|
Plagegeister aller Art und deren Bekämpfung: mmc.exe versucht Win-Dateien zu verändern; Avast deaktiviert; PC langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.04.2014, 10:24 | #1 |
| mmc.exe versucht Win-Dateien zu verändern; Avast deaktiviert; PC langsam Guten Tag liebe Community, seit gestern habe ich Probleme mit meinem PC. Es fing damit an, dass mein PC sehr langsam wurde und jegliche Aktion deutlich länger dauerte. Also startete ich diesen neu, die Probleme blieben jedoch bestehen. Mir fiel auf, dass sich die Funktion meinen Antivirenschutzes Avast einfach deaktiviert hat. Also versuchte ich diesen zu aktivieren, jedoch passierte nichts. Außerdem kam die Meldung, dass die "mmc.exe" versucht hat einige Windows-Dateien zu verändern. Da es mir durch die Benutzerkontensteuerung angezeigt wurde drückte ich auf "Nein". Obwohl ich auf nein klickte kam einige Minuten später die Meldung, dass einige Windows Dateien verändert wurden. Hier sind einige Fehlermeldungen die während der Benutzung des Computers auftraten: Code:
ATTFilter AvastUI.exe - Fehler in Anwendung: Die Anweisung bei "0x000000007359D040" verwies auf Speicher bei "0x000000007359D040". Die erforderlichen Daten wurden aufgrund eines E/A-Fehlers in "0x0000185" nicht an den Arbeitsspeicher übertragen. Klicken Sie auf "OK" um das Programm zu beenden. C:\Users\Steven\Desktop\Defogger.exe: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. WerFault.exe - Ungültiges Bild: C:\Windows\Microsoft.NET\Framework64\v4.0.30139\mscordacwks.dll ist entweder nicht für die Ausführung unter Windows vorgesehen oder enthält einen Fehler. Installieren Sie das Programm mit den Originalinstallationsmedien erneut, oder wenden Sie sich an den Systemadministrator oder Softwarelieferanten, um Unterstützung zu erhalten. CCC.exe - Ungültiges Bild: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll ist entweder nicht für die Ausführung unter Windows vorgesehen oder enthält einen Fehler. Installieren Sie das Programm mit den Originalinstallationsmedien erneut, oder wenden Sie sich an den Systemadministrator oder Softwarelieferanten, um Unterstützung zu erhalten. MOM.exe - Assert Failure (Bei Bedarf werde ich den kompletten Fehler Posten) Da es bei dem Scan zu der oben genannten Zeitüberschreitung kam, habe ich diese im Abgesicherten Modus durchgeführt. Hier sind folgende Scans: Defogger.exe: (Abgesicherter Modus) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 10:13 on 13/04/2014 (Steven) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST: (Abgesicherter Modus; wird momentan im "normalen" Modus durchgeführt) FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 Ran by Steven (administrator) on STEVEN-PC on 13-04-2014 10:14:32 Running from C:\Users\Steven\Desktop Windows 7 Ultimate (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Safe Mode (minimal) ==================== Processes (Whitelisted) ================= ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6827664 2012-08-07] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-03-12] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-12] (AVAST Software) HKU\S-1-5-21-4210536680-2876034217-3809175768-1000\...\MountPoints2: {3372c365-b374-11e3-87c9-806e6f6e6963} - D:\.\Bin\ASSETUP.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6E5820018E47CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.) BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR Extension: (ProxTube) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2014-03-26] CHR Extension: (Google Docs) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-24] CHR Extension: (Google Drive) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-24] CHR Extension: (YouTube) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-24] CHR Extension: (Adblock Plus) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-24] CHR Extension: (Google-Suche) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-24] CHR Extension: (avast! Online Security) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-03-24] CHR Extension: (Google Wallet) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-24] CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-03-27] CHR Extension: (Google Mail) - C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-24] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-03-30] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-12] ==================== Services (Whitelisted) ================= S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-12] (AVAST Software) S2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc) ==================== Drivers (Whitelisted) ==================== S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-12] (AVAST Software) S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-12] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-12] () S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-12] (AVAST Software) S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-12] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-12] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-12] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-13 10:14 - 2014-04-13 10:14 - 00006730 _____ () C:\Users\Steven\Desktop\FRST.txt 2014-04-13 10:13 - 2014-04-13 10:13 - 00000474 _____ () C:\Users\Steven\Desktop\defogger_disable.log 2014-04-13 10:10 - 2014-04-12 13:29 - 00380416 _____ () C:\Users\Steven\Desktop\Gmer-19357.exe 2014-04-13 10:10 - 2014-04-12 13:28 - 02157056 _____ (Farbar) C:\Users\Steven\Desktop\FRST64.exe 2014-04-13 10:10 - 2014-04-12 13:27 - 00050477 _____ () C:\Users\Steven\Desktop\Defogger.exe 2014-04-12 16:15 - 2014-04-12 16:15 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 16:14 - 2014-04-12 16:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 16:14 - 2014-04-12 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-12 16:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-12 16:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-12 16:14 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-12 16:11 - 2014-04-12 16:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Steven\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe 2014-04-12 14:46 - 2014-04-13 10:10 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-12 14:46 - 2014-04-12 14:46 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-12 14:46 - 2014-04-12 14:46 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-12 14:46 - 2014-04-12 14:46 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\AVAST Software 2014-04-12 14:45 - 2014-04-12 14:45 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-12 14:00 - 2014-04-12 14:00 - 00000000 ____D () C:\Windows\pss 2014-04-12 13:39 - 2014-04-13 10:14 - 00000000 ____D () C:\FRST 2014-04-12 13:37 - 2014-04-12 13:37 - 00000000 _____ () C:\Users\Steven\defogger_reenable 2014-04-09 23:17 - 2014-04-13 09:56 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-09 23:17 - 2014-04-09 23:17 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 23:17 - 2014-04-09 23:17 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-09 23:17 - 2014-04-09 23:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 23:17 - 2014-04-09 23:17 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-04-09 23:17 - 2014-04-09 23:17 - 00000000 ____D () C:\Windows\system32\Macromed 2014-04-09 23:16 - 2014-04-09 23:17 - 00000000 ____D () C:\Users\Steven\AppData\Local\Adobe 2014-04-09 23:14 - 2014-04-09 23:15 - 00000000 ____D () C:\Program Files (x86)\SarbyxTrayClock 2014-04-06 18:00 - 2014-04-06 18:00 - 00000000 ____D () C:\Users\Steven\Documents\Square Enix 2014-04-06 18:00 - 2014-04-06 18:00 - 00000000 ____D () C:\Users\Steven\AppData\Local\CrashRpt 2014-04-06 16:10 - 2014-04-06 16:10 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\WinRAR 2014-04-05 13:59 - 2014-04-10 23:22 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-04 23:46 - 2014-04-09 20:26 - 00000000 ____D () C:\Users\Steven\Documents\Diablo III 2014-04-04 21:51 - 2014-04-09 15:43 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-04-04 21:46 - 2014-04-13 00:02 - 00000000 ____D () C:\Users\Steven\AppData\Local\Battle.net 2014-04-04 21:46 - 2014-04-04 21:50 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Battle.net 2014-04-04 21:46 - 2014-04-04 21:46 - 00000000 ____D () C:\Users\Steven\AppData\Local\Blizzard Entertainment 2014-04-04 21:45 - 2014-04-04 21:45 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-04-04 21:44 - 2014-04-04 21:44 - 00000000 ____D () C:\ProgramData\Battle.net 2014-04-04 20:32 - 2014-04-04 20:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-04-04 20:28 - 2014-04-04 20:28 - 03881440 _____ (MetaQuotes Software Corp.) C:\Windows\system32\MetaViewer64.dll 2014-04-04 20:27 - 2014-04-04 20:28 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\MetaQuotes 2014-04-04 18:11 - 2014-04-04 18:11 - 00000000 ____D () C:\Users\Steven\AppData\Local\DayZCommander 2014-04-04 18:11 - 2014-04-04 18:11 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios 2014-04-02 22:48 - 2014-04-02 22:48 - 00277384 _____ () C:\Windows\Minidump\040214-16458-01.dmp 2014-03-31 18:08 - 2014-03-31 18:08 - 00000000 ____D () C:\Users\Steven\Documents\BFBC2 2014-03-31 18:08 - 2014-03-31 18:08 - 00000000 ____D () C:\Users\Steven\AppData\Local\PunkBuster 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\Users\Steven\Documents\Arma 3 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\Users\Steven\AppData\Local\Arma 3 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\ProgramData\Bohemia Interactive 2014-03-31 17:27 - 2014-04-04 18:13 - 00000000 ____D () C:\Users\Steven\AppData\Local\ArmA 2 OA 2014-03-31 17:25 - 2014-03-31 17:27 - 00000000 ____D () C:\Users\Steven\Documents\ArmA 2 2014-03-31 17:25 - 2014-03-31 17:25 - 00000000 ____D () C:\Users\Steven\AppData\Local\ArmA 2 2014-03-31 16:12 - 2014-04-12 14:48 - 00000000 ____D () C:\Users\Steven\Documents\Dokumente 2014-03-31 12:35 - 2014-03-31 12:35 - 00000000 ____D () C:\Users\Steven\AppData\Local\CDWLauncher 2014-03-31 10:22 - 2014-03-31 10:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-31 10:22 - 2014-03-31 10:22 - 00000000 ____D () C:\Program Files\WinRAR 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\OBS 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Program Files\OBS 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-30 16:30 - 2014-03-30 16:31 - 07829625 _____ () C:\Users\Steven\Documents\Livestream 30.03.14 1700Uhr.wmv 2014-03-30 16:22 - 2014-03-30 16:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\DVDVideoSoft 2014-03-30 16:22 - 2014-03-30 16:22 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-03-30 15:52 - 2014-03-30 15:52 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Publish Providers 2014-03-30 15:24 - 2014-03-30 16:29 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Sony 2014-03-30 15:24 - 2014-03-30 15:51 - 00000000 ____D () C:\Users\Steven\AppData\Local\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\ProgramData\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\Program Files\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-03-30 15:05 - 2014-03-30 15:06 - 00000000 ____D () C:\Users\Steven\Documents\Penumbra 2014-03-30 15:03 - 2014-03-30 15:05 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-03-30 15:03 - 2014-03-30 15:05 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-03-30 15:03 - 2014-03-30 15:05 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-03-30 15:03 - 2014-03-30 15:05 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-03-30 15:03 - 2014-03-30 15:03 - 00000000 ____D () C:\Users\Steven\Documents\Penumbra Overture 2014-03-30 15:03 - 2014-03-30 15:03 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-03-30 15:02 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2014-03-30 15:02 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-03-30 15:02 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-03-30 15:02 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-03-30 15:02 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-03-30 15:02 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-03-30 15:02 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2014-03-30 14:59 - 2014-03-30 14:59 - 00000000 ____D () C:\Users\Steven\Documents\EA Games 2014-03-30 14:58 - 2014-03-30 14:58 - 00000791 _____ () C:\Windows\DXError.log 2014-03-30 14:56 - 2014-03-30 14:56 - 00000000 ____D () C:\Users\Steven\AppData\Local\4A Games 2014-03-30 14:53 - 2014-03-30 14:53 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-03-30 14:52 - 2014-03-30 14:52 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-03-30 14:49 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-03-30 14:49 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-03-30 14:49 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-03-30 14:49 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-03-30 14:49 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-03-30 14:49 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-03-30 14:49 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-03-30 14:49 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-03-30 14:47 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-03-30 14:47 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-03-30 14:47 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-03-30 14:47 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-03-30 14:47 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-03-30 14:47 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-03-30 14:47 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-03-30 14:47 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-03-30 14:47 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-03-30 14:47 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-03-30 14:47 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-03-30 14:47 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-03-30 14:47 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-03-30 14:47 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-03-30 14:47 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-03-30 14:47 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-03-30 14:47 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-03-30 14:47 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-03-30 14:47 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-03-30 14:47 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-03-30 14:47 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-03-30 14:47 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-03-30 14:47 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-03-30 14:47 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-03-30 14:47 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-03-30 14:47 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-03-30 14:47 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-03-30 14:47 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-03-30 14:47 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-03-30 14:47 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-03-30 14:47 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-03-30 14:47 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-03-30 14:47 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-03-30 14:47 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-03-30 14:47 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-03-30 14:47 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-03-30 14:47 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-03-30 14:47 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-03-30 14:47 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-03-30 14:47 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-03-30 14:47 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-03-30 14:47 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-03-30 14:47 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-03-30 14:47 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-03-30 14:47 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-03-30 14:47 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-03-30 14:47 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-03-30 14:47 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-03-30 14:47 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-03-30 14:47 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-03-30 14:47 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-03-30 14:47 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-03-30 14:47 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-03-30 14:47 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-03-30 14:47 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-03-30 14:47 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-03-30 14:47 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-03-30 14:47 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-03-30 14:47 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-03-30 14:47 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-03-30 14:47 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-03-30 14:47 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-03-30 14:47 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-03-30 14:47 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-03-30 14:47 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-03-30 14:47 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-03-30 14:47 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-03-30 14:47 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-03-30 14:47 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-03-30 14:47 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-03-30 14:47 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-03-30 14:47 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-03-30 14:47 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-03-30 14:47 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-03-30 14:47 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-03-30 14:47 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-03-30 14:47 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-03-30 14:47 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-03-30 14:35 - 2014-03-30 14:46 - 00000000 ____D () C:\Users\Steven\Documents\Euro Truck Simulator 2 2014-03-30 10:59 - 2014-03-30 10:59 - 00000000 ____D () C:\ProgramData\Auslogics 2014-03-30 10:59 - 2014-03-30 10:59 - 00000000 ____D () C:\Program Files (x86)\Auslogics 2014-03-30 10:15 - 2014-03-31 17:18 - 00000000 ____D () C:\Users\Steven\Documents\my games 2014-03-30 01:50 - 2014-03-31 17:27 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-03-30 01:49 - 2014-03-31 17:34 - 00467107 _____ () C:\Windows\DirectX.log 2014-03-30 01:49 - 2006-05-31 08:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-03-30 01:49 - 2006-03-31 13:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-03-30 01:49 - 2006-03-31 13:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-03-30 01:49 - 2006-03-31 13:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-03-30 01:49 - 2006-03-31 13:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-03-30 01:49 - 2006-03-31 13:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-03-30 01:49 - 2006-03-31 13:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-03-30 01:49 - 2006-02-03 09:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-03-30 01:49 - 2006-02-03 09:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-03-30 01:49 - 2006-02-03 09:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-03-30 01:49 - 2006-02-03 09:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-03-30 01:49 - 2006-02-03 09:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-03-30 01:49 - 2006-02-03 09:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-03-30 01:49 - 2005-12-05 19:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-03-30 01:49 - 2005-12-05 19:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-03-30 01:49 - 2005-07-22 20:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-03-30 01:49 - 2005-07-22 20:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-03-30 01:49 - 2005-05-26 16:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-03-30 01:49 - 2005-05-26 16:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-03-30 01:49 - 2005-03-18 18:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-03-30 01:49 - 2005-03-18 18:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-03-30 01:49 - 2005-02-05 20:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-03-30 01:49 - 2005-02-05 20:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-03-29 22:36 - 2014-03-29 22:36 - 00000000 ____D () C:\Users\Steven\Documents\4a games 2014-03-29 01:15 - 2014-03-29 17:40 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-03-28 20:02 - 2014-03-28 20:02 - 00000000 ____D () C:\ProgramData\HP 2014-03-28 20:02 - 2012-01-31 16:12 - 00712552 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMB011.dll 2014-03-28 20:01 - 2014-03-28 20:03 - 00000000 ____D () C:\Users\Steven\AppData\Local\HP 2014-03-28 20:01 - 2014-03-28 20:01 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-03-28 20:01 - 2014-03-28 20:01 - 00000000 ____D () C:\Program Files\HP 2014-03-28 20:01 - 2014-03-28 20:01 - 00000000 ____D () C:\Program Files (x86)\HP 2014-03-28 19:45 - 2014-03-28 19:45 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\OpenOffice 2014-03-28 19:45 - 2014-03-28 19:45 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-27 00:09 - 2014-04-02 22:48 - 568331272 _____ () C:\Windows\MEMORY.DMP 2014-03-27 00:09 - 2014-04-02 22:48 - 00000000 ____D () C:\Windows\Minidump 2014-03-27 00:09 - 2014-03-27 00:09 - 00277384 _____ () C:\Windows\Minidump\032614-20092-01.dmp 2014-03-26 20:04 - 2014-03-26 20:04 - 00000493 _____ () C:\Users\Steven\Desktop\Energieoptionen - Verknüpfung.lnk 2014-03-25 19:57 - 2014-03-26 17:26 - 00000000 ____D () C:\Users\Steven\Documents\LOLReplay 2014-03-25 19:57 - 2014-03-25 19:57 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-03-25 19:52 - 2014-03-25 22:19 - 00000000 ____D () C:\Fraps 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Macromedia 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\LolClient 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Adobe 2014-03-24 20:59 - 2014-04-12 12:31 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\tor 2014-03-24 20:59 - 2014-04-12 11:57 - 00000000 ____D () C:\Users\Steven\AppData\Local\Vidalia 2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Users\Steven\AppData\Local\Tor 2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Vidalia Bridge Bundle 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\ATI 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\Users\Steven\AppData\Local\ATI 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\ProgramData\ATI 2014-03-24 20:54 - 2014-03-24 20:54 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-03-24 20:42 - 2014-03-24 20:42 - 00000000 ____D () C:\ProgramData\AMD 2014-03-24 20:42 - 2014-03-24 20:42 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-03-24 20:41 - 2014-03-24 20:41 - 00000000 ____D () C:\Program Files\AMD 2014-03-24 20:40 - 2014-03-31 12:33 - 01591896 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-24 20:40 - 2014-03-24 20:40 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-03-24 20:40 - 2014-03-24 20:40 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-03-24 20:38 - 2009-11-25 12:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-03-24 20:38 - 2009-11-25 12:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe 2014-03-24 20:38 - 2009-11-25 12:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll 2014-03-24 20:38 - 2009-11-25 12:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-03-24 20:28 - 2014-04-12 16:00 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-03-24 20:27 - 2014-03-31 12:28 - 00000000 ____D () C:\ProgramData\Package Cache 2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\ATI 2014-03-24 20:26 - 2014-03-24 20:42 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-03-24 20:25 - 2014-04-13 00:02 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\TS3Client 2014-03-24 20:25 - 2014-03-24 20:25 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-24 20:25 - 2014-03-24 20:25 - 00000000 ____D () C:\AMD 2014-03-24 20:24 - 2014-03-24 20:24 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-03-24 20:24 - 2014-03-24 20:24 - 00000000 ____D () C:\Riot Games 2014-03-24 20:24 - 2008-07-31 11:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-03-24 20:24 - 2008-07-31 11:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-03-24 20:24 - 2008-07-12 09:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-03-24 20:24 - 2008-07-12 09:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-03-24 20:24 - 2008-07-12 09:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-03-24 20:22 - 2014-03-24 20:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Google 2014-03-24 20:21 - 2014-04-10 18:46 - 00000000 ____D () C:\Users\Steven\AppData\Local\PMB Files 2014-03-24 20:21 - 2014-04-08 18:09 - 00000000 ____D () C:\ProgramData\PMB Files 2014-03-24 20:21 - 2014-03-24 20:21 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-03-24 20:20 - 2014-03-24 20:21 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Riot Games 2014-03-24 19:18 - 2014-04-13 09:43 - 00343518 _____ () C:\Windows\PFRO.log 2014-03-24 19:15 - 2014-03-31 09:35 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-24 19:15 - 2014-03-24 19:15 - 00000000 ____D () C:\ProgramData\Google 2014-03-24 19:15 - 2014-03-24 19:15 - 00000000 ____D () C:\Program Files\Google 2014-03-24 19:14 - 2014-04-13 10:03 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-24 19:14 - 2014-04-12 23:31 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-24 19:14 - 2014-04-04 17:26 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-24 19:14 - 2014-04-04 17:26 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-24 19:14 - 2014-03-24 20:22 - 00000000 ____D () C:\Users\Steven\AppData\Local\Google 2014-03-24 19:14 - 2014-03-24 19:15 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-24 19:12 - 2014-04-12 14:45 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-24 19:12 - 2014-03-31 21:03 - 00063960 _____ () C:\Users\Steven\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-24 19:04 - 2012-06-13 00:00 - 00726160 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2014-03-24 19:04 - 2012-06-13 00:00 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2014-03-24 19:04 - 2012-06-13 00:00 - 00074344 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2014-03-24 19:03 - 2014-03-24 19:03 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll 2014-03-24 19:03 - 2014-03-24 19:03 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-03-24 19:03 - 2014-03-24 19:03 - 00000000 ____D () C:\Program Files\Realtek 2014-03-24 19:03 - 2012-08-07 12:51 - 04102928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2014-03-24 19:03 - 2012-08-07 09:11 - 00329737 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT 2014-03-24 19:03 - 2012-08-06 09:44 - 01561744 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2014-03-24 19:03 - 2012-08-06 05:49 - 02743440 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2014-03-24 19:03 - 2012-08-03 06:13 - 05911552 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2014-03-24 19:03 - 2012-08-01 12:29 - 00109200 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2014-03-24 19:03 - 2012-07-24 11:30 - 00606336 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2014-03-24 19:03 - 2012-07-20 08:41 - 00880784 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2014-03-24 19:03 - 2012-07-19 10:51 - 02080120 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2014-03-24 19:03 - 2012-07-16 08:16 - 03643024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2014-03-24 19:03 - 2012-07-02 09:39 - 01264272 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2014-03-24 19:03 - 2012-01-30 05:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2014-03-24 19:03 - 2012-01-10 04:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2014-03-24 19:03 - 2011-12-20 09:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2014-03-24 19:03 - 2011-11-22 10:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2014-03-24 19:03 - 2011-09-02 08:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2014-03-24 19:03 - 2011-09-02 08:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2014-03-24 19:03 - 2011-09-02 08:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2014-03-24 19:03 - 2011-08-11 10:55 - 00001332 ____R () C:\Windows\system32\Drivers\DTSU2P.DAT 2014-03-24 19:03 - 2011-03-17 06:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2014-03-24 19:03 - 2011-03-07 11:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2014-03-24 19:03 - 2010-11-08 01:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2014-03-24 19:03 - 2010-11-03 12:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2014-03-24 19:03 - 2010-07-22 10:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2014-03-24 19:03 - 2009-11-24 03:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2014-03-24 19:03 - 2009-11-24 03:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2014-03-24 19:03 - 2009-11-24 03:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2014-03-24 19:03 - 2009-11-24 03:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2014-03-24 19:02 - 2014-03-24 19:04 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-24 19:02 - 2014-03-24 19:04 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-03-24 19:02 - 2012-08-03 12:18 - 01706640 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2014-03-24 19:02 - 2012-07-23 10:44 - 01433976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll 2014-03-24 19:02 - 2012-07-19 10:52 - 07598456 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2014-03-24 19:02 - 2012-07-19 10:52 - 02028920 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2014-03-24 19:02 - 2012-07-19 10:51 - 00834936 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2014-03-24 19:02 - 2012-07-15 15:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2014-03-24 19:02 - 2012-07-15 15:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2014-03-24 19:02 - 2012-06-20 11:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-03-24 19:02 - 2012-06-15 05:20 - 07163784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2014-03-24 19:02 - 2012-06-15 05:20 - 00433544 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2014-03-24 19:02 - 2012-06-15 05:20 - 00141192 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2014-03-24 19:02 - 2012-06-15 05:20 - 00123784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2014-03-24 19:02 - 2012-06-15 05:20 - 00074632 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2014-03-24 19:02 - 2012-04-10 08:40 - 02533952 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2014-03-24 19:02 - 2012-03-08 05:47 - 00202336 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2014-03-24 19:02 - 2012-03-08 05:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2014-03-24 19:02 - 2012-01-23 16:30 - 00537456 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2014-03-24 19:02 - 2012-01-23 16:30 - 00524656 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2014-03-24 19:02 - 2012-01-23 16:30 - 00449392 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2014-03-24 19:02 - 2011-08-23 11:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2014-03-24 19:02 - 2011-05-31 03:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2014-03-24 19:02 - 2010-09-27 03:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2014-03-24 19:01 - 2014-03-24 19:02 - 00055838 _____ () C:\Windows\Ascd_tmp.ini 2014-03-24 19:01 - 2014-03-24 19:01 - 00001769 _____ () C:\Windows\Language_trs.ini 2014-03-24 18:59 - 2014-03-24 18:59 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-03-24 18:57 - 2014-03-24 18:57 - 00001443 _____ () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-24 18:57 - 2014-03-24 18:57 - 00001409 _____ () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ____D () C:\Users\Steven\AppData\Local\VirtualStore 2014-03-24 18:56 - 2014-04-13 09:45 - 00000000 ____D () C:\Users\Steven 2014-03-24 18:56 - 2014-03-24 18:56 - 00000020 ___SH () C:\Users\Steven\ntuser.ini 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Vorlagen 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Startmenü 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Netzwerkumgebung 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Lokale Einstellungen 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Eigene Dateien 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Druckumgebung 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Documents\Eigene Musik 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Documents\Eigene Bilder 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Local\Verlauf 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Local\Anwendungsdaten 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Anwendungsdaten 2014-03-24 18:56 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-24 18:56 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-03-24 18:55 - 2014-03-24 18:55 - 00171136 __RSH () C:\w7ldr 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 __SHD () C:\Recovery 2014-03-24 18:52 - 2014-03-24 18:52 - 00001313 _____ () C:\Windows\TSSysprep.log 2014-03-24 18:51 - 2014-04-13 10:11 - 00193390 _____ () C:\Windows\WindowsUpdate.log 2014-03-24 18:48 - 2014-03-24 18:52 - 00000000 ____D () C:\Windows\Panther 2014-03-24 18:48 - 2014-03-24 18:48 - 00008192 __RSH () C:\BOOTSECT.BAK 2014-03-24 18:48 - 2009-07-14 03:38 - 00383562 __RSH () C:\bootmgr ==================== One Month Modified Files and Folders ======= 2014-04-13 10:14 - 2014-04-13 10:14 - 00006730 _____ () C:\Users\Steven\Desktop\FRST.txt 2014-04-13 10:14 - 2014-04-12 13:39 - 00000000 ____D () C:\FRST 2014-04-13 10:13 - 2014-04-13 10:13 - 00000474 _____ () C:\Users\Steven\Desktop\defogger_disable.log 2014-04-13 10:11 - 2014-03-24 18:51 - 00193390 _____ () C:\Windows\WindowsUpdate.log 2014-04-13 10:10 - 2014-04-12 14:46 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-13 10:07 - 2009-07-14 19:58 - 00698688 _____ () C:\Windows\system32\perfh007.dat 2014-04-13 10:07 - 2009-07-14 19:58 - 00148828 _____ () C:\Windows\system32\perfc007.dat 2014-04-13 10:07 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-13 10:03 - 2014-03-24 19:14 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-13 10:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-13 10:01 - 2009-07-14 07:08 - 00013734 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-13 09:56 - 2014-04-09 23:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 09:50 - 2009-07-14 06:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-13 09:50 - 2009-07-14 06:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-13 09:45 - 2014-03-24 18:56 - 00000000 ____D () C:\Users\Steven 2014-04-13 09:45 - 2009-07-14 06:51 - 00021903 _____ () C:\Windows\setupact.log 2014-04-13 09:43 - 2014-03-24 19:18 - 00343518 _____ () C:\Windows\PFRO.log 2014-04-13 00:02 - 2014-04-04 21:46 - 00000000 ____D () C:\Users\Steven\AppData\Local\Battle.net 2014-04-13 00:02 - 2014-03-24 20:25 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\TS3Client 2014-04-12 23:31 - 2014-03-24 19:14 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-12 16:15 - 2014-04-12 16:15 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 16:15 - 2014-04-12 16:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-12 16:14 - 2014-04-12 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-12 16:11 - 2014-04-12 16:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Steven\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe 2014-04-12 16:00 - 2014-03-24 20:28 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-12 14:48 - 2014-03-31 16:12 - 00000000 ____D () C:\Users\Steven\Documents\Dokumente 2014-04-12 14:46 - 2014-04-12 14:46 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-12 14:46 - 2014-04-12 14:46 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-12 14:46 - 2014-04-12 14:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-12 14:46 - 2014-04-12 14:46 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\AVAST Software 2014-04-12 14:45 - 2014-04-12 14:45 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-12 14:45 - 2014-03-24 19:12 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-12 14:00 - 2014-04-12 14:00 - 00000000 ____D () C:\Windows\pss 2014-04-12 13:37 - 2014-04-12 13:37 - 00000000 _____ () C:\Users\Steven\defogger_reenable 2014-04-12 13:29 - 2014-04-13 10:10 - 00380416 _____ () C:\Users\Steven\Desktop\Gmer-19357.exe 2014-04-12 13:28 - 2014-04-13 10:10 - 02157056 _____ (Farbar) C:\Users\Steven\Desktop\FRST64.exe 2014-04-12 13:27 - 2014-04-13 10:10 - 00050477 _____ () C:\Users\Steven\Desktop\Defogger.exe 2014-04-12 12:31 - 2014-03-24 20:59 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\tor 2014-04-12 11:57 - 2014-03-24 20:59 - 00000000 ____D () C:\Users\Steven\AppData\Local\Vidalia 2014-04-10 23:22 - 2014-04-05 13:59 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-10 18:46 - 2014-03-24 20:21 - 00000000 ____D () C:\Users\Steven\AppData\Local\PMB Files 2014-04-09 23:17 - 2014-04-09 23:17 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 23:17 - 2014-04-09 23:17 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-09 23:17 - 2014-04-09 23:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 23:17 - 2014-04-09 23:17 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-04-09 23:17 - 2014-04-09 23:17 - 00000000 ____D () C:\Windows\system32\Macromed 2014-04-09 23:17 - 2014-04-09 23:16 - 00000000 ____D () C:\Users\Steven\AppData\Local\Adobe 2014-04-09 23:15 - 2014-04-09 23:14 - 00000000 ____D () C:\Program Files (x86)\SarbyxTrayClock 2014-04-09 20:26 - 2014-04-04 23:46 - 00000000 ____D () C:\Users\Steven\Documents\Diablo III 2014-04-09 15:43 - 2014-04-04 21:51 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-04-08 18:09 - 2014-03-24 20:21 - 00000000 ____D () C:\ProgramData\PMB Files 2014-04-06 18:00 - 2014-04-06 18:00 - 00000000 ____D () C:\Users\Steven\Documents\Square Enix 2014-04-06 18:00 - 2014-04-06 18:00 - 00000000 ____D () C:\Users\Steven\AppData\Local\CrashRpt 2014-04-06 16:10 - 2014-04-06 16:10 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\WinRAR 2014-04-04 21:50 - 2014-04-04 21:46 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Battle.net 2014-04-04 21:46 - 2014-04-04 21:46 - 00000000 ____D () C:\Users\Steven\AppData\Local\Blizzard Entertainment 2014-04-04 21:45 - 2014-04-04 21:45 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-04-04 21:44 - 2014-04-04 21:44 - 00000000 ____D () C:\ProgramData\Battle.net 2014-04-04 20:32 - 2014-04-04 20:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-04-04 20:28 - 2014-04-04 20:28 - 03881440 _____ (MetaQuotes Software Corp.) C:\Windows\system32\MetaViewer64.dll 2014-04-04 20:28 - 2014-04-04 20:27 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\MetaQuotes 2014-04-04 18:13 - 2014-03-31 17:27 - 00000000 ____D () C:\Users\Steven\AppData\Local\ArmA 2 OA 2014-04-04 18:11 - 2014-04-04 18:11 - 00000000 ____D () C:\Users\Steven\AppData\Local\DayZCommander 2014-04-04 18:11 - 2014-04-04 18:11 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios 2014-04-04 17:26 - 2014-03-24 19:14 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-04 17:26 - 2014-03-24 19:14 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 09:51 - 2014-04-12 16:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-12 16:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-12 16:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 22:48 - 2014-04-02 22:48 - 00277384 _____ () C:\Windows\Minidump\040214-16458-01.dmp 2014-04-02 22:48 - 2014-03-27 00:09 - 568331272 _____ () C:\Windows\MEMORY.DMP 2014-04-02 22:48 - 2014-03-27 00:09 - 00000000 ____D () C:\Windows\Minidump 2014-04-01 17:01 - 2009-07-14 06:45 - 00293344 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-31 21:03 - 2014-03-24 19:12 - 00063960 _____ () C:\Users\Steven\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-31 18:08 - 2014-03-31 18:08 - 00000000 ____D () C:\Users\Steven\Documents\BFBC2 2014-03-31 18:08 - 2014-03-31 18:08 - 00000000 ____D () C:\Users\Steven\AppData\Local\PunkBuster 2014-03-31 17:34 - 2014-03-30 01:49 - 00467107 _____ () C:\Windows\DirectX.log 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\Users\Steven\Documents\Arma 3 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\Users\Steven\AppData\Local\Arma 3 2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\ProgramData\Bohemia Interactive 2014-03-31 17:27 - 2014-03-31 17:25 - 00000000 ____D () C:\Users\Steven\Documents\ArmA 2 2014-03-31 17:27 - 2014-03-30 01:50 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-03-31 17:25 - 2014-03-31 17:25 - 00000000 ____D () C:\Users\Steven\AppData\Local\ArmA 2 2014-03-31 17:18 - 2014-03-30 10:15 - 00000000 ____D () C:\Users\Steven\Documents\my games 2014-03-31 12:35 - 2014-03-31 12:35 - 00000000 ____D () C:\Users\Steven\AppData\Local\CDWLauncher 2014-03-31 12:33 - 2014-03-24 20:40 - 01591896 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-31 12:28 - 2014-03-24 20:27 - 00000000 ____D () C:\ProgramData\Package Cache 2014-03-31 10:22 - 2014-03-31 10:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-31 10:22 - 2014-03-31 10:22 - 00000000 ____D () C:\Program Files\WinRAR 2014-03-31 09:35 - 2014-03-24 19:15 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\OBS 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Program Files\OBS 2014-03-30 16:41 - 2014-03-30 16:41 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-30 16:31 - 2014-03-30 16:30 - 07829625 _____ () C:\Users\Steven\Documents\Livestream 30.03.14 1700Uhr.wmv 2014-03-30 16:29 - 2014-03-30 15:24 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Sony 2014-03-30 16:22 - 2014-03-30 16:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\DVDVideoSoft 2014-03-30 16:22 - 2014-03-30 16:22 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-03-30 15:52 - 2014-03-30 15:52 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Publish Providers 2014-03-30 15:51 - 2014-03-30 15:24 - 00000000 ____D () C:\Users\Steven\AppData\Local\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\ProgramData\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\Program Files\Sony 2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-03-30 15:06 - 2014-03-30 15:05 - 00000000 ____D () C:\Users\Steven\Documents\Penumbra 2014-03-30 15:05 - 2014-03-30 15:03 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-03-30 15:05 - 2014-03-30 15:03 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2014-03-30 15:05 - 2014-03-30 15:03 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-03-30 15:05 - 2014-03-30 15:03 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-03-30 15:03 - 2014-03-30 15:03 - 00000000 ____D () C:\Users\Steven\Documents\Penumbra Overture 2014-03-30 15:03 - 2014-03-30 15:03 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2014-03-30 14:59 - 2014-03-30 14:59 - 00000000 ____D () C:\Users\Steven\Documents\EA Games 2014-03-30 14:58 - 2014-03-30 14:58 - 00000791 _____ () C:\Windows\DXError.log 2014-03-30 14:56 - 2014-03-30 14:56 - 00000000 ____D () C:\Users\Steven\AppData\Local\4A Games 2014-03-30 14:53 - 2014-03-30 14:53 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-03-30 14:52 - 2014-03-30 14:52 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-03-30 14:46 - 2014-03-30 14:35 - 00000000 ____D () C:\Users\Steven\Documents\Euro Truck Simulator 2 2014-03-30 10:59 - 2014-03-30 10:59 - 00000000 ____D () C:\ProgramData\Auslogics 2014-03-30 10:59 - 2014-03-30 10:59 - 00000000 ____D () C:\Program Files (x86)\Auslogics 2014-03-29 22:36 - 2014-03-29 22:36 - 00000000 ____D () C:\Users\Steven\Documents\4a games 2014-03-29 17:40 - 2014-03-29 01:15 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-03-28 20:03 - 2014-03-28 20:01 - 00000000 ____D () C:\Users\Steven\AppData\Local\HP 2014-03-28 20:02 - 2014-03-28 20:02 - 00000000 ____D () C:\ProgramData\HP 2014-03-28 20:01 - 2014-03-28 20:01 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-03-28 20:01 - 2014-03-28 20:01 - 00000000 ____D () C:\Program Files\HP 2014-03-28 20:01 - 2014-03-28 20:01 - 00000000 ____D () C:\Program Files (x86)\HP 2014-03-28 20:00 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-03-28 19:45 - 2014-03-28 19:45 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\OpenOffice 2014-03-28 19:45 - 2014-03-28 19:45 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-27 00:09 - 2014-03-27 00:09 - 00277384 _____ () C:\Windows\Minidump\032614-20092-01.dmp 2014-03-26 20:04 - 2014-03-26 20:04 - 00000493 _____ () C:\Users\Steven\Desktop\Energieoptionen - Verknüpfung.lnk 2014-03-26 17:26 - 2014-03-25 19:57 - 00000000 ____D () C:\Users\Steven\Documents\LOLReplay 2014-03-25 22:19 - 2014-03-25 19:52 - 00000000 ____D () C:\Fraps 2014-03-25 19:57 - 2014-03-25 19:57 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Macromedia 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\LolClient 2014-03-24 21:43 - 2014-03-24 21:43 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Adobe 2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Users\Steven\AppData\Local\Tor 2014-03-24 20:59 - 2014-03-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Vidalia Bridge Bundle 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\ATI 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\Users\Steven\AppData\Local\ATI 2014-03-24 20:55 - 2014-03-24 20:55 - 00000000 ____D () C:\ProgramData\ATI 2014-03-24 20:54 - 2014-03-24 20:54 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-03-24 20:42 - 2014-03-24 20:42 - 00000000 ____D () C:\ProgramData\AMD 2014-03-24 20:42 - 2014-03-24 20:42 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-03-24 20:42 - 2014-03-24 20:26 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-03-24 20:41 - 2014-03-24 20:41 - 00000000 ____D () C:\Program Files\AMD 2014-03-24 20:40 - 2014-03-24 20:40 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-03-24 20:40 - 2014-03-24 20:40 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-03-24 20:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\ATI 2014-03-24 20:25 - 2014-03-24 20:25 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-24 20:25 - 2014-03-24 20:25 - 00000000 ____D () C:\AMD 2014-03-24 20:24 - 2014-03-24 20:24 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-03-24 20:24 - 2014-03-24 20:24 - 00000000 ____D () C:\Riot Games 2014-03-24 20:22 - 2014-03-24 20:22 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Google 2014-03-24 20:22 - 2014-03-24 19:14 - 00000000 ____D () C:\Users\Steven\AppData\Local\Google 2014-03-24 20:21 - 2014-03-24 20:21 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-03-24 20:21 - 2014-03-24 20:20 - 00000000 ____D () C:\Users\Steven\AppData\Roaming\Riot Games 2014-03-24 19:15 - 2014-03-24 19:15 - 00000000 ____D () C:\ProgramData\Google 2014-03-24 19:15 - 2014-03-24 19:15 - 00000000 ____D () C:\Program Files\Google 2014-03-24 19:15 - 2014-03-24 19:14 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-24 19:10 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-03-24 19:04 - 2014-03-24 19:02 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-24 19:04 - 2014-03-24 19:02 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-03-24 19:04 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore 2014-03-24 19:03 - 2014-03-24 19:03 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll 2014-03-24 19:03 - 2014-03-24 19:03 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-03-24 19:03 - 2014-03-24 19:03 - 00000000 ____D () C:\Program Files\Realtek 2014-03-24 19:02 - 2014-03-24 19:01 - 00055838 _____ () C:\Windows\Ascd_tmp.ini 2014-03-24 19:01 - 2014-03-24 19:01 - 00001769 _____ () C:\Windows\Language_trs.ini 2014-03-24 18:59 - 2014-03-24 18:59 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-03-24 18:57 - 2014-03-24 18:57 - 00001443 _____ () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-24 18:57 - 2014-03-24 18:57 - 00001409 _____ () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ___RD () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-24 18:57 - 2014-03-24 18:57 - 00000000 ____D () C:\Users\Steven\AppData\Local\VirtualStore 2014-03-24 18:56 - 2014-03-24 18:56 - 00000020 ___SH () C:\Users\Steven\ntuser.ini 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Vorlagen 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Startmenü 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Netzwerkumgebung 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Lokale Einstellungen 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Eigene Dateien 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Druckumgebung 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Documents\Eigene Musik 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Documents\Eigene Bilder 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Local\Verlauf 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\AppData\Local\Anwendungsdaten 2014-03-24 18:56 - 2014-03-24 18:56 - 00000000 _SHDL () C:\Users\Steven\Anwendungsdaten 2014-03-24 18:55 - 2014-03-24 18:55 - 00171136 __RSH () C:\w7ldr 2014-03-24 18:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Programme 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-03-24 18:54 - 2014-03-24 18:54 - 00000000 __SHD () C:\Recovery 2014-03-24 18:54 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-03-24 18:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Windows NT 2014-03-24 18:52 - 2014-03-24 18:52 - 00001313 _____ () C:\Windows\TSSysprep.log 2014-03-24 18:52 - 2014-03-24 18:48 - 00000000 ____D () C:\Windows\Panther 2014-03-24 18:52 - 2009-07-14 06:46 - 00001774 _____ () C:\Windows\DtcInstall.log 2014-03-24 18:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-03-24 18:49 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\CSC 2014-03-24 18:48 - 2014-03-24 18:48 - 00008192 __RSH () C:\BOOTSECT.BAK 2014-03-24 18:48 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-03-24 18:48 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-03-24 18:47 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup Some content of TEMP: ==================== C:\Users\Steven\AppData\Local\Temp\swt-win32-3349.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 16:52 ==================== End Of Log ============================ --- --- --- --- --- --- Addition: (Der Log befindet sich im Anhang) GMER (Der Scan ergab keine Systemveränderungen. Nachdem ich auf Save geklickt habe passierte nichts. Der Scan wurde ebenfalls im Abgesicherten Modus durchgeführt) Ich bedanke mich schon einmal im Vorraus für eure Hilfe. MfG Steven |
13.04.2014, 11:49 | #2 |
| mmc.exe versucht Win-Dateien zu verändern; Avast deaktiviert; PC langsam Das Problem hat sich erledigt und dieser Thread muss nicht weiter beachtet werden.
__________________ |
18.04.2014, 14:24 | #3 |
/// the machine /// TB-Ausbilder | mmc.exe versucht Win-Dateien zu verändern; Avast deaktiviert; PC langsam ok
__________________
__________________ |
Themen zu mmc.exe versucht Win-Dateien zu verändern; Avast deaktiviert; PC langsam |
adobe, adobe flash player, antivirus, asus, avast, avast deaktiviert, desktop, download, dvdvideosoft ltd., euro, explorer, flash player, focus, google, helper, iexplore.exe, langsam, langsamer pc, minidump, mmc.exe, nvidia, programm, realtek, registry, scan, security, services.exe, svchost.exe, systemadministrator, tan, teamspeak, ungültiges, winlogon.exe |