Google Drive Box wurde verschlüsselt - verdacht auf Kraken Cryptor Hallo,
leider sind mir gerade sehr komische Dateien auf meinem Google Drive aufgefallen.
In jedem Ordner ist eine .txt Datei angelegt worden die #HOW TO DECRYPT FILES#.txt heißt und folgendes beinhält: Code:
#HOW TO DECRYPT FILES#.txt
#HOW TO DECRYPT FILES#.txt
!!! ATTENTION, YOUR FILES WERE ENCRYPTED !!!
Please follow few steps below:
1.Send us your ID.
2.Then you'll get payment instruction and after payment you will get your decryption tool!
Only we can decrypt all your data!
Contact us us:
metan19@mail2tor.com
And tell us your unique ID
dtplubSPatdgJb44oXR5FB75cZd9j4GWFe0RPg9odGlgdQPdDtLpwvA9yu8K6vyvRNwvSFHZt94BagQYVbZUtV3XwtkOfsnZy8wQtu9mcQvpPc1ysEyFRCEA5X65kPy2kZi6FxkEszd1eWdk5+/Kyi/wljv/TYycI1OBbN+Xgq0qOu+2aG+82f9Tj5JlmQbyN/hrsn9SRLyl5idNVuAG7fe9QzzgV+BXNf8EsWDaRlBFOpwB0WYuesBKiwXgRcuuWXuq/MksG3phpTpXXriL0IRvEmrQY55Zkc0C/jvne1cDHfjAL4++ah3o8160NZTPDethhiYWZbYV3XrjsK12TWEMFwa0hyRtLGs4wGX33v1TX56lluD3oDpOy+8/xw8pnVTu7uD3Khp3EbprlL5nhTbNGr5ZNyo6Kcun9WZOcIx2Pu6a4xgn4k/NsXsifXZRTjVq7Ew8AU1Tgxv4CNVSTWP8ABZTsdCgaymeq+0X5snHpcqT+diO6SvjvajPoFA+HsKdgSfbC5YQS83LR395Vw839ZXC090vw+NDDCMjkG8yRBUPOvhLxtDusPv3v3LokuxJX/D7gkf3V7+Fpfm3CzjT1D0RGl4X+w9/GkdIFP5PkHXlZfE8vhZwRjhmFANmL54l+Nw1mHKd+Vmv1gG0UigerpxVeNeKh2hT22mqsnk=
Die Dateien auf der Google Drive sind mit der Endung .metan gekenzeichnet.
Die .txt Dateien und die unbennanten Dateien wurden angeblich mit meinem Google Drive Account erstellt. https://i.imgur.com/MWLU2ry.png
Zu der Uhrzeit war bei PC eigentlich ausgeschalten, zumindest bin ich der Meinung. Weiss es nicht mehr genau..
Ich habe auch die Anmeldungen bei Google überprüft. Nur mein Computer und mein Handy ist dort eingetragen, alles bekannt.
Ich nutze diesen Google Drive Account mit Google's Software "Drive File Stream". Ich habe einen weiteren Google Account, mit Gdrive. DIeser ist nicht betroffen. Mit dem nutze ich aber auch kein Drive File Stream.
Auch meine ganzen Hardware Partitionen auf Windows sind nicht betroffen.
Ich habe ein bisschen Angst, weil ich nicht genau weiss, wie es dazu kommen konnte.
Jemand eine Idee? Sollte ich meinen PC überprüfen? Oder kam der "Hack" von außerhalb?
Ich habe ein bisschen gegooglt und festgestellt, dass der Kraken Crypto solche .txt Dateien erstellt. Wie kann ich überprüfen, ob ich mir den eingefangen habe? Und müssten dann nicht alle Partitionen verschlüsselt sein?
Ich gehe eher davon aus, dass sich jemand zutritt zu meinem Google Account verschafft hat. Aber normalerweise müsste ich das ja in den Logs von Google sehen...
Gottseidank hat Google Drive eine Version History. Zumindest sind die Daten nicht weg. FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.03.2019 01
Ran by David (administrator) on DAVID-PC (11-03-2019 17:01:50)
Running from E:\Users\David\Desktop
Loaded Profiles: David (Available Profiles: David)
Platform: Windows 10 Pro Version 1803 17134.523 (X64) Language: Englisch (Vereinigte Staaten)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(CLEVO CO. -> CLEVO CO.) C:\Program Files (x86)\Hotkey\HotkeyService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Insyde Software Corp.) C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Adobe Systems Incorporated -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(OpenVPN Technologies, Inc. -> The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe
(HP Inc. -> ) C:\Windows\SysWOW64\spdsvc.exe
(Adobe Systems Incorporated -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Nitro Software, Inc. -> Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(HP Inc. -> ) C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Adobe Systems Incorporated -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation -> ) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\NisSrv.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Open Source Developer, Robin Krom -> Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\29.1.85.2056\GoogleDriveFS.exe
(Google LLC -> ) C:\Program Files\Google\Drive File Stream\29.1.85.2056\crashpad_handler.exe
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\29.1.85.2056\GoogleDriveFS.exe
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\29.1.85.2056\GoogleDriveFS.exe
(16 Software -> 16 Software (www.16software.com)) C:\Program Files (x86)\Breevy\Breevy.exe
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\29.1.85.2056\GoogleDriveFS.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(CLEVO CO.) [File not signed] C:\Program Files (x86)\Hotkey\HkeyTray.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(ROCCAT GmbH -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe
(ROCCAT GmbH) [File not signed] C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe
(CLEVO CO. -> CLEVO CO.) C:\Program Files (x86)\Hotkey\hotkeyrtk.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\QtWebEngineProcess.exe
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Cryptolayer -> ) C:\Program Files (x86)\VPN.AC Client\vpnac.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\OpenWith.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18114.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Screencast-O-Matic (Big Nerd Software, LLC) -> Screencast-O-Matic) C:\Program Files (x86)\Screencast-O-Matic\v2\Screencast-O-Matic.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1811.3241.0_x64__8wekyb3d8bbwe\Calculator.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteSubprocess.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteSubprocess.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteSubprocess.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Stefan Malzner -> Stefan Malzner) E:\Users\David\AppData\Local\Programs\franz\Franz.exe
(CLEVO CO. -> CLEVO CO.) C:\Program Files (x86)\Hotkey\hkysound.exe
(CLEVO CO. -> CLEVO CO.) C:\Program Files (x86)\Hotkey\ComboKeyTray.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft) C:\Program Files (x86)\Microsoft\Remote Desktop Connection Manager\RDCMan.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteSubprocess.exe
(Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteSubprocess.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Slack Technologies, Inc. -> Slack Technologies) E:\Users\David\AppData\Local\slack\app-3.3.7\slack.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Spotify AB -> Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe
(Dirac Research AB -> Dirac Research AB) C:\Program Files\XTZ\Dirac Audio Processor\Dirac Audio Processor.exe
(Dirac Research AB -> ) C:\Program Files\XTZ\Dirac Audio Processor\diracapsrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3951280 2016-01-07] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation - Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2015-10-07] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3255376 2018-05-06] (Open Source Developer, Dominik Reichl -> Dominik Reichl)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [4426560 2019-03-04] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2410968 2018-09-13] (Adobe Systems Incorporated -> Adobe Inc.)
HKLM-x32\...\Run: [RoccatKonePure] => C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE [561152 2014-01-20] (ROCCAT GmbH) [File not signed]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [Franz] => E:\Users\David\AppData\Local\Programs\franz\Franz.exe [93981064 2019-02-14] (Stefan Malzner -> Stefan Malzner)
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [com.squirrel.slack.slack] => E:\Users\David\AppData\Local\slack\Update.exe [1559056 2019-02-03] (Slack Technologies, Inc. -> )
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\29.1.85.2056\GoogleDriveFS.exe [33291560 2019-02-06] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3144480 2019-02-18] (Valve -> Valve Corporation)
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [Breevy] => C:\Program Files (x86)\Breevy\Breevy.exe [1170584 2016-10-13] (16 Software -> 16 Software (www.16software.com))
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [672384 2018-04-26] (OpenVPN Technologies, Inc. -> )
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53540200 2019-02-21] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\Run: [7 Taskbar Tweaker] => E:\Users\David\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [462336 2019-02-24] (RaMMicHaeL) [File not signed]
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\RunOnce: [Application Restart #0] => C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe [26154216 2019-02-01] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "E:\Users\David\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "E:\Users\David\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\RunOnce: [Uninstall 19.002.0107.0008\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "E:\Users\David\AppData\Local\Microsoft\OneDrive\19.002.0107.0008\amd64"
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\RunOnce: [Uninstall 19.002.0107.0008] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "E:\Users\David\AppData\Local\Microsoft\OneDrive\19.002.0107.0008"
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\MountPoints2: {45f14507-fd9a-11e8-bb50-b808cff39999} - "H:\OnePlus_setup.exe" /s
HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\...\MountPoints2: {9029f5b9-ffc7-11e8-bb51-b808cff39999} - "H:\SISetup.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe [2019-03-06] (Google LLC -> Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk [2018-05-09]
ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\HkeyTray.exe (CLEVO CO.) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ROCCAT Swarm Monitor.lnk [2019-02-15]
ShortcutTarget: ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe (ROCCAT GmbH -> ROCCAT)
Startup: E:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2018-05-10]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{1be550eb-ee9b-4c62-b2c1-aefef40f3bf1}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{56e7c80f-b70b-46e0-852b-f1a3cd07d12f}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{82ac9bc1-3364-4479-b758-259b2df4d378}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{8625c043-6363-417b-a8f2-a868ff24544f}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{d3e9791d-032c-40d9-8d97-060765d32f85}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2019-01-24] (Evernote Corporation -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2018-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2018-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2018-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2018-04-10] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: bcyzt6k5.default
FF ProfilePath: E:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\bcyzt6k5.default [2019-03-08]
FF Extension: (FoxyProxy Standard) - E:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\bcyzt6k5.default\Extensions\foxyproxy@eric.h.jung.xpi [2018-11-20]
FF Extension: (Nehmen Sie Screenshot der Webseite - FireShot) - E:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\bcyzt6k5.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}.xpi [2019-03-04]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-04-19] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-09-13] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc -> Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-09-13] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2455960667-3318087246-2055750665-1002: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2455960667-3318087246-2055750665-1002: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2455960667-3318087246-2055750665-1002: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-04-24] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2455960667-3318087246-2055750665-1002: @zoom.us/ZoomVideoPlugin -> E:\Users\David\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-08-20] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.delta-homes.com/?type=hp&ts=1426769397&from=wpm031932&uid=SamsungXSSDX840XEVOX250GB_S1DBNSCFA29580N
CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2019-03-11]
CHR Extension: (Redirect Path) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aomidfkchockcldhbkggjokdkkebmdll [2018-08-11]
CHR Extension: (ColorZilla) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2018-05-11]
CHR Extension: (Signal Private Messenger) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikioccmkafdpakkkcpdbppfkghcmihk [2018-11-23]
CHR Extension: (Nimbus Screenshot & Screen Video Recorder) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2019-01-31]
CHR Extension: (uBlock Origin) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-02-18]
CHR Extension: (ClickUP) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmhdadegpnihkfmpgcpilhkbnamifnld [2018-07-09]
CHR Extension: (Tampermonkey) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2019-02-22]
CHR Extension: (Facebook Pixel Helper) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2019-02-18]
CHR Extension: (EditThisCookie) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2018-11-30]
CHR Extension: (Cr!Box) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjodchcocbnbhfkjeapbdoflbiibnapp [2018-05-11]
CHR Extension: (LastPass: Free Password Manager) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2019-03-05]
CHR Extension: (Auto Refresh) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifooldnmmcmlbdennkpdnlnbgbmfalko [2019-03-11]
CHR Extension: (Todobook) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihbejplhkeifejcpijadinaicidddbde [2019-03-11]
CHR Extension: (Smile Always) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgpmhnmjbhgkhpbgelalfpplebgfjmbf [2018-05-11]
CHR Extension: (hxxps://trello.com/) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijnmpkkfkjaihbhffejemnpbbglahim [2018-05-11]
CHR Extension: (InstaG Downloader) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2018-07-12]
CHR Extension: (Tag Assistant (by Google)) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2018-11-23]
CHR Extension: (The Great Suspender) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2019-01-23]
CHR Extension: (Magic Enhancer für YouTube™) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2019-03-05]
CHR Extension: (Instapaper) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldjkgaaoikpmhmkelcgkgacicjfbofhh [2019-01-04]
CHR Extension: (Application Launcher for Drive (by Google)) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-02-22]
CHR Extension: (AntiGameReborn) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfbpacbhjchkjeopjfgdhckepclcfll [2019-03-09]
CHR Extension: (Chrome Web Store-Zahlungen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Airtable - Flexible database and organizer) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmnciefjclblnajjcmhobechdohojkbf [2018-05-11]
CHR Extension: (Wrike - Project Management) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\omoeimidjjkpidknllkcbfckmpgakpcj [2018-05-11]
CHR Extension: (Evernote Web Clipper) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2019-01-31]
CHR Extension: (Chrome Media Router) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-02-12]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-11-23]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-03-05]
CHR Extension: (LoginMonitor) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\abpapnfdogaihoalbjgkdedbaabdhbko [2018-07-12]
CHR Extension: (Clear Cache) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cppjkneekbjaeellbfkmgnhonkkjfpdn [2018-05-11]
CHR Extension: (Login) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ecjeobopgicfkbdcnfameemfakaedngc [2018-07-12]
CHR Extension: (Application Launcher for Drive (by Google)) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-02-27]
CHR Extension: (Chrome Web Store-Zahlungen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Chrome Media Router) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-02-27]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 2 [2019-01-07]
CHR Extension: (LastPass: Free Password Manager) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2019-01-06]
CHR Extension: (MetaMask) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2019-01-06]
CHR Extension: (Chrome Web Store-Zahlungen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Chrome Media Router) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-01-06]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-06-06]
CHR Extension: (Präsentationen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-24]
CHR Extension: (Docs) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-24]
CHR Extension: (Google Drive) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-24]
CHR Extension: (YouTube) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-24]
CHR Extension: (Tabellen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-24]
CHR Extension: (EditThisCookie) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2018-05-24]
CHR Extension: (Google Docs Offline) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-24]
CHR Extension: (Chrome Web Store-Zahlungen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-24]
CHR Extension: (Google Mail) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-24]
CHR Extension: (Chrome Media Router) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-24]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada [2018-05-11] <==== ATTENTION
CHR Extension: (Präsentationen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-11]
CHR Extension: (Docs) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-11]
CHR Extension: (Google Drive) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-11]
CHR Extension: (YouTube) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-11]
CHR Extension: (Tabellen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-11]
CHR Extension: (Google Docs Offline) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-11]
CHR Extension: (LastPass: Free Password Manager) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-05-11]
CHR Extension: (MetaMask) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2018-05-11]
CHR Extension: (Chrome Web Store-Zahlungen) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Google Mail) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-11]
CHR Extension: (Chrome Media Router) - E:\Users\David\AppData\Local\Google\Chrome\User Data\Profile 3asdsada\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-11]
CHR Profile: E:\Users\David\AppData\Local\Google\Chrome\User Data\System Profile [2018-11-30]
CHR HKU\S-1-5-21-2455960667-3318087246-2055750665-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818136 2018-09-13] (Adobe Systems Incorporated -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-11] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-11] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2019-03-04] (Dropbox, Inc -> Dropbox, Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [707144 2019-01-05] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7172680 2019-01-05] (GOG Sp. z o.o. -> GOG.com)
R2 HKClipSvc; C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe [254960 2015-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Insyde Software Corp.)
R2 HPSIService; C:\Windows\system32\HPSIsvc.exe [126880 2012-09-27] (Hewlett-Packard Company -> HP)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation - Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\Windows\system32\ibtsiva.exe [541800 2018-09-26] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [353768 2018-05-03] (Intel Corporation -> Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-08-03] (Intel Corporation -> )
R2 nlsX86cc; C:\Windows\SysWOW64\NLSSRV32.EXE [70752 2018-06-08] (Nitro Software, Inc. -> Nalpeiron Ltd.)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [24192 2018-03-06] (OpenVPN Technologies, Inc. -> )
R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [75392 2018-04-26] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [75392 2018-04-26] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\HotkeyService.exe [34264 2015-07-23] (CLEVO CO. -> CLEVO CO.)
R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [493088 2019-01-29] (HP Inc. -> )
R2 SamsungUPDUtilSvc; C:\Windows\SysWOW64\SecUPDUtilSvc.exe [145952 2019-01-29] (HP Inc. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246448 2016-01-07] (Synaptics Incorporated -> Synaptics Incorporated)
S3 wampapache64; c:\wamp64\bin\apache\apache2.4.35\bin\httpd.exe [29696 2018-09-19] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp64\bin\mysql\mysql5.7.23\bin\mysqld.exe [39626752 2018-06-08] () [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\NisSrv.exe [4098064 2019-02-23] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MsMpEng.exe [113992 2019-02-23] (Microsoft Corporation -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4060256 2018-08-03] (Intel Corporation -> Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AirplaneModeHid; C:\Windows\system32\DRIVERS\AirplaneModeHid.sys [37832 2017-07-03] (Insyde Software Corp. -> Insyde Corporation)
R3 DiracResearchProcessor_WDM; C:\Windows\system32\DRIVERS\diracap.sys [46728 2017-06-21] (Dirac Research AB -> Dirac Research AB)
R1 googledrivefs2622; C:\Windows\System32\DRIVERS\googledrivefs2622.sys [122920 2018-12-17] (Google LLC -> Google, Inc.)
R3 HKKbdFltr; C:\Windows\system32\DRIVERS\HKKbdFltr.sys [50392 2015-05-27] (Insyde Software Corp. -> Insyde Software Corp.)
R3 HKMouFltr; C:\Windows\system32\DRIVERS\HKMouFltr.sys [48856 2015-05-27] (Insyde Software Corp. -> Insyde Software Corp.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [143288 2018-09-26] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
S3 Netwtw04; C:\Windows\System32\drivers\Netwtw04.sys [7689728 2018-04-12] (Microsoft Windows -> Intel Corporation)
R3 Netwtw06; C:\Windows\System32\drivers\Netwtw06.sys [8815128 2018-08-02] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvcvi.inf_amd64_56e97d93d760592a\nvlddmkm.sys [17168744 2018-05-08] (NVIDIA Corporation -> NVIDIA Corporation)
S3 qcusbnet; C:\Windows\System32\drivers\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2018-04-12] (Microsoft Windows -> Realtek )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [751632 2018-05-09] (Microsoft Windows Hardware Compatibility Publisher -> Realsil Semiconductor Corporation)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42664 2016-01-07] (Synaptics Incorporated -> Synaptics Incorporated)
R1 SvThANSP; C:\Program Files (x86)\Hotkey\SvThANSP.sys [15224 2013-10-11] (Savitech Corp. -> Windows (R) Win 7 DDK provider)
R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 tapnordvpn; C:\Windows\System32\drivers\tapnordvpn.sys [44896 2018-06-13] (TEFINCOM S.A. -> The OpenVPN Project)
S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [22016 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
R1 veracrypt; C:\Windows\System32\drivers\veracrypt.sys [828688 2018-05-10] (IDRIX -> IDRIX)
R1 vmkbd3; C:\Windows\system32\DRIVERS\vmkbd.sys [52288 2018-01-08] (VMware, Inc. -> VMware, Inc.)
R0 VMSNPXY; C:\Windows\System32\drivers\VmsProxyHNic.sys [36768 2018-06-06] (Microsoft Windows -> Microsoft Corporation)
R0 vsock; C:\Windows\system32\DRIVERS\vsock.sys [91712 2016-09-30] (VMware, Inc. -> VMware, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [46472 2019-02-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [333792 2019-02-23] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [62432 2019-02-23] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-11 17:01 - 2019-03-11 17:02 - 000049330 _____ E:\Users\David\Desktop\FRST.txt
2019-03-11 17:01 - 2019-03-11 17:01 - 002434560 _____ (Farbar) E:\Users\David\Desktop\FRST64.exe
2019-03-11 17:01 - 2019-03-11 17:01 - 000000000 ____D C:\FRST
2019-03-11 15:52 - 2019-03-11 15:52 - 000029017 _____ E:\Users\David\Downloads\2018-06-12--2019-03-04_Invoice_Summary.pdf.metan (1).pdf
2019-03-11 15:52 - 2019-03-11 15:52 - 000028965 _____ E:\Users\David\Downloads\2018-06-12--2019-03-04_Invoice_Summary.pdf.metan.pdf
2019-03-09 19:34 - 2019-03-09 19:34 - 000002365 _____ E:\Users\Public\Desktop\Evernote.lnk
2019-03-09 19:34 - 2019-03-09 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2019-03-09 16:45 - 2019-03-09 16:45 - 000002388 _____ E:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-09 13:20 - 2019-03-09 13:20 - 000369648 _____ E:\Users\David\Downloads\Aufenthaltsticket-276283544.pdf
2019-03-08 22:58 - 2019-03-08 23:02 - 1996488704 _____ E:\Users\David\Downloads\ubuntu-18.04.2-desktop-amd64.iso
2019-03-08 20:01 - 2019-03-08 20:01 - 000042323 _____ E:\Users\David\Downloads\Rechnung_R-00161_element_one_GmbH_2019-03-08.pdf
2019-03-08 20:01 - 2019-03-08 20:01 - 000042317 _____ E:\Users\David\Downloads\Rechnung_R-00162_element_one_GmbH_2019-03-08.pdf
2019-03-08 19:41 - 2019-03-08 19:41 - 007939824 _____ (Tim Kosse) E:\Users\David\Downloads\FileZilla_3.41.1_win64-setup.exe
2019-03-08 02:08 - 2019-03-08 02:09 - 000000000 ____D E:\Users\David\Desktop\fflux-move
2019-03-08 01:50 - 2019-03-08 21:08 - 000000815 _____ E:\Users\David\Desktop\news-clk.txt
2019-03-07 20:56 - 2019-03-07 20:56 - 000000000 ____D E:\Users\David\AppData\Roaming\HeidiSQL
2019-03-07 20:55 - 2019-03-08 02:21 - 000000000 ____D E:\Users\David\Desktop\heidi
2019-03-07 20:54 - 2019-03-07 20:54 - 011788236 _____ E:\Users\David\Downloads\HeidiSQL_10.1_64_Portable.zip
2019-03-07 09:47 - 2019-03-07 09:47 - 053726820 _____ E:\Users\David\Downloads\MullvadVPN-2019.1_amd64.deb
2019-03-06 23:29 - 2019-03-06 23:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2019-03-06 18:24 - 2019-03-06 18:24 - 000000000 ____D E:\Users\David\Desktop\b4b transactions
2019-03-06 17:39 - 2019-03-06 17:39 - 000070833 _____ E:\Users\David\Downloads\Umsaetze_KtoNr170334700_EUR_06-03-2019_1739.CSV
2019-03-06 17:11 - 2019-03-07 01:05 - 000111627 _____ E:\Users\David\Desktop\Company spend detail (2).csv
2019-03-06 16:59 - 2019-03-07 00:59 - 000016806 _____ E:\Users\David\Desktop\Company spend detail (1).csv
2019-03-06 15:23 - 2019-03-06 15:26 - 000000773 _____ E:\Users\David\Desktop\index.html
2019-03-06 12:35 - 2019-03-06 12:35 - 043565841 _____ E:\Users\David\Downloads\PVFacebookLeakRevisedEdition.pdf
2019-03-06 11:04 - 2019-03-06 11:04 - 000000000 ____D C:\HashiCorp
2019-03-06 10:49 - 2019-03-06 11:01 - 240357376 _____ E:\Users\David\Downloads\vagrant_2.2.4_x86_64.msi
2019-03-06 10:15 - 2019-03-06 10:17 - 016525553 _____ E:\Users\David\Downloads\statamic-2.11.9 (1).zip
2019-03-06 10:14 - 2019-03-06 10:18 - 000000000 ____D E:\Users\David\Documents\statamic
2019-03-05 17:55 - 2019-03-05 17:55 - 000000994 _____ E:\Users\Public\Desktop\Multilogin.lnk
2019-03-05 17:48 - 2019-03-05 17:51 - 115564304 _____ (Multilogin ) E:\Users\David\Downloads\multilogin-3.1.2-windows_x86_32_setup.exe
2019-03-05 09:42 - 2019-03-08 16:49 - 000001305 _____ E:\Users\David\Desktop\1.txt
2019-03-05 09:42 - 2019-03-05 09:42 - 000001699 _____ E:\Users\David\Desktop\2.txt
2019-03-05 09:27 - 2019-03-05 09:28 - 016525553 _____ E:\Users\David\Downloads\statamic-2.11.9.zip
2019-03-04 21:28 - 2019-03-04 21:29 - 874512384 _____ E:\Users\David\Downloads\ubuntu-18.04.2-live-server-amd64.iso
2019-03-04 20:35 - 2019-03-04 20:35 - 000011881 _____ E:\Users\David\Downloads\Koken_Installer.zip
2019-03-04 20:22 - 2019-03-04 20:23 - 035908163 _____ E:\Users\David\Downloads\hola.zip
2019-03-04 20:18 - 2019-03-04 20:18 - 001625025 _____ E:\Users\David\Downloads\perch_v3.1.4.zip
2019-03-04 20:15 - 2019-03-04 20:15 - 002499150 _____ E:\Users\David\Downloads\CouchCMS-2.1.zip
2019-03-04 20:11 - 2019-03-04 20:11 - 001332046 _____ E:\Users\David\Downloads\html5up-massively.zip
2019-03-04 18:15 - 2019-03-04 18:16 - 010233031 _____ E:\Users\David\Downloads\grav-admin-v1.5.8.zip
2019-03-04 14:18 - 2019-03-04 14:18 - 000001249 _____ E:\Users\Public\Desktop\Skype.lnk
2019-03-04 14:17 - 2019-03-04 14:17 - 000047800 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2019-03-04 14:17 - 2019-03-04 14:17 - 000047800 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2019-03-04 14:17 - 2019-03-04 14:17 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2019-03-04 11:32 - 2019-03-04 11:32 - 000031269 _____ E:\Users\David\Downloads\retour-for-kirby-master.zip
2019-03-04 10:52 - 2019-03-04 10:52 - 011294943 _____ E:\Users\David\Downloads\starterkit-master (4).zip
2019-03-04 00:20 - 2019-03-04 14:08 - 000000000 ____D E:\Users\David\Downloads\Invoices
2019-03-03 19:05 - 2019-03-03 19:05 - 002678518 _____ E:\Users\David\Downloads\keepassxc_2.3.4-1_amd64_stable_stretch.deb
2019-03-03 18:13 - 2019-03-03 18:13 - 003126386 _____ E:\Users\David\Downloads\macOS-master.zip
2019-03-03 17:30 - 2019-03-03 20:56 - 000000000 ____D E:\Users\David\Desktop\vm
2019-03-03 16:10 - 2019-03-08 20:04 - 000000000 ____D E:\Users\David\AppData\LocalLow\Mozilla
2019-03-03 16:09 - 2019-03-03 16:09 - 011294943 _____ E:\Users\David\Downloads\starterkit-master (3).zip
2019-03-03 16:08 - 2019-03-03 16:08 - 011294943 _____ E:\Users\David\Downloads\starterkit-master (2).zip
2019-03-03 16:07 - 2019-03-03 16:07 - 011294943 _____ E:\Users\David\Downloads\starterkit-master (1).zip
2019-03-02 17:36 - 2019-03-02 17:36 - 000019695 _____ E:\Users\David\Downloads\2019-02-01--2019-03-02_Invoice_Summary.pdf
2019-02-28 18:18 - 2019-02-28 18:24 - 2352574464 _____ E:\Users\David\Downloads\deepin-15.9-amd64.iso
2019-02-28 14:08 - 2019-02-28 17:04 - 000000000 ____D E:\Users\David\Desktop\Stepper
2019-02-28 10:15 - 2019-02-28 10:15 - 000130644 _____ E:\Users\David\Downloads\Emmarhee Contract 2019.pdf
2019-02-27 23:18 - 2019-02-27 23:18 - 000750054 _____ E:\Users\David\Downloads\ScoutGear.bmp
2019-02-27 21:46 - 2018-01-31 13:53 - 000000018 _____ E:\Users\David\Desktop\account_daten.txt
2019-02-27 21:36 - 2019-02-27 21:36 - 000000000 ____D E:\Users\David\AppData\Roaming\Celestial World
2019-02-27 21:33 - 2019-02-27 21:46 - 000000000 ____D E:\Users\David\Desktop\Celestial - World 2.0
2019-02-27 21:28 - 2019-02-27 21:32 - 1516089953 _____ E:\Users\David\Downloads\Celestial - World 2.0.rar
2019-02-27 09:52 - 2019-02-27 09:52 - 000389838 _____ E:\Users\David\Downloads\privacy_customer.pdf
2019-02-26 14:43 - 2019-02-26 14:43 - 008427214 _____ E:\Users\David\Downloads\DE06_Grabler_MANOVA.pdf
2019-02-26 14:33 - 2019-02-26 14:33 - 007954904 _____ (Tim Kosse) E:\Users\David\Downloads\FileZilla_3.40.0_win64-setup.exe
2019-02-26 12:14 - 2019-02-26 12:14 - 000116031 _____ E:\Users\David\Downloads\Audience Funnel Cheatsheet - FUNNEL AUDIENCES 2.pdf
2019-02-25 00:32 - 2019-03-06 18:58 - 000000585 _____ E:\Users\David\Desktop\clk-ueu--new.txt
2019-02-24 15:15 - 2019-02-24 15:15 - 123351951 _____ E:\Users\David\Downloads\7 Figure BPM System.rar
2019-02-23 10:43 - 2019-02-27 12:45 - 000000000 ____D E:\Users\David\Desktop\new-sb
2019-02-22 18:59 - 2019-02-22 19:23 - 000013064 _____ E:\Users\David\Desktop\pdf.pdf
2019-02-22 18:58 - 2019-02-22 18:58 - 000070144 _____ E:\Users\David\Downloads\Kuendigung_690456.msg
2019-02-22 17:02 - 2019-03-08 19:48 - 000000000 ____D E:\Users\David\Desktop\VPS
2019-02-22 11:24 - 2019-02-22 11:24 - 000121279 _____ E:\Users\David\Desktop\c332234a-e7d7-4f14-ad16-2fdfc2cc9cb8.jpeg
2019-02-21 17:36 - 2019-02-21 17:36 - 000000000 ____D E:\Users\David\AppData\Local\franz-updater
2019-02-19 13:30 - 2019-02-19 13:30 - 000103743 _____ E:\Users\David\Downloads\02_EN_02.2019.pdf
2019-02-19 13:30 - 2019-02-19 13:30 - 000103708 _____ E:\Users\David\Downloads\03_EN_02.2019.pdf
2019-02-19 13:30 - 2019-02-19 13:30 - 000103188 _____ E:\Users\David\Downloads\03_EN_02.2019 (1).pdf
2019-02-18 21:30 - 2019-02-18 21:30 - 000082768 _____ E:\Users\David\Downloads\pressemitteilung-deutsche-mittelstaendler-als-steuereintreiber-bei-google-und-co-100.pdf
2019-02-16 19:18 - 2019-02-16 19:18 - 002492333 _____ E:\Users\David\Downloads\thk2_m6.7z
2019-02-16 16:23 - 2019-02-16 16:23 - 009180985 _____ E:\Users\David\Downloads\proxmox_pfsense_port-redirect-2019-02-16_13.09.49.mp4
2019-02-16 16:06 - 2019-02-16 16:06 - 008941805 _____ E:\Users\David\Downloads\proxmox_pfsense_windows_ubuntu-2019-02-16_12.57.19.mp4
2019-02-16 16:03 - 2019-02-18 00:33 - 000001544 _____ E:\Users\David\Downloads\PROXMOX_pfSense_Windows_Ubuntu.txt
2019-02-15 20:34 - 2019-02-15 20:34 - 000003666 _____ C:\Windows\System32\Tasks\ROCCAT DEVICE SERVICE
2019-02-15 20:34 - 2019-02-15 20:34 - 000000000 ____D E:\Users\David\AppData\Roaming\ROCCAT
2019-02-15 20:23 - 2018-12-18 03:22 - 160226664 _____ (ROCCAT GmbH) E:\Users\David\Desktop\ROCCAT Swarm.exe
2019-02-15 20:18 - 2019-02-15 20:19 - 159372857 _____ E:\Users\David\Downloads\ROCCAT Swarm_v19333-v1-v2.zip
2019-02-14 20:37 - 2019-02-14 20:37 - 000000000 ____D C:\ProgramData\Mozilla
2019-02-13 15:13 - 2019-02-13 17:15 - 000000000 ____D E:\Users\David\Desktop\SoSo Agency
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-11 16:47 - 2018-10-30 12:48 - 000000000 ____D C:\Program Files (x86)\VPN.AC Client
2019-03-11 16:37 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-03-11 15:35 - 2018-05-09 13:49 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-03-11 09:48 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\AppReadiness
2019-03-09 21:48 - 2018-05-20 15:20 - 000000600 _____ E:\Users\David\AppData\Local\PUTTY.RND
2019-03-09 21:48 - 2018-05-10 19:44 - 000000000 ____D E:\Users\David\AppData\Roaming\FileZilla
2019-03-09 21:17 - 2019-01-08 17:56 - 000000000 ____D E:\Users\David\AppData\Roaming\Code
2019-03-09 21:17 - 2018-05-11 13:51 - 000000000 ____D E:\Users\David\AppData\Local\VMware
2019-03-09 20:57 - 2018-05-10 22:03 - 000000000 ____D C:\ProgramData\VMware
2019-03-09 19:37 - 2018-05-09 12:09 - 000000000 ____D E:\Users\David\AppData\Roaming\VMware
2019-03-09 16:45 - 2018-05-09 14:35 - 000003364 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2455960667-3318087246-2055750665-1002
2019-03-09 00:37 - 2018-05-11 13:44 - 000000000 ____D E:\Users\David\AppData\Local\Screencast-O-Matic-v2
2019-03-08 23:04 - 2018-05-11 08:58 - 000000000 ____D E:\Users\David\Documents\Virtual Machines
2019-03-08 19:52 - 2019-01-23 17:12 - 000000000 ____D E:\Users\David\AppData\Roaming\Postman
2019-03-08 16:57 - 2019-01-23 17:12 - 000000000 ____D E:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Postman
2019-03-08 16:57 - 2019-01-23 17:12 - 000000000 ____D E:\Users\David\AppData\Local\Postman
2019-03-08 16:56 - 2018-05-10 22:14 - 000000000 ____D E:\Users\David\AppData\Local\SquirrelTemp
2019-03-08 16:09 - 2019-01-08 17:56 - 000000000 ____D E:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2019-03-08 09:36 - 2018-05-13 10:02 - 000000000 ____D E:\Users\David\AppData\Local\JxBrowser
2019-03-08 09:09 - 2018-05-10 19:45 - 000000000 ____D E:\Users\David\AppData\Roaming\Franz
2019-03-07 23:52 - 2018-05-09 15:02 - 000000000 ____D E:\Users\David\AppData\Local\Mozilla
2019-03-07 23:27 - 2018-05-09 15:02 - 000000000 ____D E:\Users\David\AppData\Roaming\Mozilla
2019-03-07 19:51 - 2018-05-10 22:14 - 000000000 ____D E:\Users\David\AppData\Roaming\Slack
2019-03-07 17:23 - 2018-05-09 15:19 - 000744838 _____ C:\Windows\system32\perfh007.dat
2019-03-07 17:23 - 2018-05-09 15:19 - 000151326 _____ C:\Windows\system32\perfc007.dat
2019-03-07 17:23 - 2018-05-09 13:58 - 001730196 _____ C:\Windows\system32\PerfStringBackup.INI
2019-03-07 17:23 - 2018-04-12 00:36 - 000000000 ____D C:\Windows\INF
2019-03-07 17:20 - 2018-05-11 08:56 - 000000000 ___RD E:\Users\David\Dropbox
2019-03-07 17:19 - 2018-05-09 14:28 - 000000000 ____D C:\ProgramData\NVIDIA
2019-03-07 17:19 - 2018-05-09 14:19 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2019-03-07 17:19 - 2018-05-09 13:49 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-03-07 17:19 - 2018-04-11 22:04 - 000786432 _____ C:\Windows\system32\config\BBI
2019-03-07 17:18 - 2018-05-11 13:49 - 000000000 ____D E:\Users\David\AppData\Roaming\Breevy
2019-03-07 11:48 - 2018-05-11 09:03 - 000000000 ____D E:\Users\David\AppData\Roaming\Exodus
2019-03-06 23:39 - 2018-05-11 10:22 - 000000000 ____D E:\Users\David\AppData\Roaming\vlc
2019-03-06 23:29 - 2018-05-11 08:52 - 000000000 ____D C:\Program Files (x86)\Dropbox
2019-03-06 21:38 - 2018-05-11 09:02 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-06 18:58 - 2019-01-29 18:29 - 000000771 _____ E:\Users\David\Desktop\clk-us.txt
2019-03-05 19:02 - 2018-05-10 19:58 - 000000000 ____D E:\Users\David\AppData\Roaming\KeePass
2019-03-05 17:55 - 2018-05-13 10:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multilogin
2019-03-05 17:55 - 2018-05-13 10:01 - 000000000 ____D C:\Program Files (x86)\Multilogin
2019-03-05 16:19 - 2018-05-11 12:41 - 000000000 ____D E:\Users\David\AppData\Local\Adobe
2019-03-05 09:43 - 2018-05-11 10:24 - 000000000 ____D C:\Program Files (x86)\Steam
2019-03-05 09:43 - 2018-05-11 08:52 - 000000924 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2019-03-05 09:43 - 2018-05-11 08:52 - 000000920 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2019-03-05 09:43 - 2018-05-09 15:02 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-03-05 09:36 - 2018-05-10 16:47 - 000000000 ____D E:\Users\David\AppData\Local\CrashDumps
2019-03-05 09:29 - 2018-05-09 15:02 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-03-05 09:29 - 2018-05-09 15:02 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-03-04 14:18 - 2019-01-25 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-03-04 14:17 - 2018-07-13 03:01 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2019-03-03 17:26 - 2015-04-20 03:45 - 000000000 ____D E:\Users\David\Desktop\Archiv
2019-02-27 21:46 - 2018-01-10 14:05 - 000000000 ____D E:\Users\David\Desktop\Celestial World 2.0
2019-02-26 12:00 - 2019-01-28 15:41 - 000000000 ____D E:\Users\David\Desktop\processst
2019-02-26 10:27 - 2018-05-10 19:55 - 000000000 ____D E:\Users\David\AppData\Local\JDownloader 2.0
2019-02-25 20:52 - 2018-05-14 13:51 - 000001456 _____ E:\Users\David\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2019-02-23 10:02 - 2018-05-09 13:49 - 000000000 ____D C:\Windows\system32\Drivers\wd
2019-02-22 19:05 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\system32\FxsTmp
2019-02-19 14:40 - 2018-05-11 14:23 - 000000000 ____D E:\Users\David\AppData\Local\ElevatedDiagnostics
2019-02-18 09:49 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\LiveKernelReports
2019-02-18 00:33 - 2018-11-15 14:21 - 000000000 ____D E:\Users\David\AppData\Roaming\Basecamp 3
2019-02-15 20:33 - 2018-06-23 09:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT
2019-02-15 20:33 - 2018-06-23 09:22 - 000000000 ____D C:\Program Files (x86)\ROCCAT
2019-02-15 20:33 - 2018-05-09 14:42 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2019-02-15 20:25 - 2018-05-09 14:35 - 000000000 ____D C:\ProgramData\Package Cache
2019-02-14 19:55 - 2018-05-11 08:52 - 000003984 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2019-02-14 19:55 - 2018-05-11 08:52 - 000003752 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
==================== Files in the root of some directories =======
2019-01-31 15:28 - 2019-01-31 15:28 - 000000033 _____ () E:\Users\David\AppData\Roaming\AdobeWLCMCache.dat
2018-06-04 16:53 - 2018-11-27 13:18 - 000000600 _____ () E:\Users\David\AppData\Roaming\PUTTY.RND
2018-05-14 13:51 - 2019-02-25 20:52 - 000001456 _____ () E:\Users\David\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2018-10-23 11:19 - 2018-10-23 11:19 - 000000000 _____ () E:\Users\David\AppData\Local\oobelibMkey.log
2018-05-20 15:20 - 2019-03-09 21:48 - 000000600 _____ () E:\Users\David\AppData\Local\PUTTY.RND
Some files in TEMP:
====================
2018-12-16 13:15 - 2012-09-27 01:28 - 000608160 ____R (HP) E:\Users\David\AppData\Local\Temp\siinst.exe
2019-03-07 23:32 - 2019-03-07 23:32 - 000913408 ____N () E:\Users\David\AppData\Local\Temp\sqlite-3.23.1-4dd7995d-a3e6-4a70-ad46-223c7f7f33e6-sqlitejdbc.dll
2018-12-16 13:15 - 2012-09-26 06:57 - 000270336 ____R (HP) E:\Users\David\AppData\Local\Temp\strings.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-05-09 13:49
==================== End of FRST.txt ============================ --- --- --- |