|
Log-Analyse und Auswertung: PC plötzlich total langsam (VISTA)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.01.2008, 11:52 | #1 |
| PC plötzlich total langsam (VISTA) Hallo. Ich hoffe, Ihr könnt mir vielleicht helfen... Seit gestern läuft mein PC aus mir unerklärlichen Gründen total langsam. Beim Googlen bin ich zufällig auf diese Seite gestoßen. Ich habe das hijack Logfile angehängt, vielleicht ist da etwas ersichtliches drin.... Und noch eine Frage: Warum steht das irgendwas von Yahoo drin, obwohl ich damit noch nichts zu tun gehabt habe... LG Christina Logfile of HijackThis v1.99.1 Scan saved at 11:40:36, on 25.01.2008 Platform: Unknown Windows (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\IZArc\IZArc.exe C:\Users\CHRIST~1\AppData\Local\Temp\ARCA4E7\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://de.rd.yahoo.com/customize/ycomp/defaults/sp/*http://de.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://de.intl.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.intl.acer.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://de.rd.yahoo.com/customize/ycomp/defaults/su/*http://de.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKCU\..\Run: [?????????] ??????????????e O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://static.ak.studivz.net/photouploader/ImageUploader4.cab?nocache=20071128-1 O20 - Winlogon Notify: WgaLogon - C:\Windows\ O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HWR - Sysinternals - www.sysinternals.com - C:\Users\CHRIST~1\AppData\Local\Temp\HWR.exe O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing) O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe |
25.01.2008, 12:13 | #2 |
/// TB-Ausbilder | PC plötzlich total langsam (VISTA) Hi,
__________________Ich muss gleich als erstes Mal sagen, dass ich mich mit Vista nicht soo gut auskenn. Allerdings kann ich dir sagen, dass die von dir verwendete HJT-Version für Vista nicht die richtige ist. Benutze bitte folgende Version: klick Die Anleitung dazu befindet sich zb hier Erstelle bitte auch ein Log mit dem 2. Tool aus der Anleitung, dem filelist. Mache bitte auch noch Logs mit folgenden Tools: - Silentrunners - Blacklight Dann sollten wir sehen, was nicht stimmt. lg myrtille |
25.01.2008, 13:34 | #3 |
| PC plötzlich total langsam (VISTA) Logfile of Trend Micro HijackThis v2.0.2
__________________Scan saved at 12:51:50, on 25.01.2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Grisoft\AVG7\avgwb.dat C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe C:\Windows\system32\firewallSettings.exe C:\Windows\system32\FirewallSettings.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://de.rd.yahoo.com/customize/ycomp/defaults/sp/*http://de.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://de.intl.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.intl.acer.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://de.rd.yahoo.com/customize/ycomp/defaults/su/*http://de.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [?????????] ??????????????e O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user') O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O13 - Gopher Prefix: O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://static.ak.studivz.net/photouploader/ImageUploader4.cab?nocache=20071128-1 O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Automatisches LiveUpdate - Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HWR - Sysinternals - www.sysinternals.com - C:\Users\CHRIST~1\AppData\Local\Temp\HWR.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 7036 bytes |
25.01.2008, 13:36 | #4 |
| PC plötzlich total langsam (VISTA) VistaFind 2. Teil Verzeichnis von C:\Users\CHRIST~1\AppData\Local\Temp 25.01.2008 12:38 855 jusched.log 25.01.2008 12:27 166.224 avg7inst.log 25.01.2008 12:26 621.614 MSI6eae6.LOG 25.01.2008 12:21 435.906 Norton Setup 10,1,0 1-25-2008 12h6m3s.log 25.01.2008 12:18 171 isDel.bat 25.01.2008 12:18 8.952.542 Norton Internet Security 2007 Uninstall 1-25-2008 12h6m11s.log 25.01.2008 12:17 5.266 SNDunin.log 25.01.2008 12:17 11.454 SYMEVENT.LOG 25.01.2008 12:17 3.163 IDSinst.LOG 25.01.2008 12:12 9.078 srtUnin.log 25.01.2008 11:25 461.696 HWR.exe 24.01.2008 16:47 4.592 SIntfIcn.ani 24.01.2008 16:47 24.516 SIntfNT.dll 24.01.2008 16:47 19.924 SIntf32.dll 24.01.2008 16:47 12.067 SIntf16.dll 24.01.2008 16:47 36.864 CmdLineExt02.dll 23.01.2008 14:39 0 h2r2B83.tmp 23.01.2008 14:39 5.149 r2h2B63.tmp 23.01.2008 12:16 1.650 wmplog04.sqm 23.01.2008 12:13 1.830 wmplog00.sqm 23.01.2008 11:23 1.179.648 7.4.20.2-EasyShrx.Dll 21.01.2008 14:43 131.072 d82d.rra 21.01.2008 14:42 147.456 48ce.rra 21.01.2008 14:25 0 DMI99BB.tmp 21.01.2008 13:55 1.462 wmplog03.sqm 21.01.2008 08:35 1.412 wmplog02.sqm 19.01.2008 22:08 1.586 wmplog01.sqm 18.01.2008 22:01 127 D653F3EC.TMP 17.01.2008 13:02 32.848 Administrator.bmp 16.01.2008 21:53 524 srtspsp.dat 42 Datei(en), 14.136.202 Bytes 0 Verzeichnis(se), 27.474.550.784 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Windows\prefetch 25.01.2008 13:14 16.018 DLLHOST.EXE-766398D2.pf 25.01.2008 13:14 61.518 CONSENT.EXE-531BD9EA.pf 25.01.2008 13:13 14.038 SEARCHFILTERHOST.EXE-77482212.pf 25.01.2008 13:13 23.322 SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf 25.01.2008 13:13 15.274 DLLHOST.EXE-5E46FA0D.pf 25.01.2008 13:13 18.606 VERCLSID.EXE-7C52E31C.pf 25.01.2008 13:13 21.800 GOOGLETOOLBAR1USER.EXE-B7E47A27.pf 25.01.2008 13:12 17.178 FLASHUTIL9E.EXE-9F0CDBD8.pf 25.01.2008 13:09 22.416 NOTEPAD.EXE-D8414F97.pf 25.01.2008 13:08 50.762 WMIPRVSE.EXE-1628051C.pf 25.01.2008 13:05 125.318 EXPLORER.EXE-A80E4F97.pf 25.01.2008 13:05 113.792 WERCON.EXE-E36BD04E.pf 25.01.2008 13:04 31.520 WERFAULT.EXE-E69F695A.pf 25.01.2008 12:54 16.230 MPCMDRUN.EXE-F401FBB4.pf 25.01.2008 12:48 120.172 IEXPLORE.EXE-908C99F8.pf 25.01.2008 12:48 30.550 WERMGR.EXE-0F2AC88C.pf 25.01.2008 12:48 36.900 IEUSER.EXE-7C0FE221.pf 25.01.2008 12:47 18.180 FIREWALLSETTINGS.EXE-26A7E14B.pf 25.01.2008 12:47 93.664 TRUSTEDINSTALLER.EXE-3CC531E5.pf 25.01.2008 12:47 27.134 TASKENG.EXE-48D4E289.pf 25.01.2008 12:47 22.260 FIREWALLCONTROLPANEL.EXE-3F1BCAAB.pf 25.01.2008 12:46 36.140 RUNDLL32.EXE-7DFD42F1.pf 25.01.2008 12:42 49.240 AD-AWARE2007.EXE-554FC3F0.pf 25.01.2008 12:42 45.464 AAWSERVICE.EXE-CF90ECB3.pf 25.01.2008 12:41 67.664 LSUPDATEMANAGER.EXE-3C4FECCA.pf 25.01.2008 12:39 31.398 AD-WATCH2007.EXE-CECFF9CB.pf 25.01.2008 12:39 127.612 AVGINET.EXE-0658186F.pf 25.01.2008 12:38 127.918 AVGWB.DAT-9BEA3D8F.pf 25.01.2008 12:38 109.666 AVGW.EXE-44073A5A.pf 25.01.2008 12:37 20.156 WMIADAP.EXE-F8DFDFA2.pf 25.01.2008 12:36 32.400 WUAUCLT.EXE-70318591.pf 25.01.2008 12:35 104.880 AVGWSC.EXE-E66FD150.pf 25.01.2008 12:35 50.704 RUNDLL32.EXE-E8AC3089.pf 25.01.2008 12:35 19.674 CONTROL.EXE-817F8F1D.pf 25.01.2008 12:34 33.422 AGENT.EXE-D2852D29.pf 25.01.2008 12:34 20.536 MOBSYNC.EXE-C5E2284F.pf 25.01.2008 12:34 59.800 SVCHOST.EXE-DD6406E8.pf 25.01.2008 12:34 1.991.370 NTOSBOOT-B00DFAAD.pf 25.01.2008 12:29 1.295.800 AgGlFgAppHistory.db 25.01.2008 12:29 685.199 AgGlFaultHistory.db 25.01.2008 12:29 2.400.989 AgGlGlobalHistory.db 25.01.2008 12:29 548.392 AgRobust.db 25.01.2008 12:29 508 PfSvPerfStats.bin 25.01.2008 12:29 37.318 LOGONUI.EXE-09140401.pf 25.01.2008 12:27 105.956 AVGCC.EXE-C682FED5.pf 25.01.2008 12:27 108.314 AVGAMSVR.EXE-EAA17DE7.pf 25.01.2008 12:27 106.336 AVGEMC.EXE-94D72343.pf 25.01.2008 12:27 106.744 AVGRSSVC.EXE-1E7655DF.pf 25.01.2008 12:26 22.826 AVGUPSVC.EXE-20C3B947.pf 25.01.2008 12:24 38.858 MSIEXEC.EXE-A2D55CB6.pf 25.01.2008 12:21 20.482 SVCHOST.EXE-7CFEDEA3.pf 25.01.2008 12:21 39.246 VSSVC.EXE-B8AFC319.pf 25.01.2008 12:21 5.594 LUINIT.EXE-37541056.pf 25.01.2008 12:21 23.802 LSETUP.EXE-049D00FE.pf 25.01.2008 12:21 19.992 DLLHOST.EXE-7FAA2E4C.pf 25.01.2008 12:21 13.976 ALUSCHEDULERSVC.EXE-46534E5E.pf 25.01.2008 12:21 55.946 LUCOMS~1.EXE-F2E330F7.pf 25.01.2008 12:21 26.936 CMD.EXE-4A81B364.pf 25.01.2008 12:17 19.174 SEVINST.EXE-BD639899.pf 25.01.2008 12:17 45.682 SEVINST.EXE-3CB4F161.pf 25.01.2008 12:17 45.392 IDSINST.EXE-A221B636.pf 25.01.2008 12:16 23.898 ISPWDSVC.EXE-7F209BCA.pf 25.01.2008 12:16 30.122 MSI5B7B.TMP-01AE4C7C.pf 25.01.2008 12:15 39.918 REGISTERMCEAPP.EXE-9D2CDFB3.pf 25.01.2008 12:15 19.756 SYMLCSVC.EXE-C9160B19.pf 25.01.2008 12:14 19.180 SEVINST.EXE-9A5506B8.pf 25.01.2008 12:10 16.490 DLLHOST.EXE-8EF34503.pf 25.01.2008 12:09 23.570 AVGSETUP.EXE-00993EA2.pf 25.01.2008 12:09 107.726 AVG75FREE_516A1225[1].EXE-7F76B46C.pf 25.01.2008 12:09 65.474 AAW2007V7.0.2.3[1].EXE-084810C8.pf 25.01.2008 12:06 39.042 {5AA2CD16-706F-41F3-87C5-2B5A-B448193D.pf 25.01.2008 11:54 26.746 _IU14D2N.TMP-6770265E.pf 25.01.2008 11:54 20.600 UNINS000.EXE-3922950D.pf 25.01.2008 11:54 16.356 UNINS000.EXE-989DA231.pf 25.01.2008 11:45 157.686 WINMAIL.EXE-1092D371.pf 25.01.2008 11:39 19.250 HIJACKTHIS.EXE-E2A39DFE.pf 25.01.2008 11:39 54.542 IZARC.EXE-B9F4341B.pf 25.01.2008 11:36 40.486 TASKMGR.EXE-5F5F473D.pf 25.01.2008 11:32 1.116.592 AgCx_S1_S-1-5-21-1252488340-3432948945-3923439615-1000.snp.db 25.01.2008 11:31 9.464 ATBROKER.EXE-2E15A492.pf 25.01.2008 11:30 262.994 AgCx_SC3_6D904E68.db 25.01.2008 11:30 23.288 UI0DETECT.EXE-A794C8BB.pf 25.01.2008 11:30 17.714 VFUZPI.EXE-19939999.pf 25.01.2008 11:30 23.184 ROOTKITREVEALER.EXE-882EA83F.pf 25.01.2008 11:29 17.426 ATI2EVXX.EXE-0327F1E7.pf 25.01.2008 11:29 24.266 WINLOGON.EXE-B020DC41.pf 25.01.2008 11:28 29.154 CSRSS.EXE-3FE41F7E.pf 25.01.2008 11:28 3.684 SMSS.EXE-E9C28FC6.pf 25.01.2008 11:27 7.282 CHCP.COM-61043047.pf 25.01.2008 11:26 20.486 RYTWPYHVD.EXE-C0E804E2.pf 25.01.2008 11:26 16.738 ROOTKITREVEALER.EXE-3D8DA115.pf 25.01.2008 11:25 21.564 HWR.EXE-1F3F6B42.pf 25.01.2008 11:25 20.438 ROOTKITREVEALER.EXE-DDCE90DC.pf 25.01.2008 11:21 42.996 GOOGLEUPDATER.EXE-39628337.pf 25.01.2008 11:18 151.654 LUCALLBACKPROXY.EXE-63F065B5.pf 25.01.2008 11:16 18.128 MPSIGSTUB.EXE-D8A1640B.pf 25.01.2008 11:16 11.930 MPAS-D.EXE-40FE95BA.pf 25.01.2008 11:15 37.698 AUPDATE.EXE-F14A3D51.pf 25.01.2008 11:11 18.412 PRESENTATIONSETTINGS.EXE-2F4708C9.pf 25.01.2008 11:11 116.012 WMPNETWK.EXE-D9F2A96F.pf 25.01.2008 11:07 209.542 WINDOWS-KB890830-V1.37.EXE-13737EC9.pf 25.01.2008 11:07 17.770 MRTSTUB.EXE-EA36500B.pf 24.01.2008 21:06 678.327 AgCx_SC2.db 24.01.2008 16:49 24.462 WAR3.EXE-EBDEDE10.pf 24.01.2008 16:49 17.972 WARCRAFT III.EXE-17B13300.pf 24.01.2008 16:49 28.838 RUNDLL32.EXE-5FE6719B.pf 24.01.2008 16:46 17.698 MRTSTUB.EXE-E9282197.pf 24.01.2008 16:45 62.856 HELPPANE.EXE-FEDC965B.pf 24.01.2008 16:43 30.316 WUAPP.EXE-C6167071.pf 24.01.2008 16:04 1.175.569 AgGlUAD_P_S-1-5-21-1252488340-3432948945-3923439615-1000.db 24.01.2008 16:04 1.289.913 AgGlUAD_S-1-5-21-1252488340-3432948945-3923439615-1000.db 24.01.2008 11:40 704.726 AgCx_SC1.db 24.01.2008 11:39 287.342 AgCx_SC1.db.trx 24.01.2008 11:39 27.228 SSAUTORN.EXE-E6E36F94.pf 24.01.2008 10:56 22.036 DLLHOST.EXE-C373C89E.pf 24.01.2008 10:54 31.706 RUNDLL32.EXE-6B0F4161.pf 24.01.2008 09:48 30.698 DWM.EXE-6FFD3DA8.pf 24.01.2008 09:48 12.208 USERINIT.EXE-2257A3E7.pf 24.01.2008 09:48 21.984 RUNONCE.EXE-D0649312.pf 24.01.2008 09:48 48.976 CLI.EXE-CCC9251D.pf 24.01.2008 09:24 48.042 LUCOMSERVER_3_2.EXE-C5DF32C7.pf 24.01.2008 08:22 1.213.488 Layout.ini 24.01.2008 06:06 19.842 SYMLCSVC.EXE-6FCCB913.pf 24.01.2008 06:06 12.692 SYMLCSV1.EXE-BEA9F10E.pf 24.01.2008 03:02 17.758 MRTSTUB.EXE-7092B733.pf 24.01.2008 01:10 760 RUNDLL32.EXE-230FC512.pf 24.01.2008 00:31 29.406 LOGON.SCR-30601369.pf 24.01.2008 00:14 25.310 SYMLCSVC.EXE-3ACB1A24.pf 24.01.2008 00:14 50.544 LUALL.EXE-FFC9570F.pf 24.01.2008 00:14 23.490 NOTIFYHA.EXE-8C0F8427.pf 23.01.2008 23:09 143.614 SOFFICE.BIN-AA830623.pf 23.01.2008 23:09 19.052 SOFFICE.EXE-B6F4ED48.pf 23.01.2008 22:54 31.498 ALUNOTIFY.EXE-E106665C.pf 23.01.2008 21:37 25.660 SETUP.EXE-9922217F.pf 23.01.2008 17:48 66.692 ACRORD32.EXE-C7F7B209.pf 23.01.2008 17:47 8.978 PCAUI.EXE-3E82C312.pf 23.01.2008 17:16 11.322 SYMLCSV1.EXE-6D0EEDBF.pf 23.01.2008 17:07 1.150 MCUPDATE.EXE-62E74733.pf 23.01.2008 16:43 12.690 CALC.EXE-77FDF17F.pf 23.01.2008 12:16 38.952 WLLOGINPROXY.EXE-9E0DCEF8.pf 23.01.2008 10:36 22.966 FLASHUTIL9D.EXE-8BB72153.pf 143 Datei(en), 20.448.131 Bytes 0 Verzeichnis(se), 27.474.534.400 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Windows\tasks 25.01.2008 12:32 6 SA.DAT 25.01.2008 12:29 32.592 SCHEDLGU.TXT 3 Datei(en), 33.010 Bytes 0 Verzeichnis(se), 27.474.542.592 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Program Files 25.01.2008 12:51 <DIR> . 25.01.2008 12:51 <DIR> .. 25.01.2008 12:17 <DIR> Common Files 23.01.2008 18:45 <DIR> Creative 25.01.2008 12:26 <DIR> Grisoft 16.01.2008 22:22 <DIR> Internet Explorer 25.01.2008 12:24 <DIR> Lavasoft 22.01.2008 01:01 <DIR> Microsoft CAPICOM 2.1.0.2 25.01.2008 12:51 <DIR> Trend Micro 24.01.2008 17:02 <DIR> Warcraft III 22.10.2007 11:03 <DIR> Windows Calendar 16.01.2008 21:58 <DIR> Windows Mail 21.01.2008 23:21 <DIR> Windows Resource Kits 16.01.2008 22:22 <DIR> Windows Sidebar 0 Datei(en), 0 Bytes 56 Verzeichnis(se), 27.474.538.496 Bytes frei |
25.01.2008, 13:37 | #5 |
| PC plötzlich total langsam (VISTA) VistaFind 1. Teil Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\ 25.01.2008 13:14 0 VistaFind.txt 25.01.2008 12:32 937.607.168 hiberfil.sys 25.01.2008 12:32 1.251.540.992 pagefile.sys 12.01.2008 20:42 0 IO.SYS 12.01.2008 20:42 0 MSDOS.SYS 12 Datei(en), 2.189.587.991 Bytes 0 Verzeichnis(se), 27.474.677.760 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Windows 25.01.2008 12:57 1.264.708 WindowsUpdate.log 25.01.2008 12:32 67.584 bootstat.dat 25.01.2008 12:32 129.853.124 MEMORY.DMP 25.01.2008 12:32 131.994 PFRO.log 16.01.2008 22:05 266.396 msxml4-KB941833-deu.LOG 06.01.2008 20:08 8.428 setupact.log 63 Datei(en), 152.927.366 Bytes 0 Verzeichnis(se), 27.474.673.664 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Windows\system 22 Datei(en), 700.380 Bytes 0 Verzeichnis(se), 27.474.673.664 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 Verzeichnis von C:\Windows\system32 25.01.2008 12:41 12.632 lsdelete.exe 25.01.2008 12:38 1.492.044 PerfStringBackup.TMP 25.01.2008 12:32 3.200 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 25.01.2008 12:32 3.200 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 25.01.2008 12:26 9.216 avgwlntf.dll 25.01.2008 12:15 904.595.535 NFSXWT 22.01.2008 00:25 9.728 LAPRXY.DLL 22.01.2008 00:25 2.048 asferror.dll 22.01.2008 00:25 223.232 WMASF.DLL 21.01.2008 23:59 1.524.224 wucltux.dll 21.01.2008 23:59 43.352 wups2.dll 21.01.2008 23:59 53.080 wuauclt.exe 21.01.2008 23:59 1.712.984 wuaueng.dll 21.01.2008 23:59 80.896 wudriver.dll 21.01.2008 23:59 33.624 wups.dll 21.01.2008 23:58 549.720 wuapi.dll 21.01.2008 23:58 163.000 wuwebv.dll 21.01.2008 23:58 31.232 wuapp.exe 21.01.2008 23:49 248.744 FNTCACHE.DAT 16.01.2008 22:16 11.776 sbunattend.exe 16.01.2008 22:15 24.064 netcfg.exe 16.01.2008 22:15 167.424 tcpipcfg.dll 16.01.2008 22:15 22.016 netiougc.exe 16.01.2008 22:12 4.247.552 GameUXLegacyGDFs.dll 16.01.2008 22:12 1.686.016 gameux.dll 16.01.2008 22:09 180.736 ieui.dll 16.01.2008 22:09 6.065.664 ieframe.dll 16.01.2008 22:09 478.208 mshtmled.dll 16.01.2008 22:09 3.590.656 mshtml.dll 16.01.2008 22:09 1.383.424 mshtml.tlb 16.01.2008 22:09 124.928 advpack.dll 16.01.2008 22:09 824.832 wininet.dll 16.01.2008 22:09 27.648 jsproxy.dll 16.01.2008 22:09 1.159.680 urlmon.dll 16.01.2008 22:09 383.488 ieapfltr.dll 16.01.2008 22:09 214.528 dxtrans.dll 16.01.2008 22:09 347.136 dxtmsft.dll 16.01.2008 22:09 671.232 mstime.dll 16.01.2008 22:09 63.488 icardie.dll 16.01.2008 22:09 1.830.912 inetcpl.cpl 16.01.2008 22:09 26.624 ieUnatt.exe 16.01.2008 22:09 70.656 ie4uinit.exe 16.01.2008 22:09 44.544 iernonce.dll 16.01.2008 22:09 56.320 iesetup.dll 16.01.2008 22:06 3.504.824 ntkrnlpa.exe 16.01.2008 22:06 3.470.520 ntoskrnl.exe 16.01.2008 22:05 1.327.104 quartz.dll 16.01.2008 22:03 21.504 netbtugc.exe 16.01.2008 22:01 2.048 tzres.dll 16.01.2008 21:59 1.585.152 setupapi.dll 2412 Datei(en), 1.814.395.276 Bytes 0 Verzeichnis(se), 27.474.485.248 Bytes frei Datentr„ger in Laufwerk C: ist ACER Volumeseriennummer: 6C0A-CB69 |
25.01.2008, 13:38 | #6 |
| PC plötzlich total langsam (VISTA) "Silent Runners.vbs", revision 55, http://www.silentrunners.org/ Operating System: Windows Vista Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "****r" (unwritable string) = "*cÄa*******" (unwritable string) [file not found] "*********" (unwritable string) = "**************e" (unwritable string) [file not found] "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ["Google Inc."] "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [file not found] "Sidebar" = "C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [MS] "ISUSPM Startup" = ""C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup" ["Macrovision Corporation"] "WMPNSCFG" = "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"" ["Sun Microsystems, Inc."] "Windows Mobile-based device management" = "C:\Windows\WindowsMobile\wmdSync.exe" "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper" \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll" ["Sun Microsystems, Inc."] {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided) -> {HKLM...CLSID} = "Google Toolbar Helper" \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Germany GmbH"] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided) -> {HKLM...CLSID} = "Google Toolbar Notifier BHO" \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll" ["Google Inc."] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."] "{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0}" = "EPM-PO Shell Extension" -> {HKLM...CLSID} = "EPM-PO Shell Extensions" \InProcServer32\(Default) = "epm-po.dll" [file not found] "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "Nokia Phone Browser" -> {HKLM...CLSID} = "Nokia Phone Browser" \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll" ["Nokia"] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] "{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682}" = "IZArc DragDrop Menu" -> {HKLM...CLSID} = "IZArc DragDrop Menu" \InProcServer32\(Default) = "C:\PROGRA~1\IZArc\IZArcCM.dll" [null data] "{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}" = "IZArc Shell Context Menu" -> {HKLM...CLSID} = "IZArc Shell Context Menu" \InProcServer32\(Default) = "C:\PROGRA~1\IZArc\IZArcCM.dll" [null data] "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension" -> {HKLM...CLSID} = "AVG7 Shell Extension Class" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."] "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension" -> {HKLM...CLSID} = "AVG7 Find Extension Class" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."] HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\ <<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data] HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."] {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" -> {HKLM...CLSID} = "PDF Shell Extension" \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" -> {HKLM...CLSID} = "AVG7 Shell Extension Class" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."] IZArcCM\(Default) = "{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}" -> {HKLM...CLSID} = "IZArc Shell Context Menu" \InProcServer32\(Default) = "C:\PROGRA~1\IZArc\IZArcCM.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ IZArcCM\(Default) = "{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}" -> {HKLM...CLSID} = "IZArc Shell Context Menu" \InProcServer32\(Default) = "C:\PROGRA~1\IZArc\IZArcCM.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" -> {HKLM...CLSID} = "AVG7 Shell Extension Class" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ "ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode} "ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Standard Users} "EnableInstallerDetection" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Detect Application Installations And Prompt For Elevation} "EnableLUA" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Run All Administrators In Admin Approval Mode} "EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Only elevate UIAccess applications that are installed in secure locations} "EnableVirtualization" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Virtualize file and registry write failures to per-user locations} "PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Conrol: Switch to the secure desktop when prompting for elevation} "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} "FilterAdministratorToken" = (REG_DWORD) dword:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Admin Approval Mode for the Built-in Administrator Account} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Users\Christina\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp" Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ "SCRNSAVE.EXE" = "C:\Windows\system32\SSBRAN~1.SCR" [file not found] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS] 000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] 000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 18 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" -> {HKLM...CLSID} = "&Google" \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Germany GmbH"] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided) -> {HKLM...CLSID} = "&Google" \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Germany GmbH"] HOSTS file ---------- C:\Windows\System32\drivers\etc\HOSTS maps: 2 domain names to IP addresses, 1 of the IP addresses is *not* localhost! Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ad-Aware 2007 Service, aawservice, ""C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"" ["Lavasoft"] Ati External Event Utility, Ati External Event Utility, "C:\Windows\system32\Ati2evxx.exe" ["ATI Technologies Inc."] Automatische WLAN-Konfiguration, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]} AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVG7\avgemc.exe" ["GRISOFT, s.r.o."] AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" ["GRISOFT, s.r.o."] AVG7 Resident Shield Service, AvgCoreSvc, "C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe" ["GRISOFT, s.r.o."] AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" ["GRISOFT, s.r.o."] CNG-Schlüsselisolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS] Computerbrowser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]} Cyberlink RichVideo Service(CRVS), RichVideo, ""C:\Program Files\CyberLink\Shared Files\RichVideo.exe"" [empty string] eLock Service, eLockService, "C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe" [null data] eNet Service, eNet Service, "C:\Acer\Empowering Technology\eNet\eNet Service.exe" ["Acer Inc."] ePower Service, WMIService, "C:\Acer\Empowering Technology\ePower\ePowerSvc.exe" ["acer"] eRecovery Service, eRecoveryService, "C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe" [null data] eSettings Service, eSettingsService, "C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe" [null data] Extensible Authentication-Protokoll, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]} Google Updater Service, gusvc, ""C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"" ["Google"] LightScribeService Direct Disc Labeling Service, LightScribeService, ""C:\Program Files\Common Files\LightScribe\LSSrvc.exe"" ["Hewlett-Packard Company"] MobilityService, MobilityService, "C:\Acer\Mobility Center\MobilityService.exe -p" [null data] Windows Driver Foundation - Benutzermodus-Treiberframework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]} Windows Media Player-Netzwerkfreigabedienst, WMPNetworkSvc, ""C:\Program Files\Windows Media Player\wmpnetwk.exe"" [MS] Windows Mobile 2003-basierte Geräteverbindung, WcesComm, "C:\Windows\system32\svchost.exe -k WindowsMobile" {"C:\Windows\WindowsMobile\wcescomm.dll" [MS]} Windows Mobile-basierte Geräteverbindung, RapiMgr, "C:\Windows\system32\svchost.exe -k WindowsMobile" {"C:\Windows\WindowsMobile\rapimgr.dll" [MS]} Windows-Bilderfassung, stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]} XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" ["Conexant Systems, Inc."] Zugriff auf Eingabegeräte, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]} Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ Canon BJ Language Monitor MP160\Driver = "CNMLM83.DLL" ["CANON INC."] ---------- (launch time: 2008-01-25 13:08:03) <<!>>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer "No" at the first message box and "Yes" at the second message box. ---------- (total run time: 54 seconds, including 5 seconds for message boxes) |
25.01.2008, 13:39 | #7 |
| PC plötzlich total langsam (VISTA) Vielen Dank für die schnelle Antwort! Anbei die Logs... BlackLight 01/25/08 13:11:49 [Info]: BlackLight Engine 1.0.67 initialized 01/25/08 13:11:49 [Info]: OS: 6.0 build 6000 () 01/25/08 13:11:50 [Note]: 7019 4 01/25/08 13:11:50 [Note]: 7005 0 01/25/08 13:11:56 [Note]: 7006 0 01/25/08 13:11:56 [Note]: 7027 0 01/25/08 13:11:57 [Note]: 7026 0 01/25/08 13:11:57 [Note]: 7026 0 01/25/08 13:12:04 [Note]: FSRAW library version 1.7.1024 01/25/08 13:30:42 [Note]: 7007 0 |
25.01.2008, 13:55 | #8 | |
/// TB-Ausbilder | PC plötzlich total langsam (VISTA) Hi, lass bitte mal folgende Dateien bei virustotal auswerten: Zitat:
|
25.01.2008, 13:58 | #9 |
| PC plötzlich total langsam (VISTA) Datei hwr.exe__ empfangen 2007.03.25 17:26:23 (CET) Status: Beendet Ergebnis: 1/32 (3.12%) Filter Drucken der Ergebnisse Antivirus Version letzte aktualisierung Ergebnis AhnLab-V3 - - - AntiVir - - - Authentium - - - Avast - - - AVG - - - BitDefender - - - CAT-QuickHeal - - - ClamAV - - - DrWeb - - - eSafe - - - eTrust-Vet - - - Ewido - - - FileAdvisor - - - Fortinet - - suspicious F-Prot - - - F-Secure - - - Ikarus - - - Kaspersky - - - McAfee - - - Microsoft - - - NOD32v2 - - - Norman - - - Panda - - - Prevx1 - - - Sophos - - - Sunbelt - - - Symantec - - - TheHacker - - - UNA - - - VBA32 - - - VirusBuster - - - Webwasher-Gateway - - - weitere Informationen MD5: 93414c458acd8fbd54b0b0d153747c66 SHA1: 7c13532b407c8b7fcddfec7945e2fe660672e2ed SHA256: 38019c5edc99f9c3a141115b6f8e9bdb7eb164a8eb4f619b535e3722be22ac68 SHA512: b572065e07e8d899c39bbe55d0caa2b39028e24c1d4f4dbd013d7c6c73671cf9 c8195cef43538ed4a34dea67b98477870e4a028b7d84fa228e0a9ecf866f0e45 |
25.01.2008, 14:08 | #10 |
/// TB-Ausbilder | PC plötzlich total langsam (VISTA) hmm. Was hast du denn gemacht bevor dein Rechner auf einmal langsam wurde? In deinem Log ist eindeutig Malwarebefall zu erkennen, allerdings werd ich mich dazu erst noch etwas informieren müssen. Der Ursprung des Befalls wäre deswegen hilfreich. Ich hab dich nicht vergessen, auch wenn die Antwort etwas länger dauern könnte. lg myrtille EDIT: Bitte auch die beiden anderen Dateien auswerten lassen. |
25.01.2008, 14:45 | #11 |
| PC plötzlich total langsam (VISTA) Bei den anderen beiden Dateien erscheint "0 bytes size received" Ich hatte die ganze Zeit Probleme mit den Windows Updates. Ich konnte über den Updater keine Updates suchen und installieren. Die Woche habe ich nach verschiedenen Anweisungen in verschiedenen Foren das Problem lösen können. So weit ich es verstanden habe, was ich da gemacht habe, war es ein Fehler mit meinen Admin-Rechten. Das habe ich gemacht: Windows Update Error Code 80070005 Vista Home Premium - TechNet Forums und das: Re: Windows Update Error Code 80070005 Vista Home Premium - TechNet Forums |
25.01.2008, 18:49 | #12 |
/// TB-Ausbilder | PC plötzlich total langsam (VISTA) Ruf mal MSConfig auf und sieh nach ob du dort im Autostart einen Eintrag der Art: *cÄa******* oder ?????????? siehst. Wenn ja, dann deaktivier den mal beim Autostart und schau was passiert. lg myrtille |
25.01.2008, 18:55 | #13 |
| PC plötzlich total langsam (VISTA) Ich hab da was Anderes komisches entdeckt: |
25.01.2008, 19:53 | #14 |
/// TB-Ausbilder | PC plötzlich total langsam (VISTA) Oder ausgefallene Schriftzeichen. Ja. Das ist auf jedenfall der Eintrag den wir suchen. Das sieht nicht gut aus und ich finde derzeit auch keine Infos dazu. Insbesondere fehlt mir die Datei, auf die der Eintrag verweist. Ich vermute mal dein Virenscanner findet auch nichts Auffälliges? Hast du auf den verlinkten Seiten irgendetwas heruntergeladen, dass nicht von Windows war? Was passiert wenn du den chinesischen Eintrag über MSConfig deaktivierst (kann jederzeit rückgängig gemacht werden, indem du MSConfig erneut aufrufst und den Haken wieder setzst) lg myrtille |
25.01.2008, 21:44 | #15 |
| PC plötzlich total langsam (VISTA) Ich möchte mich jetzt erstmal für Deine Mühe bedanken! Ich finde Dein Wissen echt bewundernswert. :aplaus: Also ich kann mich nicht genau dran erinnern, was ich eventuell noch runter geladen habe. Meinen Verlauf habe ich leider erst kürzlich gelöscht. Der Virenscanner hat nichts bemerkt. Ich habe jetzt den Eintrag deaktiviert und Windows neu gestartet.... Daraufhin hat sich der Defender gemeldet, dass ein Autostart geblockt wurde. Ich habe da vielleicht was Interessantes gefunden: |
Themen zu PC plötzlich total langsam (VISTA) |
?????, adobe, bho, browser, drivers, excel, explorer, frage, google, helper, hijack, hijackthis, internet, internet explorer, internet security, langsam, local\temp, logfile, pdf, pop-up-blocker, security, software, solution, svchost.exe, symantec, system, temp, unknown file in winsock lsp, urlsearchhook, vista, warum, windows, windows sidebar, windows\system32\drivers, wmp, yahoo |