|
Plagegeister aller Art und deren Bekämpfung: Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.11.2012, 21:20 | #1 |
| Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Hallo! Ich habe ein merkwürdiges Problem!!! Seit einigen Tagen habe ich riesen Probleme Dateien zu laden, aber lediglich von bekannten herstellern wie z.B. folgendes: Flash Plugin, Firefox Update, Java Plugin. Diese wollen einfach nicht heruntergeladen werden. Wenn ich jedoch einen Testdownload (auch größere Dateien) mache, habe ich kein Problem. Ich kann auch Problemlos Online spielen und Skypen. Sämtliche Speedtests bestätigen mir auch das meine Verbindung rasend schnell ist. Des Weiteren fiel mir auf das Seiten wie Facebook irgendwie gebremst werden. Kann dies Malware sein und wie gehe ich da vor? Liebe Grüße Bruellmuecke Geändert von Bruellmuecke (21.11.2012 um 21:38 Uhr) |
21.11.2012, 23:12 | #2 |
| Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Im Anhang 3 Logfiles
__________________OTL Extras Mailwarebytes Danke Bruellmuecke |
25.11.2012, 08:51 | #3 |
/// Helfer-Team | Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell.Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL MOD - C:\Users\Woodruff\AppData\Roaming\BrowserCompanion\tcbhn.exe () O4 - HKCU..\Run: [AdobeBridge] File not found O4 - Startup: C:\Users\Woodruff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk = C:\Users\Woodruff\AppData\Roaming\BrowserCompanion\tcbhn.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 :Files C:\ProgramData\*.exe C:\ProgramData\*.dll C:\ProgramData\*.tmp C:\ProgramData\TEMP C:\Users\Woodruff\*.tmp C:\Users\Woodruff\AppData\Local\Temp\*.exe C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk ipconfig /flushdns /c :Commands [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ |
25.11.2012, 15:21 | #4 |
| Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Hey t'john, vielen Dank für deine Hilfe. Habe alle Schritte befolgt. Schritt 1 OTL Log Code:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. C:\Users\Woodruff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk moved successfully. C:\Users\Woodruff\AppData\Roaming\BrowserCompanion\tcbhn.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{C59C179C-668D-49A9-B6EA-0121CCFC1243} folder moved successfully. C:\ProgramData\Temp\{B7A0CE06-068E-11D6-97FD-0050BACBF861} folder moved successfully. C:\ProgramData\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8} folder moved successfully. C:\ProgramData\Temp\{80E158EA-7181-40FE-A701-301CE6BE64AB} folder moved successfully. C:\ProgramData\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41} folder moved successfully. C:\ProgramData\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658} folder moved successfully. C:\ProgramData\Temp\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} folder moved successfully. C:\ProgramData\Temp\{01FB4998-33C4-4431-85ED-079E3EEFE75D} folder moved successfully. C:\ProgramData\Temp folder moved successfully. File\Folder C:\Users\Woodruff\*.tmp not found. C:\Users\Woodruff\AppData\Local\Temp\AdobeApplicationManager.exe moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Woodruff\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. File/Folder C:\Users\Woodruff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Woodruff\Desktop\cmd.bat deleted successfully. C:\Users\Woodruff\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 500118 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: test ->Temp folder emptied: 67803026 bytes ->Temporary Internet Files folder emptied: 46075688 bytes ->Flash cache emptied: 456 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Woodruff ->Temp folder emptied: 10220410 bytes ->Temporary Internet Files folder emptied: 11429042 bytes ->FireFox cache emptied: 76476838 bytes ->Google Chrome cache emptied: 6778587 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 59617 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1557726 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 773418160 bytes Total Files Cleaned = 948,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11252012_144604 Files\Folders moved on Reboot... C:\Users\Woodruff\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Mbar Log 1 Code:
ATTFilter Malwarebytes Anti-Rootkit 1.1.0.1009 www.malwarebytes.org Database version: v2012.11.25.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Woodruff :: SOKS003 [administrator] 25.11.2012 14:59:22 mbar-log-2012-11-25 (14-59-22).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: PUP | PUM | P2P Objects scanned: 6180 Time elapsed: 3 minute(s), 15 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 22 HKCR\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCR\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCR\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCR\wit4ie.WitBHO.2 (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCR\wit4ie.WitBHO (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Delete on reboot. [156c6e4bb0adf83ef478f61a19e9b34d] HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Delete on reboot. [156c6e4bb0adf83ef478f61a19e9b34d] HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Delete on reboot. [156c6e4bb0adf83ef478f61a19e9b34d] HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Delete on reboot. [156c6e4bb0adf83ef478f61a19e9b34d] HKCR\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCR\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCR\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCR\updatebho.TimerBHO.1 (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCR\updatebho.TimerBHO (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> Delete on reboot. [daa7b801a7b692a42afe2c6506fda759] HKCR\PROTOCOLS\HANDLER\CHROME (PUP.Blabbers) -> Delete on reboot. [0a775366b3aa2214e148cdc4798a748c] Registry Values Detected: 2 HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Delete on reboot. [daa7b801a7b692a42afe2c6506fda759] HKCR\protocols\Handler\chrome|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Delete on reboot. [0a775366b3aa2214e148cdc4798a748c] Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 4 C:\Program Files (x86)\BrowserCompanion (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] Files Detected: 51 C:\Program Files (x86)\BrowserCompanion\jsloader.dll (PUP.Blabbers) -> Delete on reboot. [3e43caef4d10dd59f37800103ac81ae6] C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (PUP.Blabbers) -> Delete on reboot. [156c6e4bb0adf83ef478f61a19e9b34d] C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll (PUP.Blabbers) -> Delete on reboot. [1d645069c8954ee8ea80d53bb949bb45] C:\Program Files (x86)\BrowserCompanion\blabbers-ff-full.xpi (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\logo.ico (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\toolbar.dll (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\uninstall.exe (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\updater.ini (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Program Files (x86)\BrowserCompanion\widgetserv.exe (PUP.Blabbers) -> Delete on reboot. [cbb6d1e888d557dfa08bb6db13f03bc5] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\BCHelper.exe (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\fix2.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\icon.png (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\lock.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\witapi.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\witmain.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\8ffbb13aa6f702b0cafab391f90d1db7_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\2a86ac4f3322238b4f27d14a09839275 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\2a86ac4f3322238b4f27d14a09839275_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\3023ea304694934d7ae4a2980eb93de4 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\3023ea304694934d7ae4a2980eb93de4_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\7d61457befacdfa8390e7fb224e39ea1 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\7d61457befacdfa8390e7fb224e39ea1_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\8ffbb13aa6f702b0cafab391f90d1db7 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\a38dbdd1af07f4236d43e8fd995f57a6 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\a38dbdd1af07f4236d43e8fd995f57a6_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\b2838e48188f7cc4b9b0ecaddfa35418 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\b2838e48188f7cc4b9b0ecaddfa35418_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\b67ae40ff20f98eb9d7904c21b97a16d (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\b67ae40ff20f98eb9d7904c21b97a16d_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\bf73732e1f0b76bac435293ba3880579 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\bf73732e1f0b76bac435293ba3880579_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\d89bfd841403290d610bcf662008b443 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\d89bfd841403290d610bcf662008b443_expire (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] C:\Users\Woodruff\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271 (PUP.Blabbers) -> Delete on reboot. [dda4ffba332a4cea33821e445ba7ef11] (end) Code:
ATTFilter Malwarebytes Anti-Rootkit 1.1.0.1009 www.malwarebytes.org Database version: v2012.11.25.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Woodruff :: SOKS003 [administrator] 25.11.2012 15:06:02 mbar-log-2012-11-25 (15-06-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: PUP | PUM | P2P Objects scanned: 6019 Time elapsed: 2 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Vielen Dank für deine Hilfe |
26.11.2012, 03:18 | #5 |
/// Helfer-Team | Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Also keine Logs im c:\ gefunden? danach: Sehr gut! Wie laeuft der Rechner? Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
26.11.2012, 18:19 | #6 |
| Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Hey danke nochmal für deine Hilfe, also auch unter C:\ liegt nix hab extra nochmal geschaut. Der Rechner läuft jetzt eigentlich super, mir fällt nichts auf. Leider kann ich Emisoft Anti Maleware nicht laden weil Filepony nicht läd. LG und nochmal Danke |
27.11.2012, 12:40 | #7 |
/// Helfer-Team | Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. War wohl Serverausfall, jetzt geht es, bitte mit Emsisoft weitermachen. |
19.01.2013, 16:41 | #8 |
/// Helfer-Team | Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Themen zu Downloads wie Flash, Java oder Firefox Updates laden sehr langsam. Unbekannte Downloads laden jedoch schnell. |
bekannte, dateien, download, downloads, einfach, facebook, firefox, flash, größere, java, laden, malware, merkwürdiges, plugin, problem, probleme, riesen, schnell, seite, seiten, spezielle downloads langsam, spielen, tagen, unbekannte, update, updates, weiteren |