|
Plagegeister aller Art und deren Bekämpfung: Monstermarketplace.com: Google Chrome Problem!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
04.08.2013, 17:29 | #1 |
| Monstermarketplace.com: Google Chrome Problem!Hi, ich habe mich mit dem Thema schon befasst, aber ich bin absoluter Anfänger! Ich habe das Problem, dass wenn ich bei bestimmten Seiten z.B bei Youtube bin auf jeder Seite 2-5 Wörter grün unterstrichen werden und wenn ich auf ein Wort draufklicke öffnet sich eine beliebige Seite. Ich habe schon nach einer Lösung gesucht, aber finde nichts vernünftiges. Ich hoffe hier kann mir jemand bei meinem Problem weiterhelfen, darüber wäre ich sehr dankbar! Danke schonmal! Liebe Grüße Leo |
04.08.2013, 18:28 | #2 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! Hi.
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
04.08.2013, 18:52 | #3 |
| Monstermarketplace.com: Google Chrome Problem! Ich führe das Programm gerade aus, es steht aber schon seit 20 Minuten bei der gleichen Stelle und oben links steht:
__________________"Getting Application errors: 106428" Was bedeutet das? Ist das normal oder ist dass irgendein Fehler?? #MfG €: Habe das Programm nun beendet, da es immernoch diese Meldung anzeigt. Ich werde erst wieder am Dienstag am PC sein, und dann werde ich es nochmals probieren und hier in den Thread posten. Ich hoffe, dass ich dann immernoch Hilfe bekomme! Bis dahin, Grüße Leo Geändert von xaster (04.08.2013 um 19:08 Uhr) |
05.08.2013, 07:59 | #4 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! klar
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.08.2013, 16:23 | #5 |
| Monstermarketplace.com: Google Chrome Problem! Ich lasse gerade das Farbar's Recovery Scan Tool laufen, doch es bleibt wieder wie gestern bei "Getting Application errors: 106428" stehen. Was soll ich nun machen? Seit dem das angezeigt wird, wurde auf meinem Desktop eine 'Additon.txt' Datei erstellt. Hier der Code: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-08-2013 01 Ran by Leonard at 2013-08-05 17:19:41 Running from C:\Users\Leonard\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) µTorrent (Version: 3.3.0.29544) Adobe Acrobat XI Pro (Version: 11.0) Adobe Acrobat XI Pro (Version: 11.0.00) Adobe After Effects CS4 (Version: 9) Adobe After Effects CS4 Presets (Version: 9) Adobe After Effects CS4 Third Party Content (Version: 9) Adobe AIR (Version: 3.7.0.1860) Adobe Anchor Service CS4 (Version: 2.0) Adobe Bridge CS4 (Version: 3) Adobe CMaps CS4 (Version: 2.0) Adobe Color Video Profiles AE CS4 (Version: 2.0) Adobe Creative Suite 6 Master Collection (Version: 6) Adobe Default Language CS4 (Version: 2.0) Adobe Device Central CS4 (Version: 2) Adobe Download Assistant (Version: 1.2.5) Adobe Dynamiclink Support (Version: 1) Adobe Edge Animate (Version: 1.5) Adobe Exchange Panel (Version: 1) Adobe ExtendScript Toolkit CS4 (Version: 3.0.0) Adobe Extension Manager CS4 (Version: 2.0) Adobe Flash Builder 4.7 (Version: 4.7) Adobe Flash Player 11 ActiveX (Version: 11.6.602.180) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Fonts All (Version: 2.0) Adobe Help Manager (Version: 4.0.244) Adobe Illustrator CS6 (Version: 16.0) Adobe Media Encoder CS4 (Version: 1.0) Adobe Media Encoder CS4 Additional Exporter (Version: 1.0) Adobe Media Player (Version: 0.0.0) Adobe Media Player (Version: 1.1) Adobe MotionPicture Color Files CS4 (Version: 2.0) Adobe Muse (Version: 4.1) Adobe Muse (Version: 4.1.8) Adobe Output Module (Version: 2.0) Adobe PDF Library Files CS4 (Version: 9.0) Adobe Photoshop CS5 (Version: 12.0) Adobe Premiere Elements 11 (Version: 11.0) Adobe Reader 9.5.3 - Deutsch (Version: 9.5.3) Adobe Setup (Version: 2.0) Adobe Touch App Plugins (Version: 1.0) Adobe Type Support CS4 (Version: 9.0) Adobe Update Manager CS4 (Version: 6.0.0) Adobe Widget Browser (Version: 2.0 Build 348) Adobe Widget Browser (Version: 2.0.348) Adobe XMP Panels CS4 (Version: 2.0) Adobe® Content Viewer (Version: 3.1.0) Angry Birds (Version: 2.0.2) Apple Application Support (Version: 2.3.4) Apple Software Update (Version: 2.1.3.127) Audacity 2.0.2 (Version: 2.0.2) BatteryLifeExtender (Version: 1.0.1) bl (Version: 1.0.0) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) CCleaner (Version: 4.04) Color My Facebook 2 (Version: 1.26.153.2) Crossfire Europe (Version: 1.172) CyberLink YouCam (Version: 2.0.2907) D3DX10 (Version: 15.4.2368.0902) DAEMON Tools Lite (Version: 4.47.1.0333) devolo dLAN Wireless extender Konfiguration (Version: 1.0.0.0) devolo dLAN-Konfigurationsassistent (Version: 14.0.0.0) devolo EasyShare (Version: 4.0.0.0) devolo Informer (Version: 22.0.0.0) Digital DJ (Version: 2.0) Easy Display Manager (Version: 3.0) Easy Network Manager (Version: 4.0.2) Easy SpeedUp Manager (Version: 3.0.0.4) EasyBatteryManager (Version: 4.0.0.2) Elements 11 Organizer (Version: 11.0) EPSON BX525WD Series Printer Uninstall Epson Easy Photo Print 2 (Version: 2.2.3.0) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (Version: 1.00.0000) Epson Event Manager (Version: 2.40.0001) EpsonNet Print (Version: 2.4i) EpsonNet Setup 3.3 (Version: 3.3a) ESET Online Scanner v3 F1 2011 (Version: 1.0.0000.129) F1 2011 (Version: 1.0.0002.129) Facebook Video Calling 1.2.0.287 (Version: 1.2.287) Free YouTube Uploader version 4.0.1.622 (Version: 4.0.1.622) Google Chrome (HKCU Version: 27.0.1453.110) Hotfix für Microsoft Visual C++ 2010 Express - DEU (KB2635973) (Version: 1) HyperCam 3 (Version: 3.3.1111.16) IrfanView (remove only) (Version: 4.35) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) League of Legends (Version: 3.0.1) LibUSB-Win32-0.1.10.1 (Version: 0.1.10.1) LogMeIn Hamachi (Version: 2.1.0.294) MAGIX Foto Designer 7 (Version: 7.0.1.1) MAGIX Guitar Backing Maker (Version: 17.0.3.2) MAGIX Music Maker 17 Download-Version (Version: 17.0.2.6) MAGIX Music Maker for MySpace 15.0.1.8 (D) (Version: 15.0.1.8) MAGIX Music Maker MX Download-Version (Version: 18.0.0.42) MAGIX Screenshare (Version: 4.3.6.1987) MAGIX Slideshow Maker 2 (Version: 2.0.0.8) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (Version: 3.5.30730.0) Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.92.0) Microsoft Games for Windows Marketplace (Version: 3.5.50.0) Microsoft Help Viewer 1.1 (Version: 1.1.40219) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server 2008 Microsoft SQL Server 2008 Browser (Version: 10.3.5500.0) Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0) Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0) Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0) Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0) Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0) Microsoft SQL Server Compact 3.5 SP2 DEU (Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 ENU (Version: 3.5.8080.0) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 10.3.5500.0) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (Version: 10.0.40219) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 Express - DEU (Version: 10.0.40219) Microsoft Visual Studio 2010 Service Pack 1 (Version: 10.0.40219) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40303) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40308) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053) Microsoft_VC90_ATL_x86 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (Version: 1.00.0000) Mobile Connection Manager (Version: 8.7.6.767) Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSVCRT (Version: 15.4.2862.0708) MSVCRT Redists (Version: 1.0) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) Native Instruments Mikro Prism (Version: 1.0.0.001) Need for Speed™ The Run (Version: 1.0.0.0) Nexon Game Manager Norton 360 (Version: 20.4.0.40) Numedia CD-DVD writing as non-admin user (Version: 1.0.0) NVIDIA Grafiktreiber 301.42 (Version: 301.42) NVIDIA Install Application (Version: 2.1002.75.420) NVIDIA PhysX (Version: 9.11.0621) NVIDIA PhysX-Systemsoftware 9.11.0621 (Version: 9.11.0621) NVIDIA Systemsteuerung 301.42 (Version: 301.42) Origin (Version: 8.5.2.23) Pando Media Booster (Version: 2.6.0.9) PDF Settings CS5 (Version: 10.0) PDF Settings CS6 (Version: 11.0) PDF24 Creator ph (Version: 1.0.0) PhotoScape Photoshop Camera Raw (Version: 5.0) Picasa 3 (Version: 3.9) Pixel Bender Toolkit (Version: 1.0) PlayStation(R)Network Downloader (Version: 2.07.00849) PlayStation(R)Store (Version: 4.8.1.14440) Plus-HD-1.6 (Version: 1.27.153.8) PRE11 STI Installer (Version: 11.0) QuickTime (Version: 7.74.80.86) S4 League_EU (Version: 1.00.0000) Samsung Kies (Version: 2.5.2.13021_10) Samsung Recovery Solution 4 (Version: 4.0.0.3) Samsung Support Center (Version: 1.0.1) Samsung Update Plus (Version: 2.0) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.22.0) Service Pack 3 für SQL Server 2008 (KB2546951) (Version: 10.3.5500.0) Skype Voice Changer (Version: 2.3.0.0) Skype™ 6.6 (Version: 6.6.106) Spotify (HKCU Version: 0.8.5.1333.g822e0de8) Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0) Steam (Version: 1.0.0.0) Suite Shared Configuration CS4 (Version: 1.0) swMSM (Version: 12.0.0.1) Team Fortress 2 TmNationsForever TuneUp Utilities 2013 (Version: 13.0.3020.2) TuneUp Utilities Language Pack (de-DE) (Version: 13.0.3020.2) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (Version: 10.3.5500.0) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4.5 (KB2750147) (Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) User Guide (Version: 1.0) Vegas Pro 11.0 (Version: 11.0.700) VirtualDJ Home FREE (Version: 7.0.5) Vocup 1.4.3 (Version: 1.4.3) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) WinRAR (Version: 4.00.0) XMedia Recode Version 3.1.6.4 (Version: 3.1.6.4) ==================== Restore Points ========================= 01-08-2013 16:51:42 Geplanter Prüfpunkt 04-08-2013 13:33:52 COMPUTERBILD-Abzockschutz wird installiert 04-08-2013 13:47:09 COMPUTERBILD-Abzockschutz wird entfernt ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-08-04 16:48 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05A23E3E-165F-4275-B7ED-8DA1C7D4249A} - System32\Tasks\{80EDBB16-0F8C-43AB-B97E-583675D5A148} => c:\program files\mozilla firefox\firefox.exe [2013-06-18] (Mozilla Corporation) Task: {05C8D1DD-38A2-424D-B01D-0080DDB72F7B} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {0BDCC2C2-C951-458F-AA34-5D439757E843} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-771618654-3341757510-301361698-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: {0CFE20F4-557D-44FC-852A-B309C36CD61E} - System32\Tasks\{BAE3D1D8-4D04-4E2A-9592-F702C29ECF2A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {0E913043-1000-4E43-9B6E-1B35107D9897} - System32\Tasks\Plus-HD-1.6-firefoxinstaller => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe [2013-07-11] (Plus HD) Task: {1CCDF7FB-ACBA-4D0A-87CC-1EFE7E679086} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-08-01] (SAMSUNG Electronics co., LTD.) Task: {1F6F07E6-441B-4D2E-98B6-BC5F71480390} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-771618654-3341757510-301361698-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe No File Task: {2D1E2E27-EE28-4E8A-9C60-171157CCE783} - System32\Tasks\Google Updater and Installer => C:\Users\Leonard\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-06] (Google Inc.) Task: {2E2C36E3-EC17-4A67-969D-69196F696EA4} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {31C68D58-AC39-4AF3-8080-45603F50948A} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-09-21] (Samsung Electronics. Co. Ltd.) Task: {3B4632BB-681D-427E-99E0-14EF80404B4A} - System32\Tasks\BrowserDefendert => C:\windows\system32\sc.exe [2009-07-14] (Microsoft Corporation) Task: {45212845-7052-430B-8E26-47B027397C5A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {51C86909-2D4E-4AD7-825C-0B977B69BAB1} - System32\Tasks\Funmoods => C:\Users\Leonard\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe No File Task: {56DA2983-093C-4A5F-98F5-96E61822F4D6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-771618654-3341757510-301361698-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: {570D6923-3A2F-4869-A701-60BFD50C30D4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000Core => C:\Users\Leonard\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-06] (Google Inc.) Task: {6552F7F8-A711-46E8-8DA3-7E119F3896C2} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {66C32559-3BF4-4CDE-8292-CF653355C3C2} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-09-07] (SAMSUNG Electronics) Task: {6B169DC4-551A-45DD-B4CD-97EBA73A3A60} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe [2013-01-28] (TuneUp Software) Task: {6D428225-1FF0-4A8F-9347-6D8D4D0680F5} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-771618654-3341757510-301361698-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe No File Task: {6E445981-CC21-4081-9575-6124D83BCA2A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {6E88F924-A731-4BAC-A698-38DB59DC599C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000UA => C:\Users\Leonard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-01] (Facebook Inc.) Task: {7BDEB6FD-0B49-4F08-8065-BB22D0ACFB71} - System32\Tasks\Plus-HD-1.6-updater => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe [2013-07-11] (Plus HD) Task: {831A96F3-371D-484E-B705-3B221A300B15} - System32\Tasks\Plus-HD-1.6-enabler => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe [2013-07-11] (Plus HD) Task: {8973F993-FE06-419A-9F93-CFCE592424A5} - System32\Tasks\{09A04A76-36F1-46E2-859E-F445648329C5} => c:\program files\mozilla firefox\firefox.exe [2013-06-18] (Mozilla Corporation) Task: {90E030CB-8425-42D9-9B9C-DEAC3636A887} - System32\Tasks\Updater23606.exe => C:\Users\Leonard\AppData\Local\Updater23606\Updater23606.exe No File Task: {94EF4783-28AB-4036-B514-2C0D513C6F5C} - System32\Tasks\AdobeAAMUpdater-1.0-Leonard-PC-Leonard => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-03-21] (Adobe Systems Incorporated) Task: {98D3BB53-B176-47A3-A2EA-3B28F6F88ECA} - System32\Tasks\Express FilesUpdate => C:\Program Files\ExpressFiles\EFUpdater.exe No File Task: {9941B42A-61F9-4FFD-9CF3-4BEF723CF1EA} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000Core => C:\Users\Leonard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-01] (Facebook Inc.) Task: {A6A4519F-ADA4-443A-82CC-276A5E3522DE} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2009-08-06] (SEC) Task: {A6E77E5F-F06C-46B1-AEA0-18090EC2A83F} - System32\Tasks\Plus-HD-1.6-codedownloader => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe [2013-07-11] (Plus HD) Task: {A8C36A01-1DBD-4C14-B972-E4BA993EB056} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {BA94DD49-B0E6-4729-A251-1B0385C163E8} - System32\Tasks\Plus-HD-1.6-chromeinstaller => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe [2013-07-11] (Plus HD) Task: {BF27E82A-F722-4B74-A16F-9ADF7C26080A} - System32\Tasks\{7B2D089C-7FC0-4AFE-9C29-9D81038F4D7E} => C:\Users\Leonard\Desktop\S4League\patcher_s4.exe No File Task: {C7AD6C6B-CB53-402E-BDED-3E55E922E51C} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-04-20] () Task: {C929E3BE-AB1D-40EB-9F3D-30E69DF17DD2} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {C931D73C-C024-43D2-A3F8-98F696FBB7F6} - System32\Tasks\{033209EF-0B99-46B6-AF0C-7628337EB517} => c:\program files\mozilla firefox\firefox.exe [2013-06-18] (Mozilla Corporation) Task: {CB400724-0ED1-4436-A736-84C53E2FC0BE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000UA => C:\Users\Leonard\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-06] (Google Inc.) Task: {CBDE57D4-1E45-4F31-8DBD-3965733D3637} - System32\Tasks\Express Files Updater => C:\Program Files\ExpressFiles\EFupdater.exe No File Task: {CCF1EBA0-C146-4174-9912-81BE08BF9C99} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-04] (Adobe Systems Incorporated) Task: {E52F12AA-3919-4BE5-A7CC-463E29D089D9} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {EEF76F66-3042-41C5-9CCD-1D0D366E3792} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {F53554AE-071E-4C5F-8E22-B7D8DE397F9A} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-771618654-3341757510-301361698-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe No File Task: {FCC85F9D-CE13-4427-ABDC-98A596891E6A} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2009-08-23] (Samsung Electronics Co., Ltd.) Task: {FD2B13DB-9FB4-4103-9102-81B1AE2B12B4} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {FF520546-9FBB-40D0-B9B4-CEE701894095} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2009-09-08] (Samsung Electronics Co., Ltd.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000Core.job => C:\Users\Leonard\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000UA.job => C:\Users\Leonard\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000Core.job => C:\Users\Leonard\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000UA.job => C:\Users\Leonard\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe Task: C:\windows\Tasks\Plus-HD-1.6-codedownloader.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe Task: C:\windows\Tasks\Plus-HD-1.6-enabler.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe Task: C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe Task: C:\windows\Tasks\Plus-HD-1.6-updater.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/04/2013 05:11:25 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/04/2013 05:08:35 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/04/2013 05:08:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/04/2013 05:07:20 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". |
06.08.2013, 15:50 | #6 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! Downloade Dir bitte AdwCleaner auf deinen Desktop.
Downloade Dir bitte Malwarebytes Anti-Malware
und ein frisches FRST log bitte.
__________________ --> Monstermarketplace.com: Google Chrome Problem! |
07.08.2013, 09:41 | #7 |
| Monstermarketplace.com: Google Chrome Problem! Habe alles so gemacht, wie du es gesagt hast Hier die Logdatei von dem AdwCleaner: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 07/08/2013 um 10:16:18 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzer : Leonard - LEONARD-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Leonard\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v28.0.1500.95 Datei : C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [341 octets] - [04/08/2013 16:10:32] AdwCleaner[S2].txt - [6537 octets] - [04/08/2013 16:11:17] AdwCleaner[S3].txt - [41691 octets] - [04/08/2013 16:12:03] AdwCleaner[S4].txt - [1065 octets] - [07/08/2013 10:16:18] ########## EOF - C:\AdwCleaner[S4].txt - [1125 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.07.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16635 Leonard :: LEONARD-PC [Administrator] Schutz: Deaktiviert 07.08.2013 10:23:50 mbam-log-2013-08-07 (10-23-50).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 336627 Laufzeit: 16 Minute(n), Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCU\SOFTWARE\CYBER (Backdoor.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKCU\Software\Cyber|FirstExecution (Backdoor.Trace) -> Daten: 22/12/2010 -- 16:49 -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Windows\Installer\13779c8.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
07.08.2013, 12:46 | #8 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! Supi ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.08.2013, 20:56 | #9 |
| Monstermarketplace.com: Google Chrome Problem! Nach sagenhaften 6 Stunden und 36 Minuten ist es endlich abgeschlossen. Es wurde nichts 'bedrohliches' gefunden. Hier der Code: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=74691438f29a2141a3541d75530dddab # engine=14686 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-07 07:39:54 # local_time=2013-08-07 09:39:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3592 16777213 100 93 25388 126566890 0 0 # compatibility_mode=5893 16776574 100 94 2421549 127535585 0 0 # scanned=373309 # found=0 # cleaned=0 # scan_time=23768 Code:
ATTFilter Results of screen317's Security Check version 0.99.71 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Norton 360 WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 TuneUp Utilities 2013 TuneUp Utilities Language Pack (de-DE) CCleaner Java 7 Update 25 Adobe Flash Player 11.8.800.94 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (22.0) Google Chrome 27.0.1453.110 Google Chrome 28.0.1500.95 Google Chrome Plugins... ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Es ist wieder das gleiche Problem, wie beim ersten Start von der FRST.exe .. Ich drücke auf Scan und dann arbeitet er schön und dann bleibt er bei 'Getting Application errors: 106428" stehen und es läuft nichts mehr. Wieso ist das so?? Das 'monstermarketplace.com' Problem ist immer noch da. (Leider) Was soll ich nun machen ? #MfG |
08.08.2013, 06:53 | #10 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! Mach den Haken raus bei Additional und scanne nochmal
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.08.2013, 10:37 | #11 |
| Monstermarketplace.com: Google Chrome Problem! Habe den Haken bei Addition.txt mal rausgemacht und gescannt. Diesmal hat es geklappt! Hier der Code: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-08-2013 05 Ran by Leonard (administrator) on 08-08-2013 11:34:15 Running from C:\Users\Leonard\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe () C:\Users\Leonard\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe (hxxp://libusb-win32.sourceforge.net) C:\windows\system32\libusbd-nt.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe () C:\windows\system32\PnkBstrA.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Acrobat Assistant 8.0] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.) HKCU\...\Run: [ccleaner] - C:\Program Files\CCleaner\CCleaner.exe [3643160 2013-07-22] (Piriform Ltd) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation) HKCU\...\Policies\system: [EnableLUA] 0 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: (No Name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No File URLSearchHook: (No Name) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {1B8B75C1-AEA2-4B28-B88A-BF4E99DA5DFA} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 SearchScopes: HKCU - {30750DD1-EADD-4cf1-A485-C736C96936AB} URL = hxxp://search.etoolkit.com/search?q={searchTerms}&id=0267a5f427498a433994a2b297cd77dec56&s=p SearchScopes: HKCU - {3F278068-BDCA-45EB-9FBD-552C44CF791A} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - No Name - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - No File Toolbar: HKLM - No Name - {D3B22A92-87A2-47b6-B3E6-A64877B5C242} - No File Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU -Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU -No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File Toolbar: HKCU -No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File Toolbar: HKCU -Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {93C449FA-ECFB-402F-A8C7-37E4F8D60E49} hxxp://dl.pmang.com/common/pmangctl/pmangax.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} hxxp://update.nprotect.net/keycrypt/neowiz/npkcx_1004191.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{F57D79F8-5B7D-4A18-B03D-C1C5D5A069F0}: [NameServer]193.189.244.206 193.189.244.225 FireFox: ======== FF ProfilePath: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin: @nielsen/FirefoxTracker - C:\Program Files\NetRatingsNetSight\NetSight\meter2\FirefoxAddOns\npfirefoxtracker.dll No File FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin: @pmang.com/npPMangFX - C:\windows\system32\npPMangFX.dll ( ) FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VLC\npvlc.dll No File FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: Adobe Acrobat - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Leonard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Leonard\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Leonard\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\searchplugins\winload-customized-web-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\toolkitsearch.xml FF Extension: No Name - C:\Users\Leonard\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\678af7f4-3941-4adf-9561-6a57d5ccc43e@6703c9f7-0011-4f82-b9aa-c3115f7ad728.com FF Extension: No Name - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\ich@maltegoetz.de FF Extension: Flagfox - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\info@flagfox.net FF Extension: iMacros for Firefox - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} FF Extension: extension - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\extension@preispilot.com.xpi FF Extension: toolbar - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\toolbar@gmx.net.xpi FF Extension: torntv2 - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\torntv2@torntv.com.xpi FF Extension: No Name - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\moh0htl1.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\ FF HKLM\...\Firefox\Extensions: [netsight@nielsen.com] C:\Program Files\NetRatingsNetSight\NetSight\meter2\FirefoxAddOns\netsight@nielsen.xpi FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\ Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Leonard\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Leonard\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\npcoplgn.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (LoadTubes Plugin) - C:\Program Files\Mozilla Firefox\plugins\npmieze.dll No File CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (Orbit Downloader) - C:\Users\Leonard\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll ( ) CHR Plugin: (AdobeAAMDetect) - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) CHR Plugin: (VLC Web Plugin) - C:\Program Files\VLC\npvlc.dll No File CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Leonard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Google Update) - C:\Users\Leonard\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Mozilla PMangFX Session Plugin_1.0.0.8) - C:\windows\system32\npPMangFX.dll ( ) CHR Extension: (Plus-HD-1.6) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.23.43_0 CHR Extension: (Click&Clean App) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_1 CHR HKLM\...\Chrome\Extension: [abepbblpkilpjohncjbccmdjhdhbnhdj] - C:\Program Files\SingAlong\Chrome.crx CHR HKLM\...\Chrome\Extension: [bgnnidmnbdkmhfkjgdnngciimpdgohok] - C:\Program Files\LSHunter.TV\stv11.crx CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx CHR HKLM\...\Chrome\Extension: [ildldcbkkbkhnjghnbidklpepakbepnd] - C:\Users\Leonard\AppData\LocalLow\Flagfox\CHROME\Flagfox.crx CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton 360\Engine\20.4.0.40\Exts\Chrome.crx CHR HKLM\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files\TornTV.com\torn2_10.crx CHR StartMenuInternet: Google Chrome - C:\Users\Leonard\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor11.0; C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-23] (Adobe Systems Incorporated) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) R2 FlagfoxUpdater; C:\Users\Leonard\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe [18432 2012-02-28] () S4 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1435568 2012-12-10] (LogMeIn Inc.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) S4 NMSAccessU; C:\Program Files\Common Files\NMSAccessU.exe [65536 2007-01-25] () S3 npggsvc; C:\windows\system32\GameMon.des [4122968 2011-06-19] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\windows\system32\PnkBstrA.exe [75136 2011-07-30] () S4 TGCM_ImportWiFiSvc; C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe [201080 2011-06-14] (Telefónica) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1724192 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 aksfridge; C:\windows\system32\drivers\aksfridge.sys [365056 2012-08-07] (SafeNet Inc.) R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130715.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-07-31] (DT Soft Ltd) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-05-01] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-06-27] (Symantec Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] () R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R2 hardlock; C:\windows\system32\drivers\hardlock.sys [605128 2012-09-27] (SafeNet Inc.) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130807.001\IDSvix86.sys [386720 2013-05-18] (Symantec Corporation) R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130807.022\NAVENG.SYS [93272 2013-06-27] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130807.022\NAVEX15.SYS [1611992 2013-06-27] (Symantec Corporation) R2 NPF_devolo; C:\Windows\system32\drivers\npf_devolo.sys [35840 2007-02-07] (CACE Technologies) R2 npkakl; C:\windows\system32\npkakl.sys [31328 2010-03-09] (INCA Internet Co.,Ltd.) R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [46096 2012-08-10] (Corel Corporation) S4 RsFx0105; C:\Windows\System32\DRIVERS\RsFx0105.sys [238696 2011-09-22] (Microsoft Corporation) R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS) S3 SipIMNDI; C:\Windows\System32\DRIVERS\SipIMNDI.sys [24352 2009-10-15] (T-Systems International GmbH) R1 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-02-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-20] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360\1404000.028\SYMNETS.SYS [339544 2013-04-25] (Symantec Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) S3 XDva403; C:\windows\system32\XDva403.sys [78000 2013-07-31] (www.wiselogic.co.kr) S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [465408 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Leonard\AppData\Local\Temp\catchme.sys [x] S3 cpuz132; \??\C:\Users\Leonard\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [x] S3 cpuz134; \??\C:\Users\Leonard\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x] U3 DfSdkS; S3 EagleNT; No ImagePath S3 EagleXNt; \??\C:\windows\system32\drivers\EagleXNt.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 injectDLL; No ImagePath S3 IntcAzAudAddService; No ImagePath S3 XDva370; No ImagePath S3 XDva375; No ImagePath S3 XDva380; No ImagePath S3 XDva383; No ImagePath S3 XDva385; No ImagePath S3 XDva386; No ImagePath S3 XDva387; No ImagePath S3 XDva388; No ImagePath S3 XDva389; No ImagePath S3 XDva390; No ImagePath S3 XDva391; No ImagePath S3 XDva396; No ImagePath S3 XDva398; No ImagePath S3 XDva399; No ImagePath S3 XDva401; \??\C:\windows\system32\XDva401.sys [x] S3 XDva402; \??\C:\windows\system32\XDva402.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-07 21:46 - 2013-08-07 21:46 - 01229788 _____ (Farbar) C:\Users\Leonard\Downloads\FRST.exe 2013-08-07 12:20 - 2013-08-07 15:30 - 00000000 ____D C:\Users\Leonard\Downloads\Sigs für epvp 2013-08-07 10:22 - 2013-08-07 10:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-07 10:22 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-08-07 10:16 - 2013-08-07 10:16 - 00001194 _____ C:\AdwCleaner[S4].txt 2013-08-04 19:34 - 2013-08-04 19:34 - 00000000 ____D C:\FRST 2013-08-04 16:28 - 2013-08-04 16:56 - 00000000 ____D C:\ComboFix 2013-08-04 16:28 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe 2013-08-04 16:28 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe 2013-08-04 16:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-08-04 16:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-08-04 16:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-08-04 16:28 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe 2013-08-04 16:28 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe 2013-08-04 16:28 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe 2013-08-04 16:27 - 2013-08-04 16:55 - 00000000 ____D C:\windows\erdnt 2013-08-04 16:27 - 2013-08-04 16:44 - 00000000 ____D C:\Qoobox 2013-08-04 16:12 - 2013-08-04 16:12 - 00041691 _____ C:\AdwCleaner[S3].txt 2013-08-04 16:11 - 2013-08-04 16:11 - 00006537 _____ C:\AdwCleaner[S2].txt 2013-08-04 16:10 - 2013-08-04 16:10 - 00000341 _____ C:\AdwCleaner[S1].txt 2013-08-04 15:04 - 2013-08-04 15:04 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Malwarebytes 2013-08-04 15:04 - 2013-08-04 15:04 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-04 14:41 - 2013-08-04 14:41 - 00069780 _____ C:\windows\system32\bootdelete.lst 2013-08-04 14:41 - 2013-08-04 14:41 - 00012872 _____ (SurfRight B.V.) C:\windows\system32\bootdelete.exe 2013-08-04 14:33 - 2013-08-04 14:47 - 00000162 _____ C:\windows\Reimage.ini 2013-08-04 14:23 - 2013-08-04 15:50 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-08-04 14:21 - 2013-08-04 14:41 - 00030464 _____ C:\windows\system32\Drivers\hitmanpro37.sys 2013-08-04 14:12 - 2013-08-04 14:12 - 00000960 _____ C:\windows\system32\.crusader 2013-08-04 14:01 - 2013-08-04 14:12 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-03 12:19 - 2013-08-03 12:19 - 00000000 ____D C:\Users\Leonard\Documents\iMacros 2013-08-03 12:14 - 2013-08-03 12:14 - 00001065 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-03 12:14 - 2013-08-03 12:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-02 17:39 - 2013-08-02 17:40 - 00000000 ____D C:\Users\Leonard\Downloads\GFX 2013-08-02 16:57 - 2013-08-02 16:58 - 00000000 ____D C:\Users\Leonard\AppData\Local\{998D5714-0A24-4AB5-99AF-0F15B7365970} 2013-08-01 15:43 - 2013-08-01 15:43 - 00000925 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-01 10:26 - 2013-08-01 10:26 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-31 16:30 - 2013-07-31 16:30 - 00078000 _____ (www.wiselogic.co.kr) C:\windows\system32\XDva403.sys 2013-07-31 15:40 - 2013-07-31 16:29 - 00000000 ____D C:\Program Files\Crossfire Europe 2013-07-31 15:30 - 2013-07-31 15:30 - 00000000 ____D C:\Program Files\Pando Networks 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\Gast\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\vlc 2013-07-31 12:47 - 2013-07-31 12:47 - 00001904 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2013-07-31 12:43 - 2013-07-31 12:43 - 00242240 _____ (DT Soft Ltd) C:\windows\system32\Drivers\dtsoftbus01.sys 2013-07-31 12:43 - 2013-07-31 12:43 - 00000000 ____D C:\Program Files\DAEMON Tools Lite 2013-07-28 10:54 - 2013-07-28 10:54 - 00000000 ____D C:\Program Files\SG Interactive 2013-07-27 11:17 - 2013-07-30 11:25 - 00000709 _____ C:\windows\system32\ScanResults.xml 2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\ProgramData\CDB 2013-07-25 13:54 - 2013-07-25 13:59 - 00000000 ____D C:\windows\system32\MRT 2013-07-25 11:04 - 2013-07-31 11:19 - 00001056 _____ C:\windows\system32\SettingsFile 2013-07-24 15:45 - 2013-07-31 14:38 - 00000000 ____D C:\Users\Leonard\AppData\Local\Warframe 2013-07-21 15:13 - 2013-07-21 15:13 - 00000000 __SHD C:\windows\system32\AI_RecycleBin 2013-07-21 15:13 - 2013-07-21 15:13 - 00000000 ____D C:\Program Files\Riot Games 2013-07-21 15:11 - 2013-08-01 14:52 - 00000000 ____D C:\Users\Leonard\AppData\Local\PMB Files 2013-07-21 15:11 - 2013-07-31 15:30 - 00000000 ____D C:\ProgramData\PMB Files 2013-07-21 15:10 - 2013-07-21 15:10 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Riot Games 2013-07-21 14:10 - 2013-07-31 14:46 - 00000000 ____D C:\Program Files\7-Zip 2013-07-20 12:23 - 2013-07-20 12:23 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-07-20 12:21 - 2013-07-20 12:21 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 2013-07-20 08:55 - 2013-07-20 08:55 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-17 14:45 - 2013-07-17 14:46 - 00000000 ____D C:\Users\Leonard\AppData\Local\{9303BF09-15F5-4E62-9C4D-64AA4E606E56} 2013-07-11 16:20 - 2013-08-08 11:26 - 00001886 _____ C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001810 _____ C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001190 _____ C:\windows\Tasks\Plus-HD-1.6-codedownloader.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001186 _____ C:\windows\Tasks\Plus-HD-1.6-updater.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001090 _____ C:\windows\Tasks\Plus-HD-1.6-enabler.job 2013-07-11 16:20 - 2013-07-11 16:20 - 00000000 ____D C:\Program Files\Plus-HD-1.6 2013-07-10 14:34 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-07-10 14:34 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-07-10 14:34 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-07-10 14:34 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-07-10 14:34 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-07-10 14:34 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-07-10 14:20 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-07-10 14:20 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2013-07-10 14:20 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2013-07-10 14:20 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 144 ==================== One Month Modified Files and Folders ======= 2013-08-08 11:27 - 2013-08-08 11:27 - 00000000 ____D C:\Users\Leonard\Desktop\AddMeFast-Bot_update1 2013-08-08 11:26 - 2013-07-11 16:20 - 00001886 _____ C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001810 _____ C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001190 _____ C:\windows\Tasks\Plus-HD-1.6-codedownloader.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001186 _____ C:\windows\Tasks\Plus-HD-1.6-updater.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001090 _____ C:\windows\Tasks\Plus-HD-1.6-enabler.job 2013-08-08 11:16 - 2009-07-14 06:34 - 00014512 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-08 11:16 - 2009-07-14 06:34 - 00014512 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-08 11:12 - 2009-07-26 22:06 - 01969580 _____ C:\windows\system32\PerfStringBackup.INI 2013-08-08 11:08 - 2013-05-18 12:16 - 00010198 _____ C:\windows\setupact.log 2013-08-08 11:08 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-08-08 11:07 - 2013-05-18 12:15 - 00134156 _____ C:\windows\PFRO.log 2013-08-07 22:25 - 2011-05-23 16:33 - 01712651 _____ C:\windows\WindowsUpdate.log 2013-08-07 21:46 - 2013-08-07 21:46 - 01229788 _____ (Farbar) C:\Users\Leonard\Downloads\FRST.exe 2013-08-07 21:17 - 2010-12-03 14:52 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Skype 2013-08-07 20:08 - 2013-05-01 14:03 - 00000936 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000UA.job 2013-08-07 15:30 - 2013-08-07 12:20 - 00000000 ____D C:\Users\Leonard\Downloads\Sigs für epvp 2013-08-07 15:00 - 2013-06-26 13:48 - 03287040 ___SH C:\Users\Leonard\Downloads\Thumbs.db 2013-08-07 14:08 - 2013-05-01 14:03 - 00000914 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-771618654-3341757510-301361698-1000Core.job 2013-08-07 10:22 - 2013-08-07 10:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-07 10:16 - 2013-08-07 10:16 - 00001194 _____ C:\AdwCleaner[S4].txt 2013-08-06 21:59 - 2013-05-23 19:51 - 00007980 ____H C:\Users\Leonard\Downloads\.picasa.ini 2013-08-05 19:51 - 2012-07-06 14:52 - 00002378 _____ C:\Users\Leonard\Desktop\Google Chrome.lnk 2013-08-04 19:34 - 2013-08-04 19:34 - 00000000 ____D C:\FRST 2013-08-04 16:56 - 2013-08-04 16:28 - 00000000 ____D C:\ComboFix 2013-08-04 16:55 - 2013-08-04 16:27 - 00000000 ____D C:\windows\erdnt 2013-08-04 16:49 - 2011-05-21 02:01 - 00000246 _____ C:\windows\system.ini 2013-08-04 16:46 - 2009-07-14 04:03 - 69468160 _____ C:\windows\system32\config\SOFTWARE.bak 2013-08-04 16:46 - 2009-07-14 04:03 - 18350080 _____ C:\windows\system32\config\SYSTEM.bak 2013-08-04 16:46 - 2009-07-14 04:03 - 01261568 _____ C:\windows\system32\config\DEFAULT.bak 2013-08-04 16:46 - 2009-07-14 04:03 - 00065536 _____ C:\windows\system32\config\SAM.bak 2013-08-04 16:46 - 2009-07-14 04:03 - 00032768 _____ C:\windows\system32\config\SECURITY.bak 2013-08-04 16:44 - 2013-08-04 16:27 - 00000000 ____D C:\Qoobox 2013-08-04 16:14 - 2012-04-03 10:09 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-08-04 16:12 - 2013-08-04 16:12 - 00041691 _____ C:\AdwCleaner[S3].txt 2013-08-04 16:11 - 2013-08-04 16:11 - 00006537 _____ C:\AdwCleaner[S2].txt 2013-08-04 16:11 - 2010-12-04 11:31 - 00000000 ____D C:\ProgramData\ICQ 2013-08-04 16:10 - 2013-08-04 16:10 - 00000341 _____ C:\AdwCleaner[S1].txt 2013-08-04 15:50 - 2013-08-04 14:23 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-08-04 15:04 - 2013-08-04 15:04 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Malwarebytes 2013-08-04 15:04 - 2013-08-04 15:04 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-04 14:47 - 2013-08-04 14:33 - 00000162 _____ C:\windows\Reimage.ini 2013-08-04 14:41 - 2013-08-04 14:41 - 00069780 _____ C:\windows\system32\bootdelete.lst 2013-08-04 14:41 - 2013-08-04 14:41 - 00012872 _____ (SurfRight B.V.) C:\windows\system32\bootdelete.exe 2013-08-04 14:41 - 2013-08-04 14:21 - 00030464 _____ C:\windows\system32\Drivers\hitmanpro37.sys 2013-08-04 14:24 - 2009-12-20 00:36 - 00000000 ____D C:\Users\Leonard\AppData\Local\Adobe 2013-08-04 14:23 - 2012-04-03 10:09 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2013-08-04 14:23 - 2011-05-21 15:01 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2013-08-04 14:12 - 2013-08-04 14:12 - 00000960 _____ C:\windows\system32\.crusader 2013-08-04 14:12 - 2013-08-04 14:01 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-03 12:19 - 2013-08-03 12:19 - 00000000 ____D C:\Users\Leonard\Documents\iMacros 2013-08-03 12:14 - 2013-08-03 12:14 - 00001065 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-03 12:14 - 2013-08-03 12:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-03 12:14 - 2010-11-28 00:50 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-02 18:38 - 2012-06-25 17:44 - 00083456 ___SH C:\Users\Leonard\Thumbs.db 2013-08-02 17:40 - 2013-08-02 17:39 - 00000000 ____D C:\Users\Leonard\Downloads\GFX 2013-08-02 17:18 - 2013-05-22 20:53 - 00000000 ___RD C:\Users\Leonard\Desktop\Videobearbeitungsprogramme 2013-08-02 16:58 - 2013-08-02 16:57 - 00000000 ____D C:\Users\Leonard\AppData\Local\{998D5714-0A24-4AB5-99AF-0F15B7365970} 2013-08-02 10:19 - 2012-05-22 20:32 - 00000000 ____D C:\Users\UpdatusUser.Leonard-PC 2013-08-01 15:54 - 2012-05-27 11:13 - 00000000 ____D C:\Users\Leonard\Desktop\Spiele 2013-08-01 15:51 - 2012-05-26 11:25 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\DAEMON Tools Lite 2013-08-01 15:50 - 2013-04-21 13:56 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\uTorrent 2013-08-01 15:50 - 2011-10-31 19:39 - 00000000 ____D C:\Users\Leonard\AppData\Local\LogMeIn Hamachi 2013-08-01 15:50 - 2010-11-29 17:42 - 00000000 ____D C:\Users\Leonard\AppData\Local\CrashDumps 2013-08-01 15:43 - 2013-08-01 15:43 - 00000925 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-01 15:43 - 2010-11-28 01:39 - 00000000 ____D C:\Program Files\CCleaner 2013-08-01 15:33 - 2012-03-27 20:21 - 00000000 ____D C:\Program Files\Steam 2013-08-01 15:12 - 2013-01-03 10:53 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\TuneUp Software 2013-08-01 14:59 - 2009-12-20 00:35 - 00000000 ____D C:\Users\Leonard 2013-08-01 14:58 - 2009-07-14 04:03 - 83623936 _____ C:\windows\system32\config\SOFTWARE_tureg_old 2013-08-01 14:58 - 2009-07-14 04:03 - 19136512 _____ C:\windows\system32\config\SYSTEM_tureg_old 2013-08-01 14:58 - 2009-07-14 04:03 - 00032768 _____ C:\windows\system32\config\SECURITY_tureg_old 2013-08-01 14:53 - 2009-07-14 04:03 - 01572864 _____ C:\windows\system32\config\DEFAULT_tureg_old 2013-08-01 14:53 - 2009-07-14 04:03 - 00065536 _____ C:\windows\system32\config\SAM_tureg_old 2013-08-01 14:52 - 2013-07-21 15:11 - 00000000 ____D C:\Users\Leonard\AppData\Local\PMB Files 2013-08-01 10:26 - 2013-08-01 10:26 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-31 17:14 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-07-31 16:30 - 2013-07-31 16:30 - 00078000 _____ (www.wiselogic.co.kr) C:\windows\system32\XDva403.sys 2013-07-31 16:29 - 2013-07-31 15:40 - 00000000 ____D C:\Program Files\Crossfire Europe 2013-07-31 15:53 - 2012-09-17 16:00 - 00000982 _____ C:\Users\UpdatusUser.Leonard-PC\Desktop\Crossfire Europe.lnk 2013-07-31 15:30 - 2013-07-31 15:30 - 00000000 ____D C:\Program Files\Pando Networks 2013-07-31 15:30 - 2013-07-21 15:11 - 00000000 ____D C:\ProgramData\PMB Files 2013-07-31 15:12 - 2012-04-18 20:02 - 00000000 ____D C:\Users\Leonard\AppData\Local\Sony 2013-07-31 15:12 - 2012-04-18 20:02 - 00000000 ____D C:\Program Files\Sony 2013-07-31 15:10 - 2012-04-18 19:57 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Sony 2013-07-31 15:09 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-07-31 14:47 - 2013-05-18 12:15 - 06207456 _____ C:\windows\system32\FNTCACHE.DAT 2013-07-31 14:46 - 2013-07-21 14:10 - 00000000 ____D C:\Program Files\7-Zip 2013-07-31 14:46 - 2012-02-19 20:42 - 00000000 ____D C:\Program Files\ManyCam 2013-07-31 14:43 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows DVD Maker 2013-07-31 14:41 - 2012-05-27 11:13 - 00000000 ____D C:\Users\Leonard\Desktop\Musikprogramme 2013-07-31 14:41 - 2012-03-02 17:19 - 00000000 ____D C:\Program Files\Windows Live 2013-07-31 14:40 - 2011-06-08 20:13 - 00000000 ____D C:\Users\Leonard\Documents\Youcam 2013-07-31 14:39 - 2013-05-18 11:52 - 00165312 _____ C:\Users\Leonard\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-31 14:38 - 2013-07-24 15:45 - 00000000 ____D C:\Users\Leonard\AppData\Local\Warframe 2013-07-31 14:29 - 2012-02-19 19:27 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\ManyCam 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\Gast\AppData\Roaming\vlc 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\vlc 2013-07-31 14:00 - 2011-11-06 21:05 - 00000000 ____D C:\Program Files\Common Files\DFX 2013-07-31 13:56 - 2009-09-22 07:19 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-31 13:53 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries 2013-07-31 13:49 - 2009-09-22 07:20 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2013-07-31 12:49 - 2012-05-26 11:24 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2013-07-31 12:47 - 2013-07-31 12:47 - 00001904 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2013-07-31 12:43 - 2013-07-31 12:43 - 00242240 _____ (DT Soft Ltd) C:\windows\system32\Drivers\dtsoftbus01.sys 2013-07-31 12:43 - 2013-07-31 12:43 - 00000000 ____D C:\Program Files\DAEMON Tools Lite 2013-07-31 11:19 - 2013-07-25 11:04 - 00001056 _____ C:\windows\system32\SettingsFile 2013-07-30 11:25 - 2013-07-27 11:17 - 00000709 _____ C:\windows\system32\ScanResults.xml 2013-07-29 17:14 - 2013-05-25 16:54 - 00000000 ___HD C:\Users\Leonard\Downloads\.picasaoriginals 2013-07-28 10:54 - 2013-07-28 10:54 - 00000000 ____D C:\Program Files\SG Interactive 2013-07-28 10:28 - 2011-06-17 08:53 - 00000000 ____D C:\ProgramData\NexonEU 2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\ProgramData\CDB 2013-07-25 13:59 - 2013-07-25 13:54 - 00000000 ____D C:\windows\system32\MRT 2013-07-24 15:21 - 2011-06-16 19:43 - 00446464 _____ (NEXON Inc.) C:\windows\NEXON_EU_DownloaderUpdater.exe 2013-07-24 15:21 - 2011-06-16 19:43 - 00000235 _____ C:\windows\system32\nxEuUninstall.bat 2013-07-21 15:13 - 2013-07-21 15:13 - 00000000 __SHD C:\windows\system32\AI_RecycleBin 2013-07-21 15:13 - 2013-07-21 15:13 - 00000000 ____D C:\Program Files\Riot Games 2013-07-21 15:10 - 2013-07-21 15:10 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Riot Games 2013-07-21 10:09 - 2011-08-13 12:37 - 00000000 ____D C:\Program Files\Common Files\Steam 2013-07-20 12:23 - 2013-07-20 12:23 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-07-20 12:21 - 2013-07-20 12:21 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 2013-07-20 08:55 - 2013-07-20 08:55 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-18 12:24 - 2012-03-28 19:36 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-07-17 14:46 - 2013-07-17 14:45 - 00000000 ____D C:\Users\Leonard\AppData\Local\{9303BF09-15F5-4E62-9C4D-64AA4E606E56} 2013-07-12 17:08 - 2013-05-19 12:01 - 00000000 ____D C:\Users\Leonard\AppData\Local\WebPlayer 2013-07-11 16:20 - 2013-07-11 16:20 - 00000000 ____D C:\Program Files\Plus-HD-1.6 2013-07-11 13:21 - 2012-05-12 15:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-10 21:00 - 2009-09-22 23:54 - 00000000 ___HD C:\Program Files\Windows Journal 2013-07-10 21:00 - 2009-07-14 06:52 - 00000000 ___HD C:\Program Files\Windows Defender 2013-07-10 18:56 - 2013-02-10 14:04 - 00000000 ___RD C:\Program Files\Skype 2013-07-10 18:56 - 2010-12-03 14:52 - 00000000 ____D C:\ProgramData\Skype 2013-07-10 14:29 - 2009-12-20 00:40 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-10 14:15 - 2012-03-03 16:28 - 00000000 ____D C:\Users\Leonard\AppData\Roaming\systweak 2013-07-09 17:43 - 2012-01-28 22:10 - 00000000 ____D C:\Program Files\Origin Files to move or delete: ==================== C:\ProgramData\hash.dat ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-04 17:09 ==================== End Of Log ============================ --- --- --- --- --- --- #MfG |
08.08.2013, 17:50 | #12 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter SearchScopes: HKCU - {1B8B75C1-AEA2-4B28-B88A-BF4E99DA5DFA} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 SearchScopes: HKCU - {30750DD1-EADD-4cf1-A485-C736C96936AB} URL = hxxp://search.etoolkit.com/search?q={searchTerms}&id=0267a5f427498a433994a2b297cd77dec56&s=p SearchScopes: HKCU - {3F278068-BDCA-45EB-9FBD-552C44CF791A} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = Toolbar: HKCU -No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File Toolbar: HKCU -No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File CHR Plugin: (LoadTubes Plugin) - C:\Program Files\Mozilla Firefox\plugins\npmieze.dll No File CHR Extension: (Plus-HD-1.6) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.23.43_0 CHR Extension: (Click&Clean App) - C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_1 CHR HKLM\...\Chrome\Extension: [abepbblpkilpjohncjbccmdjhdhbnhdj] - C:\Program Files\SingAlong\Chrome.crx CHR HKLM\...\Chrome\Extension: [bgnnidmnbdkmhfkjgdnngciimpdgohok] - C:\Program Files\LSHunter.TV\stv11.crx S3 XDva403; C:\windows\system32\XDva403.sys [78000 2013-07-31] (www.wiselogic.co.kr) C:\windows\system32\XDva403.sys U3 DfSdkS; S3 EagleNT; No ImagePath S3 EagleXNt; \??\C:\windows\system32\drivers\EagleXNt.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 injectDLL; No ImagePath S3 IntcAzAudAddService; No ImagePath S3 XDva370; No ImagePath S3 XDva375; No ImagePath S3 XDva380; No ImagePath S3 XDva383; No ImagePath S3 XDva385; No ImagePath S3 XDva386; No ImagePath S3 XDva387; No ImagePath S3 XDva388; No ImagePath S3 XDva389; No ImagePath S3 XDva390; No ImagePath S3 XDva391; No ImagePath S3 XDva396; No ImagePath S3 XDva398; No ImagePath S3 XDva399; No ImagePath S3 XDva401; \??\C:\windows\system32\XDva401.sys [x] S3 XDva402; \??\C:\windows\system32\XDva402.sys [x] 2013-07-11 16:20 - 2013-08-08 11:26 - 00001886 _____ C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001810 _____ C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001190 _____ C:\windows\Tasks\Plus-HD-1.6-codedownloader.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001186 _____ C:\windows\Tasks\Plus-HD-1.6-updater.job 2013-07-11 16:20 - 2013-08-08 11:26 - 00001090 _____ C:\windows\Tasks\Plus-HD-1.6-enabler.job 2013-07-11 16:20 - 2013-07-11 16:20 - 00000000 ____D C:\Program Files\Plus-HD-1.6 2013-08-08 11:26 - 2013-07-11 16:20 - 00001886 _____ C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001810 _____ C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001190 _____ C:\windows\Tasks\Plus-HD-1.6-codedownloader.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001186 _____ C:\windows\Tasks\Plus-HD-1.6-updater.job 2013-08-08 11:26 - 2013-07-11 16:20 - 00001090 _____ C:\windows\Tasks\Plus-HD-1.6-enabler.job 2013-07-11 16:20 - 2013-07-11 16:20 - 00000000 ____D C:\Program Files\Plus-HD-1.6 C:\ProgramData\hash.dat Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Nochmal testen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.08.2013, 18:29 | #13 |
| Monstermarketplace.com: Google Chrome Problem! Alles gemacht. Hier der Code der Fixlog.txt Datei: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-08-2013 05 Ran by Leonard at 2013-08-08 19:29:02 Run:1 Running from C:\Users\Leonard\Desktop Boot Mode: Normal ============================================== HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1B8B75C1-AEA2-4B28-B88A-BF4E99DA5DFA} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{1B8B75C1-AEA2-4B28-B88A-BF4E99DA5DFA} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{30750DD1-EADD-4cf1-A485-C736C96936AB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{30750DD1-EADD-4cf1-A485-C736C96936AB} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3F278068-BDCA-45EB-9FBD-552C44CF791A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{3F278068-BDCA-45EB-9FBD-552C44CF791A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => Value deleted successfully. HKCR\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} => Value deleted successfully. HKCR\CLSID\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} => Key not found. C:\Program Files\Mozilla Firefox\plugins\npmieze.dll not found. C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh => Moved successfully. C:\Users\Leonard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\abepbblpkilpjohncjbccmdjhdhbnhdj => Key deleted successfully. "C:\Program Files\SingAlong\Chrome.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok => Key deleted successfully. "C:\Program Files\LSHunter.TV\stv11.crx" => File/Directory not found. XDva403 => Service deleted successfully. C:\windows\system32\XDva403.sys => Moved successfully. DfSdkS => Service deleted successfully. EagleNT => Service deleted successfully. EagleXNt => Service deleted successfully. esgiguard => Service deleted successfully. injectDLL => Service deleted successfully. IntcAzAudAddService => Service deleted successfully. XDva370 => Service deleted successfully. XDva375 => Service deleted successfully. XDva380 => Service deleted successfully. XDva383 => Service deleted successfully. XDva385 => Service deleted successfully. XDva386 => Service deleted successfully. XDva387 => Service deleted successfully. XDva388 => Service deleted successfully. XDva389 => Service deleted successfully. XDva390 => Service deleted successfully. XDva391 => Service deleted successfully. XDva396 => Service deleted successfully. XDva398 => Service deleted successfully. XDva399 => Service deleted successfully. XDva401 => Service deleted successfully. XDva402 => Service deleted successfully. C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job => Moved successfully. C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job => Moved successfully. C:\windows\Tasks\Plus-HD-1.6-codedownloader.job => Moved successfully. C:\windows\Tasks\Plus-HD-1.6-updater.job => Moved successfully. C:\windows\Tasks\Plus-HD-1.6-enabler.job => Moved successfully. C:\Program Files\Plus-HD-1.6 => Moved successfully. "C:\windows\Tasks\Plus-HD-1.6-chromeinstaller.job" => File/Directory not found. "C:\windows\Tasks\Plus-HD-1.6-firefoxinstaller.job" => File/Directory not found. "C:\windows\Tasks\Plus-HD-1.6-codedownloader.job" => File/Directory not found. "C:\windows\Tasks\Plus-HD-1.6-updater.job" => File/Directory not found. "C:\windows\Tasks\Plus-HD-1.6-enabler.job" => File/Directory not found. "C:\Program Files\Plus-HD-1.6" => File/Directory not found. C:\ProgramData\hash.dat => Moved successfully. ==== End of Fixlog ==== #MfG |
09.08.2013, 09:57 | #14 |
/// the machine /// TB-Ausbilder | Monstermarketplace.com: Google Chrome Problem! n welchem Browser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.08.2013, 10:02 | #15 |
| Monstermarketplace.com: Google Chrome Problem! wie meinst du 'n welchem Browser' ? Ich benutze Google Chrome als Browser? #MfG |
Themen zu Monstermarketplace.com: Google Chrome Problem! |
absoluter, anfänger, bestimmte, bestimmten, center, chrome, dankbar, gesuch, gesucht, google, google chrome, grün unterstrichen, hoffe, lösung, monstermarketplace.com, nichts, problem, schonmal, seite, seiten, thema, unterstrichen, verschiedene, weiterhelfen, wörter, wörter grün, youtube, öffnen |