danixx17 | 28.08.2014 12:47 | Hier die FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by Daniel (administrator) on DANIELSPC on 28-08-2014 13:43:12
Running from C:\Users\Daniel\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(Pokki) C:\Users\Daniel\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Pokki) C:\Users\Daniel\AppData\Local\Pokki\Engine\HostAppService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe
(Pokki) C:\Users\Daniel\AppData\Local\Pokki\Engine\HostAppService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
() C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Map.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [52992 2014-08-06] (Acer Incorporated)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165624 2014-08-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-05-12] (Malwarebytes Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-26] ( (Atheros Communications))
HKU\S-1-5-21-50735745-1188943747-2305243463-1001\...\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
HKU\S-1-5-21-50735745-1188943747-2305243463-1001\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-06-28] (Spotify Ltd)
HKU\S-1-5-21-50735745-1188943747-2305243463-1001\...\Policies\Explorer: [Run] "C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\IEUpdate\Fondue.exe"
HKU\S-1-5-21-50735745-1188943747-2305243463-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
HKU\S-1-5-21-50735745-1188943747-2305243463-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Fondue] => "C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\IEUpdate\Fondue.exe"
HKU\S-1-5-21-50735745-1188943747-2305243463-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-06-28] (Spotify Ltd)
HKU\S-1-5-21-50735745-1188943747-2305243463-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [Run] "C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\IEUpdate\Fondue.exe"
HKU\S-1-5-21-50735745-1188943747-2305243463-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Command Processor: "C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\IEUpdate\Fondue.exe" <===== ATTENTION!
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fondue.lnk
ShortcutTarget: Fondue.lnk -> C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\IEUpdate\Fondue.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/?pc=ACJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM - DefaultScope {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM - {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - DefaultScope {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 - {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKCU - DefaultScope {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL =
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - {B031DA4F-7CD5-4E42-8AAC-7E466069B3D7} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\QqRbgOpo.default
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\QqRbgOpo.default\Extensions\abs@avira.com [2014-08-27]
Chrome:
=======
CHR HomePage: Default -> 2ABC6AADAF063C636B8FF05566B883E88FB3647B6B83FDE941708CA7C619DDF9
CHR DefaultSearchKeyword: Default -> 59D87706058D019E5B8AACBF24AEFE8BD8749BE8C97B40047A09AE8404416CD5
CHR DefaultSearchURL: Default -> E544D0C1C6B2846855618A7B3DC3B9DFA6EF3EC3D1148463E73CBCD52B769358
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-08-27]
CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-27]
CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-27]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27]
CHR Extension: (James White) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm [2014-08-27]
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-27]
CHR Extension: (Google-Suche) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-27]
CHR Extension: (Google Tabellen) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-08-27]
CHR Extension: (Avira Browser Safety) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-27]
CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-27]
CHR Extension: (Google Mail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-26] (Windows (R) Win 7 DDK provider)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [158000 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [3058944 2014-08-06] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-03-17] (Acer Incorporate)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-22] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-03-22] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-25] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-06-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-06-28] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-13] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [225504 2014-03-28] (AppEx Networks Corporation)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-26] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [476888 2014-03-21] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-06-28] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 13:43 - 2014-08-28 13:43 - 00015998 _____ () C:\Users\Daniel\Downloads\FRST.txt
2014-08-28 13:43 - 2014-08-28 13:43 - 00000000 ____D () C:\FRST
2014-08-28 13:42 - 2014-08-28 13:42 - 02103296 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe
2014-08-28 13:26 - 2014-08-28 13:26 - 00011776 ___SH () C:\Users\Daniel\Desktop\Thumbs.db
2014-08-28 12:11 - 2014-08-28 12:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-28 12:11 - 2014-08-28 12:11 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-28 12:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-28 12:11 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-28 12:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-28 12:08 - 2014-08-28 12:08 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-28 11:17 - 2014-08-28 11:16 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-08-27 15:54 - 2014-08-27 15:54 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Avira
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ATI
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\Users\Daniel\AppData\Local\ATI
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\ProgramData\ATI
2014-08-27 15:47 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-08-27 15:47 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-08-27 15:47 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-08-27 15:43 - 2014-08-27 15:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-27 15:43 - 2014-08-27 15:47 - 00000000 ____D () C:\ProgramData\Avira
2014-08-27 15:43 - 2014-08-27 15:47 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-27 15:43 - 2014-08-27 15:43 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-27 15:43 - 2014-08-27 15:43 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Mozilla
2014-08-27 15:42 - 2014-08-27 15:43 - 04791736 _____ (Avira Operations GmbH & Co. KG) C:\Users\Daniel\Downloads\avira_de_av___ws.exe
2014-08-27 15:13 - 2014-08-27 22:58 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Acer
2014-08-27 15:12 - 2014-08-27 15:20 - 00000000 ____D () C:\Users\Daniel\Documents\CyberLink
2014-08-27 15:12 - 2014-08-27 15:20 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\CyberLink
2014-08-27 15:12 - 2014-08-27 15:12 - 00000000 ____D () C:\Users\Daniel\AppData\Local\MediaShow
2014-08-27 15:11 - 2014-08-27 15:14 - 00000000 ____D () C:\Users\Daniel\AppData\Local\CyberLink
2014-08-27 14:53 - 2014-08-27 14:54 - 00002001 _____ () C:\Users\Public\Desktop\abMedia.lnk
2014-08-27 14:53 - 2014-08-27 14:53 - 00000000 ____D () C:\ProgramData\clear.fi
2014-08-27 14:51 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Spotify
2014-08-27 14:51 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Spotify
2014-08-27 14:48 - 2014-08-27 14:48 - 00012288 ___SH () C:\Users\Daniel\Downloads\Thumbs.db
2014-08-27 14:29 - 2014-08-27 14:29 - 00002005 _____ () C:\Users\Public\Desktop\abPhoto.lnk
2014-08-27 14:10 - 2014-08-27 14:10 - 00000000 ____D () C:\Users\Public\OEM
2014-08-27 14:10 - 2014-08-27 14:10 - 00000000 ____D () C:\Users\Daniel\Documents\clear.fi
2014-08-27 14:02 - 2014-08-27 14:02 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-08-27 13:55 - 2014-08-27 13:55 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Acer Aspire R7 Tutorial
2014-08-27 13:48 - 2014-08-28 12:03 - 00002199 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-27 13:48 - 2014-08-27 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-27 13:47 - 2014-08-28 12:52 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-27 13:47 - 2014-08-28 12:03 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-27 13:47 - 2014-08-27 13:48 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Google
2014-08-27 13:47 - 2014-08-27 13:48 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-27 13:47 - 2014-08-27 13:47 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-27 13:47 - 2014-08-27 13:47 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-27 13:47 - 2014-08-27 13:47 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Deployment
2014-08-27 13:47 - 2014-08-27 13:47 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Apps\2.0
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 __SHD () C:\Users\Daniel\AppData\Local\EmieUserList
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 __SHD () C:\Users\Daniel\AppData\Local\EmieSiteList
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Macromedia
2014-08-27 13:26 - 2014-08-28 12:02 - 00000000 __RDO () C:\Users\Daniel\OneDrive
2014-08-27 13:24 - 2014-08-28 12:16 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-50735745-1188943747-2305243463-1001
2014-08-27 13:24 - 2014-08-27 13:24 - 00000000 ____D () C:\Users\Daniel\AppData\Local\AOP SDK
2014-08-27 13:23 - 2014-08-27 13:23 - 00000000 ____D () C:\Users\Public\Pokki
2014-08-27 13:22 - 2014-08-28 12:00 - 00002163 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-08-27 13:22 - 2014-08-27 13:22 - 00002334 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-08-27 13:20 - 2014-08-27 15:13 - 00000000 ____D () C:\Users\Daniel\AppData\Local\clear.fi
2014-08-27 13:20 - 2014-08-27 13:20 - 00000000 ____D () C:\Users\Daniel\PicStream
2014-08-27 13:19 - 2014-08-27 13:19 - 00002625 _____ () C:\Users\Public\Desktop\eBay.lnk
2014-08-27 13:19 - 2014-08-27 13:19 - 00001276 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-08-27 13:19 - 2014-08-27 13:19 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Atheros
2014-08-27 13:19 - 2014-08-27 13:19 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-08-27 13:18 - 2014-08-27 16:59 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Packages
2014-08-27 13:18 - 2014-08-27 13:18 - 00001786 _____ () C:\Users\Public\Desktop\Online kaufen.lnk
2014-08-27 13:18 - 2014-08-27 13:18 - 00001454 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Adobe
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Users\Daniel\AppData\Local\VirtualStore
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Program Files\Accessory Store
2014-08-27 13:16 - 2014-08-28 11:16 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Pokki
2014-08-27 13:16 - 2014-08-27 13:26 - 00000000 ____D () C:\Users\Daniel
2014-08-27 13:16 - 2014-08-27 13:16 - 00000020 ___SH () C:\Users\Daniel\ntuser.ini
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Vorlagen
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Startmenü
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Netzwerkumgebung
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Lokale Einstellungen
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Eigene Dateien
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Druckumgebung
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Documents\Eigene Musik
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Documents\Eigene Bilder
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Local\Verlauf
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Local\Anwendungsdaten
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Anwendungsdaten
2014-08-27 13:16 - 2014-06-28 08:00 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-27 13:16 - 2014-03-18 12:33 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-27 13:16 - 2014-03-18 12:13 - 00000369 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-08-27 13:16 - 2014-03-18 12:13 - 00000369 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-08-27 13:16 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-27 13:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 13:43 - 2014-08-28 13:43 - 00015998 _____ () C:\Users\Daniel\Downloads\FRST.txt
2014-08-28 13:43 - 2014-08-28 13:43 - 00000000 ____D () C:\FRST
2014-08-28 13:42 - 2014-08-28 13:42 - 02103296 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe
2014-08-28 13:26 - 2014-08-28 13:26 - 00011776 ___SH () C:\Users\Daniel\Desktop\Thumbs.db
2014-08-28 13:17 - 2014-06-28 07:27 - 01199571 _____ () C:\Windows\WindowsUpdate.log
2014-08-28 13:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-08-28 12:52 - 2014-08-27 13:47 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-28 12:16 - 2014-08-27 13:24 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-50735745-1188943747-2305243463-1001
2014-08-28 12:14 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-28 12:11 - 2014-08-28 12:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-28 12:11 - 2014-08-28 12:11 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 12:11 - 2014-08-28 12:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-28 12:08 - 2014-08-28 12:08 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-28 12:03 - 2014-08-27 13:48 - 00002199 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-28 12:03 - 2014-08-27 13:47 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-28 12:02 - 2014-08-27 13:26 - 00000000 __RDO () C:\Users\Daniel\OneDrive
2014-08-28 12:00 - 2014-08-27 13:22 - 00002163 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-08-28 11:16 - 2014-08-28 11:17 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-08-28 11:16 - 2014-08-27 13:16 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Pokki
2014-08-28 04:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-08-27 22:58 - 2014-08-27 15:13 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Acer
2014-08-27 22:58 - 2014-06-28 07:29 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2014-08-27 22:58 - 2014-05-16 08:00 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-27 22:58 - 2014-03-18 11:54 - 00139440 _____ () C:\Windows\PFRO.log
2014-08-27 22:58 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-27 22:58 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-27 22:57 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-08-27 17:04 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-08-27 16:59 - 2014-08-27 13:18 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Packages
2014-08-27 15:54 - 2014-08-27 15:54 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Avira
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ATI
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\Users\Daniel\AppData\Local\ATI
2014-08-27 15:52 - 2014-08-27 15:52 - 00000000 ____D () C:\ProgramData\ATI
2014-08-27 15:48 - 2014-08-27 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-27 15:47 - 2014-08-27 15:43 - 00000000 ____D () C:\ProgramData\Avira
2014-08-27 15:47 - 2014-08-27 15:43 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-27 15:43 - 2014-08-27 15:43 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-27 15:43 - 2014-08-27 15:43 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Mozilla
2014-08-27 15:43 - 2014-08-27 15:42 - 04791736 _____ (Avira Operations GmbH & Co. KG) C:\Users\Daniel\Downloads\avira_de_av___ws.exe
2014-08-27 15:43 - 2014-06-28 07:27 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-27 15:21 - 2014-06-28 08:04 - 00000000 ____D () C:\Users\Public\CyberLink
2014-08-27 15:20 - 2014-08-27 15:12 - 00000000 ____D () C:\Users\Daniel\Documents\CyberLink
2014-08-27 15:20 - 2014-08-27 15:12 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\CyberLink
2014-08-27 15:14 - 2014-08-27 15:11 - 00000000 ____D () C:\Users\Daniel\AppData\Local\CyberLink
2014-08-27 15:13 - 2014-08-27 13:20 - 00000000 ____D () C:\Users\Daniel\AppData\Local\clear.fi
2014-08-27 15:13 - 2014-05-16 08:25 - 00000000 ___HD () C:\OEM
2014-08-27 15:12 - 2014-08-27 15:12 - 00000000 ____D () C:\Users\Daniel\AppData\Local\MediaShow
2014-08-27 15:12 - 2014-06-28 07:54 - 00000000 ____D () C:\ProgramData\CyberLink
2014-08-27 14:54 - 2014-08-27 14:53 - 00002001 _____ () C:\Users\Public\Desktop\abMedia.lnk
2014-08-27 14:54 - 2014-05-16 07:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-08-27 14:54 - 2014-05-16 07:47 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-08-27 14:53 - 2014-08-27 14:53 - 00000000 ____D () C:\ProgramData\clear.fi
2014-08-27 14:51 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Spotify
2014-08-27 14:51 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Spotify
2014-08-27 14:48 - 2014-08-27 14:48 - 00012288 ___SH () C:\Users\Daniel\Downloads\Thumbs.db
2014-08-27 14:29 - 2014-08-27 14:29 - 00002005 _____ () C:\Users\Public\Desktop\abPhoto.lnk
2014-08-27 14:10 - 2014-08-27 14:10 - 00000000 ____D () C:\Users\Public\OEM
2014-08-27 14:10 - 2014-08-27 14:10 - 00000000 ____D () C:\Users\Daniel\Documents\clear.fi
2014-08-27 14:02 - 2014-08-27 14:02 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-08-27 14:02 - 2013-08-22 16:46 - 00017521 _____ () C:\Windows\setupact.log
2014-08-27 13:55 - 2014-08-27 13:55 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Acer Aspire R7 Tutorial
2014-08-27 13:49 - 2014-06-28 07:57 - 00793160 _____ () C:\Windows\system32\perfh010.dat
2014-08-27 13:49 - 2014-06-28 07:57 - 00156082 _____ () C:\Windows\system32\perfc010.dat
2014-08-27 13:49 - 2014-06-28 07:47 - 00801394 _____ () C:\Windows\system32\perfh00C.dat
2014-08-27 13:49 - 2014-06-28 07:47 - 00158846 _____ () C:\Windows\system32\perfc00C.dat
2014-08-27 13:49 - 2014-06-28 07:36 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-08-27 13:49 - 2014-06-28 07:36 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-08-27 13:49 - 2014-03-18 12:03 - 03686756 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 13:48 - 2014-08-27 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-27 13:48 - 2014-08-27 13:47 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Google
2014-08-27 13:48 - 2014-08-27 13:47 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-27 13:47 - 2014-08-27 13:47 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-27 13:47 - 2014-08-27 13:47 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-27 13:47 - 2014-08-27 13:47 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Deployment
2014-08-27 13:47 - 2014-08-27 13:47 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Apps\2.0
2014-08-27 13:42 - 2013-08-22 16:44 - 00344840 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 __SHD () C:\Users\Daniel\AppData\Local\EmieUserList
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 __SHD () C:\Users\Daniel\AppData\Local\EmieSiteList
2014-08-27 13:36 - 2014-08-27 13:36 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Macromedia
2014-08-27 13:26 - 2014-08-27 13:16 - 00000000 ____D () C:\Users\Daniel
2014-08-27 13:24 - 2014-08-27 13:24 - 00000000 ____D () C:\Users\Daniel\AppData\Local\AOP SDK
2014-08-27 13:23 - 2014-08-27 13:23 - 00000000 ____D () C:\Users\Public\Pokki
2014-08-27 13:22 - 2014-08-27 13:22 - 00002334 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-08-27 13:20 - 2014-08-27 13:20 - 00000000 ____D () C:\Users\Daniel\PicStream
2014-08-27 13:20 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-08-27 13:19 - 2014-08-27 13:19 - 00002625 _____ () C:\Users\Public\Desktop\eBay.lnk
2014-08-27 13:19 - 2014-08-27 13:19 - 00001276 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-08-27 13:19 - 2014-08-27 13:19 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Atheros
2014-08-27 13:19 - 2014-08-27 13:19 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-08-27 13:19 - 2014-05-16 08:32 - 00000000 ____D () C:\Windows\Panther
2014-08-27 13:18 - 2014-08-27 13:18 - 00001786 _____ () C:\Users\Public\Desktop\Online kaufen.lnk
2014-08-27 13:18 - 2014-08-27 13:18 - 00001454 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Adobe
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Users\Daniel\AppData\Local\VirtualStore
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-08-27 13:18 - 2014-08-27 13:18 - 00000000 ____D () C:\Program Files\Accessory Store
2014-08-27 13:16 - 2014-08-27 13:16 - 00000020 ___SH () C:\Users\Daniel\ntuser.ini
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Vorlagen
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Startmenü
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Netzwerkumgebung
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Lokale Einstellungen
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Eigene Dateien
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Druckumgebung
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Documents\Eigene Musik
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Documents\Eigene Bilder
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Local\Verlauf
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\AppData\Local\Anwendungsdaten
2014-08-27 13:16 - 2014-08-27 13:16 - 00000000 _SHDL () C:\Users\Daniel\Anwendungsdaten
2014-08-15 10:30 - 2014-08-27 15:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-08-15 10:30 - 2014-08-27 15:47 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-08-15 10:30 - 2014-08-27 15:47 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\0245331409172919mcinst.exe
C:\Users\Daniel\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-05-16 07:33
==================== End Of Log ============================ --- --- ---
Und hier die Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-08-2014
Ran by Daniel at 2014-08-28 13:44:21
Running from C:\Users\Daniel\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2007.2 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2011.1 - Acer Incorporated)
Acer Docs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2001 - Acer)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8105 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.04.2007 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8104 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3012 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8106 - Acer Incorporated)
Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.02.2003 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.01.3003 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.01.3003 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2001.4 - Acer Incorporated)
Adobe Reader XI (11.0.04) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD Accelerated Video Transcoding (Version: 13.30.100.40402 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{9D98D3EC-9BB8-47EF-66B6-B652B9846634}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.10.0.0 - AppEx Networks)
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.01.2012.1 - Acer Incorporated)
Avira (HKLM-x32\...\{c5039061-0c7c-4f6c-96e5-348a19bd22ec}) (Version: 1.1.20.29573 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.20.29573 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.1.4917 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.3721 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.0.3721 - CyberLink Corp.) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3914.57 - CyberLink Corp.)
CyberLink PowerDVD 12 (x32 Version: 12.0.3914.57 - CyberLink Corp.) Hidden
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8101 - Acer Incorporated)
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated)
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Nero BackItUp (x32 Version: 12.5.11000 - Nero AG) Hidden
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
Nero BackItUp Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 11.0.15900 - Nero AG) Hidden
Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
Nero Core Components (x32 Version: 11.0.20900 - Nero AG) Hidden
Nero Launcher (x32 Version: 12.2.7000 - Nero AG) Hidden
Nero RescueAgent (x32 Version: 12.0.3001 - Nero AG) Hidden
Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden
OEM Application Profile (HKLM-x32\...\{276FD4A2-030F-8A24-7DFE-9B1384131BCD}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pokki Start Menu (HKCU\...\Pokki) (Version: 0.269.2.261 - Pokki)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21250 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7218 - Realtek Semiconductor Corp.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {017B4F6F-F52A-4F3D-8064-A93DB9B11CE5} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-22] (Acer Incorporate)
Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {07B9017E-FB98-4206-A0AC-82BCD32CC1A6} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] ()
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {19BA4228-DA48-48CA-9CE4-3A8F4AAE11BC} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-03-21] (Acer Incorporated)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {7544F2B2-6499-49AD-94FD-D176BEF96B87} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-27] (Google Inc.)
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {84501431-C070-4220-A3FC-525A73D64737} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-03-19] (Acer Incorporated)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {919E294D-A128-4303-B478-BA8DC5ACC131} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A4664EC2-D31F-4018-92E4-28B775BB1846} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-27] (Google Inc.)
Task: {BE014269-9D99-46C2-9B08-2420A755199B} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-03-17] (Acer Incorporate)
Task: {BF58E14B-1069-43E0-80DD-BB525A2FD9CD} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {CB4289A7-8EFD-45A6-81F7-8F781AE1C724} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe [2014-01-17] (Acer Incorporated)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D08F1AB1-8F5E-4779-937E-7A750E734C77} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E2ACF668-4308-4463-9ECA-B3DD4467FB01} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {E3BDCA69-0278-4D27-AE94-D673C4802877} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F054EBC7-92E7-415D-8F61-0C36EB6AB56E} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-01-25] (TODO: <Company name>)
Task: {FB719D15-9B06-4B64-ABFD-65A74787CAAB} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-22] (Acer Incorporate)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-06-28 07:57 - 2012-04-24 12:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-06-28 08:05 - 2014-01-03 23:13 - 00111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2014-02-26 07:14 - 2014-02-26 07:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-02-26 07:11 - 2014-02-26 07:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-02-26 07:17 - 2014-02-26 07:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2013-08-22 09:19 - 2013-08-22 08:54 - 00174592 _____ () C:\Windows\system32\WinMetadata\Windows.UI.winmd
2012-08-31 20:28 - 2012-08-31 20:28 - 00005120 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MetroNotifications.dll
2013-08-22 09:19 - 2013-08-22 08:54 - 00050176 _____ () C:\Windows\system32\WinMetadata\Windows.Data.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00030208 _____ () C:\Windows\system32\WinMetadata\Windows.Foundation.winmd
2014-03-18 11:51 - 2014-03-18 11:51 - 01632768 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Map.exe
2013-08-22 09:19 - 2013-08-22 08:54 - 00792064 _____ () C:\Windows\system32\WinMetadata\Windows.UI.Xaml.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00134144 _____ () C:\Windows\system32\WinMetadata\Windows.ApplicationModel.winmd
2014-03-18 11:51 - 2014-03-18 11:51 - 00183808 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\DataTypes.DLL
2014-03-18 11:51 - 2014-03-18 11:51 - 00034816 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Utils.DLL
2014-03-18 11:51 - 2014-03-18 11:51 - 00129432 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Bing.Maps.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00112640 _____ () C:\Windows\system32\WinMetadata\Windows.Networking.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00020480 _____ () C:\Windows\system32\WinMetadata\Windows.System.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00054784 _____ () C:\Windows\system32\WinMetadata\Windows.Globalization.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00096256 _____ () C:\Windows\system32\WinMetadata\Windows.Storage.winmd
2014-03-18 11:51 - 2014-03-18 11:51 - 00060928 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Requests.DLL
2014-03-18 11:51 - 2014-03-18 11:51 - 00169408 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Microsoft.Bing.Platform.Logging.ClientWinRT.DLL
2013-08-22 09:19 - 2013-08-22 08:54 - 00169472 _____ () C:\Windows\system32\WinMetadata\Windows.Devices.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00066560 _____ () C:\Windows\system32\WinMetadata\Windows.Security.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00049664 _____ () C:\Windows\system32\WinMetadata\Windows.Graphics.winmd
2014-03-18 11:51 - 2014-03-18 11:51 - 00039936 _____ () C:\Program Files\WindowsApps\Microsoft.BingMaps_2.0.2530.2317_x64__8wekyb3d8bbwe\Authentication.DLL
2014-08-14 17:27 - 2014-08-14 17:27 - 00140024 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-08-14 17:27 - 2014-08-14 17:27 - 00067832 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2014-08-27 14:29 - 2014-08-27 14:29 - 00015616 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-08-06 16:47 - 2014-08-06 16:47 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-08-06 16:44 - 2014-08-06 16:44 - 00277096 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2014-08-27 16:14 - 2014-08-14 17:27 - 00051504 _____ () C:\Users\Daniel\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-08-27 13:16 - 2014-01-17 18:32 - 00569856 _____ () C:\Users\Daniel\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2014-08-27 13:16 - 2014-01-17 18:32 - 01400846 _____ () C:\Users\Daniel\AppData\Local\Pokki\Engine\avcodec-54.dll
2014-08-27 13:16 - 2014-01-17 18:32 - 00151054 _____ () C:\Users\Daniel\AppData\Local\Pokki\Engine\avutil-51.dll
2014-08-27 13:16 - 2014-01-17 18:32 - 00222734 _____ () C:\Users\Daniel\AppData\Local\Pokki\Engine\avformat-54.dll
2014-06-28 08:05 - 2014-01-03 23:13 - 00090368 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll
2014-08-27 13:48 - 2014-08-20 00:16 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.94\libglesv2.dll
2014-08-27 13:48 - 2014-08-20 00:16 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.94\libegl.dll
2014-08-27 13:48 - 2014-08-20 00:16 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.94\pdf.dll
2014-08-27 13:48 - 2014-08-20 00:16 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.94\ppGoogleNaClPluginChrome.dll
2014-08-27 13:48 - 2014-08-20 00:16 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.94\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Daniel\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/28/2014 00:04:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm backgroundTaskHost.exe, Version 6.3.9600.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: c2c
Startzeit: 01cfc2a6c5cf3486
Endzeit: 4294967295
Anwendungspfad: C:\Windows\system32\backgroundTaskHost.exe
Berichts-ID: b93ebe76-2e9a-11e4-8261-f8a96375ef20
Vollständiger Name des fehlerhaften Pakets: Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nnt
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (08/27/2014 04:13:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: abPhoto.exe, Version: 3.0.2011.0, Zeitstempel: 0x53f71973
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.8387, Zeitstempel: 0x51ea24a5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00056b1d
ID des fehlerhaften Prozesses: 0x9d8
Startzeit der fehlerhaften Anwendung: 0xabPhoto.exe0
Pfad der fehlerhaften Anwendung: abPhoto.exe1
Pfad des fehlerhaften Moduls: abPhoto.exe2
Berichtskennung: abPhoto.exe3
Vollständiger Name des fehlerhaften Pakets: abPhoto.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: abPhoto.exe5
Error: (08/27/2014 01:44:54 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DANIELSPC)
Description: Bei der Aktivierung der App „winstore_cw5n1h2txyewy!Windows.Store“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (08/27/2014 01:17:57 PM) (Source: AVLogEvent) (EventID: 5005) (User: NT-AUTORITÄT)
Description: a7f42014
Error: (08/28/2014 04:01:56 AM) (Source: AVLogEvent) (EventID: 5005) (User: NT-AUTORITÄT)
Description: a7f42014
System errors:
=============
Error: (08/27/2014 11:22:41 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 11:22:41 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 11:22:40 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 11:22:40 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 11:22:40 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 11:22:40 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/27/2014 10:56:56 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (08/27/2014 10:56:26 PM) (Source: DCOM) (EventID: 10010) (User: DANIELSPC)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (08/27/2014 10:52:28 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: 3gupdate/comsvc{4EB61BAC-A3B6-4760-9581-655041EF4D69}
Error: (08/27/2014 10:52:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%3
Microsoft Office Sessions:
=========================
Error: (08/28/2014 00:04:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: backgroundTaskHost.exe6.3.9600.16384c2c01cfc2a6c5cf34864294967295C:\Windows\system32\backgroundTaskHost.exeb93ebe76-2e9a-11e4-8261-f8a96375ef20Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nntApp
Error: (08/27/2014 04:13:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: abPhoto.exe3.0.2011.053f71973MSVCR90.dll9.0.30729.838751ea24a5c000000500056b1d9d801cfc1f29c2d2028C:\Program Files (x86)\Acer\abPhoto\abPhoto.exeC:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb\MSVCR90.dll5895fe7d-2df4-11e4-8260-f8a96375ef20
Error: (08/27/2014 01:44:54 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DANIELSPC)
Description: winstore_cw5n1h2txyewy!Windows.Store-2144927141
Error: (08/27/2014 01:17:57 PM) (Source: AVLogEvent) (EventID: 5005) (User: NT-AUTORITÄT)
Description: a7f42014
Error: (08/28/2014 04:01:56 AM) (Source: AVLogEvent) (EventID: 5005) (User: NT-AUTORITÄT)
Description: a7f42014
CodeIntegrity Errors:
===================================
Date: 2014-08-27 15:50:37.222
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Temp\RarSFX0\setup.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: AMD A10-7300 Radeon R6, 10 Compute Cores 4C+6G
Percentage of memory in use: 29%
Total physical RAM: 7114.26 MB
Available physical RAM: 5030.36 MB
Total Pagefile: 8906.26 MB
Available Pagefile: 5755.08 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:914.06 GB) (Free:880.77 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: EE13F922)
Partition: GPT Partition Type.
==================== End Of Log ============================ |