Ich würde vorschlagen, den Computer im Safemode ohne Netzwerkstart neu zu starten und dann Ihre AV-Scans auszuführen.
Überprüfen Sie auch, dass kein Browser-Hilfsobjekt vorhanden ist, indem Sie HijackThis ausführen und prüfen, ob die DLL-Dateien ebenfalls gelöscht werden.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BarBroker.EXE HKEY_CURRENT_USER\Software\baidu HKEY_CLASSES_ROOT\BaiduBar.Tool.1 HKEY_CLASSES_ROOT\BaiduBar.Tool HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBar.Tool HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBar.Tool.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.ToolBand.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.ToolBand HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.BandIE.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.BandIE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage.4 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage.3 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage.2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BDHomePage.5 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.BDLogin.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarX.BDLogin HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage.5 HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage.4 HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage.3 HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage.2 HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage.1 HKEY_CLASSES_ROOT\BaiduBarEx.BDHomePage HKEY_CLASSES_ROOT\clsid\ HKEY_CLASSES_ROOT\clsid\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BaiduBarX HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ HKEY_LOCAL_MACHINE\SOFTWARE\Baidu HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ HKEY_CLASSES_ROOT\CLSID\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ HKEY_LOCAL_MACHINE\SOFTWARE\Baidu\BaiduBar HKEY_CURRENT_USER\Software\Baidu\BaiduBar HKEY_CLASSES_ROOT\CLSID\ HKEY_CLASSES_ROOT\TypeLib\ HKEY_CLASSES_ROOT\BaiduBar.Baidu.1 HKEY_CLASSES_ROOT\BaiduBar.Baidu HKEY_CLASSES_ROOT\Interface\ HKEY_CLASSES_ROOT\Interface\ HKEY_CLASSES_ROOT\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBar.Baidu.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBar.Baidu HKEY_CLASSES_ROOT\CLSID\ HKEY_CLASSES_ROOT\BaiduBarEx.BandIE.1 HKEY_CLASSES_ROOT\BaiduBarEx.BandIE HKEY_CLASSES_ROOT\BaiduBarEx.DropTarget.1 HKEY_CLASSES_ROOT\BaiduBarEx.DropTarget HKEY_CLASSES_ROOT\Interface\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.DropTarget.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.DropTarget HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BandIE.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBarEx.BandIE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdGuard HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sobar HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ HKEY_LOCAL_MACHINE\SOFTWARE\Baidu_bar HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduBar HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\ HKEY_CLASSES_ROOT\clsid\ HKEY_CLASSES_ROOT\clsid\
Sind die Registrierungsschlüssel, die erstellt werden.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]=65CF80B551E1C349B73F70B13FCA8E86 [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar]=12 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]=4BCCFD89918DB04981A618BCFF582735 [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar]=00 [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar]=sobar [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar]=BaiduBar [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar] =00 [HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar] =BaiduBar
Sind die Werte Wenn es immer wiederkommt, haben Sie eine Art zugrunde liegender Infektion, weshalb ich empfehle, Ihre Scans im Safemode ohne Netzwerkverbindung durchzuführen.