schrauber | 23.01.2015 21:03 | Java, Adobe und Thunderbird updaten.
in dem folgenden Fix bitte alle Namen die du durch *** ersetze hast wieder korrigieren bevor du den Fix speicherst!
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\101_cortica_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\102_dealply_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\103_intext_5_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\104_jollywallet_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\105_corticas_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\108_icm_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\116_ads_only_5_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\117_coupons_intext_ads_5_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\119_similar_web_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\120_luck_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\123_intext_adv_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\124_superfish_no_search_no_coupons_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\125_arcadi2_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\126_revizer_ws_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\127_revizer_p_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\128_superfish_pricora_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\129_widdit_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\135_arcadi3_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\138_getdeal_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\141_corticas_ru_m.js.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\142_intext_fa_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\155_ibario_pops_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\159_cortica_rollover_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\171_arcadi2_sourceID_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\175_coolmirage_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\178_revizer_ws_dynamic_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\179_revizer_p_dynamic_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\91_monetizationLoader.js.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\92_superfish_m.js
C:\Users\...\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.25.48_0\extensionData\plugins\93_superfish_no_coupons_m.js
C:\Users\...\AppData\Roaming\SCheck
C:\Users\...\AppData\Roaming\Windows Net Data
C:\Users\.......-PC\Downloads\chiptuning_dualcore - CHIP-Installer(1).exe
C:\Users\.......-PC\Downloads\chiptuning_dualcore - CHIP-Installer(2).exe
C:\Users\.......-PC\Downloads\chiptuning_dualcore - CHIP-Installer.exe
C:\Users\.......-PC\Downloads\Rufus - CHIP-Installer.exe
C:\Users\.......-PC\Downloads\san2015x-2115_CB-DL-Manager.exe
C:\Users\.......-PC\Downloads\SiSoft Sandra Lite 2015 - CHIP-Installer(1).exe
C:\Users\.......-PC\Downloads\SiSoft Sandra Lite 2015 - CHIP-Installer.exe
HKU\S-1-5-18\...\RunOnce: [{91140000-0011-0000-0000-0000000FF1CE}] => C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90140000-001A-0407-0000-0000000FF1CE}] => C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
S3 WatAdminSvc; C:\Windows\system32\Wat\WatAdminSvc.exe [1343400 2013-11-18] () [File not signed]
C:\Windows\system32\Wat\WatAdminSvc.exe
Emptytemp:
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
- Starte nun FRST erneut und klicke den Entfernen Button.
- Das Tool erstellt eine Fixlog.txt.
- Poste mir deren Inhalt.
http://www.deeprybka.trojaner-board....r/wraioneu.PNG- Lade Dir bitte Windows Repair - All in one von tweaking.com hier herunter und installiere es.
- Deaktiviere bitte (wenn möglich) Dein Antivirusprogramm.
- Bedenke, dass die einzelnen Reparaturen einige Zeit benötigen. Starte keine anderen Anwendungen in dieser Zeit.
- Starte das Programm und führe die Punkte 1-5 durch. (Siehe Bildanleitung)
- Achte darauf, dass bei Dir die Häkchen so gesetzt sind wie unter Punkt 4.
- Setze auch ein Häkchen bei "Restart/Shutdown System" und klicke "Restart System" an bevor Du Punkt 5 durchführst.
http://deeprybka.trojaner-board.de/b...srepair271.png |