-01.dmp 2016-08-18 11:42 - 2016-08-18 11:43 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\FRST 2016-08-18 11:32 - 2016-08-19 16:16 - 00000000 ____D C:\FRST 2016-08-15 13:05 - 2016-08-15 13:05 - 00001924 _____ C:\Users\Public\Desktop\IrfanView 64 Thumbnails.lnk 2016-08-15 13:05 - 2016-08-15 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView 2016-08-15 13:04 - 2016-08-15 13:05 - 00000000 ____D C:\Program Files\IrfanView 2016-08-13 11:39 - 2016-08-13 11:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2016-08-10 18:01 - 2016-08-03 12:22 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-08-10 18:01 - 2016-08-03 12:21 - 00566112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-08-10 18:01 - 2016-08-03 12:19 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-08-10 18:01 - 2016-08-03 12:19 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2016-08-10 18:01 - 2016-08-03 11:51 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-08-10 18:01 - 2016-08-03 11:44 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2016-08-10 18:01 - 2016-08-03 11:40 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2016-08-10 18:01 - 2016-08-03 11:31 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe 2016-08-10 18:01 - 2016-08-03 11:29 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-08-10 18:01 - 2016-08-03 11:18 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-08-10 18:01 - 2016-08-03 11:18 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-08-10 18:01 - 2016-08-03 11:16 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2016-08-10 18:01 - 2016-08-03 11:11 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-08-10 18:01 - 2016-08-03 07:34 - 00501592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-08-10 18:01 - 2016-08-03 07:34 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-08-10 18:01 - 2016-08-03 07:33 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-08-10 18:01 - 2016-08-03 06:32 - 12585984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-08-10 18:01 - 2016-08-03 06:32 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2016-08-10 18:01 - 2016-08-03 06:25 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2016-08-10 18:01 - 2016-08-03 06:19 - 02180096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 01505984 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-08-10 18:00 - 2016-08-03 13:14 - 00050368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-08-10 18:00 - 2016-08-03 12:36 - 07469408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-08-10 18:00 - 2016-08-03 12:36 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2016-08-10 18:00 - 2016-08-03 12:36 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2016-08-10 18:00 - 2016-08-03 12:30 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-08-10 18:00 - 2016-08-03 12:23 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-08-10 18:00 - 2016-08-03 12:23 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-08-10 18:00 - 2016-08-03 12:22 - 01322760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-08-10 18:00 - 2016-08-03 12:22 - 00465248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2016-08-10 18:00 - 2016-08-03 12:22 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-08-10 18:00 - 2016-08-03 12:22 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-08-10 18:00 - 2016-08-03 12:21 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-08-10 18:00 - 2016-08-03 12:20 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-08-10 18:00 - 2016-08-03 12:20 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-08-10 18:00 - 2016-08-03 12:13 - 01988448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-08-10 18:00 - 2016-08-03 12:13 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-08-10 18:00 - 2016-08-03 12:13 - 00393056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-08-10 18:00 - 2016-08-03 12:11 - 00422744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-08-10 18:00 - 2016-08-03 11:51 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe 2016-08-10 18:00 - 2016-08-03 11:46 - 22384128 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-08-10 18:00 - 2016-08-03 11:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll 2016-08-10 18:00 - 2016-08-03 11:44 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2016-08-10 18:00 - 2016-08-03 11:43 - 16985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-08-10 18:00 - 2016-08-03 11:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-08-10 18:00 - 2016-08-03 11:41 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll 2016-08-10 18:00 - 2016-08-03 11:40 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2016-08-10 18:00 - 2016-08-03 11:39 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-08-10 18:00 - 2016-08-03 11:39 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll 2016-08-10 18:00 - 2016-08-03 11:38 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-08-10 18:00 - 2016-08-03 11:38 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-08-10 18:00 - 2016-08-03 11:37 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-08-10 18:00 - 2016-08-03 11:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-08-10 18:00 - 2016-08-03 11:36 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-08-10 18:00 - 2016-08-03 11:36 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2016-08-10 18:00 - 2016-08-03 11:35 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-08-10 18:00 - 2016-08-03 11:35 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll 2016-08-10 18:00 - 2016-08-03 11:34 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-08-10 18:00 - 2016-08-03 11:33 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2016-08-10 18:00 - 2016-08-03 11:33 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-08-10 18:00 - 2016-08-03 11:31 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-08-10 18:00 - 2016-08-03 11:31 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 24613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-08-10 18:00 - 2016-08-03 11:30 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 11:29 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-08-10 18:00 - 2016-08-03 11:29 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2016-08-10 18:00 - 2016-08-03 11:29 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-08-10 18:00 - 2016-08-03 11:29 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2016-08-10 18:00 - 2016-08-03 11:28 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 07536640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 01717760 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2016-08-10 18:00 - 2016-08-03 11:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-08-10 18:00 - 2016-08-03 11:20 - 13390336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-08-10 18:00 - 2016-08-03 11:18 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-08-10 18:00 - 2016-08-03 11:17 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-08-10 18:00 - 2016-08-03 11:16 - 03589120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-08-10 18:00 - 2016-08-03 11:16 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-08-10 18:00 - 2016-08-03 11:16 - 01732096 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-08-10 18:00 - 2016-08-03 11:15 - 07833088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-08-10 18:00 - 2016-08-03 11:14 - 04895232 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-08-10 18:00 - 2016-08-03 11:14 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 11:13 - 03025920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-08-10 18:00 - 2016-08-03 11:13 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-08-10 18:00 - 2016-08-03 11:12 - 02746368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-08-10 18:00 - 2016-08-03 07:52 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 02921368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-08-10 18:00 - 2016-08-03 07:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-08-10 18:00 - 2016-08-03 07:30 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-08-10 18:00 - 2016-08-03 07:30 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-08-10 18:00 - 2016-08-03 07:30 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-08-10 18:00 - 2016-08-03 06:57 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe 2016-08-10 18:00 - 2016-08-03 06:48 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll 2016-08-10 18:00 - 2016-08-03 06:47 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-08-10 18:00 - 2016-08-03 06:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-08-10 18:00 - 2016-08-03 06:44 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll 2016-08-10 18:00 - 2016-08-03 06:42 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll 2016-08-10 18:00 - 2016-08-03 06:40 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll 2016-08-10 18:00 - 2016-08-03 06:39 - 19351040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-08-10 18:00 - 2016-08-03 06:37 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-08-10 18:00 - 2016-08-03 06:37 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-08-10 18:00 - 2016-08-03 06:35 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2016-08-10 18:00 - 2016-08-03 06:35 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe 2016-08-10 18:00 - 2016-08-03 06:34 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-08-10 18:00 - 2016-08-03 06:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-08-10 18:00 - 2016-08-03 06:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-08-10 18:00 - 2016-08-03 06:33 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-08-10 18:00 - 2016-08-03 06:33 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-08-10 18:00 - 2016-08-03 06:32 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-08-10 18:00 - 2016-08-03 06:32 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-08-10 18:00 - 2016-08-03 06:31 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-08-10 18:00 - 2016-08-03 06:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2016-08-10 18:00 - 2016-08-03 06:29 - 12133376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-08-10 18:00 - 2016-08-03 06:28 - 03663360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-08-10 18:00 - 2016-08-03 06:25 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-08-10 18:00 - 2016-08-03 06:23 - 05660672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-08-10 18:00 - 2016-08-03 06:23 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-08-10 18:00 - 2016-08-03 06:22 - 02501120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-08-10 18:00 - 2016-08-03 06:22 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-08-10 18:00 - 2016-08-03 06:21 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-08-08 18:24 - 2016-08-08 18:24 - 00001829 _____ C:\Users\Public\Desktop\iTunes.lnk 2016-08-08 18:24 - 2016-08-08 18:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-08-08 18:23 - 2016-08-08 18:23 - 00000000 ____D C:\Program Files (x86)\iTunes 2016-08-08 18:22 - 2016-08-08 18:24 - 00000000 ____D C:\Program Files\iTunes 2016-08-08 18:22 - 2016-08-08 18:22 - 00000000 ____D C:\Program Files\iPod 2016-07-30 10:39 - 2016-07-30 10:41 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Driver Genius (Driver-Soft) 2016-07-30 10:23 - 2016-07-30 10:23 - 00003368 _____ C:\WINDOWS\System32\Tasks\Driver Genius Scheduler 2016-07-30 10:23 - 2016-07-30 10:23 - 00003022 _____ C:\WINDOWS\System32\Tasks\Driver Genius Skip UAC 2016-07-30 10:23 - 2016-07-30 10:23 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\Avanquest Software 2016-07-30 10:22 - 2016-07-30 10:22 - 00001287 _____ C:\Users\Jordan BUH2\Desktop\Driver Genius.lnk 2016-07-30 10:22 - 2016-07-30 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius 2016-07-30 10:22 - 2016-07-30 10:22 - 00000000 ____D C:\Program Files (x86)\Driver-Soft 2016-07-27 17:27 - 2016-07-27 17:27 - 00000424 _____ C:\Users\Jordan BUH2\Desktop\Dieser PC - Verknüpfung.lnk 2016-07-26 10:26 - 2016-07-26 10:26 - 00028466 _____ C:\Users\Jordan BUH2\Desktop\Ihre Spende wurde gesendet - PayPal.htm 2016-07-26 10:26 - 2016-07-26 10:26 - 00000000 ____D C:\Users\Jordan BUH2\Desktop\Ihre Spende wurde gesendet - PayPal-Dateien 2016-07-25 10:30 - 2016-07-25 10:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2016-07-23 10:51 - 2016-07-23 10:51 - 00009702 _____ C:\Users\Jordan BUH2\Desktop\GEORGs DIP MIX.tmd 2016-07-20 18:07 - 2016-07-20 18:05 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-08-19 16:08 - 2015-11-13 19:22 - 00000000 ____D C:\ProgramData\SoftMaker 2016-08-19 16:06 - 2016-01-05 18:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-08-19 16:06 - 2016-01-05 17:33 - 00000000 ____D C:\ProgramData\NVIDIA 2016-08-19 16:06 - 2013-12-27 14:44 - 00000000 ____D C:\ProgramData\HitmanPro.Alert 2016-08-19 16:05 - 2015-10-30 08:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-08-19 15:56 - 2016-05-23 14:11 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\AdwCleaner 2016-08-19 15:51 - 2015-02-10 14:05 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-08-19 15:35 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-08-19 14:00 - 2016-03-17 19:54 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\eM Client 2016-08-19 11:51 - 2016-01-05 17:36 - 01007716 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-08-19 11:51 - 2015-10-30 20:35 - 03534032 _____ C:\WINDOWS\system32\perfh007.dat 2016-08-19 11:51 - 2015-10-30 20:35 - 00970902 _____ C:\WINDOWS\system32\perfc007.dat 2016-08-19 11:34 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-08-18 16:32 - 2016-03-18 17:34 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\G-Data 2016-08-18 16:08 - 2014-02-19 10:12 - 00000000 ____D C:\Users\Jordan BUH2\Infiz.Verdacht 2016-08-18 16:04 - 2016-01-30 11:11 - 00000000 ____D C:\WINDOWS\Minidump 2016-08-18 13:40 - 2016-03-16 19:27 - 00000000 ____D C:\Users\Jordan BUH2 2016-08-18 10:16 - 2014-07-23 16:34 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-08-17 21:18 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-08-17 18:18 - 2016-03-18 17:35 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Downloads - Medion 2016-08-17 15:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-08-17 14:48 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-08-17 14:44 - 2016-03-18 17:33 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\CCleaner 2016-08-17 14:29 - 2016-03-17 14:42 - 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-08-17 14:20 - 2014-05-18 20:13 - 00000000 ____D C:\Users\Jordan BUH2\Documents\VBR Roki 2016-08-17 14:13 - 2013-12-28 15:43 - 00000000 ____D C:\Program Files\Lx_cats 2016-08-16 18:08 - 2016-03-23 17:21 - 00000000 ____D C:\Onlineüberweisungen 2016-08-16 15:23 - 2016-05-24 11:29 - 00000000 ____D C:\Diakonie Michaelshoven 2016-08-15 17:08 - 2016-01-10 18:55 - 00000000 ____D C:\Café Fuga - WiSü 2016-08-15 14:12 - 2016-03-18 16:11 - 00000000 ____D C:\Users\Jordan BUH2\Desktop\Selten genutzte Desktopverknüpfungen 2016-08-15 13:59 - 2016-03-18 18:15 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Irfan View 2016-08-15 13:05 - 2016-03-30 10:50 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\IrfanView 2016-08-13 11:39 - 2015-10-03 11:19 - 00000000 ____D C:\Program Files\McAfee Security Scan 2016-08-13 11:39 - 2014-06-12 11:19 - 00002016 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2016-08-12 17:24 - 2013-12-06 17:50 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Texte 2016-08-12 13:50 - 2016-06-01 10:34 - 00050032 _____ C:\Users\Jordan BUH2\AppData\Local\GDIPFONTCACHEV1.DAT 2016-08-11 18:01 - 2016-01-05 18:12 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-08-11 17:55 - 2015-10-30 20:47 - 00000000 ____D C:\Program Files\Windows Journal 2016-08-11 17:55 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-08-11 17:55 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-08-11 16:47 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2016-08-11 16:47 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-08-11 16:47 - 2013-11-14 23:39 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-08-11 16:36 - 2013-04-29 11:44 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-08-11 11:42 - 2016-06-01 14:31 - 00258200 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-08-10 18:30 - 2016-03-22 13:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-10 18:05 - 2013-12-06 18:36 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Form 2016-08-10 17:16 - 2016-05-09 14:06 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Softmaker freefont 2016-08-10 17:15 - 2016-03-18 18:13 - 00000000 ____D C:\Users\Jordan BUH2\Downloads\Schriften 2016-08-08 18:22 - 2013-12-28 16:26 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-08-04 11:32 - 2015-10-17 15:13 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-07-30 11:11 - 2013-12-06 17:51 - 00000000 ____D C:\Users\Jordan BUH2\Documents\Bilderprint + f. Mails 2016-07-30 10:28 - 2013-12-27 11:47 - 00000000 ____D C:\ProgramData\DriverGenius 2016-07-30 10:22 - 2016-03-16 19:30 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Local\Avanquest 2016-07-28 10:24 - 2016-03-22 19:28 - 00000000 ____D C:\Program Files (x86)\HitmanPro.Alert 2016-07-27 14:55 - 2016-03-18 16:22 - 00011465 _____ C:\Users\Jordan BUH2\Desktop\Heizungszähler Mildred 8.xlsx 2016-07-27 11:11 - 2016-03-22 19:28 - 00863888 _____ (SurfRight B.V.) C:\WINDOWS\system32\hmpalert.dll 2016-07-27 11:11 - 2016-03-22 19:28 - 00789136 _____ (SurfRight B.V.) C:\WINDOWS\SysWOW64\hmpalert.dll 2016-07-27 11:11 - 2016-03-22 19:28 - 00245288 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpalert.sys 2016-07-27 11:11 - 2016-03-22 19:28 - 00078256 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpnet.sys 2016-07-25 18:04 - 2016-03-16 19:27 - 00000000 ____D C:\Users\Jordan BUH2\AppData\Roaming\Apple Computer 2016-07-20 18:08 - 2014-07-09 14:12 - 00000000 ____D C:\ProgramData\Oracle 2016-07-20 18:07 - 2016-02-05 02:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-07-20 18:07 - 2014-09-12 11:37 - 00000000 ____D C:\Program Files\Java 2016-07-20 18:07 - 2014-03-06 18:03 - 00000000 ____D C:\Program Files (x86)\Java 2016-07-20 18:06 - 2016-03-24 10:36 - 00000000 ____D C:\Users\Jordan BUH2\.oracle_jre_usage 2016-07-20 18:05 - 2016-04-22 11:22 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2016-07-20 18:04 - 2016-02-05 02:54 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-03-06 13:26 - 2015-03-06 13:26 - 0000057 _____ () C:\ProgramData\Ament.ini 2013-11-30 18:02 - 2015-02-10 17:57 - 0006986 _____ () C:\ProgramData\hpzinstall.log Einige Dateien in TEMP: ==================== C:\Users\Jordan BUH\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\Jordan BUH\AppData\Local\Temp\sqlite3.dll C:\Users\Jordan BUH2\AppData\Local\Temp\HitmanPro_x64.exe C:\Users\Jordan BUH2\AppData\Local\Temp\iv_uninstall.exe C:\Users\Jordan BUH2\AppData\Local\Temp\jre-8u101-windows-au.exe C:\Users\Jordan BUH2\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Jordan BUH2\AppData\Local\Temp\libeay32.dll C:\Users\Jordan BUH2\AppData\Local\Temp\msvcr120.dll C:\Users\Jordan BUH2\AppData\Local\Temp\rk.exe C:\Users\Jordan BUH2\AppData\Local\Temp\sqlite3.dll C:\Users\Jordan BUH2\AppData\Local\Temp\vlc-2.2.4-win64.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-08-11 16:19 ==================== Ende von FRST.txt ============================ Code:
ATTFilter # AdwCleaner v6.000 - Bericht erstellt am 19/08/2016 um 16:01:07 # Aktualisiert am 12/08/2016 von ToolsLib # Datenbank : 2016-08-19.1 [Server] # Betriebssystem : Windows 10 Pro (X64) # Benutzername : Jordan BUH2 - JORDANBUH-PC # Gestartet von : C:\Users\Jordan BUH2\Downloads\AdwCleaner\AdwCleaner_6.000.exe # Modus: Suchlauf # Unterstützung : https://toolslib.net/forum ***** [ Dienste ] ***** Keine schädlichen Dienste gefunden. ***** [ Ordner ] ***** Keine schädlichen Ordner gefunden. ***** [ Dateien ] ***** Keine schädlichen Dateien gefunden. ***** [ DLL ] ***** Keine infizierten DLLs gefunden. ***** [ WMI ] ***** Keine schädlichen Schlüssel gefunden. ***** [ Verknüpfungen ] ***** Keine infizierten Verknüpfungen gefunden. ***** [ Aufgabenplanung ] ***** Keine schädlichen Aufgaben gefunden. ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9} ***** [ Internetbrowser ] ***** Keine schädlichen Elemente in Firefox basierten Browsern gefunden. Keine schädlichen Elemente in Chrome basierten Browsern gefunden. ************************* C:\AdwCleaner\AdwCleaner[S0].txt - [1220 Bytes] - [19/08/2016 16:01:07] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1293 Bytes] ########## |
22.08.2016, 07:56 | #5 | |
/// Malwareteam | Trojan.Generic.17748374 Hi, Zitat:
Code:
ATTFilter Task: {1878DB26-E0D0-4101-827C-9BB73BB14766} - System32\Tasks\{49772CC1-8E42-4FB7-A3BF-4B25D0933878} => pcalua.exe -a "C:\Users\Jordan BUH\AppData\Local\Temp\NERO02000168\setup.exe" -d C:\Windows\SysWOW64 |
22.08.2016, 09:45 | #6 |
| Trojan.Generic.17748374 Hallo Dennis, was besagt denn diese Zeile "Task ..." aus? Ich bin reiner PC-Nutzer und kenne mich damit nicht aus. Vielen Dank für die schnelle Unterstützung, offensichtlich scheint mein PC ja nicht durch Viren oder einen Trojaner befallen zu sein, bis auf einen gefährdenden Registrierungsschlüssel, der ja durch AdwCleaner gelöscht wurde. MfG |
22.08.2016, 09:50 | #7 |
/// Malwareteam | Trojan.Generic.17748374 Hi, Windows bietet an, dass es gewisse Sachen regelmäßig macht mit Tasks. How to start and create basic tasks with Task Scheduler Ist aber für die normale Benutzung nicht wichtig |
22.08.2016, 10:12 | #8 |
| Trojan.Generic.17748374 Nochmals besten Dank |
22.08.2016, 10:44 | #9 |
/// Malwareteam | Trojan.Generic.17748374 Gerne gerne |
Themen zu Trojan.Generic.17748374 |
.dll, bonjour, converter, cpu, defender, desktop, explorer, firefox, firewall, flash player, homepage, internet, launch, mozilla, neustart, office 2016, officejet, performance, prozesse, registry, rundll, security, services.exe, software, system, virus, vlc updater, windows, windowsapps, winlogon.exe |