|
Plagegeister aller Art und deren Bekämpfung: Nach Snap.do deinstallation Nat typ geändertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.12.2012, 22:11 | #31 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Nach Snap.do deinstallation Nat typ geändertCode:
ATTFilter C:\Users\Phil\Client1.7.0.586601.7z
__________________ Logfiles bitte immer in CODE-Tags posten |
12.12.2012, 17:40 | #32 |
| Nach Snap.do deinstallation Nat typ geändert Wenn ich den Ordner mit winrar öffne steht da was von ABP woraus ich schließe das das von einem f2p spiel ist welches so heißt. Hab das immernoch aufm pc.
__________________ |
13.12.2012, 13:11 | #33 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Nach Snap.do deinstallation Nat typ geändertZitat:
Aus welcher Quelle hast du diese Datei? Was soll der Inhalt der 7Z-Datei bezwecken?
__________________ |
13.12.2012, 22:17 | #34 |
| Nach Snap.do deinstallation Nat typ geändert Also ABP ist ein inline free to play spiel welches ich mir vor ein paar monaten gewownloadet habe ( spiele es jedoch nicht mehr ) Was diese Datei bezweckt weiss ich nicht aber es hat wahrscheinlich etwas mit dem Spiel zu tun |
14.12.2012, 10:05 | #35 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Nach Snap.do deinstallation Nat typ geändertFixen mit OTL
Code:
ATTFilter :OTL O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O4 - HKU\S-1-5-21-2348945888-1469418193-1697157937-1001..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\S-1-5-21-2348945888-1469418193-1697157937-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1 O20 - AppInit_DLLs: (c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll) - File not found :Files C:\PROGRA~2\Raptr c:\progra~3\browse~1 C:\Users\Phil\APB_Reloaded_Installer.exe C:\Users\Phil\Client1.7.0.586601.7z C:\$Recycle.Bin\S-1-5-21-2348945888-1469418193-1697157937-1001\$d9d4daf50f88dc16ae9de30528a9231a C:\$Recycle.Bin\S-1-5-18\$d9d4daf50f88dc16ae9de30528a9231a ipconfig /flushdns /c :Commands [purity] [emptytemp] [resethosts]
__________________ Logfiles bitte immer in CODE-Tags posten |
16.12.2012, 12:57 | #36 |
| Nach Snap.do deinstallation Nat typ geändertCode:
ATTFilter All processes killed ========== OTL ========== 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_USERS\S-1-5-21-2348945888-1469418193-1697157937-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Raptr deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully. Registry value HKEY_USERS\S-1-5-21-2348945888-1469418193-1697157937-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HideSCAHealth deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll deleted successfully. ========== FILES ========== C:\PROGRA~2\Raptr\resources\sound folder moved successfully. C:\PROGRA~2\Raptr\resources\locale folder moved successfully. C:\PROGRA~2\Raptr\resources\images\webwidget folder moved successfully. C:\PROGRA~2\Raptr\resources\images\webbrowser folder moved successfully. C:\PROGRA~2\Raptr\resources\images\pokes folder moved successfully. C:\PROGRA~2\Raptr\resources\images\navdock folder moved successfully. C:\PROGRA~2\Raptr\resources\images\ingame folder moved successfully. C:\PROGRA~2\Raptr\resources\images\im_icons folder moved successfully. C:\PROGRA~2\Raptr\resources\images\emoticons folder moved successfully. C:\PROGRA~2\Raptr\resources\images\dl_mgr folder moved successfully. C:\PROGRA~2\Raptr\resources\images\dinos folder moved successfully. C:\PROGRA~2\Raptr\resources\images\bundle\logo folder moved successfully. C:\PROGRA~2\Raptr\resources\images\bundle\fte_signup folder moved successfully. C:\PROGRA~2\Raptr\resources\images\bundle\detect folder moved successfully. C:\PROGRA~2\Raptr\resources\images\bundle folder moved successfully. C:\PROGRA~2\Raptr\resources\images folder moved successfully. C:\PROGRA~2\Raptr\resources folder moved successfully. C:\PROGRA~2\Raptr\PyQt4\plugins\phonon_backend folder moved successfully. C:\PROGRA~2\Raptr\PyQt4\plugins\imageformats folder moved successfully. C:\PROGRA~2\Raptr\PyQt4\plugins\codecs folder moved successfully. C:\PROGRA~2\Raptr\PyQt4\plugins folder moved successfully. C:\PROGRA~2\Raptr\PyQt4 folder moved successfully. C:\PROGRA~2\Raptr\plugins folder moved successfully. C:\PROGRA~2\Raptr\ca-certs folder moved successfully. Folder move failed. C:\PROGRA~2\Raptr scheduled to be moved on reboot. File\Folder c:\progra~3\browse~1 not found. C:\Users\Phil\APB_Reloaded_Installer.exe moved successfully. C:\Users\Phil\Client1.7.0.586601.7z moved successfully. File\Folder C:\$Recycle.Bin\S-1-5-21-2348945888-1469418193-1697157937-1001\$d9d4daf50f88dc16ae9de30528a9231a not found. File\Folder C:\$Recycle.Bin\S-1-5-18\$d9d4daf50f88dc16ae9de30528a9231a not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Phil\Downloads\cmd.bat deleted successfully. C:\Users\Phil\Downloads\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User User: Phil ->Temp folder emptied: 3193585 bytes ->Temporary Internet Files folder emptied: 681195 bytes ->Java cache emptied: 266576 bytes ->Google Chrome cache emptied: 7921915 bytes ->Opera cache emptied: 188 bytes ->Flash cache emptied: 725 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 587442 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 48310114 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 751 bytes RecycleBin emptied: 6082779278 bytes Total Files Cleaned = 5.859,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.69.0 log created on 12112012_182944 Files\Folders moved on Reboot... C:\PROGRA~2\Raptr folder moved successfully. C:\Users\Phil\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
16.12.2012, 15:06 | #37 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Nach Snap.do deinstallation Nat typ geändert Eine Kontrolle mit OTL bitte:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Nach Snap.do deinstallation Nat typ geändert |
adware.gameplaylabs, anti maleware, auf einmal, chrome, conduitsearch, conduitsearch entfernen, deaktiviert, deinstallation, eingefangen, einstellungen, geändert, google chrome, infektion, pum.disabled.securitycenter, pup.blabbers, snap.do, spielen, spyhunter, spyhunter entfernen, spyware.password, spyware.zbot, systems, systemsteuerung, trojan.0access, trojan.lameshield |