Antinomie | 23.10.2014 19:12 | vlc.de malware eingefangen War ein wenig zu hektisch und hab mir nun auch den vlc.de trojaner eingefangen. Bevor ich das richtig kapiert habe, hab ich noch den richtigen vlc-player gedownloaded. Sonst aber nix verändert. Wär cool, wenn ihr mir helfen könntet. Hier die ersten Scans:
FRST: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-10-2014
Ran by User 1 (administrator) on HOMIE on 24-10-2014 19:49:46
Running from C:\Users\User 1\Desktop
Loaded Profile: User 1 (Available profiles: User 1)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe.86c1.deleteme
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McA2B43.tmp
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\mcu2EA2.tmp
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Pokki) C:\Users\User 1\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\msm\McSmtFwk.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(Pokki) C:\Users\User 1\AppData\Local\Pokki\Engine\HostAppService.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe
(Pokki) C:\Users\User 1\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\User 1\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-10-17] (Acer Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-02] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-3034447575-3866697844-1120935809-1001\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://liberation.fr/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM - DefaultScope {9363AE46-D0F3-4C33-8464-342623FD2525} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {9363AE46-D0F3-4C33-8464-342623FD2525} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {9363AE46-D0F3-4C33-8464-342623FD2525} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {9363AE46-D0F3-4C33-8464-342623FD2525} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - DefaultScope {9363AE46-D0F3-4C33-8464-342623FD2525} URL =
SearchScopes: HKCU - {9363AE46-D0F3-4C33-8464-342623FD2525} URL =
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\User 1\AppData\Roaming\Mozilla\Firefox\Profiles\w8dq653w.default
FF Homepage: liberation.fr
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll ()
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\User 1\AppData\Roaming\Mozilla\Firefox\Profiles\w8dq653w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-24]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-07-25]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-07-25]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-10-24]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 0059641414154310mcinstcleanup; C:\Windows\TEMP\005964~1.EXE [836168 2014-03-13] (McAfee, Inc.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [3096832 2014-10-17] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
S2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-30] (McAfee, Inc.)
S2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [225504 2014-03-28] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7549616 2014-02-25] (Broadcom Corporation)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
U3 mfehidk01; No ImagePath
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.)
U3 mfencbdc01; No ImagePath
U3 mfencbdc02; No ImagePath
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [476888 2014-03-21] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-24 19:49 - 2014-10-24 19:50 - 00017704 _____ () C:\Users\User 1\Desktop\FRST.txt
2014-10-24 19:48 - 2014-10-24 19:49 - 00000000 ____D () C:\FRST
2014-10-24 19:46 - 2014-10-24 19:46 - 02112000 _____ (Farbar) C:\Users\User 1\Desktop\FRST64.exe
2014-10-24 14:42 - 2014-10-24 14:43 - 24743106 _____ () C:\Users\User 1\Desktop\vlc-2.1.5-win32.exe
2014-10-24 14:39 - 2014-10-24 14:39 - 00000000 ____D () C:\Users\User 1\AppData\Local\Acer Aspire R7 Tutorial
2014-10-24 14:33 - 2014-10-24 14:33 - 00001132 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
2014-10-24 14:33 - 2014-10-24 14:33 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-10-24 14:32 - 2014-10-24 14:33 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-10-24 14:31 - 2014-10-24 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-10-24 14:29 - 2014-10-24 14:29 - 00000000 ____D () C:\Users\User 1\AppData\Local\iGware
2014-10-24 00:55 - 2014-10-24 00:57 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-24 00:55 - 2014-10-03 10:02 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-24 00:40 - 2014-10-24 00:40 - 00000000 ___RD () C:\Windows\BrowserChoice
2014-10-24 00:36 - 2014-10-24 00:36 - 00002118 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-10-24 00:36 - 2014-10-24 00:36 - 00002106 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-10-24 00:36 - 2014-10-24 00:36 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Thunderbird
2014-10-24 00:36 - 2014-10-24 00:36 - 00000000 ____D () C:\Users\User 1\AppData\Local\Thunderbird
2014-10-24 00:36 - 2014-10-24 00:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-10-24 00:25 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-24 00:25 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-24 00:25 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-24 00:25 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-24 00:25 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-24 00:25 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-24 00:25 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-24 00:25 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-24 00:25 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-24 00:25 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-24 00:25 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-24 00:25 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-24 00:25 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-24 00:25 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-24 00:25 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-24 00:25 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-24 00:25 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-24 00:25 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-24 00:25 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-24 00:25 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-24 00:25 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-24 00:25 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-24 00:25 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-24 00:25 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-24 00:25 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-24 00:25 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-24 00:25 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-24 00:25 - 2013-08-22 13:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-24 00:25 - 2013-08-22 06:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-24 00:24 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-24 00:24 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-24 00:24 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-24 00:24 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-24 00:24 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-24 00:24 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-24 00:24 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-24 00:24 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-24 00:22 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-10-24 00:22 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-10-24 00:22 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-10-24 00:22 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-10-24 00:22 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2014-10-24 00:22 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-10-24 00:21 - 2014-10-24 00:21 - 00003334 _____ () C:\Windows\System32\Tasks\AcerCloud
2014-10-24 00:21 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-10-24 00:21 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-10-24 00:21 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-10-24 00:21 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2014-10-24 00:21 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-10-24 00:21 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-10-24 00:21 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-24 00:21 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-10-24 00:21 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-10-24 00:21 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-24 00:21 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-10-24 00:21 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-10-24 00:21 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-10-24 00:21 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2014-10-24 00:21 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-10-24 00:21 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2014-10-24 00:21 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-10-24 00:20 - 2014-10-24 00:21 - 00002030 _____ () C:\Users\Public\Desktop\Acer Portal.lnk
2014-10-24 00:11 - 2014-10-24 00:12 - 00002001 _____ () C:\Users\Public\Desktop\abMedia.lnk
2014-10-24 00:05 - 2014-10-24 00:05 - 00027136 ___SH () C:\Users\User 1\Desktop\Thumbs.db
2014-10-24 00:02 - 2014-10-24 14:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-24 00:02 - 2014-10-24 00:02 - 00001179 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-24 00:02 - 2014-10-24 00:02 - 00001167 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-24 00:02 - 2014-10-24 00:02 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Mozilla
2014-10-24 00:02 - 2014-10-24 00:02 - 00000000 ____D () C:\Users\User 1\AppData\Local\Mozilla
2014-10-24 00:02 - 2014-10-24 00:02 - 00000000 ____D () C:\ProgramData\Mozilla
2014-10-24 00:02 - 2014-10-24 00:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-24 00:02 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-24 00:00 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\drvcfg.exe
2014-10-24 00:00 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2014-10-24 00:00 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-10-23 23:53 - 2014-10-24 19:45 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\ClassicShell
2014-10-23 23:50 - 2014-10-23 23:50 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-10-23 23:49 - 2014-10-23 23:49 - 00000000 ____D () C:\Users\Public\OEM
2014-10-23 23:48 - 2014-10-23 23:48 - 00002005 _____ () C:\Users\Public\Desktop\abPhoto.lnk
2014-10-23 23:46 - 2014-10-23 23:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-10-23 23:46 - 2014-10-23 23:46 - 00000000 ____D () C:\Program Files\Classic Shell
2014-10-23 23:44 - 2014-10-23 23:44 - 00000190 _____ () C:\Users\User 1\Downloads\acv.js
2014-10-23 23:43 - 2014-10-23 23:43 - 00001070 _____ () C:\Users\Public\Desktop\CHIP Updater.lnk
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Abelssoft
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\Users\User 1\AppData\Local\Abelssoft
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-10-23 23:43 - 2014-10-23 23:43 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-10-23 23:39 - 2014-10-24 16:05 - 00000000 ____D () C:\Users\User 1\AppData\Local\CrashDumps
2014-10-23 23:37 - 2014-10-23 23:37 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Macromedia
2014-10-23 23:36 - 2014-10-23 23:36 - 00000000 __SHD () C:\Users\User 1\AppData\Local\EmieUserList
2014-10-23 23:36 - 2014-10-23 23:36 - 00000000 __SHD () C:\Users\User 1\AppData\Local\EmieSiteList
2014-10-23 05:26 - 2014-10-24 19:43 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3034447575-3866697844-1120935809-1001
2014-10-23 05:25 - 2014-10-23 05:25 - 00000000 ____D () C:\Users\Public\Pokki
2014-10-23 05:24 - 2014-10-24 19:37 - 00002163 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-10-23 05:24 - 2014-10-24 14:32 - 00002334 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-10-23 05:22 - 2014-10-24 00:17 - 00000000 ____D () C:\Users\User 1\AppData\Local\clear.fi
2014-10-23 05:22 - 2014-10-23 05:22 - 00001280 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-10-23 05:22 - 2014-10-23 05:22 - 00000000 ____D () C:\Users\User 1\PicStream
2014-10-23 05:22 - 2014-10-23 05:22 - 00000000 ____D () C:\Users\User 1\AppData\Local\AOP SDK
2014-10-23 05:22 - 2014-10-23 05:22 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-10-23 05:21 - 2014-10-24 00:40 - 00000000 ____D () C:\Users\User 1\AppData\Local\Packages
2014-10-23 05:21 - 2014-10-23 05:21 - 00001458 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\Windows\oem
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Adobe
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\Users\User 1\AppData\Local\VirtualStore
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\Users\User 1\AppData\Local\OEM
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-10-23 05:21 - 2014-10-23 05:21 - 00000000 ____D () C:\Program Files\Accessory Store
2014-10-23 05:13 - 2014-10-24 14:33 - 00000000 ____D () C:\Users\User 1\AppData\Local\Pokki
2014-10-23 05:13 - 2014-10-23 05:22 - 00000000 ____D () C:\Users\User 1
2014-10-23 05:13 - 2014-10-23 05:13 - 00000020 ___SH () C:\Users\User 1\ntuser.ini
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Vorlagen
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Startmenü
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Netzwerkumgebung
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Lokale Einstellungen
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Eigene Dateien
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Druckumgebung
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Documents\Eigene Musik
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Documents\Eigene Bilder
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\AppData\Local\Verlauf
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\AppData\Local\Anwendungsdaten
2014-10-23 05:13 - 2014-10-23 05:13 - 00000000 _SHDL () C:\Users\User 1\Anwendungsdaten
2014-10-23 05:13 - 2014-07-25 23:18 - 00000000 ___RD () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-10-23 05:13 - 2014-03-18 12:33 - 00000000 ___RD () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-10-23 05:13 - 2014-03-18 12:13 - 00000369 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-10-23 05:13 - 2014-03-18 12:13 - 00000369 _____ () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-10-23 05:13 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-23 05:13 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Programme
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-10-23 04:59 - 2014-10-23 04:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-24 19:48 - 2014-08-20 15:31 - 01579246 _____ () C:\Windows\WindowsUpdate.log
2014-10-24 19:48 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-24 19:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-10-24 19:37 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-10-24 14:51 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-10-24 14:38 - 2014-07-25 23:28 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-10-24 14:38 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-10-24 14:36 - 2014-07-25 23:28 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-24 14:36 - 2014-07-25 23:28 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-10-24 14:27 - 2014-08-20 23:49 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-10-24 14:27 - 2014-08-20 23:49 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-10-24 14:27 - 2014-03-18 12:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-24 14:22 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-24 14:21 - 2014-08-20 14:40 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2014-10-24 14:21 - 2014-03-18 11:54 - 00004174 _____ () C:\Windows\PFRO.log
2014-10-24 14:20 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-10-24 14:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-10-24 14:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-10-24 14:17 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-10-24 14:11 - 2013-08-22 16:44 - 00349040 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-24 00:45 - 2014-03-18 11:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-10-24 00:21 - 2014-07-25 23:21 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-10-24 00:12 - 2014-07-25 23:20 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-10-24 00:10 - 2014-07-25 23:57 - 00000000 ___HD () C:\OEM
2014-10-23 23:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\restore
2014-10-23 23:38 - 2014-07-25 23:30 - 00001969 _____ () C:\Users\Public\Desktop\abDocs.lnk
2014-10-23 05:29 - 2014-07-25 23:21 - 00000000 ____D () C:\ProgramData\OEM
2014-10-23 05:22 - 2014-07-25 23:20 - 00000000 ____D () C:\ProgramData\acer
2014-10-23 05:21 - 2014-07-25 23:58 - 00000000 ____D () C:\Windows\Panther
2014-10-23 05:04 - 2014-07-25 23:00 - 00000000 ____D () C:\Users\Administrator
2014-10-23 05:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-10-23 04:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-10-23 04:59 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
Some content of TEMP:
====================
C:\Users\User 1\AppData\Local\Temp\oct15B9.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-25 22:59
==================== End Of Log ============================
Und hier noch der Addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-10-2014
Ran by User 1 at 2014-10-24 19:50:39
Running from C:\Users\User 1\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.04.3005 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2002 - Acer Incorporated)
abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2008.6 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2013.0 - Acer Incorporated)
Acer Care Center (HKLM\...\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3002 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8107 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.02.2006 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD Accelerated Video Transcoding (Version: 13.30.100.40402 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2014.0402.434.6267 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{9D98D3EC-9BB8-47EF-66B6-B652B9846634}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.10.0.0 - AppEx Networks)
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.02.2004.7 - Acer Incorporated)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.223.234 - Broadcom Corporation)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0402.0433.6267 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0402.434.6267 - Advanced Micro Devices, Inc.) Hidden
CHIP Updater (HKLM-x32\...\CHIP Updater_is1) (Version: 2.33 - Abelssoft)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.1.4917 - CyberLink Corp.) Hidden
CyberLink Power Media Player 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.4218 - CyberLink Corp.)
CyberLink Power Media Player 12 (x32 Version: 12.0.3.4218 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.0.4220 - CyberLink Corp.) Hidden
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Foxit PhantomPDF (HKLM-x32\...\{D4DF5498-C95C-4A02-9951-725FB2D7BC0D}) (Version: 6.0.121.624 - Foxit Corporation)
Game Explorer Categories - genres (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Host App Service (HKCU\...\Pokki) (Version: 0.269.3.181 - Pokki)
Jewel Match 3 (x32 Version: 3.0.2.59 - WildTangent) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.2.0 - Mozilla)
Mozilla Thunderbird 31.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.2.0 (x86 de)) (Version: 31.2.0 - Mozilla)
OEM Application Profile (HKLM-x32\...\{276FD4A2-030F-8A24-7DFE-9B1384131BCD}) (Version: 1.00.0000 - Ihr Firmenname)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 3.0.2.59 - WildTangent) Hidden
Pokki Start Menu (HKCU\...\Pokki_Start_Menu) (Version: 0.269.3.181 - )
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21250 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7218 - Realtek Semiconductor Corp.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
WIDCOMM Bluetooth Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.9350 - Broadcom Corporation)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
23-10-2014 21:46:17 Installed Classic Shell
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {06C81F7B-3EF8-4ADD-A706-476F1345EB31} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {142CD5A0-EDC4-42B8-91C8-3D8A488DC4AE} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-06-10] (Acer Incorporate)
Task: {1F7FADEB-93D3-427B-B515-9BFF0BF7D9C5} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2014-10-20] (Acer)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2923779E-6EEB-48BE-A74D-8C074541E151} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-07-02] ()
Task: {29D4C0D1-05D7-4861-A0D0-E095A3656461} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {308C4CB0-75CA-4EAE-9F38-D3B1A5BE48A8} - System32\Tasks\Upgrade Acer Care Center Application => C:\ProgramData\OEM\UpgradeTool\CareCenter\UpgradeTool.exe [2014-07-01] (Acer Incorporated)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {4621F24C-2B09-4415-A9B5-59E80B23B1ED} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-07-02] ()
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7CC3A020-2B4B-420B-B12D-B45BF4A1101B} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-17] (Acer Incorporated)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9F0EB514-5D9B-4566-9D69-E070849ECFA6} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe [2014-09-19] (CHIP)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {AA9F1F0F-147D-4013-A93A-B1C5D81C0680} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-08] (Acer Incorporated)
Task: {BF58E14B-1069-43E0-80DD-BB525A2FD9CD} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D08F1AB1-8F5E-4779-937E-7A750E734C77} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DDFE19C7-1536-4600-8D05-CF048B6268F4} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
Task: {E2ACF668-4308-4463-9ECA-B3DD4467FB01} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {E3BDCA69-0278-4D27-AE94-D673C4802877} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F319C2C0-8B35-4211-85B3-C71D37B77995} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {F69239AC-BF10-463C-8CAE-7FD508923AE7} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: <Company name>)
Task: {FC6E253D-C967-4BB2-8809-0D66DB8439A1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-03] (Microsoft Corporation)
==================== Loaded Modules (whitelisted) =============
2014-02-18 20:02 - 2014-02-18 20:02 - 00049368 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
2014-07-25 23:23 - 2012-04-24 12:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-07-25 23:27 - 2014-07-01 23:13 - 00111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2014-10-24 00:20 - 2014-10-24 00:20 - 00015616 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-10-17 18:02 - 2014-10-17 18:02 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-08-20 17:45 - 2014-08-20 17:45 - 00279296 _____ () C:\Program Files (x86)\Acer\abDocs\libcurl.dll
2014-09-16 10:15 - 2014-09-16 10:15 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-09-16 10:16 - 2014-09-16 10:16 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-09-16 10:16 - 2014-09-16 10:16 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-09-16 10:16 - 2014-09-16 10:16 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2014-10-24 00:02 - 2014-10-11 14:53 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00569856 _____ () C:\Users\User 1\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 01400846 _____ () C:\Users\User 1\AppData\Local\Pokki\Engine\avcodec-54.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00151054 _____ () C:\Users\User 1\AppData\Local\Pokki\Engine\avutil-51.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00222734 _____ () C:\Users\User 1\AppData\Local\Pokki\Engine\avformat-54.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-3034447575-3866697844-1120935809-500 - Administrator - Disabled)
Gast (S-1-5-21-3034447575-3866697844-1120935809-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3034447575-3866697844-1120935809-1003 - Limited - Enabled)
User 1 (S-1-5-21-3034447575-3866697844-1120935809-1001 - Administrator - Enabled) => C:\Users\User 1
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/24/2014 03:58:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x5440e919
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.8387, Zeitstempel: 0x51ea24a5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00056b1d
ID des fehlerhaften Prozesses: 0x1058
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/24/2014 02:32:05 PM) (Source: MsiInstaller) (EventID: 10005) (User: Homie)
Description: Produkt: OpenOffice 4.1.1 -- Bitte benutzen Sie die Datei setup.exe, um die Installation zu starten.
Error: (10/24/2014 00:19:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x541fd7d6
Name des fehlerhaften Moduls: UPMonitor.dll, Version: 0.0.0.0, Zeitstempel: 0x53eda1e1
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000e29f
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/24/2014 00:18:39 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/24/2014 00:18:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x541fd7d6
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0025c70e
ID des fehlerhaften Prozesses: 0x1bf8
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/24/2014 00:18:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x541fd7d6
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc00001a5
Fehleroffset: 0x00279b54
ID des fehlerhaften Prozesses: 0x1bf8
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/23/2014 11:48:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x5410344e
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0025c70e
ID des fehlerhaften Prozesses: 0xff0
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/23/2014 11:48:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x5410344e
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc00001a5
Fehleroffset: 0x00279b54
ID des fehlerhaften Prozesses: 0xff0
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/23/2014 11:39:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.5, Zeitstempel: 0x53e1eb8b
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0025b078
ID des fehlerhaften Prozesses: 0x89c
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (10/23/2014 11:39:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.5, Zeitstempel: 0x53e1eb8b
Name des fehlerhaften Moduls: UPMonitor.dll_unloaded, Version: 1.0.3.1, Zeitstempel: 0x53b14733
Ausnahmecode: 0xc00001a5
Fehleroffset: 0x0027cc53
ID des fehlerhaften Prozesses: 0x89c
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
System errors:
=============
Error: (10/24/2014 03:30:10 PM) (Source: DCOM) (EventID: 10010) (User: Homie)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (10/24/2014 03:29:40 PM) (Source: DCOM) (EventID: 10010) (User: Homie)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (10/24/2014 02:50:56 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (10/24/2014 02:39:15 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: 1053mcpltsvcNicht verfügbar{20966775-18A4-4299-B8E3-772C336B52A7}
Error: (10/24/2014 02:39:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Platform Services" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/24/2014 02:39:15 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst McAfee Platform Services erreicht.
Error: (10/24/2014 02:39:15 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: 1053mcpltsvcNicht verfügbar{20966775-18A4-4299-B8E3-772C336B52A7}
Error: (10/24/2014 02:39:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Platform Services" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/24/2014 02:39:15 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst McAfee Platform Services erreicht.
Error: (10/24/2014 02:39:14 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: 1053mcpltsvcNicht verfügbar{26608B46-476A-4BF1-9CC6-AFEA28EBBC17}
Microsoft Office Sessions:
=========================
Error: (10/24/2014 03:58:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.65440e919MSVCR90.dll9.0.30729.838751ea24a5c000000500056b1d105801cfef863eed64d3C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeC:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb\MSVCR90.dlld76804bc-5b85-11e4-8261-f8a963e28f87
Error: (10/24/2014 02:32:05 PM) (Source: MsiInstaller) (EventID: 10005) (User: Homie)
Description: Produkt: OpenOffice 4.1.1 -- Bitte benutzen Sie die Datei setup.exe, um die Installation zu starten. (NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/24/2014 00:19:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.6541fd7d6UPMonitor.dll0.0.0.053eda1e1c00000050000e29f
Error: (10/24/2014 00:18:39 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll
Error: (10/24/2014 00:18:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.6541fd7d6UPMonitor.dll_unloaded1.0.3.153b14733c00000050025c70e1bf801cfef0e5a53cec1C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll85357fb5-5b02-11e4-825e-f8a963e28f87
Error: (10/24/2014 00:18:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.6541fd7d6UPMonitor.dll_unloaded1.0.3.153b14733c00001a500279b541bf801cfef0e5a53cec1C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll8146d38a-5b02-11e4-825e-f8a963e28f87
Error: (10/23/2014 11:48:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.65410344eUPMonitor.dll_unloaded1.0.3.153b14733c00000050025c70eff001cfef0b08dde191C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll4d27cfe0-5afe-11e4-825e-f8a963e28f87
Error: (10/23/2014 11:48:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.65410344eUPMonitor.dll_unloaded1.0.3.153b14733c00001a500279b54ff001cfef0b08dde191C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll4b805028-5afe-11e4-825e-f8a963e28f87
Error: (10/23/2014 11:39:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.553e1eb8bUPMonitor.dll_unloaded1.0.3.153b14733c00000050025b07889c01cfef09daeb2831C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll1e865e9b-5afd-11e4-825e-f8a963e28f87
Error: (10/23/2014 11:39:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.553e1eb8bUPMonitor.dll_unloaded1.0.3.153b14733c00001a50027cc5389c01cfef09daeb2831C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeUPMonitor.dll1bfe174f-5afd-11e4-825e-f8a963e28f87
==================== Memory info ===========================
Processor: AMD A10-7300 Radeon R6, 10 Compute Cores 4C+6G
Percentage of memory in use: 38%
Total physical RAM: 7114.26 MB
Available physical RAM: 4345.9 MB
Total Pagefile: 8906.26 MB
Available Pagefile: 6115.89 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:449.17 GB) (Free:414.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 1B4BA8FB)
Partition: GPT Partition Type.
==================== End Of Log ============================
Könnt ihr da was machen?
Beste Grüße
Antinomie |