kupferdach | 10.04.2017 15:24 | Frst als Admin Teil 3 Code:
2017-03-16 10:27 - 2017-03-04 09:35 - 00378720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-03-16 10:27 - 2017-03-04 09:35 - 00343904 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-03-16 10:27 - 2017-03-04 09:35 - 00315232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-03-16 10:27 - 2017-03-04 09:35 - 00242528 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-03-16 10:27 - 2017-03-04 09:35 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-03-16 10:27 - 2017-03-04 09:35 - 00086368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-03-16 10:27 - 2017-03-04 09:35 - 00038240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-03-16 10:27 - 2017-03-04 09:25 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2017-03-16 10:27 - 2017-03-04 09:24 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-03-16 10:27 - 2017-03-04 09:24 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-03-16 10:27 - 2017-03-04 09:24 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2017-03-16 10:27 - 2017-03-04 09:22 - 01354312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-03-16 10:27 - 2017-03-04 09:22 - 01172984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-03-16 10:27 - 2017-03-04 09:21 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-03-16 10:27 - 2017-03-04 09:20 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2017-03-16 10:27 - 2017-03-04 09:20 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-03-16 10:27 - 2017-03-04 09:18 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-03-16 10:27 - 2017-03-04 09:15 - 00404320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2017-03-16 10:27 - 2017-03-04 09:13 - 00635456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-03-16 10:27 - 2017-03-04 09:11 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-03-16 10:27 - 2017-03-04 09:09 - 00578392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-03-16 10:27 - 2017-03-04 09:09 - 00178520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-03-16 10:27 - 2017-03-04 09:08 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-03-16 10:27 - 2017-03-04 09:08 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-03-16 10:27 - 2017-03-04 09:08 - 00342456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 02446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-03-16 10:27 - 2017-03-04 09:07 - 00989016 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-03-16 10:27 - 2017-03-04 09:07 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-03-16 10:27 - 2017-03-04 09:07 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-03-16 10:27 - 2017-03-04 09:07 - 00682808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2017-03-16 10:27 - 2017-03-04 09:07 - 00110944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2017-03-16 10:27 - 2017-03-04 09:07 - 00080224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2017-03-16 10:27 - 2017-03-04 09:03 - 04674360 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-03-16 10:27 - 2017-03-04 09:03 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-03-16 10:27 - 2017-03-04 09:03 - 00038768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2017-03-16 10:27 - 2017-03-04 09:01 - 00201568 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2017-03-16 10:27 - 2017-03-04 09:01 - 00128648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2017-03-16 10:27 - 2017-03-04 08:59 - 01570208 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-03-16 10:27 - 2017-03-04 08:58 - 01416224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-03-16 10:27 - 2017-03-04 08:58 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-03-16 10:27 - 2017-03-04 08:58 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2017-03-16 10:27 - 2017-03-04 08:57 - 00372432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-03-16 10:27 - 2017-03-04 08:42 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-03-16 10:27 - 2017-03-04 08:37 - 00025088 _____ C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-03-16 10:27 - 2017-03-04 08:36 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2017-03-16 10:27 - 2017-03-04 08:36 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-03-16 10:27 - 2017-03-04 08:36 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-03-16 10:27 - 2017-03-04 08:34 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-03-16 10:27 - 2017-03-04 08:34 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfui.dll
2017-03-16 10:27 - 2017-03-04 08:34 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2017-03-16 10:27 - 2017-03-04 08:33 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2017-03-16 10:27 - 2017-03-04 08:33 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-03-16 10:27 - 2017-03-04 08:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2017-03-16 10:27 - 2017-03-04 08:33 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
2017-03-16 10:27 - 2017-03-04 08:33 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInputUap.dll
2017-03-16 10:27 - 2017-03-04 08:32 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2017-03-16 10:27 - 2017-03-04 08:32 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-03-16 10:27 - 2017-03-04 08:32 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-03-16 10:27 - 2017-03-04 08:32 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-03-16 10:27 - 2017-03-04 08:32 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-03-16 10:27 - 2017-03-04 08:31 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-03-16 10:27 - 2017-03-04 08:31 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscandui.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
2017-03-16 10:27 - 2017-03-04 08:30 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-03-16 10:27 - 2017-03-04 08:29 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-03-16 10:27 - 2017-03-04 08:29 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-03-16 10:27 - 2017-03-04 08:28 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-03-16 10:27 - 2017-03-04 08:27 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-03-16 10:27 - 2017-03-04 08:26 - 00643072 _____ (Microsoft Corporation) C:\WINDOWS\system32\main.cpl
2017-03-16 10:27 - 2017-03-04 08:26 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2017-03-16 10:27 - 2017-03-04 08:26 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-03-16 10:27 - 2017-03-04 08:26 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-03-16 10:27 - 2017-03-04 08:26 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-03-16 10:27 - 2017-03-04 08:26 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-03-16 10:27 - 2017-03-04 08:25 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2017-03-16 10:27 - 2017-03-04 08:25 - 01016320 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2017-03-16 10:27 - 2017-03-04 08:25 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 01092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2017-03-16 10:27 - 2017-03-04 08:24 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2017-03-16 10:27 - 2017-03-04 08:23 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2017-03-16 10:27 - 2017-03-04 08:23 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-03-16 10:27 - 2017-03-04 08:23 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-03-16 10:27 - 2017-03-04 08:23 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-03-16 10:27 - 2017-03-04 08:23 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-03-16 10:27 - 2017-03-04 08:22 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-03-16 10:27 - 2017-03-04 08:22 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-03-16 10:27 - 2017-03-04 08:21 - 00776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabletPC.cpl
2017-03-16 10:27 - 2017-03-04 08:21 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-03-16 10:27 - 2017-03-04 08:20 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-03-16 10:27 - 2017-03-04 08:20 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-03-16 10:27 - 2017-03-04 08:20 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-03-16 10:27 - 2017-03-04 08:20 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2017-03-16 10:27 - 2017-03-04 08:20 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-03-16 10:27 - 2017-03-04 08:19 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-03-16 10:27 - 2017-03-04 08:19 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-03-16 10:27 - 2017-03-04 08:19 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabcal.exe
2017-03-16 10:27 - 2017-03-04 08:18 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2017-03-16 10:27 - 2017-03-04 08:18 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2017-03-16 10:27 - 2017-03-04 08:17 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-03-16 10:27 - 2017-03-04 08:17 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2017-03-16 10:27 - 2017-03-04 08:16 - 03289088 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-03-16 10:27 - 2017-03-04 08:16 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-03-16 10:27 - 2017-03-04 08:16 - 00583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2017-03-16 10:27 - 2017-03-04 08:15 - 09130496 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-03-16 10:27 - 2017-03-04 08:15 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-03-16 10:27 - 2017-03-04 08:15 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-03-16 10:27 - 2017-03-04 08:14 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-03-16 10:27 - 2017-03-04 08:14 - 01562112 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2017-03-16 10:27 - 2017-03-04 08:14 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-03-16 10:27 - 2017-03-04 08:14 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-03-16 10:27 - 2017-03-04 08:14 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2017-03-16 10:27 - 2017-03-04 08:14 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2017-03-16 10:27 - 2017-03-04 08:13 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-03-16 10:27 - 2017-03-04 08:13 - 00961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2017-03-16 10:27 - 2017-03-04 08:13 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2017-03-16 10:27 - 2017-03-04 08:13 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2017-03-16 10:27 - 2017-03-04 08:13 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MultiDigiMon.exe
2017-03-16 10:27 - 2017-03-04 08:12 - 01692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-03-16 10:27 - 2017-03-04 08:12 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-03-16 10:27 - 2017-03-04 08:11 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-03-16 10:27 - 2017-03-04 08:11 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-03-16 10:27 - 2017-03-04 08:11 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-03-16 10:27 - 2017-03-04 08:11 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-03-16 10:27 - 2017-03-04 08:11 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2017-03-16 10:27 - 2017-03-04 08:11 - 00818176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-03-16 10:27 - 2017-03-04 08:10 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-03-16 10:27 - 2017-03-04 08:10 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-03-16 10:27 - 2017-03-04 08:10 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-03-16 10:27 - 2017-03-04 08:10 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-03-16 10:27 - 2017-03-04 08:10 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-03-16 10:27 - 2017-03-04 08:09 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-03-16 10:27 - 2017-03-04 08:08 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2017-03-16 10:27 - 2017-03-04 08:08 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 02914816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-03-16 10:27 - 2017-03-04 08:07 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 04060672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 03614720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-03-16 10:27 - 2017-03-04 08:06 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-03-16 10:27 - 2017-03-04 08:06 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2017-03-16 10:27 - 2017-03-04 08:05 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-03-16 10:27 - 2017-03-04 08:05 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2017-03-16 10:27 - 2017-03-04 08:04 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2017-03-16 10:27 - 2017-03-04 08:03 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-03-16 10:27 - 2017-03-04 08:01 - 03478528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2017-03-16 10:27 - 2016-07-16 04:29 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CspCellularSettings.dll
2017-03-16 10:27 - 2016-07-16 04:28 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-03-16 10:27 - 2016-07-16 04:26 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CfgSPCellular.dll
2017-03-16 10:26 - 2017-03-04 08:35 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-03-16 10:26 - 2017-03-04 08:26 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-03-16 10:25 - 2016-05-29 20:38 - 08886976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSetup.exe
2017-03-16 08:56 - 2017-04-04 18:35 - 00653072 _____ C:\Users\Wolfgang\Downloads\alNgAhGQG7UByuww5TtPP6v6ifRV4+vqjyzeOU+AyOuWZp+FxLRS5AZwUptr1MVYf-0Q0YhrNRUURf2byxNfhmuoGpICYgR1er2+YUxFitg=.B97CE01B9A4E2DAE5F93.no_more_ransom
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-04-10 16:06 - 2016-01-19 21:12 - 00000000 ____D C:\Users\Admin\AppData\Local\MicrosoftEdge
2017-04-10 16:06 - 2014-09-17 17:58 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2017-04-10 16:05 - 2016-12-17 20:17 - 00000000 ____D C:\Users\Admin\AppData\Local\ConnectedDevicesPlatform
2017-04-10 16:05 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Admin
2017-04-10 16:04 - 2016-10-09 10:48 - 00000000 ____D C:\Program Files\AMD
2017-04-10 16:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-04-10 16:04 - 2016-01-18 19:29 - 00000000 ____D C:\ProgramData\AMD
2017-04-10 16:04 - 2014-09-13 17:04 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages
2017-04-10 16:04 - 2014-09-12 11:12 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-04-10 16:02 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-04-10 15:52 - 2016-10-09 11:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-04-10 15:52 - 2016-10-09 10:48 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-04-10 15:52 - 2016-07-16 08:04 - 01835008 _____ C:\WINDOWS\system32\config\BBI
2017-04-10 15:44 - 2016-02-28 15:03 - 00000000 ___RD C:\Users\Eggartskirch\OneDrive
2017-04-10 15:44 - 2016-01-20 17:32 - 00000000 ___HD C:\OneDriveTemp
2017-04-10 15:31 - 2014-09-13 18:16 - 00000000 ____D C:\ProgramData\Adobe
2017-04-10 15:02 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Eggartskirch
2017-04-10 14:13 - 2016-10-09 10:46 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-04-10 14:06 - 2014-10-12 16:52 - 00532136 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-04-10 13:59 - 2016-01-21 16:40 - 00002271 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-10 13:59 - 2016-01-21 16:40 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-09 15:35 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Gast
2017-04-09 15:35 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Annette
2017-04-09 15:35 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Anika
2017-04-06 12:40 - 2016-10-09 11:53 - 00000000 ____D C:\Users\Wolfgang\AppData\Local\ConnectedDevicesPlatform
2017-04-06 12:35 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-04-04 20:00 - 2015-12-09 15:02 - 00000000 ____D C:\ProgramData\hps
2017-04-04 19:59 - 2014-11-14 11:26 - 00000000 ____D C:\ProgramData\Ulead Systems
2017-04-04 19:55 - 2014-09-12 11:35 - 00000000 ____D C:\Users\Wolfgang\AppData\Local\VirtualStore
2017-04-04 19:33 - 2016-07-17 00:51 - 00653424 _____ C:\WINDOWS\system32\perfh007.dat
2017-04-04 19:33 - 2016-07-17 00:51 - 00133686 _____ C:\WINDOWS\system32\perfc007.dat
2017-04-04 19:33 - 2016-01-18 19:36 - 01760256 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-04 19:26 - 2016-10-09 10:53 - 00000000 ____D C:\Users\Wolfgang
2017-04-04 19:12 - 2015-02-16 15:58 - 00000000 ____D C:\output
2017-04-04 19:12 - 2014-09-16 16:10 - 00000000 ____D C:\Scanner
2017-04-04 18:56 - 2014-10-24 16:29 - 00000000 ____D C:\Users\Wolfgang\.phase-6
2017-04-04 18:56 - 2014-09-19 10:31 - 00000000 ____D C:\ProgramData\Phase6
2017-04-04 18:56 - 2014-09-14 21:55 - 00000816 _____ C:\Users\Wolfgang\3GN8MUwnFIymPKft0C0UzokAONHOlcxFmKU2v+eabIU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:55 - 2015-06-07 14:40 - 00000000 ____D C:\Users\Wolfgang\AppData\Local\GWX
2017-04-04 18:55 - 2014-09-13 16:20 - 00000000 ____D C:\Users\Wolfgang\AppData\Local\CrashDumps
2017-04-04 18:39 - 2017-01-23 21:15 - 00012224 _____ C:\Users\Wolfgang\Documents\aimRM52azG5S8hnG-f58YBZfnBQgHNeLTQ0RDVNfIuiTfQ9rbdA+Bu8DoMSwKhrSAxVMOvsiJ+UtwvM3dn-bTVjF57pPatnen0byi6qr04dNIhNZR6eGU0stSvWujdaL.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2017-01-23 21:15 - 00000560 ____H C:\Users\Wolfgang\Documents\LIMNjAhStQvCg5I1V30r1IQrEZk3IuymXX97g-133JMZg4iU2cACm3M2wtT8BNJtX35r0U+MDpD09Kzvb2ONF3vsAumkg+BAV5cjdGXv0GA85H-Sdonm7E-ONko+5jsh.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2016-11-30 19:39 - 00014352 _____ C:\Users\Wolfgang\Documents\nJTPA2OatYOawbxIM7Z-o1-j0W2LjMV+82+w8U-ADkFUzVqRqvc85ua1civVSBvRhaoXIhZLMJS4TjGM7oM-1A==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-11-04 11:30 - 00000000 ____D C:\Users\Wolfgang\Documents\Annika
2017-04-04 18:39 - 2015-10-04 18:45 - 00000000 ____D C:\Users\Wolfgang\Documents\Babysitten
2017-04-04 18:39 - 2015-10-04 13:10 - 00192896 _____ C:\Users\Wolfgang\Desktop\4AXhrKk33vpJdYcHjP8frhG8JXQrSbqet-WJl+iBj7ddCjLakqr4WobiVkrKJg4EkmRpcM53WQzBpDFEaqO2k9Bi55lHblK0tBMAKjJPix8=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-10-02 18:58 - 00192896 _____ C:\Users\Wolfgang\Desktop\muxXA1rNhZAhL4OXKtlpkCNmZy1iUJiCcbo4jTS0pax6K8MnTA+R0u8KAGbjbffr7zr+saaucTZMrceAaYS+bUvsrbcyISfm-9lyYxM-Bog=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-09-12 07:59 - 00000560 ____H C:\Users\Wolfgang\Documents\gosPL5k17Xmoey2CKL5UdIYJgXVkBdKRF1oiVJKgjJ9lcp9Z0CaH0ynUm+3ErcChXPGf5s7CfeRmE2qRVnLYWlD-5jO4fZZuEwGXsK-1xPU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-09-11 09:50 - 00000000 ____D C:\Users\Wolfgang\Documents\12.09.2015 Jehle
2017-04-04 18:39 - 2015-09-11 08:01 - 00013840 _____ C:\Users\Wolfgang\Documents\2udcNl-9yZBTOt4wgMGQEiPcA3zJsOoiEKMtjeNE+mck0toGgRWNvh45CgChaFC3B0EWK6UWAxVqiKWN7vn6BAbcAysi1x3dTqeYLm7kR1E=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-08-12 17:01 - 00000000 ____D C:\Users\Wolfgang\Documents\A-Block1415
2017-04-04 18:39 - 2015-07-26 14:56 - 00028032 _____ C:\Users\Wolfgang\Documents\Qqk91kiqpMzdw-RS9npVRbm5rAHeXrn1M6Cd4WZ2rZLfU-hUcXkRDV11bpByHgla86CYMWLJAXcW090Vr-ZkMCyw020uW0ZXtKngH5CXPUk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-07-05 20:33 - 00013968 _____ C:\Users\Wolfgang\Documents\nIIwtPNvzo+ttAxir4fgnhooyZm7-8QTW7kmRe1RVBtMtqxZZ2sUiSyT5MTZ1NBjZdm+VQrOcpJH8Z7hEOuAvKmhymQs0tkMj7yFzjtXW3yNuB8AgptxhQHZpSJ3Zbh3hvIRreDEVBQWZpR7OAqmdcDji2q+Iu6QGfx7bYl1GYQ=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-07-03 09:44 - 00014896 _____ C:\Users\Wolfgang\Documents\K6L-68st7u4yLLQWNiJSOx4IvTWKVkH7rAfHuaUPendvW9n+3s8jYUTFKM99Dm9S.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-02-20 10:50 - 00000000 ____D C:\Users\Wolfgang\Documents\daten wolfgang computer anett
2017-04-04 18:39 - 2015-01-09 13:12 - 00010176 _____ C:\Users\Wolfgang\Documents\LID5yxwPZp4uyL46bPw7b4HqUVX6pHDRupf0R4l6uxczxWG7CLlC+mB0+zz+PlOD.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:39 - 2015-01-02 18:00 - 00000000 ____D C:\Users\Wolfgang\AppData\Roaming\Skype
2017-04-04 18:35 - 2017-02-10 11:29 - 00050112 _____ C:\Users\Wolfgang\Downloads\7VXu5VokzSR+Dwc+uf3TX1fXpahHg5FYXb8yUSWxFGk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-02-10 11:28 - 00047552 _____ C:\Users\Wolfgang\Downloads\pPkjirEraocSXJkRuPAdT-n6bP90Xvghz1YWPGQPH8U=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-02-10 11:28 - 00044512 _____ C:\Users\Wolfgang\Downloads\ZH6RUX529QST8jl-3NAR+5RJ3IT+czMxPyrx-upuEl0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-02-08 21:06 - 00045632 _____ C:\Users\Wolfgang\Downloads\vt3AVvCds4GgWsluYWFIeLAfa14K8e-dI9D1ZQ5r7hw=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-02-08 21:06 - 00044096 _____ C:\Users\Wolfgang\Downloads\szzy4lVr-hcqWMJErZBzvWayB3dZxOFUI0YlBYxbuow=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-02-08 21:05 - 00051600 _____ C:\Users\Wolfgang\Downloads\5DJvWj+xxTnmtAttmwd6O+XSZP7Uvm2Q68dMtp90-oM=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-28 10:06 - 00011264 _____ C:\Users\Wolfgang\Downloads\QtX9JiAJuUKg3JF9+9z0ds0oD4ZUJOuTFPP5t5nFYS3FKd6luMq38rENsSOFalIs.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-20 14:29 - 00431504 _____ C:\Users\Wolfgang\Downloads\2l1hra6svMRKtRgMpxqLi3CobQgForAZF6n8YpkXTOaJry8WZmNxB9hVrppq529s8mMCE+UlyyJUnOtZ9nJH6Q==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-19 11:24 - 00018096 _____ C:\Users\Wolfgang\Downloads\AcHa1OxjnhgSsqdqoJRV-sfGLtMRSfeuxpqTu5z873idTiEbqfXjEBu1CQFWCLHW.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-19 11:22 - 00088704 _____ C:\Users\Wolfgang\Downloads\wVwbrmGvnlrocFUnB6OtDE6m35ii2HCQnkZqJOUsao8ynML2youkG9yW143iR21z.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-06 12:45 - 01157600 _____ C:\Users\Wolfgang\Downloads\FfQHqX89WxVJJllIIqN0QLQLwFH8cQVlBhqWcHyhJpvL2bJ1n5wI5FDC0RDnQNJonoTzoqmPiriMgtjvsQ3X4g5ePMJ+ZFajjUj3noHnhEUeAgTIcbWfkOMYg6X5KEKa-ObNFxtesGHo8wkFlIf7koU38qcT04h9UPjoIU37cbE=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-06 12:39 - 01157600 _____ C:\Users\Wolfgang\Downloads\YYTYbSb6QonRwZR1qFTcFe6xBvu+rAZZ4yDkT-yPqZezD4N-yKyfPtZPY6CtWzBaazQ5pN5iuEi24KAxqqpSdZwN4T1qR3qbeDmGjIwF+FTKexDMLmkukp-9Dwm5KrKyvnHgdtG5OTEX-BChECJTu+wNQW-0pVrzDTaB9xYbZJw=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-05 23:33 - 01157600 _____ C:\Users\Wolfgang\Downloads\BVOAF7PCmyCCRQ9H3kkiLzUT8zBs5UL-aCCaklMyE4thkXB2a6KgjJTburkj1k2n7bOwwhMTy2bF+N5cVdDlp-mALoGFApnN+rThzwljMhL5dG6heCR-eU8emlld5OjGWNA6jUfRYsOMY0PWgxbnvCm-pbKg72p7ljMC80tdOh4=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2017-01-05 23:22 - 01157600 _____ C:\Users\Wolfgang\Downloads\1Y9vf3CVjhwY6i5j64l2tvUMdmAs5xi4L4HBnZKJwItQemSVcVrxUfRFRfro2ncAAN--EwHWxCFcfyq2Vzdt9kyMkwXIQ6KeySUrnk705IHrAceRK2YOCX2hVoBKU6i2EQwY3NknwGjrrjI1PQG8jwkdCHRDfXZlelS3PmQtEC8=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-30 11:08 - 00149856 _____ C:\Users\Wolfgang\Downloads\EzMnWQ2gh08wfpDcU-PwviRSeL3ECNHaPi1sWw1Fz+hWCFZkmKX4lt0dxJ6NAl6WTBbLAsa4ivqyEPNCjQmXbQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-22 08:49 - 00415808 _____ C:\Users\Wolfgang\Downloads\-vYMba-jCLad+I4XjLu3lESgkL4bYjAxUnhp5SDq8n7VLis6Y-RfpoN3q1UPB68eyER8ezu+fiDAnxGzhvsaPQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-15 09:40 - 00075440 _____ C:\Users\Wolfgang\Downloads\lV0iuDpSRrNvRBJhKVWUhRK1g7UKpJn151N7XLKKBbU8XOZLmHx7CBtSm72UAwr-naWYVTPsnNTkMRLtqWzVdc86Pz9KugDRwYT8epRLLo9+2kRhJ9mkGF261L5iJ+RL4aTRpi4F17IzkmxQXl0+pw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-10 10:25 - 00200864 _____ C:\Users\Wolfgang\Downloads\6-67PatKTxqyH3uaYI3qZeIu-kYUaeyLvK+54ePFxe0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-10 10:17 - 00200848 _____ C:\Users\Wolfgang\Downloads\EJKlwHjpaGJolVEyOesUwUZ+996Ps4EJ0UPDo9y6YA0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-10 10:00 - 00200912 _____ C:\Users\Wolfgang\Downloads\b43m3INCCd9GGTsq19OWEMAijaskmNn+MPBfCsSjC1Y=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-12-10 09:56 - 00200880 _____ C:\Users\Wolfgang\Downloads\d4Lo1-WfBuBDDjLg3MizcA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-11-28 18:17 - 00151376 _____ C:\Users\Wolfgang\Downloads\ZhE3LgcPpqmanaWS4aiLKOU7G9FBynDfFgHlm8cBUuOlg6egqU72RV67CjF7eNmKTg1UAabFsE61Ijch6wrM3g==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-11-24 11:49 - 00104624 _____ C:\Users\Wolfgang\Downloads\mYlXVWCTbTZoZ6nzhU4HPaoRM4h4yiDqEh4HNfLlk4hTOfxgGht94qm9r7FVe6LrcDxqO+04CFjql7QUVGDiqg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-11-19 00:28 - 00059792 _____ C:\Users\Wolfgang\Downloads\LAfaodGzl9YwY+aFPBkjWJgkKbdBd6sh8R1zUDvlAinuuDjM9f7UgmcRu3aeIL4+.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-11-05 12:18 - 00345264 _____ C:\Users\Wolfgang\Downloads\ayL-FMAMlGJ00oDLNGwgxv7ZwpVXBaDZHYM+Oc3aYEze11aZrh1+G+mINFMXxo-7Rwg6FoR37SYALOWvXBArng==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-11-05 12:12 - 00214608 _____ C:\Users\Wolfgang\Downloads\sl7GjCoTdMWBnCIWaVvnyyqXK34vlyu7YzKhZCyodWk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-27 20:19 - 00132784 _____ C:\Users\Wolfgang\Downloads\xdHZpKL1G6SHXH4k9yUIUW-YcldxoKQ3JKOv-MSmvCFqxJNEXsEBJnjgF73Je20wMJI9wh1QEuyCTd6Ap2AL2A==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-22 16:58 - 00132784 _____ C:\Users\Wolfgang\Downloads\R6fYWeHjM69ZBgsDC48aD3Fwcf0iZGwquVKGZ3kZZsVD8AjbtjpWGPX0mzZcAHZi.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-12 19:41 - 00050224 _____ C:\Users\Wolfgang\Downloads\daOrpTnQlMFOVy0ON+VQ7Jw2uX5i1On5g4A32u+NT3IXLIrxlSVkjRumRj59sqW1.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-10 21:09 - 03414432 _____ C:\Users\Wolfgang\Downloads\dz2ACiWgGiPjpoxFWS9HV27cU07vfxT0E8RdDxId2pvOPq3ELqRpGKDLf3r2I9FI7pId04R5hpZbwQNdwKU6nA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-09 20:44 - 00317440 _____ C:\Users\Wolfgang\Downloads\-4mto-gBEk47lc9WxbYSeKazNaxW5UZpjMJiYzp2VuBOatSpi+DxxBUu9H5G8WG1mH+kcdvPXEfCMFc2s08r8Q==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-07 17:41 - 00284944 _____ C:\Users\Wolfgang\Downloads\+8zMXLNYyszNW2kwzWJIt9owDeEVQp7-CW-v+KeA-CTLyqeBwHk3Je8IivJEybn4.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-05 20:02 - 00467488 _____ C:\Users\Wolfgang\Downloads\J0etVDVnrlPDl6xwbqlRlJCuovtTOL0oy7zA4FeUjk6iey3vet6173dSE2pmhz+rPohlh9KmPywg1ncxLh+cTLURP7soRu2gMC800WWL8YozIZ48i4chg-w5aTPKWdRR.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-04 22:43 - 00467488 _____ C:\Users\Wolfgang\Downloads\LTkUgYCkdRY6aSaZ0g3OZcOLY3Zqnvh7w9TOJ+lp+6pihwxUJRHmmWdrWzxHDTcnYiyD8+NxNj0FjJfF11nVdKFpg0uIcqCBIoBED7TkrTYVqFRNJAGDEZ5j4bLxaTh6.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-10-04 22:40 - 00467488 _____ C:\Users\Wolfgang\Downloads\vPNU3Ibx89z2S8GHaCHYPnSy3jUT48GL1IKiD-6PdTBbTcfQSeUvZWVjOlUhnI9J7vx54HnjrLjQTUDsOxaLl9K0y0ThDDm0xyCSSgCS+xc=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-14 23:16 - 00133296 _____ C:\Users\Wolfgang\Downloads\f960Rt4+7LqNFdII3fgm96K8UXfOrAD4twJl3jW2WOoyCKeW62DqsxYxnfg77SzF2CjbTo-ojRY-1t+ZYl4HrA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:56 - 00045376 _____ C:\Users\Wolfgang\Downloads\PGH2VI4+Hys3GNTvZd-5pi5qCICRrB+UfZydRe8pJe34hTk5US8AgIKOAowUGtAmQvWPp5W6P-khaH0EAM5shA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:54 - 00359952 _____ C:\Users\Wolfgang\Downloads\dEw0DT8pHFRuyHrRQKU-bNjz+vJvn4yM5Jo76H2JqPDGilt9G5ozgqnjc8v0URGj.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:23 - 00176992 _____ C:\Users\Wolfgang\Downloads\x+hd1t-Y6Rg7i8OmWZeWIkvBZhQcdZkd3RHx7-rwYbE=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:23 - 00122528 _____ C:\Users\Wolfgang\Downloads\Ltw05g2qUd4CCLcqnU2fKIJdsRMmNhPcFWU45mcH6faitTTLYFtn39sKCMp8HSqp.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:22 - 00121232 _____ C:\Users\Wolfgang\Downloads\LLkOsyFJ0GOg-hqc4Nt8qGKi5iy4v0y8xz9ewcwCmLdDf9A9QTd5EDuuoPzhXaz5.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:22 - 00030464 _____ C:\Users\Wolfgang\Downloads\9fWa1ww5Lwc2K2xnI8wl04RKvzrkWiBbBlKm15uATUzgwLRxlEw90T3Kwo8qUSeJxBpVLLvpAvELHqRUbUwWUA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-09-09 18:21 - 00140224 _____ C:\Users\Wolfgang\Downloads\MXbeGeDs9IMqyc5ZcR3HlTU6Hf35UZO3ZnXVox00b3b4glz6-UEU+6uZ2racU9BxemBlG63oE3-5yiuTC7qO1pL5QGt0giL5rfgwEJcrNs0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-08-15 14:43 - 00026496 _____ C:\Users\Wolfgang\Downloads\ROc8hxin34ws2mSCaL3bE+D4ODI04SLa5FTzRyYaiLmRqNdVepbonKFlPiNJjbCC.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-08-01 09:06 - 00588880 _____ C:\Users\Wolfgang\Downloads\3T8IPaSFjfVA5foq4+OoGWqoaHyXE8Nd+knyloo1-eA=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-26 11:35 - 04333808 _____ C:\Users\Wolfgang\Downloads\4JnRrJBvHP7z1M9dpIMf6rqXurwnq9HK1L7DEDJhCJHnFX5eprvMAJcbwFkuSPBj.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-23 15:27 - 00030592 _____ C:\Users\Wolfgang\Downloads\fSGW1os1JUlHA8pF51ZHCf8e8jTXODzsp0o7qO7oxo2T-aWGyN5e8yAxiQZDkkYOx5XgnUtgz7N+cFpmC7MNUA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-23 11:19 - 00022912 _____ C:\Users\Wolfgang\Downloads\1jMgCvd6PpPov5oE7AHUE30u2LS88JOs3bMJvF2PEY-ICSrCwHB9-QO6MiwRx5QE.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-15 17:51 - 00060288 _____ C:\Users\Wolfgang\Downloads\6mqMhR0yu+D4qLufS0xT8UgIRs14e69acOv-QwpI4GM=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-15 17:51 - 00035600 _____ C:\Users\Wolfgang\Downloads\FB9kP68j5QICQqFKXWaeoBw4pZidEnOk99VTObQkJNU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-13 22:23 - 00000624 _____ C:\Users\Wolfgang\Downloads\L8m5Q+V+mTSm+K9GkxiP9eoT3qSamaMnL6FxkYNWvK8BdK900FSEsPjS6a9wuQ4Fv6jC1n7V4jyae2Q5NGh3GgqpJtGrNaPkIYjSbT5b0bY=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-13 22:22 - 00047424 _____ C:\Users\Wolfgang\Downloads\ojoCkXOI5E6LovWROyvFiRYTdHHtC8tu8CPpSmnwuyY=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-13 22:22 - 00000624 _____ C:\Users\Wolfgang\Downloads\4zlliOoc4mw3cuHzty9C8sviFnflyJluyy2vaj5jMAJLvh49fyPBVMzJ2MWofsjA+owIgwNBOKHCAdDbZPSE6h2dazV1L245UEN6SMKYn-s=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-11 05:58 - 00097440 _____ C:\Users\Wolfgang\Downloads\csadsV+G8stbrhfzEcMo2on8ADO1rYiZZDtxBDOToP-HTre6IKrU4nQxEkepo+JwvqzuoHJoQ+rbsZ2+MVLfyw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-11 05:56 - 00038272 _____ C:\Users\Wolfgang\Downloads\cEnghqu8J-l8yv+fqrN+prPn4aupKQf5hq0Ym7AkVy4OuOkpDtW3snx94oUOO9Q5Gw6P1eWqY6bwY4fiSlXIKBi2XRKp8IqTDXrJjZYsO4I=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:31 - 00047792 _____ C:\Users\Wolfgang\Downloads\o2N6ITGkyheLanJ-xunlbEs39QL+jkErcxFRKAt4suUbqpfmsE-s4odf7FFK0gEYMSkbgfoynVTTrGrjv8jT2A==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:31 - 00039200 _____ C:\Users\Wolfgang\Downloads\eyZJ4gp49EPFSi+C86wrQNZ6Sd0+YxmC2toL-g0oP1I9FEt-BZWTbC3DeUHW1QZfbdmR5itGN0MrTFQpyq9jBg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:30 - 00047792 _____ C:\Users\Wolfgang\Downloads\477qDCgNknX0+iE2FDzyYx-rCwDSg1CdZoHb3q5iCjZjMJwebph8JErVuu+v5u9Vd3s1qWEu9Frdi19uesQsbQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:30 - 00039200 _____ C:\Users\Wolfgang\Downloads\4gcWy5ElYkAoNN77nYHwUL7lsSDzjGTRJQ8a0UmFAjRSu+EneXDBmRRMb0t+6gK7.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:29 - 00047792 _____ C:\Users\Wolfgang\Downloads\V1QnIsUK3LxB3qTjUWfcnfTNZLIRJicOSYzdyC0mufrRYReN+4JMKpjUP3ityKsu.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:28 - 00049008 _____ C:\Users\Wolfgang\Downloads\r2b9ei7gKk8j2XwvLXRZJTOp1lo-YoGR5l4aC2b3oj8UwdukJxFOAUhjdGdYGx2s.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:28 - 00048224 _____ C:\Users\Wolfgang\Downloads\MiqfQhOWRz2tEkNQw6Fmy30JwuzM0qaRxOZnrG+WtYEgu2H211j2aWWPnnZtLRe6.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:27 - 00053760 _____ C:\Users\Wolfgang\Downloads\K60skZfc0nSBHchzDilLamDYVbxoKYjXh9hexsK7eCzQuTcNERdJFtNhPA8xcrWM.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-09 14:27 - 00052800 _____ C:\Users\Wolfgang\Downloads\nbrg8vJUo00Xh9ImUBOdnhc4LCSYoXVRptkBIYV0Sh-UTZu+6okW2AG0aEQ8Most.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-08 05:49 - 00082448 _____ C:\Users\Wolfgang\Downloads\P4NZ6WbZ+ikV0NDKfXafXiCN4k-A-jWbdfscH9Yg6Dtwx-TPdyRmdZ+7LDGTubcMvSaGrrS+m1cK5P+g6zSiEQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-05 18:00 - 00284528 _____ C:\Users\Wolfgang\Downloads\OkmRqGKXyHSNWQAGuoZxWytVSl8Sq1nRanKkXgSdDIM=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-05 17:59 - 00270016 _____ C:\Users\Wolfgang\Downloads\A2iaxhNreeBaE5NufCaTbRx3qulf6QD-MkgJBdi2Ygs=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-05 17:58 - 00433280 _____ C:\Users\Wolfgang\Downloads\C0GrCsMLRaFSl+sqNUXgt1FhVPyjgXVEEttbx97vKyarIe2t1qQo++MbDbJ51X9qQsq9889NYnABFsCri8lofQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-02 10:15 - 00047632 _____ C:\Users\Wolfgang\Downloads\b3qe8qnvtFJPo1pfCkitw4tcCf8cyU87SwE8NNhB56XJxWsPoKKXKFxXdQOS0MK+WVxVmxKdXudMpULtpXM2GA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-01 05:57 - 00034976 _____ C:\Users\Wolfgang\Downloads\wRGJtaOQglkjfnXC2JbZkQtTi5-QcdAzXorrmnYA6PuNC2UoJuIkEK0hUPzXZlOmtaIacdfxBvLutAy2DEN1RMq13hnLfC91zgYcJNkK4QenbFrxot2z45W1sNi78gqWfsVa1UQZ42ASLx+y42vWzpSRsXfjbeL6lLRCV7ql-WyhUV35Cfb9DbVFWgoIqFSq.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-07-01 05:51 - 00034976 _____ C:\Users\Wolfgang\Downloads\VLKsHcqIa79jSKEoMiFseRAi9vDPQlm8aa695dqCUB2+83BoYUPwb9ejmKifZl-QUH6k5gkjJAcQl7wRMyqFxvNHHbQqf8WKMlFZL9GCZ-4CCYiXB-OJ+qGQp2szlZArXYypMMM2Pi7Q1hIG66A5N2cUYSGUt2NHowVxfdmKbK-OEvzVbLfJG4QND+VYmxTR.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-30 09:14 - 00150304 _____ C:\Users\Wolfgang\Downloads\wLI74Zwdfi9UNM2u54cjNk2F4Cdq2Pos5jeRWDb7EYp6gW3kcYzRO2vqGkO0QyOYOI0HkQ2Xy2lSoQCa3DOUAw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-30 09:09 - 00328064 _____ C:\Users\Wolfgang\Downloads\2uBg8+fa5+mahqfVcMz8u3tQZyvgXfxD4cs5wJJjPsZh0pIDrX+maaV-Wbmu4GwpIhQ9koGdc2MmCebgC1ZWN6KV9uhDEo+oXMHsPMr2o2iwRx5dm2LT5pUG+78VJ35n.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-30 08:48 - 00055680 _____ C:\Users\Wolfgang\Downloads\YDphAlW9YOFyu221ZoDG3qeohvrSUjTfOQI9pJHZZ1fm5sPb9QPAxkuJEhp6nXF8f98zoon0KEMxPr4eTVJO4w==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-22 06:44 - 00046048 _____ C:\Users\Wolfgang\Downloads\cfCDVSWUSZi2WuBVK3r-YOO-au3W4AorkWyhjImKMENc7xBt6sfm1DdrOySUaaSJ-fxhyTjyaSXFFaEcxv9fZ5xQbTJpgksYlzQQA4PkPjJTL6ETVoev4V2nUQKBvLtN-uKQ6k5tj5PcodQyHAgijR6uk1SDoQGX8fULPmx0Ovk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-21 07:30 - 00157568 _____ C:\Users\Wolfgang\Downloads\HEWhwqugX1IPDK+6Cr+dik2ilWVK25IZSYSa-1DmTKCQo+Bcf+SSeF4olDjW4iOC.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-15 15:34 - 00410240 _____ C:\Users\Wolfgang\Downloads\euDyJ64MPgEvvTw0r8-8c-Zi3Dxl-GRd8D1HwehBW77V21+VnxdPtsmrAbsUAwtx.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-06-11 18:01 - 00013696 _____ C:\Users\Wolfgang\Downloads\VM0JJQU1vnmGYBCMkx228FqOvz8oxpN4Ydr1cssngUWhUlgS6-kprT094-oZ8ll4lri4E5eyOaeIijy6Bcr7dQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-30 05:54 - 00146864 _____ C:\Users\Wolfgang\Downloads\N8k8gjLNGcxnK8YkMxGS-svRz5XlGumn+cTOsXSv36apoVgsGrCjjzem1NnvwO+3.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-23 17:12 - 00911760 _____ C:\Users\Wolfgang\Downloads\iVJXVwk7YoOvbwfAwwpS95sBtrgiR84EmAsPXC98A9DBt1dqjH+Q7x3GK8Il-Mwj.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-23 17:09 - 00911024 _____ C:\Users\Wolfgang\Downloads\UxZw-Gcw7v+lJCBpYoXo0WbXgysIZ+W5PyiT5YtL6nAz1iVz5srjFcFReT5EMiXg.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-20 09:16 - 01545696 _____ C:\Users\Wolfgang\Downloads\kH8ftl+7EFMlY5b7TPMnIpinfH3kUgdU9vYCZj1C2IR+TpvWqBvhGB+O+3p0NW66+qGRaVAcqrusjuCPgBhLh8h47Oqs4FHYOH5B3DFos0Dxzd1oBjhKBIMAtqhg8Ym+.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-20 08:45 - 06639760 _____ C:\Users\Wolfgang\Downloads\cqTRTDHei-m4u5en5fdhh-39bbOZtNefrIu2emdYq5TM42Uj7xI4c2tYLm3bjlHk.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-18 09:40 - 00803680 _____ C:\Users\Wolfgang\Downloads\aoWm-YMlULq77uXHzRYYBS5XmYDFQkCNAEz3E3PcJuyHzZXfoZ0qhwlaz+iktbvcg5dFthXzseWMtpnJsCixmcSBpzheqLz+717JF8mrSw4=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-17 08:53 - 00018288 _____ C:\Users\Wolfgang\Downloads\e6VXHk299ooclKSRdJNBK3aOj3TTSpCAFvZ+OcwI1ggcFYMugFYiyJB0dubpYGWdadYQ6zOfYPb1O4zFtNenjLBcEMlQ+KwllqxdP2L1PKHS7EGi0pD6B5SzMXY2z-xPWCGmW-1ExmqdiP4Sqn3uCQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-12 23:51 - 00534864 _____ C:\Users\Wolfgang\Downloads\B0OEekmPaa0wBbwUaya863m7qguGABRhjCUT4xTHVSNp6du+nItMoXpOm+XA8zVexJ3JXDOVpr5ahBI3OINtgcf7oWKZ8DkQlnU6yUGWHGU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-12 23:47 - 01021072 _____ C:\Users\Wolfgang\Downloads\twrP+WdcFlEJVVdOORrAxw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-12 23:44 - 01545696 _____ C:\Users\Wolfgang\Downloads\iU9Lt-vyonMB4bWXE5ZeyklUrzdxYpqaAEXzMcocCl7lu3uBDIKjqO83E4rIrCljWfQSo3YuZOZhJalthxH3SzdGl3eYEBS5i0jL+-xJoYfn83FcLVN3B+KP+1Vy0GVc.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-12 23:39 - 00534864 _____ C:\Users\Wolfgang\Downloads\3QAjSa9oqvNN4YRTXoqtI-AxK0yfOkuBPZyttvYTz2cNXZd-jdGKuLY8CAbRgVWPYOVdoOqz446qSEeGRO5GiQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 14:18 - 00090240 _____ C:\Users\Wolfgang\Downloads\uJUPa3OfjcE0MCBFLBEJNajJvPEAqSeK4Ib2zuSY-2VwlVXBxPNOPOxpYzRKQiUAJhbcWe8VQNMYuV1BWHHJ3a95KLBkjrlbM-3S8tPLtVKTL2s+h3EQKep-buitxG4V.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 14:18 - 00070288 _____ C:\Users\Wolfgang\Downloads\t9OlYTJiYQQ4ArZs4VA3NVJTLoK1e4rSzvQHmG2o0ZMbkGe5Ym5fup67tHsTtthlGybABT0joPMGoy-lgIbD6fBO8YWmMmwjnRyr-bEbYELdN5oUd5ylt4drfmQNgyho.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 13:20 - 00651152 _____ C:\Users\Wolfgang\Downloads\DUgFBg04gLRLv8sixzBmZfKSDo7fn1Phg8w7i3LVYvUQirWlqzqMuxEEXYMPFpzrdgpJpvMePhI3YYZdzlv9Ca4TRiY4o7LSpCYN42jO6No=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 13:20 - 00620864 _____ C:\Users\Wolfgang\Downloads\736uh1LKq8rFGMElDxW5hXI3leThnQFMl54gvlJL8rwCLzQu3aL0rapdRuyNjS7NOt7ah89Zr2pdOwppj59AVw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 09:55 - 00118560 _____ C:\Users\Wolfgang\Downloads\lAxmk-CEbS-mxsfx7Ed5dntpCTTZlfRKGpQGr147F0wMitRuoOTquWPV4m2dJtdZr07I7b5qdxaslqcyC+H79qy3W22Es3-3Cj77M0GRCu8=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 09:49 - 00118560 _____ C:\Users\Wolfgang\Downloads\9aOi+pXqpWh+b6s70AkrSznCs-enVZPOouxl4BVAUv+8apMZC-WlTvUAM+TN8Zbni7oWwz7Ls6eYputkiyfpJ+EHzXRCIYI0Q49XNXhUfe0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-11 09:16 - 00118560 _____ C:\Users\Wolfgang\Downloads\TmA+13m-zbuuAGFF9qLhthKyPUauTWe1qEIM5ErW07mhRcZ8hA4LWuaziZw8aum48T6vYaUS0QD9fijD-ZsyC4GCGkuCQjyrI80HXEZ6ma8=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-09 05:43 - 00101936 _____ C:\Users\Wolfgang\Downloads\Ju7LSbN9dsBtOtDObugmFz4NQYDrU6lFXgFOQv6jIpXWTYeHEvdXxXXeo3IgjqZ14FkOFlxZOFTOX-cRclQlkyvsCBwYbjXN4R5FfWxWqKY=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-09 05:42 - 00099328 _____ C:\Users\Wolfgang\Downloads\wWacQ520wXqvpXd+a+CjM-SDXlavJUCWRal-3+eSEoJMGSpzBE0lElQSvJZ3Y1CaMZ7UP7bn6jPPC31roxBX6o26Z3fLA7CvoEthIpvcObI=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-09 05:38 - 00098400 _____ C:\Users\Wolfgang\Downloads\Xi1lvjm56vFpwbk70PmJR1ZxkspKIoj6iYM9JwmunRQfLUOeNcL5yvdX2EloMNatYgUVyeNTtqvCACBL7TLqW4BRdTSrsOtOZxR38j3i74Q=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-08 12:00 - 00048064 _____ C:\Users\Wolfgang\Downloads\3qicjfjK4NC8IOwoZ9V+iUcSllEHK7FTMlMoX0vf4ndTQP4aaEvptp8lhudJH0Lt6PK1pcs3v9CxpoyekMrEYN3rtYifq8TInjj9BdbXxQOWE3pSs1teC11vOMW8AolI.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-06 16:13 - 00534880 _____ C:\Users\Wolfgang\Downloads\ZDXNgjzRfx+xNByf2fsRkgcBfjs67NdQ42ARsddEvVPhb2Ne7q-DhoDXTAYz0ip9VFJm7Kr8G1yX678lo0rfdg89hdePxXA7TFjhsSRMOWxcTR6MHPqFxIQTfcYszFz1GGVS++nRjSq5pTCpEpcbCA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-01 22:11 - 00099872 _____ C:\Users\Wolfgang\Downloads\TEFR6qobArHTBlVoqzYooCd8jSdgmzHVSeKmAFikOycV31MMrzz7kSWS6DjH09wsF-3pII9TqT9jo-SGgJ5IuhtW7hHXgdvELTH88rzaxOI=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-05-01 15:00 - 00099456 _____ C:\Users\Wolfgang\Downloads\BPGbx-ISMh7sEniQg5L-B3DlBE0OuTy1JHd7BeMHU7wZj4VMD1Ea6Bep52voH6JAo++LlYWjVxfDdSVhbZtFs+bDb4fWBw5iF5E3LLYcQ7g=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-22 16:24 - 00641664 _____ C:\Users\Wolfgang\Downloads\76siyQEq1nFLECT9KmlV7gtYHim-+EVzEYHMgB6sCjLnT8wHFiXi8SHdVzUHiUdhKw3zRtTcF3e8UNY6HnhXOvDRxdLJvKeg3l+SdX6rVU8=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-22 16:19 - 00118560 _____ C:\Users\Wolfgang\Downloads\kEo2barYD0llpkGDk17BxIG+zn5nwDmBXlimSDQU8EforG6PDZ6k5AEzx4fForDLwvvqpsY6B9zrxKKiezNSjg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-21 11:12 - 00028544 _____ C:\Users\Wolfgang\Downloads\nbgKpNgv9TkpEo82piZIK1oHQswkq1INo38xswqgS3yOrgsyDdYAKOIXPOBNy0BmL+Gb93SP++O-Wk1L5nosxnAOMUHEiox1fEGdzjMgKai-Z-momSYzyikhoa+sIV26.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-21 11:11 - 00022800 _____ C:\Users\Wolfgang\Downloads\8v4k2ovbI+y+I+yTZugOxZGSFAU9U9EmAe4TxOJEFlQG+KWjgI1IS4tRjVX15shkotM7XLECRgK0K07qYgCsFYPNVsSyBgUxSAJsbwVn+z0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-20 05:45 - 00191520 _____ C:\Users\Wolfgang\Downloads\gbVAsoHBlasGmxT2QVKADgyhd2zksWjjpGvIcfm7Q23LIRPByz5ZJM0N4Lkl0yj3TcavPvAgMTO-xRdDfqXYoVzwLi9ayYPJ-OFhXPYsYGU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-18 16:58 - 00401904 _____ C:\Users\Wolfgang\Downloads\zB7q83h5hjlKpOBzG4PKZl4ZGUHZlBRrcO+jal06D9I=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-18 16:55 - 00152320 _____ C:\Users\Wolfgang\Downloads\cPbLqVpMH32QPlsTCAI0hLt5SkdwVa-4c7-GsB8xPqWKZgN0-TRrHfdmH+Pukz0jKWXkyr-E76RJou7OvKZFlA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-14 23:26 - 00049680 _____ C:\Users\Wolfgang\Downloads\owUVMijRjnv29aDFR+qToabhB0aBjQmD1IaUrCKfjtkMWMmk80TWRjffyK9GTFi9dUOlkR7uxEQ+poZ-VsWTqw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-09 00:13 - 00056000 _____ C:\Users\Wolfgang\Downloads\RUpH8NjjOPsTS1wxSoVwt7AL-qhxfcJ9DCwe1dYfWM0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-09 00:12 - 00077184 _____ C:\Users\Wolfgang\Downloads\pioZIetkFk0p0v2aZE55eI+nfBympVi5F22xR1gUpkw=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-09 00:12 - 00077184 _____ C:\Users\Wolfgang\Downloads\NQQO0pkOnp-LLETx8AYuHA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-09 00:11 - 00040320 _____ C:\Users\Wolfgang\Downloads\10SFq4Td30nOISytQzEXax0T1M5-lY6LWwepLIjmuQHGkif7l7qHno7iblWJwwpL3R2Or7VtEO2QYgN+Ttoxv2JKt1jmmlVuz3KT-qjfy4w=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-07 23:48 - 00283072 _____ C:\Users\Wolfgang\Downloads\qShF29GWB-nWEUnHz99fyNORkZJ9xZre0OzcMqsP1m4=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-07 23:47 - 00129264 _____ C:\Users\Wolfgang\Downloads\oLGMpeSxPoJwCY2LzG0kdNRVLDvdo+mMi+tpfwjs8RV+0d0G8axecE9pndQ6FqMyWqLCPL2afoarIGuQ-ZxtGySmfuPKS55oEPXvzG7+c3o=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-02 09:35 - 00061040 _____ C:\Users\Wolfgang\Downloads\dU3JwrbH+qAIDsleVbvgByvcX7i2rNU7FQFWyVW6QdYXPRkX-pfL6ZxAUbbotOlo.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-04-02 09:35 - 00037376 _____ C:\Users\Wolfgang\Downloads\An3LQbMmPjD0RpBJ-MWGhHldNaO7n9y4H+lvwrw9Vyk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-25 09:37 - 03570608 _____ C:\Users\Wolfgang\Downloads\MMOOPz5FH7TLoZm9DjH-Sq7XM0RJ1o4wWy1Er0v3mac=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-25 09:34 - 00347920 _____ C:\Users\Wolfgang\Downloads\TWilr7g3UZx1T2ZqIKN8PnVCh-w2xU6sMMQJQHwi+UI=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-17 11:27 - 03570608 _____ C:\Users\Wolfgang\Downloads\KnHTHXCW-riqH1oT8DXGD1hAsr3m6mOXGbtoUlSQ2ho=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 18:53 - 00021712 _____ C:\Users\Wolfgang\Downloads\+yBQugumgaAwjt7tZuRy-kAsiEZr4jb2hKW28k0Xhzo=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 18:52 - 00051648 _____ C:\Users\Wolfgang\Downloads\3cDPBHApCkPnX9V0cDYkbd7PDGTemLLZ7CA4qqRO6pU=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 18:51 - 00028112 _____ C:\Users\Wolfgang\Downloads\o-Y+LF2EctqpkxJFRCu-uiyTni7ajYZPf8tzjCOuW38=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 17:42 - 00082480 _____ C:\Users\Wolfgang\Downloads\EzrcqX9Dn2y-6aE82i4JeZp1XlV2wlDLKR3tLasQSFBu9OPJPjOI-G3pSKLeqJr8LSNwUmvtuZy3hk+u8cmFJ6rQntg4WGy1WfrwO5Mc+FZaQ7L1utg0KZqU38w8XsMS.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 17:41 - 00081520 _____ C:\Users\Wolfgang\Downloads\Q1BTC+LSaEsFgSwGB7ctVv2y80tvky5yUnuqX7MTH9qzIpE+CNrkJN1GZx8xmVNSsuyx6v9s-XHNZ076cPMjXxpeItRuEjhgibO2U9e4FmaeEqbKSFy2CYC5dh8Ooudo.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 17:40 - 00161728 _____ C:\Users\Wolfgang\Downloads\On3IdkVmBodLHbD2tiv7CZLC5ceRV7zDqDQXx9aTYobhpXgG6U8DMzt+Q9u01TP4llv0S-w8+ZHa2Kkxzoljfg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-11 17:39 - 00122240 _____ C:\Users\Wolfgang\Downloads\gBhi-a-Ol3+hvLdnp0iYaPhjXVBROY+452UTYXDNN-HVrL4-W78MRYkkAgScx7o5xqujKtzk0r59jaOi1qjWqnSBvcuNeonB67BufH-x8KI=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-04 06:53 - 00098768 _____ C:\Users\Wolfgang\Downloads\sZJJT2xb-lnOJik1WH82h8irbsvjKqrZQY2QIWX-liR4pOcFcq+BkGHBrBVZ+BbZbKhTF9jDprYE8BjzucW0HQ==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-03-02 23:04 - 00058800 _____ C:\Users\Wolfgang\Downloads\IbVASXpSaK5JNHceoSGW25-EJwJ6VD1wc6C30YZP0uSz2uIp1wCQ1-QloiScWI99Ld1-e9RLi7KkOaG6DgUeLJERYYebMr2g3bdgYzdBAFgd5XKwD2xbMb59kcXHFRiZ9ZGlEnVrqjmxNE1hG7LYNg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 12:04 - 00148864 _____ C:\Users\Wolfgang\Downloads\cMCRP3xz+PjABXT2zoVaaw-OW+mmd5EgWegAtZc3JJWkbidBnYb7fMFj3pxOPiL+Iw0LW+ymDf5kMDQ3mt+QDTMzIQmJebOv2sUdMgS07joW2zB4-Q4QcqxFzC+YsAd9sgsAn5EW+IFwYl4KqUHtuqMcLnuQD56rj7+gz-tOTtVDP8Iya87JyWzn10mbrQEL.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 12:04 - 00053136 _____ C:\Users\Wolfgang\Downloads\p-j-DGcNDiXG-h+sFPJUsPvRUd2KxHzcnYI2fVThayt8pRe3KAQVKx9TOhSlilTFKUtZjl40BkIStfBStNP67A==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 12:04 - 00043696 _____ C:\Users\Wolfgang\Downloads\oE0KQykbOdwrIUC3dWTdaUQo9kgITKzLaOPaksm6rngXnoEFgDBRgdtd7bD5tJ4g3-3m9iEyZUThh7VjULH2Nw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 12:02 - 00038608 _____ C:\Users\Wolfgang\Downloads\NF8adQy1T6T1VEmVQal52ZRgH3fETeFpLoU-GeFH4FTuT-wA74nLgRvXGj6IwH9EUKybnJ2Vgoxk8+jQzamh17J-UUNQNLiPZOibiGHhgsM=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 12:00 - 00044176 _____ C:\Users\Wolfgang\Downloads\mmADeITJ0fUyqFCECs4-LXSqBTUDW2dw8tAQwgcDJv6u-dypDbUSv-uSC9H6wwrIlcQlEgit0Jc62+OIWLroLCmEvTxgbz0bI8-dRTUYxMBfVsx9z8IgDYPzlKN2aF+m.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-28 11:53 - 00148864 _____ C:\Users\Wolfgang\Downloads\4dE5L3Y9Mw3TPpS1wP6jytILTkyX+nlEQYtzbs-m2ziK0RTvxohL8p7qDVnX5O7HDxCTRjrAUZbVqwUU05h0CVHRLhaFFkhm1VCZd1sv9dSxebmBLWtzPKlGWwHkdxYTNlBAHXtFOeTXtp+p-QNPvNLo43sjxXvSrU6MI-OVwVVdpLnX3syETish2beEKPpn.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-20 23:21 - 00209280 _____ C:\Users\Wolfgang\Downloads\QwRSSVxeHh5iL2v6cm1Cn5ccMdY5K9bJ+x2rAvXafjZJUenVV8EWg4sE264VT9wBdRaXLe1Y+rOkxvblVdB6A8B5zKo-WbX4-JHm+-RNF86Qv261fB3biZU9KpNWN4b+QojmVdBVGZ4j-OQIkxpgJE82ZooWlCkjaPDOLopUaaE=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-12 03:57 - 00197632 _____ C:\Users\Wolfgang\Downloads\UwG4wQG1Wzc9uQ+QyqRhpdx0hdtzXIP1zKZlu5N2S2+BBWlvsmKM9c5lq5+4bAGUelui3jcAj5GjhG6s6ZSJIA==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-05 17:23 - 00060960 _____ C:\Users\Wolfgang\Downloads\JTlSoxQgIRA9qFOqbfMb4rZTjzxgf+U3LMUAR4KsAkrjowSXVpMEQnvJhOAXMwHT.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-05 17:23 - 00025584 _____ C:\Users\Wolfgang\Downloads\h-41VsTxECEgUt3b9ilyRXaqIwu-mzd9lXX69waEllECSAmbMyTOQqFo+6Go1lag6xNNOE14JDD2uYx84vTlZw==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-05 17:22 - 00701600 _____ C:\Users\Wolfgang\Downloads\WSHjM0owLa8MxVoJH4RqSo-4hEqloHZhIoRb-qTk-pyYxBhzfZPsKjW2OcYjFW-oP-Wu31gEOXPxDTqLu+YdEtVc4aR7XHnzt73Ge0SDkYlTEOvvXcjJmZ2pRATucyDt.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-05 17:22 - 00035904 _____ C:\Users\Wolfgang\Downloads\VfQe2rSFCH8+mUfbRI5QxfWmAP9Cy1y1bausxNFPn5M=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-02-05 17:20 - 00803648 _____ C:\Users\Wolfgang\Downloads\H4YIR4s0iR2qZnJWLZX-rxn7-UnhIVxT3Wx9xatUQrdcnX+vZG9te-4XF-5RjmNhpoN8Nbeq--llXUrIPru-13B2ZRZ0xn4XUlcTu-X5IaQ=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-01-29 09:40 - 00058608 _____ C:\Users\Wolfgang\Downloads\VX3Yz1S4mTblS0Han8CY0UT9VLX2sl2a9DeThi4uBIlLCQmZrBGB2BIrncKL4iW8vcAhtPrrAucV5hWUANkn9w==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2016-01-28 08:31 - 00150192 _____ C:\Users\Wolfgang\Downloads\nFQvUQ5rNSUYtNDjhzQLdDxirrZYzPh+vsVsrdhRTCb4poIY35N4cJPDrfXYFNNOgOUo9qUFHukJfoRnuiKr7g==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-11-01 23:30 - 00475472 _____ C:\Users\Wolfgang\Downloads\qEJqCXDTxhsmnI9XeGeJ76uE0nGymKguXY7QDTDADsLYlUiSkhe9kelcNC0vUXuk-LJhC3QwdVi3-KL3uWOeLh9NKo3fe1K2VofAKcq1T7uOdrB35wgobw3xSt1grtKK.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-10-04 16:35 - 00012000 _____ C:\Users\Wolfgang\Downloads\PhrbqfVfgNTobW7qx2g93O7pd56e-zhsU1EoPd533IaddDUWzt6Um-rUDPSjVJeV.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-09-24 14:46 - 00116592 _____ C:\Users\Wolfgang\Downloads\4VOownK3sGPtm6OKNkasKhZn4Z9+F-9WyWKz11eNTovVP2sL9ZHkl-mX3bKANJMVFPi9H8kOR9jrhIkLR9uf9WkRNN8wNsSLWKBjMQ4ibB0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-09-24 14:45 - 00639040 _____ C:\Users\Wolfgang\Downloads\zZ5L0oi5dL6JulAs5gqaG0tXhfHoOntnAfczWe1ISxBVbH6TQjETOZAqc5Vul90AeKJ2TreZNb-YWiFU68S9PLPbwBLGW8S22V0eFqC7a-Y=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-02-18 17:35 - 14600240 _____ C:\Users\Wolfgang\Downloads\yIYMbOKTXYfrNajCL2NZrDX4oHi4EZmprKGGwye68UBGFm6GGYlNCC19G4qHTvQOW9bGyKxy4pFgiLAYUOR8Mg==.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-02-18 17:21 - 00283024 _____ C:\Users\Wolfgang\Downloads\YWuoV1DgveBXbcJbRQeTCNgYe9qW0eX2zBiW1+jXA-0=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2015-01-08 13:26 - 00052016 _____ C:\Users\Wolfgang\Downloads\0ZO1RjeGgHUE-eFqc60IqWD1vqKfuc20EWWAQcNFONk=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2014-11-28 19:12 - 00862496 _____ C:\Users\Wolfgang\Downloads\tN-hgZTG0pM-+WZUoE+HQMvCHbECn6TRQzyFKVsP1hw=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2014-11-28 15:24 - 00494512 _____ C:\Users\Wolfgang\Downloads\A9hvz-AyRd-mcvr6x1pgay9JWtsqeZtvFuJDBYmO1DthVPm1kzmaxGKPjWdeIXvC.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2014-09-15 21:33 - 00251504 _____ C:\Users\Wolfgang\Downloads\6ysBAbhsNo6BnKSHxkqRZoDbdy+cuAMBbSAmXRiqv3tSbGWaHyuAKTZ-sYmYMJOusZ7xxv2shdaprPb7avfcP9mQFphOS+oFGcUty9xyH78=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:35 - 2014-09-15 20:02 - 00251504 _____ C:\Users\Wolfgang\Downloads\YQWup5nqrBafGEIaEvcXpBeQyanGfhtSJL7zpjwnh5tGbW9rGyQSNteWUl91dqIryYbGIGKKmwjoIzP7y5jugPUclvYbjiBVZjPGEeapjkQ=.B97CE01B9A4E2DAE5F93.no_more_ransom
2017-04-04 18:31 - 2014-09-12 11:43 - 00000000 __RDO C:\Users\Wolfgang\OneDrive
2017-04-01 09:43 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-29 10:52 - 2014-09-13 19:58 - 00000000 ____D C:\Users\Anika\AppData\Local\Packages
2017-03-26 20:44 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-03-24 10:19 - 2016-05-29 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-24 10:16 - 2016-10-08 11:36 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-03-24 10:16 - 2014-10-12 16:28 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-03-24 10:16 - 2014-10-12 16:28 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-03-24 10:16 - 2014-10-12 16:28 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2017-03-24 10:16 - 2014-10-12 16:28 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2017-03-24 07:52 - 2016-10-09 10:49 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-19 22:08 - 2016-03-02 16:11 - 00000000 ____D C:\Users\Eggartskirch\Documents\Rutenfest
2017-03-19 21:41 - 2015-12-09 15:02 - 00000000 ____D C:\ProgramData\tmp
2017-03-19 18:42 - 2016-04-27 18:32 - 00000000 ____D C:\Users\Eggartskirch\AppData\Local\AMD
2017-03-18 15:49 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2017-03-17 01:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-03-17 01:04 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-16 19:38 - 2016-10-09 10:46 - 00364656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-03-16 19:33 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-03-16 19:33 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-03-16 19:33 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-03-16 19:33 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\setup
2017-03-16 19:33 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-03-16 19:32 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-03-16 12:15 - 2014-09-13 15:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-16 12:07 - 2014-09-13 15:42 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2016-08-19 08:39 - 2012-05-15 10:33 - 1456640 _____ () C:\Program Files (x86)\Common Files\Falk Navi-Manager classic.msi
2014-11-04 21:01 - 2014-11-04 21:01 - 0007602 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg
2016-10-09 10:49 - 2016-10-09 10:49 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
2017-04-04 19:09 - 2017-04-04 19:09 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN2536.tmp.exe
2017-04-04 18:26 - 2017-04-04 18:26 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN2BE7.tmp.exe
2017-04-04 18:49 - 2017-04-04 18:49 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN634E.tmp.exe
2017-04-04 18:57 - 2017-04-04 18:57 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN68BC.tmp.exe
2017-04-04 19:52 - 2017-04-04 19:52 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN85AC.tmp.exe
2017-04-04 20:08 - 2017-04-04 20:08 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NN96D0.tmp.exe
2017-04-04 18:38 - 2017-04-04 18:38 - 1021500 _____ () C:\Users\Wolfgang\AppData\Local\Temp\NNDC2C.tmp.exe
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-04-09 15:25
==================== Ende von FRST.txt ============================ Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017
durchgeführt von Admin (10-04-2017 16:13:24)
Gestartet von C:\Users\Admin\Desktop
Windows 10 Home Version 1607 (X64) (2016-10-09 09:51:59)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Admin (S-1-5-21-2778323970-3418293088-4074538823-1006 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-2778323970-3418293088-4074538823-500 - Administrator - Disabled)
Anika (S-1-5-21-2778323970-3418293088-4074538823-1004 - Limited - Enabled) => C:\Users\Anika
Annette (S-1-5-21-2778323970-3418293088-4074538823-1005 - Limited - Enabled) => C:\Users\Annette
DefaultAccount (S-1-5-21-2778323970-3418293088-4074538823-503 - Limited - Disabled)
Eggartskirch (S-1-5-21-2778323970-3418293088-4074538823-1010 - Limited - Enabled) => C:\Users\Eggartskirch
Gast (S-1-5-21-2778323970-3418293088-4074538823-501 - Limited - Disabled) => C:\Users\Gast
HomeGroupUser$ (S-1-5-21-2778323970-3418293088-4074538823-1003 - Limited - Enabled)
Wolfgang (S-1-5-21-2778323970-3418293088-4074538823-1001 - Limited - Enabled) => C:\Users\Wolfgang
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
AMD Settings (HKLM\...\WUCCCApp) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Apple Application Support (32-Bit) (HKLM-x32\...\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ArcSoft MediaImpression HD Edition (HKLM-x32\...\{A7C359B8-BDF3-436B-9AEC-254DA8C38B7F}) (Version: 3.5.86.1219 - ArcSoft)
Avira Connect (HKLM-x32\...\{0b46d918-af4f-4612-8076-5c0ae67cb2aa}) (Version: 1.2.81.41506 - Avira Operations GmbH & Co. KG)
Avira Connect (x32 Version: 1.2.81.41506 - Avira Operations GmbH & Co. KG) Hidden
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Catalyst Control Center Next Localization BR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.5.2014 - Georgy Berdyshev)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
Druckerdeinstallation für EPSON WF-3520 Series (HKLM\...\EPSON WF-3520 Series) (Version: - SEIKO EPSON Corporation)
Epson Benutzerhandbuch WF-3520 Series (HKLM-x32\...\WF-3520 Series Useg) (Version: - )
Epson Connect Guide (HKLM-x32\...\Epson Connect Guide) (Version: - )
Epson Easy Photo Print 2 (HKLM-x32\...\{02A312B5-1542-47B6-BFE9-F51358C39E86}) (Version: 2.4.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM-x32\...\{8F01524C-0676-4CC1-B4AE-64753C723391}) (Version: 3.01.0005 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.31.00 - SEIKO EPSON CORPORATION)
Epson Netzwerkhandbuch WF-3520 Series (HKLM-x32\...\WF-3520 Series Netg) (Version: - )
Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version: - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON StandardBusinessPrinters Printer Uninstall (HKLM\...\EPSON StandardBusinessPrinters) (Version: - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Filedrop version 1.1.1 (HKLM-x32\...\{3A309583-1B4A-4C90-85EA-124EB8DB331A}_is1) (Version: 1.1.1 - Filedrop)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
GeoGebra 5 (HKLM-x32\...\GeoGebra 5) (Version: 5.0.190.0 - International GeoGebra Institute)
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Earth (HKLM-x32\...\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
iCloud (HKLM\...\{4BB313CE-D3D1-424C-8823-15CF85B00B05}) (Version: 6.1.0.30 - Apple Inc.)
iTunes (HKLM\...\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Microsoft Office Standard 2013 (HKLM\...\Office15.STANDARD) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation)
MyEpson Portal (x32 Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
phase-6 2.3.4 (HKLM-x32\...\phase-6) (Version: 2.3.4 - phase-6)
Pixum Fotowelt (HKLM-x32\...\Pixum Fotowelt) (Version: 6.2.1 - CEWE Stiftung u Co. KGaA)
ProtectDisc Helper Driver (HKLM-x32\...\ProtectDisc Driver) (Version: 9.1.0.0 - )
Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7841 - Realtek Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0012-0000-1000-0000000FF1CE}_Office15.STANDARD_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TomTom MyDrive Connect 4.1.1.2797 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.1.2797 - TomTom)
Update for Skype for Business 2015 (KB3127976) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.STANDARD_{E0107125-62C7-43B6-8E66-0582F397469E}) (Version: - Microsoft)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {08DD833B-55B2-444F-9B37-96CF66EE65BB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {12EC59B4-1AED-4881-ACD3-C9923A4A5A17} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {1E917894-2CBA-4382-A1B3-AB8507409B9D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe
Task: {22C8983C-DE93-4E04-9B86-ED31C279736B} - System32\Tasks\{A67F2DC5-10E4-4B2E-A284-D7B64E55B322} => pcalua.exe -a "C:\Program Files\Reimage\Reimage Repair\uninst.exe"
Task: {28D52EFF-0584-4CCB-83B0-89DF66691629} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {2B15F3CA-C726-4566-AC90-E63642DBB97F} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {2BB3413C-1CE2-4E23-B6D9-CF12CAAF17D0} - System32\Tasks\{8B1F08CE-7A77-4837-BEF7-4BD58B16919C} => pcalua.exe -a D:\Start.exe -d D:\
Task: {2DD2EFAF-31A8-4514-BD0F-1FC8977F77FE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {2EB41968-AE35-4609-B4E2-8D97A626C5C6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe
Task: {392369CD-A446-49EE-8FAA-5A63FBFF372E} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG
Task: {3B9B52B5-6550-4279-8AA1-2C8D6F004919} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2017-03-04] (Microsoft Corporation)
Task: {3F3D2D2A-433C-4F5D-9EB8-BCB3FA9AEB39} - System32\Tasks\ZF9lYlJZXFxfXgxx => C:\Users\Wolfgang\AppData\Roaming\ZF9lYlJZXFxfXgxx\jvauyc32.exe [2017-04-04] ()
Task: {42F96E4A-A279-43F7-92FD-3B47A73CF70C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {5172382E-FA0C-42E4-AD5B-5A9DAEF50064} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe
Task: {541ACFA6-7AB5-4B01-A58C-E908F6B09FC0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2017-03-04] (Microsoft Corporation)
Task: {59B8FA7B-92F3-4884-89D1-1DBA2BCDBBC8} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe
Task: {5D481081-650E-4214-88C3-7D08277F60FD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {5F8199F3-2286-4BE2-B327-AE43AA5136AC} - System32\Tasks\{997593C6-22C8-417F-A7AD-E7809E35AEDE} => pcalua.exe -a D:\Start.exe -d D:\
Task: {602DE8F4-F69D-457E-BC42-E79DC4ECDB44} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG
Task: {651AF7A4-5315-459A-AAAD-9BD745803DA6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-03-16] (Microsoft Corporation)
Task: {739B8BF7-A8EE-486D-96ED-58D76CFDD47F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {76E5D3B5-EBFC-4FA1-93AB-50C411DA1079} - \GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-2778323970-3418293088-4074538823-1001 -> Keine Datei <==== ACHTUNG
Task: {81818CB5-CADA-412B-BDC6-3B8A79CADB0A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {8D768DB1-EB95-458D-A3E6-BE81EDFE3BDD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {8F5EF510-AB0D-4F0D-9327-44AE6B0F6581} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {9710073E-D6D5-409B-9556-E585BD5F8916} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {B57110EC-DDDE-470B-B9EB-0E3E6FDB7A10} - \GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-2778323970-3418293088-4074538823-1004 -> Keine Datei <==== ACHTUNG
Task: {C90A61A8-D5FD-49B0-AE0E-B6DBDCEF617D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2017-03-04] (Microsoft Corporation)
Task: {C9119F03-D4D9-452C-8562-2094559D0956} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {CB6218FA-E65B-4654-8816-A5A6C28E4E8E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2017-03-04] (Microsoft Corporation)
Task: {DE4D79AD-4859-4554-9BE6-FA8840929DB3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {DFA8BDE3-350F-4E41-9DBE-7AD357FC3F22} - System32\Tasks\OneDrive Standalone Update Task v2 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {E3A4F176-12D9-4132-8C79-3273CF878E9C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {E757E0A1-5497-4B9D-9B03-8ACA1E6E319B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {F7DA0F45-0CE3-44F0-ACD4-970B80BC7F17} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Wolfgang\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2016-11-17 02:28 - 2016-11-17 02:28 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 02:28 - 2016-11-17 02:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-03-16 10:28 - 2017-03-04 09:19 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-03-16 10:28 - 2017-03-04 09:19 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-12-17 20:19 - 2016-12-17 20:19 - 00959168 _____ () C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll
2016-10-16 15:57 - 2016-09-07 06:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-16 10:26 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-16 10:28 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-16 10:28 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-16 10:28 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-03-16 10:28 - 2017-03-04 08:05 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-03-16 10:28 - 2017-03-04 08:05 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-03-16 10:28 - 2017-03-04 08:08 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-03-16 10:28 - 2017-03-04 08:04 - 00114176 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Dss.BackgroundTask.dll
2017-04-10 14:29 - 2017-04-10 14:29 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-04-10 14:29 - 2017-04-10 14:29 - 00189952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-04-10 14:29 - 2017-04-10 14:29 - 42507264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-04-10 14:29 - 2017-04-10 14:29 - 02334184 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\skypert.dll
2016-12-17 20:19 - 2016-12-17 20:19 - 00679624 _____ () C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\ClientTelemetry.dll
2016-11-17 02:29 - 2016-11-17 02:29 - 01041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-11-17 02:28 - 2016-11-17 02:28 - 00189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2016-11-17 02:29 - 2016-11-17 02:29 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\GMX Homepage.website:TASKICON_0favicon-2099680105 [14814]
AlternateDataStreams: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\GMX Homepage.website:TASKICON_1favicon1569103102 [14814]
AlternateDataStreams: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\GMX Homepage.website:TASKICON_2favicon1972122725 [14814]
AlternateDataStreams: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\GMX Homepage.website:TASKICON_3favicon1780458250 [14814]
AlternateDataStreams: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\GMX Homepage.website:TASKICON_4favicon-933502785 [14814]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-2778323970-3418293088-4074538823-1006\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: SkypeUpdate => 2
HKLM\...\StartupApproved\StartupFolder: => "phase-6 Reminder.lnk"
HKLM\...\StartupApproved\Run: => "Windows Mobile-based device management"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "My Scrap Nook Search Scope Monitor"
HKU\S-1-5-21-2778323970-3418293088-4074538823-1006\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2778323970-3418293088-4074538823-1006\...\StartupApproved\Run: => "MyDriveConnect.exe"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3FA229CC-F50E-441C-ADC5-4554D1FEC204}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{393C054D-87C1-4183-B7DF-C5A32780A5E9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2357793D-4FE7-4F77-85E8-8F25B339428D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3FA100C1-B95F-4555-8BA3-B122BFAF0C84}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{45D8C7FC-B84B-4DF5-A35A-D373BD1F80D5}C:\program files (x86)\filedrop\filedrop.exe] => (Allow) C:\program files (x86)\filedrop\filedrop.exe
FirewallRules: [TCP Query User{F78C2D37-B86A-4EB6-895E-2A81603D1238}C:\program files (x86)\filedrop\filedrop.exe] => (Allow) C:\program files (x86)\filedrop\filedrop.exe
FirewallRules: [{D55A3407-5D82-401B-AD75-B73434773F1B}] => (Allow) C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{B5075C1E-08DE-4225-A0EB-D5CC87008896}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{3B047AE0-00FB-4D65-88DA-7FA3DB17F584}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [TCP Query User{57201749-5D37-4A63-98E1-26718EAC79DE}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{711FEEA5-C8E2-407B-94AD-1FE3CCDAD738}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{A1AA391F-D8C5-497E-A8B6-F4603C925312}] => (Allow) C:\Program Files (x86)\Advanced Driver Updater\adu.exe
FirewallRules: [{9D6BC0FD-1061-4347-9764-4E81A7476465}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{287AA7C5-561B-445D-A6C8-2FDB8C7907F5}] => (Allow) LPort=2869
FirewallRules: [{EBE78399-919F-43B8-9186-0B5F4EFB2FC5}] => (Allow) LPort=1900
FirewallRules: [{B7DE4F08-FE4C-4E8F-A384-0E4D13931103}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zS6FDC.tmp\SymNRT.exe
FirewallRules: [{9B056046-CC3E-4BFF-8892-4980E9E86E28}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zS6FDC.tmp\SymNRT.exe
FirewallRules: [TCP Query User{E5E03460-2E6A-483D-983A-10D1BD80E397}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{2C439AB1-A147-4F2C-8483-489007DA1B5F}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{0FD47E93-17AB-4C37-AA7A-16516CE62B14}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{20772494-172B-40D6-8382-07DC5ECE970F}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{4A40BC25-9422-42D6-8105-57EBB21953A1}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{68EF58B3-9BA6-4544-812E-DD9559F320BC}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{D0ECD111-F891-451A-8FD9-EF429B093739}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [UDP Query User{B0D76C84-BFCB-4054-A133-4AD2B88D3309}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [{A487D533-B6A5-419E-B1DA-1D0A3B3BCAB4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BBB3ADB1-7D4D-495F-B9F2-2D9A3033A2B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{41EDB4EF-9BB3-4D1F-933B-AE061C910178}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{89F792D9-A7B0-4497-9777-0B78B52F90C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C361ABC3-0095-4C1E-96AB-BB9CE416A430}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A7137022-CDED-41DE-8D1D-CF40CE05787E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Wiederherstellungspunkte =========================
09-04-2017 15:45:45 Geplanter Prüfpunkt
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (04/10/2017 04:04:42 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: Büro-links)
Description: Die Anwendung oder der Dienst "AdaptiveSleepService" konnte nicht neu gestartet werden.
Error: (04/10/2017 04:04:33 PM) (Source: Adaptive Sleep Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (04/10/2017 03:46:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppxrAPI.exe, Version: 5.2.2.504, Zeitstempel: 0x58e3c00b
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 10.0.14393.0, Zeitstempel: 0x57898ef6
Ausnahmecode: 0xc0000409
Fehleroffset: 0x00061e5d
ID des fehlerhaften Prozesses: 0x1404
Startzeit der fehlerhaften Anwendung: 0x01d2b200c8c11635
Pfad der fehlerhaften Anwendung: C:\Users\Wolfgang\AppData\Roaming\Microsoft\Certoml2\AppxrAPI.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\KERNEL32.DLL
Berichtskennung: 63037739-4724-4b8e-b832-64611633b8bb
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/10/2017 03:46:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: csrss.exe, Version: 1.0.0.500, Zeitstempel: 0x58e3c05e
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0061221e
ID des fehlerhaften Prozesses: 0x20fc
Startzeit der fehlerhaften Anwendung: 0x01d2b200c2b8d858
Pfad der fehlerhaften Anwendung: C:\ProgramData\Windows\csrss.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 8eadada8-8b6a-4674-9690-b11573c0662a
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/10/2017 03:44:40 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Büro-links)
Description: Bei der Aktivierung der App „Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/10/2017 03:36:02 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Fehler beim Aufzählen von Benutzersitzungen zum Generieren von Filterpools.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (04/10/2017 03:36:02 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Fehler beim Aufzählen von Benutzersitzungen zum Generieren von Filterpools.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (04/10/2017 03:36:02 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Fehler beim Aufzählen von Benutzersitzungen zum Generieren von Filterpools.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (04/10/2017 03:36:02 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Fehler beim Aufzählen von Benutzersitzungen zum Generieren von Filterpools.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (04/10/2017 03:36:02 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Fehler beim Aufzählen von Benutzersitzungen zum Generieren von Filterpools.
Details:
(HRESULT : 0x80040210) (0x80040210)
Systemfehler:
=============
Error: (04/10/2017 04:07:18 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: Der Server "{784E29F4-5EBE-4279-9948-1E8FE941646D}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (04/10/2017 04:05:46 PM) (Source: DCOM) (EventID: 10016) (User: Büro-links)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "Büro-links\Admin" (SID: S-1-5-21-2778323970-3418293088-4074538823-1006) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
und der APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
im Anwendungscontainer "Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe" (SID: S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 04:04:17 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 04:04:02 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 03:55:34 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Plattformdienst für verbundene Geräte" wurde mit folgendem Fehler beendet:
Unbekannter Fehler
Error: (04/10/2017 03:55:09 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 03:51:50 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 03:45:29 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/10/2017 03:44:41 PM) (Source: DCOM) (EventID: 10010) (User: Büro-links)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (04/10/2017 03:44:40 PM) (Source: DCOM) (EventID: 10010) (User: Büro-links)
Description: Der Server "Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
CodeIntegrity:
===================================
Date: 2017-04-09 15:25:04.342
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-17 21:08:38.454
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-16 20:17:00.762
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-05 11:50:27.815
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-03 15:56:29.007
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-17 20:38:14.941
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-10 20:51:47.494
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-07 19:35:04.920
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-29 19:57:08.137
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-15 08:44:45.329
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: AMD Sempron(tm) 3850 APU with Radeon(tm) R3
Prozentuale Nutzung des RAM: 50%
Installierter physikalischer RAM: 3517.44 MB
Verfügbarer physikalischer RAM: 1729.46 MB
Summe virtueller Speicher: 9917.44 MB
Verfügbarer virtueller Speicher: 7588.92 MB
==================== Laufwerke ================================
Drive c: (Windows) (Fixed) (Total:453.91 GB) (Free:287.08 GB) NTFS
Drive e: (CORSAIR 2) (Removable) (Total:28.95 GB) (Free:28.95 GB) exFAT
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 29 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=29 GB) - (Type=07 NTFS)
==================== Ende von Addition.txt ============================ |