![]() |
Log-Analyse und Auswertung: CPU Auslastung von 0 auf 100% ProzentWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
| ![]() CPU Auslastung von 0 auf 100% Prozent Hallo, vor 2 Tagen habe ich meinen Laptop neu installiert / aufgesetzt, seid dem habe ich das Problem das die CPU von 0-4% einfach so auf 100% steigt und dann nach 10 bis 30 sekunden wieder sinkt. Dies passiert ca. alle 5 Minuten. Was kann das sein? Danke für eure Antworten PS: Hier das Ergebnis von OTLOTL Logfile: Code:
ATTFilter OTL logfile created on: 24.03.2015 15:21:58 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Armin\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,75 Gb Total Physical Memory | 2,47 Gb Available Physical Memory | 66,02% Memory free 7,49 Gb Paging File | 5,80 Gb Available in Paging File | 77,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 220,78 Gb Total Space | 115,73 Gb Free Space | 52,42% Space Free | Partition Type: NTFS Drive E: | 465,76 Gb Total Space | 320,05 Gb Free Space | 68,72% Space Free | Partition Type: NTFS Computer Name: ARMINSPC | User Name: Armin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Armin Stafflinger\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) ========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\pdf.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libglesv2.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libegl.dll () MOD - C:\Program Files (x86)\Avira\My Avira\System.ComponentModel.Composition.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\\System.ServiceModel.resources.dll () MOD - C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\\PresentationFramework.resources.dll () MOD - C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\\PresentationCore.resources.dll () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.ServiceProcess.resources\\System.ServiceProcess.resources.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e791f7aea04b8d379f6dbaadb5fdeb96\System.IdentityModel.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e1adf6b481f5120153829fa54ee8a041\System.ServiceModel.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\39e53f507d9cbc5c10a2f47c4b0d09dd\System.Runtime.Serialization.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\81282964925798589021d3e0e6de779f\SMDiagnostics.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ad8a7493b8e2280fc404be082e295478\System.Xml.Linq.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c69c5877e9c9033a6dc6dd35ef20a896\System.Data.Linq.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\1762137638019a091020b3baf52f6de3\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\39f5a71b5185d267b0f55cd4cea26d6b\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\97adf9fccd70327b839a92c3d038b101\System.Transactions.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\7f457271e765b5d72f081942b829469c\System.Data.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\68e5eeb3c6ef18ba2dc1ad70eb74aeee\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b459c5815af8123e4bf30d4e05bba65\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll () MOD - C:\Windows\assembly\GAC_32\System.Transactions\\System.Transactions.dll () MOD - C:\Windows\assembly\GAC_32\System.Data\\System.Data.dll () ========== Services (SafeList) ========== SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (Avira.OE.ServiceHost) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (k57nd60a) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 4E 3D 70 7F 65 D0 01 [binary data] IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) ========== Chrome ========== CHR - plugin: Error reading preferences file CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\\ CHR - Extension: No name found = C:\Users\Armin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8_0\ O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C65E7DA-0359-46C8-8988-21FADAF2F892}: DhcpNameServer = O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{c0985055-d16f-11e4-88bc-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c0985055-d16f-11e4-88bc-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE O33 - MountPoints2\{c0985055-d16f-11e4-88bc-806e6f6e6963}\Shell\configure\command - "" = D:\SETUP.EXE O33 - MountPoints2\{c0985055-d16f-11e4-88bc-806e6f6e6963}\Shell\install\command - "" = D:\SETUP.EXE O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2015.03.24 15:19:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Armin Stafflinger\Desktop\OTL.exe [2015.03.24 14:55:14 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT [2015.03.24 14:41:10 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll [2015.03.24 14:41:10 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll [2015.03.24 14:41:10 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll [2015.03.24 14:41:10 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll [2015.03.24 14:41:10 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll [2015.03.24 14:41:10 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll [2015.03.24 14:41:09 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll [2015.03.24 14:41:09 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll [2015.03.24 14:41:09 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll [2015.03.24 14:41:09 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll [2015.03.24 14:41:09 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll [2015.03.24 14:41:09 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll [2015.03.24 14:41:08 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll [2015.03.24 14:41:08 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll [2015.03.24 14:41:08 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll [2015.03.24 14:41:08 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll [2015.03.24 14:41:07 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_6.dll [2015.03.24 14:41:07 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_6.dll [2015.03.24 14:41:07 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_4.dll [2015.03.24 14:41:07 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_4.dll [2015.03.24 14:41:06 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_6.dll [2015.03.24 14:41:06 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_6.dll [2015.03.24 14:41:06 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_7.dll [2015.03.24 14:41:06 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_7.dll [2015.03.24 14:41:04 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_5.dll [2015.03.24 14:41:04 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll [2015.03.24 14:41:04 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll [2015.03.24 14:41:04 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_5.dll [2015.03.24 14:41:03 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_42.dll [2015.03.24 14:41:03 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll [2015.03.24 14:41:03 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_42.dll [2015.03.24 14:41:03 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll [2015.03.24 14:41:03 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_42.dll [2015.03.24 14:41:03 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll [2015.03.24 14:41:02 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_42.dll [2015.03.24 14:41:02 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll [2015.03.24 14:41:02 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll [2015.03.24 14:41:02 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll [2015.03.24 14:41:01 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll [2015.03.24 14:41:01 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll [2015.03.24 14:41:01 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll [2015.03.24 14:41:01 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll [2015.03.24 14:41:01 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll [2015.03.24 14:41:01 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll [2015.03.24 14:41:00 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll [2015.03.24 14:41:00 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll [2015.03.24 14:41:00 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll [2015.03.24 14:41:00 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll [2015.03.24 14:41:00 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll [2015.03.24 14:41:00 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll [2015.03.24 14:40:59 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll [2015.03.24 14:40:59 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll [2015.03.24 14:40:59 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll [2015.03.24 14:40:59 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll [2015.03.24 14:40:59 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll [2015.03.24 14:40:59 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll [2015.03.24 14:40:58 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll [2015.03.24 14:40:58 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll [2015.03.24 14:40:57 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll [2015.03.24 14:40:57 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll [2015.03.24 14:40:57 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll [2015.03.24 14:40:57 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll [2015.03.24 14:40:56 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll [2015.03.24 14:40:56 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll [2015.03.24 14:40:56 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll [2015.03.24 14:40:56 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll [2015.03.24 14:40:56 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll [2015.03.24 14:40:56 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll [2015.03.24 14:40:56 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll [2015.03.24 14:40:56 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll [2015.03.24 14:40:55 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll [2015.03.24 14:40:55 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll [2015.03.24 14:40:54 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll [2015.03.24 14:40:54 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll [2015.03.24 14:40:54 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll [2015.03.24 14:40:54 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll [2015.03.24 14:40:53 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll [2015.03.24 14:40:53 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll [2015.03.24 14:40:53 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll [2015.03.24 14:40:53 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll [2015.03.24 14:40:53 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll [2015.03.24 14:40:53 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll [2015.03.24 14:40:52 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll [2015.03.24 14:40:52 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll [2015.03.24 14:40:52 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll [2015.03.24 14:40:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll [2015.03.24 14:40:52 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll [2015.03.24 14:40:52 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll [2015.03.24 14:40:52 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll [2015.03.24 14:40:52 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll [2015.03.24 14:40:50 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll [2015.03.24 14:40:50 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll [2015.03.24 14:40:50 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll [2015.03.24 14:40:50 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll [2015.03.24 14:40:49 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll [2015.03.24 14:40:49 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll [2015.03.24 14:40:49 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll [2015.03.24 14:40:49 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll [2015.03.24 14:40:48 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll [2015.03.24 14:40:48 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll [2015.03.24 14:40:48 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll [2015.03.24 14:40:48 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll [2015.03.24 14:40:48 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll [2015.03.24 14:40:48 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll [2015.03.24 14:40:47 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll [2015.03.24 14:40:47 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll [2015.03.24 14:40:46 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll [2015.03.24 14:40:46 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll [2015.03.24 14:40:46 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll [2015.03.24 14:40:46 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll [2015.03.24 14:40:45 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll [2015.03.24 14:40:45 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll [2015.03.24 14:40:43 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll [2015.03.24 14:40:43 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll [2015.03.24 14:40:43 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll [2015.03.24 14:40:43 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll [2015.03.24 14:40:43 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll [2015.03.24 14:40:43 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll [2015.03.24 14:40:42 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll [2015.03.24 14:40:42 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll [2015.03.24 14:40:42 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll [2015.03.24 14:40:42 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll [2015.03.24 14:40:42 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll [2015.03.24 14:40:42 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll [2015.03.24 14:40:41 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll [2015.03.24 14:40:41 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll [2015.03.24 14:40:41 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll [2015.03.24 14:40:41 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll [2015.03.24 14:40:40 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll [2015.03.24 14:40:40 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll [2015.03.24 14:40:40 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll [2015.03.24 14:40:40 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll [2015.03.24 14:40:39 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll [2015.03.24 14:40:39 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll [2015.03.24 14:40:39 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll [2015.03.24 14:40:39 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll [2015.03.24 14:40:39 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll [2015.03.24 14:40:39 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll [2015.03.24 14:40:38 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll [2015.03.24 14:40:38 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll [2015.03.24 14:40:38 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll [2015.03.24 14:40:38 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll [2015.03.24 14:40:37 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll [2015.03.24 14:40:37 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll [2015.03.24 14:40:37 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll [2015.03.24 14:40:37 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll [2015.03.24 14:40:36 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll [2015.03.24 14:40:36 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll [2015.03.24 14:40:36 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll [2015.03.24 14:40:36 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll [2015.03.24 14:40:36 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll [2015.03.24 14:40:36 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll [2015.03.24 14:40:35 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll [2015.03.24 14:40:35 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll [2015.03.24 14:40:34 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll [2015.03.24 14:40:34 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll [2015.03.24 14:40:34 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll [2015.03.24 14:40:34 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll [2015.03.24 14:40:33 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll [2015.03.24 14:40:33 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll [2015.03.24 14:40:33 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll [2015.03.24 14:40:33 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll [2015.03.24 14:40:32 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll [2015.03.24 14:40:32 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll [2015.03.24 14:40:29 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll [2015.03.24 14:40:29 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2015.03.24 14:40:25 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll [2015.03.24 14:40:25 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll [2015.03.24 14:40:25 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll [2015.03.24 14:40:25 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll [2015.03.24 14:40:24 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll [2015.03.24 14:40:24 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll [2015.03.24 14:40:24 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll [2015.03.24 14:40:24 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll [2015.03.24 14:40:23 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll [2015.03.24 14:40:23 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll [2015.03.24 14:40:23 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll [2015.03.24 14:40:23 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll [2015.03.24 14:40:22 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll [2015.03.24 14:40:22 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll [2015.03.24 14:40:21 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll [2015.03.24 14:40:21 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll [2015.03.24 14:35:58 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2015.03.24 14:14:45 | 000,044,088 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys [2015.03.24 14:13:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2015.03.23 17:20:47 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Roaming\LolClient [2015.03.23 17:20:43 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Roaming\Macromedia [2015.03.23 17:20:37 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Roaming\Adobe [2015.03.23 17:20:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Riot Games [2015.03.23 17:13:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [2015.03.23 17:11:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works [2015.03.23 17:11:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio [2015.03.23 17:11:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER [2015.03.23 17:10:46 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2015.03.23 17:10:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2015.03.23 17:08:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2015.03.23 17:07:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2015.03.23 17:06:59 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Local\Microsoft Help [2015.03.23 17:06:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2015.03.23 17:06:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help [2015.03.23 17:01:02 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2015.03.23 16:57:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2015.03.23 16:55:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2015.03.23 16:55:50 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Local\Google [2015.03.23 16:55:18 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Local\Deployment [2015.03.23 16:55:18 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Local\Apps [2015.03.23 16:48:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache [2015.03.23 16:48:18 | 000,000,000 | ---D | C] -- C:\Users\Armin Stafflinger\AppData\Roaming\Avira [2015.03.23 16:45:56 | 000,132,120 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys [2015.03.23 16:45:56 | 000,128,536 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys [2015.03.23 16:45:56 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys [2015.03.23 16:45:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2015.03.23 16:45:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2015.03.23 16:36:39 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll [2015.03.23 16:36:39 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe [2015.03.23 16:36:39 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll [2015.03.23 16:36:17 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll [2015.03.23 16:36:17 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll [2015.03.23 16:36:17 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll [2015.03.23 16:36:14 | 000,000,000 | R--D | C] -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2015.03.23 16:36:14 | 000,000,000 | R--D | C] -- C:\Users\Armin\Searches [2015.03.23 16:36:14 | 000,000,000 | R--D | C] -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2015.03.23 16:35:50 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll [2015.03.23 16:35:50 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe [2015.03.23 16:35:31 | 000,000,000 | ---D | C] -- C:\Users\Armin \AppData\Roaming\Identities [2015.03.23 16:35:24 | 000,000,000 | R--D | C] -- C:\Users\Armin\Contacts [2015.03.23 16:35:21 | 000,000,000 | ---D | C] -- C:\Users\Armin \AppData\Local\VirtualStore [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Vorlagen [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \AppData\Local\Verlauf [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \AppData\Local\Temporary Internet Files [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Startmenü [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\SendTo [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Recent [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \Netzwerkumgebung [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Lokale Einstellungen [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \Documents\Eigene Videos [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \Documents\Eigene Musik [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \Documents\Eigene Bilder [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \Druckumgebung [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Cookies [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin \AppData\Local\Anwendungsdaten [2015.03.23 16:35:00 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Anwendungsdaten [2015.03.23 16:34:59 | 000,000,000 | --SD | C] -- C:\Users\Armin \AppData\Roaming\Microsoft [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Videos [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Saved Games [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Pictures [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Music [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Links [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Favorites [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Downloads [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Documents [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin\Desktop [2015.03.23 16:34:59 | 000,000,000 | R--D | C] -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2015.03.23 16:34:59 | 000,000,000 | -HSD | C] -- C:\Users\Armin\Eigene Dateien [2015.03.23 16:34:59 | 000,000,000 | -H-D | C] -- C:\Users\Armin\AppData [2015.03.23 16:34:59 | 000,000,000 | ---D | C] -- C:\Users\Armin \AppData\Local\Temp [2015.03.23 16:34:59 | 000,000,000 | ---D | C] -- C:\Users\Armin \AppData\Local\Microsoft [2015.03.23 16:34:59 | 000,000,000 | ---D | C] -- C:\Users\Armin \AppData\Roaming\Media Center Programs [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2015.03.23 16:34:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2015.03.23 16:21:27 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2015.03.23 16:18:01 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2015.03.23 16:17:12 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2015.03.23 16:01:53 | 000,000,000 | ---D | C] -- C:\Windows.old.000 [2015.03.23 15:16:40 | 000,000,000 | ---D | C] -- C:\Windows.old ========== Files - Modified Within 30 Days ========== [2015.03.24 15:19:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Armin Stafflinger\Desktop\OTL.exe [2015.03.24 15:01:26 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2015.03.24 14:26:25 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2015.03.24 14:26:25 | 000,643,866 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2015.03.24 14:26:25 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2015.03.24 14:26:25 | 000,126,394 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2015.03.24 14:26:25 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2015.03.24 14:19:56 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2015.03.24 14:16:06 | 000,013,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2015.03.24 14:16:06 | 000,013,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2015.03.24 14:13:28 | 000,001,137 | ---- | M] () -- C:\Users\Public\Desktop\Avira.lnk [2015.03.24 14:13:21 | 000,044,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys [2015.03.24 14:11:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2015.03.24 14:10:47 | 3016,912,896 | -HS- | M] () -- C:\hiberfil.sys [2015.03.23 17:59:08 | 000,416,336 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2015.03.23 17:18:57 | 000,000,722 | ---- | M] () -- C:\Users\Armin\Desktop\LeagueOfLegends.lnk [2015.03.23 17:13:33 | 000,002,697 | ---- | M] () -- C:\Users\Armin\Desktop\Microsoft Office Word 2007.lnk [2015.03.23 17:13:32 | 000,002,795 | ---- | M] () -- C:\Users\Armin\Desktop\Microsoft Office Outlook 2007.lnk [2015.03.23 17:13:32 | 000,002,703 | ---- | M] () -- C:\Users\Armin\Desktop\Microsoft Office Excel 2007.lnk [2015.03.23 17:11:14 | 000,007,600 | ---- | M] () -- C:\Users\Armin\AppData\Local\Resmon.ResmonCfg [2015.03.23 16:57:27 | 000,002,251 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2015.03.23 16:50:10 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin [2015.03.23 16:46:55 | 000,002,070 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2015.03.23 16:24:00 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2015.03.23 16:24:00 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2015.03.17 13:01:54 | 000,132,120 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys [2015.03.17 13:01:54 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys [2015.03.17 13:01:53 | 000,128,536 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys ========== Files Created - No Company Name ========== [2015.03.24 14:13:28 | 000,001,137 | ---- | C] () -- C:\Users\Public\Desktop\Avira.lnk [2015.03.23 17:18:57 | 000,000,722 | ---- | C] () -- C:\Users\Armin \Desktop\LeagueOfLegends.lnk [2015.03.23 17:13:33 | 000,002,697 | ---- | C] () -- C:\Users\Armin \Desktop\Microsoft Office Word 2007.lnk [2015.03.23 17:13:32 | 000,002,795 | ---- | C] () -- C:\Users\Armin \Desktop\Microsoft Office Outlook 2007.lnk [2015.03.23 17:13:32 | 000,002,703 | ---- | C] () -- C:\Users\Armin \Desktop\Microsoft Office Excel 2007.lnk [2015.03.23 17:11:14 | 000,007,600 | ---- | C] () -- C:\Users\Armin \AppData\Local\Resmon.ResmonCfg [2015.03.23 16:57:27 | 000,002,251 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2015.03.23 16:56:03 | 000,001,132 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2015.03.23 16:56:01 | 000,001,128 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2015.03.23 16:50:10 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2015.03.23 16:46:55 | 000,002,070 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2015.03.23 16:36:34 | 000,001,409 | ---- | C] () -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2015.03.23 16:36:20 | 000,001,443 | ---- | C] () -- C:\Users\Armin \AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2015.03.23 16:23:39 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2015.03.23 16:23:35 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2015.03.23 17:20:47 | 000,000,000 | ---D | M] -- C:\Users\Armin \AppData\Roaming\LolClient ========== Purity Check ========== < End of report > Geändert von staffti (24.03.2015 um 15:50 Uhr) |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() CPU Auslastung von 0 auf 100% Prozent hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | #3 |
| ![]() CPU Auslastung von 0 auf 100% Prozent Hier die FRST datei:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by Armin Stafflinger (administrator) on ARMINSPC on 24-03-2015 16:01:59 Running from C:\Users\Armin Stafflinger\Downloads Loaded Profiles: Armin Stafflinger (Available profiles: Armin Stafflinger) Platform: Windows 7 Home Premium (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\...\MountPoints2: {c0985055-d16f-11e4-88bc-806e6f6e6963} - D:\SETUP.EXE ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2015-03-23] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2015-03-23] (Google Inc.) Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.t-online.de/", "hxxp://google.de/" CHR Profile: C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-23] CHR Extension: (Google Docs) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-23] CHR Extension: (Google Drive) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-23] CHR Extension: (YouTube) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-23] CHR Extension: (Google Search) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-23] CHR Extension: (Google Sheets) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-23] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-23] CHR Extension: (Google Wallet) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-23] CHR Extension: (Gmail) - C:\Users\Armin Stafflinger\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-23] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-03-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-03-17] (Avira Operations GmbH & Co. KG) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-24 16:01 - 2015-03-24 16:02 - 00006563 _____ () C:\Users\Armin Stafflinger\Downloads\FRST.txt 2015-03-24 16:01 - 2015-03-24 16:02 - 00000000 ____D () C:\FRST 2015-03-24 16:00 - 2015-03-24 16:00 - 02095616 _____ (Farbar) C:\Users\Armin Stafflinger\Downloads\FRST64.exe 2015-03-24 15:30 - 2015-03-24 15:30 - 00105662 _____ () C:\Users\Armin Stafflinger\Desktop\OTL.Txt 2015-03-24 15:30 - 2015-03-24 15:30 - 00029288 _____ () C:\Users\Armin Stafflinger\Desktop\Extras.Txt 2015-03-24 15:19 - 2015-03-24 15:19 - 00602112 _____ (OldTimer Tools) C:\Users\Armin Stafflinger\Downloads\OTL.exe 2015-03-24 15:19 - 2015-03-24 15:19 - 00602112 _____ (OldTimer Tools) C:\Users\Armin Stafflinger\Desktop\OTL.exe 2015-03-24 14:55 - 2015-03-24 14:58 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-24 14:55 - 2015-02-26 21:14 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-24 14:41 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2015-03-24 14:41 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2015-03-24 14:41 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2015-03-24 14:41 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2015-03-24 14:41 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2015-03-24 14:41 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2015-03-24 14:41 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2015-03-24 14:41 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2015-03-24 14:41 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2015-03-24 14:41 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2015-03-24 14:41 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2015-03-24 14:41 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2015-03-24 14:41 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2015-03-24 14:41 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2015-03-24 14:41 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2015-03-24 14:40 - 2015-03-24 14:40 - 00010123 _____ () C:\Windows\DirectX.log 2015-03-24 14:40 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2015-03-24 14:40 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2015-03-24 14:40 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2015-03-24 14:40 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2015-03-24 14:40 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2015-03-24 14:40 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2015-03-24 14:40 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2015-03-24 14:40 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2015-03-24 14:40 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2015-03-24 14:40 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2015-03-24 14:40 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2015-03-24 14:40 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2015-03-24 14:40 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2015-03-24 14:40 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2015-03-24 14:40 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2015-03-24 14:40 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2015-03-24 14:40 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-03-24 14:40 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2015-03-24 14:40 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2015-03-24 14:40 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-03-24 14:40 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-03-24 14:40 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2015-03-24 14:40 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2015-03-24 14:40 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-03-24 14:40 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2015-03-24 14:40 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-03-24 14:40 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2015-03-24 14:40 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2015-03-24 14:40 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-03-24 14:40 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-03-24 14:40 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2015-03-24 14:40 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-03-24 14:40 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2015-03-24 14:40 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-03-24 14:40 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2015-03-24 14:40 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-03-24 14:40 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2015-03-24 14:40 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-03-24 14:40 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2015-03-24 14:40 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-03-24 14:40 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2015-03-24 14:40 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-03-24 14:40 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2015-03-24 14:40 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-03-24 14:40 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2015-03-24 14:40 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-03-24 14:40 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2015-03-24 14:40 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-03-24 14:40 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-03-24 14:40 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2015-03-24 14:40 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-03-24 14:40 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-03-24 14:40 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2015-03-24 14:40 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-03-24 14:40 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2015-03-24 14:40 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-03-24 14:40 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2015-03-24 14:40 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-03-24 14:40 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2015-03-24 14:40 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-03-24 14:40 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2015-03-24 14:40 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-03-24 14:40 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2015-03-24 14:40 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-03-24 14:40 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2015-03-24 14:40 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-03-24 14:40 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2015-03-24 14:40 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2015-03-24 14:40 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-03-24 14:40 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-03-24 14:40 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2015-03-24 14:40 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-03-24 14:40 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2015-03-24 14:40 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-03-24 14:40 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2015-03-24 14:40 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2015-03-24 14:40 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-03-24 14:40 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-03-24 14:40 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-03-24 14:40 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2015-03-24 14:40 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2015-03-24 14:40 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2015-03-24 14:40 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-03-24 14:40 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-03-24 14:40 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2015-03-24 14:40 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-03-24 14:40 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2015-03-24 14:40 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-03-24 14:40 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2015-03-24 14:40 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-03-24 14:40 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2015-03-24 14:40 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-03-24 14:40 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2015-03-24 14:40 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-03-24 14:40 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2015-03-24 14:40 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-03-24 14:40 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2015-03-24 14:40 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-03-24 14:40 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2015-03-24 14:40 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-03-24 14:40 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2015-03-24 14:40 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-03-24 14:40 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2015-03-24 14:40 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-03-24 14:40 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2015-03-24 14:35 - 2015-03-24 14:41 - 00000000 ____D () C:\Windows\SysWOW64\directx 2015-03-24 14:35 - 2015-03-24 14:35 - 00292184 _____ (Microsoft Corporation) C:\Users\Armin Stafflinger\Downloads\dxwebsetup.exe 2015-03-24 14:14 - 2015-03-24 14:13 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2015-03-24 14:13 - 2015-03-24 14:13 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-03-24 14:13 - 2015-03-24 14:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-03-23 17:20 - 2015-03-23 17:20 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Roaming\Macromedia 2015-03-23 17:20 - 2015-03-23 17:20 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Roaming\LolClient 2015-03-23 17:20 - 2015-03-23 17:20 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Roaming\Adobe 2015-03-23 17:20 - 2015-03-23 17:20 - 00000000 ____D () C:\ProgramData\Riot Games 2015-03-23 17:18 - 2015-03-23 17:18 - 00000722 _____ () C:\Users\Armin Stafflinger\Desktop\LeagueOfLegends.lnk 2015-03-23 17:13 - 2015-03-23 17:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2015-03-23 17:13 - 2015-03-23 17:13 - 00002795 _____ () C:\Users\Armin Stafflinger\Desktop\Microsoft Office Outlook 2007.lnk 2015-03-23 17:13 - 2015-03-23 17:13 - 00002703 _____ () C:\Users\Armin Stafflinger\Desktop\Microsoft Office Excel 2007.lnk 2015-03-23 17:13 - 2015-03-23 17:13 - 00002697 _____ () C:\Users\Armin Stafflinger\Desktop\Microsoft Office Word 2007.lnk 2015-03-23 17:11 - 2015-03-24 14:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2015-03-23 17:11 - 2015-03-23 17:11 - 00007600 _____ () C:\Users\Armin Stafflinger\AppData\Local\Resmon.ResmonCfg 2015-03-23 17:11 - 2015-03-23 17:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 2015-03-23 17:10 - 2015-03-23 17:10 - 00000000 ____D () C:\Windows\PCHEALTH 2015-03-23 17:08 - 2015-03-23 17:08 - 00000000 ____D () C:\Program Files\Microsoft Office 2015-03-23 17:07 - 2015-03-23 17:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 2015-03-23 17:06 - 2015-03-24 14:54 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-23 17:06 - 2015-03-23 17:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2015-03-23 17:06 - 2015-03-23 17:06 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Local\Microsoft Help 2015-03-23 16:57 - 2015-03-23 16:57 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-03-23 16:57 - 2015-03-23 16:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-03-23 16:56 - 2015-03-24 16:01 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-23 16:56 - 2015-03-24 14:19 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-23 16:56 - 2015-03-23 16:56 - 00004128 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-23 16:56 - 2015-03-23 16:56 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-23 16:55 - 2015-03-24 14:58 - 00108840 _____ () C:\Users\Armin Stafflinger\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-23 16:55 - 2015-03-23 16:57 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Local\Google 2015-03-23 16:55 - 2015-03-23 16:57 - 00000000 ____D () C:\Program Files (x86)\Google 2015-03-23 16:55 - 2015-03-23 16:55 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Local\Deployment 2015-03-23 16:55 - 2015-03-23 16:55 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Local\Apps\2.0 2015-03-23 16:50 - 2015-03-23 16:50 - 00000000 _____ () C:\Windows\ativpsrm.bin 2015-03-23 16:49 - 2015-03-23 17:58 - 00159780 _____ () C:\Windows\PFRO.log 2015-03-23 16:48 - 2015-03-24 14:12 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-23 16:48 - 2015-03-23 16:48 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Roaming\Avira 2015-03-23 16:46 - 2015-03-23 16:46 - 00002070 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2015-03-23 16:45 - 2015-03-24 14:13 - 00000000 ____D () C:\ProgramData\Avira 2015-03-23 16:45 - 2015-03-24 14:13 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-03-23 16:45 - 2015-03-17 13:01 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-03-23 16:45 - 2015-03-17 13:01 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-03-23 16:45 - 2015-03-17 13:01 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-03-23 16:36 - 2015-03-23 16:36 - 00001443 _____ () C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-03-23 16:36 - 2015-03-23 16:36 - 00001409 _____ () C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2015-03-23 16:36 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-03-23 16:36 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-03-23 16:36 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-03-23 16:36 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-03-23 16:36 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-03-23 16:36 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-03-23 16:36 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-03-23 16:35 - 2015-03-23 16:35 - 00000020 ___SH () C:\Users\Armin Stafflinger\ntuser.ini 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Vorlagen 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Startmenü 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Netzwerkumgebung 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Lokale Einstellungen 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Druckumgebung 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Documents\Eigene Musik 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Documents\Eigene Bilder 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\AppData\Local\Verlauf 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\AppData\Local\Anwendungsdaten 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Anwendungsdaten 2015-03-23 16:35 - 2015-03-23 16:35 - 00000000 ____D () C:\Users\Armin Stafflinger\AppData\Local\VirtualStore 2015-03-23 16:35 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-03-23 16:35 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-03-23 16:34 - 2015-03-23 16:36 - 00000000 ____D () C:\Users\Armin Stafflinger 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Startmenü 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Users\Armin Stafflinger\Eigene Dateien 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Startmenü 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Favoriten 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Dokumente 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2015-03-23 16:34 - 2015-03-23 16:34 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2015-03-23 16:34 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-03-23 16:34 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-03-23 16:23 - 2015-03-23 16:23 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-03-23 16:23 - 2015-03-23 16:23 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-03-23 16:23 - 2015-03-23 16:23 - 00001313 _____ () C:\Windows\TSSysprep.log 2015-03-23 16:21 - 2015-03-24 15:14 - 00520086 _____ () C:\Windows\WindowsUpdate.log 2015-03-23 16:17 - 2015-03-23 16:34 - 00000000 ____D () C:\Windows\Panther 2015-03-23 16:01 - 2015-03-23 16:01 - 00000000 ____D () C:\Windows.old.000 2015-03-23 15:16 - 2015-03-23 15:16 - 00000000 ____D () C:\Windows.old ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-24 15:45 - 2009-07-14 05:45 - 00013600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-24 15:45 - 2009-07-14 05:45 - 00013600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-24 14:51 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini 2015-03-24 14:26 - 2009-07-14 18:58 - 00643866 _____ () C:\Windows\system32\perfh007.dat 2015-03-24 14:26 - 2009-07-14 18:58 - 00126394 _____ () C:\Windows\system32\perfc007.dat 2015-03-24 14:26 - 2009-07-14 06:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-24 14:20 - 2009-07-14 05:51 - 00016060 _____ () C:\Windows\setupact.log 2015-03-24 14:19 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-24 14:18 - 2009-07-14 06:08 - 00001890 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-03-23 17:59 - 2009-07-14 05:45 - 00416336 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-23 17:11 - 2009-07-14 19:18 - 00000000 ____D () C:\Windows\ShellNew 2015-03-23 17:11 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2015-03-23 17:09 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-03-23 16:35 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore 2015-03-23 16:34 - 2013-10-14 17:11 - 00000000 __SHD () C:\Recovery 2015-03-23 16:34 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2015-03-23 16:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery 2015-03-23 16:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT 2015-03-23 16:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-03-23 16:23 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-03-23 16:23 - 2009-07-14 05:46 - 00001774 _____ () C:\Windows\DtcInstall.log 2015-03-23 16:23 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-03-23 16:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2015-03-23 16:17 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2015-03-23 16:17 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template ==================== Files in the root of some directories ======= 2015-03-23 17:11 - 2015-03-23 17:11 - 0007600 _____ () C:\Users\Armin Stafflinger\AppData\Local\Resmon.ResmonCfg Some content of TEMP: ==================== C:\Users\Armin Stafflinger\AppData\Local\Temp\avgnt.exe C:\Users\Armin Stafflinger\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-23 16:17 ==================== End Of Log ============================ Und die Addition:FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by Armin Stafflinger at 2015-03-24 16:02:50 Running from C:\Users\Armin Stafflinger\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: - Avira Operations & Co. KG) Avira (x32 Version: - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.) Google Update Helper (x32 Version: - Google Inc.) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 23-03-2015 16:35:19 Windows Update 23-03-2015 16:39:59 Windows Update 23-03-2015 17:05:36 Installed Microsoft Office Enterprise 2007 24-03-2015 14:39:51 DirectX wurde installiert 24-03-2015 14:47:55 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {4DB5CA33-A30D-4814-A2FA-F9337A341E43} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-23] (Google Inc.) Task: {F3FBFD36-A6ED-4AA8-B186-AADC6633CCA0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-23] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2015-01-19 12:03 - 2015-01-19 12:03 - 00245760 _____ () C:\Program Files (x86)\Avira\My Avira\System.ComponentModel.Composition.dll 2015-03-23 16:57 - 2015-03-14 11:12 - 01174856 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libglesv2.dll 2015-03-23 16:57 - 2015-03-14 11:12 - 00080200 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libegl.dll 2015-03-23 16:57 - 2015-03-14 11:12 - 09278792 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\pdf.dll 2015-03-23 16:57 - 2015-03-14 11:12 - 14974280 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2742310802-1817215174-2526529294-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Armin Stafflinger\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-2742310802-1817215174-2526529294-500 - Administrator - Disabled) Armin Stafflinger (S-1-5-21-2742310802-1817215174-2526529294-1000 - Administrator - Enabled) => C:\Users\Armin Stafflinger Gast (S-1-5-21-2742310802-1817215174-2526529294-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (03/24/2015 02:20:54 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Multimediaklassenplaner" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (03/24/2015 02:20:54 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows-Verwaltungsinstrumentation" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (03/24/2015 02:20:09 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Programmkompatibilitäts-Assistent-Dienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (03/24/2015 02:19:54 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Server" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Automatische WLAN-Konfiguration" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Diagnosesystemhost" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Sitzungs-Manager für Desktopfenster-Manager" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Überwachung verteilter Verknüpfungen (Client)" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Superfetch" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (03/24/2015 02:19:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Programmkompatibilitäts-Assistent-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: AMD Athlon(tm) II Dual-Core M300 Percentage of memory in use: 34% Total physical RAM: 3836.2 MB Available physical RAM: 2514.72 MB Total Pagefile: 7670.55 MB Available Pagefile: 5960.65 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:220.78 GB) (Free:115.66 GB) NTFS Drive e: (Iomega_HDD) (Fixed) (Total:465.76 GB) (Free:320.05 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 99D4F02A) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=102 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=220.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 465.8 GB) (Disk ID: 40ED0235) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() CPU Auslastung von 0 auf 100% Prozent ProcessExplorer als Ersatz für den Windows Taskmanager installieren Lade Dir den Process Explorer als Ersatz für den Taskmanager herunter und installiere ihn, hier findest Du eine Anleitung. Das ist ein wesentlich leistungsfähigerer Ersatz für den Windows-Taskmanager. Im Menü unter "Options" kannst Du den ProcessExplorer dauerhaft als Ersatz für den Taskmanager einrichten (Replace Taskmanager). Das ist sehr empfehlenswert, weil der ProcessExplorer erheblich mehr Funktionen als der Taskmanager hat. Wenn Du diese Einstellung gemacht hast, öffnet sich mit der Tastenkombination STRG + ALT + Entf. nicht mehr der Taskmanager, sondern der ProcessExplorer. Das kann jederzeit durch Abhaken dieser Einstellung wieder rückgängig gemacht werden. Was wir jetzt konkret brauchen: In jeder Zeile steht ein Prozess, ein paar der Zeilen sind keine richtigen Prozesse, sondern nur Pseudoprozesse für die Tätigkeit des Windos-Kernels. Im Menü View => Select Columns wird ein Dialog geöffnet, in dem Du auswählen kannst, welche Spalten mit Informationen zu den Prozessen angezeigt werden sollen. In dem gehe in das Register "Process Performance" und stelle sicher, dass dort "CPU Usage" angehakt ist, "CPU History" wäre ebenfalls sinnvoll. Unter "CPU Usage" wird der aktuelle Wert der Prozessorauslastung für jeden Prozess angezeigt (im Tabellentitel steht nur kurz "CPU"), "CPU History" blendet für jeden Prozess ein Diagramm ein, das eine Kurve mit der Prozessorauslastung für die letzte Zeit anzeigt. Damit sollte es Dir möglich sein, zu identifizieren, welcher Prozess Deine CPU in Trab hält. Mache einen Doppelklick auf den Prozess. Du kannst von dem ganzen auch einen Screenshot machen und ihn als Anhang mit Deiner Antwort hochladen (auf "Erweitert" unter dem Textfeld klicken und über "Anhänge verwalten" auf Deinem Rechner suchen lassen und über "Hochladen" anhängen).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #5 |
| ![]() CPU Auslastung von 0 auf 100% Prozent Hallo Schrauber, DANKE für deine Hilfreiche Antwort. Ich habe das gemacht was du gesagt hast und wie es aus sieht ist der Prozess Interrupts schuld. Jedes mal wenn der Laptop anfängt zu laggen beginnt eine neue Rote Linie in der CPU History des Programms. (Wie im Anhang zu sehen). Nun habe ich zwei fragen: 1. Was macht der Prozess 2. Kann man diesen Dauerhaft beenden Danke für deine Antwort Mfg staffti |
![]() | #6 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() CPU Auslastung von 0 auf 100% Prozent Laut dem Screenshot hast Du 67% Auslastung, aber der Interrupts hat nur 2%. Hast Du die Tabelle nach CPU Last sortiert? Sieht nicht so aus. Interrupts: Hardwarefehler werden erkannt.
__________________ --> CPU Auslastung von 0 auf 100% Prozent |
![]() | #7 |
| ![]() CPU Auslastung von 0 auf 100% Prozent Es ist halt so das die CPU immer flüssig läuft aber alle 2 - 3 Minuten fängt der ganze laptop an zu hängen. Und genau immer dann bildet sich eine neue Rote Linie bei Interrupts. Und genau dann springt, wenn ich nach Cpu Last sortiert habe, Interrupts von <0.01 auf 100% und ist somit ganz oben. |
![]() | #8 |
| ![]() CPU Auslastung von 0 auf 100% Prozent Und fast genau so schaut das dann aus (Das bild im Anhang). Ich habe versucht es trotz brutaler lags zu screenshoten |
![]() | #9 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() CPU Auslastung von 0 auf 100% Prozent Schau mal hier: Wondering why mscorsvw.exe has high CPU usage? You can speed it up. - .NET Blog - Site Home - MSDN Blogs
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu CPU Auslastung von 0 auf 100% Prozent |
100%, antivir, auslastung, autorun, avg, avira, cpu, cpu auslastung, error, explorer, firefox, format, google, home, laptop, logfile, microsoft, neu, opera, problem, programme, registry, scan, sekunden, senden, software, windows, windows 7 64 bit home |