![]() |
|
Plagegeister aller Art und deren Bekämpfung: PC langsam, Downloads brechen abWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() PC langsam, Downloads brechen ab Hi, habe ein Problem mit meinem PC. Es handelt sich um ein älteres Teil aber es ging bis jetzt immer ganz okay. Jetzt is der PC super langsam, und wenn ich über den IE was runterladen will, dann bricht der Download nach einer kurzen Zeit ab. HiJackthis hab ich schon durch also hier ein Escan log: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Header ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ find.bat Version 2007.06.16.01 Microsoft Windows XP [Version 5.1.2600] Bootmodus: NORMAL eScan Version: 9.2.8 Sprache: English Virus Database Date: 6/28/2007 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Infektionsmeldungen ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ System found infected with funwebproducts Spyware/Adware ({147a976f-eee1-4377-8ea7-4716e4cdd239})! Action taken: No Action Taken. System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken. System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken. System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken. System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken. System found infected with funwebproducts Spyware/Adware ({147a976f-eee1-4377-8ea7-4716e4cdd239})! Action taken: No Action Taken. System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken. System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken. System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken. System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken. ~~~~~~~~~~~ Dateien ~~~~~~~~~~~ ~~~~ Infected files ~~~~~~~~~~~ ~~~~~~~~~~~ ~~~~ Tagged files ~~~~~~~~~~~ File C:\Documents and Settings\Beth\Local Settings\Temporary Internet Files\Content.IE5\ALW9UZC9\hbtools[1].exe//data0018//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken. File C:\Documents and Settings\Beth\Local Settings\Temporary Internet Files\Content.IE5\ALW9UZC9\hbtools[1].exe//data0018//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101572.exe tagged as "not-a-virus:AdWare.Win32.HotBar.bt". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101573.dll tagged as "not-a-virus:AdWare.Win32.HotBar.be". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101575.exe tagged as "not-a-virus:AdWare.Win32.HotBar.by". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101576.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bz". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101578.exe tagged as "not-a-virus:AdWare.Win32.HotBar.by". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101579.exe tagged as "not-a-virus:AdWare.Win32.HotBar.bw". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101580.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bj". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101582.exe tagged as "not-a-virus:AdWare.Win32.Hotbar.an". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101584.dll tagged as "not-a-virus:AdWare.Win32.Hotbar.ar". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101585.exe//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102443.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bx". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102444.exe//UPX tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102445.dll tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102455.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102456.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102457.scr tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102458.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102459.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102460.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102461.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102462.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102463.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102464.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102466.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.bc". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102467.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102468.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.l". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102469.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.af". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102470.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102471.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102472.SCR tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102473.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102474.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102475.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.an". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102476.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.aq". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102477.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102479.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.bc". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102480.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ax". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102482.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102484.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102485.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102486.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102488.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102489.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102490.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102491.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102492.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102493.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.i". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102500.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102501.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102502.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102503.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102507.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102508.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken. File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102696.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken. ~~~~~~~~~~~ ~~~~ Offending files ~~~~~~~~~~~ Offending file found: C:\Documents and Settings\Victoria\Desktop\internet.lnk Offending file found: C:\Documents and Settings\Victoria\Desktop\internet.lnk ~~~~~~~~~~~ Ordner ~~~~~~~~~~~ Offending Folder found: C:\Program Files\hotbar Offending Folder found: C:\Program Files\mywebsearch Offending Folder found: C:\Documents and Settings\Victoria\Application Data\funwebproducts Offending Folder found: C:\Documents and Settings\Victoria\Application Data\funwebproducts ~~~~~~~~~~~ Registry ~~~~~~~~~~~ Offending Key found: HKLM\Software\focusinteractive !!! Offending Key found: HKLM\Software\fun web products !!! Offending Key found: HKLM\Software\funwebproducts !!! Offending Key found: HKLM\Software\magnet !!! Offending Key found: HKLM\Software\mywebsearch !!! Offending Key found: HKCU\Software\fun web products !!! Offending Key found: HKCU\Software\funwebproducts !!! Offending Key found: HKCU\Software\mywebsearch !!! Offending Key found: HKCU\\magnet !!! Offending Key found: HKLM\Software\focusinteractive !!! Offending Key found: HKLM\Software\fun web products !!! Offending Key found: HKLM\Software\funwebproducts !!! Offending Key found: HKLM\Software\magnet !!! Offending Key found: HKLM\Software\mywebsearch !!! Offending Key found: HKCU\Software\fun web products !!! Offending Key found: HKCU\Software\funwebproducts !!! Offending Key found: HKCU\Software\mywebsearch !!! Offending Key found: HKCU\\magnet !!! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Diverses ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~ Prozesse und Module ~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~ Scanfehler ~~~~~~~~~~~~~~~~~~~~~~ C:\DOCUME~1\Victoria\LOCALS~1\TEMPOR~1\Content.IE5\W7M72UV0\iTunesSetup[1].exe not Scanned. Possibly password protected... ~~~~~~~~~~~~~~~~~~~~~~ Hosts-Datei ~~~~~~~~~~~~~~~~~~~~~~ DataBasePath: %SystemRoot%\System32\drivers\etc C:\WINDOWS\System32\drivers\etc\hosts : ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Total Critical Objects: 18 Total Critical Objects: 70 Total Disinfected Objects: 0 Total Disinfected Objects: 0 Total Objects Renamed: 0 Total Objects Renamed: 0 Total Deleted Objects: 0 Total Deleted Objects: 0 Total Errors: 21 Total Errors: 11 Time Elapsed: 00:49:39 Time Elapsed: 02:13:05 Total Objects Scanned: 55309 Total Objects Scanned: 97365 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan-Optionen ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Memory Check: Enabled Memory Check: Enabled Registry Check: Enabled Registry Check: Enabled System Folder Check: Enabled System Folder Check: Enabled System Area Check: Disabled System Area Check: Disabled Services Check: Enabled Services Check: Enabled Drive Check: Disabled All Drive Check :Enabled Drive Check: Disabled All Drive Check :Enabled All Drive Check :Enabled All Drive Check :Enabled Batchstart: 15:39:05.86 Batchende: 15:39:28.43 |
Themen zu PC langsam, Downloads brechen ab |
.dll, 1.exe, application, brechen ab, check, content.ie5, dateien, desktop, download, drivers, escan, fehler, file, handel, hosts-datei, infected, langsam, log, object, ordner, pc langsam, problem, prozesse, registry, software, super, system, system volume information, system32, virus, windows, windows xp, windows\system32\drivers |