G Data Internet Security VIRENFUND von heute [Teil 3]: Code:
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.NarratorQuickStart_10.0.19041.1023_neutral_neutral_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.OOBENetworkCaptivePortal_10.0.19041.1023_neutral__cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.OOBENetworkConnectionFlow_10.0.19041.1023_neutral__cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.ParentalControls_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.PeopleExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.Photos_2022.30070.26007.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.Photos_2022.30070.26007.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.Photos_2022.30070.26007.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.Photos_2022.30070.26007.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.Search_1.14.7.19041_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.PinningConfirmationDialog_1000.19041.1023.0_neutral__cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.ShellExperienceHost_10.0.18362.449_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.SecHealthUI_10.0.19041.1865_neutral__cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.StartMenuExperienceHost_10.0.18362.449_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.ShellExperienceHost_10.0.19041.1949_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.XGpuEjectDialog_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Windows.StartMenuExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsAlarms_11.2206.27.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsAlarms_11.2206.27.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsAlarms_11.2206.27.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsAlarms_2022.2206.27.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCalculator_10.2103.8.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCalculator_10.2103.8.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCalculator_2020.2103.8.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCamera_2021.105.10.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCamera_2021.105.10.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\microsoft.windowscommunicationsapps_16005.14326.20970.0_neutral_de-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsCamera_2021.105.10.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\microsoft.windowscommunicationsapps_16005.14326.20970.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsFeedbackHub_1.1907.3152.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsFeedbackHub_1.1907.3152.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsFeedbackHub_1.1907.3152.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsFeedbackHub_1.1907.3152.0_neutral_split.scale-125_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsMaps_11.2206.6.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsFeedbackHub_2019.1111.2029.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsMaps_11.2206.6.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsMaps_11.2206.6.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsSoundRecorder_10.2103.28.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsMaps_2022.2206.6.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsSoundRecorder_10.2103.28.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.WindowsSoundRecorder_2021.2103.28.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Xbox.TCUI_1.24.10001.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Xbox.TCUI_1.24.10001.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.Xbox.TCUI_1.24.10001.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxApp_48.67.14001.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxApp_48.67.14001.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxApp_48.67.14001.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGameCallableUI_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGameOverlay_1.54.4001.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGameOverlay_1.54.4001.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGamingOverlay_5.822.6271.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGamingOverlay_5.822.6271.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGamingOverlay_5.822.6271.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxIdentityProvider_12.93.6001.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxIdentityProvider_12.93.6001.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxIdentityProvider_12.93.6001.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.YourPhone_1.22072.207.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.YourPhone_1.22072.207.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.YourPhone_1.22072.207.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.YourPhone_1.22072.207.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneMusic_10.20032.12611.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneMusic_10.20032.12611.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneMusic_2019.20032.12611.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneMusic_10.20032.12611.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneVideo_10.20032.16211.0_neutral_split.scale-100_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneVideo_10.20032.16211.0_neutral_split.language-de_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneVideo_2019.20032.16211.0_neutral_~_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Microsoft.ZuneVideo_10.20032.16211.0_x64__8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\MicrosoftWindows.Client.CBS_120.2212.4180.0_x64__cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\MicrosoftWindows.UndockedDevKit_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\NcsiUwpApp_1000.19041.1023.0_neutral_neutral_8wekyb3d8bbwe.xml
C:\ProgramData\Microsoft\Windows\AppRepository\RealtekSemiconductorCorp.RealtekAudioControl_1.30.259.0_neutral_split.scale-100_dt26b99r8h8gj.xml
C:\ProgramData\Microsoft\Windows\AppRepository\RealtekSemiconductorCorp.RealtekAudioControl_1.30.259.0_x64__dt26b99r8h8gj.xml
C:\ProgramData\Microsoft\Windows\AppRepository\RealtekSemiconductorCorp.RealtekAudioControl_1.30.259.0_neutral_~_dt26b99r8h8gj.xml
C:\ProgramData\Microsoft\Windows\AppRepository\SCHUFAHoldingAG.meineSCHUFAplus_1.1.4.0_neutral_split.scale-100_tpk8v36tk93y2.xml
C:\ProgramData\Microsoft\Windows\AppRepository\SCHUFAHoldingAG.meineSCHUFAplus_1.1.4.0_neutral_~_tpk8v36tk93y2.xml
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
C:\ProgramData\Microsoft\Windows\AppRepository\SCHUFAHoldingAG.meineSCHUFAplus_1.1.4.0_x64__tpk8v36tk93y2.xml
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-wal
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
C:\ProgramData\Microsoft\Windows\AppRepository\Windows.CBSPreview_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\AppRepository\Windows.PrintDialog_6.2.1.0_neutral_neutral_cw5n1h2txyewy.xml
C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\GeofenceApplicationID.dat
C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-21-1985118773-2268224356-3260620144-1005_S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742\Geofence.dat
C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-21-1985118773-2268224356-3260620144-1005_S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\Geofence.dat
C:\ProgramData\Microsoft\Windows\Models\ModelPayload.json
C:\ProgramData\Microsoft\Windows\Models\SBCModel.txt
C:\ProgramData\Microsoft\Windows\Models\SBCModel.json
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-03.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-04.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-05.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-07.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-09.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-08.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-10.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-11.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-12.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-13.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-15.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-14.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-16.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-17.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-19.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-18.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-21.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-20.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-22.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2022-09-23.xml
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report.html
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-latest.xml
C:\ProgramData\Microsoft\Windows\SystemData\S-1-5-21-1985118773-2268224356-3260620144-1007\ReadOnly\LockScreen_W\LockScreen___1920_1080_notdimmed.jpg
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_AcroCEF.exe_724927afa625593142e98daa0cfb3d89be27cd1_54d78eea_16f99d7a-1eec-4c37-88ed-af3473766153\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_35776778-a8e4-4e0b-b454-80fa8e3ef51c\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_ADelRCP.exe_c9c3348410a0a8c9239947d7ec3baee6ed65893_8b27915e_f8418ce8-a6ef-40cf-8abf-ebe9e6aca0ad\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_464a50e9-c160-47e1-9594-f50849d9648b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_5c73bb68-02de-45e5-ba29-33ce1b68ee05\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_4b586024-40b5-41f3-8030-0cfe3b4c828b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_6e193c0e-3ac0-4f06-9b45-25db5093e600\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_94828768-e4ca-48a7-9c19-4b3f401c3e31\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_b88c0af5-6c4e-450a-b458-69954a70d585\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_9f450dc3-e3ca-412a-9e7b-60f935f4bbe6\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_ab48eba2-36d7-4124-b0ad-f98c86149c47\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_ca1dc4ec-4f09-47f7-a671-e3ffa216ca7b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Steinberg Downlo_bab05a175616d482fde651d6dc2716f355d9e2a3_f96f2dc8_e2e28c26-fc2a-495b-be21-23d77f6ab53e\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_STEINB~1.EXE_a888e4729e2110afeb814ad5b8a923fec35de23_af858151_5c4454f6-9a08-4d85-901d-2955e5f15e2c\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_STEINB~1.EXE_a888e4729e2110afeb814ad5b8a923fec35de23_af858151_b16aec46-51b9-45ad-9c99-daf190b156b3\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_explorer.exe_c8d152c615f76e474844ba8a0f2ede1a0bb95e1_475969b1_f8c6655d-fb7a-4d4b-855c-49535cd6e0d2\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_explorer.exe_e3b552bb452c9da3e49fed4aa77c42ce5d23b76c_bb0dc81a_fe71989f-c7d9-4fcd-a262-59b54ed8ba26\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_1287fce1bb8133c74b8853e4a3bb5f0a928bc6f_bb747bac_322398ec-1c3b-4fd2-8d71-27053a9664da\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_1287fce1bb8133c74b8853e4a3bb5f0a928bc6f_bb747bac_3a3716e5-1bc1-43b8-85f1-8c31470aa0ae\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_1287fce1bb8133c74b8853e4a3bb5f0a928bc6f_bb747bac_c3f063e3-8903-4ea9-befb-566a0eff007f\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_1ef68b92ffc8fc8ffacff6b079f150bf43e6122f_bb747bac_f86c0652-a133-4166-9e21-7f24921de29c\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_16fc88a515436180cd3d6df1c50a3ba229bbb76_bb747bac_5a9bfceb-5a54-4f42-aae9-c6d7255d512b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_3ba04cdc12dc3662fbc237f7c7b719fd5be1169f_bb747bac_d2470097-93b0-48de-ba89-5543d19275be\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_4433d76dad5d5c6e2428b62b051e56538fe4f4b_bb747bac_7793e93d-2281-4088-a77a-05a134787c42\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_4433d76dad5d5c6e2428b62b051e56538fe4f4b_bb747bac_d719f5c7-872d-4231-9888-4a3fe7e11b89\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_491eb64f15ae3ffbff4baa884823fa29dc1_bb747bac_2632163e-1c61-49d0-a9df-2800a549b012\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_491eb64f15ae3ffbff4baa884823fa29dc1_bb747bac_35e858b0-d85d-49ed-862e-c341cb489b54\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_491eb64f15ae3ffbff4baa884823fa29dc1_bb747bac_6205dfb2-8bb1-4ed2-ba10-dcfd30c6a292\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_dbc514ac23cd13c459491bf21e74630da72728a_bb747bac_b33a5a6f-db9a-432d-ace7-98311b1c6624\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Microsoft.Window_fd5743293929f3413fa829e4c2de65773996c743_bb747bac_9db207b2-d22e-4ccd-826c-ea0cd6a6e33e\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1022__b0f14a2fdb0ad12dca9c36b770d6e4ba33c24_00000000_c1d140b2-d036-4a2b-b17c-d79ca3aa99d1\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1081__692c63f61f7a2941b74cd1a4eb6af190c878f059_00000000_29ada6fa-2057-4e73-8744-765149b66957\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1161__54a0539ea9d07c7f7937b61396e4682f5157ce79_00000000_d3a8b18d-e02c-4079-970f-995083273e0b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1081__836fc813ddf69982b8dfd939d4773f3d35c40_00000000_7f8afc50-be45-4956-b4c8-33256868766d\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1220__302f9619b692aca58fe4b121dfa7b853cdfc93e_00000000_b9b57913-e559-4c6a-b247-cd2cb83a99b3\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1220__302f9619b692aca58fe4b121dfa7b853cdfc93e_00000000_e4f9d5a3-1ea3-400c-adb9-24ebba2a6e36\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1371__e5cb5417e0db8386a01ad51dc853893d7e3aff76_00000000_4f07a2a1-e3e2-4248-aec1-b46251902036\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1310__764fd7936e19847cc6874d54b17db731701e8fc1_00000000_767bd186-c7f4-4e27-9637-86a2a73bd181\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1525__c8347ab5e3814d3ba2ce6b79a36172f8ebb873a6_00000000_4d2c45db-8eab-4226-8049-a3ed17e33f8c\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1371__e5cb5417e0db8386a01ad51dc853893d7e3aff76_00000000_bc4cbdaf-3fa3-4a50-962f-4b67e80fa59d\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1613__bb1cf2bdaaaba9436fdc1e84eedd19294eb3e3_00000000_9d3d9f29-f7b5-40fa-85b6-0953307f3147\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1525__c8347ab5e3814d3ba2ce6b79a36172f8ebb873a6_00000000_d18c746d-7e11-450c-b2cf-4c72cc529aab\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1737__bd3a68c1887a2b523b2d85b63fee611a5949_00000000_b7d00637-74aa-4c64-bb87-9ece441a6ff5\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1704__8168f4a25971099de6d14a99acbb674a8396d_00000000_7d75c86e-b9b5-4803-ae39-ff66582bf593\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1790__e8822bd2b10a99fe875c31f911912d43ee33d9_00000000_fc92761c-2516-4685-9cc3-b98c80bffddd\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1852__bf87d9e9bfc18eddb6fb87c14ce236779e7145be_00000000_4d4cab8a-64c7-48c1-bb3a-0a6baa27779b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.1940__d22e85b72d2e8dc9e33dbc15a7bf2780c7c0a4_00000000_e8ce5255-d20d-4ef6-a6b0-80fcb4e7a3de\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.860_1_4f13a1e5aa1a845f693fc541bd4bffe8750edce_00000000_f3ac71de-2b2e-44fb-b49b-03ed132f8649\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.985_1_c121d4fff316c67767a8cebc783cc6dbb8a4053_00000000_5e20f714-6c6f-4763-bba1-72250fdd3ed4\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.19041.925_1_877ee917729228984c1dcbc0565145159d81d95_00000000_c6600fa6-adf3-4461-9643-b59239a3d4b7\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_00000000_cab_cb586984-345a-4e28-a9e5-b17f19835398\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_00000000_cab_f1a2ec47-9be6-4d58-bc90-080fd68095b3\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000009f_59fc4b2a7d9bfd6b5a23bd79f9b19f1e1934ec1_00000000_cab_ed1f1ee9-ed70-4cb5-8c40-6c048b5fd247\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000015e_e8bd181032701bc5a7469786d450fd161a1f86_00000000_cab_46ec000e-4199-4416-9e27-394b69ef0575\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000015e_f4fe168b5150c22ef5cea81f616bb74355991678_00000000_cab_6be4f22d-9e42-473f-976e-fe48bd93e06b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000015e_e8bd181032701bc5a7469786d450fd161a1f86_00000000_cab_53525bf4-a93e-43f6-92aa-8fc514d91025\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_354aceb25712467438e17860b05d2c79e99e26b1_00000000_cab_0adae044-a224-4cfd-b64e-3ed012e3d6a5\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_54246054530233a82c23b70a9beabb089eedbc_00000000_cab_a45b3d7e-41d9-4548-878d-45e084e5ad70\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_9e20289bb1764683fd194e4a34812c30e6415a25_00000000_cab_3a957e47-eb55-4b6f-b082-bda40779437e\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_5564e673302431b823760944165d04fbbc6e854_00000000_cab_467600a3-72f4-4eb3-afdd-0c7b06b34feb\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_c1bf93762a6a8dfbee6f246806e133377dfdfc_00000000_cab_6f9fcf2a-2ba2-4fb0-ad37-84574d0a9782\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_a7402dedba8e718d4ba70ea5647a06992d4a3d0_00000000_cab_db2a3608-8ddd-4e06-9e06-2fb48becf130\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_141_e28742f084fea23e8608c309bc86ce6f485a291_00000000_cab_3167d301-c135-4c6d-971d-2062a3aa9af1\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Acquisition;DSIC_5d38a30c42ddb5aad3fc260934d8b826f6b896a_00000000_f50c91a4-86d2-4e0e-9bb1-24cd87adfd88\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_MicrosoftEdgeUpd_62bfba244c775f99187e3d945477abfa3724fd_00000000_284fe5f2-cb23-4bb7-a27f-4aeba720ced9\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft Corpor_92b5549fbabc4a49b6caeb6eba77bec84b871fd_00000000_80af75a5-d643-4a88-a37c-26c88e978843\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_MicrosoftEdgeUpd_794567d2aa1498726d8ef2a1136f51c16ec8e5c_00000000_3d802cfb-ca1b-48b9-b691-cfa77dd2c46b\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_MicrosoftEdgeUpd_ef40d22def9ac7f6d36e2dd23f11d758b94d22e_00000000_a3c6a003-5ea3-48f7-8f31-3f39262b9979\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_unspecified_2cefb992bcc7966a74f05dc375bbc39ee4885dfd_00000000_690e7bdd-65ac-4f73-bdd8-6b2a81f38914\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_unspecified_6c31a8d38748845bda55d4b2bc42f36f7d29c3_00000000_e4061a76-3273-4f9f-b1ad-ad8130e38697\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;_381e13a27ae48864dd8229837b39bde5beb5d10_00000000_501c28a7-810a-4c8b-82f2-9f403f54e745\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;_4a65d394173a92126a60f477903eeea2e1b5d38f_00000000_f3ff906f-f890-4270-9fb4-1850f6657367\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;_ab38782b50583c2150875b1513bd2e4ea704b24_00000000_3f89028f-6fde-403d-a0dd-a50b5606f3de\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;_e5a7faefeba9a97e50ecb784fa2312314d7e879_00000000_21f956f1-6d39-45f6-8ca3-988a3a827ecd\Report.wer
C:\ProgramData\Microsoft\Windows\wfp\wfpdiag.etl
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.5B
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.67
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.6C
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.79
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.7C
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.80
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.7E
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.87
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.83
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DBAAF88C1DA6CAA9D97269FC2BB82CEE914AB9B8.bin.A0
C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db
C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\BED77A0F-7D56-41B3-849D-01FDF61C5A41-0.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\AD09F91E-CAE2-4CF7-A3DC-474E5BD78DD4-0.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\99E0472A-D71F-4AAF-9727-B98C881E4DD0-1.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\C9CE1554-707E-4CAF-B3D4-0FDF2F0A5592-0.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\0
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick\52E29ABB-7E94-4E21-9BD3-3BA34DB379F7
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick\5D44544F-5CAB-47F5-9013-3ED391287F42
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\B0D5F4C9-ABF6-40D2-B1E4-B36F315CB599
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\F3855694DDC89AE86AA6088A9F0CC087
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log
C:\ProgramData\Microsoft\Windows Defender\Scans\Scans\History\CacheManager\7A012CB2-69ED-4AFD-BEF6-F12032FAA46E
C:\ProgramData\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\e8a9c4243b9623b1.dat
C:\ProgramData\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\e8a9c4243b9623b1_COM15.dat
C:\ProgramData\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\e8a9c4243b9623b1_COM15.dat.LOG1
C:\ProgramData\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\e8a9c4243b9623b1_COM15.dat.LOG2
C:\ProgramData\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\ff0916a1ff3e4f84.dat
C:\ProgramData\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\ff0916a1ff3e4f84_COM15.dat
C:\ProgramData\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\ff0916a1ff3e4f84_COM15.dat.LOG1
C:\ProgramData\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\S-1-5-21-1985118773-2268224356-3260620144-1005\SystemAppData\Helium\Cache\ff0916a1ff3e4f84_COM15.dat.LOG2
C:\System Volume Information\IndexerVolumeGuid
C:\System Volume Information\MountPointManagerRemoteDatabase
C:\System Volume Information\smartdb_Volume99e0472a-d71f-4aaf-9727-b98c881e4dd0.sdb
C:\System Volume Information\tracking.log
C:\System Volume Information\Wcifs.md
C:\System Volume Information\WPSettings.dat
C:\System Volume Information\3808876b-c176-4e48-b7ae-04046e6cc752
C:\System Volume Information\c6834703-385e-11ed-80b7-5c879cd783303808876b-c176-4e48-b7ae-04046e6cc752
C:\System Volume Information\SPP\OnlineMetadataCache\9c367114-7c21-4aaf-886f-f8ef1dc32eb2_OnDiskSnapshotProp
C:\System Volume Information\SPP\OnlineMetadataCache\ae8096c3-f589-4c26-97db-429ed64a0f87_OnDiskSnapshotProp
C:\System Volume Information\SPP\SppGroupCache\9C367114-7C21-4AAF-886F-F8EF1DC32EB2_DriverPackageInfo
C:\System Volume Information\SPP\SppGroupCache\9C367114-7C21-4AAF-886F-F8EF1DC32EB2_WindowsUpdateInfo
C:\System Volume Information\SPP\SppGroupCache\AE8096C3-F589-4C26-97DB-429ED64A0F87_WindowsUpdateInfo
C:\System Volume Information\SPP\SppGroupCache\AE8096C3-F589-4C26-97DB-429ED64A0F87_DriverPackageInfo
C:\System Volume Information\Windows Backup\Catalogs\GlobalCatalogLock.dat
C:\Users\defaultuser100000\NTUSER.DAT
C:\Users\defaultuser100000\ntuser.dat.LOG1
C:\Users\defaultuser100000\ntuser.dat.LOG2
C:\Users\defaultuser100000\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TM.blf
C:\Users\defaultuser100000\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000001.regtrans-ms
C:\Users\defaultuser100000\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000002.regtrans-ms
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\Connected Devices Platform certificates.sst
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000.cdp
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000.cdpresource
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db-shm
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db
C:\Users\defaultuser100000\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db-wal
C:\Users\defaultuser100000\AppData\Local\Intel\CUIPromotions\Config\status.cst
C:\Users\defaultuser100000\AppData\Local\Intel\Games\Common\status.cst
C:\Users\defaultuser100000\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\GfxDownloadWrapper.exe.log
C:\Users\defaultuser100000\AppData\Local\Microsoft\Credentials\DFBE70A7E5CC19A398EBF1B96859CE5D
C:\Users\defaultuser100000\AppData\Local\Microsoft\GameDVR\KnownGameList.bin
C:\Users\defaultuser100000\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
C:\Users\defaultuser100000\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
C:\Users\defaultuser100000\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\Policy.vpol
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat6d6525e2-7e0a-11eb-8082-5c879cd78330.TM.blf
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat6d6525e2-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000002.regtrans-ms
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\UsrClass.dat6d6525e2-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000001.regtrans-ms
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\Shell\LayoutModification.xml
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\V01.chk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\V01.log
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\V01res00001.jrs
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\V01res00002.jrs
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group1\desktop.ini
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group2\desktop.ini
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows Sidebar\settings (1).ini
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows\WinX\Group3\desktop.ini
C:\Users\defaultuser100000\AppData\Local\Microsoft\Windows Sidebar\settings.ini
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\AppCache\container.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\AppCache\K7O8Q0C0\container.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\container.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\2_bc3d32a696895f78c19df6c717586a5d[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\bootstrap_3.3.0_B68S-_daR6nLiLVZsh4XiA2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\ellipsis_635a63d500a92a0b8497cdc58d0f66b1[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\converged_ux_v2_dfnIq4HVug6NeVWURJemhw2[1].css
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\OldWin10HostLogin_PCore_ydew_m5S9rkNJ_ghDEhqTQ2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\resetpasswordnewpackage_OwdMiCIuaIOFwZsFgmMxPw2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\B0NHN3GZ\wlivepackagefull_cHeSkPsNhc9yilRlgEedHg2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\AppCentipede_Microsoft_HFeToeM4u6fzMQF_f_rQ5Q2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\AppCentipede_Microsoft_white_ufRYlllWOw4YyDRiKcBvxQ2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\datarequestpackage_dT3VZJ_4lD5UykUFoE8W2w2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\marching_ants_white_166de53471265253ab3a456defe6da23[1].gif
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\F0LIC1HG\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\accountcorepackage_YcAvD2KLYy2k7TD4CG_FKA2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\ConvergedLoginPaginatedStrings.de__DGyVNT4ZqkYAgmkfIA_ug2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\corewin10_agofQhKqSUxTqus2sWhueg2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\hostfooterpackage_tC8_bbOadBEXnyHS8HRGMQ2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\marching_ants_b540a8e518037192e32c4fe58bf2dbab[1].gif
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\Microsoft_Logotype_Gray_X-qkgtg8KmnQEvm_9mDTcw2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\I6SB1QAL\WinJS_Pt8gJb7BbW7ot52jCT0KgQ2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\Converged_v21031_-0mnSwu67knBd7qR7YN9GQ2[1].css
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\ellipsis_grey_2b5d393db04a5e6e1f739cb266e65b4c[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\ellipsis_white_5ac590ee72bfe06a7cecfd75b588ad73[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\favicon[1].ico
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\knockout_9HcnWxbPHdJ-ovZeA-tF1g2[1].js
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\Microsoft_Logotype_White_4MYDQRab31HKDWWN-1HafA2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\NAC390ZT\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[2].svg
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCookies\ESE\container.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\container.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\45K5ACBG\account.live[1].xml
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\F5FCHDCN\login.live[1].xml
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\GH6DM1DH\microsoft.windows[1].xml
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\LocalState\_sessionState.json
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100000\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_5FDD03068CBBD8A96F3AB9595BA10093
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_5FDD03068CBBD8A96F3AB9595BA10093
C:\Users\defaultuser100000\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_d214d7f6-1a83-4fd9-968b-af54e11f2311
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Network\Connections\Pbk_old\_hiddenPbk\rasphone.pbk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Protect\CREDHIST
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Protect\S-1-5-21-1985118773-2268224356-3260620144-1007\898d0efa-ea65-4ac8-a8a9-d6ba53403d69
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Protect\S-1-5-21-1985118773-2268224356-3260620144-1007\Preferred
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5f7b5f1e01b83767.automaticDestinations-ms
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\SendTo\Notepad.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk
C:\Users\defaultuser100000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk
C:\Users\defaultuser100000\IntelGraphicsProfiles\Brighten Video.man.igpi
C:\Users\defaultuser100000\IntelGraphicsProfiles\Darken Video.man.igpi
C:\Users\defaultuser100000\IntelGraphicsProfiles\Enhance Video Colors.man.igpi
C:\Users\defaultuser100000\OneDrive\desktop.ini
C:\Users\defaultuser100000.KLAUS\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db
C:\Users\defaultuser100000.KLAUS\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db-shm
C:\Users\defaultuser100000.KLAUS\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100000\ActivitiesCache.db-wal
C:\Users\defaultuser100001\NTUSER.DAT
C:\Users\defaultuser100001\ntuser.dat.LOG2
C:\Users\defaultuser100001\ntuser.dat.LOG1
C:\Users\defaultuser100001\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TM.blf
C:\Users\defaultuser100001\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000001.regtrans-ms
C:\Users\defaultuser100001\NTUSER.DAT6d65259f-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000002.regtrans-ms
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\Connected Devices Platform certificates.sst
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100001.cdp
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100001.cdpresource
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100001\ActivitiesCache.db
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100001\ActivitiesCache.db-shm
C:\Users\defaultuser100001\AppData\Local\ConnectedDevicesPlatform\L.defaultuser100001\ActivitiesCache.db-wal
C:\Users\defaultuser100001\AppData\Local\Intel\CUIPromotions\Config\status.cst
C:\Users\defaultuser100001\AppData\Local\Intel\Games\Common\status.cst
C:\Users\defaultuser100001\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\GfxDownloadWrapper.exe.log
C:\Users\defaultuser100001\AppData\Local\Microsoft\Credentials\DFBE70A7E5CC19A398EBF1B96859CE5D
C:\Users\defaultuser100001\AppData\Local\Microsoft\GameDVR\KnownGameList.bin
C:\Users\defaultuser100001\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
C:\Users\defaultuser100001\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\Policy.vpol
C:\Users\defaultuser100001\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat6d652605-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000001.regtrans-ms
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat6d652605-7e0a-11eb-8082-5c879cd78330.TM.blf
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\UsrClass.dat6d652605-7e0a-11eb-8082-5c879cd78330.TMContainer00000000000000000002.regtrans-ms
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\Shell\LayoutModification.xml
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\V01.chk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\V01.log
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\V01res00001.jrs
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\V01res00002.jrs
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group1\desktop.ini
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group2\desktop.ini
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows Sidebar\settings (1).ini
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\desktop.ini
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk
C:\Users\defaultuser100001\AppData\Local\Microsoft\Windows Sidebar\settings.ini
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\AppCache\container.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\AppCache\OB4T9XPQ\container.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\container.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\accountcorepackage_YcAvD2KLYy2k7TD4CG_FKA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\ConvergedLoginPaginatedStrings.de__DGyVNT4ZqkYAgmkfIA_ug2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\AppCentipede_Microsoft_HFeToeM4u6fzMQF_f_rQ5Q2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\FinishWin10_Strings1031_PIxpV0JR5-uEM2iZzMwpPA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\hostfooterpackage_tC8_bbOadBEXnyHS8HRGMQ2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\OldConvergedSA_Core_YTTFJlpzyQTk6HUchN-pCg2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\marching_ants_white_166de53471265253ab3a456defe6da23[1].gif
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\WinJS_Pt8gJb7BbW7ot52jCT0KgQ2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\win10settingsdesktop_y4l-HlFd9oxF8a80titMgw2[2].css
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\8BPA87RY\wlivepackagefull_cHeSkPsNhc9yilRlgEedHg2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\ConvergedSAStrings.de_q6hNxC660eewTlfmr87DhQ2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\Converged_v21031_-0mnSwu67knBd7qR7YN9GQ2[1].css
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\ellipsis_grey_2b5d393db04a5e6e1f739cb266e65b4c[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\favicon[1].ico
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\ellipsis_white_5ac590ee72bfe06a7cecfd75b588ad73[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\knockout_9HcnWxbPHdJ-ovZeA-tF1g2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\Microsoft_Logotype_White_4MYDQRab31HKDWWN-1HafA2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[2].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\OldWin10HostFinish_PCore_H-lwSKUp-IcCOFK5Fm-txw2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\BZ05HN37\Win10Set1031_q2z_a_u1jk_edeceELfNJg2[1].css
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\2_bc3d32a696895f78c19df6c717586a5d[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\bootstrap_3.3.0_B68S-_daR6nLiLVZsh4XiA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\corewin10_agofQhKqSUxTqus2sWhueg2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\converged_ux_v2_dfnIq4HVug6NeVWURJemhw2[1].css
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\marching_ants_b540a8e518037192e32c4fe58bf2dbab[1].gif
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\OldWin10HostLogin_PCore_ydew_m5S9rkNJ_ghDEhqTQ2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\picker_verify_email_59759b80e24a89c8cd029b14700e646d[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\pin-setup-icon_iSsOlYRpU4iSlQNDTJYe_Q2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\resetpasswordnewpackage_OwdMiCIuaIOFwZsFgmMxPw2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\viewmodelflow_B9BAV5wTYwE9sNv4LH_D1Q2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\L5AE5U5P\win10msangc_CAr4a55ib08YeMYKqT7XBA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\AppCentipede_Microsoft_white_ufRYlllWOw4YyDRiKcBvxQ2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\ConvergedFinishStrings.de_UTl_gDXHd2boEU2bmjTwtA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\ellipsis_635a63d500a92a0b8497cdc58d0f66b1[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\datarequestpackage_dT3VZJ_4lD5UykUFoE8W2w2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\Logout_Core_VmaP6hMN-_ohCNAvN0OiEw2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\FinishWin10_Core_EnQVx36yJ2H7BOD45TzBYA2[1].js
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\Microsoft_Logotype_Gray_X-qkgtg8KmnQEvm_9mDTcw2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\XNB6O1EA\pin-setup-icon_iSsOlYRpU4iSlQNDTJYe_Q2[1].svg
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCookies\ESE\container.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_BEB37ABADF39714871232B4792417E04
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\container.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\1QN5S4TY\account.live[1].xml
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\S1MSCCBV\login.live[1].xml
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\AF8UEUKN\microsoft.windows[1].xml
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\roaming.lock
C:\Users\defaultuser100001\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_5FDD03068CBBD8A96F3AB9595BA10093
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
C:\Users\defaultuser100001\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_5FDD03068CBBD8A96F3AB9595BA10093
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_d214d7f6-1a83-4fd9-968b-af54e11f2311
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Protect\CREDHIST
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Network\Connections\Pbk_old\_hiddenPbk\rasphone.pbk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Protect\S-1-5-21-1985118773-2268224356-3260620144-1008\ff60585d-9208-412a-92f8-093ac10944f7
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Protect\S-1-5-21-1985118773-2268224356-3260620144-1008\Preferred
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5f7b5f1e01b83767.automaticDestinations-ms
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\SendTo\Notepad.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk
C:\Users\defaultuser100001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk
C:\Users\defaultuser100001\IntelGraphicsProfiles\Brighten Video.man.igpi
C:\Users\defaultuser100001\IntelGraphicsProfiles\Darken Video.man.igpi
C:\Users\defaultuser100001\IntelGraphicsProfiles\Enhance Video Colors.man.igpi
C:\Users\defaultuser100001\OneDrive\desktop.ini
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\GameBarElevatedFT_Alias.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\msoxmled.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\MicrosoftEdge.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\protocolhandler.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\python.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\python3.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\sdxhelper.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\winget.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\selfcert.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\python.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\python3.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\winget.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.Office.Desktop_8wekyb3d8bbwe\protocolhandler.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.Office.Desktop_8wekyb3d8bbwe\msoxmled.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.Office.Desktop_8wekyb3d8bbwe\sdxhelper.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.Office.Desktop_8wekyb3d8bbwe\selfcert.exe
C:\Users\klaus\AppData\Local\Microsoft\WindowsApps\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\GameBarElevatedFT_Alias.exe
D:\DumpStack.log.tmp
D:\System Volume Information\IndexerVolumeGuid
D:\System Volume Information\smartdb_Volume010c3cef-551c-4ddf-bc36-52f5ccca3f7f.sdb
D:\System Volume Information\tracking.log
D:\System Volume Information\WPSettings.dat
E:\System Volume Information\IndexerVolumeGuid
E:\System Volume Information\smartdb_Volumee3aea15e-7e0d-47da-8abf-c2468401671d.sdb
E:\System Volume Information\tracking.log
E:\System Volume Information\WPSettings.dat
---------------------------------------------------------------- FRST.txt: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022
durchgeführt von klaus (Administrator) auf KLAUS (MEDION MD34503/D001) (23-09-2022 22:22:43)
Gestartet von C:\Users\klaus\Downloads
Geladene Profile: klaus
Plattform: Microsoft Windows 10 Home Version 21H2 19044.2006 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: FF
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe ->) (G DATA Software AG -> G DATA CyberDefense AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltSur64.exe
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe ->) (G DATA CyberDefense AG -> G Data CyberDefense AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\DnsCloudClientHost64.exe
(C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe ->) (G DATA CyberDefense AG -> G DATA CyberDefense AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe
(C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe ->) (G DATA CyberDefense AG -> G DATA Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVK.exe
(C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe ->) (G DATA Software AG -> G DATA CyberDefense AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe
(C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe ->) (G DATA CyberDefense AG -> G DATA Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
(C:\Program Files (x86)\Garmin\Express\express.exe ->) (The CefSharp Authors) [Datei ist nicht signiert] C:\Program Files (x86)\Garmin\Express\CefSharp.BrowserSubprocess.exe <2>
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (G DATA CyberDefense AG -> G DATA CyberDefense AG) C:\Program Files (x86)\Common Files\G Data\WebProtection\NativeMessagingWP.exe <2>
(DriverStore\FileRepository\cui_dch.inf_amd64_ba5b1813656e5c27\igfxCUIService.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ba5b1813656e5c27\igfxEM.exe
(explorer.exe ->) (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Express\express.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <37>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (G DATA CyberDefense AG -> G DATA CyberDefense AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe
(services.exe ->) (G DATA CyberDefense AG -> G DATA Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(services.exe ->) (G DATA CyberDefense AG -> G DATA Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(services.exe ->) (G DATA CyberDefense AG -> G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ba5b1813656e5c27\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e8f9f51120464f93\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e8f9f51120464f93\IntelCpHeciSvc.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_6ca78a08b838e305\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c60facea9c32a6cb\RtkAudUService64.exe <2>
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22072.207.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c60facea9c32a6cb\RtkAudUService64.exe [3380320 2021-11-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710776 2020-06-18] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Beschränkung <==== ACHTUNG
HKU\S-1-5-21-1985118773-2268224356-3260620144-1005\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2630024 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1985118773-2268224356-3260620144-1005\...\Run: [Google Update] => C:\Users\klaus\AppData\Local\Google\Update\1.3.36.152\GoogleUpdateCore.exe [230360 2022-08-30] (Google LLC -> Google LLC)
HKU\S-1-5-21-1985118773-2268224356-3260620144-1005\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31184216 2021-11-15] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1985118773-2268224356-3260620144-1005\...\Run: [MicrosoftEdgeAutoLaunch_F75BE088442289830962033269060EA1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3795360 2022-09-15] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon MP630 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9C.DLL [27648 2009-12-22] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP630 series: C:\WINDOWS\system32\CNMLM9C.DLL [279040 2009-12-22] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\105.1.43.93\Installer\chrmstp.exe [2022-09-14] (Brave Software, Inc. -> Brave Software, Inc.)
IFEO\taskmgr.exe: [Debugger] "C:\PROCESSEXPLORER\PROCEXP64.EXE"
Startup: C:\Users\klaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2021-02-15]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [Datei ist nicht signiert]
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {027F899B-7284-43E6-9921-0D97AEFC85BE} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {063096C6-3875-429F-9E28-5D5304B2C3F8} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA{07EC2224-F51A-48A6-B91F-4281BF65B567} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174976 2022-09-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {077E7466-E43D-4E7C-921F-25BDC7880152} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe)
Task: {0A575A62-5763-4B38-AE22-EDF662D81240} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4165000 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {23D987F1-5932-4C75-AB8B-21F29BFF14EA} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
Task: {376D73C1-20F8-407C-9587-F7F224CF945E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1985118773-2268224356-3260620144-1005Core => C:\Users\klaus\AppData\Local\Google\Update\GoogleUpdate.exe [156104 2020-05-12] (Google LLC -> Google LLC)
Task: {44814823-A178-4555-8298-E6AD798BEB4B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1985118773-2268224356-3260620144-1005UA => C:\Users\klaus\AppData\Local\Google\Update\GoogleUpdate.exe [156104 2020-05-12] (Google LLC -> Google LLC)
Task: {750A4CB9-4874-4341-9A97-4EBD5DB4E04D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1555696 2022-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {BBE571B2-EFB5-418C-B4A9-684620B9F44B} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{E0F5C3E8-AB4E-4148-8721-6389F1A35A80} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174976 2022-09-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {C4B1819B-C026-4921-9C19-F83F3CC40EC4} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {CBFEFB9B-CACF-418D-8C30-F4CA03FDD4A4} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1985118773-2268224356-3260620144-1005 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4165000 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {CFB8BA5F-F82D-45FA-9907-E49E102ACE9D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\system32\MRT.exe [141646296 2022-09-13] (Microsoft Windows -> Microsoft Corporation)
Task: {FAE6EBB2-25C1-4BD0-886A-67AE22AB3103} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [26968 2021-11-15] (Garmin International, Inc. -> )
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{d29fac2a-b487-4f46-894b-474ffa6f50a1}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{eee49704-d675-4418-82b8-de86627a6d2d}: [DhcpNameServer] 192.168.2.1
Edge:
=======
DownloadDir: C:\Users\klaus\Downloads
Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden]
Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden]
Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden]
Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden]
Edge Profile: C:\Users\klaus\AppData\Local\Microsoft\Edge\User Data\Default [2022-09-23]
Edge DownloadDir: Default -> C:\Users\klaus\Downloads
Edge StartupUrls: Default -> "hxxps://www.google.de/"
Edge Extension: (G DATA WebProtection) - C:\Users\klaus\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pehnahjhohlhchmcpcjcfnafkebenbgn [2020-08-23]
FireFox:
========
FF DefaultProfile: 8r6bam7c.default
FF ProfilePath: C:\Users\klaus\AppData\Roaming\Mozilla\Firefox\Profiles\8r6bam7c.default [2020-07-18]
FF ProfilePath: C:\Users\klaus\AppData\Roaming\Mozilla\Firefox\Profiles\y5cw0b67.default-release [2022-09-23]
FF Homepage: Mozilla\Firefox\Profiles\y5cw0b67.default-release -> hxxps://www.google.de/|hxxps://www.silkeleopold.de/downloads/|hxxps://midi.pianoforproducers.com/niko-midi-pack?creativeId=537673095089&gc_id=13334922380&gclid=Cj0KCQjw-pCVBhCFARIsAGMxhAfhJFUajjbNwQ_2Qfg7T25ll2EGFns1pOiZ7I0MXhMYe2lwqGx-9CoaAkmkEALw_wcB&h_ad_id=537673095089&utm_content=121336535165&utm_id=13334922380
FF Notifications: Mozilla\Firefox\Profiles\y5cw0b67.default-release -> hxxps://www.wallstreet-online.de; hxxps://www.sportwetten-jaxx.de; hxxps://bchamp.bwin.de; hxxps://www.news.de; hxxps://www.jdsports.de; hxxps://www.sat1.de
FF Extension: (ReloadMatic) - C:\Users\klaus\AppData\Roaming\Mozilla\Firefox\Profiles\y5cw0b67.default-release\Extensions\0.id@reloadmatic.webex.xpi [2020-07-19]
FF Extension: (G DATA WebProtection) - C:\Users\klaus\AppData\Roaming\Mozilla\Firefox\Profiles\y5cw0b67.default-release\Extensions\webprotection@gdata.de.xpi [2020-08-26] [UpdateUrl:hxxps://gdata-a.akamaihd.net/R/CommonUpdate/extensions/webprotection/updates.json]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2020-12-08] (Adobe Inc. -> )
FF Plugin: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-19] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-19] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-09-08] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-08] (Adobe Inc. -> )
Chrome:
=======
CHR Profile: C:\Users\klaus\AppData\Local\Google\Chrome\User Data\Default [2022-06-03]
CHR Notifications: Default -> hxxps://www.wallstreet-online.de
CHR StartupUrls: Default -> "hxxps://www.google.de/"
CHR Extension: (Google Docs Offline) - C:\Users\klaus\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-05-09]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\klaus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-18]
Brave:
=======
BRA Profile: C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2022-09-08]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2022-09-08]
BRA Extension: (Brave NTP background images) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2022-09-08]
BRA Extension: (Wallet Data Files Updater) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2022-09-08]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2022-09-08]
BRA Extension: (Brave Ad Block Updater (EasyList Germany)) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\faknfgalcghekhfggcdikddilkpjbonh [2022-09-08]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-09-08]
BRA Extension: (Brave NTP sponsored images) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\obbokncgfcbepeipkhpdepjjoncelefj [2022-09-08]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\klaus\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2022-09-08]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2021-02-15] (Adobe Systems) [Datei ist nicht signiert]
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172264 2022-08-03] (Adobe Inc. -> Adobe Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [7472952 2022-03-15] (G DATA CyberDefense AG -> G DATA Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe [4113728 2022-03-15] (G DATA CyberDefense AG -> G DATA CyberDefense AG)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174976 2022-09-08] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [174976 2022-09-08] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncHelper.exe [3383688 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
S3 GDBackupSvc; C:\Program Files (x86)\G DATA\InternetSecurity\AVKBackup\AVKBackupService.exe [5763416 2022-03-15] (G DATA CyberDefense AG -> G DATA Software AG)
R3 GDFwSvc; C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe [6984512 2022-03-15] (G DATA CyberDefense AG -> G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [2018096 2022-03-15] (G DATA CyberDefense AG -> G DATA Software AG)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.181.0828.0002\OneDriveUpdaterService.exe [3803528 2022-09-22] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\NisSrv.exe [2496144 2020-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MsMpEng.exe [104192 2020-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 BraveElevationService; "C:\Program Files\BraveSoftware\Brave-Browser\Application\105.1.43.93\elevation_service.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert]
S0 GDElam; C:\WINDOWS\System32\DRIVERS\GDElam.sys [234432 2021-05-13] (Microsoft Windows Early Launch Anti-malware Publisher -> G DATA CyberDefense AG)
R3 GDKBB; C:\WINDOWS\system32\drivers\GDKBB64.sys [49808 2022-04-28] (G DATA Software AG -> G DATA Software AG)
R3 GDKBFlt; C:\WINDOWS\system32\drivers\GDKBFlt64.sys [38984 2022-04-28] (G DATA Software AG -> G DATA Software AG)
R1 GDMnIcpt; C:\WINDOWS\system32\drivers\MiniIcpt.sys [896424 2022-06-23] (Microsoft Windows Hardware Compatibility Publisher -> G DATA CyberDefense AG)
R3 GDNetflt; C:\WINDOWS\System32\DRIVERS\gdnetflt.sys [147880 2020-07-12] (G DATA Software AG -> G DATA Software AG)
R3 GDPkIcpt; C:\WINDOWS\system32\drivers\PktIcpt.sys [313768 2022-06-23] (Microsoft Windows Hardware Compatibility Publisher -> G DATA CyberDefense AG)
R1 gdwfpcd; C:\WINDOWS\System32\drivers\gdwfpcd64.sys [97560 2022-04-28] (G DATA Software AG -> G DATA Software AG)
R3 GRD; C:\WINDOWS\system32\drivers\GRD.sys [125640 2022-09-23] (G DATA Software AG -> G Data Software)
R1 HookCentre; C:\WINDOWS\system32\drivers\HookCentre.sys [327104 2022-06-23] (Microsoft Windows Hardware Compatibility Publisher -> G DATA CyberDefense AG)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45976 2020-07-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [408816 2020-07-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-07-08] (Microsoft Windows -> Microsoft Corporation)
R3 ysusb64; C:\WINDOWS\system32\drivers\ysusb64.sys [132712 2014-07-22] (Yamaha Corporation -> Yamaha Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2022-09-23 22:22 - 2022-09-23 22:23 - 000022932 _____ C:\Users\klaus\Downloads\FRST.txt
2022-09-23 22:22 - 2022-09-23 22:23 - 000000000 ____D C:\FRST
2022-09-23 22:22 - 2022-09-23 22:22 - 002371072 _____ (Farbar) C:\Users\klaus\Downloads\FRST64.exe
2022-09-23 22:22 - 2022-09-23 22:22 - 002371072 _____ (Farbar) C:\Users\klaus\Downloads\FRST64(1).exe
2022-09-23 20:27 - 2022-09-23 20:27 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-09-14 08:31 - 2022-09-14 08:31 - 000000000 _____ C:\Users\klaus\Downloads\gW7NqzAJ.htm
2022-09-13 20:19 - 2022-09-13 20:19 - 000413696 _____ C:\WINDOWS\system32\AzureCheck.dll
2022-09-13 20:19 - 2022-09-13 20:19 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-09-13 20:19 - 2022-09-13 20:19 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2022-09-13 20:19 - 2022-09-13 20:19 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-09-13 20:19 - 2022-09-13 20:19 - 000011813 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-09-13 20:15 - 2022-09-13 20:15 - 000000000 ___HD C:\$WinREAgent
2022-09-13 08:19 - 2022-09-13 08:19 - 000000000 ____D C:\Users\klaus\AppData\Roaming\com.adobe.dunamis
2022-09-08 19:01 - 2022-09-14 23:07 - 000002363 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2022-09-08 19:01 - 2022-09-14 23:07 - 000002322 _____ C:\Users\Public\Desktop\Brave.lnk
2022-09-08 19:01 - 2022-09-08 19:01 - 000003730 _____ C:\WINDOWS\system32\Tasks\BraveSoftwareUpdateTaskMachineUA{07EC2224-F51A-48A6-B91F-4281BF65B567}
2022-09-08 19:01 - 2022-09-08 19:01 - 000003606 _____ C:\WINDOWS\system32\Tasks\BraveSoftwareUpdateTaskMachineCore{E0F5C3E8-AB4E-4148-8721-6389F1A35A80}
2022-09-08 19:01 - 2022-09-08 19:01 - 000000000 ____D C:\Users\klaus\AppData\Local\BraveSoftware
2022-09-08 19:01 - 2022-09-08 19:01 - 000000000 ____D C:\Program Files\BraveSoftware
2022-09-08 19:01 - 2022-09-08 19:01 - 000000000 ____D C:\Program Files (x86)\BraveSoftware
2022-09-08 19:00 - 2022-09-08 19:00 - 001211536 _____ (BraveSoftware Inc.) C:\Users\klaus\Downloads\BraveBrowserSetup.exe
2022-09-06 08:57 - 2022-09-06 08:57 - 000693217 _____ C:\Users\klaus\Downloads\RSR Update 20220905.pdf
2022-09-05 09:13 - 2022-09-05 09:13 - 000000000 _____ C:\Users\klaus\Downloads\5VB5HRH3.htm
2022-09-02 11:19 - 2022-09-02 11:19 - 000072761 _____ C:\Users\klaus\Downloads\Bestellung_54245966875.pdf
2022-09-01 17:28 - 2022-09-01 17:28 - 000000000 _____ C:\Users\klaus\Downloads\cNtkvwTt.htm
2022-08-30 17:44 - 2022-08-30 17:44 - 004388518 _____ C:\Users\klaus\Downloads\202208_FASTBREAK_4gewinnt.pdf
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2022-09-23 22:20 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-09-23 22:14 - 2021-03-17 08:27 - 000125640 _____ (G Data Software) C:\WINDOWS\system32\Drivers\GRD.sys
2022-09-23 21:57 - 2021-03-06 01:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-09-23 21:10 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-09-23 21:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-09-23 20:59 - 2021-03-06 01:36 - 001722788 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-09-23 20:59 - 2019-12-07 16:50 - 000743708 _____ C:\WINDOWS\system32\perfh007.dat
2022-09-23 20:59 - 2019-12-07 16:50 - 000150130 _____ C:\WINDOWS\system32\perfc007.dat
2022-09-23 20:59 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2022-09-23 20:52 - 2021-10-10 09:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-09-23 20:52 - 2021-06-24 19:13 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-09-23 20:52 - 2021-03-06 01:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-09-23 20:52 - 2021-03-06 01:28 - 000008192 ___SH C:\DumpStack.log.tmp
2022-09-23 20:52 - 2020-07-18 20:46 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-09-23 20:52 - 2020-07-18 20:46 - 000000000 ____D C:\Users\klaus\AppData\LocalLow\Mozilla
2022-09-23 20:52 - 2020-07-18 20:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-09-23 20:52 - 2020-05-12 20:56 - 000000000 ___RD C:\Users\klaus\OneDrive
2022-09-23 20:52 - 2020-05-12 20:54 - 000000000 __SHD C:\Users\klaus\IntelGraphicsProfiles
2022-09-23 20:52 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-09-23 20:52 - 2018-12-17 19:06 - 000000000 ____D C:\Intel
2022-09-23 20:39 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2022-09-22 09:35 - 2021-12-11 09:51 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1985118773-2268224356-3260620144-1005
2022-09-22 09:35 - 2021-03-06 01:33 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-09-22 09:35 - 2020-07-19 23:15 - 000002155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-09-19 23:05 - 2021-03-06 01:28 - 000488856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-09-19 23:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-09-17 09:48 - 2020-05-12 21:02 - 000002501 _____ C:\Users\klaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-09-17 09:48 - 2020-05-12 21:02 - 000002464 _____ C:\Users\klaus\Desktop\Google Chrome.lnk
2022-09-17 09:05 - 2020-07-18 02:04 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-09-17 09:05 - 2020-07-18 02:04 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-09-13 20:21 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-09-13 20:19 - 2021-03-06 01:31 - 003011072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-09-13 20:13 - 2020-05-12 21:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-09-13 20:12 - 2018-12-17 16:11 - 141646296 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-09-12 08:36 - 2021-12-25 20:39 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2022-09-12 08:36 - 2021-12-25 20:39 - 000002068 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2022-09-12 08:36 - 2021-03-06 01:33 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-09-08 19:03 - 2020-05-27 22:04 - 000000000 ____D C:\Users\klaus\AppData\Local\D3DSCache
2022-09-06 17:44 - 2020-05-12 20:54 - 000000000 ____D C:\Users\klaus\AppData\Local\Packages
2022-08-30 13:42 - 2021-03-06 01:33 - 000003896 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-1985118773-2268224356-3260620144-1005UA
2022-08-30 13:42 - 2021-03-06 01:33 - 000003628 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-1985118773-2268224356-3260620144-1005Core
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2020-07-18 20:38 - 2020-07-18 20:38 - 000000000 _____ () C:\Users\klaus\AppData\Roaming\gdfw.log
2020-07-18 20:38 - 2020-07-18 20:38 - 000000779 _____ () C:\Users\klaus\AppData\Roaming\gdscan.log
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== |