|
Plagegeister aller Art und deren Bekämpfung: Win32.Webprefix - Was tun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.01.2011, 16:12 | #1 |
| Win32.Webprefix - Was tun? Also, bevor ich irgendwelceh Dateien poste oder so - suche seit heute Morgen im Netz nach einer Lösung, teilweise habe ich auch was vor Augen, aber eben nur teilweise. Nun zur Lage: Seit einigen Tage ist mein System bzw. Firefox extrem lan.gsam geworden. Hatte keine Erklärung dafür. Nur nen Verdacht, dass ich mir was eingefangen habe. Also AntiVira drüber laufen lassen - nix erkannt. SpyBot drüber laufen lassen - sieben Sachen gefunden. Sechs konnten behoben werden, das Problem Win32.Webprefix nicht. Geguckt, scheint halt nen Trojaner zu sein. Also dachte ich mir, System neu. Will erst CDL o CBL Datenshredder laufen lassen und dann neu installieren. Ist das der richtige Weg? Um die vorhandenen Daten zu retten, externe Festplatte ran und rüber kopiert. Nu will ich checken, ob die Festplatte auch befallen ist. Nur mit Spybot komme ich da nicht ran. Also Malwarebytes geladen und geprüft. Problem: Malwarebytes findet nix, weder auf C: noch auf E:. Also wenn das Programm Win32.Webprefix auf C: nicht findet, wie kann ich sicher gehen, dass es auf der Externen nicht auch ist? Ich hoffe, dass mir jmd. helfen kann? |
27.01.2011, 20:11 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun? Poste alle relevanten Logs, auch alle von Malwarebytes und auch dann wenn nichts gefunden wurd.
__________________
__________________ |
27.01.2011, 20:18 | #3 |
| Win32.Webprefix - Was tun? Hier die Logs von Malewarebytes. Die von SpyBot auch? Wenn ja, wo finde ich die?
__________________Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 5617 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 27.01.2011 15:30:35 mbam-log-2011-01-27 (15-30-35).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Durchsuchte Objekte: 247992 Laufzeit: 50 Minute(n), 8 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 5621 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 27.01.2011 19:34:38 mbam-log-2011-01-27 (19-34-38).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 248107 Laufzeit: 45 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
27.01.2011, 20:19 | #4 |
| Win32.Webprefix - Was tun? Nutze aber Firefox, wieso überprüft Malewarebytes den Ie?! Habe zudem Angst, dass meine PS3 und Ipod und Iphone betroffen sind - kann das sein? |
27.01.2011, 20:26 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun? Hab Spybot schon ewig nicht mehr genutzt. Nach einer kurzen Recherche müsste es in der Expertenansicht unter Werkzeuge / Berichte zu sehen sein.
__________________ Logfiles bitte immer in CODE-Tags posten |
27.01.2011, 20:38 | #6 |
| Win32.Webprefix - Was tun? 27.01.2011 13:50:18 - ##### check started ##### 27.01.2011 13:50:18 - ### Version: 1.6.2 27.01.2011 13:50:18 - ### Date: 27.01.2011 13:50:18 27.01.2011 13:50:22 - ##### checking bots ##### 27.01.2011 13:58:37 - found: Win32.Webprefix Bibliothek 27.01.2011 14:13:37 - found: MediaPlex Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:37 - found: Right Media Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:37 - found: AdBrite Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:38 - found: MediaPlex Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:38 - found: Tradedoubler Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:38 - found: DoubleClick Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 14:13:38 - ##### check finished ##### --- Report generated: 2011-01-27 14:13 --- Win32.Webprefix: [SBI $D40E955A] Bibliothek (Datei, nothing done) C:\Windows\System32\KBDIOASA.DLL Properties.size=28672 Properties.md5=4498EBE1FDD375DB558F1EC481BAEBF7 Properties.filedate=1294875305 Properties.filedatetext=2011-01-13 00:35:05 MediaPlex: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) Right Media: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) AdBrite: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) MediaPlex: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) Tradedoubler: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) DoubleClick: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2011-01-27 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2010-10-05 Includes\Adware.sbi (*) 2010-11-30 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2010-12-14 Includes\DialerC.sbi (*) 2010-01-25 Includes\HeavyDuty.sbi (*) 2010-11-30 Includes\Hijackers.sbi (*) 2011-01-25 Includes\HijackersC.sbi (*) 2010-06-02 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2010-12-14 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2010-12-14 Includes\Malware.sbi (*) 2011-01-25 Includes\MalwareC.sbi (*) 2010-05-18 Includes\PUPS.sbi (*) 2010-12-14 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2010-12-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-01-18 Includes\Spyware.sbi (*) 2011-01-18 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-01-25 Includes\TrojansC-02.sbi (*) 2011-01-13 Includes\TrojansC-03.sbi (*) 2011-01-25 Includes\TrojansC-04.sbi (*) 2011-01-25 Includes\TrojansC-05.sbi (*) 2010-12-28 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll 27.01.2011 14:15:15 - ##### check started ##### 27.01.2011 14:15:15 - ### Version: 1.6.2 27.01.2011 14:15:15 - ### Date: 27.01.2011 14:15:15 27.01.2011 14:15:20 - ##### checking bots ##### --- Report generated: 2011-01-27 14:15 --- --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2011-01-27 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2010-10-05 Includes\Adware.sbi (*) 2010-11-30 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2010-12-14 Includes\DialerC.sbi (*) 2010-01-25 Includes\HeavyDuty.sbi (*) 2010-11-30 Includes\Hijackers.sbi (*) 2011-01-25 Includes\HijackersC.sbi (*) 2010-06-02 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2010-12-14 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2010-12-14 Includes\Malware.sbi (*) 2011-01-25 Includes\MalwareC.sbi (*) 2010-05-18 Includes\PUPS.sbi (*) 2010-12-14 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2010-12-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-01-18 Includes\Spyware.sbi (*) 2011-01-18 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-01-25 Includes\TrojansC-02.sbi (*) 2011-01-13 Includes\TrojansC-03.sbi (*) 2011-01-25 Includes\TrojansC-04.sbi (*) 2011-01-25 Includes\TrojansC-05.sbi (*) 2010-12-28 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll 27.01.2011 15:01:32 - ##### check started ##### 27.01.2011 15:01:32 - ### Version: 1.6.2 27.01.2011 15:01:32 - ### Date: 27.01.2011 15:01:32 27.01.2011 15:01:37 - ##### checking bots ##### 27.01.2011 15:08:57 - found: Win32.Webprefix Bibliothek 27.01.2011 15:25:41 - ##### check finished ##### --- Report generated: 2011-01-27 15:25 --- Win32.Webprefix: [SBI $D40E955A] Bibliothek (Datei, nothing done) C:\Windows\System32\KBDIOASA.DLL Properties.size=28672 Properties.md5=4498EBE1FDD375DB558F1EC481BAEBF7 Properties.filedate=1294875305 Properties.filedatetext=2011-01-13 00:35:05 --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2011-01-27 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2010-10-05 Includes\Adware.sbi (*) 2010-11-30 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2010-12-14 Includes\DialerC.sbi (*) 2010-01-25 Includes\HeavyDuty.sbi (*) 2010-11-30 Includes\Hijackers.sbi (*) 2011-01-25 Includes\HijackersC.sbi (*) 2010-06-02 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2010-12-14 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2010-12-14 Includes\Malware.sbi (*) 2011-01-25 Includes\MalwareC.sbi (*) 2010-05-18 Includes\PUPS.sbi (*) 2010-12-14 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2010-12-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-01-18 Includes\Spyware.sbi (*) 2011-01-18 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-01-25 Includes\TrojansC-02.sbi (*) 2011-01-13 Includes\TrojansC-03.sbi (*) 2011-01-25 Includes\TrojansC-04.sbi (*) 2011-01-25 Includes\TrojansC-05.sbi (*) 2010-12-28 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll 27.01.2011 15:35:12 - ##### check started ##### 27.01.2011 15:35:12 - ### Version: 1.6.2 27.01.2011 15:35:12 - ### Date: 27.01.2011 15:35:12 27.01.2011 15:35:17 - ##### checking bots ##### 27.01.2011 15:40:17 - found: Win32.Webprefix Bibliothek 27.01.2011 15:55:03 - ##### check finished ##### --- Report generated: 2011-01-27 15:55 --- Win32.Webprefix: [SBI $D40E955A] Bibliothek (Datei, nothing done) C:\Windows\System32\KBDIOASA.DLL Properties.size=28672 Properties.md5=4498EBE1FDD375DB558F1EC481BAEBF7 Properties.filedate=1294875305 Properties.filedatetext=2011-01-13 00:35:05 --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2011-01-27 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2010-10-05 Includes\Adware.sbi (*) 2010-11-30 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2010-12-14 Includes\DialerC.sbi (*) 2010-01-25 Includes\HeavyDuty.sbi (*) 2010-11-30 Includes\Hijackers.sbi (*) 2011-01-25 Includes\HijackersC.sbi (*) 2010-06-02 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2010-12-14 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2010-12-14 Includes\Malware.sbi (*) 2011-01-25 Includes\MalwareC.sbi (*) 2010-05-18 Includes\PUPS.sbi (*) 2010-12-14 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2010-12-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-01-18 Includes\Spyware.sbi (*) 2011-01-18 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-01-25 Includes\TrojansC-02.sbi (*) 2011-01-13 Includes\TrojansC-03.sbi (*) 2011-01-25 Includes\TrojansC-04.sbi (*) 2011-01-25 Includes\TrojansC-05.sbi (*) 2010-12-28 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll 27.01.2011 20:16:46 - ##### check started ##### 27.01.2011 20:16:46 - ### Version: 1.6.2 27.01.2011 20:16:46 - ### Date: 27.01.2011 20:16:46 27.01.2011 20:16:51 - ##### checking bots ##### 27.01.2011 20:22:14 - found: Win32.Webprefix Bibliothek 27.01.2011 20:32:17 - found: MediaPlex Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 20:32:17 - found: Right Media Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 20:32:17 - found: MediaPlex Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 20:32:17 - found: DoubleClick Verfolgender Cookie (Internet Explorer: Kalle) 27.01.2011 20:32:17 - ##### check finished ##### --- Report generated: 2011-01-27 20:32 --- Win32.Webprefix: [SBI $D40E955A] Bibliothek (Datei, nothing done) C:\Windows\System32\KBDIOASA.DLL Properties.size=28672 Properties.md5=4498EBE1FDD375DB558F1EC481BAEBF7 Properties.filedate=1294875305 Properties.filedatetext=2011-01-13 00:35:05 MediaPlex: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) Right Media: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) MediaPlex: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) DoubleClick: Verfolgender Cookie (Internet Explorer: Kalle) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SDWinSec.exe (1.0.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2011-01-27 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2010-10-05 Includes\Adware.sbi (*) 2010-11-30 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2010-12-14 Includes\Dialer.sbi (*) 2010-12-14 Includes\DialerC.sbi (*) 2010-01-25 Includes\HeavyDuty.sbi (*) 2010-11-30 Includes\Hijackers.sbi (*) 2011-01-25 Includes\HijackersC.sbi (*) 2010-06-02 Includes\iPhone.sbi (*) 2010-12-14 Includes\Keyloggers.sbi (*) 2010-12-14 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2010-12-14 Includes\Malware.sbi (*) 2011-01-25 Includes\MalwareC.sbi (*) 2010-05-18 Includes\PUPS.sbi (*) 2010-12-14 Includes\PUPSC.sbi (*) 2010-01-25 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2010-12-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2011-01-18 Includes\Spyware.sbi (*) 2011-01-18 Includes\SpywareC.sbi (*) 2010-03-08 Includes\Tracks.uti 2010-12-28 Includes\Trojans.sbi (*) 2011-01-25 Includes\TrojansC-02.sbi (*) 2011-01-13 Includes\TrojansC-03.sbi (*) 2011-01-25 Includes\TrojansC-04.sbi (*) 2011-01-25 Includes\TrojansC-05.sbi (*) 2010-12-28 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll |
27.01.2011, 20:55 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun? Seh ich nur Cookies. Harmlos bis jetzt. Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
27.01.2011, 21:02 | #8 |
| Win32.Webprefix - Was tun? TL logfile created on: 27.01.2011 21:00:20 - Run 1 OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Kalle\Desktop Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,95 Gb Total Space | 108,59 Gb Free Space | 72,91% Space Free | Partition Type: NTFS Drive E: | 232,83 Gb Total Space | 158,64 Gb Free Space | 68,14% Space Free | Partition Type: FAT32 Computer Name: KALLE-PC | User Name: Kalle | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Kalle\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Programme\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) ========== Modules (SafeList) ========== MOD - C:\Users\Kalle\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation) MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation) MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation) MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation) MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation) MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation) MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation) MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation) MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation) MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation) SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation) SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation) SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation) SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation) SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation) SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation) SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation) SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation) SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation) SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation) SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation) SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation) SRV - (AxInstSV) ActiveX-Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation) SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation) SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation) SRV - (SBSDWSCService) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) ========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia) DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia) DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia) DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia) DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation) DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.) DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.) DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.) DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.) DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.) DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.) DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.) DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices) DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.) DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices) DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.) DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation) DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation) DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation) DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation) DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation) DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation) DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation) DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation) DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation) DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation) DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex) DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.) DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company) DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation) DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation) DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation) DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation) DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.) DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation) DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation) DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation) DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems) DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation) DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.) DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology) DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.) DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation) DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation) DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation) DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation) DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation) DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation) DRV - (1394ohci) -- C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation) DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation) DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation) DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation) DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation) DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation) DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation) DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation) DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation) DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation) DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.) DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.) DRV - (netw5v32) Intel(R) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation) DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation) DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation) DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation) DRV - (AtcL001) -- C:\Windows\System32\drivers\l160x86.sys (Atheros Communications, Inc.) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100) DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 45 21 A1 C5 1E BE CB 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.startup.homepage: "hxxp://www.lego.de" FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.09.17 17:32:56 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.12.18 09:59:22 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.18 09:59:21 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.09.17 17:32:57 | 000,000,000 | ---D | M] [2010.09.16 10:34:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kalle\AppData\Roaming\mozilla\Extensions [2010.09.16 23:09:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kalle\AppData\Roaming\mozilla\Firefox\Profiles\ylrskrzj.default\extensions [2010.12.14 07:47:48 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2010.12.14 07:47:48 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2010.09.14 22:32:39 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.09.14 22:32:39 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.09.14 22:32:39 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.09.14 22:32:39 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.09.14 22:32:39 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.01.27 20:58:58 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Users\Kalle\Desktop\OTL.exe [2011.01.27 15:44:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Hijack Recover(BHR) [2011.01.27 15:44:18 | 000,000,000 | ---D | C] -- C:\Programme\Browser Hijack Recover [2011.01.27 14:35:45 | 000,000,000 | ---D | C] -- C:\Users\Kalle\AppData\Roaming\Malwarebytes [2011.01.27 14:35:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.01.27 14:35:21 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011.01.27 14:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.01.27 14:35:16 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.01.27 14:35:16 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2011.01.27 13:49:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2011.01.27 13:48:58 | 000,000,000 | ---D | C] -- C:\Programme\Spybot - Search & Destroy [2011.01.27 13:48:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2011.01.13 21:01:32 | 000,000,000 | ---D | C] -- C:\Users\Kalle\AppData\Local\Zattoo [2011.01.13 21:01:24 | 000,000,000 | ---D | C] -- C:\Users\Kalle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zattoo4 [2011.01.13 21:01:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zattoo4 [2011.01.13 21:01:23 | 000,000,000 | ---D | C] -- C:\Programme\Zattoo4 [2011.01.12 15:13:43 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll [2011.01.12 15:13:39 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2011.01.12 15:13:39 | 001,076,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2011.01.12 15:13:39 | 000,804,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll [2011.01.12 15:13:39 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2011.01.12 15:13:39 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011.01.12 15:13:38 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2011.01.12 15:13:38 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2011.01.12 15:13:38 | 000,211,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys [2011.01.12 15:13:38 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2011.01.12 15:13:38 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011.01.12 15:13:38 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011.01.06 13:35:23 | 000,000,000 | ---D | C] -- C:\Users\Kalle\AppData\Local\PokerStars.NET [2011.01.06 13:35:12 | 000,000,000 | ---D | C] -- C:\Users\Kalle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.NET [2011.01.06 13:34:43 | 000,000,000 | ---D | C] -- C:\Programme\PokerStars.NET ========== Files - Modified Within 30 Days ========== [2011.01.27 20:59:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Kalle\Desktop\OTL.exe [2011.01.27 15:44:24 | 000,000,000 | ---- | M] () -- C:\Windows\System32\8104297.jun [2011.01.27 14:19:24 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.01.27 14:19:24 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.01.27 14:19:24 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.01.27 14:19:24 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.01.27 13:50:03 | 000,015,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.01.27 13:50:03 | 000,015,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.01.27 10:37:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.01.27 10:37:29 | 1610,014,720 | -HS- | M] () -- C:\hiberfil.sys [2011.01.26 18:56:55 | 000,647,168 | ---- | M] () -- C:\Users\Kalle\Documents\Schriftliche Arbeit.doc [2011.01.13 21:05:10 | 000,017,408 | ---- | M] () -- C:\Users\Kalle\AppData\Local\WebpageIcons.db [2011.01.13 00:35:05 | 000,028,672 | ---- | M] () -- C:\Windows\System32\KBDIOASA.DLL ========== Files Created - No Company Name ========== [2011.01.27 15:44:24 | 000,000,000 | ---- | C] () -- C:\Windows\System32\8104297.jun [2011.01.26 17:54:00 | 000,647,168 | ---- | C] () -- C:\Users\Kalle\Documents\Schriftliche Arbeit.doc [2011.01.13 21:01:32 | 000,017,408 | ---- | C] () -- C:\Users\Kalle\AppData\Local\WebpageIcons.db [2011.01.13 00:35:05 | 000,028,672 | ---- | C] () -- C:\Windows\System32\KBDIOASA.DLL [2010.09.16 11:58:01 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.09.16 10:59:04 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2005.05.06 18:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll [2003.02.20 16:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI < End of report >OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 27.01.2011 21:00:20 - Run 1 OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Kalle\Desktop Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,95 Gb Total Space | 108,59 Gb Free Space | 72,91% Space Free | Partition Type: NTFS Drive E: | 232,83 Gb Total Space | 158,64 Gb Free Space | 68,14% Space Free | Partition Type: FAT32 Computer Name: KALLE-PC | User Name: Kalle | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [MediaMonkey.1Play] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.) Directory [MediaMonkey.2PlayNext] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.) Directory [MediaMonkey.3Enqueue] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{45DF6D99-666D-41FA-8D62-0E183B6240F3}" = PC Connectivity Solution "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2 "{749A1EDD-16C2-4C63-B013-D38F0F953973}" = OviMPlatform "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{8112C6B3-91E1-4560-8AB9-876DADFA37C5}" = Ovi Desktop Sync Engine "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel "{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.1 - Deutsch "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B8B4446F-87E1-4423-A47A-16832C24A199}" = Nokia Ovi Suite "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars "{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5 "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0 "{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89}" = Nokia Ovi Suite Software Updater "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour "504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Browser Hijack Recover_is1" = Browser Hijack Recover(BHR) 2.2 "DivX Setup.divx.com" = DivX-Setup "Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 4.1 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "MediaMonkey_is1" = MediaMonkey 3.2 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13) "Nokia Ovi Suite" = Nokia Ovi Suite "NVIDIA Drivers" = NVIDIA Drivers "PokerStars.net" = PokerStars.net "SMSERIAL" = Motorola SM56 Speakerphone Modem "SopCast" = SopCast 3.2.9 "Uninstall_is1" = Uninstall 1.0.0.1 "VLC media player" = VLC media player 1.1.4 "WinRAR archiver" = WinRAR "Zattoo4" = Zattoo4 4.0.5 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 26.01.2011 11:07:35 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 26.01.2011 11:07:35 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 5304 Error - 26.01.2011 11:07:35 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 5304 Error - 26.01.2011 11:07:36 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 26.01.2011 11:07:36 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6365 Error - 26.01.2011 11:07:36 | Computer Name = Kalle-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6365 Error - 27.01.2011 06:22:41 | Computer Name = Kalle-PC | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 27.01.2011 08:11:57 | Computer Name = Kalle-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: svchost.exe_TapiSrv, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x03463e4a ID des fehlerhaften Prozesses: 0x448 Startzeit der fehlerhaften Anwendung: 0x01cbbe05d5cf8604 Pfad der fehlerhaften Anwendung: C:\Windows\system32\svchost.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: a246489a-2a0e-11e0-80f1-001d60077220 Error - 27.01.2011 13:38:12 | Computer Name = Kalle-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program files\spybot - search & destroy\DelZip179.dll" in Zeile 8. Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig. Error - 27.01.2011 13:38:29 | Computer Name = Kalle-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Spybot - Search & Destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "C:\Program Files\Spybot - Search & Destroy\DelZip179.dll" in Zeile 8. Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig. [ System Events ] Error - 24.01.2011 19:23:25 | Computer Name = Kalle-PC | Source = atapi | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error - 24.01.2011 19:23:25 | Computer Name = Kalle-PC | Source = atapi | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error - 26.01.2011 14:09:46 | Computer Name = Kalle-PC | Source = atapi | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error - 27.01.2011 08:11:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Kryptografiedienste" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error - 27.01.2011 08:11:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "DNS-Client" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error - 27.01.2011 08:11:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Arbeitsstationsdienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error - 27.01.2011 08:11:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "NLA (Network Location Awareness)" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 100 Millisekunden durchgeführt: Neustart des Diensts. Error - 27.01.2011 08:11:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Telefonie" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error - 27.01.2011 08:13:58 | Computer Name = Kalle-PC | Source = Service Control Manager | ID = 7032 Description = Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "DNS-Client" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error - 27.01.2011 14:39:38 | Computer Name = Kalle-PC | Source = atapi | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. < End of report > |
28.01.2011, 10:04 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun? Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL O4 - HKCU..\Run: [] File not found [2011.01.27 15:44:24 | 000,000,000 | ---- | M] () -- C:\Windows\System32\8104297.jun [2011.01.13 00:35:05 | 000,028,672 | ---- | M] () -- C:\Windows\System32\KBDIOASA.DLL :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten |
28.01.2011, 16:58 | #10 |
| Win32.Webprefix - Was tun? Danke schonmal...gibt es auch einen Weg, der Sicherheitskopie auf der Systempartition aus dem Weg zu gehen? Will die nicht haben! |
28.01.2011, 17:05 | #11 |
| Win32.Webprefix - Was tun? All processes killed ========== OTL ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ deleted successfully. C:\Windows\System32\8104297.jun moved successfully. C:\Windows\System32\KBDIOASA.DLL moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Kalle ->Temp folder emptied: 314749 bytes ->Temporary Internet Files folder emptied: 42644935 bytes ->FireFox cache emptied: 54590447 bytes ->Flash cache emptied: 1046 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 10959371 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 103,00 mb OTL by OldTimer - Version 3.2.20.6 log created on 01282011_170215 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
28.01.2011, 19:33 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun? Was für ne Sicherheitskopie meinst du da?
__________________ Logfiles bitte immer in CODE-Tags posten |
31.01.2011, 11:56 | #13 |
| Win32.Webprefix - Was tun? Habe den Ordner "Eigene Dateien" auf ne externe kopiert. Leider ohne nachzudenken...nun würde ich gerne wissen, ob der webprefix vllt auch mit auf die Externe gehuscht ist. Zudem hat Spybot nachdem ich gefixt habe bereits vier neue Probleme erkannt. Würde gerne wissen, ob ein komplettes Shreddern des Systems und Neuinstallieren die Dinger wegbekommen würde?! Zudem interessiert mich, ob auch andere Rechner die an unserem Router hängen, sowie PS3 und iphone/ipod betroffen sein könnten? |
31.01.2011, 11:57 | #14 |
| Win32.Webprefix - Was tun? Da meinte ich den OTL Ordner der durchs fixen entsteht! |
31.01.2011, 12:30 | #15 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32.Webprefix - Was tun?Zitat:
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Win32.Webprefix - Was tun? |
befallen, checken, dateien, eingefangen, externe festplatte, festplatte, firefox, heute, lösung, malwarebytes, platte, problem, programm, retten, sache, sachen, shredder, sieben, spybot, suche, system, trojaner, verdacht, was tun, was tun?, win |