hab noch was:
Go to Control Panel>Folder Options>View tab,and enable 'Show hidden files and Folders',now press Apply>OK.
Boot into Safe Mode and delete if present:
C:\WINDOWS\WIN2\System32\deskpapi.exe
C:\WINDOWS\WIN2\System32\qksgcrqb.dll
C:\WINDOWS\WIN2\system32\holdapi.dll
Reboot normally.
========================================
Download and scan with the free trial of Sunbelt's Counterspy.
Delete everything it finds.
Save the report when it's finished.
========================
Download and scan with Ewido Anti Malware v3.5
1. After download, double click on the file to launch the install process.
2. During installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
3. Launch ewido by double-clicking the "e" icon on your desktop.
4. The program will prompt you to update - click the "OK" button.
5. On the left side of the main screen, click on "Update" and then click "Start Update". The update will start and a progress bar will show the updates being installed.
6. After the updates are installed, you will see "Update Successful" in the lower left corner. If you are having problems with the updater, manually update from here.
Once the updates are installed do the following:
1. Click on "Scanner" and choose "Settings".
2. Under the bottom section "What to Scan?" make sure "Scan every file" is selected.
3. Select "OK" and you will return to scanning options.
4. On the main screen click on "Complete System Scan" to start the scan.
5. While the scan is in progress, you will be prompted to clean the first infected file if finds. Put a check next to "Perform action on all infections" in the lower left corner.
6. Then choose "Remove" and click "OK".
7. When the scan has completed, Ewido will create a report.txt file.
8. Click the "Save Report" button on the bottom of the screen and save the log to your desktop.
9. Exit Ewido when done.
Reboot,post the Counterspy and Ewido reports,and a new Hijack This log please.
gefunden hier:
http://forum.tweakxp.com/forum/Topic192445-29-1.aspx