Eigentlich habe ich ja darum gebeten das Thema bis heute offen zu lassen, da ich wie angekündigt bis gestern weg war deswegen hoffe ich auf eine Wiederaufnahme des Themas
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 02-06-2017
durchgeführt von Pascal (03-06-2017 09:28:42) Run:2
Gestartet von C:\Users\Pascal\Downloads
Geladene Profile: Pascal (Verfügbare Profile: Pascal)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
CloseProcesses:
Task: {A912C1A7-DEA3-4EE3-AEB0-6622D9890796} - \GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-1229423121-489186376-597309758-1001 -> Keine Datei <==== ACHTUNG
EmptyTemp:
*****************
Prozesse erfolgreich geschlossen.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A912C1A7-DEA3-4EE3-AEB0-6622D9890796} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A912C1A7-DEA3-4EE3-AEB0-6622D9890796} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-1229423121-489186376-597309758-1001 => Schlüssel erfolgreich entfernt
=========== EmptyTemp: ==========
BITS transfer queue => 7364608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19180235 B
Java, Flash, Steam htmlcache => 27853186 B
Windows/system/drivers => 21210028 B
Edge => 0 B
Chrome => 729968246 B
Firefox => 31530272 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 2420 B
NetworkService => 4300 B
Pascal => 4937927 B
RecycleBin => 0 B
EmptyTemp: => 803 MB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 09:28:48 ====
Code:
HitmanPro 3.7.20.286
www.hitmanpro.com
Computer name . . . . : PASCAL
Windows . . . . . . . : 10.0.0.15063.X64/4
User name . . . . . . : PASCAL\Pascal
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2017-06-03 09:33:37
Scan mode . . . . . . : Normal
Scan duration . . . . : 1m 50s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 13
Objects scanned . . . : 2.226.863
Files scanned . . . . : 73.553
Remnants scanned . . : 542.176 files / 1.611.134 keys
Malware _____________________________________________________________________
C:\Users\AMD\Packages\Apps\Radeon-Crimson-15.11-ccc-zh-chs64-64bit.exe
Size . . . . . . . : 260.600 bytes
Age . . . . . . . : 544.5 days (2015-12-06 22:04:30)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 229FCE050DF598451691B5EA3DA9BFA523DCBD94FB28E9D5116C73A6CBE9A5BE
Product . . . . . : Radeon Software Crimson Edition
Publisher . . . . : AMD Inc.
Description . . . : Radeon Software Crimson Edition
Version . . . . . : 0.0.0.0
Copyright . . . . : AMD Inc.
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> HitmanPro . . . . : Mal/Generic-S
Fuzzy . . . . . . : 104.0
Suspicious files ____________________________________________________________
C:\Users\Pascal\Downloads\FRST-OlderVersion\FRST64.exe
Size . . . . . . . : 2.429.952 bytes
Age . . . . . . . : 6.8 days (2017-05-27 14:12:18)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 2B4DE3E0A23A0E4A8C83875C0BA9A3FDC4B332D90777DC0D9624DB4876BCD630
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Users\Pascal\Downloads\FRST64.exe
Size . . . . . . . : 2.433.536 bytes
Age . . . . . . . : 0.0 days (2017-06-03 09:27:41)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 9E51FA16E351CB637E687A806F8F803BBABBFBD15977B3C7A418AF189D397266
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-32.5s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{03E0732F-F716-4B6E-812A-8C14CFC468A4}
-31.8s C:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\qh5dvH6z.default\xulstore.json
-31.8s C:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\qh5dvH6z.default\sessionCheckpoints.json
-31.5s C:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\qh5dvH6z.default\prefs.js
-31.5s C:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\qh5dvH6z.default\datareporting\archived\2017-06\
-31.5s C:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\qh5dvH6z.default\datareporting\archived\2017-06\1496474829936.965554e0-d087-4c6c-8b48-bfaa810e500c.main.jsonlz4
-3.6s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\77\
-2.5s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\77\F7131A43846CCF15.dat
-2.1s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{6742C018-7F6C-42D0-9B7E-A1E9D3F6506E}
0.0s C:\Users\Pascal\Downloads\FRST64.exe
1.7s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\6B9FB2B98D250EB745AFF143BAE13914
1.7s C:\Users\Pascal\Downloads\FRST-OlderVersion\
22.4s C:\Users\Pascal\AppData\Local\Packages\microsoft.windows.authhost.sso.c_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
22.4s C:\Users\Pascal\AppData\Local\Packages\microsoft.windows.authhost.sso.c_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
22.5s C:\Users\Pascal\AppData\Local\Packages\microsoft.windows.authhost.sso.c_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_FC2B1E54BF228194FDCCB7229F4C62AE
22.5s C:\Users\Pascal\AppData\Local\Packages\microsoft.windows.authhost.sso.c_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_FC2B1E54BF228194FDCCB7229F4C62AE
22.6s C:\Users\Pascal\AppData\Local\Packages\microsoft.windows.authhost.sso.c_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT
39.9s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\86\9191AAA0530D1E5A.dat
43.2s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\77\F7131A43846CCF15.dat
61.1s C:\FRST\Logs\ct
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_768.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1280.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1920.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_2560.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_wide.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_exif.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_wide_alternate.db
63.8s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\thumbcache_custom_stream.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_768.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_1280.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_1920.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_2560.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db
63.9s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db
67.9s C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\
67.9s C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
71.0s C:\FRST\Logs\Fixlog_03-06-2017 09.28.52.txt
71.4s C:\Users\Pascal\AppData\Local\IconCache.db
71.5s C:\Users\Pascal\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000004c.db
71.9s C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc\{8BB4D0A2-1632-453C-945A-D20F09F38F71}\Protectors\1\6.dat
71.9s C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc\{8BB4D0A2-1632-453C-945A-D20F09F38F71}\Protectors\1\16.dat
71.9s C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc\{8BB4D0A2-1632-453C-945A-D20F09F38F71}\Protectors\1\17.dat
71.9s C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc\{8BB4D0A2-1632-453C-945A-D20F09F38F71}\Protectors\1\11.dat
72.3s C:\ProgramData\Microsoft\Diagnosis\VortexSchemaRequests.dat
72.7s C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\counters2.dat
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\18\107002
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\18\107001
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\17\109001
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\18\109002
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\22\109003
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\02\109004
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\04\109005
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\22\109006
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\19\328
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\09\238
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\317
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\10\197
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\01\198
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\199
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\11\200
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\100013
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\08\15004
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\08\107003
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\06\107007
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\13\107009
72.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\20\107012
90.9s C:\ProgramData\Kaspersky Lab\AVP17.0.0\dummy.tmp
90.9s C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\dummy.tmp
91.8s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
91.9s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
96.2s C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
96.2s C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
97.6s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTWFP-IPsec Diagnostics.etl
98.0s C:\Windows\Temp\{7F927AB9-44F3-441A-A51F-87A5C0D0F02E} - OProcSessId.dat
98.1s C:\Windows\Temp\PASCAL-20170603-0929.log
98.1s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagtrack-Listener.etl
98.3s C:\Windows\Temp\officeclicktorun.exe_streamserver(20170603092919ED4).log
98.3s C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06032017-092919-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin
98.7s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\settings.kvdb-wal
98.7s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\settings.kvdb-shm
98.7s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\data.kvdb-wal
98.7s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\data.kvdb-shm
98.8s C:\Program Files (x86)\MSI\MSITrigger\VGA Boost\autogpuoc.ini
98.8s C:\ProgramData\Kaspersky Lab\AVP17.0.0\a1d1b6563e3f2e336502a383b2e393820326ba253f22661d22393e38659763e3f2e33
99.0s C:\Windows\System32\SleepStudy\ScreenOn\ScreenOnPowerStudyTraceSession-2017-06-03-09-29-20.etl
99.0s C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind.arw
100.3s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Report\Database\reports.db-wal
100.3s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Report\Database\reports.db-shm
100.3s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\Cache\intctrl_00000000.lck_00000002
100.5s C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-06032017-092921-00000003-ffffffff.bin
100.9s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDefenderAuditLogger.etl
102.4s C:\Users\Pascal\NTUSER.DAT{1d886739-2443-11e7-991c-acd3b2ed4b91}.TxR.blf
102.4s C:\Users\Pascal\NTUSER.DAT{1d886739-2443-11e7-991c-acd3b2ed4b91}.TxR.0.regtrans-ms
102.4s C:\Users\Pascal\NTUSER.DAT{1d886739-2443-11e7-991c-acd3b2ed4b91}.TxR.1.regtrans-ms
102.4s C:\Users\Pascal\NTUSER.DAT{1d886739-2443-11e7-991c-acd3b2ed4b91}.TxR.2.regtrans-ms
103.5s C:\Users\Pascal\AppData\Local\Microsoft\Windows\UPPS\UPPS.bin
106.9s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\persistent_q.db-wal
106.9s C:\Windows\Temp\etilqs_Wz1RYzx3Shxooct
106.9s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\persistent_q.db-shm
107.1s C:\Windows\Temp\etilqs_U0zTwXXA6xEjdBB
107.5s C:\Users\Pascal\AppData\Local\Microsoft\Windows\INetCache\counters2.dat
108.2s C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\
109.4s C:\Windows\Temp\cpuz140\
109.4s C:\Windows\Temp\cpuz140\cpuz140_x64.sys
112.1s C:\Users\Pascal\AppData\Local\Comms\UnistoreDB\tmp.edb
112.6s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\10\1968DF1EDF47BEC2.dat
112.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\EB5F5A0D383677DBE90E6BC406F564BC
112.8s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0AA53920C5D1A6A05C080146314E3B26
112.8s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0AA53920C5D1A6A05C080146314E3B26
112.9s C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0AA53920C5D1A6A05C080146314E3B26
112.9s C:\ProgramData\Kaspersky Lab\AVP17.0.0\1617791a2223322f791c3624273225243c2e771639233e7a13e252224791021e1a2223322f1
113.6s C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\
114.1s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache131409485733937181.txt
114.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicGenre_02.0407.digest.bin
114.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicAlbum_02.0407.digest.bin
114.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicSong_02.0407.digest.bin
114.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicGenre_02.0407.cfg.txt
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\Apps.index
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicGenre_02.0407.cfg
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\0.0.filtertrie.intermediate.txt
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\0.1.filtertrie.intermediate.txt
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\0.2.filtertrie.intermediate.txt
114.3s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{d4070f64-8b94-411f-922a-652a2682f373}\Apps.ft
114.4s C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5f7b5f1e01b83767.automaticDestinations-ms
114.4s C:\Users\Pascal\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\
114.4s C:\Users\Pascal\AppData\Local\Microsoft\Windows\INetCache\IE\
114.5s C:\Users\Pascal\AppData\Local\Microsoft\Windows\History\History.IE5\container.dat
115.1s C:\Users\Pascal\AppData\Local\Microsoft\Windows\INetCache\IE\container.dat
115.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{082E0C7C-0CE1-4595-907B-DDE089A58064}
117.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\27B5508F9886AF565659AB8474A585F5
118.5s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicAlbum_02.0407.cfg.txt
118.5s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicAlbum_02.0407.cfg
119.5s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicSong_02.0407.cfg.txt
119.6s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\MusicSong_02.0407.cfg
119.6s C:\Users\Pascal\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\LocalState\TileThumbnails\primarytileimage_0.jpg
120.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\74\7C1D332ECBA25CA2.dat
121.1s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0407.digest.bin
123.1s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\02487C042C983299AFCECCD06C10C8FE
123.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0407.cfg.txt
123.7s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0407.cfg
125.4s C:\Users\Pascal\AppData\Local\Temp\jusched.log
126.6s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0407.digest.bin
127.0s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0407.cfg.txt
127.0s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0407.cfg
127.7s C:\Users\Pascal\AppData\Local\Temp\qtsingleapp-roccat-b578-1-lockfile
128.3s C:\Users\Pascal\Documents\ROCCAT\Swarm\setting\monitor.ini
128.3s C:\Users\Pascal\Documents\ROCCAT\Swarm\setting\Swarm
129.7s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\
129.7s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Age of Conan.dat
129.7s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Anno 2070.dat
129.7s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Battlefield 3.dat
129.7s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Battlefield 4.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Batman Arkham City.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Battle for Middle Earth.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Battlefield Bad Company 2.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Bioshock 2.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Borderlands 2.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\C&C 3.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Civilization 5.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Counter Strike 1.6.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Counter-Strike Global Offensive.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Counter Strike Source.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Crysis Crysis Warhead.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Dota 2.dat
129.8s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Dragon Age.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Elder Scrolls V Skyrim.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Football Manager 2013(EA).dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Football Manager 2013(SEGA).dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Guild Wars.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\League of Legends.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Left4Dead.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Lineage 2.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\LotR Online.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Mass Effect 2.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Minecraft.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Modern Warfare 2.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Neverwinter.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Path of Exile.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Sacred 2.dat
129.9s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Sims 3.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\StarCraft 2.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Star Wars The Old Republic.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Team Fortress 2.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Warhammer Online.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\War Thunder.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\World of Tanks.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\World of Warcraft.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\World of Warplanes.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Firefox.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Internet Explorer.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Office Functions.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Photoshop.dat
130.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Safari.dat
130.1s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Skype.dat
130.1s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Team Speak 2.dat
130.1s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Team Speak 3.dat
130.1s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Windows Functions.dat
130.1s C:\Users\Pascal\Documents\ROCCAT\Swarm\preset_macro\Xfire.dat
130.9s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\61\8E2A40B668B94161.dat
131.0s C:\Users\Pascal\Documents\ROCCAT\Swarm\faq\Swarm\english.ini
131.1s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\antimalware.patch_management.product_registry.kvdb-wal
131.1s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\antimalware.patch_management.product_registry.kvdb-shm
131.1s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\antimalware.unwanted_products.product_registry.kvdb-wal
131.1s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Data\antimalware.unwanted_products.product_registry.kvdb-shm
131.2s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Report\traffic_stats.db-wal
131.2s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Report\traffic_stats.db-shm
132.5s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\92\7EDA96F523C29F50.dat
133.1s C:\Windows\Temp\MSIb045.LOG
133.1s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\Cache\kavbase_000000a6.lck_00000047
133.3s C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys
133.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\99\50054FF4CAB6A5BB.dat
133.4s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{16D2007E-5E49-441E-B020-A70BEC77D1F1}
134.6s C:\Users\Pascal\Documents\ROCCAT\Swarm\setting\APP_Clients
135.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\E4B8BBA2005DE7AEB31181B75DF2A795
136.7s C:\Windows\Temp\{A4E7CFD7-DDD1-4A0A-BBD8-702F0D6AD62E}\
136.7s C:\Windows\Temp\{A4E7CFD7-DDD1-4A0A-BBD8-702F0D6AD62E}\msi_misc.dll
137.4s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\48BFA6128DB09A3A6796B777D4D09E87
137.5s C:\Windows\Temp\{A4E7CFD7-DDD1-4A0A-BBD8-702F0D6AD62E}\msi_common.dll
137.6s C:\Windows\Temp\{A4E7CFD7-DDD1-4A0A-BBD8-702F0D6AD62E}\product_info.dll
138.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\History
138.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
138.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\History-journal
138.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
139.2s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
139.2s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Visited Links
139.2s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG
139.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\31\FB70187285595B7F.dat
139.6s C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\1d9f7f6a83e3e8c79854cd63d4c4ee05af6eb299
139.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index
139.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0
139.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
139.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_2
139.7s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_3
139.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
140.0s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
140.1s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal
140.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
140.9s C:\Windows\System32\catroot2\edb.log
140.9s C:\Windows\System32\catroot2\edbtmp.log
140.9s C:\Windows\System32\catroot2\edbres00001.jrs
140.9s C:\Windows\System32\catroot2\edbres00002.jrs
140.9s C:\Windows\System32\catroot2\edb.chk
141.1s C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\klelam.cat
141.2s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Current Session
142.0s C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRT{1C1EC973-62BC-4CE2-8374-98C3F294B479}.etl
142.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\index
142.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
142.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
142.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
142.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
142.5s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cookies
142.5s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
143.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001
143.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002
143.4s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000003
143.5s C:\Users\Pascal\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
143.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004
143.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000005
143.8s C:\Windows\Temp\obuDA26.tmp
144.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000006
144.3s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000007
144.5s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000008
144.5s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000009
144.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000a
144.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000b
144.6s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000c
145.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOG
146.6s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_02.0407.digest.bin
146.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000e
146.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000f
146.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000010
147.1s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_02.0407.cfg.txt
147.1s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_02.0407.cfg
147.2s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000011
156.0s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\63\1E991D057216C553.dat
156.3s C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\2b450c65c4420925a316a9186a6caa630f3febcc
156.3s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F998893A-5DD9-4FAF-A839-1BC5B5BA48B2}
157.2s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_02.0407.digest.bin
157.9s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_02.0407.cfg.txt
158.1s C:\Users\Pascal\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_02.0407.cfg
158.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trojaner-board.de_0.localstorage
158.9s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trojaner-board.de_0.localstorage-journal
160.0s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage
160.0s C:\Users\Pascal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage-journal
C:\WINDOWS\SysWOW64\GameMon.des
Size . . . . . . . : 3.916.368 bytes
Age . . . . . . . : 495.9 days (2016-01-24 12:40:55)
Entropy . . . . . : 8.0
SHA-256 . . . . . : C2FA0CBBF038F74F8A30F86E289C09D488A36285BF6BBD45CD44C855F6696B1B
Product . . . . . : nProtect Game Monitor
Publisher . . . . : INCA Internet Co., Ltd.
Description . . . : nProtect Game Monitor Rev 2368
Version . . . . . : 2016.1.10.1
RSA Key Size . . . : 2048
Service . . . . . : npggsvc
LanguageID . . . . : 1042
Authenticode . . . : Valid
Fuzzy . . . . . . : 25.0
The file name extension of this program is not common.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Starts automatically as a service during system bootup.
Program is code signed with a valid Authenticode certificate.
Startup
HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
L:\Programme\bass.dll
Size . . . . . . . : 110.207 bytes
Age . . . . . . . : 81.6 days (2017-03-13 19:48:39)
Entropy . . . . . : 7.9
SHA-256 . . . . . : A8D979460E970E84EACCE36B8A68AE5F6B9CC0FE16E05A6209B4EAD52B81B021
Fuzzy . . . . . . : 22.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\f\ (Funmoods)
HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}\ (ReimageRepair)
HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}\ (ReimageRepair)
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}\ (SaleCharger)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}\ (SaleCharger)
HKU\S-1-5-21-1229423121-489186376-597309758-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}\ (SaleCharger)
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=9ceabbcaa6e28240be4fd63a54640feb
# end=init
# utc_time=2017-06-03 07:37:30
# local_time=2017-06-03 09:37:30 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 33599
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=9ceabbcaa6e28240be4fd63a54640feb
# end=updated
# utc_time=2017-06-03 07:40:46
# local_time=2017-06-03 09:40:46 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=9ceabbcaa6e28240be4fd63a54640feb
# engine=33599
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-06-03 09:18:20
# local_time=2017-06-03 11:18:20 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1313 16777213 100 100 6441 29412034 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 43496 6614496 0 0
# scanned=345350
# found=0
# cleaned=0
# scan_time=5854