Malware:
schutz-protokoll Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 19.02.2015 10:38:48, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Starting,
Protection, 19.02.2015 10:38:48, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Started,
Protection, 19.02.2015 10:38:48, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 10:40:28, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
Update, 19.02.2015 12:45:49, SYSTEM, ALIENWAREGAMING, Scheduler, Failed, Unable to access update server,
Detection, 19.02.2015 12:47:41, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 50809, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:47:41, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 50809, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:47:41, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 50812, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:47:59, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 50928, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:48:06, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 50976, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:48:23, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51013, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:48:30, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51042, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:48:51, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51095, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:48:58, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51120, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:49:17, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51161, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 12:49:52, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51215, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Protection, 19.02.2015 12:50:28, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopping,
Protection, 19.02.2015 12:50:29, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopped,
Protection, 19.02.2015 12:50:29, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopping,
Protection, 19.02.2015 12:50:30, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopped,
Protection, 19.02.2015 12:53:39, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Starting,
Protection, 19.02.2015 12:53:39, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Started,
Protection, 19.02.2015 12:53:39, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 12:55:21, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
Protection, 19.02.2015 13:11:57, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopping,
Protection, 19.02.2015 13:11:57, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopped,
Protection, 19.02.2015 13:11:57, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopping,
Protection, 19.02.2015 13:11:57, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopped,
Protection, 19.02.2015 14:27:35, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Starting,
Protection, 19.02.2015 14:27:35, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Started,
Protection, 19.02.2015 14:27:35, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 14:29:40, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
Detection, 19.02.2015 14:30:58, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 49800, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:30:58, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 49800, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:30:58, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 49801, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:31:09, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 50046, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:31:24, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 50090, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:49:01, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51255, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:49:01, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.228, adrotator.se, 51255, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:49:06, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 5.150.195.169, adrotator.se, 51273, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:49:06, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 5.150.195.169, adrotator.se, 51273, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 14:51:43, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 5.150.195.169, adrotator.se, 51500, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Protection, 19.02.2015 14:54:59, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopping,
Protection, 19.02.2015 14:54:59, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopped,
Protection, 19.02.2015 14:54:59, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopping,
Protection, 19.02.2015 14:54:59, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopped,
Protection, 19.02.2015 15:03:07, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Starting,
Protection, 19.02.2015 15:03:07, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Started,
Protection, 19.02.2015 15:03:07, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 15:03:07, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
Update, 19.02.2015 15:03:21, SYSTEM, ALIENWAREGAMING, Manual, Malware Database, 2015.2.18.9, 2015.2.19.5,
Protection, 19.02.2015 15:03:21, SYSTEM, ALIENWAREGAMING, Protection, Refresh, Starting,
Protection, 19.02.2015 15:03:21, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopping,
Protection, 19.02.2015 15:03:21, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopped,
Protection, 19.02.2015 15:03:25, SYSTEM, ALIENWAREGAMING, Protection, Refresh, Success,
Protection, 19.02.2015 15:03:25, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 15:03:25, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
Detection, 19.02.2015 15:06:00, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 52593, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 15:06:00, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 52593, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 15:06:01, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 52595, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 15:06:16, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 52646, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Detection, 19.02.2015 15:06:25, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, IP, 80.252.188.229, adrotator.se, 52670, Outbound, C:\Program Files (x86)\Opera\27.0.1689.69_0\opera.exe,
Scan, 19.02.2015 15:14:12, SYSTEM, ALIENWAREGAMING, Manual, Start: % 1 "% 2", Dauer: % 1 min 10 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 0-Malwareerkennung,
Protection, 19.02.2015 15:14:41, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopping,
Protection, 19.02.2015 15:14:41, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Stopped,
Protection, 19.02.2015 15:14:41, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopping,
Protection, 19.02.2015 15:14:42, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Stopped,
Protection, 19.02.2015 20:12:44, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Starting,
Protection, 19.02.2015 20:12:44, SYSTEM, ALIENWAREGAMING, Protection, Malware Protection, Started,
Protection, 19.02.2015 20:12:48, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Starting,
Protection, 19.02.2015 20:12:48, SYSTEM, ALIENWAREGAMING, Protection, Malicious Website Protection, Started,
(end)
ESET: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=8ca566f9d0b6964b9a5550a88b362e8b
# engine=22551
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-19 07:08:49
# local_time=2015-02-19 08:08:49 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 642272 65686245 0 0
# scanned=486170
# found=23
# cleaned=0
# scan_time=17452
sh=D2DCCFB4FE655C8E5E4867F9A15F56AEEA9977C5 ft=1 fh=3d3f7ab02d17a7b1 vn="Variante von Win32/VOPackage.BP evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\André\AppData\Roaming\ASPackage\asrunasu.exe.vir"
sh=031354307C5A12046B871503E153FC012609EC7A ft=1 fh=959b5f6c75425872 vn="Variante von Win32/Adware.AdService.AD Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\André\AppData\Roaming\ASPackage\ASSrv.exe.vir"
sh=4BD0487D0FAB1F6A5FF50804A8AB3E9483666419 ft=1 fh=c71c00114b43a950 vn="Variante von Win32/Adware.MultiPlug.DX Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\DealDragon\HotDealsa.dll"
sh=C02F227A9DD4F15CF5574CB9822EC0D0AFDFE269 ft=1 fh=f8eb500258be1760 vn="Variante von Win32/KoyoteLab.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Hot Jingle Player\Uninstall.exe"
sh=078A82F1B7F616E77A39DFFCF3A74ECD7CAD1700 ft=1 fh=c71c00111fff4264 vn="Variante von Win32/Skintrim.NE.Gen Trojaner" ac=I fn="C:\Users\André\AppData\Local\hrbug.exe"
sh=BBB0960277A7E0C41B5159DBC6286B97EB833FD6 ft=1 fh=c71c00114b4e31d5 vn="Variante von Win32/Skintrim.NO Trojaner" ac=I fn="C:\Users\André\AppData\Local\wngofv.exe"
sh=C0969DF5DD611CC48EBF5FFB51AAC5A48B920DE5 ft=1 fh=c71c0011d9b46d79 vn="Variante von Win32/Adware.Pirrit.R Anwendung" ac=I fn="C:\Users\André\AppData\Local\dashboardtxview64\firmwarekernelUI.exe"
sh=AF49DF8B2DEBA24F3E15700CEE93BDD057EF28CA ft=1 fh=c71c0011b7854b01 vn="Variante von MSIL/TrojanDropper.Agent.BFS Trojaner" ac=I fn="C:\Users\André\Desktop\Eigenschaften\Schule\inf\Tune up utility 2013\Tune up utility 2013.exe"
sh=C669C42C32D1BB82056A0F3FF6AD2096869BC6E9 ft=0 fh=0000000000000000 vn="Variante von Win32/Kryptik.AWYM Trojaner" ac=I fn="C:\Users\André\Desktop\UseNeXT\90er\alt.binaries.mp3\Snap-Rhythm_Is_A_Dancer-(885_308)-CDM-FLAC-1992-WRE.rar"
sh=39D82EEB76BA9FFE54B9F80325E26485245DAEC1 ft=0 fh=0000000000000000 vn="Variante von MSIL/Injector.CYM Trojaner" ac=I fn="C:\Users\André\Desktop\UseNeXT\90er\alt.binaries.nl\Dune_-_Hardcore_Vibes_RTone-Bluebox.rar"
sh=821818819B99E78B12E2883E42892C6933613084 ft=0 fh=0000000000000000 vn="Variante von MSIL/Injector.CYM Trojaner" ac=I fn="C:\Users\André\Desktop\UseNeXT\90er\alt.binaries.nl\Tiga_and_Zyntherius_-_Sunglasses_at_Night_RTone-Bluebox.rar"
sh=D8658959B782236151629045367108EE351FF2A2 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\André\Downloads\ipswDownloader_v201_win (1).zip"
sh=D8658959B782236151629045367108EE351FF2A2 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\André\Downloads\ipswDownloader_v201_win.zip"
sh=F07D5ABD9D2BA37E8BD7C12950C53FA029F6EA16 ft=1 fh=e381a374218ba866 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\André\Downloads\scary-halloween-sounds (1).exe"
sh=D07372C412F7063A93A9B2CFC0475362BB643A5D ft=1 fh=e381a374218ba866 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\André\Downloads\scary-halloween-sounds.exe"
sh=9BCE9F9D07E7A0C0F4183BB3ECD70E73B4ADEE88 ft=1 fh=8c894a88c3df88a0 vn="Variante von Win32/DownloadGuide.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\André\Downloads\SUPERAntiSpyware_CB-DL-Manager.exe"
sh=CF54558AC105F39DAA2357376E9FC8C04A452FB2 ft=1 fh=a245b9a60105caa2 vn="Win32/Adware.Pirrit.S Anwendung" ac=I fn="C:\Windows\System32\controlfirmwareGUI\controlfirmwareGUI.exe"
sh=737798535E7A693ADC760EA4132D12D387D34356 ft=1 fh=96fbfd2a42e1df7c vn="Variante von Win32/Toolbar.Perion.H evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\mjcm\dnkt.exe"
sh=181241E6431887DC27F4E2B92159F77D82831893 ft=1 fh=80d13d017bfcdcc5 vn="Variante von Win32/Toolbar.Perion.H evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\mjcm\5113\nsib.dll"
sh=CF54558AC105F39DAA2357376E9FC8C04A452FB2 ft=1 fh=a245b9a60105caa2 vn="Win32/Adware.Pirrit.S Anwendung" ac=I fn="C:\Windows\SysWOW64\controlfirmwareGUI\controlfirmwareGUI.exe"
sh=737798535E7A693ADC760EA4132D12D387D34356 ft=1 fh=96fbfd2a42e1df7c vn="Variante von Win32/Toolbar.Perion.H evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\SysWOW64\mjcm\dnkt.exe"
sh=181241E6431887DC27F4E2B92159F77D82831893 ft=1 fh=80d13d017bfcdcc5 vn="Variante von Win32/Toolbar.Perion.H evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\SysWOW64\mjcm\5113\nsib.dll"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Adware.Pirrit.R Anwendung" ac=I fn="${Memory}" |