Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-11-2013
Ran by Steidle at 2013-11-19 17:05:49 Run:1
Running from C:\Users\Steidle\Downloads
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://do-search.com/?type=hp&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://do-search.com/?type=sc&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX
CHR HomePage: hxxp://do-search.com/?type=hp&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX
C:\Users\Steidle\AppData\Local\Temp\582f07fd-df64-4ab9-bf15-19c42fe849cf.exe
C:\Users\Steidle\AppData\Local\Temp\AntiToolbarPackage.exe
C:\Users\Steidle\AppData\Local\Temp\avgnt.exe
C:\Users\Steidle\AppData\Local\Temp\AVG_AV_Setup.exe
C:\Users\Steidle\AppData\Local\Temp\Quarantine.exe
C:\Users\Steidle\AppData\Local\Temp\SHSetup.exe
*****************
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
CHR HomePage: hxxp://do-search.com/?type=hp&ts=1384554182&from=tugs&uid=HGSTXHTS541010A9E680_JA1003BVGR9HEPGR9HEPX ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\Steidle\AppData\Local\Temp\582f07fd-df64-4ab9-bf15-19c42fe849cf.exe => Moved successfully.
C:\Users\Steidle\AppData\Local\Temp\AntiToolbarPackage.exe => Moved successfully.
C:\Users\Steidle\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\Steidle\AppData\Local\Temp\AVG_AV_Setup.exe => Moved successfully.
C:\Users\Steidle\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Steidle\AppData\Local\Temp\SHSetup.exe => Moved successfully.
==== End of Fixlog ====
Zum Thema Do-Search Startseite in allen Brwosern - Code:
Alles auswählen Aufklappen ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-11-2013
Ran by Steidle at 2013-11-19 17:05:49 Run:1
Running from C:\Users\Steidle\Downloads
Boot Mode: - Do-Search Startseite in allen Brwosern...