![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: PC langsam, Downloads brechen abWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #1 |
![]() ![]() | PC langsam, Downloads brechen ab Hi, habe ein Problem mit meinem PC. Es handelt sich um ein älteres Teil aber es ging bis jetzt immer ganz okay. Jetzt is der PC super langsam, und wenn ich über den IE was runterladen will, dann bricht der Download nach einer kurzen Zeit ab. HiJackthis hab ich schon durch also hier ein Escan log: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Header
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
find.bat Version 2007.06.16.01
Microsoft Windows XP [Version 5.1.2600]
Bootmodus: NORMAL
eScan Version: 9.2.8
Sprache: English
Virus Database Date: 6/28/2007
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infektionsmeldungen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
System found infected with funwebproducts Spyware/Adware ({147a976f-eee1-4377-8ea7-4716e4cdd239})! Action taken: No Action Taken.
System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken.
System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken.
System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken.
System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken.
System found infected with funwebproducts Spyware/Adware ({147a976f-eee1-4377-8ea7-4716e4cdd239})! Action taken: No Action Taken.
System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken.
System found infected with hotbar Spyware/Adware ({74cc49f7-eb32-4a08-b204-948962a6e3db})! Action taken: No Action Taken.
System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken.
System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "funwebproducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
~~~~~~~~~~~
Dateien
~~~~~~~~~~~
~~~~ Infected files
~~~~~~~~~~~
~~~~~~~~~~~
~~~~ Tagged files
~~~~~~~~~~~
File C:\Documents and Settings\Beth\Local Settings\Temporary Internet Files\Content.IE5\ALW9UZC9\hbtools[1].exe//data0018//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken.
File C:\Documents and Settings\Beth\Local Settings\Temporary Internet Files\Content.IE5\ALW9UZC9\hbtools[1].exe//data0018//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101572.exe tagged as "not-a-virus:AdWare.Win32.HotBar.bt". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101573.dll tagged as "not-a-virus:AdWare.Win32.HotBar.be". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101575.exe tagged as "not-a-virus:AdWare.Win32.HotBar.by". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101576.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bz". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101578.exe tagged as "not-a-virus:AdWare.Win32.HotBar.by". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101579.exe tagged as "not-a-virus:AdWare.Win32.HotBar.bw". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101580.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bj". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101582.exe tagged as "not-a-virus:AdWare.Win32.Hotbar.an". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101584.dll tagged as "not-a-virus:AdWare.Win32.Hotbar.ar". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0101585.exe//data0002 tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102443.dll tagged as "not-a-virus:AdWare.Win32.HotBar.bx". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102444.exe//UPX tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP258\A0102445.dll tagged as "not-a-virus:AdWare.Win32.180Solutions.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102455.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102456.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102457.scr tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102458.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102459.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102460.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102461.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102462.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102463.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102464.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102466.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.bc". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102467.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102468.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.l". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102469.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.af". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102470.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102471.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102472.SCR tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102473.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102474.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102475.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.an". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102476.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.aq". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102477.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102479.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.bc". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102480.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ax". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102482.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.at". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102484.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102485.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102486.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ad". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102488.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102489.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102490.EXE tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102491.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102492.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102493.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.i". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102500.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102501.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102502.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.au". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102503.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102507.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102508.DLL tagged as "not-a-virus:AdTool.Win32.MyWebSearch.as". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{65421CB6-CA6F-485D-97F5-131BA2DEC3F4}\RP259\A0102696.dll tagged as "not-a-virus:AdTool.Win32.MyWebSearch.ba". Action Taken: No Action Taken.
~~~~~~~~~~~
~~~~ Offending files
~~~~~~~~~~~
Offending file found: C:\Documents and Settings\Victoria\Desktop\internet.lnk
Offending file found: C:\Documents and Settings\Victoria\Desktop\internet.lnk
~~~~~~~~~~~
Ordner
~~~~~~~~~~~
Offending Folder found: C:\Program Files\hotbar
Offending Folder found: C:\Program Files\mywebsearch
Offending Folder found: C:\Documents and Settings\Victoria\Application Data\funwebproducts
Offending Folder found: C:\Documents and Settings\Victoria\Application Data\funwebproducts
~~~~~~~~~~~
Registry
~~~~~~~~~~~
Offending Key found: HKLM\Software\focusinteractive !!!
Offending Key found: HKLM\Software\fun web products !!!
Offending Key found: HKLM\Software\funwebproducts !!!
Offending Key found: HKLM\Software\magnet !!!
Offending Key found: HKLM\Software\mywebsearch !!!
Offending Key found: HKCU\Software\fun web products !!!
Offending Key found: HKCU\Software\funwebproducts !!!
Offending Key found: HKCU\Software\mywebsearch !!!
Offending Key found: HKCU\\magnet !!!
Offending Key found: HKLM\Software\focusinteractive !!!
Offending Key found: HKLM\Software\fun web products !!!
Offending Key found: HKLM\Software\funwebproducts !!!
Offending Key found: HKLM\Software\magnet !!!
Offending Key found: HKLM\Software\mywebsearch !!!
Offending Key found: HKCU\Software\fun web products !!!
Offending Key found: HKCU\Software\funwebproducts !!!
Offending Key found: HKCU\Software\mywebsearch !!!
Offending Key found: HKCU\\magnet !!!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Diverses
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Prozesse und Module
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Scanfehler
~~~~~~~~~~~~~~~~~~~~~~
C:\DOCUME~1\Victoria\LOCALS~1\TEMPOR~1\Content.IE5\W7M72UV0\iTunesSetup[1].exe not Scanned. Possibly password protected...
~~~~~~~~~~~~~~~~~~~~~~
Hosts-Datei
~~~~~~~~~~~~~~~~~~~~~~
DataBasePath: %SystemRoot%\System32\drivers\etc
C:\WINDOWS\System32\drivers\etc\hosts :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Total Critical Objects: 18
Total Critical Objects: 70
Total Disinfected Objects: 0
Total Disinfected Objects: 0
Total Objects Renamed: 0
Total Objects Renamed: 0
Total Deleted Objects: 0
Total Deleted Objects: 0
Total Errors: 21
Total Errors: 11
Time Elapsed: 00:49:39
Time Elapsed: 02:13:05
Total Objects Scanned: 55309
Total Objects Scanned: 97365
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan-Optionen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Memory Check: Enabled
Memory Check: Enabled
Registry Check: Enabled
Registry Check: Enabled
System Folder Check: Enabled
System Folder Check: Enabled
System Area Check: Disabled
System Area Check: Disabled
Services Check: Enabled
Services Check: Enabled
Drive Check: Disabled
All Drive Check :Enabled
Drive Check: Disabled
All Drive Check :Enabled
All Drive Check :Enabled
All Drive Check :Enabled
Batchstart: 15:39:05.86
Batchende: 15:39:28.43
|
| Themen zu PC langsam, Downloads brechen ab |
| .dll, 1.exe, application, brechen ab, check, content.ie5, dateien, desktop, download, drivers, escan, fehler, file, handel, hosts-datei, infected, langsam, log, object, ordner, pc langsam, problem, prozesse, registry, software, super, system, system volume information, system32, virus, windows, windows xp, windows\system32\drivers |