Den hab ich dann noch: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.01.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Fetzla :: FETZLA-PC [Administrator]
Schutz: Aktiviert
02.09.2013 00:30:56
mbam-log-2013-09-02 (00-30-56).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 217423
Laufzeit: 17 Minute(n), 4 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) [CODE
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-09-2013 04
Ran by Fetzla (administrator) on FETZLA-PC on 02-09-2013 17:06:38
Running from C:\Users\Fetzla\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\adminservice.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Insyde Software Corp.) C:\Program Files\Acer\Android Manager\iSync.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Insyde Software Corp.) C:\Program Files\Acer\Updater\iUpdate.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-08-03] (Realtek Semiconductor)
HKLM\...\Run: [SuiteTray] - C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] - C:\Program Files\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] - C:\Program Files\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] - C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files\Bluetooth Suite\BtvStack.exe [470176 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] - C:\Program Files\Bluetooth Suite\AthBtTray.exe [289952 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe [407416 2010-01-08] (Insyde Software Corp.)
HKLM\...\Run: [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe [508280 2010-01-08] ()
HKLM\...\Run: [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe [489848 2010-11-30] (Insyde Software Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [AgentMonitor] - C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [377800 2012-11-05] ()
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [439360 2013-08-13] (BillP Studios)
HKCU\...\Policies\Explorer: [NoDrives] 0
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MWLService; C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1532280 2012-08-23] (AVG)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
==================== Drivers (Whitelisted) ====================
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-05-20] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-05-20] (Windows (R) Win 7 DDK provider)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [256360 2010-05-20] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28200 2010-05-20] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [177704 2010-05-20] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [46952 2010-05-20] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143080 2010-05-20] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [230760 2010-05-25] (Atheros)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-17] (ENE Technology Inc.)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-03] (Egis Technology Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [10088 2012-07-04] (TuneUp Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Fetzla\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:05 - 2013-09-02 17:06 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 16:54 - 2013-09-02 16:56 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 01:44 - 2013-09-02 01:42 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:44 - 2013-09-02 01:42 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:32 - 2013-09-02 17:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 01:32 - 2013-09-02 01:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:16 - 2013-09-02 01:17 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:04 - 2013-09-02 01:05 - 00001151 _____ C:\DelFix.txt
2013-09-01 20:00 - 2013-09-02 01:04 - 00000000 ____D C:\Windows\ERUNT
2013-09-01 19:42 - 2013-09-01 19:50 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 19:01 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-01 18:42 - 2013-09-02 01:47 - 00022260 _____ C:\Windows\PFRO.log
2013-09-01 17:50 - 2013-09-02 00:59 - 00000000 ____D C:\Windows\erdnt
2013-09-01 17:16 - 2013-09-02 12:15 - 00000448 _____ C:\Windows\setupact.log
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:17 - 2012-08-23 11:31 - 00032120 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-09-01 12:17 - 2012-08-23 11:31 - 00021880 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:14 - 2013-09-01 12:18 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-01 12:07 - 2013-09-01 12:13 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-09-01 12:07 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:27 - 2013-08-23 21:28 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2013-09-01 12:15 - 00000000 ____D C:\Program Files\AVG
2013-08-23 21:18 - 2013-09-02 13:56 - 00000000 ____D C:\ProgramData\MFAData
2013-08-23 21:18 - 2013-08-23 21:43 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:22 - 2013-08-23 18:27 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 17:52 - 2013-08-23 18:07 - 00000000 ____D C:\Windows\system32\MRT
2013-08-19 17:09 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-05 19:39 - 2013-09-01 12:35 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-08-03 21:26 - 2013-09-01 18:37 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-08-03 21:13 - 2013-09-01 17:16 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-08-03 21:13 - 2013-09-01 17:16 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
==================== One Month Modified Files and Folders =======
2013-09-02 17:07 - 2013-09-02 17:07 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-09-02 17:07 - 2013-09-02 01:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:06 - 2013-09-02 17:05 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 17:01 - 2011-03-22 13:46 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-02 16:56 - 2013-09-02 16:54 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:56 - 2010-12-04 15:05 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:54 - 2010-12-04 14:32 - 00000000 ____D C:\Users\Fetzla
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 16:36 - 2010-09-23 12:04 - 00000043 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2013-09-02 16:31 - 2010-09-23 11:20 - 01798813 _____ C:\Windows\WindowsUpdate.log
2013-09-02 13:56 - 2013-08-23 21:18 - 00000000 ____D C:\ProgramData\MFAData
2013-09-02 12:56 - 2010-12-04 15:05 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:19 - 2011-05-02 09:16 - 00000000 ____D C:\Users\Fetzla\AppData\Local\CrashDumps
2013-09-02 12:17 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-02 12:15 - 2013-09-01 17:16 - 00000448 _____ C:\Windows\setupact.log
2013-09-02 01:47 - 2013-09-01 18:42 - 00022260 _____ C:\Windows\PFRO.log
2013-09-02 01:42 - 2013-09-02 01:44 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:42 - 2013-09-02 01:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:42 - 2011-05-05 21:11 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-02 01:42 - 2011-05-05 21:10 - 00000000 ____D C:\Program Files\Java
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:33 - 2013-09-02 01:32 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:33 - 2011-07-04 09:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:30 - 2011-10-19 21:35 - 00000000 ____D C:\Windows\system32\Adobe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:17 - 2013-09-02 01:16 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:05 - 2013-09-02 01:04 - 00001151 _____ C:\DelFix.txt
2013-09-02 01:04 - 2013-09-01 20:00 - 00000000 ____D C:\Windows\ERUNT
2013-09-02 00:59 - 2013-09-01 17:50 - 00000000 ____D C:\Windows\erdnt
2013-09-01 19:50 - 2013-09-01 19:42 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:50 - 2010-12-15 23:12 - 00000000 ____D C:\ProgramData\ICQ
2013-09-01 19:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-09-01 18:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-09-01 18:40 - 2009-07-14 04:03 - 45088768 _____ C:\Windows\system32\config\software.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 17301504 _____ C:\Windows\system32\config\system.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 01048576 _____ C:\Windows\system32\config\default.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-09-01 18:37 - 2013-08-03 21:26 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-09-01 17:57 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-01 17:38 - 2011-06-28 22:11 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Windows Live
2013-09-01 17:16 - 2013-08-03 21:13 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-09-01 17:16 - 2013-08-03 21:13 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
2013-09-01 12:35 - 2013-08-05 19:39 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-09-01 12:28 - 2011-06-17 18:02 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-01 12:18 - 2013-09-01 12:14 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:15 - 2013-08-23 21:25 - 00000000 ____D C:\Program Files\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-09-01 12:07 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-24 22:17 - 2010-08-31 17:35 - 00000000 ____D C:\Program Files\Google
2013-08-23 21:43 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:36 - 2010-08-31 17:21 - 00000000 ____D C:\Program Files\Acer GameZone
2013-08-23 21:34 - 2012-05-30 13:19 - 00000000 ____D C:\Users\Fetzla\Desktop\Neuer Ordner
2013-08-23 21:31 - 2013-08-02 20:45 - 00000000 __SHD C:\Users\Fetzla\Documents\MSDCSC
2013-08-23 21:30 - 2010-08-31 17:33 - 00000000 ____D C:\Program Files\Acer
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:28 - 2013-08-23 21:27 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2010-12-04 14:35 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Google
2013-08-23 21:25 - 2010-08-31 17:35 - 00000000 ____D C:\ProgramData\Google
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:06 - 2010-09-23 11:58 - 00000000 ____D C:\Program Files\Windows Live
2013-08-23 21:02 - 2011-10-20 08:23 - 00000000 ____D C:\ProgramData\Norton
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:58 - 2011-06-17 17:55 - 00000000 ____D C:\ProgramData\Skype
2013-08-23 20:57 - 2011-06-17 17:56 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Skype
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:28 - 2010-08-31 17:09 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-08-23 19:09 - 2011-03-08 13:00 - 00000000 ____D C:\Windows\Minidump
2013-08-23 19:09 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:27 - 2013-08-23 18:22 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 18:07 - 2013-08-23 17:52 - 00000000 ____D C:\Windows\system32\MRT
2013-08-23 17:52 - 2010-12-05 14:16 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-11-03 22:03
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
][/CODE]
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-09-2013 04
Ran by Fetzla (administrator) on FETZLA-PC on 02-09-2013 17:06:38
Running from C:\Users\Fetzla\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\adminservice.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Insyde Software Corp.) C:\Program Files\Acer\Android Manager\iSync.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Insyde Software Corp.) C:\Program Files\Acer\Updater\iUpdate.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-08-03] (Realtek Semiconductor)
HKLM\...\Run: [SuiteTray] - C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] - C:\Program Files\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] - C:\Program Files\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] - C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files\Bluetooth Suite\BtvStack.exe [470176 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] - C:\Program Files\Bluetooth Suite\AthBtTray.exe [289952 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe [407416 2010-01-08] (Insyde Software Corp.)
HKLM\...\Run: [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe [508280 2010-01-08] ()
HKLM\...\Run: [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe [489848 2010-11-30] (Insyde Software Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [AgentMonitor] - C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [377800 2012-11-05] ()
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [439360 2013-08-13] (BillP Studios)
HKCU\...\Policies\Explorer: [NoDrives] 0
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MWLService; C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1532280 2012-08-23] (AVG)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
==================== Drivers (Whitelisted) ====================
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-05-20] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-05-20] (Windows (R) Win 7 DDK provider)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [256360 2010-05-20] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28200 2010-05-20] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [177704 2010-05-20] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [46952 2010-05-20] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143080 2010-05-20] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [230760 2010-05-25] (Atheros)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-17] (ENE Technology Inc.)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-03] (Egis Technology Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [10088 2012-07-04] (TuneUp Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Fetzla\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:05 - 2013-09-02 17:06 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 16:54 - 2013-09-02 16:56 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 01:44 - 2013-09-02 01:42 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:44 - 2013-09-02 01:42 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:32 - 2013-09-02 17:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 01:32 - 2013-09-02 01:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:16 - 2013-09-02 01:17 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:04 - 2013-09-02 01:05 - 00001151 _____ C:\DelFix.txt
2013-09-01 20:00 - 2013-09-02 01:04 - 00000000 ____D C:\Windows\ERUNT
2013-09-01 19:42 - 2013-09-01 19:50 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 19:01 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-01 18:42 - 2013-09-02 01:47 - 00022260 _____ C:\Windows\PFRO.log
2013-09-01 17:50 - 2013-09-02 00:59 - 00000000 ____D C:\Windows\erdnt
2013-09-01 17:16 - 2013-09-02 12:15 - 00000448 _____ C:\Windows\setupact.log
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:17 - 2012-08-23 11:31 - 00032120 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-09-01 12:17 - 2012-08-23 11:31 - 00021880 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:14 - 2013-09-01 12:18 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-01 12:07 - 2013-09-01 12:13 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-09-01 12:07 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:27 - 2013-08-23 21:28 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2013-09-01 12:15 - 00000000 ____D C:\Program Files\AVG
2013-08-23 21:18 - 2013-09-02 13:56 - 00000000 ____D C:\ProgramData\MFAData
2013-08-23 21:18 - 2013-08-23 21:43 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:22 - 2013-08-23 18:27 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 17:52 - 2013-08-23 18:07 - 00000000 ____D C:\Windows\system32\MRT
2013-08-19 17:09 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-05 19:39 - 2013-09-01 12:35 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-08-03 21:26 - 2013-09-01 18:37 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-08-03 21:13 - 2013-09-01 17:16 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-08-03 21:13 - 2013-09-01 17:16 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
==================== One Month Modified Files and Folders =======
2013-09-02 17:07 - 2013-09-02 17:07 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-09-02 17:07 - 2013-09-02 01:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:06 - 2013-09-02 17:05 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 17:01 - 2011-03-22 13:46 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-02 16:56 - 2013-09-02 16:54 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:56 - 2010-12-04 15:05 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:54 - 2010-12-04 14:32 - 00000000 ____D C:\Users\Fetzla
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 16:36 - 2010-09-23 12:04 - 00000043 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2013-09-02 16:31 - 2010-09-23 11:20 - 01798813 _____ C:\Windows\WindowsUpdate.log
2013-09-02 13:56 - 2013-08-23 21:18 - 00000000 ____D C:\ProgramData\MFAData
2013-09-02 12:56 - 2010-12-04 15:05 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:19 - 2011-05-02 09:16 - 00000000 ____D C:\Users\Fetzla\AppData\Local\CrashDumps
2013-09-02 12:17 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-02 12:15 - 2013-09-01 17:16 - 00000448 _____ C:\Windows\setupact.log
2013-09-02 01:47 - 2013-09-01 18:42 - 00022260 _____ C:\Windows\PFRO.log
2013-09-02 01:42 - 2013-09-02 01:44 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:42 - 2013-09-02 01:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:42 - 2011-05-05 21:11 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-02 01:42 - 2011-05-05 21:10 - 00000000 ____D C:\Program Files\Java
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:33 - 2013-09-02 01:32 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:33 - 2011-07-04 09:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:30 - 2011-10-19 21:35 - 00000000 ____D C:\Windows\system32\Adobe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:17 - 2013-09-02 01:16 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:05 - 2013-09-02 01:04 - 00001151 _____ C:\DelFix.txt
2013-09-02 01:04 - 2013-09-01 20:00 - 00000000 ____D C:\Windows\ERUNT
2013-09-02 00:59 - 2013-09-01 17:50 - 00000000 ____D C:\Windows\erdnt
2013-09-01 19:50 - 2013-09-01 19:42 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:50 - 2010-12-15 23:12 - 00000000 ____D C:\ProgramData\ICQ
2013-09-01 19:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-09-01 18:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-09-01 18:40 - 2009-07-14 04:03 - 45088768 _____ C:\Windows\system32\config\software.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 17301504 _____ C:\Windows\system32\config\system.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 01048576 _____ C:\Windows\system32\config\default.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-09-01 18:37 - 2013-08-03 21:26 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-09-01 17:57 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-01 17:38 - 2011-06-28 22:11 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Windows Live
2013-09-01 17:16 - 2013-08-03 21:13 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-09-01 17:16 - 2013-08-03 21:13 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
2013-09-01 12:35 - 2013-08-05 19:39 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-09-01 12:28 - 2011-06-17 18:02 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-01 12:18 - 2013-09-01 12:14 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:15 - 2013-08-23 21:25 - 00000000 ____D C:\Program Files\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-09-01 12:07 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-24 22:17 - 2010-08-31 17:35 - 00000000 ____D C:\Program Files\Google
2013-08-23 21:43 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:36 - 2010-08-31 17:21 - 00000000 ____D C:\Program Files\Acer GameZone
2013-08-23 21:34 - 2012-05-30 13:19 - 00000000 ____D C:\Users\Fetzla\Desktop\Neuer Ordner
2013-08-23 21:31 - 2013-08-02 20:45 - 00000000 __SHD C:\Users\Fetzla\Documents\MSDCSC
2013-08-23 21:30 - 2010-08-31 17:33 - 00000000 ____D C:\Program Files\Acer
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:28 - 2013-08-23 21:27 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2010-12-04 14:35 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Google
2013-08-23 21:25 - 2010-08-31 17:35 - 00000000 ____D C:\ProgramData\Google
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:06 - 2010-09-23 11:58 - 00000000 ____D C:\Program Files\Windows Live
2013-08-23 21:02 - 2011-10-20 08:23 - 00000000 ____D C:\ProgramData\Norton
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:58 - 2011-06-17 17:55 - 00000000 ____D C:\ProgramData\Skype
2013-08-23 20:57 - 2011-06-17 17:56 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Skype
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:28 - 2010-08-31 17:09 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-08-23 19:09 - 2011-03-08 13:00 - 00000000 ____D C:\Windows\Minidump
2013-08-23 19:09 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:27 - 2013-08-23 18:22 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 18:07 - 2013-08-23 17:52 - 00000000 ____D C:\Windows\system32\MRT
2013-08-23 17:52 - 2010-12-05 14:16 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-11-03 22:03
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-09-2013 04
Ran by Fetzla (administrator) on FETZLA-PC on 02-09-2013 17:06:38
Running from C:\Users\Fetzla\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\adminservice.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(Insyde Software Corp.) C:\Program Files\Acer\Android Manager\iSync.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Insyde Software Corp.) C:\Program Files\Acer\Updater\iUpdate.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-08-03] (Realtek Semiconductor)
HKLM\...\Run: [SuiteTray] - C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] - C:\Program Files\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] - C:\Program Files\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] - C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files\Bluetooth Suite\BtvStack.exe [470176 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] - C:\Program Files\Bluetooth Suite\AthBtTray.exe [289952 2010-05-25] (Atheros Commnucations)
HKLM\...\Run: [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe [407416 2010-01-08] (Insyde Software Corp.)
HKLM\...\Run: [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe [508280 2010-01-08] ()
HKLM\...\Run: [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe [489848 2010-11-30] (Insyde Software Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [AgentMonitor] - C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [377800 2012-11-05] ()
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [439360 2013-08-13] (BillP Studios)
HKCU\...\Policies\Explorer: [NoDrives] 0
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MWLService; C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1532280 2012-08-23] (AVG)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
==================== Drivers (Whitelisted) ====================
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-05-20] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-05-20] (Windows (R) Win 7 DDK provider)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [256360 2010-05-20] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28200 2010-05-20] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [177704 2010-05-20] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [46952 2010-05-20] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143080 2010-05-20] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [230760 2010-05-25] (Atheros)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-17] (ENE Technology Inc.)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-03] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-03] (Egis Technology Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [10088 2012-07-04] (TuneUp Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Fetzla\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:05 - 2013-09-02 17:06 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 16:54 - 2013-09-02 16:56 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 01:44 - 2013-09-02 01:42 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:44 - 2013-09-02 01:42 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:43 - 2013-09-02 01:42 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:32 - 2013-09-02 17:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 01:32 - 2013-09-02 01:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:16 - 2013-09-02 01:17 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:04 - 2013-09-02 01:05 - 00001151 _____ C:\DelFix.txt
2013-09-01 20:00 - 2013-09-02 01:04 - 00000000 ____D C:\Windows\ERUNT
2013-09-01 19:42 - 2013-09-01 19:50 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 19:01 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-01 18:42 - 2013-09-02 01:47 - 00022260 _____ C:\Windows\PFRO.log
2013-09-01 17:50 - 2013-09-02 00:59 - 00000000 ____D C:\Windows\erdnt
2013-09-01 17:16 - 2013-09-02 12:15 - 00000448 _____ C:\Windows\setupact.log
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:17 - 2012-08-23 11:31 - 00032120 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-09-01 12:17 - 2012-08-23 11:31 - 00021880 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:14 - 2013-09-01 12:18 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-01 12:07 - 2013-09-01 12:13 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-09-01 12:07 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:27 - 2013-08-23 21:28 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2013-09-01 12:15 - 00000000 ____D C:\Program Files\AVG
2013-08-23 21:18 - 2013-09-02 13:56 - 00000000 ____D C:\ProgramData\MFAData
2013-08-23 21:18 - 2013-08-23 21:43 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:22 - 2013-08-23 18:27 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 17:52 - 2013-08-23 18:07 - 00000000 ____D C:\Windows\system32\MRT
2013-08-19 17:09 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-05 19:39 - 2013-09-01 12:35 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-08-03 21:26 - 2013-09-01 18:37 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-08-03 21:13 - 2013-09-01 17:16 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-08-03 21:13 - 2013-09-01 17:16 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
==================== One Month Modified Files and Folders =======
2013-09-02 17:07 - 2013-09-02 17:07 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-09-02 17:07 - 2013-09-02 01:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 17:06 - 2013-09-02 17:06 - 00000000 ____D C:\FRST
2013-09-02 17:06 - 2013-09-02 17:05 - 01085803 _____ (Farbar) C:\Users\Fetzla\Desktop\FRST.exe
2013-09-02 17:01 - 2011-03-22 13:46 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-02 16:56 - 2013-09-02 16:54 - 00000474 _____ C:\Users\Fetzla\Desktop\defogger_disable.log
2013-09-02 16:56 - 2010-12-04 15:05 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-02 16:54 - 2013-09-02 16:54 - 00000000 _____ C:\Users\Fetzla\defogger_reenable
2013-09-02 16:54 - 2010-12-04 14:32 - 00000000 ____D C:\Users\Fetzla
2013-09-02 16:53 - 2013-09-02 16:53 - 00050477 _____ C:\Users\Fetzla\Desktop\Defogger.exe
2013-09-02 16:36 - 2010-09-23 12:04 - 00000043 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2013-09-02 16:31 - 2010-09-23 11:20 - 01798813 _____ C:\Windows\WindowsUpdate.log
2013-09-02 13:56 - 2013-08-23 21:18 - 00000000 ____D C:\ProgramData\MFAData
2013-09-02 12:56 - 2010-12-04 15:05 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:27 - 2009-07-14 06:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 12:19 - 2011-05-02 09:16 - 00000000 ____D C:\Users\Fetzla\AppData\Local\CrashDumps
2013-09-02 12:17 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-02 12:15 - 2013-09-01 17:16 - 00000448 _____ C:\Windows\setupact.log
2013-09-02 01:47 - 2013-09-01 18:42 - 00022260 _____ C:\Windows\PFRO.log
2013-09-02 01:42 - 2013-09-02 01:44 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-02 01:42 - 2013-09-02 01:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-02 01:42 - 2013-09-02 01:43 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-02 01:42 - 2011-05-05 21:11 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-02 01:42 - 2011-05-05 21:10 - 00000000 ____D C:\Program Files\Java
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\WinPatrol
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\ProgramData\InstallMate
2013-09-02 01:34 - 2013-09-02 01:34 - 00000000 ____D C:\Program Files\BillP Studios
2013-09-02 01:33 - 2013-09-02 01:32 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-02 01:33 - 2011-07-04 09:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-02 01:32 - 2013-09-02 01:32 - 00922152 _____ (BillP Studios) C:\Users\Fetzla\Downloads\wpsetup.exe
2013-09-02 01:30 - 2011-10-19 21:35 - 00000000 ____D C:\Windows\system32\Adobe
2013-09-02 01:17 - 2013-09-02 01:17 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Secunia PSI
2013-09-02 01:17 - 2013-09-02 01:16 - 03272136 _____ (Secunia) C:\Users\Fetzla\Desktop\PSISetup711.exe
2013-09-02 01:16 - 2013-09-02 01:16 - 00000000 ____D C:\Program Files\Secunia
2013-09-02 01:05 - 2013-09-02 01:04 - 00001151 _____ C:\DelFix.txt
2013-09-02 01:04 - 2013-09-01 20:00 - 00000000 ____D C:\Windows\ERUNT
2013-09-02 00:59 - 2013-09-01 17:50 - 00000000 ____D C:\Windows\erdnt
2013-09-01 19:50 - 2013-09-01 19:42 - 00000000 ____D C:\AdwCleaner
2013-09-01 19:50 - 2010-12-15 23:12 - 00000000 ____D C:\ProgramData\ICQ
2013-09-01 19:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat
2013-09-01 19:01 - 2013-09-01 19:01 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-01 19:01 - 2013-09-01 19:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-09-01 18:53 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-09-01 18:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-09-01 18:40 - 2009-07-14 04:03 - 45088768 _____ C:\Windows\system32\config\software.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 17301504 _____ C:\Windows\system32\config\system.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 01048576 _____ C:\Windows\system32\config\default.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-09-01 18:40 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-09-01 18:37 - 2013-08-03 21:26 - 00000000 ____D C:\ProgramData\CEC5BA903ECC35130000CEC4EBD13AFB
2013-09-01 17:57 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-01 17:38 - 2011-06-28 22:11 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Windows Live
2013-09-01 17:16 - 2013-08-03 21:13 - 03233806 _____ C:\Users\Fetzla\AppData\Roaming\tor.bin
2013-09-01 17:16 - 2013-08-03 21:13 - 00000141 _____ C:\Users\Fetzla\AppData\Roaming\torrc
2013-09-01 12:35 - 2013-08-05 19:39 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\tor
2013-09-01 12:28 - 2011-06-17 18:02 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-01 12:18 - 2013-09-01 12:14 - 00000000 ____D C:\ProgramData\AVG
2013-09-01 12:17 - 2013-09-01 12:17 - 00002171 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2013-09-01 12:17 - 2013-09-01 12:17 - 00002129 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2013-09-01 12:16 - 2013-09-01 12:16 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG
2013-09-01 12:15 - 2013-08-23 21:25 - 00000000 ____D C:\Program Files\AVG
2013-09-01 12:14 - 2013-09-01 12:14 - 00000000 __SHD C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 12:13 - 2013-09-01 12:07 - 58674136 _____ (AVG) C:\Users\Fetzla\Desktop\avg_tuh_stf_all_2013_2_24c43.exe
2013-08-24 22:17 - 2013-08-24 22:17 - 00000000 _____ C:\Windows\setuperr.log
2013-08-24 22:17 - 2010-08-31 17:35 - 00000000 ____D C:\Program Files\Google
2013-08-23 21:43 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Avg2013
2013-08-23 21:36 - 2010-08-31 17:21 - 00000000 ____D C:\Program Files\Acer GameZone
2013-08-23 21:34 - 2012-05-30 13:19 - 00000000 ____D C:\Users\Fetzla\Desktop\Neuer Ordner
2013-08-23 21:31 - 2013-08-02 20:45 - 00000000 __SHD C:\Users\Fetzla\Documents\MSDCSC
2013-08-23 21:30 - 2010-08-31 17:33 - 00000000 ____D C:\Program Files\Acer
2013-08-23 21:29 - 2013-08-23 21:29 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\AVG2013
2013-08-23 21:28 - 2013-08-23 21:27 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-23 21:27 - 2013-08-23 21:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\TuneUp Software
2013-08-23 21:27 - 2013-08-23 21:27 - 00000000 ____D C:\$AVG
2013-08-23 21:25 - 2010-12-04 14:35 - 00000000 ____D C:\Users\Fetzla\AppData\Local\Google
2013-08-23 21:25 - 2010-08-31 17:35 - 00000000 ____D C:\ProgramData\Google
2013-08-23 21:18 - 2013-08-23 21:18 - 00000000 ____D C:\Users\Fetzla\AppData\Local\MFAData
2013-08-23 21:06 - 2010-09-23 11:58 - 00000000 ____D C:\Program Files\Windows Live
2013-08-23 21:02 - 2011-10-20 08:23 - 00000000 ____D C:\ProgramData\Norton
2013-08-23 21:00 - 2013-08-23 21:00 - 00168800 _____ C:\Users\Fetzla\Documents\cc_20130823_210027.reg
2013-08-23 20:58 - 2011-06-17 17:55 - 00000000 ____D C:\ProgramData\Skype
2013-08-23 20:57 - 2011-06-17 17:56 - 00000000 ____D C:\Users\Fetzla\AppData\Roaming\Skype
2013-08-23 20:56 - 2013-08-23 20:56 - 00000000 ____D C:\Users\Fetzla\AppData\Local\avgchrome
2013-08-23 20:46 - 2013-08-23 20:46 - 00000057 _____ C:\Users\Fetzla\AppData\Roaming\WB.CFG
2013-08-23 19:28 - 2010-08-31 17:09 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-08-23 19:09 - 2011-03-08 13:00 - 00000000 ____D C:\Windows\Minidump
2013-08-23 19:09 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\searchplugins
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Windows\system32\Extensions
2013-08-23 19:04 - 2013-08-23 19:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-23 18:56 - 2013-08-23 18:56 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Program Files\CCleaner
2013-08-23 18:27 - 2013-08-23 18:22 - 00000000 ____D C:\490658c479c0de7c0d39
2013-08-23 18:07 - 2013-08-23 17:52 - 00000000 ____D C:\Windows\system32\MRT
2013-08-23 17:52 - 2010-12-05 14:16 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2012-11-03 22:03
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
Ich glaub das war jetzt alles auf Liste, oder?
Sorry, das es ein bisschen gedauert hat. Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-02 19:10:46
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.PB2O 232,89GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Fetzla\AppData\Local\Temp\uwdiipow.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0x8A8625D0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0x8A862700]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0x8A862010]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0x8A862300]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0x8A8623E0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateProcess [0x8A862120]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0x8A862210]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0x8A8624D0]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 81C409F5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81C7A1F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1357 81C8169C 8 Bytes [D0, 25, 86, 8A, 00, 27, 86, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 139F 81C816E4 4 Bytes [10, 20, 86, 8A]
.text ntkrnlpa.exe!KeRemoveQueueEx + 165F 81C819A4 8 Bytes [00, 23, 86, 8A, E0, 23, 86, ...] {ADD [EBX], AH; XCHG [EDX-0x7579dc20], CL}
.text ntkrnlpa.exe!KeRemoveQueueEx + 166F 81C819B4 8 Bytes [20, 21, 86, 8A, 10, 22, 86, ...] {AND [ECX], AH; XCHG [EDX-0x7579ddf0], CL}
.text ntkrnlpa.exe!KeRemoveQueueEx + 16E3 81C81A28 4 Bytes [D0, 24, 86, 8A]
---- Devices - GMER 2.1 ----
Device Ntfs.sys
Device fastfat.SYS
Device Sftfslh.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys
AttachedDevice fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c0f6e7b5908
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c0f6e7b5908 (not active ControlSet)
---- EOF - GMER 2.1 ---- |