rogue killer zeigt mir folgendes an:
¤¤¤ Böswillige Prozesse : 0 ¤¤¤
¤¤¤ Registry-Einträge : 1 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> GEFUNDEN
¤¤¤ Geplante Tasks : 2 ¤¤¤
[V1][ROGUE ST] Plus-HD-1.3-firefoxinstaller.job : C:\Programme\Plus-HD-1.3\Plus-HD-1.3-firefoxinstaller.exe - /installxpi /agentregpath='Plus-HD-1.3' /extensionfilepath='C:\Programme\Plus-HD-1.3\31257.xpi' /appid=31257 /srcid='000173' /subid='0' /zdata='0' /bic=824D954AE79944B9A0E6FA78C81DACE6IE /verifier=a77d9010d6be26b280abc818fe1b88a4 /installerversion=1_27_153 /installerfullversion=1.27.153.7 /installationtime=1373993997 /statsdomain=hxxp://stats.datasrvstats.com /errorsdomain=hxxp://errors.datasrvstats.com /waitforbrowser=300 /extensionid=509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com /extensionversion=0.91 /prefsbranch=a509508ef0b144616a5570d58601be33dc4a581e90ea646dba18558e021ee138ccom31257 /updateurl=hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/31257.rdf /allusers /allprofiles /externallog='' [7]
[ROGUE ST] Plus-HD-1.3-chromeinstaller.job : C:\Programme\Plus-HD-1.3\Plus-HD-1.3-chromeinstaller.exe - /installcrx /agentregpath='Plus-HD-1.3' /extensionfilepath='C:\Programme\Plus-HD-1.3\31257.crx' /appid=31257 /srcid='000173' /subid='0' /zdata='0' /bic=824D954AE79944B9A0E6FA78C81DACE6IE /verifier=a77d9010d6be26b280abc818fe1b88a4 /installerversion=1_27_153 /installerfullversion=1.27.153.7 /installationtime=1373993997 /statsdomain=hxxp://stats.datasrvstats.com /errorsdomain=hxxp://errors.datasrvstats.com /waitforbrowser=300 /extensionid=hhlmghjmomaoodfgjeikphfdljhpcpkl /extensionversion=1.23.33 /extensionpublickey=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkiFzfJnrcFGXgHHHwXJguczOPG3lC2rahFv0pR05x5NxDI2Z8wtXcM0Cxq57bVT3x29N/TCncz9CAmU2FcR27fYjCdK3pf2YX8mFbbAyrayfGFdA6sKn1SDBLzjWKIeYe7CVHEBZEXE8pl4S5nI+cxo5WG6l+lgqwCpez0f7CEQIDAQAB /allusers /allprofiles /externallog='' [7]
¤¤¤ Autostart-Einträge : 0 ¤¤¤
¤¤¤ Web-Browsern : 0 ¤¤¤
¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤
¤¤¤ Treiber : [GELADEN] ¤¤¤
[Address] IRP[IRP_MJ_DEVICE_CONTROL] : atapi.sys -> HOOKED ([Address] \SystemRoot\System32\drivers\sdcplh.sys @ 0xF79E5A08)
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : atapi.sys -> HOOKED ([Address] \SystemRoot\System32\drivers\sdcplh.sys @ 0xF79E5684)
¤¤¤ Externe Hives: ¤¤¤
¤¤¤ Infektion : ¤¤¤
¤¤¤ Hosts-Datei: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR überprüfen: ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK1234GSX +++++
--- User ---
[MBR] 8b16fae19d57b0b82614809277927f98
[BSP] 63cc686ee906c724ff3db6a6ea170df6 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 114470 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Abgeschlossen : << RKreport[0]_S_07262013_131046.txt >>