|
Plagegeister aller Art und deren Bekämpfung: Teamspeak und andere Prozesse geben aufeinmal keine RückmeldungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.01.2014, 18:00 | #1 |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Schönen Guten Tag Seit fast 2 wochen habe ich ein Problem undzwar kommt sehr oft wenn ich z.b ts3 öffne und da auf verbinden gehe und dan auf okey die meldung "Keine Rückmeldung" Teamspeak reagiert nicht mehr aber nicht nur das sondern wenn ich in der such zeile von Windows 8 sound eingeben um die soundsysteme umzuschalten öffnet sich einfach mal garnichts und ob und zu öffnet sich dann der prozess als hätte der Laptop seinen eigenen Kopf und macht nur etwas wenn er lust dazu hat, und Kaspersky internetsecurity finden garnichts. Ich habe es auch schon 2 mal mit einer System wiederhestellung probiert dan ging es auch einmal wieder aber sobald ich dan Teamspeak wieder schlisse geht wieder garnichtsmehr. bitte um hilfe. Hadwear: HP Pavillion Dev 7 8GB Ram 500Gb Festplatte Software: Windows 8 |
31.01.2014, 22:13 | #2 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
31.01.2014, 22:35 | #3 |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung FRST Additions Logfile:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01 Ran by araton7811 at 2014-01-31 22:17:14 Running from C:\Users\araton7811\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.3.2.30416 - BitTorrent Inc.) 4Story DE 4.0.167 (x32 Version: - ) Ask Toolbar (x32 Version: 1.15.15.0 - Ask.com) <==== ATTENTION Ask Toolbar Updater (HKCU Version: 1.2.4.36191 - Ask.com) <==== ATTENTION Audacity 2.0.3 (x32 Version: 2.0.3 - Audacity Team) Battlefield Play4Free (x32 Version: - EA Digital illusions) Camtasia Studio 8 (x32 Version: 8.0.4.1060 - TechSmith Corporation) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) Elsword_DE (x32 Version: - ) FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse) Fraps (remove only) (x32 Version: - ) Free Realms (HKCU Version: - Sony Online Entertainment) Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0 - Gameforge) GameSpy Arcade (x32 Version: - ) GIMP 2.8.6 (Version: 2.8.6 - The GIMP Team) Google Chrome (x32 Version: 32.0.1700.102 - Google Inc.) Google Drive (x32 Version: 1.13.5782.599 - Google, Inc.) Google Talk Plugin (x32 Version: 4.9.1.16010 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Intel(R) Processor Graphics (x32 Version: 9.17.10.2932 - Intel Corporation) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java SE Development Kit 7 Update 45 (64-bit) (Version: 1.7.0.450 - Oracle) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.50 (Version: 8.50.281 - Logitech Inc.) ManiaPlanet (x32 Version: - Nadeo) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Notepad++ (x32 Version: 6.3 - ) NVIDIA Grafiktreiber 327.02 (Version: 327.02 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.14.17 (Version: 1.14.17 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden NVIDIA Update 1.14.17 (Version: 1.14.17 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.14.17 - NVIDIA Corporation) Hidden Origin (x32 Version: 9.1.15.109 - Electronic Arts, Inc.) Overwolf (x32 Version: 0.47.284 - Overwolf) PhotoScape (x32 Version: - ) Security Task Manager 1.8g (x32 Version: 1.8g - Neuber Software) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Spotify (HKCU Version: 0.9.6.72.ge389c074 - Spotify AB) Synaptics Pointing Device Driver (Version: 16.2.10.12 - Synaptics Incorporated) TapinRadio 1.58.2 (x32 Version: - Raimersoft) TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH) TeamViewer 8 (x32 Version: 8.0.22298 - TeamViewer) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft) Virtual Audio Cable 4.10 (Version: - ) Winamp (x32 Version: 5.666 - Nullsoft, Inc) WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) ==================== Restore Points ========================= 16-01-2014 20:40:49 Windows Update 21-01-2014 13:24:17 Windows Update 23-01-2014 17:35:45 Wiederherstellungsvorgang 30-01-2014 17:58:48 Geplanter Prüfpunkt 31-01-2014 12:09:20 Wiederherstellungsvorgang ==================== Hosts content: ========================== 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {14702AD0-4C17-4CF7-9770-F55C16D58567} - System32\Tasks\Microsoft\Windows\RestartManager\{FFC24748-2FAB-4df9-98EE-D93A11AC5519} => C:\WINDOWS\system32\rmclient.exe [2013-08-22] (Microsoft Corporation) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {8102FC99-D53D-4B62-99C0-86E75F20E5B8} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-02-08] () Task: {86ECBD2B-54DC-4248-B0D7-9D192F536164} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <==== ATTENTION Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C1D0B11-CE00-4458-A050-4A30CE16F056} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA => C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-18] (Google Inc.) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9895EDB7-AA41-4EAF-A133-2CF29B218E32} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-01-24] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {C8F43592-D9C7-496A-BE5A-80ADDB16D13E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06] (Google Inc.) Task: {CAA2B29E-2F39-4C2A-AB3D-16244489E496} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core => C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-18] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {FAB217A0-C175-40F7-9AF5-DB6216FD13F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06] (Google Inc.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core.job => C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA.job => C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-10-23 13:15 - 2013-10-23 13:15 - 00302056 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2013-10-23 13:15 - 2013-10-23 13:15 - 00320488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2013-10-23 13:15 - 2013-10-23 13:15 - 00565224 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-10-23 13:15 - 2013-10-23 13:15 - 00700904 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-01-29 15:29 - 2014-01-23 06:56 - 00715544 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libglesv2.dll 2014-01-29 15:29 - 2014-01-23 06:56 - 00100120 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libegl.dll 2014-01-29 15:29 - 2014-01-23 06:56 - 04055320 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll 2014-01-29 15:29 - 2014-01-23 06:57 - 00399640 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll 2014-01-29 15:29 - 2014-01-23 06:55 - 01634584 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ffmpegsumo.dll 2014-01-29 15:29 - 2014-01-23 06:56 - 13615896 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\araton7811\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: PCI-Gerät Description: PCI-Gerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Could not start eventlog service, could not read events. Der angeforderte Dienst wurde bereits gestartet. Sie erhalten weitere Hilfe, wenn Sie NET HELPMSG 2182 eingeben. ==================== Memory info =========================== Percentage of memory in use: 27% Total physical RAM: 8091.3 MB Available physical RAM: 5840.36 MB Total Pagefile: 26523.3 MB Available Pagefile: 24047.58 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:573.82 GB) (Free:463.22 GB) NTFS Drive d: (Recovery) (Fixed) (Total:22.06 GB) (Free:2.29 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 12E059A3) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=574 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=22 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ |
01.02.2014, 17:33 | #4 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung FRST.txt fehlt noch
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.02.2014, 13:32 | #5 |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Ich muss eventuell noch hinzufügen das ich nicht der einzige bin der diesen Laptop benutzt und Zugriff hat. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by araton7811 (administrator) on ARATON7811-HP on 31-01-2014 22:16:05 Running from C:\Users\araton7811\Downloads Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16422_x64__8wekyb3d8bbwe\glcnd.exe (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe (Beepa P/L) C:\Fraps\fraps.exe (Beepa P/L) C:\Fraps\fraps64.dat (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-28] (Synaptics Incorporated) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [4StoryPrePatch] - C:\Program Files (x86)\GameforgeLive\Games\DEU_deu\4Story\PrePatch.exe [327680 2012-11-29] (Zemi Interactive Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3549528 2013-08-06] (Electronic Arts) HKCU\...\Run: [Spotify] - C:\Users\araton7811\AppData\Roaming\Spotify\Spotify.exe [5955072 2013-11-15] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\araton7811\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-11-15] (Spotify Ltd) HKCU\...\Run: [BackgroundContainer] - C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [319264 2013-10-15] (Conduit Ltd.) <===== ATTENTION HKCU\...\Run: [uTorrent] - C:\Users\araton7811\AppData\Roaming\uTorrent\uTorrent.exe [1142864 2014-01-15] (BitTorrent Inc.) HKCU\...\Run: [Google Update] - C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-18] (Google Inc.) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) MountPoints2: {f78d13f2-63f6-11e3-be91-e006e6e1512d} - "G:\autorun.exe" AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation) Startup: C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7AD0BBD2E10BCF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE URLSearchHook: HKLM-x32 - Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll No File URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM-x32 - DefaultScope {A9469375-475B-4ADA-AEEC-A9EB68088CA2} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{C50C1A80-FF31-4E37-9D84-8A66DC6BD5B7}: [NameServer]79.141.167.14,79.141.160.23 Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll () CHR Plugin: (Downloader Detector) - C:\Program Files (x86)\Downloader\npdd.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File CHR Plugin: (SOE Web Installer) - C:\Users\araton7811\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\npsoe.dll () CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-06] CHR Extension: (Google Drive) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-06] CHR Extension: (YouTube) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-06] CHR Extension: (Google-Suche) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-06] CHR Extension: (Google Wallet) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08] CHR Extension: (Google Mail) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-06] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) S2 valWBFPolicyService; %SystemRoot%\system32\valWBFPolicyService.exe [x] ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 AX88179; C:\Windows\system32\DRIVERS\ax88179_178a.sys [72192 2013-12-04] (ASIX Electronics Corp.) R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation) R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) R0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-03] (Microsoft Corporation) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-09-17] (Anchorfree Inc.) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-31 22:16 - 2014-01-31 22:16 - 00011955 _____ C:\Users\araton7811\Downloads\FRST.txt 2014-01-31 22:15 - 2014-01-31 22:16 - 00000000 ____D C:\FRST 2014-01-31 22:15 - 2014-01-31 22:15 - 02079744 _____ (Farbar) C:\Users\araton7811\Downloads\FRST64.exe 2014-01-31 21:33 - 2014-01-31 21:33 - 00044745 _____ C:\Users\araton7811\Desktop\ad.aup 2014-01-31 21:33 - 2014-01-31 21:33 - 00000000 ____D C:\Users\araton7811\Desktop\ad_data 2014-01-31 21:31 - 2014-01-31 21:32 - 146994164 _____ C:\Users\araton7811\Desktop\griefen.wav 2014-01-31 17:36 - 2014-01-31 17:44 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-31 17:36 - 2014-01-31 17:36 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-31 17:27 - 2014-01-31 17:27 - 00001987 _____ C:\Users\Public\Desktop\Overwolf.lnk 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Program Files (x86)\Overwolf 2014-01-31 17:26 - 2014-01-31 21:30 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\TS3Client 2014-01-31 17:25 - 2014-01-31 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-01-31 17:25 - 2014-01-31 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2014-01-31 12:36 - 2014-01-31 13:16 - 00000000 ____D C:\Program Files\Sandboxie 2014-01-30 20:32 - 2014-01-30 20:32 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2014-01-30 17:07 - 2014-01-30 17:07 - 00172971 _____ C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2 (1).zip 2014-01-30 15:09 - 2014-01-30 17:57 - 00002032 _____ C:\Users\araton7811\Desktop\PwDbDE-2.db 2014-01-30 15:05 - 2014-01-30 15:05 - 03096576 _____ (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe 2014-01-29 21:25 - 2014-01-29 21:25 - 00000000 ____D C:\Users\araton7811\Documents\OneNote-Notizbücher 2014-01-29 19:28 - 2014-01-29 19:28 - 1112106018 _____ C:\Users\araton7811\Desktop\araton7811 Feat. Nick.mp4 2014-01-25 18:04 - 2014-01-25 18:04 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Mozilla 2014-01-18 21:53 - 2014-01-31 22:04 - 00001168 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA.job 2014-01-18 21:53 - 2014-01-31 22:04 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core.job 2014-01-18 21:53 - 2014-01-18 21:59 - 00004124 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA 2014-01-18 21:53 - 2014-01-18 21:59 - 00003744 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core 2014-01-17 23:28 - 2014-01-17 23:28 - 01561040 _____ C:\Users\araton7811\ts3_recording_14_01_17_23_28_1.wav 2014-01-16 19:28 - 2014-01-23 18:39 - 00000000 ____D C:\Users\araton7811\TapinRadio 2014-01-16 19:28 - 2014-01-16 19:28 - 00001047 _____ C:\Users\araton7811\Desktop\TapinRadio.lnk 2014-01-16 19:27 - 2014-01-23 18:44 - 00000000 ____D C:\Program Files (x86)\TapinRadio 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\Users\araton7811\AppData\Local\Mozilla 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-15 18:56 - 2014-01-15 19:47 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\iSafe 2014-01-15 18:56 - 2014-01-15 18:56 - 00000907 _____ C:\Users\araton7811\Desktop\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000887 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000000 ____D C:\WINDOWS\system32\log 2014-01-15 18:55 - 2014-01-23 18:44 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\uTorrent 2014-01-15 14:44 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2014-01-15 14:44 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2014-01-15 14:44 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe 2014-01-15 14:44 - 2013-11-27 11:34 - 00138240 _____ C:\WINDOWS\system32\OEMLicense.dll 2014-01-15 14:44 - 2013-11-27 10:54 - 00103936 _____ C:\WINDOWS\SysWOW64\OEMLicense.dll 2014-01-15 14:44 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 14:44 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll 2014-01-15 14:44 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 14:44 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll 2014-01-15 14:44 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-01-15 14:44 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-01-13 14:57 - 2014-01-13 17:10 - 00000000 ____D C:\Program Files (x86)\Skype 2014-01-13 14:57 - 2014-01-13 17:09 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Skype 2014-01-13 14:56 - 2014-01-13 16:30 - 00000000 ____D C:\ProgramData\Skype 2014-01-13 14:05 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Local\Overwolf 2014-01-12 16:53 - 2014-01-13 16:26 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-12 16:53 - 2014-01-12 16:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2014-01-11 17:53 - 2014-01-17 17:52 - 00052736 ___SH C:\Users\araton7811\Documents\Thumbs.db 2014-01-10 13:12 - 2014-01-26 15:22 - 00018432 ___SH C:\Users\araton7811\Downloads\Thumbs.db 2014-01-10 12:58 - 2010-02-15 23:07 - 00031912 _____ (Eugene V. Muzychenko) C:\Users\araton7811\Desktop\vcctlpan.exe 2014-01-10 12:50 - 2014-01-10 12:51 - 00000000 ____D C:\Program Files\Virtual Audio Cable 2014-01-10 12:50 - 2014-01-10 12:50 - 00066728 _____ (Eugene V. Muzychenko) C:\WINDOWS\system32\Drivers\vrtaucbl.sys 2014-01-10 12:17 - 2014-01-23 18:44 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Winamp 2014-01-10 12:17 - 2014-01-10 12:18 - 00000000 ____D C:\Program Files (x86)\Winamp 2014-01-10 12:17 - 2014-01-10 12:17 - 00000995 _____ C:\Users\Public\Desktop\Winamp.lnk 2014-01-06 05:39 - 2014-01-06 05:39 - 00000482 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery (D).lnk ==================== One Month Modified Files and Folders ======= 2014-01-31 22:16 - 2014-01-31 22:16 - 00011955 _____ C:\Users\araton7811\Downloads\FRST.txt 2014-01-31 22:16 - 2014-01-31 22:15 - 00000000 ____D C:\FRST 2014-01-31 22:15 - 2014-01-31 22:15 - 02079744 _____ (Farbar) C:\Users\araton7811\Downloads\FRST64.exe 2014-01-31 22:04 - 2014-01-18 21:53 - 00001168 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA.job 2014-01-31 22:04 - 2014-01-18 21:53 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core.job 2014-01-31 22:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2014-01-31 21:34 - 2013-08-28 20:38 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\.minecraft 2014-01-31 21:33 - 2014-01-31 21:33 - 00044745 _____ C:\Users\araton7811\Desktop\ad.aup 2014-01-31 21:33 - 2014-01-31 21:33 - 00000000 ____D C:\Users\araton7811\Desktop\ad_data 2014-01-31 21:33 - 2013-08-30 22:14 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Audacity 2014-01-31 21:32 - 2014-01-31 21:31 - 146994164 _____ C:\Users\araton7811\Desktop\griefen.wav 2014-01-31 21:32 - 2013-12-03 17:32 - 01959779 _____ C:\WINDOWS\WindowsUpdate.log 2014-01-31 21:30 - 2014-01-31 17:26 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\TS3Client 2014-01-31 21:27 - 2013-04-06 13:50 - 00001146 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-31 18:09 - 2013-02-17 13:50 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1223374180-3426500295-1664088304-1001 2014-01-31 17:51 - 2013-08-30 18:08 - 00000000 ____D C:\Users\araton7811\Desktop\Alles 2014-01-31 17:47 - 2013-12-05 16:30 - 00003970 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{99E42AA7-BC62-4085-83F8-322BFA951D46} 2014-01-31 17:44 - 2014-01-31 17:36 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-31 17:42 - 2013-11-17 13:37 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-31 17:40 - 2013-04-06 13:50 - 00000000 ____D C:\Users\araton7811\AppData\Local\Google 2014-01-31 17:40 - 2013-04-06 13:50 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-31 17:38 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-31 17:36 - 2014-01-31 17:36 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-31 17:27 - 2014-01-31 17:27 - 00001987 _____ C:\Users\Public\Desktop\Overwolf.lnk 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Program Files (x86)\Overwolf 2014-01-31 17:27 - 2014-01-13 14:05 - 00000000 ____D C:\Users\araton7811\AppData\Local\Overwolf 2014-01-31 17:25 - 2014-01-31 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-01-31 17:25 - 2014-01-31 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2014-01-31 17:16 - 2013-12-03 17:47 - 00000000 __RDO C:\Users\araton7811\SkyDrive 2014-01-31 17:16 - 2013-09-08 21:00 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-31 17:16 - 2013-04-06 13:50 - 00001142 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-31 14:29 - 2013-12-09 15:23 - 00103936 ___SH C:\Users\araton7811\Desktop\Thumbs.db 2014-01-31 14:28 - 2013-12-03 17:15 - 00000000 ____D C:\Users\araton7811 2014-01-31 13:21 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2014-01-31 13:21 - 2013-09-30 04:56 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat 2014-01-31 13:21 - 2013-09-30 04:56 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat 2014-01-31 13:17 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2014-01-31 13:16 - 2014-01-31 12:36 - 00000000 ____D C:\Program Files\Sandboxie 2014-01-31 13:16 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-31 13:11 - 2013-09-04 15:48 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-31 13:11 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration 2014-01-30 20:32 - 2014-01-30 20:32 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2014-01-30 17:57 - 2014-01-30 15:09 - 00002032 _____ C:\Users\araton7811\Desktop\PwDbDE-2.db 2014-01-30 17:07 - 2014-01-30 17:07 - 00172971 _____ C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2 (1).zip 2014-01-30 16:07 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2014-01-30 15:05 - 2014-01-30 15:05 - 03096576 _____ (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe 2014-01-29 21:25 - 2014-01-29 21:25 - 00000000 ____D C:\Users\araton7811\Documents\OneNote-Notizbücher 2014-01-29 21:25 - 2013-02-17 13:41 - 00000000 ___RD C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-29 19:57 - 2013-11-24 14:32 - 00000000 ____D C:\Users\araton7811\.gimp-2.8 2014-01-29 19:28 - 2014-01-29 19:28 - 1112106018 _____ C:\Users\araton7811\Desktop\araton7811 Feat. Nick.mp4 2014-01-29 19:10 - 2013-06-11 18:49 - 00000000 ____D C:\Users\araton7811\Documents\Camtasia Studio 2014-01-26 16:17 - 2013-03-02 15:07 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\FileZilla 2014-01-26 15:22 - 2014-01-10 13:12 - 00018432 ___SH C:\Users\araton7811\Downloads\Thumbs.db 2014-01-25 18:04 - 2014-01-25 18:04 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Mozilla 2014-01-24 13:55 - 2013-08-19 12:34 - 00000000 ____D C:\WINDOWS\system32\MRT 2014-01-24 13:54 - 2013-02-18 19:58 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-01-24 12:42 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2014-01-23 18:45 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2014-01-23 18:44 - 2014-01-16 19:27 - 00000000 ____D C:\Program Files (x86)\TapinRadio 2014-01-23 18:44 - 2014-01-15 18:55 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\uTorrent 2014-01-23 18:44 - 2014-01-10 12:17 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Winamp 2014-01-23 18:39 - 2014-01-16 19:28 - 00000000 ____D C:\Users\araton7811\TapinRadio 2014-01-23 17:21 - 2013-09-29 20:04 - 00065208 _____ C:\WINDOWS\PFRO.log 2014-01-21 20:40 - 2013-05-29 23:49 - 00000000 ____D C:\Users\araton7811\AppData\Local\Spotify 2014-01-19 08:38 - 2013-02-18 19:52 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2014-01-18 21:59 - 2014-01-18 21:53 - 00004124 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA 2014-01-18 21:59 - 2014-01-18 21:53 - 00003744 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core 2014-01-17 23:28 - 2014-01-17 23:28 - 01561040 _____ C:\Users\araton7811\ts3_recording_14_01_17_23_28_1.wav 2014-01-17 17:52 - 2014-01-11 17:53 - 00052736 ___SH C:\Users\araton7811\Documents\Thumbs.db 2014-01-16 19:28 - 2014-01-16 19:28 - 00001047 _____ C:\Users\araton7811\Desktop\TapinRadio.lnk 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\Users\araton7811\AppData\Local\Mozilla 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-15 19:47 - 2014-01-15 18:56 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\iSafe 2014-01-15 18:56 - 2014-01-15 18:56 - 00000907 _____ C:\Users\araton7811\Desktop\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000887 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000000 ____D C:\WINDOWS\system32\log 2014-01-13 17:14 - 2013-08-22 15:46 - 00351627 _____ C:\WINDOWS\setupact.log 2014-01-13 17:10 - 2014-01-13 14:57 - 00000000 ____D C:\Program Files (x86)\Skype 2014-01-13 17:09 - 2014-01-13 14:57 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Skype 2014-01-13 17:09 - 2012-07-26 09:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2014-01-13 17:04 - 2012-11-19 19:29 - 00000000 ____D C:\Users\araton7811\AppData\Local\Packages 2014-01-13 17:03 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files\Java 2014-01-13 16:30 - 2014-01-13 14:56 - 00000000 ____D C:\ProgramData\Skype 2014-01-13 16:26 - 2014-01-12 16:53 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-12 16:54 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2014-01-12 16:53 - 2014-01-12 16:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2014-01-10 12:51 - 2014-01-10 12:50 - 00000000 ____D C:\Program Files\Virtual Audio Cable 2014-01-10 12:50 - 2014-01-10 12:50 - 00066728 _____ (Eugene V. Muzychenko) C:\WINDOWS\system32\Drivers\vrtaucbl.sys 2014-01-10 12:18 - 2014-01-10 12:17 - 00000000 ____D C:\Program Files (x86)\Winamp 2014-01-10 12:17 - 2014-01-10 12:17 - 00000995 _____ C:\Users\Public\Desktop\Winamp.lnk 2014-01-06 23:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-01-06 23:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-06 05:39 - 2014-01-06 05:39 - 00000482 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery (D).lnk Files to move or delete: ==================== C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll Some content of TEMP: ==================== C:\Users\araton7811\AppData\Local\Temp\20140130151202.874.exe C:\Users\araton7811\AppData\Local\Temp\ICReinstall_20140130151202.874.exe C:\Users\araton7811\AppData\Local\Temp\nsc765.exe C:\Users\araton7811\AppData\Local\Temp\nsl7505.exe C:\Users\araton7811\AppData\Local\Temp\nsnDADB.exe C:\Users\araton7811\AppData\Local\Temp\nsp10B.exe C:\Users\araton7811\AppData\Local\Temp\nss7AF1.exe C:\Users\araton7811\AppData\Local\Temp\Show-Password_1030-8102.exe C:\Users\araton7811\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\araton7811\AppData\Local\Temp\utt3AFC.tmp.exe C:\Users\araton7811\AppData\Local\Temp\yac_3.8.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-31 13:28 ==================== End Of Log ============================ |
03.02.2014, 10:55 | #6 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Irgendwer hat da ganz schön die Sau gemacht mit dem Teil Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung |
03.02.2014, 21:40 | #7 | ||
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Hier mal das erste: Zitat:
hatte nur keine zeit mehr AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 03/02/2014 um 21:17:29 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 8.1 Pro (64 bits) # Benutzername : araton7811 - ARATON7811-HP # Gestartet von : C:\Users\araton7811\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Conduit Ordner Gelöscht : C:\Program Files (x86)\Ask.com Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\Hotspot_Shield Ordner Gelöscht : C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} Ordner Gelöscht : C:\Users\araton7811\AppData\Local\apn Ordner Gelöscht : C:\Users\araton7811\AppData\Local\Conduit Ordner Gelöscht : C:\Users\araton7811\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\araton7811\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\araton7811\AppData\LocalLow\Hotspot_Shield Ordner Gelöscht : C:\Users\araton7811\AppData\Roaming\OpenCandy Datei Gelöscht : C:\WINDOWS\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT1561552 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Wert Gelöscht : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1] Schlüssel Gelöscht : HKCU\Software\anchorfree Schlüssel Gelöscht : HKCU\Software\APN Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\smartbar Schlüssel Gelöscht : HKLM\Software\APN Schlüssel Gelöscht : HKLM\Software\AskToolbar Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16384 -\\ Google Chrome v32.0.1700.102 [ Datei : C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5512 octets] - [03/02/2014 21:16:50] AdwCleaner[S0].txt - [5194 octets] - [03/02/2014 21:17:29] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5254 octets] ########## Zitat:
Geändert von araton7811 (03.02.2014 um 21:32 Uhr) |
04.02.2014, 17:09 | #8 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine RückmeldungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.02.2014, 19:43 | #9 | |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Ich bin mir nicht sicher ob es das ist aber Okey ^^ Zitat:
|
06.02.2014, 14:28 | #10 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung jap, und weiter
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.02.2014, 16:35 | #11 |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by araton7811 (administrator) on ARATON7811-HP on 31-01-2014 22:16:05 Running from C:\Users\araton7811\Downloads Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16422_x64__8wekyb3d8bbwe\glcnd.exe (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe (Beepa P/L) C:\Fraps\fraps.exe (Beepa P/L) C:\Fraps\fraps64.dat (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-28] (Synaptics Incorporated) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [4StoryPrePatch] - C:\Program Files (x86)\GameforgeLive\Games\DEU_deu\4Story\PrePatch.exe [327680 2012-11-29] (Zemi Interactive Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3549528 2013-08-06] (Electronic Arts) HKCU\...\Run: [Spotify] - C:\Users\araton7811\AppData\Roaming\Spotify\Spotify.exe [5955072 2013-11-15] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\araton7811\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-11-15] (Spotify Ltd) HKCU\...\Run: [BackgroundContainer] - C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [319264 2013-10-15] (Conduit Ltd.) <===== ATTENTION HKCU\...\Run: [uTorrent] - C:\Users\araton7811\AppData\Roaming\uTorrent\uTorrent.exe [1142864 2014-01-15] (BitTorrent Inc.) HKCU\...\Run: [Google Update] - C:\Users\araton7811\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-18] (Google Inc.) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) MountPoints2: {f78d13f2-63f6-11e3-be91-e006e6e1512d} - "G:\autorun.exe" AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation) Startup: C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7AD0BBD2E10BCF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE URLSearchHook: HKLM-x32 - Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll No File URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM-x32 - DefaultScope {A9469375-475B-4ADA-AEEC-A9EB68088CA2} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{C50C1A80-FF31-4E37-9D84-8A66DC6BD5B7}: [NameServer]79.141.167.14,79.141.160.23 Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll () CHR Plugin: (Downloader Detector) - C:\Program Files (x86)\Downloader\npdd.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File CHR Plugin: (SOE Web Installer) - C:\Users\araton7811\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\npsoe.dll () CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-06] CHR Extension: (Google Drive) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-06] CHR Extension: (YouTube) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-06] CHR Extension: (Google-Suche) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-06] CHR Extension: (Google Wallet) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08] CHR Extension: (Google Mail) - C:\Users\araton7811\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-06] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) S2 valWBFPolicyService; %SystemRoot%\system32\valWBFPolicyService.exe [x] ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 AX88179; C:\Windows\system32\DRIVERS\ax88179_178a.sys [72192 2013-12-04] (ASIX Electronics Corp.) R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation) R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) R0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-03] (Microsoft Corporation) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-09-17] (Anchorfree Inc.) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-31 22:16 - 2014-01-31 22:16 - 00011955 _____ C:\Users\araton7811\Downloads\FRST.txt 2014-01-31 22:15 - 2014-01-31 22:16 - 00000000 ____D C:\FRST 2014-01-31 22:15 - 2014-01-31 22:15 - 02079744 _____ (Farbar) C:\Users\araton7811\Downloads\FRST64.exe 2014-01-31 21:33 - 2014-01-31 21:33 - 00044745 _____ C:\Users\araton7811\Desktop\ad.aup 2014-01-31 21:33 - 2014-01-31 21:33 - 00000000 ____D C:\Users\araton7811\Desktop\ad_data 2014-01-31 21:31 - 2014-01-31 21:32 - 146994164 _____ C:\Users\araton7811\Desktop\griefen.wav 2014-01-31 17:36 - 2014-01-31 17:44 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-31 17:36 - 2014-01-31 17:36 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-31 17:27 - 2014-01-31 17:27 - 00001987 _____ C:\Users\Public\Desktop\Overwolf.lnk 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Program Files (x86)\Overwolf 2014-01-31 17:26 - 2014-01-31 21:30 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\TS3Client 2014-01-31 17:25 - 2014-01-31 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-01-31 17:25 - 2014-01-31 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2014-01-31 12:36 - 2014-01-31 13:16 - 00000000 ____D C:\Program Files\Sandboxie 2014-01-30 20:32 - 2014-01-30 20:32 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2014-01-30 17:07 - 2014-01-30 17:07 - 00172971 _____ C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2 (1).zip 2014-01-30 15:09 - 2014-01-30 17:57 - 00002032 _____ C:\Users\araton7811\Desktop\PwDbDE-2.db 2014-01-30 15:05 - 2014-01-30 15:05 - 03096576 _____ (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe 2014-01-29 21:25 - 2014-01-29 21:25 - 00000000 ____D C:\Users\araton7811\Documents\OneNote-Notizbücher 2014-01-29 19:28 - 2014-01-29 19:28 - 1112106018 _____ C:\Users\araton7811\Desktop\araton7811 Feat. Nick.mp4 2014-01-25 18:04 - 2014-01-25 18:04 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Mozilla 2014-01-18 21:53 - 2014-01-31 22:04 - 00001168 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA.job 2014-01-18 21:53 - 2014-01-31 22:04 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core.job 2014-01-18 21:53 - 2014-01-18 21:59 - 00004124 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA 2014-01-18 21:53 - 2014-01-18 21:59 - 00003744 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core 2014-01-17 23:28 - 2014-01-17 23:28 - 01561040 _____ C:\Users\araton7811\ts3_recording_14_01_17_23_28_1.wav 2014-01-16 19:28 - 2014-01-23 18:39 - 00000000 ____D C:\Users\araton7811\TapinRadio 2014-01-16 19:28 - 2014-01-16 19:28 - 00001047 _____ C:\Users\araton7811\Desktop\TapinRadio.lnk 2014-01-16 19:27 - 2014-01-23 18:44 - 00000000 ____D C:\Program Files (x86)\TapinRadio 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\Users\araton7811\AppData\Local\Mozilla 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-15 18:56 - 2014-01-15 19:47 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\iSafe 2014-01-15 18:56 - 2014-01-15 18:56 - 00000907 _____ C:\Users\araton7811\Desktop\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000887 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000000 ____D C:\WINDOWS\system32\log 2014-01-15 18:55 - 2014-01-23 18:44 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\uTorrent 2014-01-15 14:44 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2014-01-15 14:44 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll 2014-01-15 14:44 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe 2014-01-15 14:44 - 2013-11-27 11:34 - 00138240 _____ C:\WINDOWS\system32\OEMLicense.dll 2014-01-15 14:44 - 2013-11-27 10:54 - 00103936 _____ C:\WINDOWS\SysWOW64\OEMLicense.dll 2014-01-15 14:44 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 14:44 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll 2014-01-15 14:44 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 14:44 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll 2014-01-15 14:44 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-01-15 14:44 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-01-13 14:57 - 2014-01-13 17:10 - 00000000 ____D C:\Program Files (x86)\Skype 2014-01-13 14:57 - 2014-01-13 17:09 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Skype 2014-01-13 14:56 - 2014-01-13 16:30 - 00000000 ____D C:\ProgramData\Skype 2014-01-13 14:05 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Local\Overwolf 2014-01-12 16:53 - 2014-01-13 16:26 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-12 16:53 - 2014-01-12 16:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2014-01-11 17:53 - 2014-01-17 17:52 - 00052736 ___SH C:\Users\araton7811\Documents\Thumbs.db 2014-01-10 13:12 - 2014-01-26 15:22 - 00018432 ___SH C:\Users\araton7811\Downloads\Thumbs.db 2014-01-10 12:58 - 2010-02-15 23:07 - 00031912 _____ (Eugene V. Muzychenko) C:\Users\araton7811\Desktop\vcctlpan.exe 2014-01-10 12:50 - 2014-01-10 12:51 - 00000000 ____D C:\Program Files\Virtual Audio Cable 2014-01-10 12:50 - 2014-01-10 12:50 - 00066728 _____ (Eugene V. Muzychenko) C:\WINDOWS\system32\Drivers\vrtaucbl.sys 2014-01-10 12:17 - 2014-01-23 18:44 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Winamp 2014-01-10 12:17 - 2014-01-10 12:18 - 00000000 ____D C:\Program Files (x86)\Winamp 2014-01-10 12:17 - 2014-01-10 12:17 - 00000995 _____ C:\Users\Public\Desktop\Winamp.lnk 2014-01-06 05:39 - 2014-01-06 05:39 - 00000482 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery (D).lnk ==================== One Month Modified Files and Folders ======= 2014-01-31 22:16 - 2014-01-31 22:16 - 00011955 _____ C:\Users\araton7811\Downloads\FRST.txt 2014-01-31 22:16 - 2014-01-31 22:15 - 00000000 ____D C:\FRST 2014-01-31 22:15 - 2014-01-31 22:15 - 02079744 _____ (Farbar) C:\Users\araton7811\Downloads\FRST64.exe 2014-01-31 22:04 - 2014-01-18 21:53 - 00001168 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA.job 2014-01-31 22:04 - 2014-01-18 21:53 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core.job 2014-01-31 22:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2014-01-31 21:34 - 2013-08-28 20:38 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\.minecraft 2014-01-31 21:33 - 2014-01-31 21:33 - 00044745 _____ C:\Users\araton7811\Desktop\ad.aup 2014-01-31 21:33 - 2014-01-31 21:33 - 00000000 ____D C:\Users\araton7811\Desktop\ad_data 2014-01-31 21:33 - 2013-08-30 22:14 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Audacity 2014-01-31 21:32 - 2014-01-31 21:31 - 146994164 _____ C:\Users\araton7811\Desktop\griefen.wav 2014-01-31 21:32 - 2013-12-03 17:32 - 01959779 _____ C:\WINDOWS\WindowsUpdate.log 2014-01-31 21:30 - 2014-01-31 17:26 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\TS3Client 2014-01-31 21:27 - 2013-04-06 13:50 - 00001146 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-31 18:09 - 2013-02-17 13:50 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1223374180-3426500295-1664088304-1001 2014-01-31 17:51 - 2013-08-30 18:08 - 00000000 ____D C:\Users\araton7811\Desktop\Alles 2014-01-31 17:47 - 2013-12-05 16:30 - 00003970 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{99E42AA7-BC62-4085-83F8-322BFA951D46} 2014-01-31 17:44 - 2014-01-31 17:36 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-31 17:42 - 2013-11-17 13:37 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-31 17:40 - 2013-04-06 13:50 - 00000000 ____D C:\Users\araton7811\AppData\Local\Google 2014-01-31 17:40 - 2013-04-06 13:50 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-31 17:38 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-31 17:36 - 2014-01-31 17:36 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-31 17:27 - 2014-01-31 17:27 - 00001987 _____ C:\Users\Public\Desktop\Overwolf.lnk 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2014-01-31 17:27 - 2014-01-31 17:27 - 00000000 ____D C:\Program Files (x86)\Overwolf 2014-01-31 17:27 - 2014-01-13 14:05 - 00000000 ____D C:\Users\araton7811\AppData\Local\Overwolf 2014-01-31 17:25 - 2014-01-31 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-01-31 17:25 - 2014-01-31 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2014-01-31 17:16 - 2013-12-03 17:47 - 00000000 __RDO C:\Users\araton7811\SkyDrive 2014-01-31 17:16 - 2013-09-08 21:00 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-31 17:16 - 2013-04-06 13:50 - 00001142 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-31 14:29 - 2013-12-09 15:23 - 00103936 ___SH C:\Users\araton7811\Desktop\Thumbs.db 2014-01-31 14:28 - 2013-12-03 17:15 - 00000000 ____D C:\Users\araton7811 2014-01-31 13:21 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2014-01-31 13:21 - 2013-09-30 04:56 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat 2014-01-31 13:21 - 2013-09-30 04:56 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat 2014-01-31 13:17 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2014-01-31 13:16 - 2014-01-31 12:36 - 00000000 ____D C:\Program Files\Sandboxie 2014-01-31 13:16 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-31 13:11 - 2013-09-04 15:48 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-31 13:11 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration 2014-01-30 20:32 - 2014-01-30 20:32 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2014-01-30 17:57 - 2014-01-30 15:09 - 00002032 _____ C:\Users\araton7811\Desktop\PwDbDE-2.db 2014-01-30 17:07 - 2014-01-30 17:07 - 00172971 _____ C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2 (1).zip 2014-01-30 16:07 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2014-01-30 15:05 - 2014-01-30 15:05 - 03096576 _____ (QueryGriefer) C:\Users\araton7811\Desktop\AuthmePasswordCrackerV2.exe 2014-01-29 21:25 - 2014-01-29 21:25 - 00000000 ____D C:\Users\araton7811\Documents\OneNote-Notizbücher 2014-01-29 21:25 - 2013-02-17 13:41 - 00000000 ___RD C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-29 19:57 - 2013-11-24 14:32 - 00000000 ____D C:\Users\araton7811\.gimp-2.8 2014-01-29 19:28 - 2014-01-29 19:28 - 1112106018 _____ C:\Users\araton7811\Desktop\araton7811 Feat. Nick.mp4 2014-01-29 19:10 - 2013-06-11 18:49 - 00000000 ____D C:\Users\araton7811\Documents\Camtasia Studio 2014-01-26 16:17 - 2013-03-02 15:07 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\FileZilla 2014-01-26 15:22 - 2014-01-10 13:12 - 00018432 ___SH C:\Users\araton7811\Downloads\Thumbs.db 2014-01-25 18:04 - 2014-01-25 18:04 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Mozilla 2014-01-24 13:55 - 2013-08-19 12:34 - 00000000 ____D C:\WINDOWS\system32\MRT 2014-01-24 13:54 - 2013-02-18 19:58 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-01-24 12:42 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2014-01-23 18:45 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2014-01-23 18:44 - 2014-01-16 19:27 - 00000000 ____D C:\Program Files (x86)\TapinRadio 2014-01-23 18:44 - 2014-01-15 18:55 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\uTorrent 2014-01-23 18:44 - 2014-01-10 12:17 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Winamp 2014-01-23 18:39 - 2014-01-16 19:28 - 00000000 ____D C:\Users\araton7811\TapinRadio 2014-01-23 17:21 - 2013-09-29 20:04 - 00065208 _____ C:\WINDOWS\PFRO.log 2014-01-21 20:40 - 2013-05-29 23:49 - 00000000 ____D C:\Users\araton7811\AppData\Local\Spotify 2014-01-19 08:38 - 2013-02-18 19:52 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2014-01-18 21:59 - 2014-01-18 21:53 - 00004124 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001UA 2014-01-18 21:59 - 2014-01-18 21:53 - 00003744 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1223374180-3426500295-1664088304-1001Core 2014-01-17 23:28 - 2014-01-17 23:28 - 01561040 _____ C:\Users\araton7811\ts3_recording_14_01_17_23_28_1.wav 2014-01-17 17:52 - 2014-01-11 17:53 - 00052736 ___SH C:\Users\araton7811\Documents\Thumbs.db 2014-01-16 19:28 - 2014-01-16 19:28 - 00001047 _____ C:\Users\araton7811\Desktop\TapinRadio.lnk 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\Users\araton7811\AppData\Local\Mozilla 2014-01-16 16:38 - 2014-01-16 16:38 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-15 19:47 - 2014-01-15 18:56 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\iSafe 2014-01-15 18:56 - 2014-01-15 18:56 - 00000907 _____ C:\Users\araton7811\Desktop\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000887 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-01-15 18:56 - 2014-01-15 18:56 - 00000000 ____D C:\WINDOWS\system32\log 2014-01-13 17:14 - 2013-08-22 15:46 - 00351627 _____ C:\WINDOWS\setupact.log 2014-01-13 17:10 - 2014-01-13 14:57 - 00000000 ____D C:\Program Files (x86)\Skype 2014-01-13 17:09 - 2014-01-13 14:57 - 00000000 ____D C:\Users\araton7811\AppData\Roaming\Skype 2014-01-13 17:09 - 2012-07-26 09:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2014-01-13 17:04 - 2012-11-19 19:29 - 00000000 ____D C:\Users\araton7811\AppData\Local\Packages 2014-01-13 17:03 - 2013-10-28 14:07 - 00000000 ____D C:\Program Files\Java 2014-01-13 16:30 - 2014-01-13 14:56 - 00000000 ____D C:\ProgramData\Skype 2014-01-13 16:26 - 2014-01-12 16:53 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-12 16:54 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2014-01-12 16:53 - 2014-01-12 16:53 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2014-01-10 12:51 - 2014-01-10 12:50 - 00000000 ____D C:\Program Files\Virtual Audio Cable 2014-01-10 12:50 - 2014-01-10 12:50 - 00066728 _____ (Eugene V. Muzychenko) C:\WINDOWS\system32\Drivers\vrtaucbl.sys 2014-01-10 12:18 - 2014-01-10 12:17 - 00000000 ____D C:\Program Files (x86)\Winamp 2014-01-10 12:17 - 2014-01-10 12:17 - 00000995 _____ C:\Users\Public\Desktop\Winamp.lnk 2014-01-06 23:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-01-06 23:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-06 05:39 - 2014-01-06 05:39 - 00000482 _____ C:\Users\araton7811\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery (D).lnk Files to move or delete: ==================== C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll Some content of TEMP: ==================== C:\Users\araton7811\AppData\Local\Temp\20140130151202.874.exe C:\Users\araton7811\AppData\Local\Temp\ICReinstall_20140130151202.874.exe C:\Users\araton7811\AppData\Local\Temp\nsc765.exe C:\Users\araton7811\AppData\Local\Temp\nsl7505.exe C:\Users\araton7811\AppData\Local\Temp\nsnDADB.exe C:\Users\araton7811\AppData\Local\Temp\nsp10B.exe C:\Users\araton7811\AppData\Local\Temp\nss7AF1.exe C:\Users\araton7811\AppData\Local\Temp\Show-Password_1030-8102.exe C:\Users\araton7811\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\araton7811\AppData\Local\Temp\utt3AFC.tmp.exe C:\Users\araton7811\AppData\Local\Temp\yac_3.8.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-31 13:28 ==================== End Of Log ============================ --- --- --- --- --- --- Results of screen317's Security Check version 0.99.79 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Google Chrome 32.0.1700.102 Google Chrome 32.0.1700.107 ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSMpEng.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Windows Defender MpCmdRun.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
09.02.2014, 09:41 | #12 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKCU\...\Run: [BackgroundContainer] - C:\Users\araton7811\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [319264 2013-10-15] (Conduit Ltd.) <===== ATTENTION C:\Users\araton7811\AppData\Local\Conduit Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2014, 20:17 | #13 |
| Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01 Ran by araton7811 at 2014-02-15 20:12:44 Running from C:\Users\araton7811\Downloads Boot Mode: Normal ================== Search: "fixlist.txt" =================== C:\Users\araton7811\Desktop\Fixlist.txt [2014-02-15 20:09] - [2014-02-15 20:09] - 0000218 ____A () 981772143AC3F0D7D4B9D3DB53F8AC34 ====== End Of Search ====== |
16.02.2014, 08:06 | #14 |
/// the machine /// TB-Ausbilder | Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung Bitte FRST neu laden und den FIx nochmal machen. Du hast nach der Fixlist suchen lassen anstatt den Fix auszuführen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Teamspeak und andere Prozesse geben aufeinmal keine Rückmeldung |
andere, einfach, guten, interne, internetsecurity, kaspersky, keine rückmeldung, laptop, meldung, nicht mehr, problem, prozess, prozesse, reagiert, rückmeldung, schöne, schönen, security, sound, teamspeak, trojaner, verbinden, virus, windows, windows8, woche, wochen, öffnet |