Nach mehreren Versuchen hat FRST nur eine txt erstellt mit Daten.
Die Addition ist immer noch leer.
FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014
Ran by Alexander (administrator) on ASUS on 08-01-2014 19:18:51
Running from C:\Users\Alexander\Desktop
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SynptSync64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
() C:\Program Files\Synaptics\SynTP\AsusNewUI35.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\loggingserver.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-09-29] (Atheros Communications)
HKLM\...\Run: [SynAsusGestureAPIMgr] - C:\Program Files\Synaptics\SynTP\SynAsusGestureAPIMgr.exe [736568 2012-09-17] (Synaptics)
HKLM\...\Run: [AsusNewUI] - C:\Program Files\Synaptics\SynTP\AsusNewUI35.exe [1367864 2012-09-17] ()
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-09-17] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\aprp.exe [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [78352 2012-05-23] (cyberlink)
HKLM-x32\...\Run: [ROGNB] - C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe [466944 2011-09-19] ()
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2013-12-13] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2471448 2014-01-08] ()
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [Power2GoExpress] - C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe [2646504 2012-05-14] (CyberLink Corp.)
HKCU\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [AVG-Secure-Search-Update_1213b] - C:\Users\Alexander\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5 /CMPID=1213b
AppInit_DLLs: c:\progra~2\nvidia~1\3dvisi~1\nvstin~1.dll [ ] ()
Startup: C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk
ShortcutTarget: Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1ABDD229DF0BCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.5
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {D0235A4F-49C2-4EC8-A3B3-98AA6688A94F} URL =
SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms}
BHO: No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.2.0.38\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.2.0.38\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{91B1FCE1-ACC5-4D06-8229-9F23D9A2C41E}: [NameServer]156.154.70.25,156.154.71.25
Tcpip\..\Interfaces\{EFC2072A-5563-40A3-AC41-CA36EE7E67D8}: [NameServer]156.154.70.25,156.154.71.25
Chrome:
=======
CHR HomePage: hxxp://mysearch.avg.com?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=hp
CHR DefaultSearchKeyword: mysearch.avg.com
CHR DefaultSearchProvider: AVG Secure Search
CHR DefaultSearchURL: hxxp://mysearch.avg.com/search?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
CHR Extension: (Google Drive) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0
CHR Extension: (AVG SafeGuard) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.2.0.38_0
CHR Extension: (Google Wallet) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\17.2.0.38\avg.crx
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] ()
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [243728 2012-05-23] (CyberLink)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2013-12-13] (Comodo Security Solutions, Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6254152 2013-10-20] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [164056 2013-09-24] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2098880 2013-11-11] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 FanChkService; C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe [45696 2012-01-20] (ASUSTek Computer Inc.)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2013-12-13] (Comodo Security Solutions, Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [1771544 2014-01-08] (AVG Secure Search)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [46368 2014-01-08] (AVG Technologies)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-10-21] (AVG Technologies CZ, s.r.o.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-09-29] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2013-05-07] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-09-24] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [715824 2013-11-14] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [38072 2013-09-24] (COMODO)
R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2013-10-07] ()
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [118400 2013-09-24] (COMODO)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-09-17] (Synaptics Incorporated)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-07] (Microsoft Corporation)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-10-16] (Anchorfree Inc.)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
U3 fxldrpoc; \??\C:\Users\ALEXAN~1\AppData\Local\Temp\fxldrpoc.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 19:18 - 2014-01-08 19:18 - 00000000 _____ C:\Users\Alexander\Desktop\Addition.txt
2014-01-08 19:12 - 2014-01-08 19:19 - 00021803 _____ C:\Users\Alexander\Desktop\FRST.txt
2014-01-08 19:12 - 2014-01-08 19:12 - 01932624 _____ (Farbar) C:\Users\Alexander\Desktop\FRST64.exe
2014-01-08 19:10 - 2014-01-08 19:10 - 00602112 _____ (OldTimer Tools) C:\Users\Alexander\Downloads\OTL.exe
2014-01-08 19:03 - 2014-01-08 19:03 - 00046368 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\Users\Alexander\AppData\Local\AVG SafeGuard toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\ProgramData\AVG Security Toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2014-01-08 19:01 - 2014-01-08 19:05 - 00021917 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-08 19:01 - 2014-01-08 19:01 - 00000000 _____ C:\WINDOWS\setuperr.log
2014-01-08 19:01 - 2014-01-08 19:01 - 00000000 _____ C:\WINDOWS\setupact.log
2014-01-07 20:43 - 2014-01-07 20:43 - 00000981 _____ C:\Users\Alexander\Desktop\rootkit.log
2014-01-07 20:32 - 2014-01-07 20:32 - 00000000 ____D C:\Program Files (x86)\ESET
2014-01-07 19:33 - 2014-01-07 19:33 - 00000000 ____D C:\FRST
2014-01-06 21:49 - 2014-01-07 19:56 - 00250314 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2014-01-06 21:49 - 2014-01-06 21:49 - 00000000 ___HD C:\VTRoot
2014-01-06 20:40 - 2014-01-06 20:40 - 00007774 _____ C:\Users\Alexander\Downloads\gmer.zip
2014-01-06 20:25 - 2014-01-06 20:25 - 00377856 _____ C:\Users\Alexander\Desktop\gmer_2.1.19163.exe
2014-01-06 20:21 - 2014-01-06 20:21 - 00000480 _____ C:\Users\Alexander\Desktop\defogger_disable.log
2014-01-06 20:21 - 2014-01-06 20:21 - 00000000 _____ C:\Users\Alexander\defogger_reenable
2014-01-06 20:19 - 2014-01-06 20:19 - 00050477 _____ C:\Users\Alexander\Desktop\Defogger.exe
2014-01-06 19:19 - 2014-01-06 19:19 - 00048392 _____ (COMODO CA Limited) C:\WINDOWS\SysWOW64\certsentry.dll
2014-01-06 19:19 - 2014-01-06 19:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2014-01-06 19:19 - 2014-01-06 19:19 - 00000000 ____D C:\first_launch
2014-01-06 19:18 - 2014-01-06 19:18 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2014-01-06 19:18 - 2014-01-06 19:18 - 00003028 _____ C:\WINDOWS\System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}
2014-01-06 19:17 - 2014-01-06 19:19 - 00057096 _____ (COMODO CA Limited) C:\WINDOWS\system32\certsentry.dll
2014-01-06 19:17 - 2014-01-06 19:18 - 00000000 ___SD C:\ProgramData\Shared Space
2014-01-06 19:17 - 2014-01-06 19:18 - 00000000 ____D C:\ProgramData\COMODO
2014-01-06 19:17 - 2014-01-06 19:18 - 00000000 ____D C:\Program Files (x86)\Comodo
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 ____D C:\Users\Alexander\AppData\Local\Comodo
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 ____D C:\Program Files\COMODO
2014-01-06 19:16 - 2014-01-06 19:16 - 00000000 ____D C:\ProgramData\Comodo Downloader
2014-01-06 19:10 - 2014-01-06 19:10 - 03466248 _____ (TrueCrypt Foundation) C:\Users\Alexander\Downloads\TrueCrypt_Datenverschlüsselung.exe
2014-01-06 19:09 - 2014-01-06 19:10 - 214262072 _____ (COMODO) C:\Users\Alexander\Downloads\comodo firewall.exe
2014-01-05 19:11 - 2014-01-05 21:45 - 00000000 ____D C:\Users\Alexander\AppData\Local\Vidalia
2014-01-04 23:26 - 2014-01-04 23:26 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\FreeHideIP
2014-01-04 23:26 - 2014-01-04 23:26 - 00000000 ____D C:\ProgramData\FreeHideIP
2014-01-04 23:01 - 2014-01-08 19:05 - 00003930 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4FE5FCCA-9B26-4D71-B09A-491188DDEDCB}
2014-01-04 22:48 - 2014-01-04 22:48 - 00000000 ____D C:\WINDOWS\SysWOW64\SearchProtect
2014-01-04 22:47 - 2014-01-04 23:01 - 00000000 ____D C:\Users\Alexander\AppData\Local\Conduit
2014-01-04 22:47 - 2014-01-04 22:47 - 00000009 _____ C:\END
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\SearchProtect
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\ProgramData\Conduit
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\Program Files (x86)\Conduit
2014-01-04 22:13 - 2014-01-04 22:13 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-01-04 20:40 - 2014-01-04 20:40 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\AVG2014
2014-01-04 20:39 - 2014-01-04 20:40 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-04 20:39 - 2014-01-04 20:39 - 00000000 ___HD C:\$AVG
2014-01-04 20:39 - 2014-01-04 20:39 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-04 20:35 - 2014-01-04 21:40 - 00000000 ____D C:\Users\Alexander\AppData\Local\Avg2014
2014-01-04 20:21 - 2014-01-04 20:28 - 137189352 _____ (AVG Technologies) C:\Users\Alexander\Downloads\avg_free_x86_all_2014_4259a6848.exe
2014-01-02 13:27 - 2014-01-02 13:38 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Audacity
2013-12-27 14:18 - 2014-01-04 20:29 - 00000000 ____D C:\Program Files\office.tmp
2013-12-27 13:51 - 2013-12-27 14:10 - 00000000 ____D C:\Users\Alexander\Documents\Cubase AI Projects
2013-12-27 13:50 - 2013-12-27 13:50 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\VST3 Presets
2013-12-27 13:47 - 2013-12-27 13:47 - 00000000 ____D C:\Users\Alexander\AppData\Local\eLicenser
2013-12-26 17:47 - 2013-12-27 13:50 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Steinberg
2013-12-26 17:47 - 2013-12-26 17:47 - 00000000 ____D C:\ProgramData\Steinberg
2013-12-26 17:45 - 2013-12-26 17:45 - 00002892 _____ () C:\WINDOWS\SysWOW64\audcon.sys
2013-12-26 17:45 - 2013-12-26 17:45 - 00000000 ____D C:\ProgramData\Syncrosoft
2013-12-26 17:44 - 2013-12-27 14:23 - 00000000 ____D C:\ProgramData\eLicenser
2013-12-26 17:44 - 2013-12-27 13:47 - 00000051 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe.cfg
2013-12-26 17:44 - 2009-09-17 16:20 - 01695232 _____ (Steinberg Media Technologies GmbH) C:\WINDOWS\system32\synsoacc.dll
2013-12-26 17:44 - 2009-09-17 16:20 - 01261568 _____ (Steinberg Media Technologies GmbH) C:\WINDOWS\SysWOW64\SYNSOACC.dll
2013-12-26 17:44 - 2009-05-19 15:21 - 00086016 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe
2013-12-26 17:44 - 2006-01-29 10:48 - 00147425 _____ C:\WINDOWS\SysWOW64\SYNSOACC-Aide.chm
2013-12-26 17:44 - 2006-01-29 10:48 - 00147425 _____ C:\WINDOWS\system32\SYNSOACC-Aide.chm
2013-12-26 17:44 - 2006-01-29 10:48 - 00120468 _____ C:\WINDOWS\SysWOW64\SYNSOACC-Hilfe.chm
2013-12-26 17:44 - 2006-01-29 10:48 - 00120468 _____ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
2013-12-26 17:44 - 2006-01-29 10:48 - 00114279 _____ C:\WINDOWS\SysWOW64\SYNSOACC-Help.chm
2013-12-26 17:44 - 2006-01-29 10:48 - 00114279 _____ C:\WINDOWS\system32\SYNSOACC-Help.chm
2013-12-26 16:00 - 2013-12-26 16:00 - 00000000 ____D C:\Users\Alexander\Documents\MAGIX_Music_Maker_17_Silver
2013-12-26 15:25 - 2013-12-26 15:25 - 00000000 ____D C:\Users\Alexander\Documents\MAGIX
2013-12-26 15:24 - 2013-12-26 15:59 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\MAGIX
2013-12-26 15:18 - 2013-12-27 15:57 - 00000000 ____D C:\Users\Public\Documents\MAGIX_Music_Maker_MX
2013-12-26 15:17 - 2013-12-26 16:02 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-26 15:17 - 2013-12-26 15:59 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-26 15:17 - 2013-12-26 15:17 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-24 15:40 - 2013-12-24 15:40 - 00005107 _____ C:\Users\Alexander\AppData\Local\recently-used.xbel
2013-12-24 11:58 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_ID4BJCE.DLL
2013-12-24 11:58 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\WINDOWS\system32\E_GCINST.DLL
2013-12-24 11:53 - 2013-12-24 11:53 - 00000000 _____ C:\Users\Alexander\Sti_Trace.log
2013-12-22 14:12 - 2013-12-22 14:12 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\OpenOffice
2013-12-21 21:43 - 2013-12-21 21:43 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-12-21 21:35 - 2013-12-21 21:41 - 163606685 _____ C:\Users\Alexander\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-12-20 21:29 - 2013-12-22 15:31 - 00000000 ____D C:\Tools
2013-12-20 21:11 - 2013-12-20 21:11 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-20 20:44 - 2013-12-20 20:44 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-20 20:43 - 2013-12-20 21:31 - 00000000 ____D C:\AdwCleaner
2013-12-20 20:36 - 2013-12-20 20:36 - 00001185 _____ C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner.lnk
2013-12-20 20:27 - 2013-12-20 20:27 - 00002780 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2013-12-20 20:27 - 2013-12-20 20:27 - 00000000 ____D C:\Program Files\CCleaner
2013-12-20 20:26 - 2013-12-20 20:26 - 03541544 _____ (Piriform Ltd) C:\Users\Alexander\Downloads\CCleaner.exe
2013-12-20 20:17 - 2013-12-20 20:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\Malewarebytes.exe
2013-12-20 20:10 - 2013-12-26 00:18 - 00000000 ____D C:\Program Files (x86)\iCare Card Recovery Free
2013-12-20 20:09 - 2013-12-20 20:09 - 03774938 _____ (iCare Software ) C:\Users\Alexander\Downloads\icare card recovery.exe
2013-12-20 20:01 - 2013-12-20 20:01 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar
2013-12-20 20:01 - 2013-12-20 20:01 - 00000000 ____D C:\Program Files (x86)\Convar
2013-12-16 17:42 - 2013-12-16 17:42 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-14 12:28 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-12-14 12:28 - 2013-11-12 00:24 - 00840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-12-14 12:28 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-12-14 12:28 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-12-14 12:28 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2013-12-14 12:28 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2013-12-14 12:28 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2013-12-14 12:28 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2013-12-14 12:28 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-12-14 12:28 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-12-14 12:28 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2013-12-14 12:28 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2013-12-14 12:28 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-12-14 12:28 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-12-14 12:28 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2013-12-14 12:28 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2013-12-14 12:28 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2013-12-14 12:28 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2013-12-14 12:28 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2013-12-14 12:28 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-12-14 12:28 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-12-14 12:28 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-12-14 12:28 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-12-14 12:28 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-12-14 12:28 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2013-12-14 12:28 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2013-12-14 12:28 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2013-12-14 12:28 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-12-14 12:28 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-12-14 12:28 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-12-14 12:28 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-12-14 12:28 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-12-14 12:28 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-12-14 12:28 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2013-12-14 12:28 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2013-12-14 12:28 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2013-12-14 12:28 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2013-12-14 12:28 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2013-12-14 12:28 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-12-14 12:28 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-12-14 12:28 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-12-14 12:28 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-12-14 12:27 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-14 12:27 - 2013-11-12 00:40 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-14 12:27 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2013-12-14 12:27 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-12-14 12:27 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-12-12 20:54 - 2013-11-23 05:34 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2013-12-12 20:54 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2013-12-12 20:35 - 2013-11-23 04:32 - 04105728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-12-12 20:34 - 2013-11-23 04:10 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2013-12-12 20:29 - 2013-11-09 07:34 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2013-12-12 20:29 - 2013-11-09 07:34 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2013-12-12 20:28 - 2013-11-09 06:52 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2013-12-12 19:16 - 2014-01-06 19:38 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-12 18:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-12-12 18:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-12-12 18:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-12-12 18:00 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2013-12-12 18:00 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2013-12-12 18:00 - 2013-10-15 09:54 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2013-12-12 18:00 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2013-12-12 17:59 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-12-12 17:59 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-12-12 17:59 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-12-12 17:59 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-12-12 17:59 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-12-12 17:59 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-12-12 17:59 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-12-12 17:59 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-12-12 17:59 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-12-12 17:59 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-12-12 17:59 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-12-12 17:59 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2013-12-12 17:59 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-12-12 17:59 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-12-12 17:59 - 2013-11-08 08:21 - 04191744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-12-10 18:46 - 2013-12-10 18:46 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Malwarebytes
2013-12-10 18:45 - 2013-12-20 20:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-10 18:45 - 2013-12-10 18:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-10 18:45 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-10 18:04 - 2013-12-10 18:04 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\TuneUp Software
2013-12-10 18:02 - 2014-01-08 19:06 - 00000000 ____D C:\ProgramData\MFAData
2013-12-10 18:02 - 2013-12-10 18:02 - 00000000 ____D C:\Users\Alexander\AppData\Local\MFAData
==================== One Month Modified Files and Folders =======
2014-01-08 19:19 - 2014-01-08 19:12 - 00021803 _____ C:\Users\Alexander\Desktop\FRST.txt
2014-01-08 19:18 - 2014-01-08 19:18 - 00000000 _____ C:\Users\Alexander\Desktop\Addition.txt
2014-01-08 19:14 - 2013-09-11 17:41 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-782853324-163606255-2445155786-1002
2014-01-08 19:12 - 2014-01-08 19:12 - 01932624 _____ (Farbar) C:\Users\Alexander\Desktop\FRST64.exe
2014-01-08 19:11 - 2013-12-07 15:02 - 00000000 ____D C:\Papierkorb
2014-01-08 19:10 - 2014-01-08 19:10 - 00602112 _____ (OldTimer Tools) C:\Users\Alexander\Downloads\OTL.exe
2014-01-08 19:09 - 2013-09-11 17:54 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-08 19:09 - 2013-09-11 17:54 - 00001120 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-08 19:06 - 2013-12-10 18:02 - 00000000 ____D C:\ProgramData\MFAData
2014-01-08 19:05 - 2014-01-08 19:01 - 00021917 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-08 19:05 - 2014-01-04 23:01 - 00003930 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4FE5FCCA-9B26-4D71-B09A-491188DDEDCB}
2014-01-08 19:03 - 2014-01-08 19:03 - 00046368 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\Users\Alexander\AppData\Local\AVG SafeGuard toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\ProgramData\AVG Security Toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-08 19:03 - 2014-01-08 19:03 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2014-01-08 19:02 - 2013-09-11 17:34 - 00000401 _____ C:\Users\Alexander\AppData\Roaming\sp_data.sys
2014-01-08 19:01 - 2014-01-08 19:01 - 00000000 _____ C:\WINDOWS\setuperr.log
2014-01-08 19:01 - 2014-01-08 19:01 - 00000000 _____ C:\WINDOWS\setupact.log
2014-01-08 19:01 - 2013-12-07 00:38 - 00000000 __RDO C:\Users\Alexander\SkyDrive
2014-01-08 19:01 - 2013-09-12 20:30 - 00163328 ___SH C:\Users\Alexander\Desktop\Thumbs.db
2014-01-08 19:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2014-01-07 20:43 - 2014-01-07 20:43 - 00000981 _____ C:\Users\Alexander\Desktop\rootkit.log
2014-01-07 20:32 - 2014-01-07 20:32 - 00000000 ____D C:\Program Files (x86)\ESET
2014-01-07 19:57 - 2013-12-07 00:09 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-07 19:57 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-07 19:56 - 2014-01-06 21:49 - 00250314 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2014-01-07 19:56 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2014-01-07 19:33 - 2014-01-07 19:33 - 00000000 ____D C:\FRST
2014-01-07 19:05 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2014-01-06 21:49 - 2014-01-06 21:49 - 00000000 ___HD C:\VTRoot
2014-01-06 20:40 - 2014-01-06 20:40 - 00007774 _____ C:\Users\Alexander\Downloads\gmer.zip
2014-01-06 20:25 - 2014-01-06 20:25 - 00377856 _____ C:\Users\Alexander\Desktop\gmer_2.1.19163.exe
2014-01-06 20:21 - 2014-01-06 20:21 - 00000480 _____ C:\Users\Alexander\Desktop\defogger_disable.log
2014-01-06 20:21 - 2014-01-06 20:21 - 00000000 _____ C:\Users\Alexander\defogger_reenable
2014-01-06 20:21 - 2013-12-07 00:15 - 00000000 ____D C:\Users\Alexander
2014-01-06 20:19 - 2014-01-06 20:19 - 00050477 _____ C:\Users\Alexander\Desktop\Defogger.exe
2014-01-06 19:38 - 2013-12-12 19:16 - 00000000 ____D C:\ProgramData\AVAST Software
2014-01-06 19:19 - 2014-01-06 19:19 - 00048392 _____ (COMODO CA Limited) C:\WINDOWS\SysWOW64\certsentry.dll
2014-01-06 19:19 - 2014-01-06 19:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2014-01-06 19:19 - 2014-01-06 19:19 - 00000000 ____D C:\first_launch
2014-01-06 19:19 - 2014-01-06 19:17 - 00057096 _____ (COMODO CA Limited) C:\WINDOWS\system32\certsentry.dll
2014-01-06 19:18 - 2014-01-06 19:18 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2014-01-06 19:18 - 2014-01-06 19:18 - 00003028 _____ C:\WINDOWS\System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3}
2014-01-06 19:18 - 2014-01-06 19:17 - 00000000 ___SD C:\ProgramData\Shared Space
2014-01-06 19:18 - 2014-01-06 19:17 - 00000000 ____D C:\ProgramData\COMODO
2014-01-06 19:18 - 2014-01-06 19:17 - 00000000 ____D C:\Program Files (x86)\Comodo
2014-01-06 19:18 - 2012-07-26 06:37 - 00000000 ____D C:\Users\Default.migrated
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 ____D C:\Users\Alexander\AppData\Local\Comodo
2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 ____D C:\Program Files\COMODO
2014-01-06 19:16 - 2014-01-06 19:16 - 00000000 ____D C:\ProgramData\Comodo Downloader
2014-01-06 19:10 - 2014-01-06 19:10 - 03466248 _____ (TrueCrypt Foundation) C:\Users\Alexander\Downloads\TrueCrypt_Datenverschlüsselung.exe
2014-01-06 19:10 - 2014-01-06 19:09 - 214262072 _____ (COMODO) C:\Users\Alexander\Downloads\comodo firewall.exe
2014-01-05 21:45 - 2014-01-05 19:11 - 00000000 ____D C:\Users\Alexander\AppData\Local\Vidalia
2014-01-04 23:26 - 2014-01-04 23:26 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\FreeHideIP
2014-01-04 23:26 - 2014-01-04 23:26 - 00000000 ____D C:\ProgramData\FreeHideIP
2014-01-04 23:01 - 2014-01-04 22:47 - 00000000 ____D C:\Users\Alexander\AppData\Local\Conduit
2014-01-04 22:48 - 2014-01-04 22:48 - 00000000 ____D C:\WINDOWS\SysWOW64\SearchProtect
2014-01-04 22:47 - 2014-01-04 22:47 - 00000009 _____ C:\END
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\SearchProtect
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\ProgramData\Conduit
2014-01-04 22:47 - 2014-01-04 22:47 - 00000000 ____D C:\Program Files (x86)\Conduit
2014-01-04 22:13 - 2014-01-04 22:13 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-01-04 21:40 - 2014-01-04 20:35 - 00000000 ____D C:\Users\Alexander\AppData\Local\Avg2014
2014-01-04 20:43 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2014-01-04 20:40 - 2014-01-04 20:40 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\AVG2014
2014-01-04 20:40 - 2014-01-04 20:39 - 00000000 ____D C:\ProgramData\AVG2014
2014-01-04 20:39 - 2014-01-04 20:39 - 00000000 ___HD C:\$AVG
2014-01-04 20:39 - 2014-01-04 20:39 - 00000000 ____D C:\Program Files (x86)\AVG
2014-01-04 20:39 - 2012-07-26 09:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2014-01-04 20:36 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-04 20:36 - 2013-09-30 04:56 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2014-01-04 20:36 - 2013-09-30 04:56 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2014-01-04 20:29 - 2013-12-27 14:18 - 00000000 ____D C:\Program Files\office.tmp
2014-01-04 20:29 - 2013-08-22 15:44 - 00573264 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2014-01-04 20:28 - 2014-01-04 20:21 - 137189352 _____ (AVG Technologies) C:\Users\Alexander\Downloads\avg_free_x86_all_2014_4259a6848.exe
2014-01-04 20:15 - 2013-09-11 18:04 - 00000000 ____D C:\ProgramData\Ashampoo
2014-01-02 13:38 - 2014-01-02 13:27 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Audacity
2013-12-27 15:57 - 2013-12-26 15:18 - 00000000 ____D C:\Users\Public\Documents\MAGIX_Music_Maker_MX
2013-12-27 14:23 - 2013-12-26 17:44 - 00000000 ____D C:\ProgramData\eLicenser
2013-12-27 14:20 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2013-12-27 14:20 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2013-12-27 14:10 - 2013-12-27 13:51 - 00000000 ____D C:\Users\Alexander\Documents\Cubase AI Projects
2013-12-27 13:50 - 2013-12-27 13:50 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\VST3 Presets
2013-12-27 13:50 - 2013-12-26 17:47 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Steinberg
2013-12-27 13:47 - 2013-12-27 13:47 - 00000000 ____D C:\Users\Alexander\AppData\Local\eLicenser
2013-12-27 13:47 - 2013-12-26 17:44 - 00000051 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe.cfg
2013-12-26 18:59 - 2013-09-11 17:31 - 00000000 ____D C:\Users\Alexander\AppData\Local\Packages
2013-12-26 17:47 - 2013-12-26 17:47 - 00000000 ____D C:\ProgramData\Steinberg
2013-12-26 17:45 - 2013-12-26 17:45 - 00002892 _____ () C:\WINDOWS\SysWOW64\audcon.sys
2013-12-26 17:45 - 2013-12-26 17:45 - 00000000 ____D C:\ProgramData\Syncrosoft
2013-12-26 16:02 - 2013-12-26 15:17 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-26 16:00 - 2013-12-26 16:00 - 00000000 ____D C:\Users\Alexander\Documents\MAGIX_Music_Maker_17_Silver
2013-12-26 15:59 - 2013-12-26 15:24 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\MAGIX
2013-12-26 15:59 - 2013-12-26 15:17 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-26 15:25 - 2013-12-26 15:25 - 00000000 ____D C:\Users\Alexander\Documents\MAGIX
2013-12-26 15:17 - 2013-12-26 15:17 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-26 15:17 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Help
2013-12-26 00:18 - 2013-12-20 20:10 - 00000000 ____D C:\Program Files (x86)\iCare Card Recovery Free
2013-12-24 15:57 - 2013-12-08 18:45 - 00000000 ____D C:\Users\Alexander\.gimp-2.8
2013-12-24 15:40 - 2013-12-24 15:40 - 00005107 _____ C:\Users\Alexander\AppData\Local\recently-used.xbel
2013-12-24 15:40 - 2013-12-08 18:53 - 00000000 ____D C:\Users\Alexander\AppData\Local\gtk-2.0
2013-12-24 11:57 - 2013-11-16 17:05 - 00000000 ____D C:\Program Files (x86)\Epson Software
2013-12-24 11:53 - 2013-12-24 11:53 - 00000000 _____ C:\Users\Alexander\Sti_Trace.log
2013-12-22 15:31 - 2013-12-20 21:29 - 00000000 ____D C:\Tools
2013-12-22 14:12 - 2013-12-22 14:12 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\OpenOffice
2013-12-21 21:43 - 2013-12-21 21:43 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-12-21 21:41 - 2013-12-21 21:35 - 163606685 _____ C:\Users\Alexander\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-12-21 15:01 - 2013-09-11 17:32 - 00000000 ____D C:\Users\Alexander\AppData\Local\VirtualStore
2013-12-21 00:15 - 2013-12-07 00:04 - 00000000 ___DC C:\WINDOWS\Panther
2013-12-21 00:15 - 2013-09-14 12:55 - 00000000 ____D C:\Users\Alexander\AppData\Local\CrashDumps
2013-12-20 21:31 - 2013-12-20 20:43 - 00000000 ____D C:\AdwCleaner
2013-12-20 21:11 - 2013-12-20 21:11 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-20 20:44 - 2013-12-20 20:44 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-20 20:36 - 2013-12-20 20:36 - 00001185 _____ C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner.lnk
2013-12-20 20:27 - 2013-12-20 20:27 - 00002780 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2013-12-20 20:27 - 2013-12-20 20:27 - 00000000 ____D C:\Program Files\CCleaner
2013-12-20 20:26 - 2013-12-20 20:26 - 03541544 _____ (Piriform Ltd) C:\Users\Alexander\Downloads\CCleaner.exe
2013-12-20 20:18 - 2013-12-10 18:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-20 20:17 - 2013-12-20 20:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Alexander\Downloads\Malewarebytes.exe
2013-12-20 20:09 - 2013-12-20 20:09 - 03774938 _____ (iCare Software ) C:\Users\Alexander\Downloads\icare card recovery.exe
2013-12-20 20:01 - 2013-12-20 20:01 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar
2013-12-20 20:01 - 2013-12-20 20:01 - 00000000 ____D C:\Program Files (x86)\Convar
2013-12-18 20:00 - 2013-09-11 17:54 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-18 19:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-12-16 17:42 - 2013-12-16 17:42 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-15 12:25 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-12-15 12:25 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-12-15 12:25 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\MediaViewer
2013-12-15 12:25 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\FileManager
2013-12-15 12:25 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera
2013-12-14 12:52 - 2013-09-12 19:22 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-11 19:04 - 2013-09-11 17:54 - 00004096 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-11 19:04 - 2013-09-11 17:54 - 00003860 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 18:46 - 2013-12-10 18:46 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\Malwarebytes
2013-12-10 18:45 - 2013-12-10 18:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-10 18:04 - 2013-12-10 18:04 - 00000000 ____D C:\Users\Alexander\AppData\Roaming\TuneUp Software
2013-12-10 18:02 - 2013-12-10 18:02 - 00000000 ____D C:\Users\Alexander\AppData\Local\MFAData
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-07 21:13
==================== End Of Log ============================ --- --- ---
OTL
OTL Logfile: Code:
OTL logfile created on: 08.01.2014 19:22:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alexander\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16476)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,95 Gb Total Physical Memory | 5,67 Gb Available Physical Memory | 71,31% Memory free
9,20 Gb Paging File | 5,75 Gb Available in Paging File | 62,46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372,26 Gb Total Space | 320,19 Gb Free Space | 86,01% Space Free | Partition Type: NTFS
Drive D: | 537,60 Gb Total Space | 536,77 Gb Free Space | 99,85% Space Free | Partition Type: NTFS
Drive E: | 29,71 Gb Total Space | 29,71 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
Computer Name: ASUS | User Name: Alexander | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Alexander\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\loggingserver.exe ()
PRC - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.)
PRC - c:\program files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
PRC - C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTeK)
PRC - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (ASUS)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\log4cplusU.dll ()
MOD - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
MOD - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
MOD - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll ()
MOD - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll ()
MOD - c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:64bit: - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:64bit: - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (EpsonScanSvc) -- C:\Windows\SysNative\escsvc64.exe (Seiko Epson Corporation)
SRV - (vToolbarUpdater17.2.0) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (GeekBuddyRSP) -- C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (CLPSLauncher) -- C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions, Inc.)
SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (DragonUpdater) -- C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe ()
SRV - (cmdAgent) -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (cmdvirth) -- C:\Programme\COMODO\COMODO Internet Security\cmdvirth.exe (COMODO)
SRV - (avgwd) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PrintNotify) -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (Asus WebStorage Windows Service) -- C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe ()
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Qualcomm Atheros Commnucations)
SRV - (ZAtheros Bt and Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (CLKMSVC10_38F51D56) -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (Intel(R) -- C:\Programme\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (ASUS InstantOn) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (ASUS)
SRV - (FanChkService) -- C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe (ASUSTek Computer Inc.)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (EpsonBidirectionalService) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avgtp) -- C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (Avgdiska) -- C:\Windows\SysNative\drivers\avgdiska.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgloga) -- C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) -- C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgwfpa) -- C:\Windows\SysNative\drivers\avgwfpa.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (taphss6) -- C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (HIDSwitch) -- C:\Windows\SysNative\drivers\AsHIDSwitch64.sys (ASUS)
DRV:64bit: - (HMD) -- C:\Windows\SysNative\drivers\hmd.sys ()
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (cmderd) -- C:\Windows\SysNative\drivers\cmderd.sys (COMODO)
DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Avgboota) -- C:\Windows\SysNative\drivers\avgboota.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:64bit: - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:64bit: - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:64bit: - (BthLEEnum) -- C:\Windows\SysNative\drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:64bit: - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C63x64.sys (Qualcomm Atheros Co., Ltd.)
DRV:64bit: - (CFRMD) -- C:\Windows\SysNative\drivers\CFRMD.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Qualcomm Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Qualcomm Atheros)
DRV:64bit: - (AiCharger) -- C:\Windows\SysNative\drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (dc3d) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {D0235A4F-49C2-4EC8-A3B3-98AA6688A94F}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.5
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1A BD D2 29 DF 0B CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://mysearch.avg.com/search?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.2.0.38 [2014.01.08 19:03:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK
[2013.09.11 21:41:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: hxxp://mysearch.avg.com?cid={D1614F35-87CB-48D9-A087-3987D6D2466C}&mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-08 19:03:43&v=17.2.0.38&pid=safeguard&sg=&sap=hp
CHR - plugin: Shockwave Flash (Enabled) = c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Intel Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - Extension: Google Drive = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Windows Media Player Extension for HTML5 = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0\
CHR - Extension: AVG SafeGuard = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.2.0.38_0\
CHR - Extension: Google Wallet = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: Google Mail = C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2013.08.22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O2:64bit: - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.2.0.38\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.2.0.38\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O4:64bit: - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
O4:64bit: - HKLM..\Run: [AsusNewUI] C:\Program Files\Synaptics\SynTP\AsusNewUI35.exe ()
O4:64bit: - HKLM..\Run: [BtTray] C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Qualcomm Atheros)
O4:64bit: - HKLM..\Run: [BtvStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SynAsusGestureAPIMgr] C:\Programme\Synaptics\SynTP\SynAsusGestureAPIMgr.exe (Synaptics)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ROGNB] C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe ()
O4 - HKLM..\Run: [tvncontrol] C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKCU..\Run: [AVG-Secure-Search-Update_1213b] C:\Users\Alexander\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=1fc2076157c747d39d30f54322b4007d-deb938a3927238d7a2affdc79dac21437613b9d5 /CMPID=1213b File not found
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-600 Series" File not found
O4 - HKCU..\Run: [EPLTarget\P0000000000000001] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-600 Series" File not found
O4 - HKCU..\Run: [Power2GoExpress] C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe (CyberLink Corp.)
O4 - Startup: C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{91B1FCE1-ACC5-4D06-8229-9F23D9A2C41E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{91B1FCE1-ACC5-4D06-8229-9F23D9A2C41E}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFC2072A-5563-40A3-AC41-CA36EE7E67D8}: NameServer = 156.154.70.25,156.154.71.25
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - AppInit_DLLs: (c:\progra~2\nvidia~1\3dvisi~1\nvstin~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.01.08 19:12:00 | 001,932,624 | ---- | C] (Farbar) -- C:\Users\Alexander\Desktop\FRST64.exe
[2014.01.08 19:10:37 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Alexander\Desktop\OTL.exe
[2014.01.08 19:03:54 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\AVG SafeGuard toolbar
[2014.01.08 19:03:48 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar
[2014.01.08 19:03:41 | 000,046,368 | ---- | C] (AVG Technologies) -- C:\WINDOWS\SysNative\drivers\avgtpx64.sys
[2014.01.08 19:03:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2014.01.08 19:03:33 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG SafeGuard toolbar
[2014.01.08 19:03:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG SafeGuard toolbar
[2014.01.07 20:32:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2014.01.07 19:33:27 | 000,000,000 | ---D | C] -- C:\FRST
[2014.01.06 21:49:03 | 000,000,000 | -H-D | C] -- C:\VTRoot
[2014.01.06 19:28:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\COMODO
[2014.01.06 19:19:06 | 000,000,000 | ---D | C] -- C:\first_launch
[2014.01.06 19:19:04 | 000,048,392 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\SysWow64\certsentry.dll
[2014.01.06 19:18:25 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc71.dll
[2014.01.06 19:17:49 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2014.01.06 19:17:34 | 000,000,000 | ---D | C] -- C:\ProgramData\COMODO
[2014.01.06 19:17:24 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2014.01.06 19:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2014.01.06 19:17:15 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Comodo
[2014.01.06 19:17:11 | 000,057,096 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.dll
[2014.01.06 19:17:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Comodo
[2014.01.06 19:16:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2014.01.05 19:11:13 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Vidalia
[2014.01.04 23:26:38 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\FreeHideIP
[2014.01.04 23:26:38 | 000,000,000 | ---D | C] -- C:\ProgramData\FreeHideIP
[2014.01.04 22:48:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\SearchProtect
[2014.01.04 22:47:21 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\SearchProtect
[2014.01.04 22:47:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2014.01.04 22:47:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Conduit
[2014.01.04 22:47:19 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Conduit
[2014.01.04 22:38:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vidalia Bridge Bundle
[2014.01.04 22:13:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2014.01.04 20:40:23 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\AVG2014
[2014.01.04 20:39:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014.01.04 20:39:22 | 000,000,000 | -H-D | C] -- C:\$AVG
[2014.01.04 20:39:22 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014
[2014.01.04 20:39:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2014.01.04 20:35:59 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Avg2014
[2014.01.02 13:27:39 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Audacity
[2013.12.27 13:51:10 | 000,000,000 | ---D | C] -- C:\Users\Alexander\Documents\Cubase AI Projects
[2013.12.27 13:50:24 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\VST3 Presets
[2013.12.27 13:47:24 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\eLicenser
[2013.12.26 17:47:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Steinberg
[2013.12.26 17:47:02 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Steinberg
[2013.12.26 17:45:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Syncrosoft
[2013.12.26 17:44:12 | 001,695,232 | ---- | C] (Steinberg Media Technologies GmbH) -- C:\WINDOWS\SysNative\synsoacc.dll
[2013.12.26 17:44:11 | 000,000,000 | ---D | C] -- C:\ProgramData\eLicenser
[2013.12.26 17:44:07 | 001,261,568 | ---- | C] (Steinberg Media Technologies GmbH) -- C:\WINDOWS\SysWow64\SYNSOACC.dll
[2013.12.26 16:00:03 | 000,000,000 | ---D | C] -- C:\Users\Alexander\Documents\MAGIX_Music_Maker_17_Silver
[2013.12.26 15:25:28 | 000,000,000 | ---D | C] -- C:\Users\Alexander\Documents\MAGIX Downloads
[2013.12.26 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\Alexander\Documents\MAGIX
[2013.12.26 15:24:42 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\MAGIX
[2013.12.26 15:18:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\MAGIX_Music_Maker_MX
[2013.12.26 15:17:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2013.12.26 15:17:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2013.12.26 15:17:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2013.12.26 15:17:41 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2013.12.26 15:17:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Services
[2013.12.24 11:58:19 | 000,010,752 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\SysNative\E_GCINST.DLL
[2013.12.24 11:58:15 | 000,083,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\SysNative\E_ID4BJCE.DLL
[2013.12.22 14:12:28 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\OpenOffice
[2013.12.21 21:43:59 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
[2013.12.21 21:43:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice 4
[2013.12.20 21:29:06 | 000,000,000 | ---D | C] -- C:\Tools
[2013.12.20 21:11:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013.12.20 20:44:11 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2013.12.20 20:43:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.12.20 20:27:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.12.20 20:10:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCare Card Recovery Free
[2013.12.20 20:10:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iCare Card Recovery Free
[2013.12.20 20:01:50 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar
[2013.12.20 20:01:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Convar
[2013.12.18 20:00:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013.12.14 12:28:30 | 002,570,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2013.12.14 12:28:29 | 007,399,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2013.12.14 12:28:25 | 013,177,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2013.12.14 12:28:24 | 000,358,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcomp.dll
[2013.12.14 12:28:23 | 000,637,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2013.12.14 12:28:21 | 011,674,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2013.12.14 12:28:20 | 000,372,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2013.12.14 12:28:19 | 000,840,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2013.12.14 12:28:18 | 002,896,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2013.12.14 12:28:18 | 000,747,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcli.dll
[2013.12.14 12:28:18 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2013.12.14 12:28:17 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2013.12.14 12:28:17 | 000,479,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2013.12.14 12:28:14 | 001,756,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPDMC.exe
[2013.12.14 12:28:14 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2013.12.14 12:28:14 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dcomp.dll
[2013.12.14 12:28:14 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2013.12.14 12:28:13 | 001,345,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2013.12.14 12:28:12 | 001,642,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2013.12.14 12:28:12 | 001,476,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2013.12.14 12:28:09 | 001,506,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2013.12.14 12:28:08 | 002,266,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2013.12.14 12:28:08 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2013.12.14 12:28:08 | 000,086,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pdc.sys
[2013.12.14 12:28:07 | 001,391,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPDMC.exe
[2013.12.14 12:28:07 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2013.12.14 12:28:06 | 000,922,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2013.12.14 12:28:06 | 000,146,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\SerCx2.sys
[2013.12.14 12:28:05 | 000,325,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2013.12.14 12:28:05 | 000,039,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\intelpep.sys
[2013.12.14 12:28:05 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredentialMigrationHandler.dll
[2013.12.14 12:28:04 | 002,140,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2013.12.14 12:28:04 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredentialMigrationHandler.dll
[2013.12.14 12:28:03 | 001,765,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2013.12.14 12:28:02 | 001,843,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2013.12.14 12:28:02 | 001,816,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2013.12.14 12:28:02 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcli.dll
[2013.12.14 12:28:02 | 000,516,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2013.12.14 12:28:01 | 000,382,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2013.12.14 12:28:00 | 001,302,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2013.12.14 12:27:59 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2013.12.14 12:27:59 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2013.12.14 12:27:58 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2013.12.14 12:27:58 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2013.12.14 12:27:57 | 001,765,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2013.12.12 20:54:13 | 000,393,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPhoto.dll
[2013.12.12 20:54:13 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPhoto.dll
[2013.12.12 20:35:01 | 004,105,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2013.12.12 20:34:09 | 000,568,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2013.12.12 20:29:18 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmregistration.dll
[2013.12.12 20:29:12 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2013.12.12 20:28:56 | 000,240,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mdmregistration.dll
[2013.12.12 19:16:05 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013.12.12 18:00:44 | 000,075,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imagehlp.dll
[2013.12.12 18:00:42 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scrrun.dll
[2013.12.12 18:00:42 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\scrrun.dll
[2013.12.12 18:00:08 | 005,769,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2013.12.12 17:59:12 | 001,995,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2013.12.12 17:59:11 | 001,928,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2013.12.12 17:59:11 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2013.12.12 17:59:11 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2013.12.12 17:59:11 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2013.12.10 18:46:12 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Malwarebytes
[2013.12.10 18:45:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.12.10 18:45:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.12.10 18:45:16 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2013.12.10 18:45:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.12.10 18:04:38 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\TuneUp Software
[2013.12.10 18:02:01 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013.12.10 18:02:01 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\MFAData
[2013.12.10 18:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.01.08 19:12:07 | 001,932,624 | ---- | M] (Farbar) -- C:\Users\Alexander\Desktop\FRST64.exe
[2014.01.08 19:10:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alexander\Desktop\OTL.exe
[2014.01.08 19:09:54 | 000,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014.01.08 19:09:00 | 000,001,120 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014.01.08 19:03:19 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\WINDOWS\SysNative\drivers\avgtpx64.sys
[2014.01.08 19:02:06 | 000,000,401 | ---- | M] () -- C:\Users\Alexander\AppData\Roaming\sp_data.sys
[2014.01.08 19:01:24 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014.01.07 19:57:00 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014.01.07 19:56:59 | 2536,034,303 | -HS- | M] () -- C:\hiberfil.sys
[2014.01.07 19:56:05 | 000,250,314 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\fvstore.dat
[2014.01.07 19:41:11 | 000,356,928 | ---- | M] () -- C:\Users\Alexander\Desktop\Fehler FRST64.png
[2014.01.06 20:25:49 | 000,377,856 | ---- | M] () -- C:\Users\Alexander\Desktop\gmer_2.1.19163.exe
[2014.01.06 20:21:22 | 000,000,000 | ---- | M] () -- C:\Users\Alexander\defogger_reenable
[2014.01.06 20:19:33 | 000,050,477 | ---- | M] () -- C:\Users\Alexander\Desktop\Defogger.exe
[2014.01.06 19:28:10 | 000,002,031 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2014.01.06 19:19:04 | 000,057,096 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.dll
[2014.01.06 19:19:04 | 000,048,392 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\SysWow64\certsentry.dll
[2014.01.06 19:18:25 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc71.dll
[2014.01.04 22:47:45 | 000,000,009 | ---- | M] () -- C:\END
[2014.01.04 20:36:35 | 001,776,918 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014.01.04 20:36:35 | 000,765,582 | ---- | M] () -- C:\WINDOWS\SysNative\perfh007.dat
[2014.01.04 20:36:35 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014.01.04 20:36:35 | 000,159,366 | ---- | M] () -- C:\WINDOWS\SysNative\perfc007.dat
[2014.01.04 20:36:35 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014.01.04 20:29:43 | 000,573,264 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2013.12.27 13:47:09 | 000,000,051 | ---- | M] () -- C:\WINDOWS\SysWow64\SYNSOPOS.exe.cfg
[2013.12.26 17:45:52 | 000,002,892 | ---- | M] () -- C:\WINDOWS\SysWow64\audcon.sys
[2013.12.24 15:40:49 | 000,005,107 | ---- | M] () -- C:\Users\Alexander\AppData\Local\recently-used.xbel
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.01.07 19:41:11 | 000,356,928 | ---- | C] () -- C:\Users\Alexander\Desktop\Fehler FRST64.png
[2014.01.06 21:49:00 | 000,250,314 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\fvstore.dat
[2014.01.06 20:25:45 | 000,377,856 | ---- | C] () -- C:\Users\Alexander\Desktop\gmer_2.1.19163.exe
[2014.01.06 20:21:22 | 000,000,000 | ---- | C] () -- C:\Users\Alexander\defogger_reenable
[2014.01.06 20:19:32 | 000,050,477 | ---- | C] () -- C:\Users\Alexander\Desktop\Defogger.exe
[2014.01.06 19:17:26 | 000,002,031 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2014.01.04 22:47:08 | 000,000,009 | ---- | C] () -- C:\END
[2013.12.26 17:45:52 | 000,002,892 | ---- | C] () -- C:\WINDOWS\SysWow64\audcon.sys
[2013.12.26 17:44:13 | 000,147,425 | ---- | C] () -- C:\WINDOWS\SysNative\SYNSOACC-Aide.chm
[2013.12.26 17:44:13 | 000,120,468 | ---- | C] () -- C:\WINDOWS\SysNative\SYNSOACC-Hilfe.chm
[2013.12.26 17:44:13 | 000,114,279 | ---- | C] () -- C:\WINDOWS\SysNative\SYNSOACC-Help.chm
[2013.12.26 17:44:11 | 000,147,425 | ---- | C] () -- C:\WINDOWS\SysWow64\SYNSOACC-Aide.chm
[2013.12.26 17:44:11 | 000,120,468 | ---- | C] () -- C:\WINDOWS\SysWow64\SYNSOACC-Hilfe.chm
[2013.12.26 17:44:11 | 000,114,279 | ---- | C] () -- C:\WINDOWS\SysWow64\SYNSOACC-Help.chm
[2013.12.26 17:44:08 | 000,000,051 | ---- | C] () -- C:\WINDOWS\SysWow64\SYNSOPOS.exe.cfg
[2013.12.26 17:44:07 | 000,086,016 | ---- | C] () -- C:\WINDOWS\SysWow64\SYNSOPOS.exe
[2013.12.24 15:40:49 | 000,005,107 | ---- | C] () -- C:\Users\Alexander\AppData\Local\recently-used.xbel
[2013.12.20 20:36:58 | 000,001,185 | ---- | C] () -- C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner.lnk
[2013.09.11 17:34:14 | 000,000,401 | ---- | C] () -- C:\Users\Alexander\AppData\Roaming\sp_data.sys
[2013.08.22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013.08.22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013.08.22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013.08.22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013.08.22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013.08.22 04:17:46 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013.08.22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013.08.22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2013.04.26 00:15:21 | 000,024,576 | ---- | C] () -- C:\ProgramData\SetStretch.exe
[2013.04.26 00:15:21 | 000,000,256 | ---- | C] () -- C:\ProgramData\SetStretch.cmd
[2013.04.26 00:15:21 | 000,000,103 | ---- | C] () -- C:\ProgramData\SetStretch.VBS
[2012.07.25 21:22:56 | 000,267,284 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng600.bin
[2012.07.25 21:22:54 | 000,963,376 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng600.bin
[2012.04.20 13:59:44 | 000,001,536 | ---- | C] () -- C:\WINDOWS\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.12.07 00:01:15 | 021,196,664 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.12.07 00:01:15 | 018,642,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013.08.22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013.08.22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013.08.22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 220 bytes -> C:\Users\Alexander\SkyDrive:ms-properties
< End of report > --- --- ---
[/CODE] |