Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 13.05.2016
Suchlaufzeit: 22:30
Protokolldatei:
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.05.13.05
Rootkit-Datenbank: v2016.05.06.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 331820
Abgelaufene Zeit: 26 Min., 47 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 0
(keine bösartigen Elemente erkannt)
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Remediation Database, 2016.2.12.1, 2016.5.11.1,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.5.6.1,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Domain Database, 2016.2.16.8, 2016.5.13.4,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Malware Database, 2016.2.16.6, 2016.5.13.5,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, IP Database, 2016.2.8.1, 2016.5.13.2,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:28, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Detection, 13.05.2016 22:28, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, C:\ProgramData\Graveair\SumTech.dll, Quarantäne, [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:29, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:29, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, C:\ProgramData\Graveair\Stringtrax.dll, Quarantäne, [25445d78297053e39ebbebc405fc4fb1]
Detection, 13.05.2016 22:34, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:40, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Update, 13.05.2016 22:42, SYSTEM, USER-PC, Scheduler, Malware Database, 2016.5.13.5, 2016.5.13.6,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49193, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49193, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49194, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.net, 49196, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.net, 49196, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, supportt.biz, 49197, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, supportt.biz, 49197, Outbound, C:\Windows\System32\svchost.exe,
Update, 13.05.2016 23:41, SYSTEM, USER-PC, Scheduler, IP Database, 2016.5.13.2, 2016.5.13.3,
Update, 13.05.2016 23:41, SYSTEM, USER-PC, Scheduler, Domain Database, 2016.5.13.4, 2016.5.13.5,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
(end) und die ist von heut früh, ohne mein zutun entstanden. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 14.05.2016 10:38, SYSTEM, USER-PC, Scheduler, Domain Database, 2016.5.13.5, 2016.5.14.2,
Update, 14.05.2016 10:38, SYSTEM, USER-PC, Scheduler, Malware Database, 2016.5.13.6, 2016.5.14.2,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
(end)
nue diese drei eingefügten Dateien sin im MBAM hinterlegt.
unter C: ProgrammData Malwarebyte sind unter logs auch die drei Sachen abgelegt:
mbam-log vom 13.5. 22:59
protection-log 13.5. 23:41
protection-log 14.5. 10:38
diese sind als XML-Dateien abgelegt, wie mache ich diese auf? Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 13.05.2016
Suchlaufzeit: 22:30
Protokolldatei:
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.05.13.05
Rootkit-Datenbank: v2016.05.06.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 331820
Abgelaufene Zeit: 26 Min., 47 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 0
(keine bösartigen Elemente erkannt)
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:26, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Remediation Database, 2016.2.12.1, 2016.5.11.1,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.5.6.1,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Domain Database, 2016.2.16.8, 2016.5.13.4,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, Malware Database, 2016.2.16.6, 2016.5.13.5,
Update, 13.05.2016 22:27, SYSTEM, USER-PC, Manual, IP Database, 2016.2.8.1, 2016.5.13.2,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 22:27, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:28, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Detection, 13.05.2016 22:28, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, C:\ProgramData\Graveair\SumTech.dll, Quarantäne, [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:29, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:29, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, C:\ProgramData\Graveair\Stringtrax.dll, Quarantäne, [25445d78297053e39ebbebc405fc4fb1]
Detection, 13.05.2016 22:34, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Detection, 13.05.2016 22:40, SYSTEM, USER-PC, Protection, Malware-Schutz, Datei, PUP.Optional.Linkury, c:\programdata\graveair\sumtech.dll, Quarantine Failed, 6, Das Handle ist ungültig. , [e6834c89495044f238e356f0ed15bb45]
Update, 13.05.2016 22:42, SYSTEM, USER-PC, Scheduler, Malware Database, 2016.5.13.5, 2016.5.13.6,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 22:42, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 22:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 23:02, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49193, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49193, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.com, 49194, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.net, 49196, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, sethealer.net, 49196, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, supportt.biz, 49197, Outbound, C:\Windows\System32\svchost.exe,
Detection, 13.05.2016 23:04, SYSTEM, USER-PC, Protection, Malicious Website Protection, Domain, 185.17.184.11, supportt.biz, 49197, Outbound, C:\Windows\System32\svchost.exe,
Update, 13.05.2016 23:41, SYSTEM, USER-PC, Scheduler, IP Database, 2016.5.13.2, 2016.5.13.3,
Update, 13.05.2016 23:41, SYSTEM, USER-PC, Scheduler, Domain Database, 2016.5.13.4, 2016.5.13.5,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 13.05.2016 23:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 09:41, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malware Protection, Starting,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malware Protection, Started,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 09:43, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
Update, 14.05.2016 10:38, SYSTEM, USER-PC, Scheduler, Domain Database, 2016.5.13.5, 2016.5.14.2,
Update, 14.05.2016 10:38, SYSTEM, USER-PC, Scheduler, Malware Database, 2016.5.13.6, 2016.5.14.2,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Refresh, Starting,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopping,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Stopped,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Refresh, Success,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Starting,
Protection, 14.05.2016 10:38, SYSTEM, USER-PC, Protection, Malicious Website Protection, Started,
(end) Sorry jetzt hat es das zweimal das gleiche gepostet, hatte es anscheinend zweimal geöffnet.
Die XML-Dateien aus C: habe ich jetzt aufbekommen, manchmal ist man etwas vernagelt.
Steht aber auch nichts anderes drinnen als in den geposteten logs nur etwas anders dargestellt.
Wenn erforderlich stelle ich diese auch hier ein, will den treath aber nicht unnötig aufblähen. |