|
Plagegeister aller Art und deren Bekämpfung: Große Zahl Emails die als nicht zustellbar "zurückkommen"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.02.2014, 10:37 | #1 |
| Große Zahl Emails die als nicht zustellbar "zurückkommen" Hallo liebe Gemeinde, seit Kurzem habe ich in meinen emails eine relativ große Anzahl an emails die angeblich zurückkommen als "nicht zustellbar". Es handelt sich um mail-Adressen die ich nie angeschrieben habe. Gestern habe ich den "Spyware terminator" runtergeladen und prüfen lassen.Er hat auch etwas gefunden. An der email Situation hat sich aber nichts geändert. Hat jemand eine Idee? |
27.02.2014, 11:51 | #2 |
/// the machine /// TB-Ausbilder | Große Zahl Emails die als nicht zustellbar "zurückkommen" hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.02.2014, 12:49 | #3 |
| Große Zahl Emails die als nicht zustellbar "zurückkommen" Hallo, hier die Dateien - danke für deine Mühe
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-02-2014 02 Ran by Spree-Reiter (administrator) on ICKE on 27-02-2014 12:41:47 Running from C:\Users\Spree-Reiter\Downloads Windows 8.1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\PROGRAM FILES (X86)\COMMON FILES\COMODO\LAUNCHER_SERVICE.EXE (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CMDAGENT.EXE (Microsoft Corporation) C:\Windows\system32\dashost.exe () C:\PROGRAM FILES (X86)\COMODO\DRAGON\DRAGON_UPDATER.EXE (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Microsoft Corporation) C:\PROGRAM FILES\MICROSOFT OFFICE 15\CLIENTX64\INTEGRATEDOFFICE.EXE (TuneUp Software) C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2014\TUNEUPUTILITIESSERVICE64.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Acer Incorporated) C:\PROGRAM FILES\ACER\ACER POWER MANAGEMENT\EPOWERSVC.EXE (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (ELAN Microelectronics Corp.) C:\PROGRAM FILES\ELANTECH\ETDCTRL.EXE (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CISTRAY.EXE (TuneUp Software) C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2014\TUNEUPUTILITIESAPP64.EXE (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (IvoSoft) C:\PROGRAM FILES\CLASSIC SHELL\CLASSICSTARTMENU.EXE (ELAN Microelectronics Corp.) C:\PROGRAM FILES\ELANTECH\ETDCTRLHELPER.EXE (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER LAUNCH MANAGER\LMEVENT.EXE (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER QUICK ACCESS\QAEVENT.EXE (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER LAUNCH MANAGER\LMTRAY.EXE (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER QUICK ACCESS\QAMSG.EXE (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER QUICK ACCESS\QUICKACCESS.EXE (Microsoft Corporation) C:\WINDOWS\SYSTEM32\SKYDRIVE.EXE (Atheros Communications) C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\BTVSTACK.EXE () C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ACTIVATEDESKTOP.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\HKCMD.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXPERS.EXE (Realtek Semiconductor) C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVCPL64.EXE (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CIS.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE (Acer Incorporated) C:\PROGRAM FILES\ACER\ACER POWER MANAGEMENT\EPOWERTRAY.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXEXT.EXE (Acer Incorporated) C:\PROGRAM FILES\ACER\ACER POWER MANAGEMENT\EPOWEREVENT.EXE (AdTrustMedia) C:\PROGRAM FILES (X86)\ADTRUSTMEDIA\PRIVDOG\1.8.0.18\TRUSTEDADSSVC.EXE (Comodo Security Solutions, Inc.) C:\PROGRAM FILES (X86)\COMMON FILES\COMODO\GEEKBUDDYRSP.EXE (Comodo Security Solutions, Inc.) C:\PROGRAM FILES\COMODO\GEEKBUDDY\UNIT_MANAGER.EXE (Comodo Security Solutions, Inc.) C:\PROGRAM FILES\COMODO\GEEKBUDDY\UNIT.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE (Microsoft Corporation) C:\WINDOWS\SYSTEM32\SETTINGSYNCHOST.EXE (Pokki) C:\USERS\SPREE-REITER\APPDATA\LOCAL\POKKI\ENGINE\POKKI.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CAVWP.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Microsoft Corporation) C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSCOMMUNICATIONSAPPS_17.5.9600.20413_X64__8WEKYB3D8BBWE\LIVECOMM.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PrivDogService] - C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.18\trustedadssvc.exe [525480 2013-12-13] (AdTrustMedia) HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-01-20] (Comodo Security Solutions, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\Run: [Pokki] - C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\Run: [Google Update] - C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-11-29] (Google Inc.) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\RunOnce: [Application Restart #0] - C:\Users\Spree-Reiter\AppData\Local\Pokki\Engine\pokki.exe [8252744 2013-11-01] (Pokki) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_44_Plugin.exe [840584 2014-02-11] (Adobe Systems Incorporated) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= SearchScopes: HKLM - DefaultScope {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKCU - DefaultScope {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP63A11305-6847-459B-A3D1-2E60CDD62C62&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= SearchScopes: HKCU - {08C54410-0A34-483F-97A4-47C36E226903} URL = SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP63A11305-6847-459B-A3D1-2E60CDD62C62&q={searchTerms}&SSPV= SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft) BHO: PrivDog Extension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.18\trustedads.dll (AdTrustMedia) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft) BHO-x32: PrivDog Extension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.18\trustedads.dll (AdTrustMedia) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) DPF: HKLM-x32 {55A2C0CD-3DE8-4264-9637-A0B40B05714E} https://col0-sec.mail.live.com/mail/MailMigrationCabFileHolder.aspx?n=1196651482 Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default FF user.js: detected! => C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\user.js FF DefaultSearchEngine: Mysearchdial FF SelectedSearchEngine: Mysearchdial FF Homepage: www.t-online.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Spree-Reiter\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Spree-Reiter\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: PrivDog - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\PrivDog@AdTrustMedia.com [2013-12-20] FF Extension: SeoQuake - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2013-12-05] FF Extension: Firebug - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\firebug@software.joehewitt.com.xpi [2013-12-05] Chrome: ======= CHR Extension: (PrivDog) - C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja [2013-11-29] CHR Extension: (Google Wallet) - C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-29] CHR HKLM-x32\...\Chrome\Extension: [cmaiofennmphjldldcpphcechfnnohja] - C:\Program Files (x86)\AdTrustMedia\PrivDog\PrivDog_chrome.crx [2013-11-29] ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2797312 2013-11-25] (Acer Incorporated) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-01-20] (Comodo Security Solutions, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6254152 2013-10-20] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [164056 2013-09-24] (COMODO) R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-01-28] () R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-01-20] (Comodo Security Solutions, Inc.) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-10-31] (Microsoft Corporation) R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2103096 2013-12-18] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation) R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2013-05-07] (Windows (R) Win 7 DDK provider) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-09-24] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [715824 2013-11-14] (COMODO) R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [38072 2013-09-24] (COMODO) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [118400 2013-09-24] (COMODO) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-02-26] (Windows (R) Win 7 DDK provider) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-27 12:41 - 2014-02-27 12:42 - 00023471 _____ () C:\Users\Spree-Reiter\Downloads\FRST.txt 2014-02-27 12:41 - 2014-02-27 12:41 - 00000000 ____D () C:\FRST 2014-02-27 12:39 - 2014-02-27 12:39 - 02155520 _____ (Farbar) C:\Users\Spree-Reiter\Downloads\FRST64.exe 2014-02-26 20:01 - 2014-02-27 08:56 - 00089284 _____ () C:\Windows\WindowsUpdate.log 2014-02-26 11:24 - 2014-02-27 11:40 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-26 11:24 - 2014-02-26 11:24 - 00001054 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-02-26 11:22 - 2014-02-26 11:22 - 05049344 _____ (Crawler.com ) C:\Users\Spree-Reiter\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-02-25 10:45 - 2014-02-25 11:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Nico Mak Computing 2014-02-20 08:02 - 2014-02-20 08:02 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\My Weblog Posts 2014-02-17 12:27 - 2014-02-17 12:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-16 18:17 - 2013-11-26 11:13 - 04191232 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-02-16 18:17 - 2013-11-23 04:48 - 00479744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-02-16 18:16 - 2013-12-09 01:34 - 01227264 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll 2014-02-16 18:16 - 2013-12-09 01:04 - 00980480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll 2014-02-16 18:16 - 2013-11-27 16:34 - 03210528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-02-16 18:16 - 2013-11-27 16:27 - 00809872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2014-02-16 18:16 - 2013-11-27 15:00 - 00663680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2014-02-16 18:16 - 2013-11-27 14:47 - 02804528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-02-16 18:16 - 2013-11-27 13:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys 2014-02-16 18:16 - 2013-11-27 11:54 - 00461824 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-02-16 18:16 - 2013-11-27 11:24 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-02-16 18:16 - 2013-11-27 11:08 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-02-16 18:16 - 2013-11-27 10:46 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-02-16 18:16 - 2013-11-27 10:41 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2014-02-16 18:16 - 2013-11-27 10:17 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2014-02-16 18:16 - 2013-11-27 10:10 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll 2014-02-16 18:16 - 2013-11-27 09:58 - 01503232 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2014-02-16 18:16 - 2013-11-27 09:56 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll 2014-02-16 18:16 - 2013-11-27 05:01 - 00385614 _____ () C:\Windows\system32\ApnDatabase.xml 2014-02-16 18:16 - 2013-11-26 14:22 - 01928144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 02131120 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 01374384 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2014-02-16 18:16 - 2013-11-26 12:50 - 01371312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2014-02-16 18:16 - 2013-11-26 12:44 - 02142936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2014-02-16 18:16 - 2013-11-26 12:44 - 01204968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2014-02-16 18:16 - 2013-11-26 10:21 - 18577920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-02-16 18:16 - 2013-11-26 09:28 - 13925888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-02-16 18:16 - 2013-11-25 02:45 - 00142680 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-02-16 18:16 - 2013-11-25 02:32 - 01119064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-02-16 18:16 - 2013-11-25 00:30 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-02-16 18:16 - 2013-11-25 00:28 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-02-16 18:16 - 2013-11-23 13:47 - 00032088 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll 2014-02-16 18:16 - 2013-11-23 12:49 - 21196664 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-02-16 18:16 - 2013-11-23 09:19 - 18642504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-02-16 18:16 - 2013-11-23 08:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\bi.dll 2014-02-16 18:16 - 2013-11-23 08:13 - 00019456 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys 2014-02-16 18:16 - 2013-11-23 08:08 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2014-02-16 18:16 - 2013-11-23 05:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2014-02-16 18:16 - 2013-11-23 04:57 - 00637952 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-02-16 18:16 - 2013-11-23 04:25 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-02-16 18:16 - 2013-11-23 04:25 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-02-16 18:16 - 2013-11-23 04:19 - 02617344 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-02-16 18:16 - 2013-11-23 04:15 - 02295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-02-16 18:16 - 2013-11-21 07:58 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\deviceregistration.dll 2014-02-16 18:16 - 2013-11-21 07:26 - 01415680 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-02-16 18:16 - 2013-11-16 06:11 - 00764856 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2014-02-16 18:16 - 2013-11-15 19:19 - 00669344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-02-16 18:16 - 2013-11-15 15:59 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2014-02-16 18:16 - 2013-11-15 15:25 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2014-02-16 18:16 - 2013-11-15 15:08 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2014-02-16 18:16 - 2013-11-15 14:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-02-16 18:16 - 2013-11-05 21:12 - 02551128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-02-16 18:16 - 2013-10-31 01:29 - 00745336 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-02-16 18:16 - 2013-10-31 00:41 - 00552624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-02-13 12:49 - 2014-02-13 12:49 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-02-13 11:14 - 2014-02-13 11:14 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-02-13 07:18 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 07:18 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 07:18 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 07:18 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 07:18 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 07:18 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 07:18 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 07:18 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 07:18 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 07:18 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 07:18 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 07:18 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 07:18 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 07:18 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 07:18 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 07:18 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 07:18 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 07:18 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 07:18 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 07:18 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 07:18 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 07:18 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 07:18 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 07:18 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 07:18 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 07:18 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 07:18 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 07:18 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 07:18 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 07:18 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 07:18 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 07:18 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 07:18 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 07:18 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 07:18 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 07:18 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 07:18 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 07:18 - 2014-01-07 06:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 07:18 - 2014-01-07 05:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 07:18 - 2013-12-09 01:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 07:18 - 2013-12-09 01:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 07:18 - 2013-12-09 00:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 07:18 - 2013-12-09 00:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 07:18 - 2013-11-21 07:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-13 07:18 - 2013-11-21 06:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 07:17 - 2014-01-07 08:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe 2014-02-13 07:17 - 2014-01-07 06:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe 2014-02-13 07:17 - 2014-01-04 21:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2014-02-13 07:17 - 2014-01-04 20:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll 2014-02-13 07:17 - 2014-01-04 15:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-02-13 07:17 - 2014-01-04 15:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-02-13 07:17 - 2014-01-04 14:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll 2014-02-13 07:17 - 2014-01-04 14:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll 2014-02-13 07:17 - 2014-01-04 14:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll 2014-02-13 07:17 - 2014-01-04 14:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll 2014-02-13 07:17 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms 2014-02-13 07:17 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms 2014-02-13 07:17 - 2013-12-20 11:10 - 01113040 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-02-13 07:17 - 2013-12-20 07:13 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-02-13 07:17 - 2013-12-09 03:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 07:17 - 2013-12-09 02:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 07:16 - 2014-01-09 09:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-02-13 07:16 - 2014-01-09 08:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-02-13 07:16 - 2014-01-09 08:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll 2014-02-13 07:16 - 2014-01-09 08:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-02-13 07:16 - 2014-01-09 08:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll 2014-02-13 07:16 - 2014-01-09 08:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll 2014-02-13 07:16 - 2014-01-09 08:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll 2014-02-13 07:16 - 2014-01-09 08:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll 2014-02-13 07:16 - 2014-01-09 08:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2014-02-13 07:16 - 2014-01-09 08:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe 2014-02-12 18:54 - 2014-02-11 13:19 - 00000426 _____ () C:\AVScanner.ini 2014-02-12 18:47 - 2014-02-12 18:47 - 00710848 _____ ( ) C:\Users\Spree-Reiter\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-02-12 18:45 - 2014-02-12 18:45 - 00552744 _____ (Fusion Install ) C:\Users\Spree-Reiter\Downloads\Groovestream.exe 2014-02-12 18:18 - 2014-02-17 06:40 - 00000000 ____D () C:\Program Files (x86)\FindRight 2014-02-12 18:17 - 2014-02-12 18:36 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\systweak 2014-02-12 18:17 - 2014-02-12 18:36 - 00000000 ____D () C:\Program Files (x86)\RegClean Pro 2014-02-12 18:17 - 2014-02-12 18:36 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-02-12 18:17 - 2014-02-12 18:19 - 00002660 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-12 18:17 - 2014-02-12 18:17 - 00000044 _____ () C:\Users\Spree-Reiter\AppData\Roaming\WB.CFG 2014-02-12 18:17 - 2014-02-12 18:17 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\DigitalSites 2014-02-12 18:17 - 2013-12-27 18:10 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe 2014-02-12 18:16 - 2014-02-12 18:17 - 00000000 ____D () C:\Program Files (x86)\VideoConverter 2014-02-12 18:15 - 2014-02-12 18:16 - 00660792 _____ () C:\Users\Spree-Reiter\Downloads\VideoConverterSetup.exe 2014-02-12 18:12 - 2013-12-18 10:01 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2014-02-12 18:12 - 2013-12-18 10:01 - 00036152 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2014-02-12 18:09 - 2014-02-12 18:09 - 00002225 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2014-02-12 18:09 - 2014-02-12 18:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\TuneUp Software 2014-02-12 18:09 - 2013-12-18 10:01 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2014-02-12 18:09 - 2013-12-18 10:01 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2014-02-12 18:09 - 2013-12-18 10:01 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2014-02-12 18:08 - 2014-02-12 18:12 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2014-02-12 18:07 - 2014-02-13 12:49 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-02-12 18:07 - 2014-02-13 11:15 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-12 18:07 - 2014-02-12 18:10 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Freemake 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\OpenCandy 2014-02-12 18:06 - 2014-02-12 18:06 - 01307976 _____ (Ellora Assets Corporation ) C:\Users\Spree-Reiter\Downloads\FreemakeVideoConverterSetup.exe 2014-02-12 16:53 - 2014-02-12 16:53 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\XMedia Recode 2014-02-12 16:43 - 2014-02-12 16:43 - 00001083 _____ () C:\Users\Public\Desktop\XMedia Recode.lnk 2014-02-12 16:43 - 2014-02-12 16:43 - 00000000 ____D () C:\Program Files (x86)\XMedia Recode 2014-02-12 16:39 - 2014-02-12 16:39 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\AVS4YOU 2014-02-12 16:38 - 2014-02-12 18:33 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-02-12 16:38 - 2014-02-12 16:39 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-02-12 16:38 - 2012-03-23 19:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Aimersoft 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Program Files\Common Files\Aimersoft 2014-02-12 16:20 - 2013-08-23 13:36 - 00721263 _____ () C:\Windows\SysWOW64\AiCM64.dll 2014-02-12 16:20 - 2013-08-07 14:31 - 00214528 _____ () C:\Windows\SysWOW64\AiCM32.dll 2014-02-12 16:19 - 2014-02-12 16:32 - 00000000 ____D () C:\ProgramData\Aimersoft Video Converter Ultimate 2014-02-12 16:19 - 2014-02-12 16:19 - 00000000 ____D () C:\Program Files (x86)\Aimersoft 2014-02-03 16:34 - 2014-02-03 16:34 - 01718176 _____ (Netviewer GmbH) C:\Users\Spree-Reiter\Downloads\nvt_sinr111592749_sipw_sitn_kagu.exe 2014-02-02 14:34 - 2013-08-22 07:57 - 00002131 ___RS () C:\Users\Spree-Reiter\Desktop\Camera.lnk ==================== One Month Modified Files and Folders ======= 2021-10-21 14:36 - 2013-10-25 08:21 - 00000852 _____ () C:\Windows\system32\Drivers\RTKHDRC.dat 2021-10-04 08:34 - 2013-10-25 08:21 - 00000712 _____ () C:\Windows\system32\Drivers\RTMICEQ0.dat 2014-02-27 12:42 - 2014-02-27 12:41 - 00023471 _____ () C:\Users\Spree-Reiter\Downloads\FRST.txt 2014-02-27 12:41 - 2014-02-27 12:41 - 00000000 ____D () C:\FRST 2014-02-27 12:39 - 2014-02-27 12:39 - 02155520 _____ (Farbar) C:\Users\Spree-Reiter\Downloads\FRST64.exe 2014-02-27 12:37 - 2013-11-30 13:54 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\ClassicShell 2014-02-27 12:35 - 2013-11-29 14:48 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-02-27 12:33 - 2013-11-29 20:27 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2071D27F-6F73-4CA7-B28F-3925676B70DA} 2014-02-27 12:17 - 2013-11-29 20:35 - 00001158 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA.job 2014-02-27 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2014-02-27 11:55 - 2013-11-29 20:35 - 00002630 _____ () C:\Users\Spree-Reiter\Desktop\Google Chrome.lnk 2014-02-27 11:40 - 2014-02-26 11:24 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-02-27 11:22 - 2013-11-29 19:53 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3108126898-271320607-1571633106-1001 2014-02-27 11:17 - 2013-11-29 20:35 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core.job 2014-02-27 10:19 - 2013-10-25 17:42 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2014-02-27 10:19 - 2013-10-25 17:42 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2014-02-27 10:19 - 2013-09-05 12:46 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-27 09:51 - 2014-01-03 11:31 - 00005148 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ICKE-Spree-Reiter Icke 2014-02-27 08:56 - 2014-02-26 20:01 - 00089284 _____ () C:\Windows\WindowsUpdate.log 2014-02-27 08:46 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-02-27 08:40 - 2013-11-29 19:46 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Pokki 2014-02-27 08:34 - 2013-11-29 18:10 - 00000000 __RDO () C:\Users\Spree-Reiter\SkyDrive 2014-02-26 11:24 - 2014-02-26 11:24 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-26 11:24 - 2014-02-26 11:24 - 00001054 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-02-26 11:22 - 2014-02-26 11:22 - 05049344 _____ (Crawler.com ) C:\Users\Spree-Reiter\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-02-25 11:09 - 2014-02-25 10:45 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Nico Mak Computing 2014-02-24 21:53 - 2013-11-29 19:46 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Packages 2014-02-24 20:09 - 2013-12-01 18:35 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Deployment 2014-02-24 10:00 - 2013-11-29 14:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-24 10:00 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-21 22:45 - 2013-12-03 11:55 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\CrashDumps 2014-02-20 08:02 - 2014-02-20 08:02 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\My Weblog Posts 2014-02-20 08:02 - 2013-11-30 14:47 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Windows Live Writer 2014-02-18 07:35 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-02-17 22:00 - 2013-12-02 07:29 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 22:00 - 2013-12-02 07:29 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 12:27 - 2014-02-17 12:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-17 09:20 - 2013-11-29 19:47 - 00000000 ___RD () C:\Users\Spree-Reiter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-17 09:20 - 2013-11-29 19:47 - 00000000 ___RD () C:\Users\Spree-Reiter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-17 06:40 - 2014-02-12 18:18 - 00000000 ____D () C:\Program Files (x86)\FindRight 2014-02-17 06:40 - 2013-08-22 15:44 - 00505312 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-17 06:39 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ToastData 2014-02-17 06:39 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-02-17 06:39 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Dism 2014-02-17 06:39 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-02-17 06:26 - 2013-12-01 18:29 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 06:23 - 2013-12-01 18:29 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-14 11:12 - 2013-11-29 20:35 - 00004118 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA 2014-02-14 11:12 - 2013-11-29 20:35 - 00003738 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core 2014-02-13 12:49 - 2014-02-13 12:49 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-02-13 12:49 - 2014-02-12 18:07 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-02-13 11:36 - 2013-11-29 19:46 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\VirtualStore 2014-02-13 11:15 - 2014-02-12 18:07 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-13 11:14 - 2014-02-13 11:14 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\MediaViewer 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\FileManager 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Camera 2014-02-12 18:47 - 2014-02-12 18:47 - 00710848 _____ ( ) C:\Users\Spree-Reiter\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-02-12 18:45 - 2014-02-12 18:45 - 00552744 _____ (Fusion Install ) C:\Users\Spree-Reiter\Downloads\Groovestream.exe 2014-02-12 18:36 - 2014-02-12 18:17 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\systweak 2014-02-12 18:36 - 2014-02-12 18:17 - 00000000 ____D () C:\Program Files (x86)\RegClean Pro 2014-02-12 18:36 - 2014-02-12 18:17 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-02-12 18:33 - 2014-02-12 16:38 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-02-12 18:19 - 2014-02-12 18:17 - 00002660 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-12 18:17 - 2014-02-12 18:17 - 00000044 _____ () C:\Users\Spree-Reiter\AppData\Roaming\WB.CFG 2014-02-12 18:17 - 2014-02-12 18:17 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\DigitalSites 2014-02-12 18:17 - 2014-02-12 18:16 - 00000000 ____D () C:\Program Files (x86)\VideoConverter 2014-02-12 18:16 - 2014-02-12 18:15 - 00660792 _____ () C:\Users\Spree-Reiter\Downloads\VideoConverterSetup.exe 2014-02-12 18:12 - 2014-02-12 18:08 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2014-02-12 18:10 - 2014-02-12 18:07 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-12 18:09 - 2014-02-12 18:09 - 00002225 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2014-02-12 18:09 - 2014-02-12 18:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\TuneUp Software 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Freemake 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\OpenCandy 2014-02-12 18:06 - 2014-02-12 18:06 - 01307976 _____ (Ellora Assets Corporation ) C:\Users\Spree-Reiter\Downloads\FreemakeVideoConverterSetup.exe 2014-02-12 16:53 - 2014-02-12 16:53 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\XMedia Recode 2014-02-12 16:43 - 2014-02-12 16:43 - 00001083 _____ () C:\Users\Public\Desktop\XMedia Recode.lnk 2014-02-12 16:43 - 2014-02-12 16:43 - 00000000 ____D () C:\Program Files (x86)\XMedia Recode 2014-02-12 16:39 - 2014-02-12 16:39 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\AVS4YOU 2014-02-12 16:39 - 2014-02-12 16:38 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-02-12 16:32 - 2014-02-12 16:19 - 00000000 ____D () C:\ProgramData\Aimersoft Video Converter Ultimate 2014-02-12 16:30 - 2013-12-03 21:28 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\vlc 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Aimersoft 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Program Files\Common Files\Aimersoft 2014-02-12 16:19 - 2014-02-12 16:19 - 00000000 ____D () C:\Program Files (x86)\Aimersoft 2014-02-11 13:19 - 2014-02-12 18:54 - 00000426 _____ () C:\AVScanner.ini 2014-02-10 17:21 - 2013-11-29 15:40 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\FileZilla 2014-02-07 15:40 - 2013-11-29 15:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Bluetooth Folder 2014-02-06 13:16 - 2014-02-13 07:18 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 07:18 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 07:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 07:18 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 07:18 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 07:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 07:18 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 07:18 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:49 - 2014-02-13 07:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 07:18 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 07:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 07:18 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 07:18 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 07:18 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 07:18 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 07:18 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 07:18 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 07:18 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 07:18 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 07:18 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 07:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 07:18 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 07:18 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:47 - 2014-02-13 07:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 07:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 07:18 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 07:18 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 07:18 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 07:18 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 07:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 07:18 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 07:18 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 07:18 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 07:18 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 07:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 07:18 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 07:18 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-03 16:34 - 2014-02-03 16:34 - 01718176 _____ (Netviewer GmbH) C:\Users\Spree-Reiter\Downloads\nvt_sinr111592749_sipw_sitn_kagu.exe 2014-01-30 07:23 - 2014-01-03 10:00 - 00057096 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll 2014-01-30 07:23 - 2014-01-03 10:00 - 00048392 _____ (COMODO CA Limited) C:\Windows\SysWOW64\certsentry.dll 2014-01-30 07:23 - 2013-11-29 14:47 - 00000000 ____D () C:\Program Files (x86)\Comodo ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-19 06:18 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2014 02 Ran by Spree-Reiter at 2014-02-27 12:43:04 Running from C:\Users\Spree-Reiter\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: COMODO Antivirus (Enabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: COMODO Antivirus (Enabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} FW: COMODO Firewall (Enabled) {8F7746F7-FE68-E084-3B6C-7404A51E8FB3} ==================== Installed Programs ====================== Acer Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.03.2002 - Acer Incorporated) Acer Docs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 2.04.2001 - Acer) Acer Games (HKCU\...\Pokki_03d432a7e610c3e908213e7689d4342ce2111caf) (Version: 1.1.9.43466 - Pokki) Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8101 - Acer Incorporated) Acer Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.03.2004.0 - Acer Incorporated) Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.04.2002 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8100 - Acer Incorporated) Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.00.3000 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8100 - Acer Incorporated) Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.00.3007 - Acer Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden Broadcom Card Reader Driver Installer (HKLM\...\{67AA948F-8D83-4566-B84A-7CAABCF64E3F}) (Version: 16.0.2.8 - Broadcom Corporation) Broadcom NetLink Controller (HKLM\...\{D1D7ED66-5C08-40A0-AEC0-B6DF977697BB}) (Version: 16.2.1.2 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) Classic Shell (HKLM\...\{98BB5224-BC5D-4028-9D20-536C1C263AA9}) (Version: 4.0.2 - IvoSoft) Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 31.1.0.0 - COMODO) COMODO Internet Security Premium (HKLM\...\{093F13A3-177C-493E-8958-912A0C690B64}) (Version: 6.3.32439.2937 - COMODO Security Solutions Inc.) Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3126.57 - CyberLink Corp.) CyberLink PowerDVD 12 (x32 Version: 12.0.3126.57 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 14.4.20130909 - Landesfinanzdirektion Thüringen) ETDWare PS/2-X64 11.6.27.201_WHQL (HKLM\...\Elantech) (Version: 11.6.27.201 - ELAN Microelectronic Corp.) Exact Audio Copy 1.0beta3 (HKLM-x32\...\Exact Audio Copy) (Version: 1.0beta3 - Andre Wiethoff) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Free Mp3 Wma Converter V 2.2 (HKLM-x32\...\Free Mp3 Wma Converter_is1) (Version: 2.2.0.0 - Koyote Soft) Free WMA to MP3 Converter 1.16 (HKLM-x32\...\Free WMA to MP3 Converter_is1) (Version: - Jodix Technologies Ltd.) GeekBuddy (HKLM\...\{7137372F-6AD2-40C2-A794-F4A3BE5A98F8}) (Version: 4.10.86 - Comodo Security Solutions Inc) Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.117 - Google Inc.) Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8100 - Acer Incorporated) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated) Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2000 Premium (HKLM-x32\...\{00000407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2816 - Microsoft Corporation) Microsoft Office 365 Home Premium - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4551.1512 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Nero BackItUp (x32 Version: 12.5.11000 - Nero AG) Hidden Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG) Nero BackItUp Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden Nero ControlCenter (x32 Version: 11.0.15900 - Nero AG) Hidden Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.20900 - Nero AG) Hidden Nero Launcher (x32 Version: 12.2.7000 - Nero AG) Hidden Nero RescueAgent (x32 Version: 12.0.3001 - Nero AG) Hidden Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden NetObjects Fusion 12.0 (HKLM-x32\...\{76EE00F5-A435-49B1-970C-00A086A01E79}) (Version: 12 German - NetObjects) NetObjects Fusion 12.0 (x32 Version: 12.00.5000.5041 - NetObjects) Hidden Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1512 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1512 - Microsoft Corporation) Hidden Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2009 - Acer) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Pokki (HKCU\...\Pokki) (Version: 0.266.1.172 - Pokki) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden PrivDog (HKLM-x32\...\PrivDog) (Version: 1.8.0.15 - privdog.com) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.305 - Qualcomm Atheros Communications) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.05 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.) Spotify (HKLM-x32\...\Spotify) (Version: 0.9.1.57.ge7405149 - Spotify AB) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.221 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.221 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.221 - TuneUp Software) Hidden Turbo Lister 2 (HKLM-x32\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) VR-NetWorld (HKLM-x32\...\{8815F011-43AF-4F50-BBD8-D78ED3D6F5B9}) (Version: - ) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden XMedia Recode Version 3.1.7.9 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.7.9 - XMedia Recode) ==================== Restore Points ========================= 12-02-2014 17:23:33 RegClean Pro Mi, Feb 12, 14 18:23 17-02-2014 05:22:50 Windows Update 21-02-2014 05:16:48 Windows Update ==================== Hosts content: ========================== 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {1B7E600F-99B3-4165-BD71-0524B8284038} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {2C9DE1E1-617F-46C9-9A22-BFF4039A7120} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2013-08-03] (Acer Incorporate) Task: {32BD347C-B113-4568-8509-6FA3D8EA3877} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ICKE-Spree-Reiter Icke => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-01-15] (Microsoft Corporation) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3DEC0B59-24E4-4906-9708-242DEC54DE24} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-01-15] (Microsoft Corporation) Task: {48F959A5-E756-4221-B567-E17E8C1091B6} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] () Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {5EBDA711-E61F-4F9F-9C20-26CF78042E54} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2013-08-02] (Acer Incorporate) Task: {60313B80-7FEF-4C7C-925F-26C944D1A8F1} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {71E6448B-6AEF-4569-B37A-8731E40F43B3} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-11-11] (COMODO) Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {7586EE01-8EC0-49F6-A606-C95766FB8040} - System32\Tasks\Digital Sites => C:\Users\SPREE-~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {7CBD5A26-FE5C-469D-B406-09AD61966945} - System32\Tasks\Google Updater and Installer => C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-29] (Google Inc.) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8E201BC1-CA74-425E-A8F6-395747FDBC3C} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] () Task: {90DE70AA-A921-4A7B-9FD8-5D3C7B290412} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {9870D995-2687-494E-9B4F-A047580861C7} - System32\Tasks\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2013-11-20] (COMODO) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A3850D92-D1E5-4320-B888-CE02338FE887} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe [2013-11-25] (Acer Incorporated) Task: {BA8BF6B8-7E4B-4433-B839-D55985B7EBDD} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2013-12-18] (TuneUp Software) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D50FEF16-BE42-4B57-BDF9-8D296EB5A31C} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {D806E467-6DFC-41F7-B9C6-A51D7ADACE62} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2013-07-10] (Acer Incorporated) Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {D9C69297-FFAE-4232-87DB-DFD1655E2E29} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-10-31] (Microsoft Corporation) Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DC84ECD9-8E51-4B6D-BCDC-9321B507219A} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-11-11] (COMODO) Task: {E2DD089E-D25A-492A-BAF7-096816C6A381} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core => C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-29] (Google Inc.) Task: {E3B2EFEC-055E-463B-BA93-3C9CD56BAECA} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\SYSTEM32\MRT.EXE [2014-02-17] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E729E35B-7403-442C-B923-9C51A94991CE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA => C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-29] (Google Inc.) Task: {ED24A0D9-EBAB-430E-9C3A-70736D60390A} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2013-07-05] (Acer Incorporated) Task: {FC90447E-F9A5-4688-A2E2-2B3C4A9644C9} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core.job => C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA.job => C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-28 15:35 - 2014-01-28 15:35 - 02135232 _____ () C:\PROGRAM FILES (X86)\COMODO\DRAGON\DRAGON_UPDATER.EXE 2013-11-30 13:38 - 2013-08-23 14:45 - 00386216 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2rui.dll 2013-11-30 13:38 - 2013-10-31 09:08 - 00520872 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2r64.dll 2013-11-30 13:38 - 2013-10-31 09:07 - 00618152 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll 2013-12-18 10:01 - 2013-12-18 10:01 - 00742200 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2014-02-12 16:20 - 2013-08-23 13:36 - 00721263 _____ () C:\Windows\SysWOW64\AiCM64.dll 2013-09-07 00:48 - 2013-09-07 00:48 - 00011264 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll 2013-09-07 00:45 - 2013-09-07 00:45 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll 2013-09-07 00:52 - 2013-09-07 00:52 - 00012928 _____ () C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ACTIVATEDESKTOP.EXE 2013-09-13 08:27 - 2013-09-03 20:45 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-01-20 13:15 - 2014-01-20 13:15 - 02875600 _____ () C:\PROGRAM FILES\COMODO\GEEKBUDDY\QtCore4.dll 2014-01-20 13:15 - 2014-01-20 13:15 - 01283792 _____ () C:\PROGRAM FILES\COMODO\GEEKBUDDY\QtNetwork4.dll 2014-01-20 13:15 - 2014-01-20 13:15 - 10451664 _____ () C:\PROGRAM FILES\COMODO\GEEKBUDDY\QtGui4.dll 2014-01-20 13:15 - 2014-01-20 13:15 - 00039120 _____ () C:\PROGRAM FILES\COMODO\GEEKBUDDY\imageformats\qgif4.dll 2014-01-20 13:15 - 2014-01-20 13:15 - 01529040 _____ () C:\PROGRAM FILES\COMODO\GEEKBUDDY\QtScript4.dll 2013-04-15 18:39 - 2013-04-15 18:39 - 00073424 _____ () C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\scanners\smart.cav 2014-01-28 15:35 - 2014-01-28 15:35 - 02135232 _____ () C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe 2013-10-25 08:13 - 2013-09-04 00:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-02-22 20:19 - 2014-02-20 02:02 - 00051016 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll 2013-10-25 08:42 - 2013-07-30 17:11 - 00088648 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll 2014-02-22 20:19 - 2014-02-20 02:02 - 00716616 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\libglesv2.dll 2014-02-22 20:19 - 2014-02-20 02:02 - 00100168 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\libegl.dll 2014-02-22 20:19 - 2014-02-20 02:02 - 01647432 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll 2014-02-22 20:19 - 2014-02-20 02:03 - 13632840 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll 2014-02-22 20:19 - 2014-02-20 02:03 - 04060488 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\pdf.dll 2014-02-22 20:19 - 2014-02-20 02:03 - 00394568 _____ () C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Spree-Reiter\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/27/2014 08:15:30 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/27/2014 06:08:49 AM) (Source: Desktop Window Manager) (User: ) Description: Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d) festgestellt. Error: (02/26/2014 08:15:32 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/25/2014 08:15:20 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/24/2014 10:10:42 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/24/2014 10:04:04 AM) (Source: ESENT) (User: ) Description: LiveComm (3556) C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: Bei Datenbankwiederherstellung trat ein unerwarteter Fehler -543 auf. Error: (02/24/2014 10:04:04 AM) (Source: ESENT) (User: ) Description: LiveComm (3556) C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: Die Datenbank 'C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\livecomm.edb' erfordert die Protokolldateien '96' - '101' (C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb00060.log - C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb.log) für eine erfolgreiche Wiederherstellung. Es wurden nur Protokolldateien bis '100' (LiveComm0) gefunden. Error: (02/23/2014 06:59:00 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: wlmail.exe, Version: 16.4.3508.205, Zeitstempel: 0x5111f9fe Name des fehlerhaften Moduls: MAILCOMM.dll, Version: 16.4.3508.205, Zeitstempel: 0x5111f96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000fce1 ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xwlmail.exe0 Pfad der fehlerhaften Anwendung: wlmail.exe1 Pfad des fehlerhaften Moduls: wlmail.exe2 Berichtskennung: wlmail.exe3 Vollständiger Name des fehlerhaften Pakets: wlmail.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: wlmail.exe5 Error: (02/23/2014 08:15:21 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/22/2014 08:25:55 PM) (Source: ESENT) (User: ) Description: LiveComm (8896) C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb00063.log. System errors: ============= Error: (02/27/2014 00:37:55 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Software Protection" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/27/2014 00:37:55 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Software Protection erreicht. Error: (02/24/2014 09:53:57 PM) (Source: DCOM) (User: ICKE) Description: AnwendungsspezifischLokalAktivierung{9E175B6D-F52A-11D8-B9A5-505054503030}{9E175B9C-F52A-11D8-B9A5-505054503030}IckeSpree-ReiterS-1-5-21-3108126898-271320607-1571633106-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarS-1-15-2-4017773024-1875688532-1103376104-1249181219-973294121-404267584-2305394653 Error: (02/24/2014 10:00:21 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 24.02.2014 um 06:02:59 unerwartet heruntergefahren. Error: (02/22/2014 03:04:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "AppX-Bereitstellungsdienst (AppXSVC)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/22/2014 03:04:56 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst AppX-Bereitstellungsdienst (AppXSVC) erreicht. Error: (02/18/2014 07:12:00 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "AppX-Bereitstellungsdienst (AppXSVC)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/18/2014 07:12:00 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst AppX-Bereitstellungsdienst (AppXSVC) erreicht. Error: (02/17/2014 06:41:05 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Util FindRight" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/16/2014 04:42:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "AppX-Bereitstellungsdienst (AppXSVC)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (02/27/2014 08:15:30 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/27/2014 06:08:49 AM) (Source: Desktop Window Manager)(User: ) Description: 0x8898008d Error: (02/26/2014 08:15:32 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/25/2014 08:15:20 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/24/2014 10:10:42 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/24/2014 10:04:04 AM) (Source: ESENT)(User: ) Description: LiveComm3556C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: -543 Error: (02/24/2014 10:04:04 AM) (Source: ESENT)(User: ) Description: LiveComm3556C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\livecomm.edb96101100C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb00060.logC:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb.logC:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb00064.log Error: (02/23/2014 06:59:00 PM) (Source: Application Error)(User: ) Description: wlmail.exe16.4.3508.2055111f9feMAILCOMM.dll16.4.3508.2055111f96fc00000050000fce1 Error: (02/23/2014 08:15:21 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073415161 Error: (02/22/2014 08:25:55 PM) (Source: ESENT)(User: ) Description: LiveComm8896C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\: C:\Users\Spree-Reiter\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\42c13629cff9cb09\120712-0049\DBStore\LogFiles\edb00063.log-1811 (0xfffff8ed) CodeIntegrity Errors: =================================== Date: 2014-02-27 12:38:07.854 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 12:36:13.442 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 11:56:34.087 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 11:46:29.475 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 11:36:25.147 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 10:14:41.091 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 10:04:36.634 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 09:54:32.097 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 09:44:27.136 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2014-02-27 09:14:13.719 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 3985.27 MB Available physical RAM: 1889.35 MB Total Pagefile: 6545.27 MB Available Pagefile: 3137.84 MB Total Virtual: 131072 MB Available Virtual: 131071.78 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:448.19 GB) (Free:391.88 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 97E92D33) Partition: GPT Partition Type. ==================== End Of Log ============================ |
28.02.2014, 13:57 | #4 |
/// the machine /// TB-Ausbilder | Große Zahl Emails die als nicht zustellbar "zurückkommen" Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.03.2014, 17:43 | #5 |
| Große Zahl Emails die als nicht zustellbar "zurückkommen"Code:
ATTFilter # AdwCleaner v3.020 - Bericht erstellt am 03/03/2014 um 12:41:39 # Aktualisiert 27/02/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Spree-Reiter - ICKE # Gestartet von : C:\Users\Spree-Reiter\Downloads\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk Datei Gefunden : C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\searchplugins\conduit-search.xml Datei Gefunden : C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\user.js Datei Gefunden : C:\Windows\System32\roboot64.exe Ordner Gefunden C:\Program Files (x86)\FindRight Ordner Gefunden C:\Program Files (x86)\MyPC Backup Ordner Gefunden C:\Program Files (x86)\RegClean Pro Ordner Gefunden C:\ProgramData\boost_interprocess Ordner Gefunden C:\Users\Spree-Reiter\AppData\Local\Pokki Ordner Gefunden C:\Users\Spree-Reiter\AppData\Roaming\DigitalSites Ordner Gefunden C:\Users\Spree-Reiter\AppData\Roaming\OpenCandy Ordner Gefunden C:\Users\Spree-Reiter\AppData\Roaming\Systweak ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\Classes\pokki Schlüssel Gefunden : HKCU\Software\dsiteproducts Schlüssel Gefunden : HKCU\Software\InstallCore Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki Schlüssel Gefunden : HKCU\Software\Pokki Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : HKCU\Software\systweak Schlüssel Gefunden : HKCU\Software\WEDLMNGR Schlüssel Gefunden : [x64] HKCU\Software\dsiteproducts Schlüssel Gefunden : [x64] HKCU\Software\InstallCore Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : [x64] HKCU\Software\Pokki Schlüssel Gefunden : [x64] HKCU\Software\Softonic Schlüssel Gefunden : [x64] HKCU\Software\systweak Schlüssel Gefunden : [x64] HKCU\Software\WEDLMNGR Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Schlüssel Gefunden : HKLM\Software\systweak Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Wert Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki] ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1461470245&ir= -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\prefs.js ] Zeile gefunden : user_pref("browser.search.defaultenginename", "Mysearchdial"); Zeile gefunden : user_pref("browser.search.selectedEngine", "Mysearchdial"); Zeile gefunden : user_pref("extensions.mysearchdial.AL", 2); Zeile gefunden : user_pref("extensions.mysearchdial.aflt", "irmsd0202ch"); Zeile gefunden : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); Zeile gefunden : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R"); Zeile gefunden : user_pref("extensions.mysearchdial.cr", "1461470245"); Zeile gefunden : user_pref("extensions.mysearchdial.dfltLng", ""); Zeile gefunden : user_pref("extensions.mysearchdial.dfltSrch", true); Zeile gefunden : user_pref("extensions.mysearchdial.dnsErr", true); Zeile gefunden : user_pref("extensions.mysearchdial.excTlbr", false); Zeile gefunden : user_pref("extensions.mysearchdial.hmpg", true); Zeile gefunden : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...] Zeile gefunden : user_pref("extensions.mysearchdial.id", "A4DB3076BE6D9C4C"); Zeile gefunden : user_pref("extensions.mysearchdial.instlDay", "16113"); Zeile gefunden : user_pref("extensions.mysearchdial.instlRef", ""); Zeile gefunden : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1C[...] Zeile gefunden : user_pref("extensions.mysearchdial.prdct", "mysearchdial"); Zeile gefunden : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); Zeile gefunden : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); Zeile gefunden : user_pref("extensions.mysearchdial.tlbrId", "base"); Zeile gefunden : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyByC0B0EyC0Dzy0CyE0CtN0D0Tzu0SyByByEtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L[...] Zeile gefunden : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); Zeile gefunden : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); Zeile gefunden : user_pref("extensions.mysearchdial_i.hmpg", true); Zeile gefunden : user_pref("extensions.mysearchdial_i.newTab", false); Zeile gefunden : user_pref("extensions.mysearchdial_i.smplGrp", "none"); Zeile gefunden : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.018:17:1"); -\\ Google Chrome v [ Datei : C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [7713 octets] - [03/03/2014 12:41:39] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7773 octets] ########## FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-03-2014 Ran by Spree-Reiter (administrator) on ICKE on 03-03-2014 17:40:19 Running from C:\Users\Spree-Reiter\Downloads Windows 8.1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (ELAN Microelectronics Corp.) C:\PROGRAM FILES\ELANTECH\ETDCTRL.EXE (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CISTRAY.EXE (IvoSoft) C:\PROGRAM FILES\CLASSIC SHELL\CLASSICSTARTMENU.EXE (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER QUICK ACCESS\QAEVENT.EXE (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe (Acer Incorporate) C:\PROGRAM FILES\ACER\ACER QUICK ACCESS\QUICKACCESS.EXE (Microsoft Corporation) C:\WINDOWS\SYSTEM32\SKYDRIVE.EXE (Atheros Communications) C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\BTVSTACK.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE () C:\PROGRAM FILES (X86)\BLUETOOTH SUITE\ACTIVATEDESKTOP.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\HKCMD.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXPERS.EXE (Realtek Semiconductor) C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVCPL64.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE (Comodo Security Solutions, Inc.) C:\PROGRAM FILES (X86)\COMMON FILES\COMODO\GEEKBUDDYRSP.EXE (COMODO) C:\PROGRAM FILES\COMODO\COMODO INTERNET SECURITY\CIS.EXE (Acer Incorporated) C:\PROGRAM FILES\ACER\ACER POWER MANAGEMENT\EPOWERTRAY.EXE (Intel Corporation) C:\WINDOWS\SYSTEM32\IGFXEXT.EXE (Microsoft Corporation) C:\PROGRAM FILES\WINDOWSAPPS\MICROSOFT.WINDOWSCOMMUNICATIONSAPPS_17.5.9600.20413_X64__8WEKYB3D8BBWE\LIVECOMM.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE (Google Inc.) C:\USERS\SPREE-REITER\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\Run: [Google Update] - C:\Users\Spree-Reiter\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-11-29] (Google Inc.) HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\RunOnce: [Application Restart #0] - C:\Users\Spree-Reiter\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\Spree-Reiter\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session HKU\S-1-5-21-3108126898-271320607-1571633106-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB SearchScopes: HKLM - DefaultScope {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 - {08C54410-0A34-483F-97A4-47C36E226903} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKCU - {08C54410-0A34-483F-97A4-47C36E226903} URL = SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft) BHO: PrivDog Extension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.18\trustedads.dll (AdTrustMedia) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) DPF: HKLM-x32 {55A2C0CD-3DE8-4264-9637-A0B40B05714E} https://col0-sec.mail.live.com/mail/MailMigrationCabFileHolder.aspx?n=1196651482 Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default FF Homepage: www.t-online.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Spree-Reiter\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Spree-Reiter\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: PrivDog - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\PrivDog@AdTrustMedia.com [2013-12-20] FF Extension: SeoQuake - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2013-12-05] FF Extension: Firebug - C:\Users\Spree-Reiter\AppData\Roaming\Mozilla\Firefox\Profiles\f0gzgcqg.default\Extensions\firebug@software.joehewitt.com.xpi [2013-12-05] Chrome: ======= CHR Extension: (PrivDog) - C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja [2013-11-29] CHR Extension: (Google Wallet) - C:\Users\Spree-Reiter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-29] CHR HKLM-x32\...\Chrome\Extension: [cmaiofennmphjldldcpphcechfnnohja] - C:\Program Files (x86)\AdTrustMedia\PrivDog\PrivDog_chrome.crx [2013-11-29] ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2797312 2013-11-25] (Acer Incorporated) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6254152 2013-10-20] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [164056 2013-09-24] (COMODO) R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-01-28] () R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-10-31] (Microsoft Corporation) R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation) R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2013-05-07] (Windows (R) Win 7 DDK provider) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-09-24] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [715824 2013-11-14] (COMODO) R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [38072 2013-09-24] (COMODO) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [118400 2013-09-24] (COMODO) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-02-26] (Windows (R) Win 7 DDK provider) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-03 17:40 - 2014-03-03 17:40 - 00000000 ____D () C:\Users\Spree-Reiter\Downloads\FRST-OlderVersion 2014-03-03 14:51 - 2014-03-03 14:51 - 00001450 _____ () C:\Users\Spree-Reiter\Desktop\JRT.txt 2014-03-03 13:30 - 2014-03-03 13:30 - 00000000 ____D () C:\Windows\ERUNT 2014-03-03 13:29 - 2014-03-03 13:29 - 01037734 _____ (Thisisu) C:\Users\Spree-Reiter\Downloads\JRT.exe 2014-03-03 13:25 - 2014-03-03 13:37 - 00058530 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-03-03 13:25 - 2014-03-03 13:25 - 00000000 ___HD () C:\VTRoot 2014-03-03 13:19 - 2014-03-03 13:19 - 00001394 _____ () C:\Windows\PFRO.log 2014-03-03 12:40 - 2014-03-03 13:18 - 00000000 ____D () C:\AdwCleaner 2014-03-03 12:40 - 2014-03-03 12:40 - 01244192 _____ () C:\Users\Spree-Reiter\Downloads\adwcleaner.exe 2014-02-27 12:43 - 2014-02-27 12:44 - 00036680 _____ () C:\Users\Spree-Reiter\Downloads\Addition.txt 2014-02-27 12:41 - 2014-03-03 17:40 - 00018648 _____ () C:\Users\Spree-Reiter\Downloads\FRST.txt 2014-02-27 12:41 - 2014-03-03 17:40 - 00000000 ____D () C:\FRST 2014-02-27 12:39 - 2014-03-03 17:40 - 02156544 _____ (Farbar) C:\Users\Spree-Reiter\Downloads\FRST64.exe 2014-02-26 20:01 - 2014-03-03 15:45 - 00399491 _____ () C:\Windows\WindowsUpdate.log 2014-02-26 11:24 - 2014-02-28 15:21 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-26 11:24 - 2014-02-26 11:24 - 00001054 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-02-26 11:22 - 2014-02-26 11:22 - 05049344 _____ (Crawler.com ) C:\Users\Spree-Reiter\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-02-25 10:45 - 2014-02-25 11:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Nico Mak Computing 2014-02-20 08:02 - 2014-02-20 08:02 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\My Weblog Posts 2014-02-17 12:27 - 2014-02-17 12:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-16 18:17 - 2013-11-26 11:13 - 04191232 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-02-16 18:17 - 2013-11-23 04:48 - 00479744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-02-16 18:16 - 2013-12-09 01:34 - 01227264 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll 2014-02-16 18:16 - 2013-12-09 01:04 - 00980480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll 2014-02-16 18:16 - 2013-11-27 16:34 - 03210528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-02-16 18:16 - 2013-11-27 16:27 - 00809872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2014-02-16 18:16 - 2013-11-27 15:00 - 00663680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2014-02-16 18:16 - 2013-11-27 14:47 - 02804528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-02-16 18:16 - 2013-11-27 13:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys 2014-02-16 18:16 - 2013-11-27 11:54 - 00461824 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-02-16 18:16 - 2013-11-27 11:24 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-02-16 18:16 - 2013-11-27 11:08 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-02-16 18:16 - 2013-11-27 10:46 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-02-16 18:16 - 2013-11-27 10:41 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2014-02-16 18:16 - 2013-11-27 10:17 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2014-02-16 18:16 - 2013-11-27 10:10 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll 2014-02-16 18:16 - 2013-11-27 09:58 - 01503232 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2014-02-16 18:16 - 2013-11-27 09:56 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll 2014-02-16 18:16 - 2013-11-27 05:01 - 00385614 _____ () C:\Windows\system32\ApnDatabase.xml 2014-02-16 18:16 - 2013-11-26 14:22 - 01928144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 02131120 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2014-02-16 18:16 - 2013-11-26 14:20 - 01374384 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2014-02-16 18:16 - 2013-11-26 12:50 - 01371312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2014-02-16 18:16 - 2013-11-26 12:44 - 02142936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2014-02-16 18:16 - 2013-11-26 12:44 - 01204968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2014-02-16 18:16 - 2013-11-26 10:21 - 18577920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-02-16 18:16 - 2013-11-26 09:28 - 13925888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-02-16 18:16 - 2013-11-25 02:45 - 00142680 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-02-16 18:16 - 2013-11-25 02:32 - 01119064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-02-16 18:16 - 2013-11-25 00:30 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-02-16 18:16 - 2013-11-25 00:28 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-02-16 18:16 - 2013-11-23 13:47 - 00032088 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll 2014-02-16 18:16 - 2013-11-23 12:49 - 21196664 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-02-16 18:16 - 2013-11-23 09:19 - 18642504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-02-16 18:16 - 2013-11-23 08:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\bi.dll 2014-02-16 18:16 - 2013-11-23 08:13 - 00019456 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys 2014-02-16 18:16 - 2013-11-23 08:08 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2014-02-16 18:16 - 2013-11-23 05:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2014-02-16 18:16 - 2013-11-23 04:57 - 00637952 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-02-16 18:16 - 2013-11-23 04:25 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-02-16 18:16 - 2013-11-23 04:25 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-02-16 18:16 - 2013-11-23 04:19 - 02617344 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-02-16 18:16 - 2013-11-23 04:15 - 02295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-02-16 18:16 - 2013-11-21 07:58 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\deviceregistration.dll 2014-02-16 18:16 - 2013-11-21 07:26 - 01415680 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-02-16 18:16 - 2013-11-16 06:11 - 00764856 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2014-02-16 18:16 - 2013-11-15 19:19 - 00669344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-02-16 18:16 - 2013-11-15 15:59 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2014-02-16 18:16 - 2013-11-15 15:25 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2014-02-16 18:16 - 2013-11-15 15:08 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2014-02-16 18:16 - 2013-11-15 14:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-02-16 18:16 - 2013-11-05 21:12 - 02551128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-02-16 18:16 - 2013-10-31 01:29 - 00745336 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-02-16 18:16 - 2013-10-31 00:41 - 00552624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-02-13 12:49 - 2014-02-13 12:49 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-02-13 07:18 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 07:18 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 07:18 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 07:18 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 07:18 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 07:18 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 07:18 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 07:18 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 07:18 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 07:18 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 07:18 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 07:18 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 07:18 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 07:18 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 07:18 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 07:18 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 07:18 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 07:18 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 07:18 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 07:18 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 07:18 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 07:18 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 07:18 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 07:18 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 07:18 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 07:18 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 07:18 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 07:18 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 07:18 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 07:18 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 07:18 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 07:18 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 07:18 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 07:18 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 07:18 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 07:18 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 07:18 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 07:18 - 2014-01-07 06:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 07:18 - 2014-01-07 05:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 07:18 - 2013-12-09 01:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 07:18 - 2013-12-09 01:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 07:18 - 2013-12-09 00:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 07:18 - 2013-12-09 00:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 07:18 - 2013-11-21 07:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-13 07:18 - 2013-11-21 06:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 07:17 - 2014-01-07 08:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe 2014-02-13 07:17 - 2014-01-07 06:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe 2014-02-13 07:17 - 2014-01-04 21:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2014-02-13 07:17 - 2014-01-04 20:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll 2014-02-13 07:17 - 2014-01-04 15:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-02-13 07:17 - 2014-01-04 15:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-02-13 07:17 - 2014-01-04 14:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll 2014-02-13 07:17 - 2014-01-04 14:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll 2014-02-13 07:17 - 2014-01-04 14:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll 2014-02-13 07:17 - 2014-01-04 14:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll 2014-02-13 07:17 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms 2014-02-13 07:17 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms 2014-02-13 07:17 - 2013-12-20 11:10 - 01113040 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-02-13 07:17 - 2013-12-20 07:13 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-02-13 07:17 - 2013-12-09 03:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 07:17 - 2013-12-09 02:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 07:16 - 2014-01-09 09:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-02-13 07:16 - 2014-01-09 08:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-02-13 07:16 - 2014-01-09 08:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll 2014-02-13 07:16 - 2014-01-09 08:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-02-13 07:16 - 2014-01-09 08:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll 2014-02-13 07:16 - 2014-01-09 08:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll 2014-02-13 07:16 - 2014-01-09 08:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll 2014-02-13 07:16 - 2014-01-09 08:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll 2014-02-13 07:16 - 2014-01-09 08:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2014-02-13 07:16 - 2014-01-09 08:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe 2014-02-12 18:54 - 2014-02-11 13:19 - 00000426 _____ () C:\AVScanner.ini 2014-02-12 18:47 - 2014-02-12 18:47 - 00710848 _____ ( ) C:\Users\Spree-Reiter\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-02-12 18:45 - 2014-02-12 18:45 - 00552744 _____ (Fusion Install ) C:\Users\Spree-Reiter\Downloads\Groovestream.exe 2014-02-12 18:17 - 2014-02-12 18:19 - 00002660 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-12 18:17 - 2014-02-12 18:17 - 00000044 _____ () C:\Users\Spree-Reiter\AppData\Roaming\WB.CFG 2014-02-12 18:16 - 2014-02-12 18:17 - 00000000 ____D () C:\Program Files (x86)\VideoConverter 2014-02-12 18:15 - 2014-02-12 18:16 - 00660792 _____ () C:\Users\Spree-Reiter\Downloads\VideoConverterSetup.exe 2014-02-12 18:09 - 2014-02-12 18:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\TuneUp Software 2014-02-12 18:07 - 2014-02-13 12:49 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-02-12 18:07 - 2014-02-13 11:15 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-12 18:07 - 2014-02-12 18:10 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Freemake 2014-02-12 18:06 - 2014-02-12 18:06 - 01307976 _____ (Ellora Assets Corporation ) C:\Users\Spree-Reiter\Downloads\FreemakeVideoConverterSetup.exe 2014-02-12 16:53 - 2014-02-12 16:53 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\XMedia Recode 2014-02-12 16:43 - 2014-02-12 16:43 - 00001083 _____ () C:\Users\Public\Desktop\XMedia Recode.lnk 2014-02-12 16:43 - 2014-02-12 16:43 - 00000000 ____D () C:\Program Files (x86)\XMedia Recode 2014-02-12 16:39 - 2014-02-12 16:39 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\AVS4YOU 2014-02-12 16:38 - 2014-02-12 18:33 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-02-12 16:38 - 2014-02-12 16:39 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-02-12 16:38 - 2012-03-23 19:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Aimersoft 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Program Files\Common Files\Aimersoft 2014-02-12 16:20 - 2013-08-23 13:36 - 00721263 _____ () C:\Windows\SysWOW64\AiCM64.dll 2014-02-12 16:20 - 2013-08-07 14:31 - 00214528 _____ () C:\Windows\SysWOW64\AiCM32.dll 2014-02-12 16:19 - 2014-02-12 16:32 - 00000000 ____D () C:\ProgramData\Aimersoft Video Converter Ultimate 2014-02-12 16:19 - 2014-02-12 16:19 - 00000000 ____D () C:\Program Files (x86)\Aimersoft 2014-02-03 16:34 - 2014-02-03 16:34 - 01718176 _____ (Netviewer GmbH) C:\Users\Spree-Reiter\Downloads\nvt_sinr111592749_sipw_sitn_kagu.exe 2014-02-02 14:34 - 2013-08-22 07:57 - 00002131 ___RS () C:\Users\Spree-Reiter\Desktop\Camera.lnk ==================== One Month Modified Files and Folders ======= 2021-10-21 14:36 - 2013-10-25 08:21 - 00000852 _____ () C:\Windows\system32\Drivers\RTKHDRC.dat 2021-10-04 08:34 - 2013-10-25 08:21 - 00000712 _____ () C:\Windows\system32\Drivers\RTMICEQ0.dat 2014-03-03 17:40 - 2014-03-03 17:40 - 00000000 ____D () C:\Users\Spree-Reiter\Downloads\FRST-OlderVersion 2014-03-03 17:40 - 2014-02-27 12:41 - 00018648 _____ () C:\Users\Spree-Reiter\Downloads\FRST.txt 2014-03-03 17:40 - 2014-02-27 12:41 - 00000000 ____D () C:\FRST 2014-03-03 17:40 - 2014-02-27 12:39 - 02156544 _____ (Farbar) C:\Users\Spree-Reiter\Downloads\FRST64.exe 2014-03-03 17:38 - 2013-11-29 14:48 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-03-03 17:17 - 2013-11-29 20:35 - 00001158 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA.job 2014-03-03 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2014-03-03 15:45 - 2014-02-26 20:01 - 00399491 _____ () C:\Windows\WindowsUpdate.log 2014-03-03 14:51 - 2014-03-03 14:51 - 00001450 _____ () C:\Users\Spree-Reiter\Desktop\JRT.txt 2014-03-03 14:51 - 2013-11-29 19:53 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3108126898-271320607-1571633106-1001 2014-03-03 14:41 - 2013-11-30 13:54 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\ClassicShell 2014-03-03 14:35 - 2013-10-25 17:42 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2014-03-03 14:35 - 2013-10-25 17:42 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2014-03-03 14:35 - 2013-09-05 12:46 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-03 14:20 - 2014-01-03 11:31 - 00005148 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ICKE-Spree-Reiter Icke 2014-03-03 14:09 - 2013-11-29 18:10 - 00000000 __RDO () C:\Users\Spree-Reiter\SkyDrive 2014-03-03 14:09 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-03 13:40 - 2013-11-29 20:35 - 00002630 _____ () C:\Users\Spree-Reiter\Desktop\Google Chrome.lnk 2014-03-03 13:37 - 2014-03-03 13:25 - 00058530 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-03-03 13:37 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-03-03 13:30 - 2014-03-03 13:30 - 00000000 ____D () C:\Windows\ERUNT 2014-03-03 13:29 - 2014-03-03 13:29 - 01037734 _____ (Thisisu) C:\Users\Spree-Reiter\Downloads\JRT.exe 2014-03-03 13:25 - 2014-03-03 13:25 - 00000000 ___HD () C:\VTRoot 2014-03-03 13:25 - 2013-11-29 20:27 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2071D27F-6F73-4CA7-B28F-3925676B70DA} 2014-03-03 13:19 - 2014-03-03 13:19 - 00001394 _____ () C:\Windows\PFRO.log 2014-03-03 13:18 - 2014-03-03 12:40 - 00000000 ____D () C:\AdwCleaner 2014-03-03 12:40 - 2014-03-03 12:40 - 01244192 _____ () C:\Users\Spree-Reiter\Downloads\adwcleaner.exe 2014-03-03 12:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-03-03 11:27 - 2013-11-29 20:35 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core.job 2014-02-28 15:21 - 2014-02-26 11:24 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-02-28 12:49 - 2014-01-03 10:00 - 00002033 _____ () C:\Users\Public\Desktop\GeekBuddy.lnk 2014-02-27 12:44 - 2014-02-27 12:43 - 00036680 _____ () C:\Users\Spree-Reiter\Downloads\Addition.txt 2014-02-26 11:24 - 2014-02-26 11:24 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-26 11:24 - 2014-02-26 11:24 - 00001054 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Spyware Terminator 2014-02-26 11:24 - 2014-02-26 11:24 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-02-26 11:22 - 2014-02-26 11:22 - 05049344 _____ (Crawler.com ) C:\Users\Spree-Reiter\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-02-25 11:09 - 2014-02-25 10:45 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Nico Mak Computing 2014-02-24 21:53 - 2013-11-29 19:46 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Packages 2014-02-24 20:09 - 2013-12-01 18:35 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Deployment 2014-02-24 10:00 - 2013-11-29 14:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-21 22:45 - 2013-12-03 11:55 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\CrashDumps 2014-02-20 08:02 - 2014-02-20 08:02 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\My Weblog Posts 2014-02-20 08:02 - 2013-11-30 14:47 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Windows Live Writer 2014-02-18 07:35 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-02-17 22:00 - 2013-12-02 07:29 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 22:00 - 2013-12-02 07:29 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 12:27 - 2014-02-17 12:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-17 09:20 - 2013-11-29 19:47 - 00000000 ___RD () C:\Users\Spree-Reiter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-17 09:20 - 2013-11-29 19:47 - 00000000 ___RD () C:\Users\Spree-Reiter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-17 06:40 - 2013-08-22 15:44 - 00505312 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-17 06:39 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ToastData 2014-02-17 06:39 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-02-17 06:39 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Dism 2014-02-17 06:26 - 2013-12-01 18:29 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 06:23 - 2013-12-01 18:29 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-14 11:12 - 2013-11-29 20:35 - 00004118 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001UA 2014-02-14 11:12 - 2013-11-29 20:35 - 00003738 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3108126898-271320607-1571633106-1001Core 2014-02-13 12:49 - 2014-02-13 12:49 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-02-13 12:49 - 2014-02-12 18:07 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-02-13 11:36 - 2013-11-29 19:46 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\VirtualStore 2014-02-13 11:15 - 2014-02-12 18:07 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\MediaViewer 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\FileManager 2014-02-13 07:36 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Camera 2014-02-12 18:47 - 2014-02-12 18:47 - 00710848 _____ ( ) C:\Users\Spree-Reiter\Downloads\COMPUTER_BILD-Download-Manager_fuer_FreeVideoConverterSetup-r0-n-bc.exe 2014-02-12 18:45 - 2014-02-12 18:45 - 00552744 _____ (Fusion Install ) C:\Users\Spree-Reiter\Downloads\Groovestream.exe 2014-02-12 18:33 - 2014-02-12 16:38 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-02-12 18:19 - 2014-02-12 18:17 - 00002660 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-02-12 18:17 - 2014-02-12 18:17 - 00000044 _____ () C:\Users\Spree-Reiter\AppData\Roaming\WB.CFG 2014-02-12 18:17 - 2014-02-12 18:16 - 00000000 ____D () C:\Program Files (x86)\VideoConverter 2014-02-12 18:16 - 2014-02-12 18:15 - 00660792 _____ () C:\Users\Spree-Reiter\Downloads\VideoConverterSetup.exe 2014-02-12 18:10 - 2014-02-12 18:07 - 00000000 ____D () C:\Program Files (x86)\Freemake 2014-02-12 18:09 - 2014-02-12 18:09 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\TuneUp Software 2014-02-12 18:07 - 2014-02-12 18:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Freemake 2014-02-12 18:06 - 2014-02-12 18:06 - 01307976 _____ (Ellora Assets Corporation ) C:\Users\Spree-Reiter\Downloads\FreemakeVideoConverterSetup.exe 2014-02-12 16:53 - 2014-02-12 16:53 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\XMedia Recode 2014-02-12 16:43 - 2014-02-12 16:43 - 00001083 _____ () C:\Users\Public\Desktop\XMedia Recode.lnk 2014-02-12 16:43 - 2014-02-12 16:43 - 00000000 ____D () C:\Program Files (x86)\XMedia Recode 2014-02-12 16:39 - 2014-02-12 16:39 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\AVS4YOU 2014-02-12 16:39 - 2014-02-12 16:38 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-02-12 16:32 - 2014-02-12 16:19 - 00000000 ____D () C:\ProgramData\Aimersoft Video Converter Ultimate 2014-02-12 16:30 - 2013-12-03 21:28 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\vlc 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\Aimersoft Video Converter Ultimate 2014-02-12 16:21 - 2014-02-12 16:21 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Local\Aimersoft 2014-02-12 16:20 - 2014-02-12 16:20 - 00000000 ____D () C:\Program Files\Common Files\Aimersoft 2014-02-12 16:19 - 2014-02-12 16:19 - 00000000 ____D () C:\Program Files (x86)\Aimersoft 2014-02-11 13:19 - 2014-02-12 18:54 - 00000426 _____ () C:\AVScanner.ini 2014-02-10 17:21 - 2013-11-29 15:40 - 00000000 ____D () C:\Users\Spree-Reiter\AppData\Roaming\FileZilla 2014-02-07 15:40 - 2013-11-29 15:07 - 00000000 ____D () C:\Users\Spree-Reiter\Documents\Bluetooth Folder 2014-02-06 13:16 - 2014-02-13 07:18 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 07:18 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 07:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 07:18 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 07:18 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 07:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 07:18 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 07:18 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:49 - 2014-02-13 07:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 07:18 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 07:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 07:18 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 07:18 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 07:18 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 07:18 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 07:18 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 07:18 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 07:18 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 07:18 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 07:18 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 07:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 07:18 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 07:18 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:47 - 2014-02-13 07:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 07:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 07:18 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 07:18 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 07:18 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 07:18 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 07:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 07:18 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 07:18 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 07:18 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 07:18 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 07:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 07:18 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 07:18 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-03 16:34 - 2014-02-03 16:34 - 01718176 _____ (Netviewer GmbH) C:\Users\Spree-Reiter\Downloads\nvt_sinr111592749_sipw_sitn_kagu.exe Some content of TEMP: ==================== C:\Users\Spree-Reiter\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Spree-Reiter\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Spree-Reiter\AppData\Local\Temp\Quarantine.exe C:\Users\Spree-Reiter\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Spree-Reiter\AppData\Local\Temp\SDShelEx-x64.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-01 16:50 ==================== End Of Log ============================ --- --- --- |
04.03.2014, 14:36 | #6 |
/// the machine /// TB-Ausbilder | Große Zahl Emails die als nicht zustellbar "zurückkommen"ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Große Zahl Emails die als nicht zustellbar "zurückkommen" |
Themen zu Große Zahl Emails die als nicht zustellbar "zurückkommen" |
angeblich, anzahl, email account, emails, gefunde, gemeinde, große, kurzem, liebe, maleware?, nichts, prüfen, relativ, runtergeladen, situation, spyware, spyware terminator, terminator |