Fixe diese Einträge im abgesicherten Modus.
Zitat:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://hot-searches.com/search.php?v=6&aff=9086460
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://hot-searches.com/index.php?v=6&aff=9086460
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://hot-searches.com/index.php?v=6&aff=9086460
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - C:\WINDOWS\SYSTEM\XPLUGIN.DLL
|
Lösche diese Dateien:
C:\WINDOWS\SYSTEM\XPLUGIN.DLL
C:\WINDOWS\SYSTEM\tmksrvu.exe
C:\WINDOWS\SYSTEM\nsdb\hosts
Weitere Anweisungen von Symantec
Zitat:
4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
1. Click Start > Run.
2. Type regedit
Then click OK.
3. Navigate to the subkey:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the values:
"hpnt" = "[random value]"
"SetHP" = "[random value]"
4. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
In the right pane, reset the value to:
"DataBasePath" = "%System%\drivers\etc\hosts"
5. Navigate to the subkey [if present]:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
In the right pane, reset the value:
"DataBasePath" = "%System%\drivers\etc\hosts"
6. Navigate to and delete the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\XPlugin.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC3F36D4-F905-4FE9-A926-EB937E66F591}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE79D398-AAAF-47B1-8C9E-11F7D4C9111B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XPlugin.XFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XPlugin.XFilter.1
HKEY_LOCAL_MACHINE\SOFTWARE\TMKSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html
7. Exit the Registry Editor.
|
Quelle:
http://sarc.com/avcenter/venc/data/a...t.xplugin.html
Führe einen Scan mit
eScan durch und poste das Ergebnis.
Anmerkung: Die Find.bat wird nicht funktionieren, vgl. dazu
dieses Posting.
__________________