Problem: Rechner startet wie von Geisterhand

Hallo Community,

ich habe ein ziemlich seltsames Problem.

Vorweg:
Windows 10 pro 64bit (vor einigen Wochen per clean install installiert)
Asrock Z97 Anniversary
Intel i5
GTX 570
8 GB RAM

Gestern war ich den ganzen Tag nicht zu Hause (wohne alleine). Vorgestern abend hatte ich den PC ganz normal per "Herunterfahren" heruntergefahren. Letzte Nacht komme ich um 3 Uhr nach Hause: Läuft doch der Rechner.

Ich gucke in die Ereignisanzeige tauchen die ersten Ereignisse um 20:54 Uhr auf, später auch einige Fehler. Die gabs aber schon seit Wochen, meist ESENT oder Service Control Manager.

Dann hatte ich in der Nacht noch folgende Befehle ausgeführt (hatte ich mal gelesen, dass man dadurch erfährt, was der Grund war):

C:\Windows\system32>powercfg -lastwake
Aktivierungsverlaufsanzahl - 1
Aktivierungsverlauf [0]
Aktivierungsquellenanzahl - 0

C:\Windows\system32>powercfg -devicequery wake_armed
HID-Tastatur (002)
Intel(R) Ethernet Connection (2) I218-V
HID-Tastatur (003)
HID-konforme Maus

Allerdings bringen mich diese Meldungen auch nicht weiter.

Energiesparmodus nutze ich quasi nie, auch der automatische Energiesparmodus ist ausgeschaltet.

Kann mir jemand helfen?

Achja, Wake on LAN im Bios ist ausgeschaltet.
Poste das Ergebnis bitte hier.
Poste das Ergebnis bitte hier.
C:\Windows\system32>powercfg -waketimers
Im System sind keine Aktivierungszeitgeber aktiv.
__________________Im System sind keine Aktivierungszeitgeber aktiv. |
![]() ![]() ![]() ![]() | ![]() Lösung: Rechner startet wie von GeisterhandZitat:
Hast du den PC (die Wohnung) sofort beim herunterfahren verlassen ? Ich nehme an, dass der Rechner aus irgendwelchen Gründen nicht ordnungsgemäß runtergefahren wurde und einen Neustart gemacht hat. Hatte sowas ähnliches auch mal. Vllt. hat irgendein laufender Prozess den Shutdownprozess blockiert. ![]() Für weitere Analyse kannst du warten, bis sich ein Helfer meldet oder einen neuen Thread in Log-Analyse & Auswertung aufmachen. Weise darauf aber bitte hier hin, damit sich die Helfer nicht verzetteln. EDIT: burningice war schneller. |
Ich vermute mal, dass das die Automatische Wartung von Windows war. Das passiert, wenn du den PC längere Zeit nicht neugestartet hast und so keine Updates installiert werden können. Wenn du nämlich nur "Herunterfahren" drückst, geht der PC standardmäßig in eine Art "Hydrid Standby" um schneller wieder starten zu können. Dabei können keine Systemkonfigurationen vorgenommen werden und Windows erzwingt diese dann nach einiger Zeit.

Du kannst ja mal im Update Verlauf von Windows schauen, ob da was installiert wurde.

Es kann sein, dass folgender Work-around dafür funktioniert, wenn du das nicht willst: In den Energieoptionen beim aktiven Energiesparplan auf "Energiesparplaneinstellungen ändern" gehen, dort auf "Erweiterte Energieeinstellungen ändern" und im erscheinenden Dialog unter "Energie sparen" die Einstellung "Zeitgeber zur Aktivierung zulassen" auf "Deaktiviert" setzen
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ ![]() ![]() ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
Also erst mal danke an euch beide!

@Darklord666 Nein, den PC hatte ich gestern vorher gar nicht an, er wurde zuletzt heruntergefahren vorgestern Abend (also Montag). Theoretisch ist es möglich, dass er da nicht komplett heruntergefahren wurde, aber eher unwahrscheinlich, ich denke, das hätte ich gehört. Außerdem müsste es dann doch in der Ereignisanzeige schon viel früher (eigentlich permanent) irgendwelche Einträge gegeben haben.

Was mir gerade, wo ich noch mal reingucke auffällt, dass das letzte Ereignis unter "Anwendung" am Montagabend um 20:54:58 stattfand. Und nach dem geisterhaften Start gestern Abend ist der erste Eintrag um 20:55:23. Also genau 24 Stunden später. Das ist doch irgendwie seltsam, oder? Klingt nicht gerade noch einem Zufall.

@burningice Die automatische Wartung ist aktiv. Soll täglich um 2:00 Uhr starten. Ist aber alles auf Standard, hab da nie was geändert. Aber Verständnisfrage: Ein "Herunterfahren" ist doch eigentlich ein komplettes Ausschalten, dachte ich zumindest bisher? Du sagst "nur Herunterfahren"; was wäre denn stattdessen besser? Ich dachte, das ist schon die maximale Ausschaltbarkeit (tolles Wort

Gestern gab es nur ein Windows Defender Update laut Verlauf, aber da steht ja leider keine Urzeit.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop:

Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

Bitte poste dein Ergebnis zwischen Code-Tags
Wenn ein Log zu lange ist, teile ihn bitte auf mehrere Antworten.
Bitte poste dein Ergebnis zwischen Code-Tags Wenn ein Log zu lange ist, teile ihn bitte auf mehrere Antworten. ![]() Drücke einfach die # in Antwortfenster und füge den Log dazwischen ein ![]()
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ ![]() ![]() ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
So, habe FRST ausgeführt:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-09-2015 durchgeführt von Sandy (Administrator) auf BASE (09-09-2015 14:12:12) Gestartet von C:\Users\Sandy\Downloads Geladene Profile: Sandy (Verfügbare Profile: Sandy & Administrator) Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Opera) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (AOMEI Tech Co., Ltd.) C:\Program Files (x86)\AOMEI Backupper\ABService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Giulio Sosio) C:\Users\Sandy\AppData\Local\Temp\Temp1_XonarSwitch.zip\XonarSwitch.exe (Microsoft Corporation) C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe (Microsoft Corporation) C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Opera Software) C:\Program Files (x86)\Opera\31.0.1889.106\opera.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [14601160 2015-07-02] (Logitech Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [39175960 2015-08-14] (Dropbox, Inc.) HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2720144 2015-08-09] (Dominik Reichl) HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\...\Run: [XonarSwitch] => C:\Users\Sandy\AppData\Local\Temp\Temp1_XonarSwitch.zip\XonarSwitch.exe [1355776 2015-09-03] (Giulio Sosio) <===== ACHTUNG HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\...\Run: [ASRockRuefi] => [X] HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\...\Run: [OneDrive] => C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-25] (Microsoft Corporation) HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\...\Run: [GalaxyClient] => [X] HKU\S-1-5-18\...\Run: [] => [X] ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{cd7977ce-a830-4568-b433-f056ccf40ac7}: [DhcpNameServer] Internet Explorer: ================== BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-05-05] (Microsoft Corporation) FireFox: ======== FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) Opera: ======= OPR Extension: (Ghostery) - C:\Users\Sandy\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2015-08-12] OPR Extension: (Adguard) - C:\Users\Sandy\AppData\Roaming\Opera Software\Opera Stable\Extensions\bopfaehpakahokaelnomggbohfbimcia [2015-08-12] OPR Extension: (Adblock Plus) - C:\Users\Sandy\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-08-10] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Backupper Service; C:\Program Files (x86)\AOMEI Backupper\ABService.exe [29912 2015-08-06] (AOMEI Tech Co., Ltd.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-10] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-10] (Dropbox, Inc.) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1720888 2015-08-04] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6920248 2015-08-26] (GOG.com) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Datei ist nicht signiert] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Datei ist nicht signiert] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [19192 2015-07-16] (Intel(R) Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [30648 2015-02-26] () [Datei ist nicht signiert] R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [151480 2015-02-26] () [Datei ist nicht signiert] R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [17848 2015-02-26] () [Datei ist nicht signiert] S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2015-08-21] (ASRock Incorporation) S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-07-10] (Microsoft Corporation) S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [36864 2015-07-10] (Microsoft Corporation) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation) R3 cmudaxp; C:\Windows\system32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc) U5 DiagTrack; C:\Windows\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation) R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [30224 2015-05-28] (Intel Corporation) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\system32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-08-21] (Intel Corporation) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] () S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation) S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-09 14:12 - 2015-09-09 14:12 - 00014901 _____ C:\Users\Sandy\Downloads\FRST.txt 2015-09-09 14:11 - 2015-09-09 14:12 - 00000000 ____D C:\FRST 2015-09-09 14:11 - 2015-09-09 14:11 - 02190336 _____ (Farbar) C:\Users\Sandy\Downloads\FRST64.exe 2015-09-09 12:15 - 2015-09-09 12:15 - 00016148 _____ C:\Windows\system32\BASE_Sandy_HistoryPrediction.bin 2015-09-09 00:38 - 2015-09-09 00:38 - 00028661 _____ C:\Windows\system32\energy-report.html 2015-09-07 18:36 - 2015-09-07 18:36 - 303149219 _____ C:\Users\Sandy\Downloads\sternstundephilosophie_20111113_105758_vpodcast_h264_16zu9_mq1.m4v 2015-09-07 18:20 - 2015-09-07 18:21 - 00000000 ____D C:\Users\Sandy\.ebookreader 2015-09-07 18:20 - 2015-09-07 18:20 - 00001186 _____ C:\Users\Public\Desktop\Icecream Ebook Reader.lnk 2015-09-07 18:20 - 2015-09-07 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Ebook Reader 2015-09-07 18:20 - 2015-09-07 18:20 - 00000000 ____D C:\Program Files (x86)\Icecream Ebook Reader 2015-09-07 18:19 - 2015-09-07 18:19 - 17641872 _____ (Icecream Apps ) C:\Users\Sandy\Downloads\ebook_reader_setup.exe 2015-09-06 20:46 - 2015-09-06 20:46 - 00000000 ____D C:\Users\Sandy\AppData\Local\TeamViewer 2015-09-06 20:44 - 2015-09-06 20:45 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2015-09-06 20:44 - 2015-09-06 20:44 - 00001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-09-06 20:44 - 2015-09-06 20:44 - 00001104 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-09-06 20:43 - 2015-09-06 20:44 - 08140296 _____ (TeamViewer GmbH) C:\Users\Sandy\Downloads\TeamViewer_Setup_de.exe 2015-09-06 04:41 - 2015-09-06 04:52 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\avidemux 2015-09-06 04:40 - 2015-09-06 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64 bits) 2015-09-06 04:40 - 2015-09-06 04:40 - 00000000 ____D C:\Program Files\Avidemux 2.6 - 64 bits 2015-09-06 04:39 - 2015-09-06 04:39 - 15773608 _____ C:\Users\Sandy\Downloads\avidemux_2.6.10_win64.exe 2015-09-06 04:21 - 2015-09-06 04:21 - 00000165 _____ C:\Users\Sandy\Documents\falls der youtuber antwortet.txt 2015-09-05 20:51 - 2015-09-05 20:51 - 00000000 ____D C:\Program Files (x86)\FFmpeg for Audacity 2015-09-05 20:50 - 2015-09-05 20:51 - 09957947 _____ ( ) C:\Users\Sandy\Downloads\ffmpeg-win-2.2.2.exe 2015-09-05 00:23 - 2015-09-05 00:23 - 00000982 _____ C:\Windows\PFRO.log 2015-09-04 22:43 - 2015-09-04 22:43 - 00007605 _____ C:\Users\Sandy\AppData\Local\Resmon.ResmonCfg 2015-09-04 18:58 - 2015-09-04 18:58 - 00005097 _____ C:\Windows\SysWOW64\Saved_Config.txt 2015-09-04 18:58 - 2015-09-04 18:58 - 00000410 _____ C:\Windows\SysWOW64\Saved_StaticIP.txt 2015-09-04 18:57 - 2015-09-04 18:57 - 55886931 _____ C:\Users\Sandy\Downloads\PROWinx64 (1).exe 2015-09-04 13:28 - 2015-09-04 13:28 - 02599696 _____ (Microsoft Corporation ) C:\Users\Sandy\Downloads\setup.exe 2015-09-04 12:01 - 2015-09-04 12:01 - 52316160 _____ C:\Users\Sandy\Downloads\I9505XXUHOF2_MODEM.tar 2015-09-04 12:00 - 2015-09-04 12:00 - 09983584 _____ (MEGA Limited) C:\Users\Sandy\Downloads\MEGAsyncSetup.exe 2015-09-04 12:00 - 2015-09-04 12:00 - 02211840 _____ C:\Users\Sandy\Downloads\BL_I9505XXUHOF2_user_low_ship_MULTI_CERT.tar 2015-09-02 22:27 - 2015-09-02 22:27 - 00000416 _____ C:\Windows\BRWMARK.INI 2015-09-02 22:27 - 2015-09-02 22:27 - 00000034 _____ C:\Windows\SysWOW64\BD2030.DAT 2015-09-02 22:25 - 2015-09-02 22:25 - 00000000 _____ C:\Windows\setuperr.log 2015-09-02 22:25 - 2015-09-02 22:25 - 00000000 _____ C:\Windows\setupact.log 2015-09-02 22:11 - 2015-09-09 14:10 - 00000275 _____ C:\Windows\WindowsUpdate.log 2015-09-02 22:07 - 2015-09-02 22:07 - 02750327 _____ C:\Users\Sandy\Downloads\JDownloader.jar 2015-09-02 21:45 - 2015-09-02 21:45 - 00000264 _____ C:\Users\Sandy\.swfinfo 2015-09-02 21:41 - 2015-09-02 21:46 - 00000000 ____D C:\Program Files (x86)\ChrisPC VideoTube Downloader Pro 2015-09-02 21:41 - 2015-09-02 21:41 - 00000000 ____D C:\Program Files (x86)\FFMPEG Addon 2015-09-02 21:40 - 2015-09-02 21:41 - 35575992 _____ (Chris P.C. srl ) C:\Users\Sandy\Downloads\setup_chrispc_videotube_downloader_pro_8_10.exe 2015-09-02 21:22 - 2015-09-02 21:23 - 31918217 _____ C:\Users\Sandy\Downloads\MediathekView_10.zip 2015-09-02 21:08 - 2015-09-02 21:08 - 00002159 _____ C:\Users\Sandy\Desktop\JDownloader 2.lnk 2015-09-02 21:08 - 2015-09-02 21:08 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2015-09-02 21:07 - 2015-09-07 20:54 - 00000000 ____D C:\Users\Sandy\AppData\Local\JDownloader v2.0 2015-09-02 21:06 - 2015-09-02 21:06 - 00074470 _____ C:\Users\Sandy\Documents\cc_20150902_210614.reg 2015-09-02 21:01 - 2015-09-02 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-09-02 21:00 - 2015-09-02 21:00 - 06667640 _____ (Piriform Ltd) C:\Users\Sandy\Downloads\ccsetup509.exe 2015-09-02 20:22 - 2015-09-02 20:22 - 00252254 _____ C:\Users\Sandy\Downloads\JDownloader 2 Setup (1).zip 2015-09-02 17:37 - 2015-09-02 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-09-01 20:16 - 2015-09-01 20:18 - 00001908 _____ C:\Windows\diagwrn.xml 2015-09-01 20:16 - 2015-09-01 20:18 - 00001908 _____ C:\Windows\diagerr.xml 2015-09-01 20:16 - 2015-09-01 20:18 - 00000000 ___HD C:\$Windows.~BT 2015-08-31 21:26 - 2015-08-31 21:26 - 00037259 _____ C:\Users\Sandy\Downloads\MyAppsList.txt 2015-08-31 10:34 - 2015-08-31 10:34 - 00230384 _____ C:\Users\Sandy\Downloads\CrucialDEScan.exe 2015-08-28 18:37 - 2015-08-20 08:07 - 08019296 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-08-28 18:37 - 2015-08-20 08:02 - 22324656 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-08-28 18:37 - 2015-08-20 07:21 - 21875200 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2015-08-28 18:37 - 2015-08-20 07:16 - 20857848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-08-28 18:37 - 2015-08-20 06:31 - 18806272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2015-08-28 18:37 - 2015-08-18 09:56 - 02498808 _____ C:\Windows\system32\CoreUIComponents.dll 2015-08-28 18:36 - 2015-08-20 08:06 - 00609592 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-08-28 18:36 - 2015-08-20 07:57 - 00077400 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-08-28 18:36 - 2015-08-20 07:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe 2015-08-28 18:36 - 2015-08-20 07:21 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll 2015-08-28 18:36 - 2015-08-20 07:13 - 02235904 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-08-28 18:36 - 2015-08-20 07:09 - 00929280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2015-08-28 18:36 - 2015-08-18 09:55 - 00373072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2015-08-28 18:36 - 2015-08-18 09:54 - 01396064 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll 2015-08-28 18:36 - 2015-08-18 09:27 - 01771592 _____ C:\Windows\SysWOW64\CoreUIComponents.dll 2015-08-28 18:36 - 2015-08-18 09:24 - 00963920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll 2015-08-28 18:36 - 2015-08-18 09:13 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\WlanMediaManager.dll 2015-08-28 18:36 - 2015-08-18 09:13 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll 2015-08-28 18:36 - 2015-08-18 09:12 - 02225664 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll 2015-08-28 18:36 - 2015-08-18 09:07 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2015-08-28 18:36 - 2015-08-18 09:04 - 01234944 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-08-28 18:36 - 2015-08-18 09:04 - 00859136 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll 2015-08-28 18:36 - 2015-08-18 08:59 - 01294336 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll 2015-08-28 18:36 - 2015-08-18 08:59 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll 2015-08-28 18:36 - 2015-08-18 08:58 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll 2015-08-28 18:36 - 2015-08-18 08:58 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\dafWCN.dll 2015-08-28 18:36 - 2015-08-18 08:58 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2015-08-28 18:36 - 2015-08-18 08:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WcnNetsh.dll 2015-08-28 18:36 - 2015-08-18 08:57 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll 2015-08-28 18:36 - 2015-08-18 08:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\BthRadioMedia.dll 2015-08-28 18:36 - 2015-08-18 08:55 - 02178560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2015-08-28 18:36 - 2015-08-18 08:54 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll 2015-08-28 18:36 - 2015-08-18 08:54 - 00247296 _____ C:\Windows\system32\facecredentialprovider.dll 2015-08-28 18:36 - 2015-08-18 08:52 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-08-28 18:36 - 2015-08-18 08:50 - 01795072 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2015-08-28 18:36 - 2015-08-18 08:49 - 01061888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2015-08-28 18:36 - 2015-08-18 08:49 - 00274432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll 2015-08-28 18:36 - 2015-08-18 08:49 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll 2015-08-28 18:36 - 2015-08-18 08:36 - 01226752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcnwiz.dll 2015-08-28 18:36 - 2015-08-18 08:35 - 00100352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll 2015-08-28 18:36 - 2015-08-18 08:35 - 00095744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll 2015-08-28 18:36 - 2015-08-18 08:34 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfdprov.dll 2015-08-28 18:36 - 2015-08-18 08:29 - 01593344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-08-28 18:36 - 2015-08-18 08:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll 2015-08-28 18:36 - 2015-08-18 06:44 - 00008847 _____ C:\Windows\system32\ResPriHMImageList 2015-08-28 02:48 - 2015-08-28 02:48 - 00000000 ____D C:\Users\Sandy\.android 2015-08-26 03:28 - 2015-08-26 03:28 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\ScummVM 2015-08-26 03:28 - 2015-08-26 03:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lure of the Temptress [GOG.com] 2015-08-26 02:00 - 2015-08-26 02:04 - 00000000 ____D C:\Program Files (x86)\GalaxyClient 2015-08-26 02:00 - 2015-08-26 02:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2015-08-26 02:00 - 2015-08-26 02:00 - 00000000 ____D C:\ProgramData\GOG.com 2015-08-26 01:59 - 2015-08-26 01:59 - 72625848 _____ (GOG.com ) C:\Users\Sandy\Downloads\setup_galaxy_1.0.7.2023.exe 2015-08-25 20:17 - 2015-08-25 20:17 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2015-08-25 20:17 - 2015-08-25 20:17 - 00000000 ____D C:\Program Files (x86)\FormatFactory 2015-08-25 20:16 - 2015-08-25 20:17 - 02634056 _____ (Format Factory) C:\Users\Sandy\Downloads\FFInstOnline.exe 2015-08-25 20:10 - 2015-08-25 20:10 - 06072993 _____ C:\Users\Sandy\Downloads\CDex-1.77-portable-unicode.zip 2015-08-25 20:10 - 2015-08-25 20:10 - 00000000 ____D C:\Users\Sandy\AppData\Local\CDex 2015-08-25 19:02 - 2015-08-25 19:02 - 00000000 ___HD C:\OneDriveTemp 2015-08-25 18:05 - 2015-08-25 18:05 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2015-08-25 18:05 - 2015-08-25 18:05 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2015-08-25 17:11 - 2015-08-25 18:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-08-25 17:11 - 2015-08-25 17:11 - 00000000 ____D C:\Windows\PCHEALTH 2015-08-25 17:11 - 2015-08-25 17:11 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2015-08-25 17:11 - 2015-08-25 17:11 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2015-08-25 17:11 - 2015-08-25 17:11 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2015-08-25 17:10 - 2015-08-25 18:06 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-08-25 17:10 - 2015-08-25 17:11 - 00000000 ____D C:\Program Files\Microsoft Office 2015-08-25 17:10 - 2015-08-25 17:10 - 00000000 __RHD C:\MSOCache 2015-08-25 17:10 - 2015-08-25 17:10 - 00000000 ____D C:\Users\Sandy\AppData\Local\Microsoft Help 2015-08-25 17:10 - 2015-08-25 17:10 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2015-08-25 17:10 - 2015-08-25 17:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2015-08-25 17:10 - 2015-08-25 17:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2015-08-24 17:47 - 2015-08-24 17:51 - 00000000 ____D C:\ProgramData\RogueKiller 2015-08-24 17:47 - 2015-08-24 17:47 - 22720584 _____ C:\Users\Sandy\Downloads\RogueKillerX64.exe 2015-08-24 17:47 - 2015-08-24 17:47 - 00037624 _____ C:\Windows\system32\Drivers\TrueSight.sys 2015-08-24 01:51 - 2015-08-24 01:51 - 00016148 _____ C:\Windows\system32\BASE_Administrator_HistoryPrediction.bin 2015-08-24 01:25 - 2015-08-24 01:25 - 00000000 ____D C:\$SysReset 2015-08-24 00:59 - 2015-08-24 01:00 - 00000000 ____D C:\Users\Sandy\AppData\Local\paint.net 2015-08-24 00:59 - 2015-08-24 00:59 - 06557455 _____ C:\Users\Sandy\Downloads\paint.net.4.0.6.install.zip 2015-08-24 00:59 - 2015-08-24 00:59 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2015-08-24 00:59 - 2015-08-24 00:59 - 00000000 ____D C:\Program Files\paint.net 2015-08-24 00:58 - 2015-08-24 00:58 - 91931728 _____ (The GIMP Team ) C:\Users\Sandy\Downloads\gimp-2.8.14-setup-1.exe 2015-08-23 17:35 - 2015-08-23 17:35 - 00000000 ____D C:\Users\Sandy\Documents\Larian Studios 2015-08-23 17:32 - 2015-08-23 17:32 - 00000946 _____ C:\Users\Public\Desktop\Divinity Original Sin.lnk 2015-08-23 17:32 - 2015-08-23 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Divinity Original Sin 2015-08-22 21:25 - 2015-08-22 21:25 - 00907004 _____ C:\Users\Sandy\Downloads\Life is Strange-German-FanSub-beta.zip 2015-08-22 21:23 - 2015-08-22 21:23 - 00627128 _____ C:\Users\Sandy\Downloads\Life is Strange-German-FanSub-full.zip 2015-08-22 20:42 - 2015-08-22 20:42 - 00002378 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2015-08-22 20:42 - 2015-08-22 20:42 - 00000000 ___RD C:\Users\Administrator\OneDrive 2015-08-22 20:42 - 2015-08-22 20:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Publishers 2015-08-22 20:42 - 2015-08-22 20:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Logitech 2015-08-22 20:42 - 2015-08-22 20:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Dropbox 2015-08-22 20:41 - 2015-08-24 00:48 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages 2015-08-22 20:41 - 2015-08-22 20:42 - 00000000 ____D C:\Users\Administrator 2015-08-22 20:41 - 2015-08-22 20:41 - 00000020 ___SH C:\Users\Administrator\ntuser.ini 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2015-08-22 20:41 - 2015-08-22 20:41 - 00000000 ____D C:\Users\Administrator\AppData\Local\TileDataLayer 2015-08-22 20:41 - 2015-07-10 13:04 - 00000000 __RSD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 2015-08-22 20:41 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-08-22 20:41 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-08-22 20:41 - 2015-07-10 13:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-22 20:39 - 2015-08-22 20:39 - 00016148 _____ C:\Windows\system32\DESKTOP-GMTNS47_Sandy_HistoryPrediction.bin 2015-08-21 22:27 - 2015-09-09 12:15 - 00028937 _____ C:\Windows\SysWOW64\Gms.log 2015-08-21 22:20 - 2015-08-21 22:20 - 00000000 ____D C:\Users\Sandy\Intel 2015-08-21 22:18 - 2015-08-21 22:18 - 89826384 _____ C:\Users\Sandy\Downloads\ME(v11.0.0.1158_Consumer).zip 2015-08-21 21:43 - 2015-08-21 21:43 - 01978729 _____ C:\Users\Sandy\Downloads\Seven Forums.zip 2015-08-21 20:51 - 2015-08-21 20:51 - 00022280 _____ (ASRock Incorporation) C:\Windows\SysWOW64\Drivers\AsrDrv101.sys 2015-08-21 20:50 - 2015-08-21 20:50 - 01170809 _____ C:\Users\Sandy\Downloads\RestartToUEFI(v1.0.5).zip 2015-08-21 20:50 - 2015-08-21 20:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2015-08-21 20:50 - 2015-08-21 20:50 - 00000000 ____D C:\Program Files (x86)\ASRock Utility 2015-08-21 20:48 - 2015-08-21 20:48 - 00121069 _____ C:\Users\Sandy\Downloads\memtest86+-5.01.usb.installer.zip 2015-08-21 20:41 - 2015-08-21 20:41 - 00067310 _____ C:\Users\Sandy\Downloads\bluescreenview.zip 2015-08-21 20:40 - 2015-08-21 20:40 - 00053434 _____ C:\Users\Sandy\Downloads\bluetoothview.zip 2015-08-21 20:36 - 2015-09-02 21:04 - 00000000 ____D C:\Windows\Minidump 2015-08-21 15:52 - 2015-08-21 15:52 - 00679936 _____ C:\Users\Sandy\Downloads\Detection.msi 2015-08-21 15:52 - 2015-08-21 15:52 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2015-08-21 15:45 - 2015-08-21 15:45 - 01629552 _____ ( ) C:\Users\Sandy\Downloads\cpu-z_1.73-en.exe 2015-08-21 15:45 - 2015-08-21 15:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2015-08-21 15:45 - 2015-08-21 15:45 - 00000000 ____D C:\Program Files\CPUID 2015-08-21 15:44 - 2015-08-21 15:44 - 02354034 _____ C:\Users\Sandy\Downloads\cpu-z_1.73-en.zip 2015-08-21 15:22 - 2015-08-21 22:23 - 00000000 ____D C:\Program Files (x86)\Intel 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Windows\System32\Tasks\Intel 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\uninstall 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Extreme Tuning Utility 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2015-08-21 15:22 - 2015-08-21 15:22 - 00000000 ____D C:\Intel 2015-08-21 15:21 - 2015-08-21 15:22 - 38385240 _____ (Intel Corporation) C:\Users\Sandy\Downloads\XTU-Setup-exe.exe 2015-08-21 01:48 - 2015-08-21 02:13 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Trine3 2015-08-19 20:57 - 2015-08-19 20:57 - 00000000 ____H C:\Users\Sandy\AppData\Local\BIT8622.tmp 2015-08-19 20:56 - 2015-08-19 20:56 - 00000000 _____ C:\Users\Sandy\AppData\Local\{405C1CF0-C0D4-46CD-9133-FFB0F9C5EF36} 2015-08-19 12:55 - 2015-08-19 17:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2015-08-19 12:49 - 2015-08-19 12:49 - 00108580 _____ C:\Users\Sandy\Downloads\OOSU10.zip 2015-08-19 11:26 - 2015-08-13 06:33 - 24593408 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-08-19 11:26 - 2015-08-13 06:07 - 19323392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-08-19 11:26 - 2015-08-11 12:04 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-08-19 11:26 - 2015-08-11 11:50 - 01643872 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-08-19 11:26 - 2015-08-11 11:40 - 04048808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2015-08-19 11:26 - 2015-08-11 11:31 - 02880032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-08-19 11:26 - 2015-08-11 11:23 - 16706560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2015-08-19 11:26 - 2015-08-11 11:16 - 02416640 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2015-08-19 11:26 - 2015-08-11 11:11 - 02446336 _____ C:\Windows\system32\InputService.dll 2015-08-19 11:26 - 2015-08-11 11:06 - 07523328 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2015-08-19 11:26 - 2015-08-11 11:06 - 02662400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll 2015-08-19 11:26 - 2015-08-11 11:05 - 03527168 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2015-08-19 11:26 - 2015-08-11 11:03 - 02558976 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2015-08-19 11:26 - 2015-08-11 10:57 - 13024768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2015-08-19 11:26 - 2015-08-11 10:51 - 01916928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2015-08-19 11:26 - 2015-08-11 10:45 - 01820672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll 2015-08-19 11:26 - 2015-08-11 10:42 - 05454848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2015-08-19 11:26 - 2015-08-11 10:40 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2015-08-19 11:25 - 2015-08-13 06:22 - 02093056 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2015-08-19 11:25 - 2015-08-13 06:20 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2015-08-19 11:25 - 2015-08-13 05:53 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2015-08-19 11:25 - 2015-08-11 12:04 - 02462648 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2015-08-19 11:25 - 2015-08-11 12:04 - 01087296 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-08-19 11:25 - 2015-08-11 12:03 - 00442208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2015-08-19 11:25 - 2015-08-11 12:02 - 00554744 _____ (Microsoft Corporation) C:\Windows\system32\directmanipulation.dll 2015-08-19 11:25 - 2015-08-11 12:02 - 00292856 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe 2015-08-19 11:25 - 2015-08-11 12:02 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys 2015-08-19 11:25 - 2015-08-11 11:57 - 03622256 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-08-19 11:25 - 2015-08-11 11:52 - 00993104 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll 2015-08-19 11:25 - 2015-08-11 11:40 - 02151208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2015-08-19 11:25 - 2015-08-11 11:40 - 00918320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2015-08-19 11:25 - 2015-08-11 11:38 - 00454000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\directmanipulation.dll 2015-08-19 11:25 - 2015-08-11 11:37 - 00243800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe 2015-08-19 11:25 - 2015-08-11 11:26 - 00845664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll 2015-08-19 11:25 - 2015-08-11 11:21 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll 2015-08-19 11:25 - 2015-08-11 11:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll 2015-08-19 11:25 - 2015-08-11 11:20 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll 2015-08-19 11:25 - 2015-08-11 11:19 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Notifications.dll 2015-08-19 11:25 - 2015-08-11 11:18 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll 2015-08-19 11:25 - 2015-08-11 11:14 - 00404480 _____ C:\Windows\system32\diagtrack_wininternal.dll 2015-08-19 11:25 - 2015-08-11 11:13 - 00413184 _____ C:\Windows\system32\diagtrack_win.dll 2015-08-19 11:25 - 2015-08-11 11:11 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe 2015-08-19 11:25 - 2015-08-11 11:10 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2015-08-19 11:25 - 2015-08-11 11:10 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-08-19 11:25 - 2015-08-11 11:10 - 00293376 _____ C:\Windows\system32\TextInputFramework.dll 2015-08-19 11:25 - 2015-08-11 11:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\wuautoappupdate.dll 2015-08-19 11:25 - 2015-08-11 11:08 - 00893440 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll 2015-08-19 11:25 - 2015-08-11 11:08 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll 2015-08-19 11:25 - 2015-08-11 11:07 - 01178112 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2015-08-19 11:25 - 2015-08-11 11:07 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll 2015-08-19 11:25 - 2015-08-11 11:07 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2015-08-19 11:25 - 2015-08-11 11:05 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll 2015-08-19 11:25 - 2015-08-11 11:05 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\LocationGeofences.dll 2015-08-19 11:25 - 2015-08-11 11:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll 2015-08-19 11:25 - 2015-08-11 11:05 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\LocationPermissions.dll 2015-08-19 11:25 - 2015-08-11 11:05 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll 2015-08-19 11:25 - 2015-08-11 11:02 - 03588096 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2015-08-19 11:25 - 2015-08-11 11:02 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2015-08-19 11:25 - 2015-08-11 11:02 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll 2015-08-19 11:25 - 2015-08-11 11:01 - 01334784 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll 2015-08-19 11:25 - 2015-08-11 11:00 - 00336384 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2015-08-19 11:25 - 2015-08-11 11:00 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\syncutil.dll 2015-08-19 11:25 - 2015-08-11 10:59 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2015-08-19 11:25 - 2015-08-11 10:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rdbui.dll 2015-08-19 11:25 - 2015-08-11 10:59 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2015-08-19 11:25 - 2015-08-11 10:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tetheringclient.dll 2015-08-19 11:25 - 2015-08-11 10:58 - 00372224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll 2015-08-19 11:25 - 2015-08-11 10:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll 2015-08-19 11:25 - 2015-08-11 10:51 - 01823232 _____ C:\Windows\SysWOW64\InputService.dll 2015-08-19 11:25 - 2015-08-11 10:50 - 00420352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe 2015-08-19 11:25 - 2015-08-11 10:50 - 00200704 _____ C:\Windows\SysWOW64\TextInputFramework.dll 2015-08-19 11:25 - 2015-08-11 10:50 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll 2015-08-19 11:25 - 2015-08-11 10:49 - 00586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2015-08-19 11:25 - 2015-08-11 10:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-08-19 11:25 - 2015-08-11 10:48 - 00671232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll 2015-08-19 11:25 - 2015-08-11 10:47 - 00448512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll 2015-08-19 11:25 - 2015-08-11 10:43 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2015-08-19 11:25 - 2015-08-11 10:40 - 01112064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll 2015-08-19 11:25 - 2015-08-11 10:39 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2015-08-19 11:25 - 2015-08-11 10:38 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll 2015-08-18 19:07 - 2015-08-18 19:07 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Steam 2015-08-18 19:07 - 2015-08-18 19:07 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Arrowhead 2015-08-18 19:06 - 2015-08-18 19:06 - 00000936 _____ C:\Users\Sandy\Desktop\Gauntlet Slayer Edition.lnk 2015-08-18 16:31 - 2015-09-02 21:01 - 00000000 ____D C:\Program Files\CCleaner 2015-08-18 16:31 - 2015-08-18 16:31 - 00002870 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-08-18 16:26 - 2015-08-31 09:04 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-08-18 16:22 - 2015-08-18 16:30 - 05375464 _____ (Piriform Ltd) C:\Users\Sandy\Downloads\ccsetup508_slim.exe 2015-08-17 21:34 - 2015-08-17 21:34 - 00000000 ____D C:\ProgramData\NVIDIA 2015-08-17 21:34 - 2015-08-07 13:07 - 00112944 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-08-17 21:34 - 2015-08-07 13:07 - 00105264 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 06883632 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 03491960 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 02558768 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 00937776 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-08-17 21:34 - 2015-08-07 06:27 - 00385144 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-08-17 21:34 - 2015-08-03 11:22 - 05133709 _____ C:\Windows\system32\nvcoproc.bin 2015-08-17 21:32 - 2015-08-07 13:07 - 42840184 _____ C:\Windows\system32\nvcompiler.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 37819184 _____ C:\Windows\SysWOW64\nvcompiler.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 22551672 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 18564728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 17926480 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 16638896 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 15627520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 15328296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 14935968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 13663424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 12609072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 12186176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 03462776 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 03059856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 02352248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 02104440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01898288 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435560.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01567576 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01558832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435560.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01177016 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01063032 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01061168 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 01000088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00985392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00931960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00204648 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-08-17 21:32 - 2015-08-07 13:07 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-08-17 21:32 - 2015-08-07 13:07 - 00040280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-08-17 16:50 - 2015-09-07 19:13 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Victor Vran 2015-08-17 16:04 - 2015-08-17 16:04 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Macromedia 2015-08-17 03:46 - 2015-08-17 03:46 - 01385504 _____ (Skype Technologies S.A.) C:\Users\Sandy\Downloads\SkypeSetup (1).exe 2015-08-16 23:35 - 2015-08-16 23:35 - 00000000 ____D C:\Users\Sandy\Tracing 2015-08-16 23:34 - 2015-08-17 03:45 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Skype 2015-08-16 23:34 - 2015-08-16 23:34 - 01385504 _____ (Skype Technologies S.A.) C:\Users\Sandy\Downloads\SkypeSetup.exe 2015-08-16 23:34 - 2015-08-16 23:34 - 00000000 ___RD C:\Program Files (x86)\Skype 2015-08-16 23:34 - 2015-08-16 23:34 - 00000000 ____D C:\Users\Sandy\AppData\Local\Skype 2015-08-16 23:34 - 2015-08-16 23:34 - 00000000 ____D C:\ProgramData\Skype 2015-08-16 23:34 - 2015-08-16 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-08-15 23:53 - 2015-08-15 23:53 - 00000202 _____ C:\Users\Sandy\Downloads\Mama.vcf 2015-08-15 21:13 - 2015-08-21 20:26 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2015-08-15 21:13 - 2015-08-18 16:25 - 00000000 ____D C:\Windows\SysWOW64\directx 2015-08-15 21:13 - 2015-08-15 21:13 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server 2015-08-15 21:13 - 2015-08-15 21:13 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2015-08-15 21:13 - 2015-08-15 21:13 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2015-08-15 21:12 - 2015-08-15 21:12 - 36270887 _____ C:\Users\Sandy\Downloads\MSIAfterburnerSetup.zip 2015-08-15 20:16 - 2015-08-22 22:58 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\TS3Client 2015-08-15 20:16 - 2015-08-15 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2015-08-15 20:16 - 2015-08-15 20:16 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2015-08-15 20:15 - 2015-08-15 20:15 - 31071896 _____ (TeamSpeak Systems GmbH) C:\Users\Sandy\Downloads\TeamSpeak3-Client-win64-3.0.17.exe 2015-08-15 19:55 - 2015-08-15 19:55 - 00527423 _____ ( ) C:\Users\Sandy\Downloads\Lame_v3.99.3_for_Windows.exe 2015-08-15 19:55 - 2015-08-15 19:55 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2015-08-15 19:53 - 2015-08-15 19:53 - 00202295 _____ C:\Users\Sandy\Downloads\libmp3lame-win-3.99.3.zip 2015-08-14 11:41 - 2015-08-14 11:55 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\The Bat! 2015-08-14 11:41 - 2015-08-14 11:41 - 00001900 _____ C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Bat!.LNK 2015-08-14 11:39 - 2015-08-14 11:40 - 37228544 _____ C:\Users\Sandy\Downloads\thebat_64_7-0-0-56.msi 2015-08-14 11:26 - 2015-08-14 12:32 - 236588037 _____ C:\Users\Sandy\Downloads\Solomon Burke-A Change Is Gonna Come.rar 2015-08-14 11:03 - 2015-09-06 02:15 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2015-08-14 11:03 - 2015-08-14 11:03 - 00004026 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2015-08-14 11:02 - 2015-08-14 11:03 - 00000000 ____D C:\Users\Sandy\AppData\Local\Adobe 2015-08-13 19:47 - 2015-08-14 02:54 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\eM Client 2015-08-13 19:38 - 2015-08-13 19:38 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2015-08-13 19:38 - 2015-08-13 19:38 - 00000000 ____D C:\Program Files\Reference Assemblies 2015-08-13 19:38 - 2015-08-13 19:38 - 00000000 ____D C:\Program Files\MSBuild 2015-08-13 19:38 - 2015-08-13 19:38 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2015-08-13 19:38 - 2015-08-13 19:38 - 00000000 ____D C:\Program Files (x86)\MSBuild 2015-08-13 19:38 - 2015-06-17 18:10 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2015-08-13 19:38 - 2015-06-17 18:10 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 19:38 - 2015-06-17 18:10 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2015-08-13 19:38 - 2015-05-29 21:07 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll 2015-08-13 19:38 - 2015-05-29 21:07 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 19:38 - 2015-05-29 21:07 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2015-08-13 02:12 - 2015-08-13 02:13 - 00001813 _____ C:\Users\Sandy\Documents\Jobsuche.ffs_gui 2015-08-13 02:08 - 2015-08-13 02:13 - 00001807 _____ C:\Users\Sandy\Documents\Fotos.ffs_gui 2015-08-13 02:00 - 2015-08-13 19:53 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\FreeFileSync 2015-08-13 01:59 - 2015-08-13 01:59 - 00000985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk 2015-08-13 01:59 - 2015-08-13 01:59 - 00000975 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk 2015-08-13 01:59 - 2015-08-13 01:59 - 00000000 ____D C:\Program Files\FreeFileSync 2015-08-13 01:56 - 2015-08-13 01:58 - 10324648 _____ (www.FreeFileSync.org) C:\Users\Sandy\Downloads\FreeFileSync_7.3_Windows_Setup.exe 2015-08-13 01:53 - 2015-09-05 22:36 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Audacity 2015-08-13 01:53 - 2015-08-13 01:53 - 25186399 _____ (Audacity Team ) C:\Users\Sandy\Downloads\audacity-win-2.1.1.exe 2015-08-13 01:53 - 2015-08-13 01:53 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2015-08-13 01:53 - 2015-08-13 01:53 - 00000000 ____D C:\Program Files (x86)\Audacity 2015-08-13 00:46 - 2015-08-25 20:29 - 00024837 _____ C:\Users\Sandy\Documents\mp3diag_session.dat 2015-08-13 00:45 - 2015-08-25 20:29 - 00002767 _____ C:\Users\Sandy\Documents\mp3diag_session.ini 2015-08-13 00:32 - 2015-08-13 00:32 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 Diags 2015-08-13 00:32 - 2015-08-13 00:32 - 00000000 ____D C:\Program Files (x86)\MP3Diags 2015-08-13 00:31 - 2015-08-13 00:31 - 07800842 _____ C:\Users\Sandy\Downloads\MP3Diags1202Setup.exe 2015-08-13 00:31 - 2015-08-13 00:31 - 07800842 _____ C:\Users\Sandy\Downloads\MP3Diags1202Setup (1).exe 2015-08-13 00:26 - 2015-08-13 00:27 - 97743684 _____ C:\Users\Sandy\Downloads\101_M._R._James_-_Verlorene_Herzen.rar 2015-08-13 00:21 - 2015-08-13 00:21 - 136803503 _____ C:\Users\Sandy\Downloads\100_H._P._Lovecraft_-_Träume_im_Hexenhaus.rar 2015-08-13 00:17 - 2015-08-13 00:18 - 162800568 _____ C:\Users\Sandy\Downloads\100 - Träume im Hexenhaus.rar 2015-08-13 00:17 - 2015-08-13 00:18 - 117439939 _____ C:\Users\Sandy\Downloads\101 - Verlorene Herzen.rar 2015-08-13 00:11 - 2015-08-13 00:11 - 07830155 _____ C:\Users\Sandy\Downloads\MP3DiagsSetup-unstable.exe 2015-08-12 23:20 - 2015-08-12 23:20 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\NVIDIA 2015-08-12 23:15 - 2015-08-12 23:15 - 05112705 _____ C:\Users\Sandy\Downloads\dolphin-stable-5.0-rc-6-x64.7z 2015-08-12 19:29 - 2015-08-12 19:29 - 40997272 _____ C:\Users\Sandy\Downloads\InkyInstall.exe 2015-08-12 19:29 - 2015-08-12 19:29 - 00000000 ____D C:\Users\Sandy\AppData\Local\Arcode 2015-08-12 19:23 - 2015-08-12 19:23 - 00000000 ____D C:\Windows\system32\appmgmt 2015-08-12 18:54 - 2015-08-12 19:23 - 00000000 ____D C:\ProgramData\Mailbird 2015-08-12 18:54 - 2015-08-12 18:54 - 01804936 _____ (Mailbird) C:\Users\Sandy\Downloads\MailbirdInstaller.exe 2015-08-12 18:46 - 2015-08-12 18:46 - 00001035 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk 2015-08-12 18:46 - 2015-08-12 18:46 - 00000000 ____D C:\Program Files (x86)\eM Client 2015-08-12 18:45 - 2015-08-12 18:45 - 15233024 _____ C:\Users\Sandy\Downloads\setup.msi 2015-08-12 18:21 - 2015-09-06 00:44 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\MyPhoneExplorer 2015-08-12 18:21 - 2015-08-12 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer 2015-08-12 18:21 - 2015-08-12 18:21 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer 2015-08-12 18:18 - 2015-08-12 18:20 - 07332272 _____ C:\Users\Sandy\Downloads\MyPhoneExplorer_Setup_1.8.6.exe 2015-08-12 17:27 - 2015-08-12 17:27 - 00000348 _____ C:\Users\Sandy\Desktop\gbfm_white_aac (1).pls 2015-08-12 16:43 - 2015-08-12 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2015-08-12 16:43 - 2015-08-12 16:43 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo 2015-08-12 16:42 - 2015-08-12 16:43 - 03907296 _____ (Crystal Dew World ) C:\Users\Sandy\Downloads\CrystalDiskInfo6_5_2-en.exe 2015-08-12 16:22 - 2015-08-03 17:45 - 00010695 _____ C:\Users\Sandy\Documents\XonarSwitch Settings1.xbf 2015-08-12 16:22 - 2015-08-03 11:40 - 00000820 _____ C:\Users\Sandy\Documents\XonarSwitch Settings.xbf 2015-08-12 16:22 - 2015-07-22 16:34 - 00000045 _____ C:\Users\Sandy\Documents\Adresse Michel.txt 2015-08-12 16:22 - 2015-06-09 17:46 - 00000986 _____ C:\Users\Sandy\Documents\meine Meinung zur Lügenpresse.txt 2015-08-12 16:22 - 2015-06-02 14:03 - 00050022 _____ C:\Users\Sandy\Documents\MP3Diags_step2.txt 2015-08-12 16:22 - 2015-06-02 14:03 - 00036306 ____T C:\Users\Sandy\Documents\MP3Diags_trace.txt 2015-08-12 16:22 - 2015-06-02 14:03 - 00033407 _____ C:\Users\Sandy\Documents\MP3Diags_step1.txt 2015-08-12 16:22 - 2015-06-02 14:03 - 00002815 _____ C:\Users\Sandy\Documents\MP3Diags.ini 2015-08-12 16:22 - 2015-06-02 14:03 - 00001829 _____ C:\Users\Sandy\Documents\MP3Diags.dat 2015-08-12 16:22 - 2015-03-03 23:58 - 00006723 _____ C:\Users\Sandy\Documents\onedrive diss.txt 2015-08-12 16:22 - 2014-10-02 22:15 - 00002133 _____ C:\Users\Sandy\Documents\TombRaider.log 2015-08-12 16:22 - 2012-06-15 08:28 - 00001638 _____ C:\Users\Sandy\Documents\Konsumopfer.txt 2015-08-12 16:22 - 2009-07-13 10:43 - 00002891 _____ C:\Users\Sandy\Documents\Transformers.txt 2015-08-12 14:59 - 2015-08-12 14:59 - 00000000 ____D C:\Windows\system32\SleepStudy 2015-08-12 14:55 - 2015-08-12 14:56 - 00000000 ____D C:\Windows\system32\MRT 2015-08-12 14:55 - 2015-07-28 10:59 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-08-12 14:43 - 2015-08-12 14:43 - 12101952 _____ (Opera Software ASA) C:\Users\Sandy\Downloads\Opera-Mail-1.0-1040.i386.exe 2015-08-12 14:43 - 2015-08-12 14:43 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Opera Mail 2015-08-12 14:43 - 2015-08-12 14:43 - 00000000 ____D C:\Users\Sandy\AppData\Local\Opera Mail 2015-08-12 13:42 - 2015-08-03 04:18 - 08613200 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2015-08-12 13:42 - 2015-08-03 03:56 - 06878256 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2015-08-12 13:41 - 2015-08-08 09:29 - 01822280 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-08-12 13:41 - 2015-08-08 09:19 - 00608936 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe 2015-08-12 13:41 - 2015-08-08 09:01 - 01533496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-08-12 13:41 - 2015-08-08 08:48 - 00539728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe 2015-08-12 13:41 - 2015-08-08 08:40 - 00365056 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-08-12 13:41 - 2015-08-08 08:24 - 02415104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-08-12 13:41 - 2015-08-08 08:24 - 01679360 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-08-12 13:41 - 2015-08-08 08:15 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-08-12 13:41 - 2015-08-08 08:00 - 01985024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-08-12 13:41 - 2015-08-06 05:17 - 00237392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys 2015-08-12 13:41 - 2015-08-06 05:17 - 00200528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys 2015-08-12 13:41 - 2015-08-06 04:22 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys 2015-08-12 13:41 - 2015-08-05 06:49 - 00783112 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2015-08-12 13:41 - 2015-08-05 06:29 - 00644128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2015-08-12 13:41 - 2015-08-05 06:00 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll 2015-08-12 13:41 - 2015-08-05 05:54 - 01274880 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll 2015-08-12 13:41 - 2015-08-05 05:47 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2015-08-12 13:41 - 2015-08-05 05:39 - 00261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll 2015-08-12 13:41 - 2015-08-04 06:07 - 00102752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-08-12 13:41 - 2015-08-04 06:06 - 00583128 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-08-12 13:41 - 2015-08-04 06:06 - 00243248 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-08-12 13:41 - 2015-08-04 05:23 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll 2015-08-12 13:41 - 2015-08-04 04:59 - 01212416 _____ (Microsoft Corporation) C:\Windows\system32\RemoteNaturalLanguage.dll 2015-08-12 13:41 - 2015-08-04 04:47 - 00898560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RemoteNaturalLanguage.dll 2015-08-12 13:41 - 2015-08-03 04:32 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\NotificationObjFactory.dll 2015-08-12 13:41 - 2015-08-03 04:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NotificationObjFactory.dll 2015-08-12 13:41 - 2015-08-03 04:19 - 00505696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2015-08-12 13:41 - 2015-08-03 04:19 - 00393568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2015-08-12 13:41 - 2015-08-03 04:18 - 01983840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2015-08-12 13:41 - 2015-08-03 04:18 - 00594472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll 2015-08-12 13:41 - 2015-08-03 04:18 - 00046432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys 2015-08-12 13:41 - 2015-08-03 04:17 - 00516960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2015-08-12 13:41 - 2015-08-03 04:17 - 00052264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys 2015-08-12 13:41 - 2015-08-03 04:12 - 00801632 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe 2015-08-12 13:41 - 2015-08-03 03:49 - 00700256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe 2015-08-12 13:41 - 2015-08-03 03:31 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll 2015-08-12 13:41 - 2015-08-03 03:30 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_UserAccount.dll 2015-08-12 13:41 - 2015-08-03 03:24 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll 2015-08-12 13:41 - 2015-08-03 03:24 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll 2015-08-12 13:41 - 2015-08-03 03:24 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModelShim.dll 2015-08-12 13:41 - 2015-08-03 03:23 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll 2015-08-12 13:41 - 2015-08-03 03:22 - 01601536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll 2015-08-12 13:41 - 2015-08-03 03:22 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2015-08-12 13:41 - 2015-08-03 03:22 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll 2015-08-12 13:41 - 2015-08-03 03:21 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\coredpus.dll 2015-08-12 13:41 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2015-08-12 13:41 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2015-08-12 13:41 - 2015-08-03 03:18 - 12503552 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-08-12 13:41 - 2015-08-03 03:18 - 03780096 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll 2015-08-12 13:41 - 2015-08-03 03:18 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\SubscriptionMgr.dll 2015-08-12 13:41 - 2015-08-03 03:18 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\NetworkStatus.dll 2015-08-12 13:41 - 2015-08-03 03:15 - 01290752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll 2015-08-12 13:41 - 2015-08-03 03:15 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll 2015-08-12 13:41 - 2015-08-03 03:15 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll 2015-08-12 13:41 - 2015-08-03 03:15 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll 2015-08-12 13:41 - 2015-08-03 03:15 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll 2015-08-12 13:41 - 2015-08-03 03:14 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll 2015-08-12 13:41 - 2015-08-03 03:12 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll 2015-08-12 13:41 - 2015-08-03 03:12 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEDataLayerHelpers.dll 2015-08-12 13:41 - 2015-08-03 03:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll 2015-08-12 13:41 - 2015-08-03 03:10 - 01162240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll 2015-08-12 13:41 - 2015-08-03 03:06 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe 2015-08-12 13:41 - 2015-08-03 03:03 - 00494592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll 2015-08-12 13:41 - 2015-08-03 03:02 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll 2015-08-12 13:41 - 2015-08-03 03:02 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2015-08-12 13:41 - 2015-08-03 03:01 - 11262464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-08-12 13:41 - 2015-08-03 02:59 - 00752640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll 2015-08-12 00:34 - 2015-08-12 00:34 - 00021136 _____ C:\Users\Sandy\Downloads\True.Detective.S02E04.1080p.HDTV.x264-BATV.de-SC&TV4U.rar 2015-08-11 21:22 - 2015-08-11 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer 2015-08-11 21:22 - 2015-08-11 21:22 - 00000000 ____D C:\Program Files\Tracker Software 2015-08-11 21:19 - 2015-08-11 21:19 - 17294728 _____ (Tracker Software Products Ltd ) C:\Users\Sandy\Downloads\PDFXVwer.exe 2015-08-11 13:59 - 2015-08-11 13:59 - 00000348 _____ C:\Users\Sandy\Downloads\gbfm_white_aac.pls 2015-08-11 01:26 - 2015-08-11 01:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy 2015-08-11 00:11 - 2015-08-11 00:11 - 00023164 _____ C:\Users\Sandy\Downloads\True.Detective.S02E03.1080p.HDTV.x264-BATV.de-TV4U&SC.rar 2015-08-10 20:55 - 2015-08-10 20:55 - 00113964 _____ C:\Users\Sandy\Downloads\unlocker1.9.0-portable.zip 2015-08-10 20:31 - 2015-08-13 02:03 - 00001024 ____H C:\SYSTAG.BIN 2015-08-10 20:30 - 2015-08-13 02:03 - 00000082 _____ C:\Windows\SysWOW64\winsevr.dat 2015-08-10 20:30 - 2015-08-10 20:31 - 00000000 ____D C:\ProgramData\AomeiBR 2015-08-10 20:30 - 2015-08-10 20:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Backupper 2015-08-10 20:30 - 2015-08-10 20:30 - 00000000 ____D C:\Program Files (x86)\AOMEI Backupper 2015-08-10 20:30 - 2015-02-26 00:00 - 00151480 _____ C:\Windows\system32\ammntdrv.sys 2015-08-10 20:30 - 2015-02-26 00:00 - 00030648 _____ C:\Windows\system32\ambakdrv.sys 2015-08-10 20:30 - 2015-02-26 00:00 - 00017848 _____ C:\Windows\system32\amwrtdrv.sys 2015-08-10 20:28 - 2015-08-10 20:30 - 38261768 _____ (AOMEI Technology Co., Ltd. ) C:\Users\Sandy\Downloads\Backupper.exe 2015-08-10 20:27 - 2015-08-10 20:27 - 08644488 _____ (AOMEI Technology Co., Ltd. ) C:\Users\Sandy\Downloads\PAssist_Std (2).exe 2015-08-10 20:26 - 2015-08-10 20:26 - 08644488 _____ (AOMEI Technology Co., Ltd. ) C:\Users\Sandy\Downloads\PAssist_Std.exe 2015-08-10 20:26 - 2015-08-10 20:26 - 08644488 _____ (AOMEI Technology Co., Ltd. ) C:\Users\Sandy\Downloads\PAssist_Std (1).exe 2015-08-10 19:21 - 2015-08-10 19:21 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\WinRAR 2015-08-10 19:13 - 2015-08-28 06:39 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-08-10 19:13 - 2015-08-28 06:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-08-10 19:13 - 2015-08-10 19:21 - 00000000 ____D C:\Program Files\WinRAR 2015-08-10 19:09 - 2015-08-10 19:09 - 00025752 _____ C:\Users\Sandy\Downloads\True.Detective.S02E02.1080p.HDTV.x264-BATV.de-SC&TV4U.rar 2015-08-10 19:09 - 2015-08-10 19:09 - 00025752 _____ C:\Users\Sandy\Downloads\True.Detective.S02E02.1080p.HDTV.x264-BATV.de-SC&TV4U (1).rar 2015-08-10 16:46 - 2015-08-10 16:46 - 01334336 _____ (Igor Pavlov) C:\Users\Sandy\Downloads\7z1506-x64.exe 2015-08-10 16:43 - 2015-08-10 16:43 - 00020207 _____ C:\Users\Sandy\Downloads\True.Detective.S02E01.1080p.HDTV.x264-BATV.de-TV4U&SC.rar 2015-08-10 11:45 - 2015-08-11 01:26 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\TeraCopy 2015-08-10 11:45 - 2015-08-11 01:26 - 00000000 ____D C:\Program Files\TeraCopy 2015-08-10 11:45 - 2015-08-10 11:45 - 04570101 _____ (Code Sector ) C:\Users\Sandy\Downloads\teracopy3a3.exe 2015-08-10 11:34 - 2015-08-10 11:34 - 00000460 __RSH C:\ProgramData\ntuser.pol 2015-08-10 10:59 - 2015-08-10 10:59 - 00000000 ___RD C:\Sandbox 2015-08-10 10:56 - 2015-08-10 11:08 - 00000000 ____D C:\Program Files\Sandboxie 2015-08-10 10:55 - 2015-08-10 10:56 - 06979208 _____ (Sandboxie Holdings, LLC) C:\Users\Sandy\Downloads\SandboxieInstall.exe 2015-08-10 10:33 - 2015-09-04 18:59 - 00000000 ____D C:\Program Files\Intel 2015-08-10 10:33 - 2015-08-06 13:45 - 00001904 ____N C:\Windows\system32\SetupBD.din 2015-08-10 10:33 - 2015-08-06 13:13 - 00405488 _____ (Intel Corporation) C:\Windows\system32\PROUnstl.exe 2015-08-10 10:33 - 2015-06-18 09:54 - 00003130 _____ C:\Windows\system32\e1d65x64.din 2015-08-10 10:33 - 2015-06-18 09:38 - 00530416 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1d65x64.sys 2015-08-10 10:33 - 2015-06-17 01:28 - 00090608 _____ (Intel Corporation) C:\Windows\system32\NicInstD.dll 2015-08-10 10:33 - 2015-04-02 04:46 - 00075288 _____ (Intel Corporation) C:\Windows\system32\e1dmsg.dll 2015-08-10 10:33 - 2014-04-18 13:17 - 00125728 _____ (Intel Corporation) C:\Windows\system32\NicCo4.dll 2015-08-10 10:32 - 2015-08-10 10:33 - 55660622 _____ C:\Users\Sandy\Downloads\PROWinx64.exe 2015-08-10 10:27 - 2015-08-21 22:23 - 00000000 ____D C:\ProgramData\Intel 2015-08-10 10:27 - 2015-08-10 10:27 - 00000000 ____D C:\Users\Sandy\AppData\Local\Intel 2015-08-10 10:26 - 2015-08-10 10:26 - 05069632 _____ (Intel) C:\Users\Sandy\Downloads\Intel Driver Update Utility Installer.exe 2015-08-10 10:21 - 2015-08-10 10:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter 2015-08-10 10:21 - 2015-08-10 10:21 - 00000000 ____D C:\Program Files (x86)\AC3Filter 2015-08-10 10:21 - 2013-04-05 21:27 - 02231296 _____ C:\Windows\system32\ac3filter64.acm 2015-08-10 10:21 - 2013-04-05 21:26 - 01679360 _____ C:\Windows\SysWOW64\ac3filter.acm 2015-08-10 10:20 - 2015-08-10 10:21 - 04184641 _____ (Alexander Vigovsky ) C:\Users\Sandy\Downloads\ac3filter_2_6_0b.exe 2015-08-10 10:17 - 2015-08-10 10:17 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\MPC-HC 2015-08-10 10:17 - 2015-08-10 10:17 - 00000000 ____D C:\Program Files (x86)\madVR 2015-08-10 10:16 - 2015-08-10 10:16 - 09465988 _____ C:\Users\Sandy\Downloads\madVR.zip 2015-08-10 10:15 - 2015-08-10 10:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC 2015-08-10 10:15 - 2015-08-10 10:15 - 00000000 ____D C:\Program Files (x86)\MPC-HC 2015-08-10 10:14 - 2015-08-10 10:15 - 12299240 _____ (MPC-HC Team ) C:\Users\Sandy\Downloads\MPC-HC.1.7.9.x86.exe 2015-08-10 03:54 - 2015-08-10 03:54 - 00252790 _____ C:\Users\Sandy\Downloads\JDownloader 2 Setup.zip 2015-08-10 03:31 - 2015-08-10 03:31 - 00429248 _____ C:\Users\Sandy\Downloads\XonarSwitch.zip 2015-08-10 03:23 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2015-08-10 03:23 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2015-08-10 03:23 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2015-08-10 03:23 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2015-08-10 03:23 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2015-08-10 03:23 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2015-08-10 03:23 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2015-08-10 03:23 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2015-08-10 03:23 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2015-08-10 03:23 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2015-08-10 03:23 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2015-08-10 03:23 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2015-08-10 03:23 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2015-08-10 03:23 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2015-08-10 03:23 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2015-08-10 03:23 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2015-08-10 03:23 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2015-08-10 03:23 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2015-08-10 03:23 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2015-08-10 03:23 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2015-08-10 03:23 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2015-08-10 03:23 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2015-08-10 03:23 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2015-08-10 03:23 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2015-08-10 03:23 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2015-08-10 03:23 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2015-08-10 03:23 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-08-10 03:23 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2015-08-10 03:23 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2015-08-10 03:23 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-08-10 03:23 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-08-10 03:23 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2015-08-10 03:23 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2015-08-10 03:23 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-08-10 03:23 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2015-08-10 03:23 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-08-10 03:23 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2015-08-10 03:23 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2015-08-10 03:23 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-08-10 03:23 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-08-10 03:23 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2015-08-10 03:23 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-08-10 03:23 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2015-08-10 03:23 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-08-10 03:23 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2015-08-10 03:23 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-08-10 03:23 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2015-08-10 03:23 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-08-10 03:23 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2015-08-10 03:23 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-08-10 03:23 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2015-08-10 03:23 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-08-10 03:23 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2015-08-10 03:23 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-08-10 03:23 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2015-08-10 03:23 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-08-10 03:23 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2015-08-10 03:23 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-08-10 03:23 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-08-10 03:23 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2015-08-10 03:23 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-08-10 03:23 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-08-10 03:23 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2015-08-10 03:23 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-08-10 03:23 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2015-08-10 03:23 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-08-10 03:23 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2015-08-10 03:23 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-08-10 03:23 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2015-08-10 03:23 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-08-10 03:23 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2015-08-10 03:23 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-08-10 03:23 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2015-08-10 03:23 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-08-10 03:23 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2015-08-10 03:23 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-08-10 03:23 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2015-08-10 03:23 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2015-08-10 03:23 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-08-10 03:23 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-08-10 03:23 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2015-08-10 03:23 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-08-10 03:23 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2015-08-10 03:23 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-08-10 03:23 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2015-08-10 03:23 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2015-08-10 03:23 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-08-10 03:23 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-08-10 03:23 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-08-10 03:23 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2015-08-10 03:23 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2015-08-10 03:23 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2015-08-10 03:23 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-08-10 03:23 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-08-10 03:23 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2015-08-10 03:23 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-08-10 03:23 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2015-08-10 03:23 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-08-10 03:23 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2015-08-10 03:23 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-08-10 03:23 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2015-08-10 03:23 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-08-10 03:23 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2015-08-10 03:23 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-08-10 03:23 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2015-08-10 03:23 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-08-10 03:23 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2015-08-10 03:23 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-08-10 03:23 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2015-08-10 03:23 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-08-10 03:23 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2015-08-10 03:23 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-08-10 03:23 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2015-08-10 03:23 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-08-10 03:23 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2015-08-10 03:22 - 2015-08-21 20:15 - 00000000 ____D C:\Users\Sandy\Documents\giana sisters - twisted dreams 2015-08-10 03:22 - 2015-08-17 01:23 - 00000000 ____D C:\Users\Sandy\Documents\my games 2015-08-10 03:17 - 2015-09-07 20:54 - 00000000 ____D C:\Program Files (x86)\Steam 2015-08-10 03:17 - 2015-08-10 03:17 - 01476720 _____ C:\Users\Sandy\Downloads\SteamSetup.exe 2015-08-10 03:17 - 2015-08-10 03:17 - 00000000 ____D C:\Users\Sandy\AppData\Local\Steam 2015-08-10 03:17 - 2015-08-10 03:17 - 00000000 ____D C:\Users\Sandy\AppData\Local\CEF 2015-08-10 03:17 - 2015-08-10 03:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2015-08-10 03:08 - 2015-08-10 03:08 - 00000000 ____D C:\Users\Sandy\AppData\Local\Logitech 2015-08-10 03:08 - 2015-08-10 03:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2015-08-10 03:08 - 2015-08-10 03:08 - 00000000 ____D C:\ProgramData\LogiShrd 2015-08-10 03:07 - 2015-08-28 03:09 - 00000000 ____D C:\ProgramData\Package Cache 2015-08-10 03:07 - 2015-08-10 03:08 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2015-08-10 03:07 - 2015-08-10 03:07 - 82596072 _____ (Logitech Inc.) C:\Users\Sandy\Downloads\LGS_8.70.315_x64_Logitech.exe 2015-08-10 03:07 - 2015-08-10 03:07 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Logitech 2015-08-10 03:07 - 2015-08-10 03:07 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Logishrd 2015-08-10 02:30 - 2015-08-19 20:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-08-10 02:30 - 2015-08-10 02:30 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2015-08-10 02:30 - 2015-08-10 02:30 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Thunderbird 2015-08-10 02:30 - 2015-08-10 02:30 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Mozilla 2015-08-10 02:30 - 2015-08-10 02:30 - 00000000 ____D C:\Users\Sandy\AppData\Local\Thunderbird 2015-08-10 02:30 - 2015-08-10 02:30 - 00000000 ____D C:\ProgramData\Mozilla 2015-08-10 02:29 - 2015-08-10 02:29 - 40399162 _____ C:\Users\Sandy\Downloads\thunderbird-38.1.0.tar.bz2 2015-08-10 02:29 - 2015-08-10 02:29 - 33855496 _____ (Mozilla) C:\Users\Sandy\Downloads\Thunderbird Setup 38.1.0.exe 2015-08-10 02:22 - 2015-08-10 02:22 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2015-08-10 02:22 - 2015-08-10 02:22 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2015-08-10 02:22 - 2015-08-10 02:22 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2015-08-10 02:22 - 2015-08-10 02:22 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2015-08-10 02:22 - 2015-08-10 02:22 - 00043689 _____ C:\Windows\Cmicnfgp.ini.cfl 2015-08-10 02:22 - 2015-08-10 02:22 - 00000742 _____ C:\Windows\Cmicnfgp.ini.imi 2015-08-10 02:22 - 2015-08-10 02:22 - 00000681 _____ C:\Windows\system\Cmicnfgp.ini 2015-08-10 02:22 - 2015-08-10 02:22 - 00000160 _____ C:\Users\Sandy\Downloads\installsettings.ini 2015-08-10 02:22 - 2015-08-10 02:22 - 00000134 _____ C:\Windows\system\Dlap.pfx 2015-08-10 02:22 - 2015-08-10 02:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio 2015-08-10 02:22 - 2015-08-10 02:22 - 00000000 ____D C:\Program Files\UNi Xonar Audio 2015-08-10 02:22 - 2015-08-10 02:22 - 00000000 ____D C:\Program Files (x86)\OpenAL 2015-08-10 02:22 - 2014-07-24 10:58 - 00833536 ____N C:\Windows\system32\Cmeauoxy.exe 2015-08-10 02:22 - 2014-03-11 15:07 - 08048640 ____N (C-Media Corporation) C:\Windows\SysWOW64\CmiCnfgp.dll 2015-08-10 02:22 - 2013-10-16 10:55 - 00143360 ____N C:\Windows\SysWOW64\VmixP8.dll 2015-08-10 02:22 - 2013-03-13 23:47 - 00004525 ____N C:\Windows\Cmicnfgp.ini.cfg 2015-08-10 02:22 - 2012-10-05 09:37 - 00465408 ____N (C-Media Electronics Inc.) C:\Windows\system32\cmasiopx.dll 2015-08-10 02:22 - 2012-10-05 09:37 - 00303104 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\cmasiop.dll 2015-08-10 02:22 - 2012-09-16 22:23 - 00293376 ____N C:\Windows\system32\CmiCnfgP.cpl 2015-08-10 02:22 - 2012-01-06 09:30 - 00212992 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv2.dll 2015-08-10 02:22 - 2012-01-06 09:30 - 00212992 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv.dll 2015-08-10 02:22 - 2012-01-06 09:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv642.dll 2015-08-10 02:22 - 2012-01-06 09:30 - 00122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv64.dll 2015-08-10 02:22 - 2010-07-15 16:12 - 00000062 ____N C:\Windows\system32\cmasiopx.ini 2015-08-10 02:22 - 2010-07-15 16:12 - 00000057 ____N C:\Windows\SysWOW64\cmasiop.ini 2015-08-10 02:22 - 2009-08-19 15:00 - 00359424 ____N C:\Windows\system32\CmiInstallResAll64.dll 2015-08-10 02:22 - 2008-07-11 15:04 - 00200704 ____N C:\Windows\SysWOW64\HsMgr.exe 2015-08-10 02:22 - 2008-07-11 15:03 - 00282112 ____N C:\Windows\system\HsMgr64.exe 2015-08-10 02:22 - 2007-12-13 17:12 - 00122880 ____N (CMedia Electronics Inc.) C:\Windows\SysWOW64\Cm_Oal.dll 2015-08-10 02:22 - 2007-12-13 17:12 - 00122880 ____N (CMedia Electronics Inc.) C:\Windows\system32\Cm_Oal.dll 2015-08-10 02:22 - 2006-09-13 10:21 - 00200704 ____N (C-Media) C:\Windows\SysWOW64\Cmpaoxy.dll 2015-08-10 02:21 - 2014-04-24 07:08 - 00006417 ____N C:\Windows\cmudaxp.ini 2015-08-10 02:21 - 2013-12-11 11:09 - 02735616 _____ (C-Media Inc) C:\Windows\system32\Drivers\cmudaxp.sys 2015-08-10 02:21 - 2013-12-11 11:09 - 00315392 _____ (C-Media Electronics Inc.) C:\Windows\SysWOW64\CmiFltr.dll 2015-08-10 02:21 - 2013-12-11 11:09 - 00315392 _____ (C-Media Electronics Inc.) C:\Windows\system\CmiFltr.dll 2015-08-10 02:21 - 2013-12-11 11:09 - 00032768 _____ (C-Media Electronics Inc.) C:\Windows\system32\cmudaxp.dll 2015-08-10 02:21 - 2010-02-08 21:36 - 00519048 _____ (Microsoft Corporation) C:\Windows\difxapi.dll 2015-08-10 02:18 - 2015-08-10 02:21 - 07622464 _____ (CarvedInside ) C:\Users\Sandy\Downloads\UNi Xonar 1822 v1.75a r2.exe 2015-08-10 02:15 - 2015-09-06 20:47 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\KeePass 2015-08-10 02:13 - 2015-08-10 02:13 - 00001190 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk 2015-08-10 02:13 - 2015-08-10 02:13 - 00000000 ____D C:\Program Files (x86)\KeePass Password Safe 2 2015-08-10 02:11 - 2015-08-10 02:12 - 03058696 _____ (Dominik Reichl ) C:\Users\Sandy\Downloads\KeePass-2.30-Setup.exe 2015-08-10 02:08 - 2015-09-09 14:14 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\NetSpeedMonitor 2015-08-10 02:08 - 2015-08-10 02:08 - 00000000 ____D C:\Program Files\NetSpeedMonitor 2015-08-10 02:07 - 2015-08-10 02:07 - 03652608 _____ C:\Users\Sandy\Downloads\netspeedmonitor_2_5_4_0_x64_setup.msi 2015-08-10 02:03 - 2015-09-09 14:08 - 00001244 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2015-08-10 02:03 - 2015-09-09 12:15 - 00001240 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2015-08-10 02:03 - 2015-09-09 12:15 - 00000000 ____D C:\Users\Sandy\AppData\Local\Dropbox 2015-08-10 02:03 - 2015-09-02 17:37 - 00000000 ____D C:\Program Files (x86)\Dropbox 2015-08-10 02:03 - 2015-08-10 02:03 - 00660960 _____ (Dropbox, Inc.) C:\Users\Sandy\Downloads\DropboxInstaller.exe 2015-08-10 02:03 - 2015-08-10 02:03 - 00004304 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA 2015-08-10 02:03 - 2015-08-10 02:03 - 00004072 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore 2015-08-10 02:03 - 2015-08-10 02:03 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Dropbox 2015-08-10 02:03 - 2015-08-10 02:03 - 00000000 ____D C:\Users\Sandy\AppData\Local\PeerDistRepub 2015-08-10 02:03 - 2015-08-10 02:03 - 00000000 ____D C:\ProgramData\Dropbox 2015-08-10 01:57 - 2015-08-10 01:57 - 00000000 ____D C:\Users\Sandy\AppData\Roaming\Opera Software 2015-08-10 01:57 - 2015-08-10 01:57 - 00000000 ____D C:\Users\Sandy\AppData\Local\Opera Software 2015-08-10 01:56 - 2015-08-10 01:56 - 00703480 _____ (Opera Software) C:\Users\Sandy\Downloads\Opera_NI_stable.exe 2015-08-10 01:56 - 2015-08-10 01:56 - 00001208 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-08-10 01:56 - 2015-08-10 01:56 - 00000000 ____D C:\Program Files (x86)\Opera 2015-08-10 01:55 - 2015-08-10 01:56 - 00000000 ____D C:\Users\Sandy\AppData\Local\MicrosoftEdge 2015-08-10 01:53 - 2015-08-12 02:46 - 00000000 ____D C:\Users\Sandy\AppData\Local\Comms ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-09 13:17 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\sru 2015-09-09 13:10 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\AppReadiness 2015-09-09 12:19 - 2015-07-10 12:55 - 00000000 ____D C:\Windows\CbsTemp 2015-09-09 01:04 - 2015-08-09 22:25 - 01790124 _____ C:\Windows\system32\PerfStringBackup.INI 2015-09-09 01:04 - 2015-07-10 18:34 - 00771100 _____ C:\Windows\system32\perfh007.dat 2015-09-09 01:04 - 2015-07-10 18:34 - 00153964 _____ C:\Windows\system32\perfc007.dat 2015-09-09 00:58 - 2015-07-10 14:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-09 00:57 - 2015-07-10 11:05 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-09-07 18:20 - 2015-08-09 22:20 - 00000000 ____D C:\Users\Sandy 2015-09-07 18:17 - 2015-08-09 22:20 - 00000000 ____D C:\Users\Sandy\AppData\Local\Packages 2015-09-06 20:48 - 2015-07-10 14:20 - 00266792 _____ C:\Windows\system32\FNTCACHE.DAT 2015-09-04 18:55 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\NDF 2015-09-04 13:30 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\Help 2015-09-02 21:04 - 2015-08-09 23:13 - 00000000 ____D C:\Windows\Panther 2015-08-31 20:12 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\rescache 2015-08-31 00:27 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\oobe 2015-08-31 00:27 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\appraiser 2015-08-25 19:18 - 2015-08-09 22:21 - 00000000 ___RD C:\Users\Sandy\OneDrive 2015-08-25 19:00 - 2015-08-09 22:21 - 00002358 _____ C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2015-08-25 17:11 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-08-25 17:10 - 2015-07-10 18:44 - 00000000 ____D C:\Windows\ShellNew 2015-08-21 21:52 - 2015-06-12 04:54 - 00193336 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverW8x64.sys 2015-08-19 20:57 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2015-08-17 21:34 - 2015-08-09 22:21 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2015-08-17 21:34 - 2015-08-09 22:21 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2015-08-17 21:34 - 2015-08-09 22:21 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2015-08-13 19:38 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\SysWOW64\MUI 2015-08-13 19:38 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\MUI 2015-08-12 18:29 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-12 18:29 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-11 21:52 - 2015-08-09 22:21 - 11174544 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-08-10 20:17 - 2015-08-09 22:20 - 00000000 ____D C:\Users\Sandy\AppData\Local\VirtualStore 2015-08-10 11:33 - 2015-07-10 13:04 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2015-08-10 03:22 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\appcompat 2015-08-10 02:22 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\System 2015-08-10 01:54 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-08-19 20:57 - 2015-08-19 20:57 - 0000000 ____H () C:\Users\Sandy\AppData\Local\BIT8622.tmp 2015-09-04 22:43 - 2015-09-04 22:43 - 0007605 _____ () C:\Users\Sandy\AppData\Local\Resmon.ResmonCfg 2015-08-19 20:56 - 2015-08-19 20:56 - 0000000 _____ () C:\Users\Sandy\AppData\Local\{405C1CF0-C0D4-46CD-9133-FFB0F9C5EF36} Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Sandy\AppData\Local\Temp\Temp1_XonarSwitch.zip\XonarSwitch.exe Einige Dateien in TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfy9rrx.dll C:\Users\Sandy\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp3zk3tf.dll C:\Users\Sandy\AppData\Local\Temp\proxy_vole7443059428555417277.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-09-04 22:43 ==================== Ende von FRST.txt ============================ |
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:07-09-2015 durchgeführt von Sandy (2015-09-09 14:15:19) Gestartet von C:\Users\Sandy\Downloads Windows 10 Pro (X64) (2015-08-09 20:18:39) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3290226221-2357063689-2307062531-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-3290226221-2357063689-2307062531-503 - Limited - Disabled) Gast (S-1-5-21-3290226221-2357063689-2307062531-501 - Limited - Disabled) Sandy (S-1-5-21-3290226221-2357063689-2307062531-1001 - Administrator - Enabled) => C:\Users\Sandy ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: - Adobe Systems Incorporated) AOMEI Backupper Standard (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536CE9D}_is1) (Version: - AOMEI Technology Co., Ltd.) ASRock Restart to UEFI v1.0.5 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: 1.0.5 - ) Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team) Avidemux 2.6 - 64 bits (HKLM-x32\...\Avidemux 2.6 - 64 bits (64-bit)) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.09 - Piriform) CPUID CPU-Z 1.73 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CrystalDiskInfo 6.5.2 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.5.2 - Crystal Dew World) Divinity Original Sin Version (HKLM-x32\...\{F3BB599E-4153-4593-B2F7-88328E18698B}_is1) (Version: - Larian Studios) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: - Dropbox, Inc.) Hidden eM Client (HKLM-x32\...\{6D1C3187-2820-44F9-B64F-83FD3DEE0201}) (Version: 6.0.22344.0 - eM Client Inc.) FFmpeg (Windows) for Audacity Version 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - ) FFMPEG Addon (HKLM-x32\...\{111124AF-1ED4-44EF-B674-111111985342}_is1) (Version: 1.00 - FFMPEG) FormatFactory (HKLM-x32\...\FormatFactory) (Version: - Format Factory) FreeFileSync 7.3 (HKLM-x32\...\FreeFileSync) (Version: 7.3 - www.FreeFileSync.org) Gauntlet Slayer Edition (HKLM-x32\...\Gauntlet Slayer Edition_is1) (Version: - ) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Icecream Ebook Reader Version 1.70 (HKLM-x32\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 1.70 - Icecream Apps) Intel Extreme Tuning Utility (HKLM-x32\...\{ca64a229-d771-4f51-91c1-a1bd637e0da3}) (Version: - Intel Corporation) Intel Extreme Tuning Utility (x32 Version: - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: - Intel Corporation) Intel(R) Network Connections (HKLM\...\PROSetDX) (Version: - Intel) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) KeePass Password Safe 2.30 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.30 - Dominik Reichl) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Logitech Gaming Software 8.70 (HKLM\...\Logitech Gaming Software) (Version: 8.70.315 - Logitech Inc.) Lure of the Temptress (HKLM-x32\...\1207658694_is1) (Version: - GOG.com) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.1.0 - Mozilla) Mozilla Thunderbird 38.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla) MP3 Diags (HKLM-x32\...\MP3Diags) (Version: - ) MPC-HC 1.7.9 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.9 - MPC-HC Team) MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) NetSpeedMonitor x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: - Florian Gilles) NVIDIA Grafiktreiber 355.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 355.60 - NVIDIA Corporation) NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Mail 1.0 (HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\...\Opera 1.0.1040) (Version: 1.0.1040 - Opera Software ASA) Opera Stable 31.0.1889.106 (HKLM-x32\...\Opera 31.0.1889.106) (Version: 31.0.1889.106 - Opera Software) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden paint.net (HKLM\...\{DF3A46D9-67B3-44B2-9D01-25C8BA772C8A}) (Version: 4.0.6 - dotPDN LLC) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.313.1 - Tracker Software Products Ltd) RivaTuner Statistics Server 6.3.0 (HKLM-x32\...\RTSS) (Version: 6.3.0 - Unwinder) Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) System Requirements Lab Detection (HKLM-x32\...\{0D4E34E1-E485-42DB-B87D-23C6F18B0B27}) (Version: - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.17 - TeamSpeak Systems GmbH) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer) TeraCopy 2.3 (HKLM\...\TeraCopy_is1) (Version: - Code Sector) Trine 3: The Artifacts of Power (HKLM-x32\...\Steam App 319910) (Version: - Frozenbyte) UNi Xonar Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version: - ) Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CBCC2FD8-7DFE-4752-95B5-2E447C226F45}) (Version: - Microsoft) Victor Vran (HKLM-x32\...\Steam App 345180) (Version: - Haemimont Games) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3290226221-2357063689-2307062531-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Sandy\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2015-07-10 13:04 - 2015-07-10 13:02 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation) Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation) Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation) Task: {238E5901-EBC3-44D9-B53A-EB789DB124F0} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe [2015-08-14] (Adobe Systems Incorporated) Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation) Task: {468EA5D3-472D-4A68-A341-31DA2B8B80FF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {59BCBE86-624E-4C75-A4B5-6B2521F919A1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-07-28] (Microsoft Corporation) Task: {67EB2EE0-FB58-4F4D-9536-F1F69AE3A82E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-08-20] (Piriform Ltd) Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-07-15] (Microsoft Corporation) Task: {9273335A-6972-41D2-B002-E1AC73EEC0B0} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2015-05-05] (Intel Corporation) Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager Task: {B2534FAB-FD78-4732-887F-60CD69A98634} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {C53522EF-289E-40DB-B85E-58812A911DA6} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-10] (Dropbox, Inc.) Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation) Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation) Task: {EEA05918-23A2-4ED9-86A5-25EECCC79209} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {FFBCC9B3-839C-4100-9717-098F799AFCA7} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-10] (Dropbox, Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-08-09 22:25 - 2015-07-15 04:04 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll 2015-08-17 21:34 - 2015-08-07 06:27 - 00116528 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-08-28 18:37 - 2015-08-18 09:56 - 02498808 _____ () C:\Windows\system32\CoreUIComponents.dll 2015-08-28 18:37 - 2015-08-18 09:56 - 02498808 _____ () C:\Windows\System32\CoreUIComponents.dll 2015-07-10 12:59 - 2015-07-10 12:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-07-10 12:59 - 2015-07-10 12:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2015-07-02 02:28 - 2015-07-02 02:28 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2015-07-02 02:28 - 2015-07-02 02:28 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2015-08-11 01:26 - 2012-01-20 14:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll 2015-08-12 13:41 - 2015-08-03 03:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-07-10 13:00 - 2015-07-10 18:43 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-08-19 11:26 - 2015-08-11 10:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-08-12 13:41 - 2015-08-03 03:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-07-10 13:00 - 2015-07-10 18:43 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00306904 _____ () C:\Program Files (x86)\AOMEI Backupper\UiLogic.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00241368 _____ () C:\Program Files (x86)\AOMEI Backupper\diskmgr.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00290520 _____ () C:\Program Files (x86)\AOMEI Backupper\Comn.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00122584 _____ () C:\Program Files (x86)\AOMEI Backupper\FuncLogic.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00347864 _____ () C:\Program Files (x86)\AOMEI Backupper\ImgFile.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00028376 _____ () C:\Program Files (x86)\AOMEI Backupper\Encrypt.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00483032 _____ () C:\Program Files (x86)\AOMEI Backupper\EnumFolder.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00069336 _____ () C:\Program Files (x86)\AOMEI Backupper\Compress.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00691928 _____ () C:\Program Files (x86)\AOMEI Backupper\Sync.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper\BrLog.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00077528 _____ () C:\Program Files (x86)\AOMEI Backupper\Ldm.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00061144 _____ () C:\Program Files (x86)\AOMEI Backupper\Device.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00282328 _____ () C:\Program Files (x86)\AOMEI Backupper\BrFat.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00962264 _____ () C:\Program Files (x86)\AOMEI Backupper\BrNtfs.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00282328 _____ () C:\Program Files (x86)\AOMEI Backupper\Clone.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00118488 _____ () C:\Program Files (x86)\AOMEI Backupper\Backup.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00155352 _____ () C:\Program Files (x86)\AOMEI Backupper\FlBackup.dll 2015-08-10 20:30 - 2015-02-26 00:00 - 02403504 _____ () C:\Program Files (x86)\AOMEI Backupper\QtCore4.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper\BrVol.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00253656 _____ () C:\Program Files (x86)\AOMEI Backupper\GptBcd.dll 2015-08-10 20:30 - 2015-08-06 18:02 - 00175832 _____ () C:\Program Files (x86)\AOMEI Backupper\DeviceMgr.dll 2015-07-10 23:37 - 2015-07-10 23:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-09-09 12:15 - 2015-09-09 12:15 - 00071168 _____ () c:\users\sandy\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp3zk3tf.dll 2015-08-10 02:03 - 2015-08-05 07:26 - 00012800 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick.2\qtquick2plugin.dll 2015-08-10 02:03 - 2015-08-05 07:26 - 00779776 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-08-10 02:03 - 2015-08-05 07:26 - 00056320 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-08-10 02:03 - 2015-08-05 07:26 - 00012288 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Window.2\windowplugin.dll 2015-08-10 01:56 - 2015-08-06 11:43 - 58604664 _____ () C:\Program Files (x86)\Opera\31.0.1889.106\opera.dll 2015-08-10 01:56 - 2015-08-06 11:43 - 01780344 _____ () C:\Program Files (x86)\Opera\31.0.1889.106\libglesv2.dll 2015-08-10 01:56 - 2015-08-06 11:43 - 00081528 _____ () C:\Program Files (x86)\Opera\31.0.1889.106\libegl.dll 2015-08-19 12:55 - 2015-08-19 12:55 - 00153768 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2015-08-19 12:55 - 2015-08-19 12:55 - 00023208 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3290226221-2357063689-2307062531-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sandy\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [TCP Query User{42739B10-3612-468A-963C-6D4EC6BEE8E6}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{3A52917D-4E05-4709-885B-4EE84E2FD701}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{FFA9BF81-7627-4561-90FF-3343C5B7DF3F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1CB19185-6A4D-43A5-89B7-7871FCDF813B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{642C40EB-A4D1-424B-8B81-C9F08B70D481}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{1FC01A20-C45C-4F9E-807E-D67C1713725C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{1833AFB3-41CD-4189-BB68-AACD9EFF8151}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{03109387-9C7B-480B-956E-524643A6E85C}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{9DFEA940-AB91-4463-89BC-33FDFEE61821}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [UDP Query User{9A465F02-8E9D-4596-ACE5-137062EFE74E}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [{8B08A047-38B6-4DE7-9541-0D47B635F28D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{933E12B9-B431-46AF-8308-E0DB1EB1A68D}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Victor Vran\VictorVranSteam.exe FirewallRules: [{9CD37A51-F524-4CAA-9297-823E6CF2AB57}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Victor Vran\VictorVranSteam.exe FirewallRules: [{BD124CE6-1016-4458-BF2C-BCAB26DF9032}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [{8C1B8893-8A06-4455-A800-D0F6517727E9}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [{06BCDC6E-CDCA-4AE9-A294-77C4063F01F0}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Trine 3\trine3_launcher.exe FirewallRules: [{6C9EA0A3-6BA4-494B-BF7C-97AFD9ECFB9A}] => (Allow) D:\Spiele\SteamLibrary\SteamApps\common\Trine 3\trine3_launcher.exe FirewallRules: [TCP Query User{6DD91EAD-14EF-4888-9005-71298752700A}D:\spiele\steamlibrary\steamapps\common\giana sisters twisted dreams\gsgameexe.exe] => (Allow) D:\spiele\steamlibrary\steamapps\common\giana sisters twisted dreams\gsgameexe.exe FirewallRules: [UDP Query User{37F8F6CD-46D8-4C23-9EF9-843F4D41D842}D:\spiele\steamlibrary\steamapps\common\giana sisters twisted dreams\gsgameexe.exe] => (Allow) D:\spiele\steamlibrary\steamapps\common\giana sisters twisted dreams\gsgameexe.exe FirewallRules: [TCP Query User{7C19649D-2303-4AA6-89BD-4C3049AB89D4}D:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) D:\spiele\divinity original sin\shipping\eocapp.exe FirewallRules: [UDP Query User{E3CE9FAC-9902-4C7F-8E31-505D85930185}D:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) D:\spiele\divinity original sin\shipping\eocapp.exe FirewallRules: [TCP Query User{E59B7DBF-B510-4BFF-8C62-AC5C524BCE1A}C:\users\sandy\downloads\ffinstonline.exe] => (Block) C:\users\sandy\downloads\ffinstonline.exe FirewallRules: [UDP Query User{88EF0EC4-6376-44BC-AB1B-A5589B347F47}C:\users\sandy\downloads\ffinstonline.exe] => (Block) C:\users\sandy\downloads\ffinstonline.exe FirewallRules: [{22625C62-64EB-4C7C-A74A-226B4AC73059}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [TCP Query User{FBBD2FBF-7076-4ED3-94E1-49C3191B0338}C:\program files (x86)\chrispc videotube downloader pro\filespro\mgrv.dll] => (Allow) C:\program files (x86)\chrispc videotube downloader pro\filespro\mgrv.dll FirewallRules: [UDP Query User{B63A2F0E-AE21-451E-B40A-CC98C2F0BB13}C:\program files (x86)\chrispc videotube downloader pro\filespro\mgrv.dll] => (Allow) C:\program files (x86)\chrispc videotube downloader pro\filespro\mgrv.dll FirewallRules: [{B00969CE-8455-4AB2-ABFC-B87865A317E5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{24B10F87-EF28-4D42-B1A8-239CE1FB7D98}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{80A985E7-DE84-4A23-9691-325B2E37EC26}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{872BC28B-49AD-4944-BD66-CC4356CBE103}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (09/09/2015 12:17:26 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (6740) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032. Error: (09/09/2015 12:17:26 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (6740) Der Versuch, die Datei "C:\Windows\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien. Error: (09/09/2015 12:17:16 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (6740) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032. Error: (09/09/2015 12:17:16 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (6740) Der Versuch, die Datei "C:\Windows\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien. Error: (09/09/2015 12:17:05 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (6740) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032. Error: (09/09/2015 12:17:05 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (6740) Der Versuch, die Datei "C:\Windows\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien. Error: (09/09/2015 12:16:55 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (6740) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032. Error: (09/09/2015 12:16:55 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (6740) Der Versuch, die Datei "C:\Windows\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien. Error: (09/09/2015 12:16:45 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (6740) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032. Error: (09/09/2015 12:16:45 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (6740) Der Versuch, die Datei "C:\Windows\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien. Systemfehler: ============= Error: (09/09/2015 01:05:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_Session2" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:05:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _Session2" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:05:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_Session2" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:05:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_Session2" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:01:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_Session1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:01:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _Session1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:01:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_Session1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 01:01:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Synchronisierungshost_Session1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/09/2015 12:57:52 AM) (Source: DCOM) (EventID: 10010) (User: BASE) Description: CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca Error: (09/09/2015 12:54:57 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_Session1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office: ========================= Error: (09/09/2015 12:17:26 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost6740-1032 Error: (09/09/2015 12:17:26 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost6740C:\Windows\system32\edbtmp.log-1032 (0xfffffbf8)5 (0x00000005)Zugriff verweigert Error: (09/09/2015 12:17:16 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost6740-1032 Error: (09/09/2015 12:17:16 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost6740C:\Windows\system32\edbtmp.log-1032 (0xfffffbf8)5 (0x00000005)Zugriff verweigert Error: (09/09/2015 12:17:05 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost6740-1032 Error: (09/09/2015 12:17:05 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost6740C:\Windows\system32\edbtmp.log-1032 (0xfffffbf8)5 (0x00000005)Zugriff verweigert Error: (09/09/2015 12:16:55 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost6740-1032 Error: (09/09/2015 12:16:55 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost6740C:\Windows\system32\edbtmp.log-1032 (0xfffffbf8)5 (0x00000005)Zugriff verweigert Error: (09/09/2015 12:16:45 PM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost6740-1032 Error: (09/09/2015 12:16:45 PM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost6740C:\Windows\system32\edbtmp.log-1032 (0xfffffbf8)5 (0x00000005)Zugriff verweigert CodeIntegrity: =================================== Date: 2015-09-07 19:54:59.703 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-05 19:44:55.501 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-02 22:14:28.921 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-08-31 20:02:48.053 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-08-28 19:54:39.925 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-08-26 19:02:20.874 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-4690K CPU @ 3.50GHz Prozentuale Nutzung des RAM: 43% Installierter physikalischer RAM: 8142.89 MB Verfügbarer physikalischer RAM: 4608.88 MB Summe virtueller Speicher: 9422.89 MB Verfügbarer virtueller Speicher: 5167.98 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:118.69 GB) (Free:84.26 GB) NTFS Drive d: (Volume) (Fixed) (Total:419.92 GB) (Free:222.93 GB) NTFS ==>[System mit Startkomponenten (eingeholt von lesen Laufwerk)] Drive e: (Volume) (Fixed) (Total:511.59 GB) (Free:303.25 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 119.2 GB) (Disk ID: DF0B376D) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 0D76E04B) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Active) - (Size=419.9 GB) - (Type=42) Partition 3: (Not Active) - (Size=511.6 GB) - (Type=42) ==================== Ende von Addition.txt ============================ |
Das passiert bei mir unter Windows 10 auch, mitten in der Nacht fährt der einfach hoch um Updates zu deinstallieren. Wenn du sie manuell installierst, fragt er nämlich nach, wann er das tun soll (ich hab da leider jetzt keinen Screenshot davon.). Ich vermute, dass das damit zusammenhängt.

Was Win 10 auch noch gern macht ist statt runterfahren neu zu starten.
mir ist gerade aufgefallen, dass Windows auch nicht mehr richtig runterfährt. Bildschirm geht aus, Festplatte fährt auch runter, aber Rechner läuft weiter. Exakt das selbe Problem hatte ich vor einigen Wochen auch schon, als ich von Windows 8.1 auf Windows 10 geupgradet habe. Der Rechner ging einfach nicht aus. Dann hatte ich Windows 10 komplett neu installiert. Seit dem gab es keine Probleme mehr. Bis heute.

Gibt's denn keine Möglichkeit, den Problemen auf die Schliche zu kommen? Bin gerade echt mega genervt von Windows. WIeviel Zeit ich in den letzten Monaten schon wieder damit verbracht habe, dass alles läuft wie es soll...

Was mir auch noch auffällt ist, dass wenn ich per Rechtsklick aufs Startmenü ein Fenster öffne, zb Energieoptionen, dann öffnet sich das Fenster, geht sofort wieder zu und öffnet sich wieder. Oder wenn ich von Opera oder Chromeaus den Downloadordner öffne und danach wieder schließe, öffnet er sich noch einmal neu.

Könnte gerade echt göbbeln. Werde wohl wieder mal Neuinstallieren müssen. Und da beschweren sich Windowsnutzer, dass man bei Linux soviel frickeln muss. ha!

Sorry, bin gerade echt geladen. Weiß natürlich, dass hier niemand Schuld hat
Win 10 ist noch einfach nicht fehlerfrei. Das ist neue Software aber selten. Wenn man diese nicht haben will, sollte man MINDESTENS ein halbes Jahr warten, bevor man ein neues Betriebssystem installiert.
Da der Thread als "gelöst" gekennzeichnet ist, würde mich mal die Lösung interessieren.
Da der Thread als "gelöst" gekennzeichnet ist, würde mich mal die Lösung interessieren. ![]() |
Ich habe ihn bestimmt nicht als "gelöst" gekennzeichnet. War vielleicht der Poltergeist, der meinen Rechner startet und nicht mehr herunterfahren lässt.
