30.06.2004, 17:49
|
#18 |
| Hijacker , Directwebsearch Zitat:
Zitat von BigMitt Kaspersky Online hat in der winupd.exe folgenden Trojaner gefunden: TrojanDropper.Win32.Small.ig Wie geh ich weiter vor? | Hallo BigMitt, - aktualisiere bitte eScan. (siehe Signatur).
- Boote den Rechner im abgesicherten Modus neu
- Fixe mit HijackThis folgendes:
Zitat:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = h*tp://weba.directwebsearch.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h*tp://weba.directwebsearch.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h*tp://weba.directwebsearch.net/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h*tp://weba.directwebsearch.net/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h*tp://weba.directwebsearch.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h*tp://weba.directwebsearch.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = h*tp://weba.directwebsearch.net/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = h**p://weba.directwebsearch.net/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://weba.directwebsearch.net/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://weba.directwebsearch.net/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h*tp://weba.directwebsearch.net/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://weba.directwebsearch.net/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = h**p://weba.directwebsearch.net/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h*tp://weba.directwebsearch.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = h*tp://weba.directwebsearch.net/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = h*tp://weba.directwebsearch.net/search.html
O1 - Hosts: 69.31.79.101 auto.search.msn.com
O4 - HKLM\..\Run: [winupd] C:\WINNT\system32\winupd.exe | - Scanne den kompletten Rechner noch einmal mit eScan (immer noch im abgesicherten Modus
- Boote den Rechner neu
- Erstelle ein neues Log
__________________
__________________ |