Fixen:R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://4-counter.com/?a=2R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://4-counter.com/?a=2R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://4-counter.com/?a=2R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://4-counter.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.puh.ru/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://4-counter.com/?a=2R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.crooder.com/search/R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://4-counter.com/?a=2R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.puh.ru/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://4-counter.com/?a=2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://4-counter.com/?a=2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.puh.ru/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.puh.ru/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.crooder.com/search/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://4-counter.com/?a=2R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://activex.bicurioz.com/page/lp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP =
http://www.search-2003.com/R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://www.puh.ru/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://searchbar.linksummary.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) =
http://www.crooder.com/search/O2 - BHO: (no name) - {CF021F40-3E14-23A5-CBA2-717765721306} - C:\WINDOWS\SYSTEM\WER1306.DLL
O2 - BHO: (no name) - {CF021F40-3E14-23A5-CBA2-717177656032} - C:\WINDOWS\SYSTEM\QWE6032.DLL
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\BIN\DMSERVER.EXE /onreboot
(Wahrscheinlich SOBIG-Virus)O4 - HKLM\..\Run: [WindowsMGM] C:\WINDOWS\winmgm32.exe
O4 - HKCU\..\Run: [WindowsMGM]
C:\WINDOWS\winmgm32.exe
O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\SYSTEM32\WINPROC32.EXE
O13 - DefaultPrefix:
http://www.sexyque.com/cgi-bin/proliv/proliv.cgi?O13 - WWW Prefix:
http://www.sexyque.com/cgi-bin/proliv/proliv.cgi?O15 - Trusted Zone: *.isprime.com
O15 - Trusted Zone: *.0190-dialer.com
Vor dem fixen Offline gehn, alle Browserfenster schliessen.
Dann alle fixen.
Nach dem fixen neustarten in den abgesicherten Modus gehn ( F8 beim booten) und dann den Rechner mit dem Antiviren-Scanner prüfen.
Danach folgende Dateien löschen:
C:\PROGRAMME\COMET SYSTEMS\DM\BIN\DMSERVER.EXE
(Comet Cursor adware)
C:\WINDOWS\SYSTEM32\WINPROC32.EXE
(CoolWebSearch Parasit)
C:\WINDOWS\SYSTEM\WER1306.DLL
C:\WINDOWS\SYSTEM\QWE6032.DLL
Dann wieder normal starten und nochmal ein LOG machen.
Und solltest dir mal grundsätzlich Gedanken über deine Sicherheit machen, hast ja so ziemlich jede Art von Schädling auf dem Rechner.
Gruß