weitere log Files OTL Code:
OTL logfile created on: 19.09.2018 00:34:12 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Acer\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17843)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,93 Gb Total Physical Memory | 0,87 Gb Available Physical Memory | 45,18% Memory free
3,87 Gb Paging File | 2,63 Gb Available in Paging File | 68,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 41,82 Gb Free Space | 14,03% Space Free | Partition Type: NTFS
Drive D: | 3,74 Gb Total Space | 3,73 Gb Free Space | 99,84% Space Free | Partition Type: FAT32
Computer Name: ACER-PC | User Name: Acer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found
PRC - C:\Users\Acer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe (AO Kaspersky Lab)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe (AO Kaspersky Lab)
PRC - C:\Programme\Malwarebytes\Anti-Malware\mbamtray.exe (Malwarebytes)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe (AO Kaspersky Lab)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (AO Kaspersky Lab)
PRC - C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - (hasplms) -- C:\Windows\SysNative\hasplms.exe (SafeNet, Inc.)
SRV:64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (klvssbridge64_19.0.0) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe (AO Kaspersky Lab)
SRV - (ElcomsoftUpdate) -- C:\Program Files (x86)\Elcomsoft\Common Files\epr_update.exe (Elcomsoft Co. Ltd.)
SRV - (WsAppService) -- C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe (Wondershare)
SRV - (MBAMService) -- C:\Programme\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVP19.0.0) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe (AO Kaspersky Lab)
SRV - (KSDE3.0.0) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (AO Kaspersky Lab)
SRV - (PDF24) -- C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
SRV - (WsDrvInst) -- C:\Program Files (x86)\Wondershare\Wondershare dr.fone toolkit for Android\Library\DriverInstaller\DriverInstall.exe (Wondershare)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ose64) -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (OfficeSvc) -- C:\Programme\Microsoft Office 15\ClientX64\integratedoffice.exe (Microsoft Corporation)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys (Malwarebytes)
DRV:64bit: - (klhk) -- C:\Windows\SysNative\drivers\klhk.sys (AO Kaspersky Lab)
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (AO Kaspersky Lab)
DRV:64bit: - (klflt) -- C:\Windows\SysNative\drivers\klflt.sys (AO Kaspersky Lab)
DRV:64bit: - (libusbK) -- C:\Windows\SysNative\drivers\libusbK.sys (hxxp://libusb-win32.sourceforge.net)
DRV:64bit: - (libusb0) -- C:\Windows\SysNative\drivers\libusb0.sys (hxxp://libusb-win32.sourceforge.net)
DRV:64bit: - (klwtp) -- C:\Windows\SysNative\drivers\klwtp.sys (AO Kaspersky Lab)
DRV:64bit: - (kldisk) -- C:\Windows\SysNative\drivers\kldisk.sys (AO Kaspersky Lab)
DRV:64bit: - (dtliteusbbus) -- C:\Windows\SysNative\drivers\dtliteusbbus.sys (Disc Soft Ltd)
DRV:64bit: - (dtlitescsibus) -- C:\Windows\SysNative\drivers\dtlitescsibus.sys (Disc Soft Ltd)
DRV:64bit: - (kneps) -- C:\Windows\SysNative\drivers\kneps.sys (AO Kaspersky Lab)
DRV:64bit: - (kl1) -- C:\Windows\SysNative\drivers\kl1.sys (AO Kaspersky Lab)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (kltap) -- C:\Windows\SysNative\drivers\kltap.sys (The OpenVPN Project)
DRV:64bit: - (klim6) -- C:\Windows\SysNative\drivers\klim6.sys (AO Kaspersky Lab)
DRV:64bit: - (klbackupflt) -- C:\Windows\SysNative\drivers\klbackupflt.sys (AO Kaspersky Lab)
DRV:64bit: - (cm_km) -- C:\Windows\SysNative\drivers\cm_km.sys (AO Kaspersky Lab)
DRV:64bit: - (klkbdflt) -- C:\Windows\SysNative\drivers\klkbdflt.sys (AO Kaspersky Lab)
DRV:64bit: - (klbackupdisk) -- C:\Windows\SysNative\drivers\klbackupdisk.sys (AO Kaspersky Lab)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (AO Kaspersky Lab)
DRV:64bit: - (kltdi) -- C:\Windows\SysNative\drivers\kltdi.sys (AO Kaspersky Lab)
DRV:64bit: - (hardlock) -- C:\Windows\SysNative\drivers\hardlock.sys (SafeNet, Inc.)
DRV:64bit: - (aksfridge) -- C:\Windows\SysNative\drivers\aksfridge.sys (SafeNet, Inc.)
DRV:64bit: - (aksdf) -- C:\Windows\SysNative\drivers\aksdf.sys (SafeNet, Inc.)
DRV:64bit: - (aksusb) -- C:\Windows\SysNative\drivers\aksusb.sys (SafeNet, Inc.)
DRV:64bit: - (akshasp) -- C:\Windows\SysNative\drivers\akshasp.sys (SafeNet, Inc.)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (klpd) -- C:\Windows\SysNative\drivers\klpd.sys (AO Kaspersky Lab)
DRV:64bit: - (FTSER2K) -- C:\Windows\SysNative\drivers\ftser2k.sys (Future Technology Devices International Ltd.)
DRV:64bit: - (SSPORT) -- C:\Windows\SysNative\drivers\SSPORT.SYS (Samsung Electronics)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (aswTap) -- C:\Windows\SysNative\drivers\aswTap.sys (The OpenVPN Project)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbrndis6) -- C:\Windows\SysNative\drivers\usb80236.sys (Microsoft Corporation)
DRV:64bit: - (FTDIBUS) -- C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (multikey) -- C:\Windows\SysNative\drivers\multikey.sys (Chingachguk & Denger2k (Elite & SP edition))
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (msloop) -- C:\Windows\SysNative\drivers\loop.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 D5 C6 26 34 52 D0 01 [binary data]
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-8061801-39794175-114476390-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.181.2: C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.181.2: C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\Root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Acer\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Acer\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\light_plugin_F88CEF8523DE460F9FA1D6E48BF8D340@kaspersky.com: C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY TOTAL SECURITY 19.0.0\FFEXT\LIGHT_PLUGIN_FIREFOX\ADDON.XPI [2018.09.16 23:51:02 | 000,155,289 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\light_plugin_F88CEF8523DE460F9FA1D6E48BF8D340@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2018.09.16 23:51:02 | 000,155,289 | ---- | M] ()
[2015.07.23 17:24:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Extensions
[2018.03.28 12:39:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\SystemExtensionsDev
[2018.09.08 18:00:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\browser-extension-data
[2018.09.12 04:17:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2018.09.08 18:00:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\browser-extension-data\firefox@mega.co.nz
[2018.03.28 09:55:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\browser-extension-data\screenshots@mozilla.org
[2018.09.16 01:58:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\extensions
[2018.09.08 15:38:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\ietdujz6.Oli\extensions\{ab10d63e-3096-4492-ab0e-5edcf4baf988}
[2018.09.08 10:30:31 | 000,485,159 | ---- | M] () (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\firefox\profiles\ietdujz6.Oli\extensions\sp@avast.com.xpi
[2018.09.08 10:30:32 | 000,789,048 | ---- | M] () (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\firefox\profiles\ietdujz6.Oli\extensions\wrc@avast.com.xpi
[2018.09.06 20:37:22 | 001,161,002 | ---- | M] () (No name found) -- C:\Users\Acer\AppData\Roaming\mozilla\firefox\profiles\ietdujz6.Oli\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd\20.0.543.85_1\
CHR - Extension: No name found = C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6918.723.0.0_0\
O1 HOSTS File: ([2018.09.16 23:06:25 | 000,000,852 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.8.0_181\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\office15\urlredir.dll (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\office15\grooveex.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre1.8.0_181\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Kaspersky Protection) - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Kaspersky Protection) - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O3:64bit: - HKLM\..\Toolbar: (Kaspersky Protection Toolbar) - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Kaspersky Protection Toolbar) - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O3:64bit: - HKU\S-1-5-21-8061801-39794175-114476390-1000\..\Toolbar\WebBrowser: (Kaspersky Protection Toolbar) - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O3 - HKU\S-1-5-21-8061801-39794175-114476390-1000\..\Toolbar\WebBrowser: (Kaspersky Protection Toolbar) - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll (AO Kaspersky Lab)
O4:64bit: - HKLM..\Run: [CL-23-14CEAA54-7A44-47B8-A543-6C34BE9FDB21] "C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-23-14CEAA54-7A44-47B8-A543-6C34BE9FDB21\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-23-14CEAA54-7A44-47B8-A543-6C34BE9FDB21\Installer.exe" File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-21-8061801-39794175-114476390-1000..\Run: [ElcomSoft DPR Server] C:\Program Files (x86)\Elcomsoft eXplorer for WhatsApp\Distributed Password Recovery\edpr_server.exe (Elcomsoft Co. Ltd.)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DCA6370-AD15-4EB6-8449-752B392B6938}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A1A8FDA6-9070-4C34-8764-4EAB4036B63A}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE9CA609-04D4-4857-A274-4962B047307A}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\office15\msosb.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\{3155777d-0d61-11e5-9a46-dabf667e7b61}\Shell - "" = AutoRun
O33 - MountPoints2\{3155777d-0d61-11e5-9a46-dabf667e7b61}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{31557a4f-0d61-11e5-9a46-dabf667e7b61}\Shell - "" = AutoRun
O33 - MountPoints2\{31557a4f-0d61-11e5-9a46-dabf667e7b61}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2018.09.19 00:19:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Acer\Desktop\OTL.exe
[2018.09.19 00:06:47 | 005,930,728 | ---- | C] (EnigmaSoft Limited) -- C:\Users\Acer\Desktop\SpyHunter-Installer.exe
[2018.09.17 23:19:33 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\JR@
[2018.09.17 21:13:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elcomsoft
[2018.09.16 23:54:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
[2018.09.16 23:52:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
[2018.09.16 23:51:26 | 000,110,176 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\SysNative\klfphc.dll
[2018.09.16 23:50:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab
[2018.09.16 23:50:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2018.09.16 23:49:14 | 001,193,160 | ---- | C] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klhk.sys
[2018.09.16 23:49:14 | 001,127,104 | ---- | C] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2018.09.16 23:49:14 | 000,219,328 | ---- | C] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klflt.sys
[2018.09.16 23:49:14 | 000,152,360 | ---- | C] (AO Kaspersky Lab) -- C:\Windows\SysNative\klhkum.dll
[2018.09.16 23:11:28 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\Firmware
[2018.09.16 22:25:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2018.09.16 22:23:08 | 000,110,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-64.dll
[2018.09.16 22:13:16 | 000,110,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2018.09.16 22:13:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Oracle
[2018.09.16 22:09:23 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2018.09.16 17:20:30 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\mbam
[2018.09.16 17:18:40 | 000,259,360 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018.09.16 17:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2018.09.16 17:17:50 | 000,152,688 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbae64.sys
[2018.09.16 13:24:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Atc
[2018.09.16 08:33:20 | 000,000,000 | ---D | C] -- C:\Program Files\Everything
[2018.09.16 08:00:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elcomsoft Password Recovery
[2018.09.16 08:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elcomsoft eXplorer for WhatsApp
[2018.09.16 08:00:44 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Elcomsoft
[2018.09.16 08:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Elcomsoft Password Recovery
[2018.09.16 07:11:52 | 000,000,000 | ---D | C] -- C:\ProgramData\WsAppHelper
[2018.09.16 07:03:14 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2018.09.16 06:20:32 | 001,721,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01009.dll
[2018.09.16 06:20:32 | 001,002,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller2.dll
[2018.09.16 06:00:51 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Backuptrans Android SMS Transfer (x64)
[2018.09.16 06:00:46 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Backuptrans Android SMS Transfer (x64)
[2018.09.16 05:57:20 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\Datenrettung
[2018.09.16 05:35:15 | 000,206,080 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
[2018.09.16 05:35:15 | 000,110,336 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2018.09.16 04:49:53 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\WonderShare
[2018.09.16 04:18:18 | 000,000,000 | ---D | C] -- C:\Users\Acer\Documents\Wondershare
[2018.09.16 04:09:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
[2018.09.16 04:08:46 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Wondershare
[2018.09.16 04:03:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare
[2018.09.16 04:03:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Wondershare
[2018.09.16 04:01:43 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Wondershare
[2018.09.16 01:46:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2018.09.16 00:27:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2018.09.15 14:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\SecuritySuite
[2018.09.15 00:19:30 | 000,000,000 | ---D | C] -- C:\ProgramData\wsr
[2018.09.14 14:20:02 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\BackupTrans
[2018.09.14 14:19:46 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Backuptrans Android WhatsApp Transfer (x64)
[2018.09.14 14:19:16 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Backuptrans Android WhatsApp Transfer (x64)
[2018.09.12 21:11:47 | 000,238,176 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\libusbK.dll
[2018.09.12 21:11:47 | 000,170,080 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysWow64\libusbK.dll
[2018.09.12 21:11:47 | 000,076,384 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\libusb0.dll
[2018.09.12 21:11:47 | 000,067,680 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysWow64\libusb0.dll
[2018.09.12 21:11:47 | 000,052,320 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\drivers\libusb0.sys
[2018.09.12 21:11:47 | 000,047,200 | ---- | C] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\drivers\libusbK.sys
[2018.09.12 21:11:47 | 000,000,000 | ---D | C] -- C:\usb_driver
[2018.09.12 20:24:54 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
[2018.09.12 11:23:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2018.09.12 01:03:58 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\sd
[2018.09.08 18:40:06 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\Samsung Backup
[2018.09.08 15:40:13 | 000,000,000 | -H-D | C] -- C:\$AV_ASW
[2018.09.08 15:38:32 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\WServices
[2018.09.08 14:37:00 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Elcomsoft
[2018.09.08 12:36:57 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\MobileBackupForeverIni
[2018.09.08 12:34:59 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\dr.extra.config
[2018.09.08 12:34:58 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\HYXDevPsnList
[2018.09.08 10:34:50 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\AVAST Software
[2018.09.08 10:31:38 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Opera Software
[2018.09.08 10:30:48 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Opera Software
[2018.09.08 10:26:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kingo ROOT
[2018.09.08 09:34:07 | 000,713,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller.dll
[2018.09.08 09:34:07 | 000,713,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WinUSBCoInstaller.dll
[2018.09.08 09:34:06 | 001,494,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01007.dll
[2018.09.08 09:34:06 | 001,494,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfCoInstaller01007.dll
[2018.09.08 09:26:51 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\GHISLER
[2018.09.08 09:19:27 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\GHISLER
[2018.09.06 21:12:51 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Google
[2018.09.02 13:06:47 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2018.09.02 13:03:55 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Sharpened_Productions
[2018.09.02 13:03:53 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\File Viewer Plus 3
[2018.09.02 04:33:03 | 000,000,000 | ---D | C] -- C:\ProgramData\APM
[2018.09.02 04:21:19 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\apm
[2018.09.02 04:21:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\LOGS
[2018.09.02 04:19:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\abylonsoft
[2018.09.02 03:35:43 | 000,000,000 | ---D | C] -- C:\.android
[2018.09.02 03:35:14 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Roaming\Apowersoft
[2018.09.02 03:34:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apowersoft
[2018.09.01 22:19:11 | 000,000,000 | ---D | C] -- C:\Users\Acer\.android
[2018.09.01 22:16:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2018.09.01 05:25:39 | 000,000,000 | ---D | C] -- C:\Users\Acer\Documents\Samsung
[2018.09.01 05:19:00 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NativeFus_Log
[2018.09.01 05:18:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2018.09.01 04:56:25 | 000,144,664 | ---- | C] (MAPILab Ltd. & Add-in Express Ltd.) -- C:\Windows\SysWow64\secman.dll
[2018.09.01 01:51:09 | 000,000,000 | ---D | C] -- C:\Users\Acer\Desktop\Janice
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2018.09.19 00:16:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Acer\Desktop\OTL.exe
[2018.09.19 00:08:26 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2018.09.19 00:08:26 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2018.09.19 00:06:33 | 001,619,700 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2018.09.19 00:06:33 | 000,699,440 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2018.09.19 00:06:33 | 000,654,238 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2018.09.19 00:06:33 | 000,149,548 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2018.09.19 00:06:33 | 000,122,110 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2018.09.19 00:02:06 | 005,930,728 | ---- | M] (EnigmaSoft Limited) -- C:\Users\Acer\Desktop\SpyHunter-Installer.exe
[2018.09.19 00:00:58 | 000,259,360 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018.09.18 23:59:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2018.09.18 23:58:55 | 1557,368,832 | -HS- | M] () -- C:\hiberfil.sys
[2018.09.18 01:31:41 | 000,000,147 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.bak
[2018.09.16 23:54:19 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
[2018.09.16 23:52:14 | 000,002,115 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Total Security.lnk
[2018.09.16 23:52:13 | 000,002,187 | ---- | M] () -- C:\Users\Public\Desktop\Sicherer Zahlungsverkehr.lnk
[2018.09.16 23:49:14 | 001,193,160 | ---- | M] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klhk.sys
[2018.09.16 23:49:14 | 001,127,104 | ---- | M] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2018.09.16 23:49:14 | 000,219,328 | ---- | M] (AO Kaspersky Lab) -- C:\Windows\SysNative\drivers\klflt.sys
[2018.09.16 23:49:14 | 000,152,360 | ---- | M] (AO Kaspersky Lab) -- C:\Windows\SysNative\klhkum.dll
[2018.09.16 23:42:20 | 000,025,913 | ---- | M] () -- C:\ProgramData\agent.uninstall.1537134128.bdinstall.bin
[2018.09.16 23:36:32 | 000,047,395 | ---- | M] () -- C:\ProgramData\cl.1537133790.bdinstall.bin
[2018.09.16 23:36:13 | 000,177,750 | ---- | M] () -- C:\ProgramData\cl.uninstall.1537132878.bdinstall.bin
[2018.09.16 23:06:25 | 000,000,852 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2018.09.16 22:12:35 | 000,110,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-64.dll
[2018.09.16 22:12:35 | 000,110,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2018.09.16 14:08:28 | 000,046,007 | ---- | M] () -- C:\ProgramData\cl.kit.1537095966.bdinstall.bin
[2018.09.16 14:08:20 | 000,394,592 | ---- | M] () -- C:\ProgramData\cl.1537095993.bdinstall.bin
[2018.09.16 12:57:13 | 000,047,448 | ---- | M] () -- C:\ProgramData\agent.1537095425.bdinstall.bin
[2018.09.16 07:11:10 | 000,439,000 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2018.09.16 06:20:32 | 001,721,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01009.dll
[2018.09.16 06:20:32 | 001,002,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller2.dll
[2018.09.15 13:05:51 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2018.09.15 01:44:41 | 000,000,446 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2018.09.15 01:44:23 | 000,238,176 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\libusbK.dll
[2018.09.15 01:44:23 | 000,170,080 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysWow64\libusbK.dll
[2018.09.15 01:44:23 | 000,047,200 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\drivers\libusbK.sys
[2018.09.12 21:11:47 | 000,076,384 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\libusb0.dll
[2018.09.12 21:11:47 | 000,067,680 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysWow64\libusb0.dll
[2018.09.12 21:11:47 | 000,052,320 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\Windows\SysNative\drivers\libusb0.sys
[2018.09.08 10:16:07 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2018.09.08 09:52:15 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2018.09.02 12:45:51 | 001,593,980 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files Created - No Company Name ==========
[2018.09.16 23:54:34 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
[2018.09.16 23:52:48 | 000,002,187 | ---- | C] () -- C:\Users\Public\Desktop\Sicherer Zahlungsverkehr.lnk
[2018.09.16 23:52:48 | 000,002,115 | ---- | C] () -- C:\Users\Public\Desktop\Kaspersky Total Security.lnk
[2018.09.16 23:42:20 | 000,025,913 | ---- | C] () -- C:\ProgramData\agent.uninstall.1537134128.bdinstall.bin
[2018.09.16 23:36:32 | 000,047,395 | ---- | C] () -- C:\ProgramData\cl.1537133790.bdinstall.bin
[2018.09.16 23:36:13 | 000,177,750 | ---- | C] () -- C:\ProgramData\cl.uninstall.1537132878.bdinstall.bin
[2018.09.16 14:08:28 | 000,046,007 | ---- | C] () -- C:\ProgramData\cl.kit.1537095966.bdinstall.bin
[2018.09.16 14:08:18 | 000,394,592 | ---- | C] () -- C:\ProgramData\cl.1537095993.bdinstall.bin
[2018.09.16 12:57:13 | 000,047,448 | ---- | C] () -- C:\ProgramData\agent.1537095425.bdinstall.bin
[2018.09.16 04:06:47 | 000,000,232 | ---- | C] () -- C:\Windows\SysWow64\dllhost.exe.config
[2018.09.16 00:57:35 | 000,002,358 | ---- | C] () -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2018.09.15 03:07:57 | 000,439,000 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2018.09.12 21:11:53 | 000,000,446 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2018.09.08 10:16:07 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2018.09.08 09:52:15 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\UC.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\RAR.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\PKZIP.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\PKUNZIP.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\NOCLOSE.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\LHA.PIF
[2018.09.08 09:19:28 | 000,000,545 | ---- | C] () -- C:\Windows\ARJ.PIF
[2016.09.16 16:56:39 | 000,004,096 | -H-- | C] () -- C:\Users\Acer\._.Trashes
[2016.06.06 11:39:05 | 368,772,057 | ---- | C] () -- C:\Users\Acer\ISTA-D_3.54.11.7z
[2014.11.02 04:46:18 | 000,016,384 | ---- | C] () -- C:\Users\Acer\Erinnerung
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.02.13 07:22:33 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.02.13 07:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:EFB09287
< End of report > Code:
OTL Extras logfile created on: 19.09.2018 00:34:12 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Acer\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17843)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,93 Gb Total Physical Memory | 0,87 Gb Available Physical Memory | 45,18% Memory free
3,87 Gb Paging File | 2,63 Gb Available in Paging File | 68,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 41,82 Gb Free Space | 14,03% Space Free | Partition Type: NTFS
Drive D: | 3,74 Gb Total Space | 3,73 Gb Free Space | 99,84% Space Free | Partition Type: FAT32
Computer Name: ACER-PC | User Name: Acer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL" "%1"
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL" "%1"
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"TCP Query User{7F1896A5-628F-444B-9739-24749C5E0FFF}C:\program files (x86)\elcomsoft explorer for whatsapp\distributed password recovery\edpr_server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\elcomsoft explorer for whatsapp\distributed password recovery\edpr_server.exe |
"UDP Query User{30C98ECC-D2EA-471F-8A05-9596FEA09881}C:\program files (x86)\elcomsoft explorer for whatsapp\distributed password recovery\edpr_server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\elcomsoft explorer for whatsapp\distributed password recovery\edpr_server.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1733B435-DB34-25F2-F365-5E9A07363C0A}" = ATI Catalyst Install Manager
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F64180181F0}" = Java 8 Update 181 (64-bit)
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes Version 3.5.1.2522
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{63DF5C4B-E3BF-3346-A033-C57B22F44C9E}" = Microsoft .NET Framework 4.6.2
"{90150000-001C-0000-1000-0000000FF1CE}" = Microsoft Access Runtime 2013
"{90150000-001C-0407-1000-0000000FF1CE}" = Microsoft Access Runtime MUI (German) 2013
"{90150000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2013
"{90150000-007E-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{90150000-008C-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0407-1000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2013
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.6.2 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.6.2
"{98E12667-FD6F-313E-8ED4-9FEBE41F790B}" = Microsoft .NET Framework 4.6.2 (DEU)
"{C7090522-1436-4FD6-9449-B06A665E2537}" = Intel(R) Chipset Device Software
"69EB41F768721DA6C15F129E9460530E23775645" = Windows Driver Package - Intel Corporation (ialpssdma) System (09/11/2014 1.1.6.1030)
"701281E8283E9E3681220099A9DA5013A5A437AF" = Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd. (WinUSB) AndroidUsbDeviceClass (12/02/2015 2.12.1.0)
"85A33267F12961AF9ED9AE799DEDA5E62BEA236F" = Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd. (dg_ssudbus) USB (12/02/2015 2.12.1.0)
"88ED314360B98E6E82E7CC3201FAEB4A9FD291B4" = Windows-Treiberpaket - SAMSUNG Electronics Co., Ltd. (ssudmdm) Modem (12/02/2015 2.12.1.0)
"9E24492CE9279512BD465F61DB8523641BB7BBFC" = Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (01/18/2013 2.08.28)
"A002F77A6BB0D15E21DCDB8CE448B24211C9D22A" = Windows Driver Package - Intel Corporation (iaiosd) SCSIAdapter (09/11/2014 1.1.6.1030)
"CCleaner" = CCleaner
"CE5E29DEC634186EA954E2ECFA6605882836E1EA" = Windows Driver Package - Intel Corporation (iaioi2c) System (09/11/2014 1.1.6.1030)
"D43FD4059F47ACA9539247D6CF690AAEA503AF2D" = Windows-Treiberpaket - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004)
"D693C629D7721AFFE496EED1C2586C5B10254EB0" = Windows Driver Package - Intel Corporation (iaiogpio) System (09/11/2014 1.1.6.1030)
"D820295C3CB3E9A37FDC37124E80C0B34D266AD3" = Windows Driver Package - Intel Corporation (iaiospi) System (09/11/2014 1.1.6.1030)
"E61B77ECE57113AE1CA028BC7A8AD6C137BD13DD" = Windows Driver Package - FTDI CDM Driver Package - VCP Driver (01/18/2013 2.08.28)
"FA2348525EA2C7309C023320717D830CBD8CAE6A" = Windows Driver Package - Intel Corporation (iaiouart) Ports (09/11/2014 1.1.6.1030)
"Office15.AccessRT" = Microsoft Access Runtime 2013
"ProfessionalRetail - de-de" = Microsoft Office Professional 2013 - de-de
"ProPlusRetail - de-de" = Microsoft Office Professional Plus 2013 - de-de
"WinRAR archiver" = WinRAR 5.60 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{ 70994916-61E9-40D2-A30C-89D2C030017F}_is1" = BMW Standard Tools
"{010B6E51-0619-4352-BE83-9FB9030DE8E1}" = Elcomsoft Distributed Password Recovery
"{083933AF-00A2-4CFC-BE59-19DC385E8761}" = EDIABAS 7.3.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2C303EE0-A595-3543-A71A-931C7AC40EDE}" = Microsoft Primary Interoperability Assemblies 2005
"{2C8BF834-3C15-49B2-BE1F-5C24687BB2E1}" = Elcomsoft Cloud eXplorer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5ae11e9e-c192-4030-97b5-2f83e0edf570}" = Intel® Chipsatz-Gerätesoftware
"{5E0FBEB9-5570-45D2-B0F6-B8026FA68C83}_is1" = BMW Coding Database version 1.3.4
"{718613F4-492D-4272-ACC3-D04A8EF0F883}" = Kaspersky Total Security
"{74d0e5db-b326-4dae-a6b2-445b9de1836e}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
"{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"{7514E4C1-759B-4DCA-AE70-796DD2B6D562}" = Intel Processor Win7 IO Drivers 64Bit
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 8.4.1
"{8261393E-04BD-4553-9F77-295A85C4BA7E}" = Elcomsoft Phone Viewer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026
"{AC76BA86-0804-1033-1959-001824272646}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1031-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Deutsch
"{B6BE0229-3BD8-4C19-8F92-99C44CB598F5}" = Elcomsoft eXplorer for WhatsApp
"{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{CF9041ED-60C9-36ED-9DB9-F55AAD993865}" = Visual C++ 9.0 ATL (x86) WinSXS MSM
"{E7382773-CBE8-33A9-862E-C2337CD0F359}" = Visual C++ 9.0 ATL (x86) WinSXS MSM
"{E8F86DA8-B8E4-42C7-AFD4-EBB692AC43FD}_is1" = dr.fone (Version 9.6.0)
"{F10AA188-7166-430E-8810-FEAB2AD73DE3}" = Kaspersky Secure Connection
"{FDC67F80-45B6-45F9-9379-9972516A3713}" = Elcomsoft Phone Breaker
"HxD Hex Editor_is1" = HxD Hex Editor Version 1.7.7.0
"InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}" = Kaspersky Total Security
"InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}" = Kaspersky Secure Connection
"TunerPro RT_is1" = TunerPro RT v5.00
"TunerPro_is1" = TunerPro v5.00
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-8061801-39794175-114476390-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Backuptrans Android SMS Transfer (x64)" = Backuptrans Android SMS Transfer (x64) 2.14.32
"Backuptrans Android WhatsApp Transfer (x64)" = Backuptrans Android WhatsApp Transfer (x64) 3.2.108
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 17.09.2018 15:59:49 | Computer Name = Acer-PC | Source = Application Hang | ID = 1002
Description = Programm EXWAMain.exe, Version 2.42.28304.0 kann nicht mehr unter
Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in
der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen. Prozess-ID: ea0 Startzeit: 01d44ebc502cfb80 Endzeit: 265 Anwendungspfad:
C:\Program Files (x86)\Elcomsoft eXplorer for WhatsApp\Elcomsoft eXplorer for WhatsApp\EXWAMain.exe
Berichts-ID:
36e82d15-bab4-11e8-90cb-b4d42ba1e728
Error - 17.09.2018 20:30:45 | Computer Name = Acer-PC | Source = MsiInstaller | ID = 11316
Description =
Error - 17.09.2018 20:32:36 | Computer Name = Acer-PC | Source = MsiInstaller | ID = 11316
Description =
Error - 17.09.2018 20:34:00 | Computer Name = Acer-PC | Source = MsiInstaller | ID = 11316
Description =
Error - 17.09.2018 20:37:45 | Computer Name = Acer-PC | Source = MsiInstaller | ID = 11316
Description =
Error - 17.09.2018 21:06:55 | Computer Name = Acer-PC | Source = MsiInstaller | ID = 11316
Description =
Error - 18.09.2018 17:57:26 | Computer Name = Acer-PC | Source = Wininit | ID = 1015
Description = Ein kritischer Systemprozess C:\Windows\system32\lsass.exe ist fehlgeschlagen
mit den Statuscode 1. Der Computer muss neu gestartet werden.
Error - 18.09.2018 18:00:16 | Computer Name = Acer-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: edpr_server.exe, Version: 4.0.1178.0,
Zeitstempel: 0x5b6c3d32 Name des fehlerhaften Moduls: edpr_server.exe, Version:
4.0.1178.0, Zeitstempel: 0x5b6c3d32 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000c7b53
ID
des fehlerhaften Prozesses: 0x898 Startzeit der fehlerhaften Anwendung: 0x01d44f9ae3ef8fe2
Pfad
der fehlerhaften Anwendung: C:\Program Files (x86)\Elcomsoft eXplorer for WhatsApp\Distributed
Password Recovery\edpr_server.exe Pfad des fehlerhaften Moduls: C:\Program Files
(x86)\Elcomsoft eXplorer for WhatsApp\Distributed Password Recovery\edpr_server.exe
Berichtskennung:
3942ecbf-bb8e-11e8-962f-dcad6c54bd76
Error - 18.09.2018 18:29:04 | Computer Name = Acer-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.69.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 107c Startzeit:
01d44f9daeffb98c Endzeit: 0 Anwendungspfad: C:\Users\Acer\Desktop\OTL.exe Berichts-ID:
Error - 18.09.2018 18:33:21 | Computer Name = Acer-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: edpr_server.exe, Version: 4.0.1178.0,
Zeitstempel: 0x5b6c3d32 Name des fehlerhaften Moduls: edpr_server.exe, Version:
4.0.1178.0, Zeitstempel: 0x5b6c3d32 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000c7b53
ID
des fehlerhaften Prozesses: 0x171c Startzeit der fehlerhaften Anwendung: 0x01d44f9f87caba41
Pfad
der fehlerhaften Anwendung: C:\Program Files (x86)\Elcomsoft eXplorer for WhatsApp\Distributed
Password Recovery\edpr_server.exe Pfad des fehlerhaften Moduls: C:\Program Files
(x86)\Elcomsoft eXplorer for WhatsApp\Distributed Password Recovery\edpr_server.exe
Berichtskennung:
d8672e49-bb92-11e8-962f-dcad6c54bd76
[ System Events ]
Error - 18.09.2018 18:04:53 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 18.09.2018 18:04:54 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 18.09.2018 18:04:54 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 18.09.2018 18:17:18 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error - 18.09.2018 18:17:19 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error - 18.09.2018 18:17:19 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error - 18.09.2018 18:31:04 | Computer Name = Acer-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "Elcomsoft Update" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
Error - 18.09.2018 18:32:31 | Computer Name = Acer-PC | Source = DCOM | ID = 10010
Description =
Error - 18.09.2018 18:33:06 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error - 18.09.2018 18:33:08 | Computer Name = Acer-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
< End of report > GMer Code:
GMER 2.2.19882 - hxxp://www.gmer.net
Rootkit scan 2018-09-19 23:04:27
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK3259GSXP rev.GN003J 298,09GB
Running: gmer-2.2.19882.exe; Driver: C:\Users\Acer\AppData\Local\Temp\kxldrpob.sys
---- Threads - GMER 2.2 ----
Thread C:\Windows\System32\svchost.exe [1900:1980] 000007fef86a9688
---- EOF - GMER 2.2 ---- Kaspersky Total Security Code:
18.09.2018 01.51.48 Vollständige Untersuchung des Computers Die Aufgabe wurde abgeschlossen. Ende: Gestern, 18.09.2018 01:51
18.09.2018 01.28.32 Das Objekt (Datei) wurde nicht verarbeitet. C:\Windows\System32\drivers\etc\hosts.bak Datei: C:\Windows\System32\drivers\etc\hosts.bak Objektname: Trojan.Win32.Hosts2.gen Grund: Zurückgestellt
18.09.2018 01.28.32 Ein Objekt (Datei) wurde gefunden. C:\Windows\System32\drivers\etc\hosts.bak Datei: C:\Windows\System32\drivers\etc\hosts.bak Objektname: Trojan.Win32.Hosts2.gen
17.09.2018 23.01.23 Das Objekt (Datei) wurde nicht verarbeitet. C:\Users\Acer\Downloads\JDownloader1 Setup.zip//Install JDownloader 1.exe Datei: C:\Users\Acer\Downloads\JDownloader1 Setup.zip//Install JDownloader 1.exe Objektname: not-a-virus:Downloader.Win32.InstallMonster.xtd Grund: Zurückgestellt
17.09.2018 23.01.23 Ein Objekt (Datei) wurde gefunden. C:\Users\Acer\Downloads\JDownloader1 Setup.zip//Install JDownloader 1.exe Datei: C:\Users\Acer\Downloads\JDownloader1 Setup.zip//Install JDownloader 1.exe Objektname: not-a-virus:Downloader.Win32.InstallMonster.xtd
17.09.2018 22.01.26 Das Objekt (Datei) wurde nicht verarbeitet. C:\Users\Acer\Downloads\JDownloader1 Setup\Install JDownloader 1.exe Datei: C:\Users\Acer\Downloads\JDownloader1 Setup\Install JDownloader 1.exe Objektname: not-a-virus:Downloader.Win32.InstallMonster.xtd Grund: Zurückgestellt
17.09.2018 22.01.26 Ein Objekt (Datei) wurde gefunden. C:\Users\Acer\Downloads\JDownloader1 Setup\Install JDownloader 1.exe Datei: C:\Users\Acer\Downloads\JDownloader1 Setup\Install JDownloader 1.exe Objektname: not-a-virus:Downloader.Win32.InstallMonster.xtd
17.09.2018 21.45.39 Das Objekt (Datei) wurde nicht verarbeitet. C:\Users\Acer\Downloads\avenger.exe Datei: C:\Users\Acer\Downloads\avenger.exe Objektname: not-a-virus:RiskTool.Win32.Deleter.ag Grund: Zurückgestellt
17.09.2018 21.45.39 Ein Objekt (Datei) wurde gefunden. C:\Users\Acer\Downloads\avenger.exe Datei: C:\Users\Acer\Downloads\avenger.exe Objektname: not-a-virus:RiskTool.Win32.Deleter.ag
17.09.2018 20.59.21 Das Objekt (Datei) wurde nicht verarbeitet. C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx Datei: C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx Objektname: HEUR:Trojan.Script.Agent.gen Grund: Zurückgestellt
17.09.2018 20.59.18 Das Objekt (Datei) wurde nicht verarbeitet. C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx//addon.js Datei: C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx//addon.js Objektname: HEUR:Trojan.Script.Agent.gen Grund: Zurückgestellt
17.09.2018 20.59.17 Ein Objekt (Datei) wurde gefunden. C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx//addon.js Datei: C:\Users\Acer\Desktop\Desktop\BMW\BMW\mscomctlocxupdater.exe//Flagfox.crx//addon.js Objektname: HEUR:Trojan.Script.Agent.gen
17.09.2018 20.24.38 Vollständige Untersuchung des Computers Die Aufgabe wurde gestartet. Zeitpunkt: 17.09.2018 20:24 |