![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Browser öffnet automatisch neue TabsWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Browser öffnet automatisch neue Tabs Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
[2010.07.12 10:28:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Steffi\Lokale Einstellungen\Anwendungsdaten\rkshqsbtj
[2010.08.01 15:21:17 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLdw.DAT
[2010.08.01 14:54:04 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLdu.DAT
[2010.07.20 15:58:27 | 000,002,528 | ---- | M] () -- C:\Dokumente und Einstellungen\Steffi\Anwendungsdaten\$_hpcst$.hpc
:Commands
[purity]
[resethosts]
[emptytemp]
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #2 |
![]() ![]() | Browser öffnet automatisch neue Tabs Hallo Arne,
__________________erledigt: Code:
ATTFilter All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
C:\Dokumente und Einstellungen\Steffi\Lokale Einstellungen\Anwendungsdaten\rkshqsbtj folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLdw.DAT moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLdu.DAT moved successfully.
C:\Dokumente und Einstellungen\Steffi\Anwendungsdaten\$_hpcst$.hpc moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 49152 bytes
->Temporary Internet Files folder emptied: 219139 bytes
->FireFox cache emptied: 3056949 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33728 bytes
->Flash cache emptied: 41 bytes
User: Gast
->Temp folder emptied: 554078 bytes
->Temporary Internet Files folder emptied: 33728 bytes
User: Holla
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40993421 bytes
->Flash cache emptied: 2673 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 841 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2146438 bytes
->Flash cache emptied: 2730 bytes
User: Party
->Temp folder emptied: 3942769 bytes
->Temporary Internet Files folder emptied: 147589 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 98526147 bytes
->Flash cache emptied: 12338 bytes
User: Steffi
->Temp folder emptied: 43667408 bytes
->Temporary Internet Files folder emptied: 17286074 bytes
->Java cache emptied: 269711 bytes
->FireFox cache emptied: 43555482 bytes
->Flash cache emptied: 9629 bytes
User: Titel-Datenbank
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2239257 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 855281 bytes
RecycleBin emptied: 1408621456 bytes
Total Files Cleaned = 1.589,00 mb
OTL by OldTimer - Version 3.2.9.1 log created on 08052010_155518
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
|
![]() |
| Themen zu Browser öffnet automatisch neue Tabs |
| browser, computer, converter, einstellungen, fehler, fenster, festplatte, firefox, flash player, ftp, help, infizierte, infizierte dateien, install.exe, installation, logfile, modul, msiexec, msiexec.exe, neue tabs, rundll, scan, security, sekunden, software, starten, system, tabs öffnen sich automatisch, trojaner, usb, vlc media player, windows, windows xp, öffnet |