Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Wajam Adware und Proxy-Problem

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 14.01.2015, 08:18   #1
naranja
 
Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Hallo zusammen,

ich scheine ein identisches Problem wie http://www.trojaner-board.de/161536-...y-problem.html zu haben. Ich habe aber mal der Übersichtlichkeit halber ein neues Thema aufgemacht, da letzteres auch nicht abschließend geklärt wurde.

Ich habe gestern mit Malwarebytes und AntiVir zwei Schädlinge dieser Sorte entfernt und danach war in allen Browsern (Firefox, IE, Opera) eingestellt "Proxy verwenden". Nachdem ich das ausgestellt habe, gehen die Browser wieder, aber ich wollte auf Nummer sicher gehen, dass alles runter ist. Ich habe jetzt das Farbar Scan Tool heruntergeladen. Hier die beiden Textdateien. Wajam war übrigens nicht als Programm installiert, ich hatte lediglich die "Internet Ehancer.exe" unter Prozessen gefunden.


Addition.txt
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2015 02
Ran by K at 2015-01-14 07:12:33
Running from D:\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.6 64-bit (HKLM\...\{D19E99C2-6D9D-4075-B446-B4387EAF70A5}) (Version: 5.6.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advanced Renamer (HKLM-x32\...\Advanced Renamer_is1) (Version: 3.62 - Hulubulu Software)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artweaver Free 4 (HKLM-x32\...\{6567E404-A019-4D0C-BD18-10564126A579}_is1) (Version: 4.0 - Boris Eyrich Software)
Avira (HKLM-x32\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
Canon iP3300 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3300) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.0 - Canon Inc.)
Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.12.51.2 - Canon Inc.)
Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.)
Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.12.2.1 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.)
Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.12.2.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform)
ColdCut (HKLM-x32\...\{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1) (Version: ColdCut - © Jan Brummelte)
CrystalDiskInfo 6.1.14 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.1.14 - Crystal Dew World)
CrystalDiskMark 3.0.3b (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3b - Crystal Dew World)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
ETDWare X64 11.7.19.9_WHQL (HKLM\...\Elantech) (Version: 11.7.19.9 - ELAN Microelectronic Corp.)
Ext2Fsd 0.51 (HKLM\...\Ext2Fsd_is1) (Version: 0.51 - Matt Wu)
ffdshow [rev 2946] [2009-05-15] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - )
File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version:  - filetypeadvisor.com)
Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version:  - ManiacTools.com)
Gpg4win (2.2.1) (HKLM-x32\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project)
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version:  - EFD Software)
HDBook PhotoLab24 (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\HDBook PhotoLab24) (Version: HDBook PhotoLab24 3.5.0 - HD book PhotoLab24)
HDClone 5.0.3 Free Edition (HKLM\...\Miray.HDClone.Free.5.0.3.1031-{983D3A69-DC16-47A3-B78A-5783BA769B25}) (Version: 5.0 - Miray Software AG)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
JabRef 2.10 (HKLM-x32\...\JabRef 2.10) (Version: 2.10 - JabRef Team)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle)
LibreOffice 4.2.1.1 (HKLM-x32\...\{C83C3B4C-1AFF-4CEA-8078-74E7A3FE8F03}) (Version: 4.2.1.1 - The Document Foundation)
LRTimelapse 3.4 (HKLM-x32\...\{7413A137-4748-4073-BD2D-F87716D37D6C}_is1) (Version: 3.4 - Gunther Wegner)
Malwarebytes Anti-Malware versie 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
MATLAB R2013a Student Version (32-bit) (HKLM-x32\...\Matlab SV R2013a) (Version: 8.1 - The MathWorks, Inc.)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU  (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU  (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org)
Mozilla Firefox 33.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0.3 (x86 de)) (Version: 33.0.3 - Mozilla)
Mozilla Firefox 34.0.5 (x86 de) (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 de) (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla)
Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger)
Opera Stable 26.0.1656.60 (HKLM-x32\...\Opera 26.0.1656.60) (Version: 26.0.1656.60 - Opera Software ASA)
PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT)
Quick Starter (HKLM\...\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.2 - Samsung Electronics CO., LTD.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7055 - Realtek Semiconductor Corp.)
S Agent (Version: 1.1.50 - Samsung Electronics CO., LTD.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.)
Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
SRS Premium Sound (HKLM-x32\...\{E44F8A34-529E-4318-A0E1-1893C337A47F}) (Version: 1.00.4700 - DTS, Inc.)
SSDlife Pro (HKLM-x32\...\{9BA5CE24-2924-4BAA-8B76-083C065D5F9E}) (Version: 2.5.78 - BinarySense Inc.)
Steganos Online Shield (HKLM-x32\...\{896614ED-00BD-4E0C-99AB-01C76EE416D9}) (Version: 1.4.9 - Steganos Software GmbH)
Steganos Password Manager 15 (HKLM-x32\...\{B8F35E03-DC02-4CAB-AEF2-577B4CA25E8A}) (Version: 15.2.4 - Steganos Software GmbH)
Streamripper (Remove only) (HKLM-x32\...\Streamripper) (Version:  - )
Support Center (HKLM\...\{AB0DEFBB-1A16-47B5-86D2-39F0A2B24AE4}) (Version: 2.1.1210 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.14 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.)
SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft)
Taggr (HKLM-x32\...\{1249AEDC-B1DD-47FC-AA80-4DD7D377C820}) (Version: 1.3.60.0 - u-blox)
TeXnicCenter Version 2.02 Stable (HKLM\...\TeXnicCenter_is1) (Version: 2.02 Stable - The TeXnicCenter Team)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Webocton - Scriptly 0.8.95.6 (HKLM-x32\...\Webocton - Scriptly_is1) (Version: 0.8.95.6 - Webocton)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Windows-stuurprogrammapakket - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass  (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

13-01-2015 14:56:42 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0F452BA3-2E51-4A6B-90CA-9A06437F33A4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {21309E2B-F6B2-4F72-9259-7D68CF568775} - System32\Tasks\{035DC7B1-FEDB-4CA2-BCFE-2209C6D8DF01} => Firefox.exe hxxp://ui.skype.com/ui/0/6.14.0.104/en/abandoninstall?page=tsProgressBar
Task: {33288FEE-1E65-4C61-9B04-8782E078D86E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-25] (Adobe Systems Incorporated)
Task: {3A5EB20C-5B09-4CD8-BD33-F71FD114831D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {92BC0741-1B6F-4C35-9EDE-63A69463AAA4} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-10-10] (Samsung Electronics CO., LTD.)
Task: {92E3F38A-C720-4AA7-912B-CB96811501CF} - System32\Tasks\MATLAB R2013a Startup Accelerator => D:\Programme\MATLAB R2013a Student\bin\win32\MATLABStartupAccelerator.exe [2013-01-16] ()
Task: {9EEB8ED2-BE27-4968-A945-C62559EE7DE8} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2014-01-29] (Samsung Electronics CO., LTD.)
Task: {A3899F55-53BA-40F9-92AB-7814B7564098} - System32\Tasks\{8FDE0344-9CA9-4D4E-95CB-70675C320C61} => pcalua.exe -a J:\Installationsdateien\Ext2Fsd-0.51.exe -d J:\Installationsdateien
Task: {A8AAE252-7019-4C8E-B6C1-D029E856DA7A} - System32\Tasks\{FF30DD92-70C1-4EBE-96E8-3661073AC639} => Firefox.exe hxxp://ui.skype.com/ui/0/6.14.0.104/en/privacy
Task: {AB4883FB-E128-4B31-AE51-CB7387DF5264} - System32\Tasks\CCleanerSkipUAC => D:\Programme\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd)
Task: {BE71FFFC-74F7-429E-9036-E881ED01D296} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor)
Task: {CE029ADB-E31B-4A2C-BA5D-071691E87D09} - System32\Tasks\Opera scheduled Autoupdate 1397160593 => D:\Programme\Opera\launcher.exe [2014-12-17] (Opera Software)
Task: {E75D822F-313B-40E9-9043-361993C0D698} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {F3B9E7CF-1216-4812-8B16-04C7E667426C} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-04] (filetypeadvisor.com                                         )
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job => D:\Programme\MATLAB R2013a Student\bin\win32\MATLABStartupAccelerator.exe

==================== Loaded Modules (whitelisted) =============

2013-10-07 15:54 - 2013-10-07 15:54 - 00218112 _____ () D:\Programme\GnuPG\dirmngr.exe
2014-01-29 12:20 - 2014-01-29 12:20 - 00084800 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2014-01-25 01:22 - 2014-01-25 01:22 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-04-12 17:41 - 2013-10-03 09:42 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
2014-10-10 20:35 - 2014-10-10 20:35 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2013-10-07 15:49 - 2013-10-07 15:49 - 00221184 _____ () D:\Programme\GnuPG\libksba-8.dll
2013-10-07 15:44 - 2013-10-07 15:44 - 00050176 _____ () D:\Programme\GnuPG\libw32pth-0.dll
2013-10-07 15:49 - 2013-10-07 15:49 - 00069632 _____ () D:\Programme\GnuPG\libassuan-0.dll
2013-10-07 15:49 - 2013-10-07 15:49 - 00628224 _____ () D:\Programme\GnuPG\libgcrypt-11.dll
2013-10-07 15:47 - 2013-10-07 15:47 - 00037888 _____ () D:\Programme\GnuPG\libgpg-error-0.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00027968 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 01141056 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00025920 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00059712 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2014-01-29 12:20 - 2014-01-29 12:20 - 00102720 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2014-04-12 17:41 - 2013-10-03 09:42 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll
2014-04-12 16:00 - 2013-09-16 11:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-12-15 08:01 - 2014-12-15 08:01 - 03758192 _____ () D:\Programme\Mozilla Firefox\mozjs.dll
2014-06-19 11:01 - 2014-06-19 11:01 - 03022960 _____ () D:\Programme\Mozilla Thunderbird\mozjs.dll
2014-06-19 11:01 - 2014-06-19 11:01 - 00158832 _____ () D:\Programme\Mozilla Thunderbird\NSLDAP32V60.dll
2014-06-19 11:01 - 2014-06-19 11:01 - 00023152 _____ () D:\Programme\Mozilla Thunderbird\NSLDAPPR32V60.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:4FC01C57

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: SkypeUpdate => 2
HKLM\...\StartupApproved\Run32: => "DivXMediaServer"
HKLM\...\StartupApproved\Run32: => "DivXUpdate"
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\StartupApproved\Run: => "Spotify Web Helper"

========================= Accounts: ==========================

Administrator (S-1-5-21-1027477070-3827058414-3605222199-500 - Administrator - Disabled)
Gast (S-1-5-21-1027477070-3827058414-3605222199-501 - Limited - Disabled)
K (S-1-5-21-1027477070-3827058414-3605222199-1001 - Administrator - Enabled) => C:\Users\K

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.


Details:
AddWin32ServiceFiles: Unable to back up image of service Internet Enhancer Service since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.


Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (01/13/2015 02:56:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: EasySettingsCmdServer.exe, versie: 0.0.0.0, tijdstempel: 0x52e75292
Naam van module met fout: MSVCR100.dll, versie: 10.0.30319.460, tijdstempel: 0x4db13576
Uitzonderingscode: 0x40000015
Foutmarge: 0x0008cb95
Id van proces met fout: 0x18d8
Starttijd van toepassing met fout: 0xEasySettingsCmdServer.exe0
Pad naar toepassing met fout: EasySettingsCmdServer.exe1
Pad naar module met fout: EasySettingsCmdServer.exe2
Rapport-id: EasySettingsCmdServer.exe3
Volledige pakketnaam met fout: EasySettingsCmdServer.exe4
Relatieve toepassings-id van pakket met fout: EasySettingsCmdServer.exe5

Error: (01/12/2015 08:21:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: adobe.photoshop.cs6-patch.exe, versie: 0.0.0.0, tijdstempel: 0x4f556a7c
Naam van module met fout: Imagehlp.dll, versie: 6.3.9600.16438, tijdstempel: 0x5261ffbb
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00003937
Id van proces met fout: 0x125c
Starttijd van toepassing met fout: 0xadobe.photoshop.cs6-patch.exe0
Pad naar toepassing met fout: adobe.photoshop.cs6-patch.exe1
Pad naar module met fout: adobe.photoshop.cs6-patch.exe2
Rapport-id: adobe.photoshop.cs6-patch.exe3
Volledige pakketnaam met fout: adobe.photoshop.cs6-patch.exe4
Relatieve toepassings-id van pakket met fout: adobe.photoshop.cs6-patch.exe5

Error: (12/29/2014 11:25:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: SamToolBox.exe, versie: 0.0.0.0, tijdstempel: 0x4f625b19
Naam van module met fout: SamToolBox.exe, versie: 0.0.0.0, tijdstempel: 0x4f625b19
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00453016
Id van proces met fout: 0x1480
Starttijd van toepassing met fout: 0xSamToolBox.exe0
Pad naar toepassing met fout: SamToolBox.exe1
Pad naar module met fout: SamToolBox.exe2
Rapport-id: SamToolBox.exe3
Volledige pakketnaam met fout: SamToolBox.exe4
Relatieve toepassings-id van pakket met fout: SamToolBox.exe5

Error: (12/24/2014 00:00:41 PM) (Source: Python Service) (EventID: 255) (User: )
Description: Exception : HTTPConnectionPool(host='127.0.0.1', port=35600): Read timed out. (read timeout=60)

Error: (12/11/2014 09:34:37 PM) (Source: MsiInstaller) (EventID: 1024) (User: KPC)
Description: Product: Adobe Reader XI (11.0.09) - Deutsch - Update '{AC76BA86-7AD7-0000-2550-7A8C40011010}' kan niet worden geïnstalleerd. Foutcode: 1625. Windows Installer kan logboekbestanden maken om te helpen bij het oplossen van problemen tijdens het installeren van softwarepakketten. Raadpleeg de volgende koppeling voor aanwijzingen over het inschakelen van ondersteuning via logboekregistratie: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (12/06/2014 03:27:07 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Het volume Wiederherstellung is niet geoptimaliseerd, omdat er een fout is opgetreden: Falscher Parameter. (0x80070057)

Error: (11/26/2014 10:30:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: EasySettingsCmdServer.exe, versie: 0.0.0.0, tijdstempel: 0x52e75292
Naam van module met fout: MSVCR100.dll, versie: 10.0.30319.460, tijdstempel: 0x4db13576
Uitzonderingscode: 0x40000015
Foutmarge: 0x0008cb95
Id van proces met fout: 0x994
Starttijd van toepassing met fout: 0xEasySettingsCmdServer.exe0
Pad naar toepassing met fout: EasySettingsCmdServer.exe1
Pad naar module met fout: EasySettingsCmdServer.exe2
Rapport-id: EasySettingsCmdServer.exe3
Volledige pakketnaam met fout: EasySettingsCmdServer.exe4
Relatieve toepassings-id van pakket met fout: EasySettingsCmdServer.exe5

Error: (11/24/2014 09:22:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.


Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.


System errors:
=============
Error: (01/13/2015 08:58:55 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (01/13/2015 08:58:54 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (01/13/2015 02:56:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: De Superfetch-service is gestopt met de volgende foutcode: 
%%1062.

Error: (01/13/2015 09:00:48 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Internet Enhancer Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.

Error: (01/07/2015 08:54:26 AM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/02/2015 07:32:47 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Bij de schaduwkopieën van volume C: zijn afgebroken omdat de schaduwkopieopslag niet kan worden uitgebreid vanwege een door de gebruiker opgelegde limiet.

Error: (12/27/2014 09:57:28 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (12/27/2014 09:56:58 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (12/14/2014 06:26:26 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (12/14/2014 06:25:56 PM) (Source: DCOM) (EventID: 10010) (User: KPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}


Microsoft Office Sessions:
=========================
Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddWin32ServiceFiles: Unable to back up image of service Internet Enhancer Service since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (01/13/2015 02:56:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert

Error: (01/13/2015 02:56:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasySettingsCmdServer.exe0.0.0.052e75292MSVCR100.dll10.0.30319.4604db13576400000150008cb9518d801d02f38beb5b05aC:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dllff01d4d6-9b2b-11e4-82da-b4b676ef2396

Error: (01/12/2015 08:21:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: adobe.photoshop.cs6-patch.exe0.0.0.04f556a7cImagehlp.dll6.3.9600.164385261ffbbc000000500003937125c01d02e9ce6c2efb4D:\Programme\Adobe Photoshop\Adobe Photoshop CS6\adobe.photoshop.cs6-patch.exeC:\Windows\SYSTEM32\Imagehlp.dll2d6268ef-9a90-11e4-82d9-b4b676ef2396

Error: (12/29/2014 11:25:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: SamToolBox.exe0.0.0.04f625b19SamToolBox.exe0.0.0.04f625b19c000000500453016148001d023b653eb857dD:\Programme\SamsungTVChannelEditor\samtoolbox_win7_v0.11\SamToolBox.exeD:\Programme\SamsungTVChannelEditor\samtoolbox_win7_v0.11\SamToolBox.exea01a5ffa-8fa9-11e4-82d7-b4b676ef2396

Error: (12/24/2014 00:00:41 PM) (Source: Python Service) (EventID: 255) (User: )
Description: Exception : HTTPConnectionPool(host='127.0.0.1', port=35600): Read timed out. (read timeout=60)

Error: (12/11/2014 09:34:37 PM) (Source: MsiInstaller) (EventID: 1024) (User: KPC)
Description: Adobe Reader XI (11.0.09) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011010}1625(NULL)(NULL)(NULL)

Error: (12/06/2014 03:27:07 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: WiederherstellungFalscher Parameter. (0x80070057)

Error: (11/26/2014 10:30:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasySettingsCmdServer.exe0.0.0.052e75292MSVCR100.dll10.0.30319.4604db13576400000150008cb9599401d0095b8e741ac1C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dllcd8fd8e6-754e-11e4-82cd-b4b676ef2396

Error: (11/24/2014 09:22:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert


CodeIntegrity Errors:
===================================
  Date: 2014-12-05 18:24:26.842
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz
Percentage of memory in use: 22%
Total physical RAM: 7813.53 MB
Available physical RAM: 6072.86 MB
Total Pagefile: 9285.54 MB
Available Pagefile: 7247.46 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:48.3 GB) (Free:15.92 GB) NTFS
Drive d: (Divers) (Fixed) (Total:46.86 GB) (Free:15.27 GB) NTFS
Drive e: () (Fixed) (Total:20.74 GB) (Free:2.37 GB) EXT3

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: CA9BA44D)

Partition: GPT Partition Type.

==================== End Of Log ============================
         
FRST.txt

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by K (administrator) on KPC on 14-01-2015 07:11:01
Running from D:\Downloads
Loaded Profile: K (Available profiles: K)
Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() D:\Programme\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
() C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe
(Mozilla Corporation) D:\Programme\Mozilla Thunderbird\thunderbird.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299
ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml
FF Extension: Roomy Bookmarks Toolbar - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\ALone-live@ya.ru.xpi [2014-09-18]
FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10]
FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10]
FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 07:10 - 2015-01-14 07:11 - 00000000 ____D () C:\FRST
2015-01-14 06:41 - 2015-01-14 06:41 - 00000022 _____ () C:\Windows\S.dirmngr
2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList
2015-01-12 20:35 - 2015-01-14 06:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI
2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother
2014-12-29 23:24 - 2014-12-29 23:24 - 00000926 _____ () C:\Users\K\Desktop\SamToolBox.lnk
2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 07:07 - 2014-04-10 20:29 - 01634056 _____ () C:\Windows\WindowsUpdate.log
2015-01-14 07:05 - 2014-04-10 20:35 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001
2015-01-14 07:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-01-14 06:45 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat
2015-01-14 06:45 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat
2015-01-14 06:45 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-14 06:45 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2015-01-14 06:45 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2015-01-14 06:42 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job
2015-01-14 06:41 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-13 20:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-13 20:54 - 2014-11-26 07:43 - 00029664 _____ () C:\Windows\PFRO.log
2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME
2015-01-13 14:57 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-01-13 14:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit
2015-01-13 14:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor
2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc
2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe
2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe
2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify
2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log
2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify
2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-12-25 14:47 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593
2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions

Some content of TEMP:
====================
C:\Users\K\AppData\Local\Temp\avgnt.exe
C:\Users\K\AppData\Local\Temp\bassmod.dll
C:\Users\K\AppData\Local\Temp\dup2patcher.dll
C:\Users\K\AppData\Local\Temp\w64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-06 15:26

==================== End Of Log ============================
         

Geändert von schrauber (14.01.2015 um 08:26 Uhr)

Alt 14.01.2015, 08:26   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



hi,

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.




Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________

__________________

Alt 14.01.2015, 10:13   #3
naranja
 
Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Hallo schrauber,

vielen Dank für deine schnelle Antwort. Oben hatte ich ausversehen die Zitatumgebung verwendet, jetzt nach Ausführen der weiteren Ratschläge korrekt:

AdwCleaner.txt
Code:
ATTFilter
# AdwCleaner v4.107 - Bericht erstellt am 14/01/2015 um 08:32:14
# Aktualisiert 07/01/2015 von Xplode
# Database : 2015-01-13.2 [Live]
# Betriebssystem : Windows 8.1 Pro  (64 bits)
# Benutzername : K - KPC
# Gestartet von : D:\Downloads\AdwCleaner_4.107.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Datei Gelöscht : C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\ALone-live@ya.ru.xpi

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v33.0.3 (x86 de)


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [1539 octets] - [13/04/2014 11:56:57]
AdwCleaner[R1].txt - [1183 octets] - [14/01/2015 08:29:28]
AdwCleaner[S0].txt - [1088 octets] - [13/04/2014 11:58:15]
AdwCleaner[S1].txt - [1009 octets] - [14/01/2015 08:32:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1069 octets] ##########
         
JRT.txt

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 Pro x64
Ran by K on wo 14-01-2015 at  8:36:36,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on wo 14-01-2015 at  8:41:21,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Neues FRST.txt


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by K (administrator) on KPC on 14-01-2015 09:10:21
Running from D:\Downloads
Loaded Profile: K (Available profiles: K)
Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() D:\Programme\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Thisisu) D:\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299
ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Tcpip\Parameters: [DhcpNameServer] 134.95.127.1 134.95.9.74

FireFox:
========
FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml
FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10]
FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10]
FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt
2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT
2015-01-14 07:10 - 2015-01-14 09:10 - 00000000 ____D () C:\FRST
2015-01-14 06:41 - 2015-01-14 08:33 - 00000022 _____ () C:\Windows\S.dirmngr
2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList
2015-01-12 20:35 - 2015-01-14 08:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI
2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother
2014-12-29 23:24 - 2014-12-29 23:24 - 00000926 _____ () C:\Users\K\Desktop\SamToolBox.lnk
2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 09:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-01-14 08:49 - 2014-04-10 20:35 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001
2015-01-14 08:40 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat
2015-01-14 08:40 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat
2015-01-14 08:40 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-14 08:40 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2015-01-14 08:40 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-14 08:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-14 08:34 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job
2015-01-14 08:33 - 2014-11-26 07:43 - 00029970 _____ () C:\Windows\PFRO.log
2015-01-14 08:33 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner
2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log
2015-01-14 08:32 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME
2015-01-13 14:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit
2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor
2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc
2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe
2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe
2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify
2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log
2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify
2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593
2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions

Some content of TEMP:
====================
C:\Users\K\AppData\Local\Temp\avgnt.exe
C:\Users\K\AppData\Local\Temp\bassmod.dll
C:\Users\K\AppData\Local\Temp\dup2patcher.dll
C:\Users\K\AppData\Local\Temp\Quarantine.exe
C:\Users\K\AppData\Local\Temp\sqlite3.dll
C:\Users\K\AppData\Local\Temp\w64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-06 15:26

==================== End Of Log ============================
         
--- --- ---


Danke schon mal für deine Hilfe.
__________________

Alt 14.01.2015, 13:22   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.01.2015, 16:58   #5
naranja
 
Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Hi,

ich hab ESET bei 93% gerade abgebrochen. Er ist zuvor ewig über meine Ubuntu Partition gejagt und hat dort gesucht. Gefunden hatte er davor:

Code:
ATTFilter
D:\Downloads\Microsoft Camera Codec Pack - CHIP-Installer.exe	Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung
D:\Downloads\MyPhoneExplorer - CHIP-Installer.exe	Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung
D:\Downloads\SamToolBox - CHIP-Installer.exe	Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung
D:\Programme\WS_FTP\index.php	PHP/TrojanDownloader.Agent.AJ Trojaner
         
Was aber alles harmlos ist. Auch bei der index.php handelt es sich um einen Fehlalarm.

Nun der SecurityCheck:

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.93  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Avira Desktop      
Windows Defender   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Adobe Flash Player 	16.0.0.257  
 Adobe Reader XI  
 Mozilla Firefox 33.0.3 Firefox out of Date!  
 Mozilla Thunderbird (24.3.0) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Avira Antivir avgnt.exe 
 Avira Antivir avguard.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe   
 Steganos Online Shield OnlineShieldService.exe   
 Steganos Online Shield SteganosBrowserMonitor.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         
und noch eine FRST


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by K (administrator) on KPC on 14-01-2015 15:57:08
Running from D:\Downloads
Loaded Profile: K (Available profiles: K)
Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() D:\Programme\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299
ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Tcpip\Parameters: [DhcpNameServer] 134.95.213.26 134.95.127.1

FireFox:
========
FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml
FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10]
FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10]
FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 15:50 - 2015-01-14 15:50 - 00000428 _____ () C:\Users\K\Desktop\neu.txt
2015-01-14 13:41 - 2015-01-14 13:41 - 00000022 _____ () C:\Windows\S.dirmngr
2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt
2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT
2015-01-14 07:10 - 2015-01-14 15:57 - 00000000 ____D () C:\FRST
2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList
2015-01-12 20:35 - 2015-01-14 15:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI
2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother
2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 15:48 - 2014-04-10 20:35 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001
2015-01-14 15:44 - 2014-12-14 18:49 - 00000000 ____D () C:\Users\K\Desktop\Handybackup
2015-01-14 15:43 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit
2015-01-14 15:43 - 2014-04-12 22:14 - 00000000 ___RD () C:\Users\K\Desktop\Grafik und Co
2015-01-14 15:42 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Multimedia
2015-01-14 15:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Divers
2015-01-14 15:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-14 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-01-14 13:45 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat
2015-01-14 13:45 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat
2015-01-14 13:45 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-14 13:45 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2015-01-14 13:45 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2015-01-14 13:42 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job
2015-01-14 13:41 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-14 09:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-14 08:33 - 2014-11-26 07:43 - 00029970 _____ () C:\Windows\PFRO.log
2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner
2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log
2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME
2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor
2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc
2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe
2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe
2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify
2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log
2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify
2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593
2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions

Some content of TEMP:
====================
C:\Users\K\AppData\Local\Temp\avgnt.exe
C:\Users\K\AppData\Local\Temp\bassmod.dll
C:\Users\K\AppData\Local\Temp\dup2patcher.dll
C:\Users\K\AppData\Local\Temp\w64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-06 15:26

==================== End Of Log ============================
         
--- --- ---



Ich weiß, dass der Abbruch eigentlich nicht die richtige Vorgehensweise ist. Siehst du denn soweit irgendwas schädliches oder sieht es in Ordnung aus?

Vielen Dank nochmal.


Alt 14.01.2015, 18:03   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299
ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299
Emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Frisches FRST log bitte. Bestehen noch Probleme?
__________________
--> Wajam Adware und Proxy-Problem

Alt 14.01.2015, 20:05   #7
naranja
 
Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Probleme bestanden ja schon nicht mehr nachdem ich den Proxy in den Browsern manuell ausgeschaltet habe.

Hier die Logdatei

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-01-2015 01
Ran by K at 2015-01-14 19:04:11 Run:1
Running from D:\Downloads
Loaded Profiles: K (Available profiles: K)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49299;https=127.0.0.1:49299
ProxyServer: [S-1-5-21-1027477070-3827058414-3605222199-1001] => http=127.0.0.1:49299;https=127.0.0.1:49299
Emptytemp:
*****************

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
EmptyTemp: => Removed 378.4 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 19:04:36 ====
         
und das FRST


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-01-2015 01
Ran by K (administrator) on KPC on 14-01-2015 19:07:17
Running from D:\Downloads
Loaded Profiles: K (Available profiles: K)
Platform: Windows 8.1 Pro (X64) OS Language: Duits (Duitsland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() D:\Programme\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) D:\Programme\Mozilla Firefox\firefox.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
() C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DivXMediaServer] => D:\Programme\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [PDFPrint] => D:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => D:\Programme\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify] => C:\Users\K\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [Spotify Web Helper] => C:\Users\K\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [SOS Browser Monitor] => C:\Program Files (x86)\Steganos Online Shield\SteganosBrowserMonitor.exe [72704 2014-09-11] (Steganos Software GmbH)
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\...\MountPoints2: {c106a77d-c210-11e3-8251-b4b676ef2396} - "G:\setup.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1027477070-3827058414-3605222199-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programme\JRE 7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programme\JRE 7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF ProfilePath: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> D:\Programme\JRE 7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ecosia.xml
FF SearchPlugin: C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\searchplugins\ixquick-https---deutsch.xml
FF Extension: NoScript - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-10]
FF Extension: Adblock Plus - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-10]
FF Extension: DownThemAll! - C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\tyqj1lby.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-01-12]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-04-12]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 DirMngr; D:\Programme\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Online Shield Starter Service; C:\Program Files (x86)\Steganos Online Shield\OnlineShieldService.exe [320464 2014-09-11] (Steganos Software GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-12] (Disc Soft Ltd)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22832 2013-07-24] (ELAN Microelectronic Corp.)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 19:01 - 2015-01-14 19:01 - 00000022 _____ () C:\Windows\S.dirmngr
2015-01-14 15:50 - 2015-01-14 15:50 - 00000428 _____ () C:\Users\K\Desktop\neu.txt
2015-01-14 08:41 - 2015-01-14 08:41 - 00000620 _____ () C:\Users\K\Desktop\JRT.txt
2015-01-14 08:36 - 2015-01-14 08:36 - 00000000 ____D () C:\Windows\ERUNT
2015-01-14 07:10 - 2015-01-14 19:07 - 00000000 ____D () C:\FRST
2015-01-12 21:17 - 2015-01-12 21:17 - 00000000 __SHD () C:\Users\K\AppData\Local\EmieBrowserModeList
2015-01-12 20:35 - 2015-01-14 19:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 20:33 - 2015-01-12 20:33 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2015-01-12 20:33 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-01-12 20:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-12 20:33 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-12 20:18 - 2015-01-12 20:18 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-01-08 11:37 - 2015-01-08 11:37 - 00000416 _____ () C:\Windows\BRWMARK.INI
2015-01-08 11:37 - 2015-01-08 11:37 - 00000000 ____D () C:\ProgramData\Brother
2014-12-24 11:58 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-24 11:58 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-24 11:55 - 2014-12-24 11:55 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-14 19:06 - 2014-04-12 08:56 - 00797412 _____ () C:\Windows\system32\perfh013.dat
2015-01-14 19:06 - 2014-04-12 08:56 - 00161992 _____ () C:\Windows\system32\perfc013.dat
2015-01-14 19:06 - 2014-04-10 20:35 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1027477070-3827058414-3605222199-1001
2015-01-14 19:06 - 2014-04-10 20:33 - 02736500 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-14 19:06 - 2013-08-23 00:24 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2015-01-14 19:06 - 2013-08-23 00:24 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2015-01-14 19:01 - 2014-11-26 07:43 - 00030796 _____ () C:\Windows\PFRO.log
2015-01-14 19:01 - 2014-04-12 14:57 - 00000562 _____ () C:\Windows\Tasks\MATLAB R2013a Startup Accelerator.job
2015-01-14 19:01 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-14 15:44 - 2014-12-14 18:49 - 00000000 ____D () C:\Users\K\Desktop\Handybackup
2015-01-14 15:43 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Sicherheit
2015-01-14 15:43 - 2014-04-12 22:14 - 00000000 ___RD () C:\Users\K\Desktop\Grafik und Co
2015-01-14 15:42 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Multimedia
2015-01-14 15:41 - 2014-04-12 22:15 - 00000000 ___RD () C:\Users\K\Desktop\Divers
2015-01-14 15:35 - 2014-04-12 19:28 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-14 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-01-14 09:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-01-14 08:35 - 2014-04-12 19:28 - 00003828 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-14 08:32 - 2014-04-10 21:02 - 00000000 ____D () C:\AdwCleaner
2015-01-14 08:32 - 2014-04-10 20:29 - 01656918 _____ () C:\Windows\WindowsUpdate.log
2015-01-14 07:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-13 14:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\IME
2015-01-13 09:34 - 2014-04-13 09:29 - 00000000 ____D () C:\Users\K\AppData\Roaming\FileAdvisor
2015-01-13 09:32 - 2014-04-12 08:29 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2015-01-12 21:59 - 2014-06-19 13:12 - 00000000 ____D () C:\Users\K\AppData\Roaming\vlc
2015-01-12 20:56 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Web
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\Users\K\AppData\Roaming\Malwarebytes
2015-01-12 20:33 - 2014-04-10 21:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 20:28 - 2013-08-22 15:44 - 05011080 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-12 20:25 - 2014-06-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-12 20:25 - 2014-04-12 08:22 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-12 20:21 - 2014-07-09 18:46 - 00000000 ____D () C:\Users\K\AppData\Local\Adobe
2015-01-12 20:21 - 2014-04-10 20:30 - 00000000 ____D () C:\Users\K\AppData\Roaming\Adobe
2015-01-08 20:50 - 2014-05-28 18:43 - 00000000 ____D () C:\Users\K\AppData\Roaming\Spotify
2015-01-07 20:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-30 22:43 - 2014-11-30 19:51 - 00006550 _____ () C:\Windows\setupact.log
2014-12-29 19:35 - 2014-05-28 18:45 - 00000000 ____D () C:\Users\K\AppData\Local\Spotify
2014-12-27 22:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-12-25 13:33 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-12-24 11:57 - 2014-06-19 20:02 - 00003800 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1397160593
2014-12-24 11:57 - 2014-04-10 21:09 - 00000790 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-12-15 08:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PolicyDefinitions

Some content of TEMP:
====================
C:\Users\K\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-06 15:26

==================== End Of Log ============================
         
--- --- ---

Alt 15.01.2015, 07:00   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Wajam Adware und Proxy-Problem - Standard

Wajam Adware und Proxy-Problem



Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Wajam Adware und Proxy-Problem
adware, antivir, antivirus, avira, browser, converter, cpu, desktop, dllhost.exe, firefox, flash player, helper, internet, internetenhancer, mp3, object, problem, programm, proxy, prozesse, rundll, scan, security, services.exe, software, svchost.exe, usb, wajam, windows




Ähnliche Themen: Wajam Adware und Proxy-Problem


  1. Ads By Wajam entfernen
    Anleitungen, FAQs & Links - 08.11.2015 (2)
  2. NACH WAJAM hab ich eine Art Proxy Virus
    Plagegeister aller Art und deren Bekämpfung - 18.08.2015 (17)
  3. Problem mit Proxy-Server
    Log-Analyse und Auswertung - 12.02.2015 (22)
  4. Proxy server Problem: Einige Seiten lassen sich nicht öffnen
    Netzwerk und Hardware - 09.01.2015 (1)
  5. Wajam-Adware und anschließendes Proxy-Problem
    Plagegeister aller Art und deren Bekämpfung - 07.12.2014 (9)
  6. Interneteinstellungen nach Wajam-Adware nicht mehr korrekt
    Plagegeister aller Art und deren Bekämpfung - 25.10.2014 (3)
  7. haufenweise Viren , Installationsaufforderungen, unerwünschte Werbebanner usw. Problem nach Löschung proxy server verweigern die Verbindung
    Plagegeister aller Art und deren Bekämpfung - 20.10.2014 (13)
  8. Samsung Monte will Proxy-Passwort, aber kein Proxy installiert
    Smartphone, Tablet & Handy Security - 16.06.2014 (2)
  9. Trojaner gefunden TR/Dldr.Agent.314440 und verschiedene Adwares ADWARE/EoRezo.AF, ADWARE/Adware.Gen7, ADWARE/AgentCV.A.2919
    Log-Analyse und Auswertung - 02.05.2014 (19)
  10. ADWARE/Adware.Gen7 .....Problem
    Log-Analyse und Auswertung - 07.10.2013 (8)
  11. Proxy-Server Problem
    Log-Analyse und Auswertung - 20.04.2013 (30)
  12. PC von Adware.Agent.ZGen, Adware.ClickPotato, Adware.ShopperReports, Adware.Hotbar, Adwa angegriffen
    Mülltonne - 30.06.2011 (0)
  13. Sparkassen-Trojaner / Evtl. Proxy-Problem
    Log-Analyse und Auswertung - 10.05.2011 (20)
  14. Proxy.Agent.FM.1 Problem
    Log-Analyse und Auswertung - 15.05.2007 (2)
  15. Problem mit TR/Proxy.OSS.DLN
    Plagegeister aller Art und deren Bekämpfung - 25.12.2006 (2)
  16. Problem mit TR/Proxy.Horst.Gen
    Mülltonne - 17.11.2006 (0)

Zum Thema Wajam Adware und Proxy-Problem - Hallo zusammen, ich scheine ein identisches Problem wie http://www.trojaner-board.de/161536-...y-problem.html zu haben. Ich habe aber mal der Übersichtlichkeit halber ein neues Thema aufgemacht, da letzteres auch nicht abschließend geklärt wurde. Ich - Wajam Adware und Proxy-Problem...
Archiv
Du betrachtest: Wajam Adware und Proxy-Problem auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.