|
Plagegeister aller Art und deren Bekämpfung: Wajam Adware und Proxy-ProblemWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.01.2015, 08:18 | #1 |
| Wajam Adware und Proxy-Problem Hallo zusammen, ich scheine ein identisches Problem wie http://www.trojaner-board.de/161536-...y-problem.html zu haben. Ich habe aber mal der Übersichtlichkeit halber ein neues Thema aufgemacht, da letzteres auch nicht abschließend geklärt wurde. Ich habe gestern mit Malwarebytes und AntiVir zwei Schädlinge dieser Sorte entfernt und danach war in allen Browsern (Firefox, IE, Opera) eingestellt "Proxy verwenden". Nachdem ich das ausgestellt habe, gehen die Browser wieder, aber ich wollte auf Nummer sicher gehen, dass alles runter ist. Ich habe jetzt das Farbar Scan Tool heruntergeladen. Hier die beiden Textdateien. Wajam war übrigens nicht als Programm installiert, ich hatte lediglich die "Internet Ehancer.exe" unter Prozessen gefunden. Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2015 02 Ran by K at 2015-01-14 07:12:33 Running from D:\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 5.6 64-bit (HKLM\...\{D19E99C2-6D9D-4075-B446-B4387EAF70A5}) (Version: 5.6.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Advanced Renamer (HKLM-x32\...\Advanced Renamer_is1) (Version: 3.62 - Hulubulu Software) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Artweaver Free 4 (HKLM-x32\...\{6567E404-A019-4D0C-BD18-10564126A579}_is1) (Version: 4.0 - Boris Eyrich Software) Avira (HKLM-x32\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Canon iP3300 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3300) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.0 - Canon Inc.) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.12.51.2 - Canon Inc.) Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.12.2.1 - Canon Inc.) Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.12.2.0 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) ColdCut (HKLM-x32\...\{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1) (Version: ColdCut - © Jan Brummelte) CrystalDiskInfo 6.1.14 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.1.14 - Crystal Dew World) CrystalDiskMark 3.0.3b (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3b - Crystal Dew World) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) ETDWare X64 11.7.19.9_WHQL (HKLM\...\Elantech) (Version: 11.7.19.9 - ELAN Microelectronic Corp.) Ext2Fsd 0.51 (HKLM\...\Ext2Fsd_is1) (Version: 0.51 - Matt Wu) ffdshow [rev 2946] [2009-05-15] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - ) File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version: - filetypeadvisor.com) Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Gpg4win (2.2.1) (HKLM-x32\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project) HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) HDBook PhotoLab24 (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\HDBook PhotoLab24) (Version: HDBook PhotoLab24 3.5.0 - HD book PhotoLab24) HDClone 5.0.3 Free Edition (HKLM\...\Miray.HDClone.Free.5.0.3.1031-{983D3A69-DC16-47A3-B78A-5783BA769B25}) (Version: 5.0 - Miray Software AG) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation) JabRef 2.10 (HKLM-x32\...\JabRef 2.10) (Version: 2.10 - JabRef Team) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle) LibreOffice 4.2.1.1 (HKLM-x32\...\{C83C3B4C-1AFF-4CEA-8078-74E7A3FE8F03}) (Version: 4.2.1.1 - The Document Foundation) LRTimelapse 3.4 (HKLM-x32\...\{7413A137-4748-4073-BD2D-F87716D37D6C}_is1) (Version: 3.4 - Gunther Wegner) Malwarebytes Anti-Malware versie 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MATLAB R2013a Student Version (32-bit) (HKLM-x32\...\Matlab SV R2013a) (Version: 8.1 - The MathWorks, Inc.) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 33.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0.3 (x86 de)) (Version: 33.0.3 - Mozilla) Mozilla Firefox 34.0.5 (x86 de) (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla) Mozilla Thunderbird 24.6.0 (x86 de) (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) Opera Stable 26.0.1656.60 (HKLM-x32\...\Opera 26.0.1656.60) (Version: 26.0.1656.60 - Opera Software ASA) PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT) Quick Starter (HKLM\...\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.2 - Samsung Electronics CO., LTD.) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7055 - Realtek Semiconductor Corp.) S Agent (Version: 1.1.50 - Samsung Electronics CO., LTD.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.) Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.) SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.) Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) SRS Premium Sound (HKLM-x32\...\{E44F8A34-529E-4318-A0E1-1893C337A47F}) (Version: 1.00.4700 - DTS, Inc.) SSDlife Pro (HKLM-x32\...\{9BA5CE24-2924-4BAA-8B76-083C065D5F9E}) (Version: 2.5.78 - BinarySense Inc.) Steganos Online Shield (HKLM-x32\...\{896614ED-00BD-4E0C-99AB-01C76EE416D9}) (Version: 1.4.9 - Steganos Software GmbH) Steganos Password Manager 15 (HKLM-x32\...\{B8F35E03-DC02-4CAB-AEF2-577B4CA25E8A}) (Version: 15.2.4 - Steganos Software GmbH) Streamripper (Remove only) (HKLM-x32\...\Streamripper) (Version: - ) Support Center (HKLM\...\{AB0DEFBB-1A16-47B5-86D2-39F0A2B24AE4}) (Version: 2.1.1210 - Samsung Electronics CO., LTD.) Support Center FAQ (x32 Version: 1.0.14 - Samsung Electronics CO., LTD.) Hidden SW Update (HKLM-x32\...\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.) SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft) Taggr (HKLM-x32\...\{1249AEDC-B1DD-47FC-AA80-4DD7D377C820}) (Version: 1.3.60.0 - u-blox) TeXnicCenter Version 2.02 Stable (HKLM\...\TeXnicCenter_is1) (Version: 2.02 Stable - The TeXnicCenter Team) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) Webocton - Scriptly 0.8.95.6 (HKLM-x32\...\Webocton - Scriptly_is1) (Version: 0.8.95.6 - Webocton) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows-stuurprogrammapakket - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 13-01-2015 14:56:42 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0F452BA3-2E51-4A6B-90CA-9A06437F33A4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {21309E2B-F6B2-4F72-9259-7D68CF568775} - System32\Tasks\{035DC7B1-FEDB-4CA2-BCFE-2209C6D8DF01} => Firefox.exe hxxp://ui.skype.com/ui/0/6.14.0.104/en/abandoninstall?page=tsProgressBar Task: {33288FEE-1E65-4C61-9B04-8782E078D86E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-25] (Adobe Systems Incorporated) Task: {3A5EB20C-5B09-4CD8-BD33-F71FD114831D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {92BC0741-1B6F-4C35-9EDE-63A69463AAA4} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-10-10] (Samsung Electronics CO., LTD.) Task: {92E3F38A-C720-4AA7-912B-CB96811501CF} - System32\Tasks\MATLAB R2013a Startup Accelerator => D:\Programme\MATLAB R2013a Student\bin\win32\MATLABStartupAccelerator.exe [2013-01-16] () Task: {9EEB8ED2-BE27-4968-A945-C62559EE7DE8} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2014-01-29] (Samsung Electronics CO., LTD.) Task: {A3899F55-53BA-40F9-92AB-7814B7564098} - System32\Tasks\{8FDE0344-9CA9-4D4E-95CB-70675C320C61} => pcalua.exe -a J:\Installationsdateien\Ext2Fsd-0.51.exe -d J:\Installationsdateien Task: {A8AAE252-7019-4C8E-B6C1-D029E856DA7A} - System32\Tasks\{FF30DD92-70C1-4EBE-96E8-3661073AC639} => Firefox.exe hxxp://ui.skype.com/ui/0/6.14.0.104/en/privacy Task: {AB4883FB-E128-4B31-AE51-CB7387DF5264} - System32\Tasks\CCleanerSkipUAC => D:\Programme\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {BE71FFFC-74F7-429E-9036-E881ED01D296} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor) Task: {CE029ADB-E31B-4A2C-BA5D-071691E87D09} - System32\Tasks\Opera scheduled Autoupdate 1397160593 => D:\Programme\Opera\launcher.exe [2014-12-17] (Opera Software) Task: {E75D822F-313B-40E9-9043-361993C0D698} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {F3B9E7CF-1216-4812-8B16-04C7E667426C} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-04] (filetypeadvisor.com ) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job => D:\Programme\MATLAB R2013a Student\bin\win32\MATLABStartupAccelerator.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-07 15:54 - 2013-10-07 15:54 - 00218112 _____ () D:\Programme\GnuPG\dirmngr.exe 2014-01-29 12:20 - 2014-01-29 12:20 - 00084800 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe 2014-01-25 01:22 - 2014-01-25 01:22 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-04-12 17:41 - 2013-10-03 09:42 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe 2014-10-10 20:35 - 2014-10-10 20:35 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll 2013-10-07 15:49 - 2013-10-07 15:49 - 00221184 _____ () D:\Programme\GnuPG\libksba-8.dll 2013-10-07 15:44 - 2013-10-07 15:44 - 00050176 _____ () D:\Programme\GnuPG\libw32pth-0.dll 2013-10-07 15:49 - 2013-10-07 15:49 - 00069632 _____ () D:\Programme\GnuPG\libassuan-0.dll 2013-10-07 15:49 - 2013-10-07 15:49 - 00628224 _____ () D:\Programme\GnuPG\libgcrypt-11.dll 2013-10-07 15:47 - 2013-10-07 15:47 - 00037888 _____ () D:\Programme\GnuPG\libgpg-error-0.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00027968 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 01141056 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00025920 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00059712 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll 2014-01-29 12:20 - 2014-01-29 12:20 - 00102720 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll 2014-04-12 17:41 - 2013-10-03 09:42 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2014-04-12 16:00 - 2013-09-16 11:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-12-15 08:01 - 2014-12-15 08:01 - 03758192 _____ () D:\Programme\Mozilla Firefox\mozjs.dll 2014-06-19 11:01 - 2014-06-19 11:01 - 03022960 _____ () D:\Programme\Mozilla Thunderbird\mozjs.dll 2014-06-19 11:01 - 2014-06-19 11:01 - 00158832 _____ () D:\Programme\Mozilla Thunderbird\NSLDAP32V60.dll 2014-06-19 11:01 - 2014-06-19 11:01 - 00023152 _____ () D:\Programme\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:4FC01C57 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: SkypeUpdate => 2 HKLM\...\StartupApproved\Run32: => "DivXMediaServer" HKLM\...\StartupApproved\Run32: => "DivXUpdate" HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "Spotify Web Helper" ========================= Accounts: ========================== Administrator (S-1-5-21-1027477070-3827058414-3605222199-500 - Administrator - Disabled) Gast (S-1-5-21-1027477070-3827058414-3605222199-501 - Limited - Disabled) K (S-1-5-21-1027477070-3827058414-3605222199-1001 - Administrator - Enabled) => C:\Users\K ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer. Details: AddWin32ServiceFiles: Unable to back up image of service Internet Enhancer Service since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. . Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (01/13/2015 02:56:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: EasySettingsCmdServer.exe, versie: 0.0.0.0, tijdstempel: 0x52e75292 Naam van module met fout: MSVCR100.dll, versie: 10.0.30319.460, tijdstempel: 0x4db13576 Uitzonderingscode: 0x40000015 Foutmarge: 0x0008cb95 Id van proces met fout: 0x18d8 Starttijd van toepassing met fout: 0xEasySettingsCmdServer.exe0 Pad naar toepassing met fout: EasySettingsCmdServer.exe1 Pad naar module met fout: EasySettingsCmdServer.exe2 Rapport-id: EasySettingsCmdServer.exe3 Volledige pakketnaam met fout: EasySettingsCmdServer.exe4 Relatieve toepassings-id van pakket met fout: EasySettingsCmdServer.exe5 Error: (01/12/2015 08:21:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: adobe.photoshop.cs6-patch.exe, versie: 0.0.0.0, tijdstempel: 0x4f556a7c Naam van module met fout: Imagehlp.dll, versie: 6.3.9600.16438, tijdstempel: 0x5261ffbb Uitzonderingscode: 0xc0000005 Foutmarge: 0x00003937 Id van proces met fout: 0x125c Starttijd van toepassing met fout: 0xadobe.photoshop.cs6-patch.exe0 Pad naar toepassing met fout: adobe.photoshop.cs6-patch.exe1 Pad naar module met fout: adobe.photoshop.cs6-patch.exe2 Rapport-id: adobe.photoshop.cs6-patch.exe3 Volledige pakketnaam met fout: adobe.photoshop.cs6-patch.exe4 Relatieve toepassings-id van pakket met fout: adobe.photoshop.cs6-patch.exe5 Error: (12/29/2014 11:25:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: SamToolBox.exe, versie: 0.0.0.0, tijdstempel: 0x4f625b19 Naam van module met fout: SamToolBox.exe, versie: 0.0.0.0, tijdstempel: 0x4f625b19 Uitzonderingscode: 0xc0000005 Foutmarge: 0x00453016 Id van proces met fout: 0x1480 Starttijd van toepassing met fout: 0xSamToolBox.exe0 Pad naar toepassing met fout: SamToolBox.exe1 Pad naar module met fout: SamToolBox.exe2 Rapport-id: SamToolBox.exe3 Volledige pakketnaam met fout: SamToolBox.exe4 Relatieve toepassings-id van pakket met fout: SamToolBox.exe5 Error: (12/24/2014 00:00:41 PM) (Source: Python Service) (EventID: 255) (User: ) Description: Exception : HTTPConnectionPool(host='127.0.0.1', port=35600): Read timed out. (read timeout=60) Error: (12/11/2014 09:34:37 PM) (Source: MsiInstaller) (EventID: 1024) (User: KPC) Description: Product: Adobe Reader XI (11.0.09) - Deutsch - Update '{AC76BA86-7AD7-0000-2550-7A8C40011010}' kan niet worden geïnstalleerd. Foutcode: 1625. Windows Installer kan logboekbestanden maken om te helpen bij het oplossen van problemen tijdens het installeren van softwarepakketten. Raadpleeg de volgende koppeling voor aanwijzingen over het inschakelen van ondersteuning via logboekregistratie: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (12/06/2014 03:27:07 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Het volume Wiederherstellung is niet geoptimaliseerd, omdat er een fout is opgetreden: Falscher Parameter. (0x80070057) Error: (11/26/2014 10:30:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: EasySettingsCmdServer.exe, versie: 0.0.0.0, tijdstempel: 0x52e75292 Naam van module met fout: MSVCR100.dll, versie: 10.0.30319.460, tijdstempel: 0x4db13576 Uitzonderingscode: 0x40000015 Foutmarge: 0x0008cb95 Id van proces met fout: 0x994 Starttijd van toepassing met fout: 0xEasySettingsCmdServer.exe0 Pad naar toepassing met fout: EasySettingsCmdServer.exe1 Pad naar module met fout: EasySettingsCmdServer.exe2 Rapport-id: EasySettingsCmdServer.exe3 Volledige pakketnaam met fout: EasySettingsCmdServer.exe4 Relatieve toepassings-id van pakket met fout: EasySettingsCmdServer.exe5 Error: (11/24/2014 09:22:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . System errors: ============= Error: (01/13/2015 08:58:55 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (01/13/2015 08:58:54 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (01/13/2015 02:56:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: De Superfetch-service is gestopt met de volgende foutcode: %%1062. Error: (01/13/2015 09:00:48 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De Internet Enhancer Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (01/07/2015 08:54:26 AM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (01/02/2015 07:32:47 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Bij de schaduwkopieën van volume C: zijn afgebroken omdat de schaduwkopieopslag niet kan worden uitgebreid vanwege een door de gebruiker opgelegde limiet. Error: (12/27/2014 09:57:28 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (12/27/2014 09:56:58 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (12/14/2014 06:26:26 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (12/14/2014 06:25:56 PM) (Source: DCOM) (EventID: 10010) (User: KPC) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Microsoft Office Sessions: ========================= Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service Internet Enhancer Service since QueryServiceConfig API failed System Error: Das System kann die angegebene Datei nicht finden. Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert Error: (01/13/2015 02:56:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: EasySettingsCmdServer.exe0.0.0.052e75292MSVCR100.dll10.0.30319.4604db13576400000150008cb9518d801d02f38beb5b05aC:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dllff01d4d6-9b2b-11e4-82da-b4b676ef2396 Error: (01/12/2015 08:21:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: adobe.photoshop.cs6-patch.exe0.0.0.04f556a7cImagehlp.dll6.3.9600.164385261ffbbc000000500003937125c01d02e9ce6c2efb4D:\Programme\Adobe Photoshop\Adobe Photoshop CS6\adobe.photoshop.cs6-patch.exeC:\Windows\SYSTEM32\Imagehlp.dll2d6268ef-9a90-11e4-82d9-b4b676ef2396 Error: (12/29/2014 11:25:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: SamToolBox.exe0.0.0.04f625b19SamToolBox.exe0.0.0.04f625b19c000000500453016148001d023b653eb857dD:\Programme\SamsungTVChannelEditor\samtoolbox_win7_v0.11\SamToolBox.exeD:\Programme\SamsungTVChannelEditor\samtoolbox_win7_v0.11\SamToolBox.exea01a5ffa-8fa9-11e4-82d7-b4b676ef2396 Error: (12/24/2014 00:00:41 PM) (Source: Python Service) (EventID: 255) (User: ) Description: Exception : HTTPConnectionPool(host='127.0.0.1', port=35600): Read timed out. (read timeout=60) Error: (12/11/2014 09:34:37 PM) (Source: MsiInstaller) (EventID: 1024) (User: KPC) Description: Adobe Reader XI (11.0.09) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011010}1625(NULL)(NULL)(NULL) Error: (12/06/2014 03:27:07 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: WiederherstellungFalscher Parameter. (0x80070057) Error: (11/26/2014 10:30:05 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: EasySettingsCmdServer.exe0.0.0.052e75292MSVCR100.dll10.0.30319.4604db13576400000150008cb9599401d0095b8e741ac1C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dllcd8fd8e6-754e-11e4-82cd-b4b676ef2396 Error: (11/24/2014 09:22:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert CodeIntegrity Errors: =================================== Date: 2014-12-05 18:24:26.842 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz Percentage of memory in use: 22% Total physical RAM: 7813.53 MB Available physical RAM: 6072.86 MB Total Pagefile: 9285.54 MB Available Pagefile: 7247.46 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:48.3 GB) (Free:15.92 GB) NTFS Drive d: (Divers) (Fixed) (Total:46.86 GB) (Free:15.27 GB) NTFS Drive e: () (Fixed) (Total:20.74 GB) (Free:2.37 GB) EXT3 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 119.2 GB) (Disk ID: CA9BA44D) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02 Ran by K (administrator) on KPC on 14-01-2015 07:11:01 Running from D:\Downloads Loaded Profile: K (Available profiles: K) Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () D:\Programme\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Geek Software GmbH) D:\Programme\PDF24\pdf24.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) D:\Programme\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299 ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299 HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ SearchScopes: HKLM-x32 -> DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Roomy Bookmarks Toolbar - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\ALone-live@ya.ru.xpi [2014-09-18] FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10] FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10] FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12] FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH) R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 07:10 - 2015-01-14 07:11 - 00000000 ____D () C:\FRST 2015-01-14 06:41 - 2015-01-14 06:41 - 00000022 _____ () C:\Windows\S.dirmngr 2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList 2015-01-12 20:35 - 2015-01-14 06:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI 2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother 2014-12-29 23:24 - 2014-12-29 23:24 - 00000926 _____ () C:\Users\K\Desktop\SamToolBox.lnk 2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 07:07 - 2014-04-10 20:29 - 01634056 _____ () C:\Windows\WindowsUpdate.log 2015-01-14 07:05 - 2014-04-10 20:35 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001 2015-01-14 07:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-01-14 06:45 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat 2015-01-14 06:45 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat 2015-01-14 06:45 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-14 06:45 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-01-14 06:45 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-01-14 06:42 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job 2015-01-14 06:41 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-13 20:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-01-13 20:54 - 2014-11-26 07:43 - 00029664 _____ () C:\Windows\PFRO.log 2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME 2015-01-13 14:57 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-13 14:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit 2015-01-13 14:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor 2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc 2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe 2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe 2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify 2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log 2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify 2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-12-25 14:47 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593 2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions Some content of TEMP: ==================== C:\Users\K\AppData\Local\Temp\avgnt.exe C:\Users\K\AppData\Local\Temp\bassmod.dll C:\Users\K\AppData\Local\Temp\dup2patcher.dll C:\Users\K\AppData\Local\Temp\w64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-06 15:26 ==================== End Of Log ============================ Geändert von schrauber (14.01.2015 um 08:26 Uhr) |
14.01.2015, 08:26 | #2 |
/// the machine /// TB-Ausbilder | Wajam Adware und Proxy-Problem hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
14.01.2015, 10:13 | #3 |
| Wajam Adware und Proxy-Problem Hallo schrauber,
__________________vielen Dank für deine schnelle Antwort. Oben hatte ich ausversehen die Zitatumgebung verwendet, jetzt nach Ausführen der weiteren Ratschläge korrekt: AdwCleaner.txt Code:
ATTFilter # AdwCleaner v4.107 - Bericht erstellt am 14/01/2015 um 08:32:14 # Aktualisiert 07/01/2015 von Xplode # Database : 2015-01-13.2 [Live] # Betriebssystem : Windows 8.1 Pro (64 bits) # Benutzername : K - KPC # Gestartet von : D:\Downloads\AdwCleaner_4.107.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\ALone-live@ya.ru.xpi ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Mozilla Firefox v33.0.3 (x86 de) -\\ Opera v0.0.0.0 ************************* AdwCleaner[R0].txt - [1539 octets] - [13/04/2014 11:56:57] AdwCleaner[R1].txt - [1183 octets] - [14/01/2015 08:29:28] AdwCleaner[S0].txt - [1088 octets] - [13/04/2014 11:58:15] AdwCleaner[S1].txt - [1009 octets] - [14/01/2015 08:32:14] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1069 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 8.1 Pro x64 Ran by K on wo 14-01-2015 at 8:36:36,65 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on wo 14-01-2015 at 8:41:21,40 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02 Ran by K (administrator) on KPC on 14-01-2015 09:10:21 Running from D:\Downloads Loaded Profile: K (Available profiles: K) Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () D:\Programme\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Geek Software GmbH) D:\Programme\PDF24\pdf24.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Thisisu) D:\Downloads\JRT.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299 ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299 HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH) Tcpip\Parameters: [DhcpNameServer] 134.95.127.1 134.95.9.74 FireFox: ======== FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10] FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10] FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12] FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH) R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt 2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT 2015-01-14 07:10 - 2015-01-14 09:10 - 00000000 ____D () C:\FRST 2015-01-14 06:41 - 2015-01-14 08:33 - 00000022 _____ () C:\Windows\S.dirmngr 2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList 2015-01-12 20:35 - 2015-01-14 08:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI 2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother 2014-12-29 23:24 - 2014-12-29 23:24 - 00000926 _____ () C:\Users\K\Desktop\SamToolBox.lnk 2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 09:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-01-14 08:49 - 2014-04-10 20:35 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001 2015-01-14 08:40 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat 2015-01-14 08:40 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat 2015-01-14 08:40 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-14 08:40 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-01-14 08:40 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-14 08:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-14 08:34 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job 2015-01-14 08:33 - 2014-11-26 07:43 - 00029970 _____ () C:\Windows\PFRO.log 2015-01-14 08:33 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner 2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log 2015-01-14 08:32 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME 2015-01-13 14:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit 2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor 2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc 2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe 2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe 2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify 2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log 2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify 2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593 2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions Some content of TEMP: ==================== C:\Users\K\AppData\Local\Temp\avgnt.exe C:\Users\K\AppData\Local\Temp\bassmod.dll C:\Users\K\AppData\Local\Temp\dup2patcher.dll C:\Users\K\AppData\Local\Temp\Quarantine.exe C:\Users\K\AppData\Local\Temp\sqlite3.dll C:\Users\K\AppData\Local\Temp\w64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-06 15:26 ==================== End Of Log ============================ Danke schon mal für deine Hilfe. |
14.01.2015, 13:22 | #4 |
/// the machine /// TB-Ausbilder | Wajam Adware und Proxy-ProblemESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.01.2015, 16:58 | #5 |
| Wajam Adware und Proxy-Problem Hi, ich hab ESET bei 93% gerade abgebrochen. Er ist zuvor ewig über meine Ubuntu Partition gejagt und hat dort gesucht. Gefunden hatte er davor: Code:
ATTFilter D:\Downloads\Microsoft Camera Codec Pack - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung D:\Downloads\MyPhoneExplorer - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung D:\Downloads\SamToolBox - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung D:\Programme\WS_FTP\index.php PHP/TrojanDownloader.Agent.AJ Trojaner Nun der SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.93 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Avira Desktop Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 16.0.0.257 Adobe Reader XI Mozilla Firefox 33.0.3 Firefox out of Date! Mozilla Thunderbird (24.3.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe Steganos Online Shield OnlineShieldService.exe Steganos Online Shield SteganosBrowserMonitor.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02 Ran by K (administrator) on KPC on 14-01-2015 15:57:08 Running from D:\Downloads Loaded Profile: K (Available profiles: K) Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () D:\Programme\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Geek Software GmbH) D:\Programme\PDF24\pdf24.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299 ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299 HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH) Tcpip\Parameters: [DhcpNameServer] 134.95.213.26 134.95.127.1 FireFox: ======== FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10] FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10] FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12] FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH) R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 15:50 - 2015-01-14 15:50 - 00000428 _____ () C:\Users\K\Desktop\neu.txt 2015-01-14 13:41 - 2015-01-14 13:41 - 00000022 _____ () C:\Windows\S.dirmngr 2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt 2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT 2015-01-14 07:10 - 2015-01-14 15:57 - 00000000 ____D () C:\FRST 2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList 2015-01-12 20:35 - 2015-01-14 15:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI 2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother 2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 15:48 - 2014-04-10 20:35 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001 2015-01-14 15:44 - 2014-12-14 18:49 - 00000000 ____D () C:\Users\K\Desktop\Handybackup 2015-01-14 15:43 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit 2015-01-14 15:43 - 2014-04-12 22:14 - 00000000 ___RD () C:\Users\K\Desktop\Grafik und Co 2015-01-14 15:42 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Multimedia 2015-01-14 15:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Divers 2015-01-14 15:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-14 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-01-14 13:45 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat 2015-01-14 13:45 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat 2015-01-14 13:45 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-14 13:45 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-01-14 13:45 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-01-14 13:42 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job 2015-01-14 13:41 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-14 09:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-14 08:33 - 2014-11-26 07:43 - 00029970 _____ () C:\Windows\PFRO.log 2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner 2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log 2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME 2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor 2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc 2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe 2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe 2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify 2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log 2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify 2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593 2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions Some content of TEMP: ==================== C:\Users\K\AppData\Local\Temp\avgnt.exe C:\Users\K\AppData\Local\Temp\bassmod.dll C:\Users\K\AppData\Local\Temp\dup2patcher.dll C:\Users\K\AppData\Local\Temp\w64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-06 15:26 ==================== End Of Log ============================ Ich weiß, dass der Abbruch eigentlich nicht die richtige Vorgehensweise ist. Siehst du denn soweit irgendwas schädliches oder sieht es in Ordnung aus? Vielen Dank nochmal. |
14.01.2015, 18:03 | #6 |
/// the machine /// TB-Ausbilder | Wajam Adware und Proxy-Problem Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299 ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299 Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. Bestehen noch Probleme?
__________________ --> Wajam Adware und Proxy-Problem |
14.01.2015, 20:05 | #7 |
| Wajam Adware und Proxy-Problem Probleme bestanden ja schon nicht mehr nachdem ich den Proxy in den Browsern manuell ausgeschaltet habe. Hier die Logdatei Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-01-2015 01 Ran by K at 2015-01-14 19:04:11 Run:1 Running from D:\Downloads Loaded Profiles: K (Available profiles: K) Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299 ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299 Emptytemp: ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. EmptyTemp: => Removed 378.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 19:04:36 ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-01-2015 01 Ran by K (administrator) on KPC on 14-01-2015 19:07:17 Running from D:\Downloads Loaded Profiles: K (Available profiles: K) Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () D:\Programme\GnuPG\dirmngr.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Geek Software GmbH) D:\Programme\PDF24\pdf24.exe (Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH) Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default FF DefaultSearchEngine: Ecosia FF SelectedSearchEngine: Ecosia FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10] FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10] FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12] FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12] FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) R3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH) R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 19:01 - 2015-01-14 19:01 - 00000022 _____ () C:\Windows\S.dirmngr 2015-01-14 15:50 - 2015-01-14 15:50 - 00000428 _____ () C:\Users\K\Desktop\neu.txt 2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt 2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT 2015-01-14 07:10 - 2015-01-14 19:07 - 00000000 ____D () C:\FRST 2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList 2015-01-12 20:35 - 2015-01-14 19:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI 2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother 2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-14 19:06 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat 2015-01-14 19:06 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat 2015-01-14 19:06 - 2014-04-10 20:35 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001 2015-01-14 19:06 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-14 19:06 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-01-14 19:06 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-01-14 19:01 - 2014-11-26 07:43 - 00030796 _____ () C:\Windows\PFRO.log 2015-01-14 19:01 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job 2015-01-14 19:01 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-14 15:44 - 2014-12-14 18:49 - 00000000 ____D () C:\Users\K\Desktop\Handybackup 2015-01-14 15:43 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit 2015-01-14 15:43 - 2014-04-12 22:14 - 00000000 ___RD () C:\Users\K\Desktop\Grafik und Co 2015-01-14 15:42 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Multimedia 2015-01-14 15:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Divers 2015-01-14 15:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-14 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-01-14 09:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner 2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log 2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME 2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor 2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc 2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes 2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe 2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe 2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify 2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log 2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify 2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593 2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions Some content of TEMP: ==================== C:\Users\K\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-06 15:26 ==================== End Of Log ============================ |
15.01.2015, 07:00 | #8 |
/// the machine /// TB-Ausbilder | Wajam Adware und Proxy-Problem Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Wajam Adware und Proxy-Problem |
adware, antivir, antivirus, avira, browser, converter, cpu, desktop, dllhost.exe, firefox, flash player, helper, internet, internetenhancer, mp3, object, problem, programm, proxy, prozesse, rundll, scan, security, services.exe, software, svchost.exe, usb, wajam, windows |