|
Plagegeister aller Art und deren Bekämpfung: Unerwünschte GoogleweiterleitungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.03.2011, 15:32 | #16 |
| Unerwünschte Googleweiterleitung Hier die Gmer-Ausgabe: Code:
ATTFilter GMER 1.0.15.15530 - hxxp://www.gmer.net Rootkit scan 2011-03-16 15:31:10 Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST932032 rev.0003 Running: qmr6qywv.exe; Driver: C:\Users\Stefan\AppData\Local\Temp\uxryqpob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 81A47589 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81A6C092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ? C:\Windows\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. ! ? C:\Users\Stefan\AppData\Local\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. ! ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe[2400] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75A75E25] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) Device \Driver\ACPI_HAL \Device\0000004b halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd61bfc73 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd61bfc73@307c30d56083 0xEB 0x6F 0xAC 0xE6 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd61bfc73 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd61bfc73@307c30d56083 0xEB 0x6F 0xAC 0xE6 ... ---- EOF - GMER 1.0.15 ---- Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 15:43:36 on 16.03.2011 OS: Windows 7 Home Premium Edition (Build 7600), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.15 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "GlaryInitialize.job" - "Glarysoft Ltd" - C:\Program Files\Glary Utilities\initialize.exe [Control Panel Objects] -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\MLCFG32.CPL "QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "AsIO" (AsIO) - ? - C:\Windows\System32\drivers\AsIO.sys (File found, but it contains no detailed information) "AsUpIO" (AsUpIO) - ? - C:\Windows\System32\drivers\AsUpIO.sys (File found, but it contains no detailed information) "catchme" (catchme) - ? - C:\Users\Stefan\AppData\Local\Temp\catchme.sys (File not found) "mbr" (mbr) - ? - C:\cofi.exe\mbr.sys (Hidden registry entry, rootkit activity | File not found) "regi" (regi) - "InterVideo" - C:\Windows\System32\drivers\regi.sys "uxryqpob" (uxryqpob) - ? - C:\Users\Stefan\AppData\Local\Temp\uxryqpob.sys (Hidden registry entry, rootkit activity | File not found) "ZTE Diagnostic Port" (ZTEusbser6k) - ? - C:\Windows\System32\DRIVERS\ZTEusbser6k.sys (File not found) "ZTE Mass Storage Filter Driver" (massfilter) - ? - C:\Windows\System32\drivers\massfilter.sys (File not found) "ZTE NMEA Port" (ZTEusbnmea) - ? - C:\Windows\System32\DRIVERS\ZTEusbnmea.sys (File not found) "ZTE Proprietary USB Driver" (ZTEusbmdm6k) - ? - C:\Windows\System32\DRIVERS\ZTEusbmdm6k.sys (File not found) [Explorer] -----( HKLM\Software\Classes\Protocols\Filter )----- {807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {653DCCC2-13DB-45B2-A389-427885776CFE} "Activities Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplact.dll {3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {124597D8-850A-41AE-849C-017A4FA99CA2} "Buttons Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll {D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL {72923739-5A47-40A3-9895-25AF0DFBB9E4} "Glary Utilities Context Menu Shell Extension" - "Glarysoft Ltd" - C:\PROGRA~1\GLARYU~1\CONTEX~1.DLL {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL {3BEABCC1-BF31-42df-88D9-A2955D6B8528} "IntelliPoint Sensitivity Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplsens.dll {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL {00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\MLSHEXT.DLL {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? - (File not found | COM-object registry key not found) {1184D0ED-DBCE-4170-8DBB-4D0C3905DA85} "Touch Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcpltouch.dll {AF90F543-6A3A-4C1B-8B16-ECEC073E69BE} "Wheel Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll {20082881-FC36-4E47-9A7A-644C95FF749F} "Wireless Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplwir.dll [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10m.ocx / hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll {FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Shortcut exists | File exists) "desktop.ini" - ? - C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )----- "StartupPrograms" - ? - rdpclip (File not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "ASUSWebStorage" - "ecareme" - C:\Program Files\ASUS\ASUS WebStorage\3.0.88.169\AsusWSPanel.exe /S "BCSSync" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices "CapsHook" - "ASUSTek Computer Inc." - AsusSender.exe C:\Program Files\ASUS\CapsHook\CapsHook.exe "HotkeyMon" - "ASUSTek Computer Inc." - AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe "HotkeyService" - "ASUSTek Computer Inc." - AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe "IAStorIcon" - "Intel Corporation" - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe "IntelliPoint" - "Microsoft Corporation" - "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" "iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe" "LiveUpdate" - "ASUSTek Computer Inc." - AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto "PenWrite" - ? - C:\Program Files\ASUS\PenWrite\PenWrite.exe AutoRun "QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" "TouchHomeKey" - ? - C:\Program Files\asus\TouchHomeKey\TouchHomeKey.exe [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "Asus Launcher Service" (AsusService) - ? - C:\Windows\System32\AsusService.exe (File found, but it contains no detailed information) "Asus process privilege adjust service" (AsusUacSvc) - ? - C:\Program Files\asus\2DoorWayTouchSuite\AsusUacSvc.exe "Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "IviRegMgr" (IviRegMgr) - "InterVideo" - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Code:
ATTFilter MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: ASUSTeK Computer INC. BIOS Manufacturer: American Megatrends Inc. System Manufacturer: ASUSTeK Computer INC. System Product Name: T101MT Logical Drives Mask: 0x0000000c Kernel Drivers (total 168): 0x81A04000 \SystemRoot\system32\ntkrnlpa.exe 0x81E14000 \SystemRoot\system32\halmacpi.dll 0x81889000 \SystemRoot\system32\kdcom.dll 0x87C00000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x87C78000 \SystemRoot\system32\PSHED.dll 0x87C89000 \SystemRoot\system32\BOOTVID.dll 0x87C91000 \SystemRoot\system32\CLFS.SYS 0x87CD3000 \SystemRoot\system32\CI.dll 0x87D7E000 \SystemRoot\system32\drivers\Wdf01000.sys 0x87DEF000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x87E2C000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x87E74000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x87E7D000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x87E85000 \SystemRoot\system32\DRIVERS\pci.sys 0x87EAF000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x87EBA000 \SystemRoot\System32\drivers\partmgr.sys 0x87ECB000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x87ED3000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x87EDE000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x87EEE000 \SystemRoot\System32\drivers\volmgrx.sys 0x87F39000 \SystemRoot\System32\drivers\mountmgr.sys 0x88003000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x881B8000 \SystemRoot\system32\DRIVERS\atapi.sys 0x881C1000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x881E4000 \SystemRoot\system32\DRIVERS\msahci.sys 0x881EE000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x87F4F000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x87F58000 \SystemRoot\system32\drivers\fltmgr.sys 0x87F8C000 \SystemRoot\system32\drivers\fileinfo.sys 0x88216000 \SystemRoot\System32\Drivers\Ntfs.sys 0x88345000 \SystemRoot\System32\Drivers\msrpc.sys 0x88370000 \SystemRoot\System32\Drivers\ksecdd.sys 0x88383000 \SystemRoot\System32\Drivers\cng.sys 0x883E0000 \SystemRoot\System32\drivers\pcw.sys 0x883EE000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x88410000 \SystemRoot\system32\drivers\ndis.sys 0x884C7000 \SystemRoot\system32\drivers\NETIO.SYS 0x88505000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8863D000 \SystemRoot\System32\drivers\tcpip.sys 0x88786000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x887B7000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x887F6000 \SystemRoot\System32\Drivers\spldr.sys 0x88600000 \SystemRoot\System32\drivers\rdyboost.sys 0x8862D000 \SystemRoot\System32\Drivers\mup.sys 0x8852A000 \SystemRoot\System32\drivers\hwpolicy.sys 0x88532000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x88564000 \SystemRoot\system32\DRIVERS\disk.sys 0x88575000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x8AA1F000 \SystemRoot\System32\Drivers\Null.SYS 0x8ABED000 \SystemRoot\System32\Drivers\Beep.SYS 0x8ABF4000 \SystemRoot\System32\drivers\vga.sys 0x885A7000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8AA00000 \SystemRoot\System32\drivers\watchdog.sys 0x8AA0D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8AA15000 \SystemRoot\system32\drivers\rdpencdd.sys 0x885C8000 \SystemRoot\system32\drivers\rdprefmp.sys 0x885D0000 \SystemRoot\System32\Drivers\Msfs.SYS 0x885DB000 \SystemRoot\System32\Drivers\Npfs.SYS 0x885E9000 \SystemRoot\system32\DRIVERS\tdx.sys 0x88400000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x87F9D000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8BA38000 \SystemRoot\system32\drivers\afd.sys 0x8BA92000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8BA99000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8BAB8000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8BAC9000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8BAD7000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8BAEA000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8BAFA000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8BB3B000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8BB45000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8BB4F000 \SystemRoot\System32\drivers\discache.sys 0x8BB5B000 \SystemRoot\System32\Drivers\dfsc.sys 0x8BB73000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8BB81000 \SystemRoot\system32\drivers\AsUpIO.sys 0x8BB83000 \SystemRoot\system32\drivers\AsIO.sys 0x8BB85000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8BBA6000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8BC29000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x8C131000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8BBB8000 \SystemRoot\System32\drivers\dxgmms1.sys 0x8BC00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8C23A000 \SystemRoot\system32\DRIVERS\athr.sys 0x8C367000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x8C371000 \SystemRoot\system32\DRIVERS\L1C62x86.sys 0x8C381000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8C38C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8C3D7000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8C3E6000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8C200000 \SystemRoot\system32\DRIVERS\kbfiltr.sys 0x8C208000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8BA00000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x8C215000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8C217000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8C224000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x8C228000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8C1E8000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x8C231000 \SystemRoot\System32\Drivers\RootMdm.sys 0x8BBF1000 \SystemRoot\system32\drivers\modem.sys 0x88200000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x87FCF000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8C1F5000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x87E00000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x87FE7000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8C430000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8C447000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8C45E000 \SystemRoot\system32\DRIVERS\RimSerial.sys 0x8C465000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8C467000 \SystemRoot\system32\DRIVERS\ks.sys 0x8C49B000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8C4A9000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8C4ED000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8C4FE000 \SystemRoot\system32\drivers\HdAudio.sys 0x8C54E000 \SystemRoot\system32\drivers\portcls.sys 0x8C57D000 \SystemRoot\system32\drivers\drmk.sys 0x8C596000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8C5A1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8C5B4000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8C5BB000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8C5C6000 \SystemRoot\system32\DRIVERS\MTConfig.sys 0x8E8D0000 \SystemRoot\System32\win32k.sys 0x8C5CE000 \SystemRoot\System32\drivers\Dxapi.sys 0x8C5D8000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x8C400000 \SystemRoot\system32\DRIVERS\SMIksdrv.sys 0x80E08000 \SystemRoot\system32\DRIVERS\SMIEXP.SYS 0x81077000 \SystemRoot\system32\DRIVERS\monitor.sys 0x81082000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8EB30000 \SystemRoot\System32\TSDDD.dll 0x8AA26000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x8108F000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x8EB60000 \SystemRoot\System32\cdd.dll 0x810A0000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x81122000 \SystemRoot\system32\DRIVERS\usbprint.sys 0x8EB80000 \SystemRoot\System32\ATMFD.DLL 0x8118B000 \SystemRoot\system32\DRIVERS\point32.sys 0x81194000 \SystemRoot\system32\drivers\luafv.sys 0x811AF000 \SystemRoot\system32\drivers\WudfPf.sys 0x811C9000 \SystemRoot\system32\DRIVERS\lltdio.sys 0xA3C28000 \SystemRoot\system32\DRIVERS\nwifi.sys 0xA3C6E000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA3C7E000 \SystemRoot\system32\DRIVERS\rspndr.sys 0xA3C9A000 \SystemRoot\system32\drivers\HTTP.sys 0xA3D1F000 \SystemRoot\system32\DRIVERS\bowser.sys 0xA3D38000 \SystemRoot\System32\drivers\mpsdrv.sys 0xA3D4A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xA3D6D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0xA3DA8000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0xA7423000 \SystemRoot\system32\drivers\peauth.sys 0xA74BA000 \SystemRoot\system32\drivers\regi.sys 0xA74BC000 \SystemRoot\System32\Drivers\secdrv.SYS 0xA74C6000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xA74E7000 \SystemRoot\System32\drivers\tcpipreg.sys 0xA74F4000 \SystemRoot\System32\DRIVERS\srv2.sys 0xA7543000 \SystemRoot\System32\DRIVERS\srv.sys 0xA7595000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS 0xAF475000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0xAF47E000 \??\C:\Users\Stefan\AppData\Local\Temp\catchme.sys 0xAF49F000 \??\C:\Users\Stefan\AppData\Local\Temp\uxryqpob.sys 0xAF4B7000 \SystemRoot\System32\Drivers\BTHUSB.sys 0xAF4C9000 \SystemRoot\System32\Drivers\bthport.sys 0xAF52D000 \SystemRoot\system32\DRIVERS\rfcomm.sys 0xAF551000 \SystemRoot\system32\DRIVERS\BthEnum.sys 0xAF55E000 \SystemRoot\system32\DRIVERS\bthpan.sys 0xAF579000 \SystemRoot\system32\DRIVERS\bthmodem.sys 0x77A00000 \Windows\System32\ntdll.dll 0x47F30000 \Windows\System32\smss.exe 0x77C40000 \Windows\System32\apisetschema.dll 0x007A0000 \Windows\System32\autochk.exe Processes (total 68): 0 System Idle Process 4 System 248 C:\Windows\System32\smss.exe 352 csrss.exe 396 C:\Windows\System32\wininit.exe 404 csrss.exe 452 C:\Windows\System32\services.exe 488 C:\Windows\System32\winlogon.exe 508 C:\Windows\System32\lsass.exe 516 C:\Windows\System32\lsm.exe 608 C:\Windows\System32\svchost.exe 692 C:\Windows\System32\svchost.exe 788 C:\Windows\System32\svchost.exe 824 C:\Windows\System32\svchost.exe 900 C:\Windows\System32\svchost.exe 1024 C:\Windows\System32\svchost.exe 1104 C:\Windows\System32\wisptis.exe 1168 C:\Windows\System32\svchost.exe 1348 C:\Windows\System32\wisptis.exe 1360 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe 1400 C:\Windows\System32\dwm.exe 1568 C:\Windows\System32\spoolsv.exe 1620 C:\Windows\System32\svchost.exe 1752 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 1760 C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe 1768 C:\Windows\System32\igfxtray.exe 1780 C:\Windows\System32\hkcmd.exe 1796 C:\Windows\System32\igfxpers.exe 1808 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 1844 C:\Program Files\Microsoft IntelliPoint\ipoint.exe 1860 C:\Windows\System32\igfxsrvc.exe 1876 C:\Program Files\ASUS\TouchHomeKey\TouchHomeKey.exe 1884 C:\Program Files\iTunes\iTunesHelper.exe 512 C:\Program Files\ASUS\ASUS WebStorage\3.0.88.169\AsusWSPanel.exe 1868 C:\Program Files\ASUS\2DoorWayTouchSuite\AsusUacSvc.exe 392 C:\Program Files\Common Files\Java\Java Update\jusched.exe 1700 C:\Windows\System32\svchost.exe 1088 C:\Program Files\ASUS\CapsHook\CapsHook.exe 2060 C:\Program Files\EeePC\HotkeyService\HotkeyService.exe 2092 C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 2236 C:\Windows\System32\taskhost.exe 2400 C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe 2468 unsecapp.exe 2548 C:\Windows\System32\svchost.exe 2676 C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe 2952 WmiPrvSE.exe 3040 C:\Program Files\iPod\bin\iPodService.exe 3304 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 3348 C:\Windows\System32\svchost.exe 3440 C:\Windows\System32\SearchIndexer.exe 3552 C:\Program Files\ASUS\ASUS WebStorage\3.0.88.169\AsusWSService.exe 4068 C:\Windows\System32\svchost.exe 1736 C:\Program Files\Windows Media Player\wmpnetwk.exe 4196 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 4368 C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe 324 C:\Windows\explorer.exe 4076 C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 5100 C:\Program Files\Mozilla Thunderbird\thunderbird.exe 4640 WmiPrvSE.exe 4592 C:\Program Files\Mozilla Firefox\firefox.exe 3424 C:\Windows\System32\SearchProtocolHost.exe 5748 C:\Windows\System32\SearchFilterHost.exe 5436 C:\Windows\explorer.exe 3488 C:\Windows\System32\audiodg.exe 6128 dllhost.exe 3232 dllhost.exe 4496 C:\Users\Stefan\Downloads\MBRCheck.exe 2744 C:\Windows\System32\conhost.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000004a`83900000 PhysicalDrive0 Model Number: ST9320325AS, Rev: 0003SDM1 Size Device Name MBR Status -------------------------------------------- 298 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 Done! Geändert von creole (16.03.2011 um 15:48 Uhr) |
16.03.2011, 16:12 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Unerwünschte Googleweiterleitung Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs.
__________________Denk dran beide Tools zu updaten vor dem Scan!!
__________________ |
18.03.2011, 12:05 | #18 |
| Unerwünschte Googleweiterleitung Also hier Super-Anitspyware:
__________________Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 03/18/2011 at 11:53 AM Application Version : 4.49.1000 Core Rules Database Version : 6620 Trace Rules Database Version: 4432 Scan type : Quick Scan Total Scan Time : 00:11:07 Memory items scanned : 714 Memory threats detected : 0 Registry items scanned : 2500 Registry threats detected : 0 File items scanned : 6760 File threats detected : 201 Adware.Tracking Cookie ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .apmebf.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaplex.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .doubleclick.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] adx.chip.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaplex.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zanox-affiliate.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad4.adfarm1.adition.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad2.adfarm1.adition.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracking.quisma.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.burstnet.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstnet.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .myroitracking.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertiseyourgame.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertiseyourgame.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertiseyourgame.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] tracking.mlsat02.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .webmasterplan.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.zanox-affiliate.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.active-tracking.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.active-tracking.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.active-tracking.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adviva.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] de.sitestat.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zanox.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .webmasterplan.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .webmasterplan.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .traffictrack.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] bmmg.panda-media.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.quartermedia.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.quartermedia.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.quartermedia.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.quartermedia.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ww251.smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adfarm1.adition.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] adfarm1.adition.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adfarm1.adition.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .webmasterplan.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.burstnet.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .statcounter.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.zanox.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] adserver2.clipkit.de [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracking.quisma.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] statse.webtrendslive.com [ C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .doubleclick.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .ad.adnet.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.googleadservices.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.googleadservices.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.googleadservices.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] de.sitestat.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] de.sitestat.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] adx.chip.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] adx.chip.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] sega.missioncontrol.global-media.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .apmebf.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .mediaplex.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] adx.chip.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.zanox.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .zanox.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .traffictrack.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] dc.tremormedia.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .zanox-affiliate.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .elitepartner.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .2o7.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .im.banner.t-online.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .atdmt.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .atdmt.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .a.revenuemax.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .specificclick.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .specificclick.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .specificclick.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .specificclick.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .adviva.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .adfarm1.adition.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad4.adfarm1.adition.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .tracking.quisma.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad1.adfarm1.adition.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .ad.adnet.de [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .webmasterplan.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .webmasterplan.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .imrworldwide.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .imrworldwide.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] adfarm1.adition.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ad2.adfarm1.adition.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .hansenet.122.2o7.net [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ww251.smartadserver.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .de.at.atwola.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ads.zeusclicks.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] ads.crakmedia.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] www.star-advertising.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\3or8qltr.default\cookies.sqlite ] Code:
ATTFilter Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6079 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 16.03.2011 21:40:14 mbam-log-2011-03-16 (21-40-14).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 270505 Laufzeit: 46 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
18.03.2011, 13:15 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Unerwünschte Googleweiterleitung Sieht ok aus, da wurden nur Cookies gefunden. Noch Probleme oder weitere Funde in der Zwischenzeit?
__________________ Logfiles bitte immer in CODE-Tags posten |
18.03.2011, 13:19 | #20 |
| Unerwünschte Googleweiterleitung Nö, soweit ist alles ok. Läuft auch irgendwie alles flüssiger. Wenns das jetzt war, danke ich dir auf jedenfall vielmals. |
18.03.2011, 13:26 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Unerwünschte Googleweiterleitung Dann wären wir durch! Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Anleitung Windows-Update PDF-Reader aktualisieren Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink: Mozilla und andere Browser => http://filepony.de/?q=Flash+Player Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe Java-Update Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ --> Unerwünschte Googleweiterleitung |
Themen zu Unerwünschte Googleweiterleitung |
ausprobiert, dankbar, erste mal, google, googleweiterleitung, leitet, malware neuling, malwarebytes, neu, problem, schweres, seite, seiten, unerwünschte, ungewollte |