Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: trojaner im system? windows7 64 bit, onlinebanking nicht möglich

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 07.03.2017, 10:39   #16
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Einen Fix brauchen wir noch:

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\Users\nina\AppData\Roaming\codec-08
C:\Users\nina\AppData\Roaming\tssop-40
C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\codec-11.lnk
C:\Users\nina\AppData\Local\{1866C01C-B55C-448B-980C-D6FB3B80EA35}
C:\Users\nina\AppData\Local\{4D2BEA44-2425-4476-9FED-9AD5FEE6CA97}
C:\ProgramData\versabus-5
C:\ProgramData\glitch-96
C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
cmd: dir /oge-d %LOCALAPPDATA%
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 07.03.2017, 12:29   #17
kangli
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 05-03-2017
durchgeführt von nina (07-03-2017 12:06:41) Run:2
Gestartet von C:\Users\nina\Desktop
Geladene Profile: nina (Verfügbare Profile: nina & UpdatusUser)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Users\nina\AppData\Roaming\codec-08
C:\Users\nina\AppData\Roaming\tssop-40
C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\codec-11.lnk
C:\Users\nina\AppData\Local\{1866C01C-B55C-448B-980C-D6FB3B80EA35}
C:\Users\nina\AppData\Local\{4D2BEA44-2425-4476-9FED-9AD5FEE6CA97}
C:\ProgramData\versabus-5
C:\ProgramData\glitch-96
C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
cmd: dir /oge-d %LOCALAPPDATA%
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
*****************

C:\Users\nina\AppData\Roaming\codec-08 => erfolgreich verschoben
"C:\Users\nina\AppData\Roaming\tssop-40" => nicht gefunden.
C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\codec-11.lnk => erfolgreich verschoben
C:\Users\nina\AppData\Local\{1866C01C-B55C-448B-980C-D6FB3B80EA35} => erfolgreich verschoben
C:\Users\nina\AppData\Local\{4D2BEA44-2425-4476-9FED-9AD5FEE6CA97} => erfolgreich verschoben
C:\ProgramData\versabus-5 => erfolgreich verschoben
"C:\ProgramData\glitch-96" => nicht gefunden.
C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} => erfolgreich verschoben

========= dir /oge-d %LOCALAPPDATA% =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\Users\nina\AppData\Local

07.03.2017  12:06    <DIR>          ..
07.03.2017  12:06    <DIR>          .
07.03.2017  12:05    <DIR>          Temp
03.03.2017  18:02    <DIR>          Mozilla
20.01.2017  13:39    <DIR>          Akamai
16.01.2017  12:38    <DIR>          Diagnostics
08.11.2016  11:20    <DIR>          Google
22.10.2016  00:14    <DIR>          Windows Live
29.08.2016  14:08    <DIR>          Windows Live Writer
30.07.2016  09:56    <DIR>          Microsoft
31.05.2016  23:21    <DIR>          Buhl
07.05.2016  20:35    <DIR>          Skype
18.01.2016  20:38    <DIR>          ElevatedDiagnostics
23.06.2015  10:37    <DIR>          Apple Computer
23.06.2015  10:22    <DIR>          Apple
27.02.2015  17:29    <DIR>          CrashRpt
27.02.2015  17:26    <DIR>          Programs
25.11.2014  11:45    <DIR>          Adobe
19.04.2013  10:24    <DIR>          Downloaded Installations
24.02.2013  15:21    <DIR>          Logitech-LS
05.02.2013  11:37    <DIR>          VirtualStore
10.01.2012  22:11    <DIR>          Canon Easy-PhotoPrint EX
04.11.2011  15:06    <DIR>          Deployment
04.11.2011  14:24    <DIR>          Apps
16.06.2011  08:11    <DIR>          Buhl Data Service
26.02.2011  10:58    <DIR>          Microsoft Help
12.04.2010  14:43    <DIR>          Rossmann Fotoservice
27.03.2010  17:35    <DIR>          Microsoft Games
11.03.2010  12:37    <DIR>          Thunderbird
10.02.2010  18:18    <DIR>          Oberon Games
06.02.2010  12:29    <DIR>          EgisTec
04.01.2017  11:30             1.456 Adobe Fr Web speichern 12.0 Prefs
31.03.2015  18:31           112.688 GDIPFONTCACHEV1.DAT
23.08.2015  12:03            32.768 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
28.12.2016  19:32             7.632 Resmon.ResmonCfg
30.11.2012  10:56             1.188 crc32list11.txt
               5 Datei(en),        155.732 Bytes
              31 Verzeichnis(se), 32.550.289.408 Bytes frei

========= Ende von CMD: =========


========= dir /oge-d %APPDATA% =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\Users\nina\AppData\Roaming

07.03.2017  12:06    <DIR>          ..
07.03.2017  12:06    <DIR>          .
07.03.2017  10:34    <DIR>          calculus-12
03.03.2017  18:02    <DIR>          Mozilla
03.01.2017  09:18    <DIR>          vlc
11.11.2016  18:44    <DIR>          Skype
05.09.2016  08:45    <DIR>          dvdcss
19.02.2016  11:47    <DIR>          Trimble Connect for SketchUp
19.02.2016  11:05    <DIR>          SketchUp
26.11.2015  10:58    <DIR>          ZoomBrowser EX
23.06.2015  10:29    <DIR>          Apple Computer
07.04.2015  14:18    <DIR>          hps-install
02.04.2015  10:50    <DIR>          Dropbox
21.12.2014  12:00    <DIR>          Autodesk
16.12.2014  13:46    <DIR>          Ambient Design
25.11.2014  11:21    <DIR>          Adobe
24.08.2014  10:55    <DIR>          uTorrent
09.05.2013  00:07    <DIR>          CameraWindowDC
05.02.2013  11:29    <DIR>          Google
22.11.2012  10:29    <DIR>          NVIDIA
10.01.2012  18:05    <DIR>          Canon
30.08.2011  16:33    <DIR>          Buhl Data Service
19.07.2011  15:32    <DIR>          Corel
06.06.2011  22:08    <DIR>          PDAppFlex
14.04.2011  14:35    <DIR>          WinRAR
15.01.2011  17:11    <DIR>          Windows Live Writer
09.12.2010  12:01    <DIR>          Nero
12.03.2010  12:41    <DIR>          Template
04.03.2010  08:59    <DIR>          Thunderbird
23.02.2010  18:23    <DIR>          NoteTab Light
23.02.2010  11:02    <DIR>          CANON INC
15.02.2010  16:47    <DIR>          ViquaSoft
13.02.2010  12:22    <DIR>          InstallShield
12.02.2010  16:29    <DIR>          Ulead Systems
12.02.2010  15:22    <DIR>          PlayFirst
09.02.2010  15:40    <DIR>          Langenscheidt
08.02.2010  19:12    <DIR>          GameConsole
06.02.2010  12:29    <DIR>          Macromedia
06.02.2010  12:28    <DIR>          Identities
14.07.2009  08:44    <DIR>          Media Center Programs
20.11.2011  19:10    <DIR>          de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
07.09.2011  17:29    <DIR>          Adobe Mini Bridge CS5.1
07.09.2011  17:29    <DIR>          StageManager.BD092818F67280F4B42B04877600987F0111B594.1
07.06.2011  06:55    <DIR>          chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
06.06.2011  18:26    <DIR>          com.adobe.downloadassistant.AdobeDownloadAssistant
04.09.2011  12:34    <DIR>          com.adobe.dmp.contentviewer
24.05.2015  12:15    <DIR>          CasaPortale.de
19.01.2011  10:46    <DIR>          OpenOffice.org
04.03.2015  13:38               132 Adobe BMP Format CS5 Prefs
04.11.2014  11:24               132 Adobe GIF Format CS5 Prefs
27.07.2012  09:48               132 Adobe PNG Format CS5 Prefs
13.01.2014  17:02            56.793 mdbu.bin
11.09.2014  09:48             2.736 wklnhst.dat
               5 Datei(en),         59.925 Bytes
              48 Verzeichnis(se), 32.550.285.312 Bytes frei

========= Ende von CMD: =========


========= dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

07.03.2017  12:06    <DIR>          ..
07.03.2017  12:06    <DIR>          .
19.07.2011  14:58             1.389 Adobe Gamma.lnk
19.01.2011  10:47             1.243 OpenOffice.org 3.3.lnk
               2 Datei(en),          2.632 Bytes
               2 Verzeichnis(se), 32.550.285.312 Bytes frei

========= Ende von CMD: =========


========= dir /oge-d %PROGRAMDATA% =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\ProgramData

07.03.2017  10:32    <DIR>          drain-3
07.03.2017  10:32    <DIR>          cvz
07.03.2017  09:41    <DIR>          NVIDIA
04.03.2017  12:52    <DIR>          Malwarebytes' Anti-Malware (portable)
04.03.2017  10:58    <DIR>          Malwarebytes
11.11.2016  17:34    <DIR>          Skype
19.02.2016  11:03    <DIR>          Reprise
19.02.2016  11:02    <DIR>          SketchUp
22.12.2015  09:37    <DIR>          CanonIJPLM
23.06.2015  10:22    <DIR>          Apple
17.05.2015  19:35    <DIR>          Package Cache
24.04.2015  07:49    <DIR>          ZoomBrowser
13.04.2015  19:12    <DIR>          tmp
02.04.2015  10:57    <DIR>          Microsoft Help
31.03.2015  18:43    <DIR>          Corel
27.02.2015  17:28    <DIR>          Ashampoo
04.02.2015  18:41    <DIR>          Tablet
21.12.2014  12:10    <DIR>          Alias
16.12.2014  13:45    <DIR>          Caphyon
02.12.2014  17:02    <DIR>          hps
25.11.2014  11:33    <DIR>          ALM
25.11.2014  11:18    <DIR>          Adobe
25.11.2014  09:43    <DIR>          InstallShield
30.09.2014  13:09    <DIR>          Buhl Data Service GmbH
01.07.2014  15:16    <DIR>          Oracle
05.02.2013  11:29    <DIR>          Google
20.11.2012  11:10    <DIR>          NVIDIA Corporation
10.01.2012  18:06    <DIR>          CanonIJ
10.01.2012  17:52    <DIR>          CanonIJMSetup
10.01.2012  17:51    <DIR>          CanonIJWSpt
19.07.2011  15:03    <DIR>          Adobe Systems
04.03.2011  22:01    <DIR>          WinZip
17.05.2010  09:54    <DIR>          Sun
11.04.2010  18:26    <DIR>          Rossmann Fotoservice
15.02.2010  17:20    <DIR>          TEMP
13.02.2010  13:40    <DIR>          FarmFrenzy2
12.02.2010  16:26    <DIR>          Ulead Systems
12.02.2010  15:22    <DIR>          PlayFirst
11.02.2010  17:00    <DIR>          Friends Games
09.02.2010  15:40    <DIR>          Langenscheidt
08.02.2010  19:13    <DIR>          Sandlot Games
06.02.2010  13:30    <DIR>          BackupManager
06.02.2010  13:26    <DIR>          McAfee
06.02.2010  12:30    <DIR>          McQcModifier-5c47-a7b0
06.02.2010  12:27    <DIR>          OEM
17.10.2009  03:39    <DIR>          EgisTec
17.10.2009  03:37    <DIR>          eSobi
17.10.2009  03:31    <DIR>          Nero
17.10.2009  03:28    <DIR>          SiteAdvisor
17.10.2009  03:20    <DIR>          Acer
04.09.2011  12:43    <DIR>          regid.1986-12.com.adobe
18.07.2009  02:57            36.136 FullRemove.exe
               1 Datei(en),         36.136 Bytes
              51 Verzeichnis(se), 32.550.281.216 Bytes frei

========= Ende von CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15853769 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 148216020 B
Firefox => 4637245 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
nina => 2109310 B
UpdatusUser => 0 B

RecycleBin => 18850903 B
EmptyTemp: => 188.9 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 12:06:58 ====
         
__________________


Alt 07.03.2017, 12:33   #18
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

__________________
__________________

Alt 07.03.2017, 13:40   #19
kangli
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 05-03-2017
durchgeführt von nina (Administrator) auf NINA-PC (07-03-2017 13:28:20)
Gestartet von C:\Users\nina\Desktop
Geladene Profile: nina (Verfügbare Profile: nina & UpdatusUser)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Windows\System32\atwtusb.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Windows\System32\atwtusb.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
() C:\Windows\System32\WTMKM.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Akamai Technologies, Inc.) C:\Users\nina\AppData\Local\Akamai\netsession_win.exe
(Adobe Systems, Inc.) C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe
(LG Soft India) C:\Program Files (x86)\LG Soft India\fortePivot\bin\fortePivot.exe
(Autodesk Inc) C:\Program Files (x86)\Autodesk\SketchBook Pro 6\SketchBookSnapshot.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
() C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\mshaktuell.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Akamai Technologies, Inc.) C:\Users\nina\AppData\Local\Akamai\netsession_win.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Google Inc.) C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\...\Run: [MacrokeyManager] => C:\Windows\system32\WTMKM.exe [7319784 2010-12-24] ()
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-24] (CANON INC.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-18] ()
HKLM-x32\...\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [F5D7050v3] => C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-17] (Google Inc.)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [Google Update] => C:\Users\nina\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-19] (Google Inc.)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [Rainlendar2] => C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [Akamai NetSession Interface] => C:\Users\nina\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [AdobeBridge] => C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe [12008296 2011-03-02] (Adobe Systems, Inc.)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AdobeCollabSync.exe [1104288 2015-09-24] (Adobe Systems Incorporated)
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [glitch-6] => C:\ProgramData\glitch-96\glitch-87.exe -cp
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\RunOnce: [calculus-6] => C:\Users\nina\AppData\Roaming\calculus-12\calculus-2.exe [732672 2017-03-07] ()
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {126412bf-6cb6-11e5-b433-00262d1702df} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {21a61c40-a70b-11e0-ab8a-00262d1702df} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {21a61c48-a70b-11e0-ab8a-00262d1702df} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {21a61c75-a70b-11e0-ab8a-00262d1702df} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {21a61c95-a70b-11e0-ab8a-001e101f41ca} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {37765aa0-142a-11e6-b175-00262d1702df} - I:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {519900d4-ac47-11e0-9e3e-001e101f82a7} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {519900e7-ac47-11e0-9e3e-001e101f82a7} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {519900fa-ac47-11e0-9e3e-001e101f82a7} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {5c1ee904-5247-11e6-b03b-00262d1702df} - F:\autorun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {a4df9bd1-aa20-11e0-8407-001e101f1838} - H:\AutoRun.exe
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\MountPoints2: {c4c11be6-be6f-11e0-b5ad-001e101fb4df} - H:\AutoRun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-03-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\fortePivot.lnk [2010-02-09]
ShortcutTarget: fortePivot.lnk -> C:\Program Files (x86)\LG Soft India\fortePivot\bin\fortePivot.exe (LG Soft India)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SketchBook Snapshot.lnk [2014-12-21]
ShortcutTarget: SketchBook Snapshot.lnk -> C:\Program Files (x86)\Autodesk\SketchBook Pro 6\SketchBookSnapshot.exe (Autodesk Inc)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk [2014-08-31]
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\mshaktuell.exe ()
Startup: C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2011-07-19]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Keine Datei)
Startup: C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2011-01-19]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.179.1
Tcpip\..\Interfaces\{484C66B6-C4E7-4D31-8BD2-95851F759015}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{4DD898AA-0C08-4C15-AE81-7C093A461B2B}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{71180E19-DECB-479F-BF54-F85A5337D83D}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{B62FAA76-E5E9-40CC-9085-BBC8A4CD98C2}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{C0FE9B58-1084-4ECF-AB5E-BF759928A622}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{D95127F8-293E-4D69-9EBB-77CFFFC5B098}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{DC41ACF5-0F0A-4307-9C19-B2C71EE0A74C}: [DhcpNameServer] 192.168.179.1
Tcpip\..\Interfaces\{FE10970D-3AB6-4286-BCE7-F32778E10C0C}: [DhcpNameServer] 192.168.178.1

Internet Explorer:
==================
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131330358742756000&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x1301&r=17360210sn07973380sj5bh8n12912
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-22] (Google Inc.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08] (CANON INC.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-22] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-22] (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-22] (Google Inc.)
Toolbar: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-22] (Google Inc.)
Toolbar: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> Kein Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  Keine Datei
Toolbar: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000 -> Kein Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  Keine Datei
DPF: HKLM-x32 {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies)

FireFox:
========
FF DefaultProfile: 121pg7uc.default
FF ProfilePath: C:\Users\nina\AppData\Roaming\Mozilla\Firefox\Profiles\121pg7uc.default [2017-03-07]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2017-03-04] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.)
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-05-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll [Keine Datei]
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-05-07] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1885290322-1835322729-3868160957-1000: @tools.google.com/Google Update;version=3 -> C:\Users\nina\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-1885290322-1835322729-3868160957-1000: @tools.google.com/Google Update;version=9 -> C:\Users\nina\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www1.delta-search.com/?affID=119370&tt=180413_ctrl&babsrc=HP_ss&mntrId=884C9444520175F6
CHR StartupUrls: Default -> "hxxp://www.google.de/"
CHR Plugin: (Native Client) - C:\Users\nina\AppData\Local\Google\Chrome\Application\56.0.2924.87\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\nina\AppData\Local\Google\Chrome\Application\56.0.2924.87\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\nina\AppData\Local\Google\Chrome\Application\56.0.2924.87\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll => Keine Datei
CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll => Keine Datei
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll => Keine Datei
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Profile: C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default [2017-03-07]
CHR Extension: (YouTube) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28]
CHR Extension: (Google-Suche) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Skype) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-06]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Google Mail) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-12]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-07-19] (Adobe Systems) [Datei ist nicht signiert]
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] ()
S3 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTService; C:\Windows\system32\atwtusb.exe [914664 2011-01-26] () [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2015-05-07] (Huawei Technologies Co., Ltd.)
R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [7680 2009-03-08] (Windows (R) Codename Longhorn DDK provider)
R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [7552 2009-08-26] (Windows (R) Win 7 DDK provider)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-03-07 10:34 - 2017-03-07 10:34 - 00000000 ____D C:\Users\nina\AppData\Roaming\calculus-12
2017-03-07 10:32 - 2017-03-07 10:32 - 00000000 ____D C:\ProgramData\drain-3
2017-03-07 09:42 - 2017-03-07 09:42 - 00000018 _____ C:\Windows\賫ޙ
2017-03-07 09:42 - 2017-03-07 09:42 - 00000011 _____ C:\Windows\桍ޙ
2017-03-07 09:42 - 2017-03-07 09:42 - 00000011 _____ C:\Windows\ׁޕ
2017-03-07 09:42 - 2017-03-07 09:42 - 00000011 _____ C:\Windows\Έޛ
2017-03-07 09:38 - 2017-03-07 10:32 - 00000000 ____D C:\ProgramData\cvz
2017-03-07 09:32 - 2017-03-07 12:06 - 00010955 _____ C:\Users\nina\Desktop\Fixlog.txt
2017-03-07 08:08 - 2017-03-07 08:08 - 00000018 _____ C:\Windows\楮ⴴ
2017-03-07 08:08 - 2017-03-07 08:08 - 00000011 _____ C:\Windows\瓼ⴴ
2017-03-07 08:08 - 2017-03-07 08:08 - 00000011 _____ C:\Windows\ⴲ
2017-03-07 08:08 - 2017-03-07 08:08 - 00000011 _____ C:\Windows\৙ⴴ
2017-03-05 16:58 - 2017-03-05 16:58 - 00000000 ____D C:\Users\nina\Desktop\FRST-OlderVersion
2017-03-04 18:21 - 2017-03-04 18:21 - 00281822 _____ C:\Users\nina\Desktop\JRT.txt
2017-03-04 18:01 - 2017-03-04 18:01 - 01663736 _____ (Malwarebytes) C:\Users\nina\Desktop\JRT.exe
2017-03-04 17:46 - 2017-03-05 13:45 - 00000000 ____D C:\AdwCleaner
2017-03-04 17:46 - 2017-03-04 17:46 - 04031440 _____ C:\Users\nina\Desktop\adwcleaner_6.044.exe
2017-03-04 11:38 - 2017-03-04 11:38 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-03-04 10:58 - 2017-03-04 10:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-03-04 10:57 - 2017-03-04 12:52 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-03-04 10:57 - 2017-03-04 11:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-04 10:56 - 2017-03-04 12:31 - 00000000 ____D C:\Users\nina\Desktop\mbar
2017-03-04 10:56 - 2017-03-04 11:45 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-03-04 10:51 - 2017-03-05 21:47 - 00000000 ____D C:\Users\nina\Desktop\Neuer Ordner
2017-03-04 10:50 - 2017-03-04 10:51 - 16563352 _____ (Malwarebytes Corp.) C:\Users\nina\Desktop\mbar-1.09.3.1001.exe
2017-03-04 10:36 - 2017-03-04 10:36 - 00001990 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2017-03-04 00:51 - 2017-03-04 17:58 - 00049159 _____ C:\Users\nina\Desktop\troja.odt
2017-03-03 23:58 - 2017-03-05 17:02 - 00046822 _____ C:\Users\nina\Desktop\Addition.txt
2017-03-03 23:57 - 2017-03-07 13:29 - 00026044 _____ C:\Users\nina\Desktop\FRST.txt
2017-03-03 23:55 - 2017-03-07 13:28 - 00000000 ____D C:\FRST
2017-03-03 23:53 - 2017-03-05 16:58 - 02423808 _____ (Farbar) C:\Users\nina\Desktop\FRST64.exe
2017-03-03 22:35 - 2017-03-03 22:35 - 08138319 _____ C:\Users\nina\Desktop\Nicht bestätigt 928768.crdownload
2017-03-03 22:35 - 2017-03-03 22:35 - 00144521 _____ C:\Users\nina\Desktop\Nicht bestätigt 19139.crdownload
2017-03-03 22:34 - 2017-03-03 22:35 - 42033936 _____ (Microsoft Corporation) C:\Users\nina\Desktop\mpas-feX64.exe
2017-03-03 18:03 - 2017-03-07 10:27 - 00000000 ____D C:\Users\nina\AppData\LocalLow\Mozilla
2017-03-03 18:02 - 2017-03-03 18:02 - 00001127 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-03 18:02 - 2017-03-03 18:02 - 00001115 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-03-03 18:02 - 2017-03-03 18:02 - 00000000 ____D C:\Users\nina\AppData\Local\Mozilla
2017-03-03 18:02 - 2017-03-03 18:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-03 17:58 - 2017-03-03 17:58 - 00245600 _____ C:\Users\nina\Desktop\Firefox Setup Stub 51.0.1.exe
2017-02-24 07:28 - 2017-02-24 07:28 - 00000009 _____ C:\Windows\㘏ਙ

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-03-07 12:44 - 2013-02-28 09:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-03-07 12:17 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-07 12:17 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-07 12:09 - 2011-02-27 12:02 - 01041408 ___SH C:\Users\nina\Desktop\Thumbs.db
2017-03-07 12:09 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-03-07 12:09 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-07 12:09 - 2009-07-14 03:34 - 00000434 _____ C:\Windows\win.ini
2017-03-07 12:09 - 2006-10-10 19:51 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-07 09:43 - 2017-01-24 23:40 - 00000000 ____D C:\Users\nina\Desktop\hugenberg
2017-03-07 09:43 - 2014-01-11 13:29 - 00000000 ____D C:\Users\nina\Desktop\zumEntwickeln
2017-03-07 09:42 - 2017-01-02 11:29 - 00000000 ____D C:\Users\nina\Desktop\berlin-rätsel
2017-03-07 09:42 - 2016-05-03 19:29 - 00000000 ____D C:\Users\nina\Desktop\posterbilder keramik
2017-03-07 09:42 - 2016-02-05 10:21 - 00000000 ____D C:\Users\nina\Desktop\LAURA
2017-03-07 09:42 - 2015-11-26 10:34 - 00000000 ____D C:\Users\nina\Desktop\NINA website nika
2017-03-07 09:42 - 2015-01-07 10:50 - 00000000 ____D C:\Users\nina\Desktop\Nina keramikt
2017-03-07 09:42 - 2015-01-07 08:55 - 00000000 ____D C:\Users\nina\Desktop\sonderbares
2017-03-07 09:42 - 2014-01-08 15:40 - 00000000 ____D C:\Users\nina\Desktop\Ninas Bilder
2017-03-07 09:42 - 2012-06-29 12:48 - 00000000 ____D C:\Users\nina\Desktop\kinder
2017-03-07 09:42 - 2010-05-17 10:33 - 00000000 ____D C:\Users\nina\Desktop\ninas
2017-03-07 09:33 - 2011-01-19 10:39 - 00000000 ____D C:\Users\nina\AppData\LocalLow\Temp
2017-03-07 09:10 - 2010-02-12 15:07 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{662A48E4-3352-4B0B-A1E0-6692743A0C5A}
2017-03-07 08:06 - 2011-06-16 08:24 - 00000000 ____D C:\Users\nina\Documents\Mein Steuer-Sparbuch Heute
2017-03-06 10:21 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-06 10:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2017-03-06 10:21 - 2006-10-11 05:40 - 00696832 _____ C:\Windows\system32\perfh007.dat
2017-03-06 10:21 - 2006-10-11 05:40 - 00148128 _____ C:\Windows\system32\perfc007.dat
2017-03-06 10:00 - 2016-10-21 21:24 - 00016939 _____ C:\Users\nina\Desktop\LEBEN Inhaltsverzeichnis.ods
2017-03-04 17:53 - 2010-02-06 12:27 - 00000000 ____D C:\Users\nina
2017-03-04 10:51 - 2014-07-08 11:02 - 00000000 ____D C:\Users\nina\Desktop\Nina zeichnet
2017-03-04 10:36 - 2014-11-25 11:32 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2017-03-04 10:36 - 2014-11-25 11:32 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2017-03-04 10:36 - 2014-11-25 11:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2017-03-03 18:02 - 2013-04-19 10:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-03 18:02 - 2010-03-04 08:59 - 00000000 ____D C:\Users\nina\AppData\Roaming\Mozilla
2017-02-24 16:24 - 2014-01-13 10:46 - 00000000 ____D C:\Users\nina\Desktop\Matriarchat
2017-02-18 18:37 - 2016-07-31 18:28 - 00000000 ____D C:\Users\nina\Desktop\Nina kreativ
2017-02-16 17:27 - 2013-12-23 16:11 - 00000000 ____D C:\Users\nina\Desktop\AAAfamilienchronik
2017-02-15 11:44 - 2013-02-28 09:23 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-02-15 11:44 - 2013-02-28 09:23 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 11:44 - 2011-11-20 12:40 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-15 11:44 - 2011-09-12 16:55 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-15 11:44 - 2009-10-17 03:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-07 08:23 - 2010-03-12 12:13 - 00002366 _____ C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2009-10-17 03:04 - 2009-02-10 20:23 - 0192484 _____ () C:\Program Files (x86)\Common Files\Acer GameZone online.ico
2012-04-18 09:01 - 2015-03-04 13:38 - 0000132 _____ () C:\Users\nina\AppData\Roaming\Adobe BMP Format CS5 Prefs
2014-11-04 11:24 - 2014-11-04 11:24 - 0000132 _____ () C:\Users\nina\AppData\Roaming\Adobe GIF Format CS5 Prefs
2012-07-27 09:48 - 2012-07-27 09:48 - 0000132 _____ () C:\Users\nina\AppData\Roaming\Adobe PNG Format CS5 Prefs
2010-04-11 18:46 - 2014-01-13 17:02 - 0056793 _____ () C:\Users\nina\AppData\Roaming\mdbu.bin
2010-03-12 12:39 - 2014-09-11 09:48 - 0002736 _____ () C:\Users\nina\AppData\Roaming\wklnhst.dat
2012-06-10 20:25 - 2017-01-04 11:30 - 0001456 _____ () C:\Users\nina\AppData\Local\Adobe Für Web speichern 12.0 Prefs
2011-06-16 08:13 - 2012-11-30 10:56 - 0001188 _____ () C:\Users\nina\AppData\Local\crc32list11.txt
2011-03-04 17:15 - 2015-08-23 12:03 - 0032768 _____ () C:\Users\nina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-01 12:01 - 2016-12-28 19:32 - 0007632 _____ () C:\Users\nina\AppData\Local\Resmon.ResmonCfg
2011-05-23 09:39 - 2015-03-31 18:41 - 0000088 __RSH () C:\ProgramData\933CE29C00.sys
2009-10-17 03:04 - 2009-07-18 02:57 - 0036136 _____ (Oberon Media) C:\ProgramData\FullRemove.exe
2011-05-23 09:39 - 2015-03-31 18:41 - 0002516 ___SH () C:\ProgramData\KGyGaAvL.sys

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2016-11-01 11:35

==================== Ende von FRST.txt ============================
         
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 05-03-2017
durchgeführt von nina (07-03-2017 13:29:31)
Gestartet von C:\Users\nina\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2010-02-06 11:27:05)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1885290322-1835322729-3868160957-500 - Administrator - Disabled)
Gast (S-1-5-21-1885290322-1835322729-3868160957-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1885290322-1835322729-3868160957-1005 - Limited - Enabled)
nina (S-1-5-21-1885290322-1835322729-3868160957-1000 - Administrator - Enabled) => C:\Users\nina
UpdatusUser (S-1-5-21-1885290322-1835322729-3868160957-1003 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Acer Backup Manager (HKLM-x32\...\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.2.0812 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.)
Adobe Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated)
Adobe Creative Suite 5.5 Design Standard (HKLM-x32\...\{53CF3920-648B-4F99-8D05-6A6C5298F57B}) (Version: 5.5 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.1 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
ArtRage 4 Demo (HKLM-x32\...\ArtRage 4 Demo 4.5.2.0) (Version: 4.5.2.0 - Ambient Design)
ArtRage 4 Demo (Version: 4.5.2.0 - Ambient Design) Hidden
Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version:  - )
Autodesk SketchBook Pro 6 (HKLM-x32\...\{C7C8BE4E-428D-4AA9-B7D4-EA4313BDB90E}) (Version: 6.00.0000 - Autodesk)
Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden
Belkin 54Mbps Wireless Network Adapter (HKLM-x32\...\{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}) (Version: 1.00.01 - Belkin)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version:  - )
CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.7.0.4 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon Internet Library for ZoomBrowser EX (HKLM-x32\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.)
Canon MG5200 series Benutzerregistrierung (HKLM-x32\...\Canon MG5200 series Benutzerregistrierung) (Version:  - )
Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version:  - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 3.0.0.20 - Canon Inc.)
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.2.0.2 - Canon Inc.)
Canon Utilities CameraWindow DC (HKLM-x32\...\CameraWindowDC) (Version: 7.4.0.9 - Canon Inc.)
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowDVC6) (Version: 6.5.0.3 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.2.0.4 - Canon Inc.)
Canon Utilities MyCamera DC (HKLM-x32\...\MyCameraDC) (Version: 7.2.0.5 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.22.46 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.8.0.1 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.3.0.7 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.2.0.9 - Canon Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Driver Download Manager (HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\f031ef6ac137efc5) (Version: 2.1.0.0 - Dell Inc.)
FormatFactory 2.60 (HKLM-x32\...\FormatFactory) (Version: 2.60 - Free Time)
fortePivot (HKLM-x32\...\{EDF3EEF2-F0B9-440B-B8B9-A61F2DA8C78A}) (Version: 3.05 - LG Soft India)
Free WMA to MP3 Converter 1.16 (HKLM-x32\...\Free WMA to MP3 Converter_is1) (Version:  - Jodix Technologies Ltd.)
Google Chrome (HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3002 - Acer Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.600 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 51.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
myphotobook.de (HKLM-x32\...\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.3.0 - myphotobook GmbH)
myphotobook.de (x32 Version: 1.3.0 - myphotobook GmbH) Hidden
MyWinLocker (HKLM-x32\...\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nero 9 Essentials (HKLM-x32\...\{e30fce96-c91b-4f1f-af7b-1bf58fdbbf24}) (Version:  - Nero AG)
NoteTab Light 6 (Remove only) (HKLM-x32\...\NoteTab Light 6_is1) (Version: 6.2 - Fookes Holding Ltd)
NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\...\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version:  - )
NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
OpenOffice.org 3.3 (HKLM-x32\...\{45E2C43E-C111-4E4D-9C3C-65EE5D3C8A17}) (Version: 3.3.9561 - OpenOffice.org)
Paint XP version 1.1 (HKLM-x32\...\{2367FAB6-055A-4923-835F-F57F7BBBA363}_is1) (Version: 1.1 - MSPAINTXP.COM)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Print Server Utilities (HKLM-x32\...\{38697498-F4AA-4A8A-81F6-C09446AD020D}) (Version: 4.2.9.0 - Edimax Technology CO., Ltd.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.47 - Piriform)
Rossmann Fotoservice (HKLM-x32\...\Rossmann Fotoservice_is1) (Version:  - )
Rossmann Fotowelt Software 4.13 (HKLM-x32\...\Rossmann Fotowelt Software) (Version: 4.13 - ORWO Net)
Russisch für Deutsche - empfohlen (HKLM\...\{4C47DA93-303F-4165-918B-BCBAD9099DB8}) (Version: 1.0.3.40 - Uni Leipzig)
SketchUp 2016 (HKLM\...\{F40C8253-11C9-4D11-A392-B335E22D1C52}) (Version: 16.0.19912 - Trimble Navigation Limited)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Tablet Driver With Macrokey Manager (HKLM\...\RmTablet) (Version:  - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 4.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
WinZip 14.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )
WISO steuer:Sparbuch 2016 (HKLM-x32\...\{581CC200-E64B-4F7C-A38E-A32A434FA839}) (Version: 23.07.1500 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2011 (HKLM-x32\...\{02F0B8AE-7501-4333-AFBE-6BAABFEC7637}) (Version: 18.00.6928 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2012 (HKLM-x32\...\{0CC1DAFB-40C8-4903-953D-471E541477C7}) (Version: 19.00.7303 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2013 (HKLM-x32\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2014 (HKLM-x32\...\{9C0BE206-DAF0-4D5B-81C9-D4795CFF6DDD}) (Version: 21.00.8480 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2015 (HKLM-x32\...\{FACA575E-E815-4932-A5A9-FC80274C5DB0}) (Version: 22.00.8811 - Buhl Data Service GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\ChromeHTML: -> C:\Users\nina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\nina\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1885290322-1835322729-3868160957-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\nina\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {043F1DF6-F3E6-4CC7-B673-7E6C7FD0BDFA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {05F02D51-2FA2-4321-974C-37B93E6E72BE} - System32\Tasks\File Helper => C:\Program Files (x86)\File Helper\File Helper.lnk 
Task: {2DFD0298-C0AB-4E65-B474-E421C0C63042} - System32\Tasks\AdobeAAMUpdater-1.0-nina-PC-nina => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-30] (Adobe Systems Incorporated)
Task: {6AE26DE8-9AB2-4DEC-95C4-8A0B360F0E0E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {AF8ECBD9-0B11-4D23-BE27-3C3881D1D7A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1885290322-1835322729-3868160957-1000Core => C:\Users\nina\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)
Task: {D0A6CF98-AE0B-4823-B7E3-C203C1660824} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {E9015744-6B62-4150-9E1D-889544150314} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {FC820B1E-A5C9-454D-860C-136B02E7A087} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1885290322-1835322729-3868160957-1000UA => C:\Users\nina\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\File Helper.job => C:\Program Files (x86)\File Helper\File Helper.lnk

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-11-20 11:11 - 2013-01-18 16:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2011-05-25 08:26 - 2011-01-26 07:46 - 00914664 _____ () C:\Windows\system32\atwtusb.exe
2009-04-19 16:34 - 2009-04-19 16:34 - 00625184 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2009-04-19 16:34 - 2009-04-19 16:34 - 00070176 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2009-04-19 16:34 - 2009-04-19 16:34 - 00578080 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2009-04-19 16:34 - 2009-04-19 16:34 - 00207904 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2011-05-25 08:26 - 2010-12-24 08:30 - 07319784 _____ () C:\Windows\System32\WTMKM.exe
2009-08-18 08:27 - 2009-08-18 08:27 - 00629280 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
2014-08-31 18:25 - 2014-08-07 12:29 - 01427736 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\mshaktuell.exe
2009-02-03 01:33 - 2009-02-03 01:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-29 01:55 - 2008-09-29 01:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2011-03-02 21:34 - 2011-03-02 21:34 - 00073728 _____ () C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Symlib.dll
2011-03-02 21:34 - 2011-03-02 21:34 - 02748416 _____ () C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\LIBMYSQLD.dll
2010-02-09 11:56 - 2008-12-30 18:48 - 00036864 _____ () C:\Program Files (x86)\LG Soft India\fortePivot\bin\ErrorHandler.dll
2010-02-09 11:56 - 2008-12-30 18:48 - 00028672 _____ () C:\Program Files (x86)\LG Soft India\fortePivot\bin\MSGHOOK.dll
2009-08-18 08:31 - 2009-08-18 08:31 - 00163840 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 09707800 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wgui14.dll
2014-08-31 18:22 - 2014-08-07 12:28 - 00035608 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\rsdcom48.dll
2014-08-31 18:22 - 2014-08-07 12:28 - 00309016 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\rscorewinapi48.dll
2014-08-31 18:22 - 2014-08-07 12:29 - 00322840 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\rsguiwinapi48.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 03890288 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wcore14.dll
2014-08-31 18:22 - 2014-08-07 12:28 - 00136472 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\rsodbc48.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 02745624 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wfvie14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 02123032 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wsteu14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01933080 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wreli14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 04325144 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wauff14.dll
2014-08-31 18:22 - 2014-02-11 10:53 - 01043456 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\clucene-core.dll
2014-08-31 18:22 - 2014-02-11 10:53 - 00094720 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\clucene-shared.dll
2014-08-31 18:22 - 2014-02-11 10:53 - 00250368 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\clucene-contribs-lib.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01573656 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wmain14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 05300504 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wbae114.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01702168 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wbae214.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01810712 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wbae314.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01629464 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wbae414.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01117976 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\whau114.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01340696 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\whau214.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01312536 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wwerb14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 07353112 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wkont14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01287448 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wimp14.dll
2014-08-31 18:21 - 2014-08-07 12:29 - 01331480 _____ () C:\Users\nina\Desktop\ninas\AAFinanzen\steuer\2013\wfabu14.dll
2011-01-06 17:51 - 2011-01-19 10:43 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2015-09-24 16:41 - 2015-09-24 16:41 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\locale\de_de\acrotray.deu
2017-02-07 08:23 - 2017-02-01 10:01 - 01870168 _____ () C:\Users\nina\AppData\Local\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-07 08:23 - 2017-02-01 10:01 - 00085848 _____ () C:\Users\nina\AppData\Local\Google\Chrome\Application\56.0.2924.87\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\nina\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.179.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{EEF4EF4A-AF52-4CB8-9D4C-913AD70FDC91}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{001C1B99-4E11-4BA1-8012-C08E79C0FFDA}] => (Allow) LPort=2869
FirewallRules: [{8C5BC50B-65DD-49F6-8648-F0FB1A4F0CBB}] => (Allow) LPort=1900
FirewallRules: [{6EB94166-9DA6-4E62-8B65-B1F880FD04CA}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [TCP Query User{C6F12CA5-1C3F-4A94-9CDA-1768ED4BE70B}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{19A34231-2A28-4E74-B514-4BF33395F615}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F07AEB09-845E-4FB2-BD54-00467740A77E}C:\users\nina\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\nina\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{9FF133DF-54BA-47B5-B09F-69CC17200409}C:\users\nina\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\nina\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{7950B0AC-3241-4B37-B657-A8F4BC608EB5}E:\german\wizard\ezwizard.exe] => (Allow) E:\german\wizard\ezwizard.exe
FirewallRules: [UDP Query User{352CE334-715F-48D3-A95E-49184874BECB}E:\german\wizard\ezwizard.exe] => (Allow) E:\german\wizard\ezwizard.exe
FirewallRules: [TCP Query User{68F04AAB-8701-43C1-97AC-D2C08CAE2728}C:\users\nina\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\nina\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{4DE7DDBD-A7C0-466A-82F1-BBD14D09DE73}C:\users\nina\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\nina\appdata\local\akamai\netsession_win.exe
FirewallRules: [{2315058F-E8D4-4DD3-8BA6-965DD170A2F8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{2F8F9E5A-45D6-4F10-A487-62B9995AB5BE}C:\users\nina\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\nina\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{EDA1B043-D3C0-44B9-8F76-92F0D29AB751}C:\users\nina\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\nina\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{F2676715-8DA7-4750-B894-205C181C0B9A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{3BDEE524-6003-459A-89E5-F64BE7B14236}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{ECABDCF7-1806-4106-99A1-8B0971DB2253}] => (Allow) C:\Users\nina\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{EC95C674-7841-432A-A89C-FD5DAF1A2526}] => (Allow) C:\Users\nina\AppData\Local\iLivid\iLivid.exe
FirewallRules: [TCP Query User{D22916C2-6E5E-4B87-AA15-70FEFC5F2AAA}C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe] => (Allow) C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe
FirewallRules: [UDP Query User{EC033F5A-8C88-42B5-BCE0-BACEF7EF6BF9}C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe] => (Allow) C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe
FirewallRules: [TCP Query User{7D2F6F47-47A9-4F3D-AF20-1F1680149699}C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe] => (Allow) C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe
FirewallRules: [UDP Query User{7DB2EDC5-D434-4180-A631-CAF4D8E4F4D9}C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe] => (Allow) C:\program files (x86)\sketchup\sketchup 2014\sketchup.exe
FirewallRules: [TCP Query User{A3EE4320-3EAB-403A-8BCD-ACC00B16282F}C:\program files (x86)\sketchup\sketchup 2014\layout\layout.exe] => (Block) C:\program files (x86)\sketchup\sketchup 2014\layout\layout.exe
FirewallRules: [UDP Query User{A69A36A2-8F1F-4634-BBA5-831905E3B591}C:\program files (x86)\sketchup\sketchup 2014\layout\layout.exe] => (Block) C:\program files (x86)\sketchup\sketchup 2014\layout\layout.exe
FirewallRules: [TCP Query User{9897F3DC-473A-40B5-8536-DFFE9555FBE4}C:\users\nina\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\nina\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3E13093E-A869-4D54-9ABF-938E90028FEA}C:\users\nina\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\nina\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{94B921AE-EADB-485B-A93F-E8150B3CD736}C:\users\nina\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\nina\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{01B08223-DAB4-46CC-8A0B-6121C0BD490B}C:\users\nina\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\nina\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{534A5BD9-5869-4A35-917E-6D81F0C9C3B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F3B3585B-D13A-4BD4-B758-06D58DFE7F55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Wiederherstellungspunkte =========================

03-03-2017 18:29:21 Windows Defender Checkpoint
04-03-2017 11:34:33 Malwarebytes Anti-Rootkit Restore Point
04-03-2017 18:01:51 JRT Pre-Junkware Removal
04-03-2017 18:03:41 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (03/03/2017 06:29:10 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {d3508bf0-4e1d-4b01-949b-d8ae529b422f}

Error: (02/05/2017 12:16:01 PM) (Source: Distributed Link Tracking Client) (EventID: 12503) (User: )
Description: Event-ID 12503

Error: (01/20/2017 08:39:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x438
Startzeit der fehlerhaften Anwendung: 0x01d272f04c42e680
Pfad der fehlerhaften Anwendung: C:\Windows\system32\svchost.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 93f7a650-dee3-11e6-920d-00262d1702df

Error: (01/04/2017 09:26:33 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a144
Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18952, Zeitstempel: 0x55c3a0ed
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000034c40b
ID des fehlerhaften Prozesses: 0x478
Startzeit der fehlerhaften Anwendung: 0x01d2665defea0240
Pfad der fehlerhaften Anwendung: C:\Windows\Explorer.EXE
Pfad des fehlerhaften Moduls: C:\Windows\system32\SHELL32.dll
Berichtskennung: 7fa3a6b0-d257-11e6-aebc-00262d1702df

Error: (12/28/2016 07:36:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Photoshop.exe, Version 12.1.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 558

Startzeit: 01d26126c01b2670

Endzeit: 560

Anwendungspfad: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe

Berichts-ID:

Error: (11/08/2016 11:26:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: senddoc.exe, Version: 0.0.0.0, Zeitstempel: 0x4d05f0da
Name des fehlerhaften Moduls: smapi.dll, Version: 15.4.3555.308, Zeitstempel: 0x4f597079
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008d6f
ID des fehlerhaften Prozesses: 0x470
Startzeit der fehlerhaften Anwendung: 0x01d239aa85c1f470
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\OpenOffice.org 3\Basis\program\senddoc.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Windows Live\Mail\smapi.dll
Berichtskennung: cd8ce3f0-a59d-11e6-a104-00262d1702df

Error: (10/31/2016 02:33:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x724
Startzeit der fehlerhaften Anwendung: 0x01d2337b546ff8c0
Pfad der fehlerhaften Anwendung: C:\Windows\system32\svchost.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 9d8c5ee0-9f6e-11e6-ae7d-00262d1702df

Error: (10/03/2016 09:45:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AcroDist.exe, Version: 10.0.0.396, Zeitstempel: 0x4cc5d526
Name des fehlerhaften Moduls: ACE.dll, Version: 2.17.17.1, Zeitstempel: 0x4cc5f80d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00003880
ID des fehlerhaften Prozesses: 0xd28
Startzeit der fehlerhaften Anwendung: 0x01d21d525a351e00
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AcroDist.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\ACE.dll
Berichtskennung: aea524d0-8945-11e6-b06c-00262d1702df

Error: (09/08/2016 08:39:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: wmplayer.exe, Version: 12.0.7601.19148, Zeitstempel: 0x56b9adac
Name des fehlerhaften Moduls: AviSplitter.ax, Version: 1.3.1290.0, Zeitstempel: 0x4ac0eaff
Ausnahmecode: 0xc0000417
Fehleroffset: 0x00028120
ID des fehlerhaften Prozesses: 0xac0
Startzeit der fehlerhaften Anwendung: 0x01d209a40f3ca970
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Filters\AviSplitter.ax
Berichtskennung: 59019430-7597-11e6-83c7-00262d1702df

Error: (08/24/2016 09:14:46 AM) (Source: ESENT) (EventID: 215) (User: )
Description: wlcomm (2212) C:\Users\nina\AppData\Local\Microsoft\Windows Live\Contacts\default\15.5\: Die Sicherung wurde abgebrochen, weil sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen wurde.


Systemfehler:
=============
Error: (03/07/2017 12:11:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (03/07/2017 12:11:22 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Anmeldung fehlgeschlagen: Das angegebene Kennwort des Kontos ist abgelaufen.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (03/07/2017 09:43:56 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (03/07/2017 09:43:56 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Anmeldung fehlgeschlagen: Das angegebene Kennwort des Kontos ist abgelaufen.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (03/07/2017 08:06:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (03/07/2017 08:06:38 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Anmeldung fehlgeschlagen: Das angegebene Kennwort des Kontos ist abgelaufen.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (03/06/2017 08:23:22 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (03/06/2017 08:23:22 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Anmeldung fehlgeschlagen: Das angegebene Kennwort des Kontos ist abgelaufen.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (03/05/2017 01:49:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (03/05/2017 01:49:49 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Anmeldung fehlgeschlagen: Das angegebene Kennwort des Kontos ist abgelaufen.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).


CodeIntegrity:
===================================
  Date: 2015-10-17 22:16:09.155
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:09.005
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.872
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.692
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.560
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.425
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.288
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:16:08.142
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:11:54.394
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-10-17 22:11:54.262
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Speicherinformationen =========================== 

Prozessor: AMD Athlon(tm) II X2 215 Processor 
Prozentuale Nutzung des RAM: 59%
Installierter physikalischer RAM: 2814.55 MB
Verfügbarer physikalischer RAM: 1127.15 MB
Summe virtueller Speicher: 5627.29 MB
Verfügbarer virtueller Speicher: 3596.96 MB

==================== Laufwerke ================================

Drive c: (Acer) (Fixed) (Total:142.16 GB) (Free:30.48 GB) NTFS
Drive d: (DATA) (Fixed) (Total:142.16 GB) (Free:112.51 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: A8DB9BE5)
Partition 1: (Not Active) - (Size=13.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=142.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=142.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         

Alt 07.03.2017, 14:42   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Wir brauchen noch nen Fix...


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [glitch-6] => C:\ProgramData\glitch-96\glitch-87.exe -cp
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\RunOnce: [calculus-6] => C:\Users\nina\AppData\Roaming\calculus-12\calculus-2.exe [732672 2017-03-07] ()
HKLM-x32\...\Run: [] => [X]
C:\Users\nina\AppData\Roaming\calculus-12
C:\Programdata\drain-3
C:\Windows\賫ޙ
C:\Windows\桍ޙ
C:\Windows\ׁޕ
C:\Windows\Έޛ
C:\ProgramData\cvz
C:\Windows\楮ⴴ
C:\Windows\瓼ⴴ
C:\Windows\ⴲ
C:\Windows\৙ⴴ
C:\Windows\㘏ਙ
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


__________________
Logfiles bitte immer in CODE-Tags posten

Alt 07.03.2017, 15:17   #21
kangli
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



ich hab übrigens gar keinen virenscanner ...

Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 05-03-2017
durchgeführt von nina (07-03-2017 14:59:31) Run:3
Gestartet von C:\Users\nina\Desktop
Geladene Profile: nina (Verfügbare Profile: nina & UpdatusUser)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\Run: [glitch-6] => C:\ProgramData\glitch-96\glitch-87.exe -cp
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\...\RunOnce: [calculus-6] => C:\Users\nina\AppData\Roaming\calculus-12\calculus-2.exe [732672 2017-03-07] ()
HKLM-x32\...\Run: [] => [X]
C:\Users\nina\AppData\Roaming\calculus-12
C:\Programdata\drain-3
C:\Windows\賫ޙ
C:\Windows\桍ޙ
C:\Windows\ׁޕ
C:\Windows\Έޛ
C:\ProgramData\cvz
C:\Windows\楮ⴴ
C:\Windows\瓼ⴴ
C:\Windows\ⴲ
C:\Windows\৙ⴴ
C:\Windows\㘏ਙ
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
*****************

HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\Software\Microsoft\Windows\CurrentVersion\Run\\glitch-6 => Wert erfolgreich entfernt
HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\calculus-6 => Wert erfolgreich entfernt
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
C:\Users\nina\AppData\Roaming\calculus-12 => erfolgreich verschoben
C:\Programdata\drain-3 => erfolgreich verschoben
C:\Windows\賫ޙ => erfolgreich verschoben
C:\Windows\桍ޙ => erfolgreich verschoben
C:\Windows\ׁޕ => erfolgreich verschoben
C:\Windows\Έޛ => erfolgreich verschoben
C:\ProgramData\cvz => erfolgreich verschoben
C:\Windows\楮ⴴ => erfolgreich verschoben
C:\Windows\瓼ⴴ => erfolgreich verschoben
C:\Windows\ⴲ => erfolgreich verschoben
C:\Windows\৙ⴴ => erfolgreich verschoben
C:\Windows\㘏ਙ => erfolgreich verschoben

========= dir /oge-d %APPDATA% =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\Users\nina\AppData\Roaming

07.03.2017  14:59    <DIR>          ..
07.03.2017  14:59    <DIR>          .
03.03.2017  18:02    <DIR>          Mozilla
03.01.2017  09:18    <DIR>          vlc
11.11.2016  18:44    <DIR>          Skype
05.09.2016  08:45    <DIR>          dvdcss
19.02.2016  11:47    <DIR>          Trimble Connect for SketchUp
19.02.2016  11:05    <DIR>          SketchUp
26.11.2015  10:58    <DIR>          ZoomBrowser EX
23.06.2015  10:29    <DIR>          Apple Computer
07.04.2015  14:18    <DIR>          hps-install
02.04.2015  10:50    <DIR>          Dropbox
21.12.2014  12:00    <DIR>          Autodesk
16.12.2014  13:46    <DIR>          Ambient Design
25.11.2014  11:21    <DIR>          Adobe
24.08.2014  10:55    <DIR>          uTorrent
09.05.2013  00:07    <DIR>          CameraWindowDC
05.02.2013  11:29    <DIR>          Google
22.11.2012  10:29    <DIR>          NVIDIA
10.01.2012  18:05    <DIR>          Canon
30.08.2011  16:33    <DIR>          Buhl Data Service
19.07.2011  15:32    <DIR>          Corel
06.06.2011  22:08    <DIR>          PDAppFlex
14.04.2011  14:35    <DIR>          WinRAR
15.01.2011  17:11    <DIR>          Windows Live Writer
09.12.2010  12:01    <DIR>          Nero
12.03.2010  12:41    <DIR>          Template
04.03.2010  08:59    <DIR>          Thunderbird
23.02.2010  18:23    <DIR>          NoteTab Light
23.02.2010  11:02    <DIR>          CANON INC
15.02.2010  16:47    <DIR>          ViquaSoft
13.02.2010  12:22    <DIR>          InstallShield
12.02.2010  16:29    <DIR>          Ulead Systems
12.02.2010  15:22    <DIR>          PlayFirst
09.02.2010  15:40    <DIR>          Langenscheidt
08.02.2010  19:12    <DIR>          GameConsole
06.02.2010  12:29    <DIR>          Macromedia
06.02.2010  12:28    <DIR>          Identities
14.07.2009  08:44    <DIR>          Media Center Programs
20.11.2011  19:10    <DIR>          de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
07.09.2011  17:29    <DIR>          Adobe Mini Bridge CS5.1
07.09.2011  17:29    <DIR>          StageManager.BD092818F67280F4B42B04877600987F0111B594.1
07.06.2011  06:55    <DIR>          chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
06.06.2011  18:26    <DIR>          com.adobe.downloadassistant.AdobeDownloadAssistant
04.09.2011  12:34    <DIR>          com.adobe.dmp.contentviewer
24.05.2015  12:15    <DIR>          CasaPortale.de
19.01.2011  10:46    <DIR>          OpenOffice.org
04.03.2015  13:38               132 Adobe BMP Format CS5 Prefs
04.11.2014  11:24               132 Adobe GIF Format CS5 Prefs
27.07.2012  09:48               132 Adobe PNG Format CS5 Prefs
13.01.2014  17:02            56.793 mdbu.bin
11.09.2014  09:48             2.736 wklnhst.dat
               5 Datei(en),         59.925 Bytes
              47 Verzeichnis(se), 32.720.932.864 Bytes frei

========= Ende von CMD: =========


========= dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\Users\nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

07.03.2017  12:06    <DIR>          ..
07.03.2017  12:06    <DIR>          .
19.07.2011  14:58             1.389 Adobe Gamma.lnk
19.01.2011  10:47             1.243 OpenOffice.org 3.3.lnk
               2 Datei(en),          2.632 Bytes
               2 Verzeichnis(se), 32.720.932.864 Bytes frei

========= Ende von CMD: =========


========= dir /oge-d %PROGRAMDATA% =========

 Datentr„ger in Laufwerk C: ist Acer
 Volumeseriennummer: 884C-465F

 Verzeichnis von C:\ProgramData

07.03.2017  12:09    <DIR>          NVIDIA
04.03.2017  12:52    <DIR>          Malwarebytes' Anti-Malware (portable)
04.03.2017  10:58    <DIR>          Malwarebytes
11.11.2016  17:34    <DIR>          Skype
19.02.2016  11:03    <DIR>          Reprise
19.02.2016  11:02    <DIR>          SketchUp
22.12.2015  09:37    <DIR>          CanonIJPLM
23.06.2015  10:22    <DIR>          Apple
17.05.2015  19:35    <DIR>          Package Cache
24.04.2015  07:49    <DIR>          ZoomBrowser
13.04.2015  19:12    <DIR>          tmp
02.04.2015  10:57    <DIR>          Microsoft Help
31.03.2015  18:43    <DIR>          Corel
27.02.2015  17:28    <DIR>          Ashampoo
04.02.2015  18:41    <DIR>          Tablet
21.12.2014  12:10    <DIR>          Alias
16.12.2014  13:45    <DIR>          Caphyon
02.12.2014  17:02    <DIR>          hps
25.11.2014  11:33    <DIR>          ALM
25.11.2014  11:18    <DIR>          Adobe
25.11.2014  09:43    <DIR>          InstallShield
30.09.2014  13:09    <DIR>          Buhl Data Service GmbH
01.07.2014  15:16    <DIR>          Oracle
05.02.2013  11:29    <DIR>          Google
20.11.2012  11:10    <DIR>          NVIDIA Corporation
10.01.2012  18:06    <DIR>          CanonIJ
10.01.2012  17:52    <DIR>          CanonIJMSetup
10.01.2012  17:51    <DIR>          CanonIJWSpt
19.07.2011  15:03    <DIR>          Adobe Systems
04.03.2011  22:01    <DIR>          WinZip
17.05.2010  09:54    <DIR>          Sun
11.04.2010  18:26    <DIR>          Rossmann Fotoservice
15.02.2010  17:20    <DIR>          TEMP
13.02.2010  13:40    <DIR>          FarmFrenzy2
12.02.2010  16:26    <DIR>          Ulead Systems
12.02.2010  15:22    <DIR>          PlayFirst
11.02.2010  17:00    <DIR>          Friends Games
09.02.2010  15:40    <DIR>          Langenscheidt
08.02.2010  19:13    <DIR>          Sandlot Games
06.02.2010  13:30    <DIR>          BackupManager
06.02.2010  13:26    <DIR>          McAfee
06.02.2010  12:30    <DIR>          McQcModifier-5c47-a7b0
06.02.2010  12:27    <DIR>          OEM
17.10.2009  03:39    <DIR>          EgisTec
17.10.2009  03:37    <DIR>          eSobi
17.10.2009  03:31    <DIR>          Nero
17.10.2009  03:28    <DIR>          SiteAdvisor
17.10.2009  03:20    <DIR>          Acer
04.09.2011  12:43    <DIR>          regid.1986-12.com.adobe
18.07.2009  02:57            36.136 FullRemove.exe
               1 Datei(en),         36.136 Bytes
              49 Verzeichnis(se), 32.720.928.768 Bytes frei

========= Ende von CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10492296 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 7730754 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
nina => 1921377 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 27.2 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 14:59:35 ====
         

Alt 07.03.2017, 15:35   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 07.03.2017, 22:48   #23
kangli
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 07.03.2017
Suchlaufzeit: 18:40
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2017.03.07.07
Rootkit-Datenbank: v2017.02.27.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: nina

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 366701
Abgelaufene Zeit: 20 Min., 26 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 206
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{102DBAF2-FE71-4AFA-A22A-C218FE18F26D}, In Quarantäne, [181b16b1a4049a9c3483fd8d0bf82cd4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1058B9B2-59FD-414F-A427-F61F7AA2CCB1}, In Quarantäne, [1b189037c5e3de582692404a14eff709], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{109FFE1E-6AD9-4461-A68D-FEB53629AEC5}, In Quarantäne, [2e0524a39315f3439e198703cd364eb2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{13AF3910-81AB-4A8F-92C8-167E7648658A}, In Quarantäne, [ab8816b102a6dd5941765931798acb35], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14FCA6D5-C90E-479D-97A5-D335E9B08911}, In Quarantäne, [dc5796310a9ef83eb502e6a4719255ab], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1518FCA7-A5D8-4347-AB4B-C06882C4856C}, In Quarantäne, [f142ad1a2088d56111a693f7a75ca25e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15C4FABF-AD2D-40F2-A06E-A9A9E61428A2}, In Quarantäne, [f241883fa800320410a75634c142f20e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15DCF33F-EEC9-49F3-8853-5CD740D679ED}, In Quarantäne, [88abc304d9cf0d29ccec2f5b47bc6997], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16B75DED-6583-45C8-B02E-C7D5CA518BED}, In Quarantäne, [70c3dee998109e98e8cf5832e2211ae6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{174A901B-C191-41CE-949E-82EBDF1658A5}, In Quarantäne, [9f947354ecbc4cea5c5b28620df611ef], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17CED4E7-F86F-4E57-8E3B-2DAFE2C58FA7}, In Quarantäne, [42f1facd684054e211a6beccbe450bf5], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1882EAFE-384A-4FAB-8E71-F9CF83819CB1}, In Quarantäne, [e44fa423a60296a03a7dccbe72914eb2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1912241B-1753-499D-A5C3-FFFF182629D2}, In Quarantäne, [f43fffc8cadedd59e4d3d8b227dcff01], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AF9FA46-B71A-4292-BAB9-48B93D178DCB}, In Quarantäne, [ca69f2d5daceec4af5c25c2eaa5947b9], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1B816013-790D-4383-BA27-8AAD27DDE48D}, In Quarantäne, [d1629a2d3e6a3afc00b7652537cc21df], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1BE825DD-9FDD-4825-A18F-C2131DF846A3}, In Quarantäne, [5ed524a3a60291a515a372180af9d729], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C803799-F1CB-4F9B-BE3F-3BE6C133AAA0}, In Quarantäne, [0f24a0272b7d88ae87302e5c24df34cc], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D08B779-9690-47F2-80AD-BFB5F66E93A2}, In Quarantäne, [2b0807c05e4ab87e2e8ae9a13ac9b749], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D697516-D208-4CDD-8846-94CCA1A259C2}, In Quarantäne, [1b18596ed7d185b1c1f604865da6dc24], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21262941-DEED-4DD1-8FCD-4BB0D8B78778}, In Quarantäne, [12219e295850b97dfabe771335ce0af6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21E1CB10-C2DC-4F2A-9371-A2FF575BF4B4}, In Quarantäne, [37fcf6d12d7bb0868e29e9a15ca7d828], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{253A0852-A14E-4907-82BA-6CD4AA43E8C8}, In Quarantäne, [5ed526a1bfe9082ecbed0f7b798aa858], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2865E7A2-3C11-4083-AB45-FA60784A442A}, In Quarantäne, [52e19235d8d0ca6c12a57515ca3941bf], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29565A2D-9A8F-4279-8AA7-AF34AF6C3287}, In Quarantäne, [63d0bb0cb0f885b13880d7b37e85e21e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29EC6F51-3FF9-4F70-BA9D-2D59B0B93CF6}, In Quarantäne, [42f19b2c8325d85eb9ffc5c5659ef50b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2BB68979-46A4-45AE-8284-E66AE1F01C6E}, In Quarantäne, [ea49398e5454f3435f581575986b33cd], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2C8EE38B-78D6-456D-85EB-A7ED4D54C470}, In Quarantäne, [a0933b8c36721e187f3861296a99b44c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2C9FC49B-C017-4179-A674-43E55249F68A}, In Quarantäne, [b97a8b3ccade36002791cfbba55e728e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D69F8AB-6D58-4FD0-8678-8B7B5BFDF68C}, In Quarantäne, [1c17e7e0dbcdea4c01b7ed9d7b88c937], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{303714F6-E584-4AB0-8165-95DB8FA2673D}, In Quarantäne, [310222a59612c96d6d4be2a8689bd927], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31E5D657-2D6C-452C-BE42-2A745C7A8483}, In Quarantäne, [b182d3f44a5ec6702c8c3e4c8e75946c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32419134-F7E7-427F-9F4D-9F6A451BD044}, In Quarantäne, [db585770f3b5f046882f0f7b2ad9a15f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{357CCE61-1523-4B2C-8F2E-9071F899A57A}, In Quarantäne, [f43f8047a5031b1b298edeac7192847c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37BAA503-FC45-4B11-A6E3-E2146B6AF63D}, In Quarantäne, [122122a5d5d3171f496ee9a1c3404fb1], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37E693EA-BDCF-4D02-BE39-626B92F9A5A0}, In Quarantäne, [280b953230786accf3c597f3bc4711ef], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3857F6E4-DCA9-44A8-A2D8-5384CAB02CD3}, In Quarantäne, [65ce37901a8ef145befa3258669dcd33], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38F4A9CD-A7B4-45FA-A75F-222C6B9187D2}, In Quarantäne, [949f8740cbdddd597a3ed0ba1be835cb], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39C00749-719D-4EA9-923E-7DE765BF83D2}, In Quarantäne, [e44f2a9dc8e012242a8dc7c30bf8ef11], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39F95B58-CE96-4581-8B3D-17E01C2DCD6E}, In Quarantäne, [e35019aef5b3181ef4c49feb2dd67b85], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AAC9D40-2274-459F-A09C-323351804EC1}, In Quarantäne, [22110bbc387089ad09ae7812a55e20e0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D4A25FF-275E-4880-8FB2-4DC3578C8C37}, In Quarantäne, [fa398f38535575c1a017a3e7cc37ad53], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DC81C92-D5FB-4FAF-90E0-3B26C26EF6ED}, In Quarantäne, [c1720eb9e9bf3bfbc4f45634df245ca4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E3031D8-359A-4188-BAF4-A3AB5F2EE78D}, In Quarantäne, [f73ca522feaa45f1ebcc96f4d033639d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{40015344-9128-467E-9CB5-73FECB1A6CD8}, In Quarantäne, [042f0bbcaff92d097542f19942c136ca], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{42031F63-8FDE-49D9-AC2E-309A8031B27A}, In Quarantäne, [023105c28f1976c001b7e3a7d92add23], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4223E63F-1D8F-477A-BDC7-46B8A591D5AD}, In Quarantäne, [f340487f644442f48235375357ac6898], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45658B80-5286-46FE-B3B6-44109C4B5627}, In Quarantäne, [a78c685f60481f17eec9800a758e8c74], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47FAE31C-8A23-4F59-8667-3B5B53543468}, In Quarantäne, [72c18e391098f145bcfb216913f01ae6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{480B0217-A342-4518-B643-64A6A4AF367C}, In Quarantäne, [66cd5b6c6f39c274e8d0a1e9f50edd23], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{487CD475-3850-449E-B655-F22CF24DE119}, In Quarantäne, [d65d1bac3375cc6aa710cac06b98dc24], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E79F8E5-467C-4817-838C-DDB8BAC6A3CB}, In Quarantäne, [7bb83b8cbeea7eb8cbed9befc73c4bb5], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51951E71-6A43-4F93-988E-973AD01AC620}, In Quarantäne, [3ff4e4e345637cbafcbbd9b1ea1954ac], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{55F2B0A8-2AF2-4B00-BD84-1675BB3C1D55}, In Quarantäne, [37fcc502d1d738feceea1c6edf249e62], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{561100B2-E20F-4423-A682-928CB9A68439}, In Quarantäne, [a68d893e773181b58e2a7911788b43bd], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{567558B0-B036-4644-AEA7-832C593DE96B}, In Quarantäne, [181b0bbc3c6ce0569b1c8efc32d1f60a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5701B86A-FE15-473A-902F-52ADAD7BE941}, In Quarantäne, [f142992eacfcd75f0eaacbbf9d66b848], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5705C21F-BD2C-451E-9388-8FE6A4DBF2DA}, In Quarantäne, [5cd78c3b6b3dc274b602d6b404ffa858], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{571CD227-15A3-4530-B3E3-A8B968918DE8}, In Quarantäne, [e94abe095f49e15541775c2e986b42be], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57539411-DC6A-4EAA-B651-459CFD68BF54}, In Quarantäne, [75becbfc8424b185f9bed9b16c97be42], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57706007-A676-4BC8-9C50-2D7535ACEB15}, In Quarantäne, [033022a5ceda94a264544248a360cd33], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{594E7A68-354B-4518-8AB7-F1DFBEB5333C}, In Quarantäne, [9d96ad1aedbbf73f7642ff8b8c771fe1], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B0A4D49-A12B-421C-82D5-146B445FBCE1}, In Quarantäne, [c37076519711d660a612ed9d40c3e51b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B5A0DC7-21AA-46C6-89DC-BB6CF4146C60}, In Quarantäne, [fd3600c76f3963d3ddda2e5cbf4402fe], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C12988E-D931-4C8C-B019-DA61F0D11243}, In Quarantäne, [2310ccfb5058b97d11a752386a996898], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5D8FD300-CD1B-4176-9859-59249716F641}, In Quarantäne, [eb48c6016a3e191d41774446b1529c64], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5F2D1E22-87DB-4E8C-8CC8-70CA177D3035}, In Quarantäne, [0a29c1067731c76fc3f40f7b6d96b749], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62452889-3CE7-4980-AA49-3B80F28F544D}, In Quarantäne, [66cde4e3c3e57fb76c4bfb8fe51e7a86], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62955C3B-739C-438D-954C-94F4E8579FF1}, In Quarantäne, [b47f5572dccc90a6c3f59bef7f8413ed], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6306D170-6A59-47F2-B881-BA61D26C13E2}, In Quarantäne, [999aa0271593290d33857416748ff50b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63D14BE5-361D-4DA3-ACF5-371FC16EAC11}, In Quarantäne, [979c7354a800013501b71674e81be51b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{645C520F-A5DB-4429-A09B-7EFE7A91F6F1}, In Quarantäne, [6fc4e6e1c1e7a492882f701aaf54758b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64E24962-CE51-4C0E-82AD-92B74FC67483}, In Quarantäne, [59da19ae4266ce68665118724ab90ef2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{66D2DC74-1ECC-4377-B134-87433E468D1B}, In Quarantäne, [70c3299e169287afe0d85535956ec040], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67122FDA-215C-44AB-A6A2-67F5FBA0E680}, In Quarantäne, [0f248443b2f6dc5a5d5a6f1bd13204fc], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A1EBD64-D021-47A3-ADCD-877776C5133F}, In Quarantäne, [85ae5473c1e763d33b7da4e6cd363ac6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A94593A-F93B-4C5F-97C4-5911C5A52AD1}, In Quarantäne, [7db62d9a08a043f33583bdcdc142c63a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AC00A8B-F257-4336-A8B0-CB319CD49781}, In Quarantäne, [949fbd0ae9bff93d45724a407f844db3], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CED2D6A-AB69-4872-B5FC-3788EC55C462}, In Quarantäne, [c271b710109860d69a1e82080df64cb4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6DB347CD-2D62-414A-BD7E-E6E68A91CE3D}, In Quarantäne, [65ce6d5aceda76c09f18b7d334cf827e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E06AC15-1242-4701-B272-6A9A104BAEDD}, In Quarantäne, [0d266f58456316201e9a95f5c43fd32d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7123994B-F76D-44D9-8E6B-23EFE869BB97}, In Quarantäne, [68cb1ea9b7f15dd9b9ffb5d5ea19e61a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7153A2F9-E327-4820-96F8-F638AD305DF6}, In Quarantäne, [2e05ab1ce0c87cbaa413f199ec17a55b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72ED2202-49DF-4AB9-91A9-DBAEB88BCB6B}, In Quarantäne, [60d3f6d1cddb4ceae2d52466e41f6898], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72F30896-5792-44BA-8751-783FF3D894A8}, In Quarantäne, [2d06fec98a1e48ee7a3e7c0e04ff5aa6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{730AACCA-8ED5-447D-B450-C1694BED66BE}, In Quarantäne, [53e019ae3f69cf679423fc8e7192ac54], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73E1D129-2486-43B1-ACF0-AD20ACCFD181}, In Quarantäne, [42f14186aff954e2bbfc9eecbb48a35d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7627691E-7D14-453B-925A-6DD7B82A97C9}, In Quarantäne, [969d4b7c0e9ab680eec93d4db74c8f71], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{76DF2E78-BA42-4D00-A3E1-7F1237FCD9A8}, In Quarantäne, [bf7446813474211503b50288fc07718f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{78B1913B-9CB9-4F00-AB10-2BC527E1B165}, In Quarantäne, [48ebae19b2f670c6a413f991e02340c0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EC21146-435A-4E54-B9A6-9BE86C5A644F}, In Quarantäne, [5ed5f7d0abfd092d08af7d0d5fa418e8], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FC716F1-7041-4F4D-9269-27BCFC44CE48}, In Quarantäne, [cb684e797335f244caedacde8c77817f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8041F67A-A4D8-4B58-8A7D-288C30777AA4}, In Quarantäne, [0f24c502f6b239fd63554d3d8a7940c0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B82349-9A59-4CC0-9875-6B55A364DB33}, In Quarantäne, [c37052751d8b7fb7f0c7315951b2f709], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{82A47425-A1E4-4CC8-9E5D-F4E9EA5FA14E}, In Quarantäne, [59da24a374343204a117d0ba966d45bb], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{82C72347-21C9-4B51-AA78-67B71868E5BA}, In Quarantäne, [ce65883f33751a1cd4e4602a7a89f30d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{846DC43D-B7C9-47F7-B18A-34782EF981B6}, In Quarantäne, [f340982fe4c4e551991e8802a85b7c84], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{88866739-B111-4FC9-BFE8-A111161498C0}, In Quarantäne, [1f143196ddcb092d6e4a02883dc6ba46], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8916363F-D775-41C1-A01A-37D281CD88DB}, In Quarantäne, [34ff07c07335a3934e690f7b60a355ab], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8AA5D53A-8A1D-4603-98C0-628F5EF0E01E}, In Quarantäne, [e44fd9eecfd946f06c4b04868c7756aa], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8B7A5376-1069-43AD-9A9F-54EB606459F0}, In Quarantäne, [e54e5770f6b25bdbc0f8e0aa2dd635cb], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BEF0B34-E18D-4E5A-A142-A32B57D159F3}, In Quarantäne, [82b1ddea1f89b5819423e1a9d52e4bb5], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BF2328F-A070-4E2F-B482-4531B354D6AE}, In Quarantäne, [77bc2d9a693f88ae62567218ab587a86], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C5465F0-2431-4370-A574-D5438324BD40}, In Quarantäne, [6fc4f1d61395d1654671454590732cd4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8D01BD6C-F83F-4660-BAE8-A89D8BCE9130}, In Quarantäne, [b47f8443aefac86e9b1d94f658ab619f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DC13B03-A0B3-4F28-B924-7C1426D5A370}, In Quarantäne, [a68ddee9e4c42b0bd1e6e4a6e0236e92], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8E0CFC82-D3B4-4812-967B-86404F7551B7}, In Quarantäne, [72c1586f6d3bd264d3e4b0da0ef5fe02], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9197880B-9D4C-4101-99CA-7A4C892D339C}, In Quarantäne, [c96a3c8b8325d462d2e531599c67ed13], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92AA7BB7-44BC-4B5F-9B32-6774E19F1E2D}, In Quarantäne, [ba799c2bf5b321156355206a0af99b65], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92E1D6B7-4226-4AA5-A971-A1B9DD26A495}, In Quarantäne, [042f7d4a3f6972c467503f4ba65d1fe1], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{95397465-C990-49FC-ACE6-648A1DA27124}, In Quarantäne, [6bc843847b2de94de6d18a00ff041ee2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{956DDB47-6F8D-476E-AC33-433BCE6162B0}, In Quarantäne, [38fbbd0a7335082ec6f17d0d2ed510f0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{967E820E-2755-4626-952C-D2D9A268A3A9}, In Quarantäne, [af84e4e38a1e1a1c5f59028856ad936d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{98CF3705-2C35-4391-8CE5-B1B6F3A24553}, In Quarantäne, [ee4522a527813cfab9ff7c0eee155ea2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9AB6F944-11F4-4E26-AA77-CD2CF0E0895B}, In Quarantäne, [31022d9acbdd171f6d4ba9e1f90ad927], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B13D237-EA97-44E2-85BF-CE3A4A51A9A0}, In Quarantäne, [8aa9c3040f99191d8a2d1e6c927154ac], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9D309E03-65F6-4A64-838F-3833266EA898}, In Quarantäne, [58db784fbfe991a507b0a1e9b84b6c94], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F13D8D7-615D-4EDE-8060-742A3A1B9ED0}, In Quarantäne, [141f5a6ddfc990a622955b2ff3106f91], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F5A6B23-2D4A-4F3E-B2C3-758685D84266}, In Quarantäne, [48eb3c8be8c0280e12a58802f40f3bc5], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FBA9266-62A3-4BE4-B22E-5CA589D57858}, In Quarantäne, [55de90375355aa8ceecac1c941c2ee12], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0FA23BE-4710-4D79-B99D-B379CA7041D7}, In Quarantäne, [3cf76f589e0a999d506875152ad955ab], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A1D66F9C-EDBF-41A5-ACCA-FEE211812133}, In Quarantäne, [76bd6562bfe9de585265c1c9eb183fc1], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A29517EE-2FF1-4A85-98E2-19B8718C82B7}, In Quarantäne, [e0534186acfc13233d7ab4d62ad9fa06], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A31F3BF6-9B76-48A4-B796-60F15166406E}, In Quarantäne, [b87b9e293474989e8731d6b49b6810f0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3A5610C-6156-458A-BB42-3F931C6FE9CC}, In Quarantäne, [83b047800a9e46f0595fcdbdcf34817f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6092C37-1A83-43CC-939B-D4D67826E1DF}, In Quarantäne, [1122bf0871372313f6c28a00da2952ae], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A74FB09E-1110-4177-B1ED-EC7CA786B8F8}, In Quarantäne, [7bb8fdcae9bf6fc79027890117ecc13f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A77D826D-BBA8-42DA-B5F1-C449BA2D856B}, In Quarantäne, [2b08e2e55b4d73c3ebcc6f1b8e75e61a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A97F4AAD-4B69-4394-9827-BFD84CC1A656}, In Quarantäne, [a88bdfe8ecbccf676b4da0ea33d052ae], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA1F8FD6-37CD-4AF1-BB9A-5C8D125E50E4}, In Quarantäne, [76bdbc0b22861125a314e8a233d0cb35], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA43CFAE-6C1F-4555-B711-1A833DC27470}, In Quarantäne, [3bf851767731dd5982364f3bbd4612ee], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AAB1398A-63C1-4DB4-B1F9-978CF3C99538}, In Quarantäne, [969d25a2edbb41f5387fef9b2ad918e8], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABDE1233-B0A0-4B9C-8DF3-B71438F46A47}, In Quarantäne, [68cb5a6d6048b08636819af0f80b49b7], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD22EA03-C70C-4F9C-88D8-985E428CCD4F}, In Quarantäne, [79bae9deb0f892a472462961f40f758b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD58BF87-A1BF-49CC-AB75-4C743CF7E37F}, In Quarantäne, [52e1b4137b2d84b25661d5b5f80b50b0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AE6CF62F-3BFB-4607-83B2-3984D2E4FB44}, In Quarantäne, [cb684d7ab9efc86eded9cdbd38cb05fb], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B06ECF89-7607-4D5D-BAD9-93F7D5372B7E}, In Quarantäne, [2211c1060d9b8aac9a1de8a29370de22], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0CAAFF4-F190-4E5B-BA2C-65E63A27DD23}, In Quarantäne, [999a6265d3d5979fa61172182cd7c63a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B11AA588-E7BE-4021-A31A-965FA020E37E}, In Quarantäne, [78bb8a3da9ffa690d9df6822ca399967], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B17FCB0E-9083-4D49-9581-553C87C17B5E}, In Quarantäne, [64cfe1e6c9df55e1882fa9e17192e818], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B236F8AC-F375-417D-84FB-2C2B3E4C63CD}, In Quarantäne, [35fe0dbac8e06fc76b4d3d4d53b0df21], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3CAC9A3-F032-4EA4-A07A-67DECDCAB01C}, In Quarantäne, [a390dceb594fd2648b2c7a104eb51ee2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3E952CD-BD09-486A-89E1-892C89CC8568}, In Quarantäne, [80b3e1e6ddcb69cde9cf39516b987789], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4FF270C-9699-4B62-87F9-9135A7CE9219}, In Quarantäne, [b67d4e79c0e81d190eaa0a80b64d8977], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B57B6B60-A2B3-4FF7-85BD-C79A1E1D6950}, In Quarantäne, [59da75529d0b1a1c51665931ea19b44c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5A42686-B0C5-411B-A335-F0F51E77C69D}, In Quarantäne, [a0935077e3c54beb93243951bf4423dd], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B766BB38-858B-4989-8EDC-2916BB64F5C1}, In Quarantäne, [151e0bbc4662a5910bada4e6a063ee12], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8D02517-9F85-4A96-89FC-21E7AB96FDE1}, In Quarantäne, [57dce6e10f99a78f7c3c1971e122b64a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8DCE889-7791-47A0-9047-23A19BE6194C}, In Quarantäne, [1b189f2877312a0c3d7ba9e1e61dda26], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B95B23C4-7B6A-4455-9977-A2F253DBD870}, In Quarantäne, [55deaa1d990f20167444c6c405fe867a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B9DE19C6-2777-41B1-871C-1C2CE384FD25}, In Quarantäne, [999a3295b4f4bf772f89cbbfbc47926e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA0D608E-786E-4C97-88D7-FF57776270BB}, In Quarantäne, [da59ebdc931569cd3d7aec9e1fe422de], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD9D63A1-D505-4826-B638-25B712B88FCC}, In Quarantäne, [2f0422a5377188ae3088d5b53fc4ae52], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEE552FF-6F1A-49E7-A5B0-6413DB28532F}, In Quarantäne, [e2517a4d099f40f6199eeaa0659e6d93], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C05965DB-129B-4BE0-BC44-6BF57DB625BD}, In Quarantäne, [4ee51fa8fcac4de9b0070c7eda293ec2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0CFB749-4631-44EF-84D2-BBE7EBC79B6F}, In Quarantäne, [c2714f78fbad1a1cd5e3a1e96d9621df], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C12CAB25-3B27-48B5-8F78-DAC26756571B}, In Quarantäne, [132054734563f93dffb9612906fd05fb], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3250184-E7D2-422A-BF1A-CE696823B151}, In Quarantäne, [c96ae3e4149459ddbafe4545699ad729], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C42EE0E2-38FF-43AF-B9F7-2AFD63E835E3}, In Quarantäne, [6dc6ffc8b2f6231303b5078321e23ec2], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4A5ACB8-A51A-4672-AB64-B154A0B3AFFD}, In Quarantäne, [a68d31966741a88eb9ff365411f27987], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C539D253-50BA-4DF3-B584-557AD439C8E6}, In Quarantäne, [ae8557706642181ea7119eec15ee7f81], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C71C8A7A-A1C1-4423-B737-A6419ADDAF71}, In Quarantäne, [9c97784fa404a393298f5b2f4eb5f40c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C87C64DA-672B-4EF1-823A-611B19F2719A}, In Quarantäne, [3bf89b2c099fe650a216d6b48d7632ce], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C9176B25-1998-4E8A-87D6-CFDF871FEFF9}, In Quarantäne, [d45ffbccfbaded49bbfc533745be1de3], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF0C0DDE-B7B3-4BC7-859D-63DC61E46FE7}, In Quarantäne, [260d5f683573c96d298f0981fb08827e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D054B916-474E-4791-A3B0-AFF3EEACB588}, In Quarantäne, [50e37552a5038ea8dddaa6e4649feb15], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1CB9C68-E5D6-408C-824A-E33DAE68B99C}, In Quarantäne, [8ba857706444a690892e642658ab47b9], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D29912B2-935F-4F94-AD23-F111ED3EFB48}, In Quarantäne, [e350cdfaaafec76f05b24743f50eef11], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D332998D-8D41-4BE5-BDA6-5EA272F74875}, In Quarantäne, [0f24f2d56147f145e1d71476eb1834cc], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4964F3C-7DEB-4E1E-BC6C-488AD8199279}, In Quarantäne, [f63db5126c3cc86ee1d71872e71c36ca], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D50AF76F-2BA3-446C-A1BA-29D2A3AB45C3}, In Quarantäne, [e84b1ea945633df93187cac00df6d22e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D76B677D-9A04-4843-9E6D-3E15F55499E8}, In Quarantäne, [db58dee97e2a9c9a23949eec09faeb15], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9341EFF-471C-41DF-903F-FECE5555674A}, In Quarantäne, [82b1784f733576c0a116c1c9cc37c63a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA2FFAF0-DD13-409C-8AC3-4F8128673B9A}, In Quarantäne, [2c0702c58c1c0c2a45721575b64d41bf], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB2086FD-F4D3-4A18-8FA7-9A49B668ED7A}, In Quarantäne, [072c04c38622a98d22964a40a26121df], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBBB8D16-E298-49FB-9593-16696D34DE58}, In Quarantäne, [7fb46a5d10983ef83b7d6822fe0520e0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF962B78-DEE5-4193-AC73-9FC6332FAEE4}, In Quarantäne, [44eff4d3b5f3a88e40783555cf3433cd], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E080F8F3-5FA3-40F0-BBE2-1E956DF53F2F}, In Quarantäne, [a29137902286f6406751dfab15ee9f61], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E15A57D5-901D-403B-8752-46873F9C6278}, In Quarantäne, [0a29daedd8d0c3735b5d1b6f3cc7669a], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4707C81-729E-4398-A579-C9FD67D840C1}, In Quarantäne, [a192d4f3792f3df981366b1f5da60cf4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E518784F-8BC6-47FD-9028-393177975D1E}, In Quarantäne, [0a29a720fbad6dc9bafdfa90ec17ef11], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E68DBB32-33AC-45F2-BB69-19F7266FD7C8}, In Quarantäne, [ab885374aafe5fd7ffb95f2b8c77ab55], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6A668D5-8336-4A61-8174-E7C2E445CAFE}, In Quarantäne, [d162d5f2aefa6fc715a22664000355ab], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7524B69-D21B-43AC-9B7A-B8303CBC8B83}, In Quarantäne, [cc6716b16345a88e2295e4a6986b6997], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8DD2CBD-4231-4CEB-B3A3-FCC8BFF966C8}, In Quarantäne, [122124a332760f2703b428622ad93dc3], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA276E64-992D-4BDD-BCEE-2929B194D519}, In Quarantäne, [0e250dba10987eb8f9bf0b7f61a2c33d], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA4F6651-2297-4BC6-8843-7283B37837F2}, In Quarantäne, [8aa94e79b4f4a195b6024d3d9e65d42c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA8040AB-2822-4E50-939A-51957A4753D9}, In Quarantäne, [8aa9bd0a4a5e45f1f8c0ec9e030020e0], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EAD56BC8-967C-4F60-A0ED-8514E7C365DB}, In Quarantäne, [072ce2e58127d85e6057dcaec04308f8], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB218325-6741-4B31-BC83-3FC5B7569141}, In Quarantäne, [2b0813b47c2c71c5f7c092f8907322de], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB22D0CE-DA58-4575-83C4-A9734AC8EBE6}, In Quarantäne, [e54e5b6c446475c1cbec8ffb2ad9cc34], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ECE204F7-4A66-4985-8188-3B12CAEAD841}, In Quarantäne, [a48fa22507a1e74f4573a3e7ba492dd3], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF2DA774-5DC9-4BAE-BC9C-1CCD2A6CC665}, In Quarantäne, [35fed1f65256aa8c7c3ca1e9739057a9], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF57BF5F-5D39-43B7-8BE2-51DE4A1935A2}, In Quarantäne, [3300a522406879bda6118dfd21e2e719], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F022A6F2-8B5A-49D5-8F22-50ADFA3B4DD4}, In Quarantäne, [f340ffc8d2d676c072463951df24946c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1860A31-1956-415E-9658-57EE7B50327D}, In Quarantäne, [c172ac1b0d9bda5c4474fe8c41c2a15f], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F32FA745-BD2C-41CB-9731-1E718B578BAC}, In Quarantäne, [b1825473297ff4429127bdcd9073cc34], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F63C0477-C2A4-4237-87A5-BAAA9A232A31}, In Quarantäne, [f24123a405a3f73f2395addddc27de22], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F752A1F9-D754-42B1-B24A-E2F259194BC9}, In Quarantäne, [7cb7f0d73177fb3b38804d3de51e0af6], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7AB45CE-C586-4F7A-A8B0-657CCA87649D}, In Quarantäne, [76bd33948a1eba7c6b4d58327f84f20e], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F875C708-1197-4238-8160-2FA0AC6244C4}, In Quarantäne, [e94ac2051692b5819721454535ce5ca4], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F97948D7-63AD-4A81-A765-A84FE9272CD1}, In Quarantäne, [f43fecdbf2b6c1755b5d1a70c53e649c], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA2CC340-DC6B-4C2C-B5BB-6074BD364F67}, In Quarantäne, [49ea586f7137350126914c3eb35008f8], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDD31C11-A055-482A-94AC-FDE689A6DB86}, In Quarantäne, [43f02e99a404df571d9aa2e824df956b], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDFC82BD-68B1-4CB5-BADA-8D90327C281B}, In Quarantäne, [e1526c5b5d4bab8b2197dfab986bbf41], 
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FE59B725-D148-4D12-BB5B-C2B9EF11E15B}, In Quarantäne, [8ba844837b2d46f04b6da9e1a85b649c], 
PUP.Optional.Wajam, HKU\S-1-5-21-1885290322-1835322729-3868160957-1003\SOFTWARE\Wajam, In Quarantäne, [ee4590376246a294993a2a7ae61dfc04], 

Registrierungswerte: 205
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{102DBAF2-FE71-4AFA-A22A-C218FE18F26D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [181b16b1a4049a9c3483fd8d0bf82cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1058B9B2-59FD-414F-A427-F61F7AA2CCB1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [1b189037c5e3de582692404a14eff709]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{109FFE1E-6AD9-4461-A68D-FEB53629AEC5}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2e0524a39315f3439e198703cd364eb2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{13AF3910-81AB-4A8F-92C8-167E7648658A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [ab8816b102a6dd5941765931798acb35]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14FCA6D5-C90E-479D-97A5-D335E9B08911}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [dc5796310a9ef83eb502e6a4719255ab]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1518FCA7-A5D8-4347-AB4B-C06882C4856C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f142ad1a2088d56111a693f7a75ca25e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15C4FABF-AD2D-40F2-A06E-A9A9E61428A2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f241883fa800320410a75634c142f20e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15DCF33F-EEC9-49F3-8853-5CD740D679ED}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [88abc304d9cf0d29ccec2f5b47bc6997]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16B75DED-6583-45C8-B02E-C7D5CA518BED}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [70c3dee998109e98e8cf5832e2211ae6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{174A901B-C191-41CE-949E-82EBDF1658A5}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [9f947354ecbc4cea5c5b28620df611ef]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17CED4E7-F86F-4E57-8E3B-2DAFE2C58FA7}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [42f1facd684054e211a6beccbe450bf5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1882EAFE-384A-4FAB-8E71-F9CF83819CB1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e44fa423a60296a03a7dccbe72914eb2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1912241B-1753-499D-A5C3-FFFF182629D2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f43fffc8cadedd59e4d3d8b227dcff01]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AF9FA46-B71A-4292-BAB9-48B93D178DCB}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [ca69f2d5daceec4af5c25c2eaa5947b9]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1B816013-790D-4383-BA27-8AAD27DDE48D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [d1629a2d3e6a3afc00b7652537cc21df]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1BE825DD-9FDD-4825-A18F-C2131DF846A3}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [5ed524a3a60291a515a372180af9d729]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C803799-F1CB-4F9B-BE3F-3BE6C133AAA0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [0f24a0272b7d88ae87302e5c24df34cc]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D08B779-9690-47F2-80AD-BFB5F66E93A2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [2b0807c05e4ab87e2e8ae9a13ac9b749]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D697516-D208-4CDD-8846-94CCA1A259C2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [1b18596ed7d185b1c1f604865da6dc24]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21262941-DEED-4DD1-8FCD-4BB0D8B78778}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [12219e295850b97dfabe771335ce0af6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21E1CB10-C2DC-4F2A-9371-A2FF575BF4B4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [37fcf6d12d7bb0868e29e9a15ca7d828]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{253A0852-A14E-4907-82BA-6CD4AA43E8C8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [5ed526a1bfe9082ecbed0f7b798aa858]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2865E7A2-3C11-4083-AB45-FA60784A442A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [52e19235d8d0ca6c12a57515ca3941bf]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29565A2D-9A8F-4279-8AA7-AF34AF6C3287}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [63d0bb0cb0f885b13880d7b37e85e21e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29EC6F51-3FF9-4F70-BA9D-2D59B0B93CF6}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [42f19b2c8325d85eb9ffc5c5659ef50b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2BB68979-46A4-45AE-8284-E66AE1F01C6E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [ea49398e5454f3435f581575986b33cd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2C8EE38B-78D6-456D-85EB-A7ED4D54C470}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a0933b8c36721e187f3861296a99b44c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2C9FC49B-C017-4179-A674-43E55249F68A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b97a8b3ccade36002791cfbba55e728e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D69F8AB-6D58-4FD0-8678-8B7B5BFDF68C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [1c17e7e0dbcdea4c01b7ed9d7b88c937]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{303714F6-E584-4AB0-8165-95DB8FA2673D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [310222a59612c96d6d4be2a8689bd927]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31E5D657-2D6C-452C-BE42-2A745C7A8483}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b182d3f44a5ec6702c8c3e4c8e75946c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32419134-F7E7-427F-9F4D-9F6A451BD044}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [db585770f3b5f046882f0f7b2ad9a15f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{357CCE61-1523-4B2C-8F2E-9071F899A57A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f43f8047a5031b1b298edeac7192847c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37BAA503-FC45-4B11-A6E3-E2146B6AF63D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [122122a5d5d3171f496ee9a1c3404fb1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37E693EA-BDCF-4D02-BE39-626B92F9A5A0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [280b953230786accf3c597f3bc4711ef]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3857F6E4-DCA9-44A8-A2D8-5384CAB02CD3}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [65ce37901a8ef145befa3258669dcd33]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38F4A9CD-A7B4-45FA-A75F-222C6B9187D2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [949f8740cbdddd597a3ed0ba1be835cb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39C00749-719D-4EA9-923E-7DE765BF83D2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e44f2a9dc8e012242a8dc7c30bf8ef11]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39F95B58-CE96-4581-8B3D-17E01C2DCD6E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e35019aef5b3181ef4c49feb2dd67b85]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AAC9D40-2274-459F-A09C-323351804EC1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [22110bbc387089ad09ae7812a55e20e0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D4A25FF-275E-4880-8FB2-4DC3578C8C37}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [fa398f38535575c1a017a3e7cc37ad53]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DC81C92-D5FB-4FAF-90E0-3B26C26EF6ED}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c1720eb9e9bf3bfbc4f45634df245ca4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E3031D8-359A-4188-BAF4-A3AB5F2EE78D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f73ca522feaa45f1ebcc96f4d033639d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{40015344-9128-467E-9CB5-73FECB1A6CD8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [042f0bbcaff92d097542f19942c136ca]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{42031F63-8FDE-49D9-AC2E-309A8031B27A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [023105c28f1976c001b7e3a7d92add23]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4223E63F-1D8F-477A-BDC7-46B8A591D5AD}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f340487f644442f48235375357ac6898]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45658B80-5286-46FE-B3B6-44109C4B5627}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a78c685f60481f17eec9800a758e8c74]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47FAE31C-8A23-4F59-8667-3B5B53543468}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [72c18e391098f145bcfb216913f01ae6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{480B0217-A342-4518-B643-64A6A4AF367C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [66cd5b6c6f39c274e8d0a1e9f50edd23]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{487CD475-3850-449E-B655-F22CF24DE119}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [d65d1bac3375cc6aa710cac06b98dc24]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E79F8E5-467C-4817-838C-DDB8BAC6A3CB}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [7bb83b8cbeea7eb8cbed9befc73c4bb5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51951E71-6A43-4F93-988E-973AD01AC620}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [3ff4e4e345637cbafcbbd9b1ea1954ac]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{55F2B0A8-2AF2-4B00-BD84-1675BB3C1D55}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [37fcc502d1d738feceea1c6edf249e62]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{561100B2-E20F-4423-A682-928CB9A68439}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [a68d893e773181b58e2a7911788b43bd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{567558B0-B036-4644-AEA7-832C593DE96B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [181b0bbc3c6ce0569b1c8efc32d1f60a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5701B86A-FE15-473A-902F-52ADAD7BE941}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [f142992eacfcd75f0eaacbbf9d66b848]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5705C21F-BD2C-451E-9388-8FE6A4DBF2DA}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [5cd78c3b6b3dc274b602d6b404ffa858]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{571CD227-15A3-4530-B3E3-A8B968918DE8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e94abe095f49e15541775c2e986b42be]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57539411-DC6A-4EAA-B651-459CFD68BF54}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [75becbfc8424b185f9bed9b16c97be42]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57706007-A676-4BC8-9C50-2D7535ACEB15}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [033022a5ceda94a264544248a360cd33]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{594E7A68-354B-4518-8AB7-F1DFBEB5333C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [9d96ad1aedbbf73f7642ff8b8c771fe1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B0A4D49-A12B-421C-82D5-146B445FBCE1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c37076519711d660a612ed9d40c3e51b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B5A0DC7-21AA-46C6-89DC-BB6CF4146C60}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [fd3600c76f3963d3ddda2e5cbf4402fe]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C12988E-D931-4C8C-B019-DA61F0D11243}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [2310ccfb5058b97d11a752386a996898]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5D8FD300-CD1B-4176-9859-59249716F641}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [eb48c6016a3e191d41774446b1529c64]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5F2D1E22-87DB-4E8C-8CC8-70CA177D3035}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [0a29c1067731c76fc3f40f7b6d96b749]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62452889-3CE7-4980-AA49-3B80F28F544D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [66cde4e3c3e57fb76c4bfb8fe51e7a86]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62955C3B-739C-438D-954C-94F4E8579FF1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b47f5572dccc90a6c3f59bef7f8413ed]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6306D170-6A59-47F2-B881-BA61D26C13E2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [999aa0271593290d33857416748ff50b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63D14BE5-361D-4DA3-ACF5-371FC16EAC11}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [979c7354a800013501b71674e81be51b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{645C520F-A5DB-4429-A09B-7EFE7A91F6F1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [6fc4e6e1c1e7a492882f701aaf54758b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64E24962-CE51-4C0E-82AD-92B74FC67483}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [59da19ae4266ce68665118724ab90ef2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{66D2DC74-1ECC-4377-B134-87433E468D1B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [70c3299e169287afe0d85535956ec040]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67122FDA-215C-44AB-A6A2-67F5FBA0E680}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [0f248443b2f6dc5a5d5a6f1bd13204fc]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A1EBD64-D021-47A3-ADCD-877776C5133F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [85ae5473c1e763d33b7da4e6cd363ac6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A94593A-F93B-4C5F-97C4-5911C5A52AD1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [7db62d9a08a043f33583bdcdc142c63a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AC00A8B-F257-4336-A8B0-CB319CD49781}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [949fbd0ae9bff93d45724a407f844db3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CED2D6A-AB69-4872-B5FC-3788EC55C462}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c271b710109860d69a1e82080df64cb4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6DB347CD-2D62-414A-BD7E-E6E68A91CE3D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [65ce6d5aceda76c09f18b7d334cf827e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E06AC15-1242-4701-B272-6A9A104BAEDD}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [0d266f58456316201e9a95f5c43fd32d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7123994B-F76D-44D9-8E6B-23EFE869BB97}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [68cb1ea9b7f15dd9b9ffb5d5ea19e61a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7153A2F9-E327-4820-96F8-F638AD305DF6}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2e05ab1ce0c87cbaa413f199ec17a55b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72ED2202-49DF-4AB9-91A9-DBAEB88BCB6B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [60d3f6d1cddb4ceae2d52466e41f6898]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72F30896-5792-44BA-8751-783FF3D894A8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [2d06fec98a1e48ee7a3e7c0e04ff5aa6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{730AACCA-8ED5-447D-B450-C1694BED66BE}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [53e019ae3f69cf679423fc8e7192ac54]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73E1D129-2486-43B1-ACF0-AD20ACCFD181}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [42f14186aff954e2bbfc9eecbb48a35d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7627691E-7D14-453B-925A-6DD7B82A97C9}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [969d4b7c0e9ab680eec93d4db74c8f71]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{76DF2E78-BA42-4D00-A3E1-7F1237FCD9A8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [bf7446813474211503b50288fc07718f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{78B1913B-9CB9-4F00-AB10-2BC527E1B165}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [48ebae19b2f670c6a413f991e02340c0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EC21146-435A-4E54-B9A6-9BE86C5A644F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [5ed5f7d0abfd092d08af7d0d5fa418e8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FC716F1-7041-4F4D-9269-27BCFC44CE48}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [cb684e797335f244caedacde8c77817f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8041F67A-A4D8-4B58-8A7D-288C30777AA4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [0f24c502f6b239fd63554d3d8a7940c0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B82349-9A59-4CC0-9875-6B55A364DB33}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [c37052751d8b7fb7f0c7315951b2f709]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{82A47425-A1E4-4CC8-9E5D-F4E9EA5FA14E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [59da24a374343204a117d0ba966d45bb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{82C72347-21C9-4B51-AA78-67B71868E5BA}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [ce65883f33751a1cd4e4602a7a89f30d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{846DC43D-B7C9-47F7-B18A-34782EF981B6}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [f340982fe4c4e551991e8802a85b7c84]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{88866739-B111-4FC9-BFE8-A111161498C0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [1f143196ddcb092d6e4a02883dc6ba46]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8916363F-D775-41C1-A01A-37D281CD88DB}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [34ff07c07335a3934e690f7b60a355ab]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8AA5D53A-8A1D-4603-98C0-628F5EF0E01E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e44fd9eecfd946f06c4b04868c7756aa]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8B7A5376-1069-43AD-9A9F-54EB606459F0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e54e5770f6b25bdbc0f8e0aa2dd635cb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BEF0B34-E18D-4E5A-A142-A32B57D159F3}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [82b1ddea1f89b5819423e1a9d52e4bb5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BF2328F-A070-4E2F-B482-4531B354D6AE}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [77bc2d9a693f88ae62567218ab587a86]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C5465F0-2431-4370-A574-D5438324BD40}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [6fc4f1d61395d1654671454590732cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8D01BD6C-F83F-4660-BAE8-A89D8BCE9130}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b47f8443aefac86e9b1d94f658ab619f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DC13B03-A0B3-4F28-B924-7C1426D5A370}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a68ddee9e4c42b0bd1e6e4a6e0236e92]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8E0CFC82-D3B4-4812-967B-86404F7551B7}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [72c1586f6d3bd264d3e4b0da0ef5fe02]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9197880B-9D4C-4101-99CA-7A4C892D339C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [c96a3c8b8325d462d2e531599c67ed13]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92AA7BB7-44BC-4B5F-9B32-6774E19F1E2D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [ba799c2bf5b321156355206a0af99b65]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92E1D6B7-4226-4AA5-A971-A1B9DD26A495}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [042f7d4a3f6972c467503f4ba65d1fe1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{95397465-C990-49FC-ACE6-648A1DA27124}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [6bc843847b2de94de6d18a00ff041ee2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{956DDB47-6F8D-476E-AC33-433BCE6162B0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [38fbbd0a7335082ec6f17d0d2ed510f0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{967E820E-2755-4626-952C-D2D9A268A3A9}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [af84e4e38a1e1a1c5f59028856ad936d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{98CF3705-2C35-4391-8CE5-B1B6F3A24553}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [ee4522a527813cfab9ff7c0eee155ea2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9AB6F944-11F4-4E26-AA77-CD2CF0E0895B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [31022d9acbdd171f6d4ba9e1f90ad927]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B13D237-EA97-44E2-85BF-CE3A4A51A9A0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [8aa9c3040f99191d8a2d1e6c927154ac]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9D309E03-65F6-4A64-838F-3833266EA898}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [58db784fbfe991a507b0a1e9b84b6c94]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F13D8D7-615D-4EDE-8060-742A3A1B9ED0}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [141f5a6ddfc990a622955b2ff3106f91]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F5A6B23-2D4A-4F3E-B2C3-758685D84266}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [48eb3c8be8c0280e12a58802f40f3bc5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FBA9266-62A3-4BE4-B22E-5CA589D57858}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [55de90375355aa8ceecac1c941c2ee12]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0FA23BE-4710-4D79-B99D-B379CA7041D7}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [3cf76f589e0a999d506875152ad955ab]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A1D66F9C-EDBF-41A5-ACCA-FEE211812133}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [76bd6562bfe9de585265c1c9eb183fc1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A29517EE-2FF1-4A85-98E2-19B8718C82B7}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e0534186acfc13233d7ab4d62ad9fa06]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A31F3BF6-9B76-48A4-B796-60F15166406E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b87b9e293474989e8731d6b49b6810f0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3A5610C-6156-458A-BB42-3F931C6FE9CC}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [83b047800a9e46f0595fcdbdcf34817f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6092C37-1A83-43CC-939B-D4D67826E1DF}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [1122bf0871372313f6c28a00da2952ae]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A74FB09E-1110-4177-B1ED-EC7CA786B8F8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [7bb8fdcae9bf6fc79027890117ecc13f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A77D826D-BBA8-42DA-B5F1-C449BA2D856B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2b08e2e55b4d73c3ebcc6f1b8e75e61a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A97F4AAD-4B69-4394-9827-BFD84CC1A656}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [a88bdfe8ecbccf676b4da0ea33d052ae]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA1F8FD6-37CD-4AF1-BB9A-5C8D125E50E4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [76bdbc0b22861125a314e8a233d0cb35]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA43CFAE-6C1F-4555-B711-1A833DC27470}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [3bf851767731dd5982364f3bbd4612ee]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AAB1398A-63C1-4DB4-B1F9-978CF3C99538}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [969d25a2edbb41f5387fef9b2ad918e8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABDE1233-B0A0-4B9C-8DF3-B71438F46A47}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [68cb5a6d6048b08636819af0f80b49b7]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD22EA03-C70C-4F9C-88D8-985E428CCD4F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [79bae9deb0f892a472462961f40f758b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD58BF87-A1BF-49CC-AB75-4C743CF7E37F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [52e1b4137b2d84b25661d5b5f80b50b0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AE6CF62F-3BFB-4607-83B2-3984D2E4FB44}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [cb684d7ab9efc86eded9cdbd38cb05fb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B06ECF89-7607-4D5D-BAD9-93F7D5372B7E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2211c1060d9b8aac9a1de8a29370de22]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0CAAFF4-F190-4E5B-BA2C-65E63A27DD23}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [999a6265d3d5979fa61172182cd7c63a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B11AA588-E7BE-4021-A31A-965FA020E37E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [78bb8a3da9ffa690d9df6822ca399967]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B17FCB0E-9083-4D49-9581-553C87C17B5E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [64cfe1e6c9df55e1882fa9e17192e818]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B236F8AC-F375-417D-84FB-2C2B3E4C63CD}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [35fe0dbac8e06fc76b4d3d4d53b0df21]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3CAC9A3-F032-4EA4-A07A-67DECDCAB01C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a390dceb594fd2648b2c7a104eb51ee2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3E952CD-BD09-486A-89E1-892C89CC8568}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [80b3e1e6ddcb69cde9cf39516b987789]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4FF270C-9699-4B62-87F9-9135A7CE9219}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b67d4e79c0e81d190eaa0a80b64d8977]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B57B6B60-A2B3-4FF7-85BD-C79A1E1D6950}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [59da75529d0b1a1c51665931ea19b44c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5A42686-B0C5-411B-A335-F0F51E77C69D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a0935077e3c54beb93243951bf4423dd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B766BB38-858B-4989-8EDC-2916BB64F5C1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [151e0bbc4662a5910bada4e6a063ee12]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8D02517-9F85-4A96-89FC-21E7AB96FDE1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [57dce6e10f99a78f7c3c1971e122b64a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8DCE889-7791-47A0-9047-23A19BE6194C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [1b189f2877312a0c3d7ba9e1e61dda26]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B95B23C4-7B6A-4455-9977-A2F253DBD870}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [55deaa1d990f20167444c6c405fe867a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B9DE19C6-2777-41B1-871C-1C2CE384FD25}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [999a3295b4f4bf772f89cbbfbc47926e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA0D608E-786E-4C97-88D7-FF57776270BB}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [da59ebdc931569cd3d7aec9e1fe422de]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD9D63A1-D505-4826-B638-25B712B88FCC}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [2f0422a5377188ae3088d5b53fc4ae52]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEE552FF-6F1A-49E7-A5B0-6413DB28532F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e2517a4d099f40f6199eeaa0659e6d93]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C05965DB-129B-4BE0-BC44-6BF57DB625BD}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [4ee51fa8fcac4de9b0070c7eda293ec2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0CFB749-4631-44EF-84D2-BBE7EBC79B6F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c2714f78fbad1a1cd5e3a1e96d9621df]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C12CAB25-3B27-48B5-8F78-DAC26756571B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [132054734563f93dffb9612906fd05fb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3250184-E7D2-422A-BF1A-CE696823B151}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c96ae3e4149459ddbafe4545699ad729]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C42EE0E2-38FF-43AF-B9F7-2AFD63E835E3}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [6dc6ffc8b2f6231303b5078321e23ec2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4A5ACB8-A51A-4672-AB64-B154A0B3AFFD}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [a68d31966741a88eb9ff365411f27987]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C539D253-50BA-4DF3-B584-557AD439C8E6}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [ae8557706642181ea7119eec15ee7f81]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C71C8A7A-A1C1-4423-B737-A6419ADDAF71}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [9c97784fa404a393298f5b2f4eb5f40c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C87C64DA-672B-4EF1-823A-611B19F2719A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [3bf89b2c099fe650a216d6b48d7632ce]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C9176B25-1998-4E8A-87D6-CFDF871FEFF9}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [d45ffbccfbaded49bbfc533745be1de3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF0C0DDE-B7B3-4BC7-859D-63DC61E46FE7}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [260d5f683573c96d298f0981fb08827e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D054B916-474E-4791-A3B0-AFF3EEACB588}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [50e37552a5038ea8dddaa6e4649feb15]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1CB9C68-E5D6-408C-824A-E33DAE68B99C}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [8ba857706444a690892e642658ab47b9]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D29912B2-935F-4F94-AD23-F111ED3EFB48}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e350cdfaaafec76f05b24743f50eef11]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D332998D-8D41-4BE5-BDA6-5EA272F74875}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [0f24f2d56147f145e1d71476eb1834cc]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4964F3C-7DEB-4E1E-BC6C-488AD8199279}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [f63db5126c3cc86ee1d71872e71c36ca]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D50AF76F-2BA3-446C-A1BA-29D2A3AB45C3}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e84b1ea945633df93187cac00df6d22e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D76B677D-9A04-4843-9E6D-3E15F55499E8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [db58dee97e2a9c9a23949eec09faeb15]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9341EFF-471C-41DF-903F-FECE5555674A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [82b1784f733576c0a116c1c9cc37c63a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA2FFAF0-DD13-409C-8AC3-4F8128673B9A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2c0702c58c1c0c2a45721575b64d41bf]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB2086FD-F4D3-4A18-8FA7-9A49B668ED7A}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [072c04c38622a98d22964a40a26121df]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBBB8D16-E298-49FB-9593-16696D34DE58}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [7fb46a5d10983ef83b7d6822fe0520e0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF962B78-DEE5-4193-AC73-9FC6332FAEE4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [44eff4d3b5f3a88e40783555cf3433cd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E080F8F3-5FA3-40F0-BBE2-1E956DF53F2F}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [a29137902286f6406751dfab15ee9f61]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E15A57D5-901D-403B-8752-46873F9C6278}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [0a29daedd8d0c3735b5d1b6f3cc7669a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4707C81-729E-4398-A579-C9FD67D840C1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [a192d4f3792f3df981366b1f5da60cf4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E518784F-8BC6-47FD-9028-393177975D1E}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [0a29a720fbad6dc9bafdfa90ec17ef11]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E68DBB32-33AC-45F2-BB69-19F7266FD7C8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [ab885374aafe5fd7ffb95f2b8c77ab55]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6A668D5-8336-4A61-8174-E7C2E445CAFE}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [d162d5f2aefa6fc715a22664000355ab]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7524B69-D21B-43AC-9B7A-B8303CBC8B83}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [cc6716b16345a88e2295e4a6986b6997]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8DD2CBD-4231-4CEB-B3A3-FCC8BFF966C8}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [122124a332760f2703b428622ad93dc3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA276E64-992D-4BDD-BCEE-2929B194D519}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [0e250dba10987eb8f9bf0b7f61a2c33d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA4F6651-2297-4BC6-8843-7283B37837F2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [8aa94e79b4f4a195b6024d3d9e65d42c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA8040AB-2822-4E50-939A-51957A4753D9}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [8aa9bd0a4a5e45f1f8c0ec9e030020e0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EAD56BC8-967C-4F60-A0ED-8514E7C365DB}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [072ce2e58127d85e6057dcaec04308f8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB218325-6741-4B31-BC83-3FC5B7569141}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [2b0813b47c2c71c5f7c092f8907322de]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB22D0CE-DA58-4575-83C4-A9734AC8EBE6}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [e54e5b6c446475c1cbec8ffb2ad9cc34]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ECE204F7-4A66-4985-8188-3B12CAEAD841}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [a48fa22507a1e74f4573a3e7ba492dd3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF2DA774-5DC9-4BAE-BC9C-1CCD2A6CC665}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [35fed1f65256aa8c7c3ca1e9739057a9]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF57BF5F-5D39-43B7-8BE2-51DE4A1935A2}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [3300a522406879bda6118dfd21e2e719]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F022A6F2-8B5A-49D5-8F22-50ADFA3B4DD4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [f340ffc8d2d676c072463951df24946c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1860A31-1956-415E-9658-57EE7B50327D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [c172ac1b0d9bda5c4474fe8c41c2a15f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F32FA745-BD2C-41CB-9731-1E718B578BAC}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [b1825473297ff4429127bdcd9073cc34]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F63C0477-C2A4-4237-87A5-BAAA9A232A31}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [f24123a405a3f73f2395addddc27de22]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F752A1F9-D754-42B1-B24A-E2F259194BC9}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [7cb7f0d73177fb3b38804d3de51e0af6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7AB45CE-C586-4F7A-A8B0-657CCA87649D}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [76bd33948a1eba7c6b4d58327f84f20e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F875C708-1197-4238-8160-2FA0AC6244C4}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e94ac2051692b5819721454535ce5ca4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F97948D7-63AD-4A81-A765-A84FE9272CD1}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [f43fecdbf2b6c1755b5d1a70c53e649c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA2CC340-DC6B-4C2C-B5BB-6074BD364F67}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [49ea586f7137350126914c3eb35008f8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDD31C11-A055-482A-94AC-FDE689A6DB86}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-buttonutil.exe, In Quarantäne, [43f02e99a404df571d9aa2e824df956b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDFC82BD-68B1-4CB5-BADA-8D90327C281B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [e1526c5b5d4bab8b2197dfab986bbf41]
PUP.Optional.CrossRider, HKU\S-1-5-21-1885290322-1835322729-3868160957-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FE59B725-D148-4D12-BB5B-C2B9EF11E15B}|AppName, ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe-codedownloader.exe, In Quarantäne, [8ba844837b2d46f04b6da9e1a85b649c]

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 4
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 

Dateien: 11
PUP.Optional.AshampooRegistryCleaner, C:\ProgramData\Ashampoo\ico_ashampoo_marketplace.ico, In Quarantäne, [f73c9a2d8424ff37dab519b8a65a30d0], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\lsdb.js, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\background.html, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\content.js, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\manifest.json, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\mqhzZBc6.js, In Quarantäne, [a88b1fa88e1a2d09d19f8d0a53b052ae], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\lsdb.js, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\background.html, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\content.js, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\manifest.json, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 
PUP.Optional.MultiPlug, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecokdaigfnildpbkgienihjdekjkgonh\1.0\mqhzZBc6.js, In Quarantäne, [55de7750b5f374c281ef8512cb38827e], 

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c18e726ea6a3ae43b7f1df91c4aaa902
# end=init
# utc_time=2017-03-07 07:00:07
# local_time=2017-03-07 08:00:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 32635
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c18e726ea6a3ae43b7f1df91c4aaa902
# end=updated
# utc_time=2017-03-07 07:07:05
# local_time=2017-03-07 08:07:05 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c18e726ea6a3ae43b7f1df91c4aaa902
# engine=32635
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-03-07 09:07:07
# local_time=2017-03-07 10:07:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 343501 240550677 0 0
# scanned=306036
# found=7
# cleaned=0
# scan_time=7201
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dmcmkkcindsbggohlxbeculxnamqzdgz\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"
sh=AA16F7B7A99E1B2BA2BED7BA7711FC01A448B19C ft=1 fh=717626f8a812fe70 vn="Variante von Win32/Kryptik.FPIE Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\drain-3\drain-46.exe"
sh=6E140D6CA0840248A71CFCD8FF484C4323F92704 ft=1 fh=c79b59ab2e1faafd vn="Variante von Win32/Kryptik.FPIE Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\versabus-5\versabus-54.exe"
sh=05C633B9581F3B9995E13A6B53E6AD02F6DD2BD6 ft=1 fh=8ec4c156529a5196 vn="Variante von Win32/GenKryptik.XDS Trojaner" ac=I fn="C:\FRST\Quarantine\C\Users\nina\AppData\Roaming\calculus-12\calculus-2.exe"
sh=80B311D4F07E59A0227E7191E74C227AF3610114 ft=1 fh=f2b61d431aed223b vn="Variante von Win32/Kryptik.FPIE Trojaner" ac=I fn="C:\FRST\Quarantine\C\Users\nina\AppData\Roaming\codec-08\codec-80.exe"
sh=D957B0EC634B5C52AA2B8934223A6248D5152807 ft=1 fh=4c2491a4bea30714 vn="Variante von Win32/SweetIM.B eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\PDFCreator\message.exe"
sh=63D78C0254010DE6FCDF7A5596F543882EF5345B ft=0 fh=0000000000000000 vn="Java/Agent.DJ Trojaner" ac=I fn="C:\Users\nina\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\40a44ad0-7fec2c8b"
         

Alt 08.03.2017, 11:44   #24
kangli
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



Code:
ATTFilter
 Results of screen317's Security Check version 1.009  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 60  
 Java version 32-bit out of Date! 
 Adobe Flash Player 24.0.0.221  
 Adobe Reader 9 Adobe Reader out of Date! 
 Mozilla Firefox (51.0.1) 
 Google Chrome (56.0.2924.87) 
 Google Chrome (SetupMetrics...) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
danke cosiunus, es scheint alles wieder zu klappen, die tabs in chrom ploppen nicht mehr auf, chrom stürzt nicht mehr ab, ich komme wieder an mein bankkonto ran. ich würde mich gern erkenntlich zeigen, aber wie ... ? will ja nicht aufdringlich sein, aber falls du aus berlin bist, würde ich dich zu nem essen einladen oder hast du ne idee ? wie auch immer DANKE

Alt 09.03.2017, 18:59   #25
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Standard

trojaner im system? windows7 64 bit, onlinebanking nicht möglich



danke aber Berlin ist ziemlich weit weg für mich...

Du musst noch alten Mist deinstallieren:

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Java 7 Update 60

    Adobe Reader 9

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 

__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu trojaner im system? windows7 64 bit, onlinebanking nicht möglich
akamai, canon, converter, defender, flash player, format, google, helper, home, mozilla, mp3, problem, prozesse, realtek, registry, rundll, scan, services.exe, software, svchost.exe, system, trojaner, trojaner windows7 64bit, udp, vlc updater, windows, wiso, wma




Ähnliche Themen: trojaner im system? windows7 64 bit, onlinebanking nicht möglich


  1. W7-Absturz, seitdem System langsam, Runterfahren verzögert bzw. nicht möglich
    Log-Analyse und Auswertung - 02.12.2016 (0)
  2. Windows7 Trojana abgesicherter Modus nicht möglich
    Log-Analyse und Auswertung - 05.09.2015 (7)
  3. Netbook mit windows7 arbeitet sehr langsam - Neuinstallation von software nicht möglich
    Plagegeister aller Art und deren Bekämpfung - 13.04.2015 (19)
  4. Norton 360 "System Infected: Trojan.Ransomlock.G" blockiert - Virus in Quarantäne - Onlinebanking sFirm nicht mehr ausführbar
    Plagegeister aller Art und deren Bekämpfung - 31.01.2015 (15)
  5. Windows7: Booten nicht möglich, div. Bootmöglichkeiten funktionieren nicht
    Alles rund um Windows - 02.08.2014 (14)
  6. Windows7 home premium. Einloggen als Besitzer nicht möglich-password vergessen?
    Alles rund um Windows - 03.03.2014 (3)
  7. Windows7 - eGdpSvc.exe Trojan - Internetoptionen geht nicht- Onlinebanking
    Log-Analyse und Auswertung - 06.02.2014 (14)
  8. GUV-Trojaner; Start in abgesichertem Modus nicht möglich; Start von FRST nicht möglich
    Log-Analyse und Auswertung - 20.12.2013 (1)
  9. Windows7 nur noch abgesicherter Modus möglich (aka Systemwiederherstellung)
    Log-Analyse und Auswertung - 07.12.2013 (11)
  10. Windows7: hochfahren geht, dann nur Ausschalten möglich
    Log-Analyse und Auswertung - 03.12.2013 (17)
  11. GVU Trojaner – Booten von CD und USB nicht möglich, abgesicherter Modus nur mit Eingabeaufforderung möglich
    Log-Analyse und Auswertung - 06.07.2013 (39)
  12. System-Wiederherstellung nicht mehr möglich, programm browserprotect bit 89 neu und lässt sich nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 31.05.2013 (31)
  13. Onlinebanking-Trojaner Zeus2 / ZBot obwohl KEIN Onlinebanking genutzt wird
    Plagegeister aller Art und deren Bekämpfung - 21.05.2013 (4)
  14. DiBa Trojaner beim Log In Onlinebanking - er ist aufm PC, aber nicht auffindbar :(
    Plagegeister aller Art und deren Bekämpfung - 08.05.2013 (9)
  15. System Progressive Protection - Abgesicherter Modus nicht möglich
    Plagegeister aller Art und deren Bekämpfung - 03.10.2012 (1)
  16. System Conf. Utility deakt. nicht möglich??
    Log-Analyse und Auswertung - 02.01.2009 (3)
  17. Pufferüberlauf;System fährt runter, wann es will; microsoft update nicht mehr möglich
    Plagegeister aller Art und deren Bekämpfung - 16.09.2006 (5)

Zum Thema trojaner im system? windows7 64 bit, onlinebanking nicht möglich - Einen Fix brauchen wir noch: FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in - trojaner im system? windows7 64 bit, onlinebanking nicht möglich...
Archiv
Du betrachtest: trojaner im system? windows7 64 bit, onlinebanking nicht möglich auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.