Danke für die Erklärung. Hier die Protokolle:
Von Malwarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malware Protection, Starting,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malware Protection, Started,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malicious Website Protection, Starting,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malicious Website Protection, Started,
Update, 12.08.2016 22:38, SYSTEM, VINCENT, Manual, Remediation Database, 2016.2.12.1, 2016.8.8.2,
Update, 12.08.2016 22:38, SYSTEM, VINCENT, Manual, IP Database, 2016.2.8.1, 2016.8.11.1,
Update, 12.08.2016 22:38, SYSTEM, VINCENT, Manual, Rootkit Database, 2016.2.8.1, 2016.8.9.1,
Update, 12.08.2016 22:38, SYSTEM, VINCENT, Manual, Domain Database, 2016.2.16.8, 2016.8.12.4,
Update, 12.08.2016 22:38, SYSTEM, VINCENT, Manual, Malware Database, 2016.2.16.6, 2016.8.12.10,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Refresh, Starting,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malicious Website Protection, Stopping,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malicious Website Protection, Stopped,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Refresh, Success,
Protection, 12.08.2016 22:38, SYSTEM, VINCENT, Protection, Malicious Website Protection, Starting,
Protection, 12.08.2016 22:39, SYSTEM, VINCENT, Protection, Malicious Website Protection, Started,
Detection, 12.08.2016 22:39, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:39, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:40, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:40, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:53, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:53, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:53, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:54, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:54, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:54, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 22:57, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, SYSTEM, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
Detection, 12.08.2016 23:01, VincentV, VINCENT, Protection, Malware-Schutz, Datei, PUP.Optional.MorePowerfulCleaner, C:\Program Files (x86)\MPC Cleaner\MpcSafeDll64.dll, Quarantine Failed, 5, Zugriff verweigert , [31094dfdb0ea2a0c98c0e4ae7a87d52b]
(end) Und vom AdwCleaner: Code:
# AdwCleaner v6.000 - Logfile created 13/08/2016 at 10:10:06
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-12.4 [Server]
# Operating System : Windows 8.1 (X64)
# Username : VincentV - VINCENT
# Running from : C:\Users\VincentV\AppData\Local\Microsoft\Windows\INetCache\IE\730NSLY7\adwcleaner_6.000.exe
# Mode: Scan
# Support : https://toolslib.net/forum
***** [ Services ] *****
Service Found: mewumilyzbt
Service Found: MPCProtectService
Service Found: MPCKpt
Service Found: UncheckitSvc
Service Found: cktSvc
***** [ Folders ] *****
Folder Found: C:\ProgramData\CwinpC
Folder Found: C:\ProgramData\DwinpD
Folder Found: C:\ProgramData\hwinph
Folder Found: C:\ProgramData\jwinpj
Folder Found: C:\ProgramData\zwinpz
Folder Found: C:\Users\VincentV\AppData\Local\Nobean
Folder Found: C:\Users\VincentV\AppData\Local\Toolrain
Folder Found: C:\Users\VincentV\AppData\Roaming\eCyber
Folder Found: C:\Users\VincentV\AppData\Roaming\FLV and Media Player
Folder Found: C:\Users\VincentV\AppData\Roaming\qksee
Folder Found: C:\Users\VincentV\AppData\Roaming\WinZiper
Folder Found: C:\Users\VincentV\AppData\Roaming\MCorp
Folder Found: C:\Users\VincentV\AppData\Roaming\Uncheckit
Folder Found: C:\ProgramData\Uncheckit
Folder Found: C:\ProgramData\Nobean
Folder Found: C:\ProgramData\Toolrain
Folder Found: C:\ProgramData\ChelfNotify
Folder Found: C:\ProgramData\uckt
Folder Found: C:\ProgramData\Application Data\Uncheckit
Folder Found: C:\ProgramData\Application Data\Nobean
Folder Found: C:\ProgramData\Application Data\Toolrain
Folder Found: C:\ProgramData\Application Data\ChelfNotify
Folder Found: C:\ProgramData\Application Data\uckt
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uncheckit
Folder Found: C:\Program Files (x86)\MPC Cleaner
Folder Found: C:\Program Files (x86)\TXQQBrowser
Folder Found: C:\Program Files (x86)\Toolrain
Folder Found: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Uncheckit
Folder Found: C:\Users\VincentV\AppData\Roaming\MCorp
***** [ Files ] *****
File Found: C:\Windows\SysNative\log\iSafeKrnlCall.log
File Found: C:\Windows\SysNative\drivers\MPCKpt.sys
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious keys found.
***** [ Shortcuts ] *****
No infected shortcut found.
***** [ Scheduled Tasks ] *****
Task Found: Browser Updater Task(Core)
Task Found: UncheckitTaskMN
Task Found: UncheckitUpdateTaskC
Task Found: UncheckitUpdateTaskDB
Task Found: ChelfNotify Task
***** [ Registry ] *****
Key Found: HKLM\SOFTWARE\Classes\WinZippers.001
Key Found: HKLM\SOFTWARE\Classes\WinZippers.7z
Key Found: HKLM\SOFTWARE\Classes\WinZippers.arj
Key Found: HKLM\SOFTWARE\Classes\WinZippers.bz2
Key Found: HKLM\SOFTWARE\Classes\WinZippers.bzip2
Key Found: HKLM\SOFTWARE\Classes\WinZippers.cab
Key Found: HKLM\SOFTWARE\Classes\WinZippers.cpio
Key Found: HKLM\SOFTWARE\Classes\WinZippers.deb
Key Found: HKLM\SOFTWARE\Classes\WinZippers.dmg
Key Found: HKLM\SOFTWARE\Classes\WinZippers.fat
Key Found: HKLM\SOFTWARE\Classes\WinZippers.gz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.gzip
Key Found: HKLM\SOFTWARE\Classes\WinZippers.hfs
Key Found: HKLM\SOFTWARE\Classes\WinZippers.iso
Key Found: HKLM\SOFTWARE\Classes\WinZippers.lha
Key Found: HKLM\SOFTWARE\Classes\WinZippers.lzh
Key Found: HKLM\SOFTWARE\Classes\WinZippers.lzma
Key Found: HKLM\SOFTWARE\Classes\WinZippers.ntfs
Key Found: HKLM\SOFTWARE\Classes\WinZippers.rar
Key Found: HKLM\SOFTWARE\Classes\WinZippers.rpm
Key Found: HKLM\SOFTWARE\Classes\WinZippers.squashfs
Key Found: HKLM\SOFTWARE\Classes\WinZippers.swm
Key Found: HKLM\SOFTWARE\Classes\WinZippers.tar
Key Found: HKLM\SOFTWARE\Classes\WinZippers.taz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.tbz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.tbz2
Key Found: HKLM\SOFTWARE\Classes\WinZippers.tgz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.tpz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.txz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.vhd
Key Found: HKLM\SOFTWARE\Classes\WinZippers.wim
Key Found: HKLM\SOFTWARE\Classes\WinZippers.xar
Key Found: HKLM\SOFTWARE\Classes\WinZippers.xz
Key Found: HKLM\SOFTWARE\Classes\WinZippers.z
Key Found: HKLM\SOFTWARE\Classes\WinZippers.zip
Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService
Key Found: [x64] HKLM\SOFTWARE\Classes\CLSID\{98C066AB-D735-4339-9E52-A34875141B56}
Key Found: [x64] HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
Key Found: HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
Key Found: HKU\S-1-5-21-547049573-1155005164-433595549-1001\Software\OCS
Key Found: HKU\S-1-5-21-547049573-1155005164-433595549-1001\Software\Uncheckit
Key Found: HKU\S-1-5-18\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
Key Found: HKCU\Software\OCS
Key Found: HKCU\Software\Uncheckit
Key Found: HKLM\SOFTWARE\hdcode
Key Found: HKLM\SOFTWARE\MPC
Key Found: HKLM\SOFTWARE\qkseeSvc
Key Found: HKLM\SOFTWARE\qksee
Key Found: HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qksee
Data Found: HKU\S-1-5-21-547049573-1155005164-433595549-1001\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.nuesearch.com/search/?type=ds&ts=1469466400&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=ihpm0722&uid=KINGSTONXRBU-SC100S37240GE_50026B724B02A624&q={searchTerms}
Data Found: HKU\S-1-5-21-547049573-1155005164-433595549-1001\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.nuesearch.com/search/?type=ds&ts=1469466400&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=ihpm0722&uid=KINGSTONXRBU-SC100S37240GE_50026B724B02A624&q={searchTerms}
Data Found: HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.nuesearch.com/search/?type=ds&ts=1469466400&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=ihpm0722&uid=KINGSTONXRBU-SC100S37240GE_50026B724B02A624&q={searchTerms}
Data Found: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.nuesearch.com/search/?type=ds&ts=1469466400&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=ihpm0722&uid=KINGSTONXRBU-SC100S37240GE_50026B724B02A624&q={searchTerms}
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mpc.am
Key Found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.mpc.am
Key Found: HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
Key Found: HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
Key Found: HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
***** [ Web browsers ] *****
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [4402 Bytes] - [29/04/2016 18:06:57]
C:\AdwCleaner\AdwCleaner[C2].txt - [5278 Bytes] - [16/06/2016 17:37:16]
C:\AdwCleaner\AdwCleaner[S1].txt - [6778 Bytes] - [29/04/2016 18:02:02]
C:\AdwCleaner\AdwCleaner[S2].txt - [6020 Bytes] - [16/06/2016 17:29:31]
C:\AdwCleaner\AdwCleaner[S3].txt - [7688 Bytes] - [13/08/2016 10:10:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [7761 Bytes] ########## |