Hallo!
Ich hab heute etwas länger gebraucht, weil ich in der Uni viel zu tun hatte. Hab jetzt aber meine Logs parat. Zumindest die, die ich bekommen habe. Und da sind wir schon beim Problem. Bisher war ich ziemlich zuversichtlich. Aber bin jetzt ziemlich verunsichert. Aber du wirst da mehr draus lesen können:
GMER hat mir keinen Log gegeben. Nur die folgende Nachricht:
"GMER hasn't found any system modification."
Ich muss dazu sagen: Habe beim ersten Durchlauf vergessen, das Internetkabel und damit die Internet Verbindung zu trennen. Habe einen 2. Durchlauf mit exakt den Vorgaben aus der Anleitung mit gleichem Ergebnis gemacht.
Osam hat gut funktioniert. Folgender Log kam dabei heraus:
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:31:08 on 05.07.2012
OS: Windows 7 Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 13.0.1
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"MATLAB R2011b Startup Accelerator.job" - ? - C:\Program Files\MATLAB\R2011b\bin\win64\MATLABStartupAccelerator.exe (File found, but it contains no detailed information)
[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\MLCFG32.CPL
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"acsock" (acsock) - "Cisco Systems, Inc." - C:\Windows\System32\DRIVERS\acsock64.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys (File not found)
"Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - ? - C:\Windows\system32\Drivers\CVPNDRVA.sys (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"StarOpen" (StarOpen) - ? - C:\Windows\system32\drivers\StarOpen.sys (File not found)
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\MLSHEXT.DLL
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
[Internet Explorer]
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_33" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_33.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_2_202_235.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
{1E54D648-B804-468d-BC78-4AFFED8E262F} "System Requirements Lab Class" - "Husdawg, LLC" - C:\Windows\Downloaded Program Files\sysreqlab_nvd.dll / hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"Cisco AnyConnect Secure Mobility Agent for Windows" - "Cisco Systems, Inc." - "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"pdfcmon" - "pdfforge GbR" - C:\Windows\system32\pdfcmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe" (File not found)
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Cisco AnyConnect Secure Mobility Agent" (vpnagent) - "Cisco Systems, Inc." - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
"Cisco Systems, Inc. VPN Service" (CVPND) - "Cisco Systems, Inc." - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Update Service Daemon" (nvUpdatusService) - "NVIDIA Corporation" - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Dazu gab es nichts zu sagen.
Anschließend noch der aswMBR Scan. Den habe ich erst wie in der Anleitung versucht. Die Absturz Meldung kam. Dann habe ich den Laptop neu gestartet und nochmal versucht. Wieder die Absturzmeldung. Abschließend habe ich es wie in deinem Hinweis mit AV Scan "none" durchlaufen lassen. Hier der Log:
aswMBR.txt: Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-05 19:48:39
-----------------------------
19:48:39.584 OS Version: Windows x64 6.1.7601 Service Pack 1
19:48:39.584 Number of processors: 2 586 0xF0A
19:48:39.584 ComputerName: ***-PC UserName: ***
19:48:40.145 Initialize success
19:48:47.243 AVAST engine defs: 12070401
19:48:52.329 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
19:48:52.329 Disk 0 Vendor: WDC_WD5000BEVT-00ZAT0 01.01A01 Size: 476940MB BusType: 11
19:48:52.344 Disk 0 MBR read successfully
19:48:52.344 Disk 0 MBR scan
19:48:52.360 Disk 0 Windows 7 default MBR code
19:48:52.376 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:48:52.407 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 150000 MB offset 206848
19:48:52.438 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 326838 MB offset 307406848
19:48:52.454 Disk 0 scanning C:\Windows\system32\drivers
19:49:04.450 Service scanning
19:49:31.344 Modules scanning
19:49:31.344 Disk 0 trace - called modules:
19:49:31.360 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
19:49:31.376 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c42730]
19:49:31.376 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0xfffffa800469b060]
19:49:31.391 Scan finished successfully
19:50:24.619 Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\MBR.dat"
19:50:24.634 The log file has been saved successfully to "C:\Users\***\Desktop\aswMBR.txt" Achja: Ich habe nach jedem Scan den Laptop neu gestartet. Und ich schalte jetzt erstmal die Systeme (Defender und Avira Echtzeit Scan) wieder ein.
Wenn wir schon grad dabei sind, würde ich dir gerne noch ein paar Logs hochladen. Als ich Malwarebytes noch laufen hatte, hat das mir ständig Probleme angezeigt. Letztendlich ist es fast immer auf 2 Dateien zurück zu führen: Skype.exe und svchost.exe. Aber siehe selbst:
protection-log-2012-06-29.txt: Code:
2012/06/29 19:08:23 +0200 ***-PC *** MESSAGE Starting protection
2012/06/29 19:08:23 +0200 ***-PC *** MESSAGE Executing scheduled update: Daily
2012/06/29 19:08:24 +0200 ***-PC *** MESSAGE Database already up-to-date
2012/06/29 19:08:26 +0200 ***-PC *** MESSAGE Protection started successfully
2012/06/29 19:08:29 +0200 ***-PC *** MESSAGE Starting IP protection
2012/06/29 19:08:31 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/06/29 21:56:37 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/06/29 21:59:01 +0200 ***-PC *** MESSAGE IP Protection stopped
protection-log-2012-06-30.txt: Code:
2012/06/30 02:17:54 +0200 ***-PC *** MESSAGE Starting IP protection
2012/06/30 02:17:56 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/06/30 08:32:29 +0200 ***-PC *** MESSAGE Executing scheduled update: Daily
2012/06/30 08:32:30 +0200 ***-PC *** MESSAGE Starting protection
2012/06/30 08:32:35 +0200 ***-PC *** MESSAGE Protection started successfully
2012/06/30 08:32:38 +0200 ***-PC *** MESSAGE Starting IP protection
2012/06/30 08:32:40 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/06/30 08:32:43 +0200 ***-PC *** MESSAGE Scheduled update executed successfully: database updated from version v2012.06.29.08 to version v2012.06.30.02
2012/06/30 08:32:43 +0200 ***-PC *** MESSAGE Starting database refresh
2012/06/30 08:32:43 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/06/30 08:34:57 +0200 ***-PC *** MESSAGE IP Protection stopped
2012/06/30 08:35:00 +0200 ***-PC *** MESSAGE Database refreshed successfully
2012/06/30 08:35:00 +0200 ***-PC *** MESSAGE Starting IP protection
2012/06/30 08:35:01 +0200 ***-PC *** MESSAGE IP Protection started successfully
protection-log-2012-07-01.txt: Code:
2012/07/01 05:41:24 +0200 ***-PC *** MESSAGE Executing scheduled update: Daily
2012/07/01 05:41:36 +0200 ***-PC *** MESSAGE Starting database refresh
2012/07/01 05:41:36 +0200 ***-PC *** MESSAGE Scheduled update executed successfully: database updated from version v2012.06.30.02 to version v2012.07.01.01
2012/07/01 05:41:36 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/07/01 05:43:55 +0200 ***-PC *** MESSAGE IP Protection stopped
2012/07/01 05:43:59 +0200 ***-PC *** MESSAGE Database refreshed successfully
2012/07/01 05:43:59 +0200 ***-PC *** MESSAGE Starting IP protection
2012/07/01 05:44:00 +0200 ***-PC *** MESSAGE IP Protection started successfully
protection-log-2012-07-02.txt: Code:
2012/07/02 15:20:53 +0200 ***-PC *** MESSAGE Starting database refresh
2012/07/02 15:20:53 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/07/02 15:23:12 +0200 ***-PC *** MESSAGE IP Protection stopped
2012/07/02 15:23:26 +0200 ***-PC *** MESSAGE Database refreshed successfully
2012/07/02 15:23:26 +0200 ***-PC *** MESSAGE Starting IP protection
2012/07/02 15:23:27 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/07/02 15:36:29 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/07/02 15:38:45 +0200 ***-PC *** MESSAGE IP Protection stopped
2012/07/02 15:45:22 +0200 ***-PC *** MESSAGE Starting protection
2012/07/02 15:45:25 +0200 ***-PC *** MESSAGE Protection started successfully
2012/07/02 15:45:28 +0200 ***-PC *** MESSAGE Starting IP protection
2012/07/02 15:45:30 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/07/02 19:55:51 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/07/02 19:58:06 +0200 ***-PC *** MESSAGE IP Protection stopped
2012/07/02 20:08:34 +0200 ***-PC *** MESSAGE Starting protection
2012/07/02 20:08:37 +0200 ***-PC *** MESSAGE Protection started successfully
2012/07/02 20:08:40 +0200 ***-PC *** MESSAGE Starting IP protection
2012/07/02 20:08:41 +0200 ***-PC *** MESSAGE IP Protection started successfully
2012/07/02 22:04:36 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:04:36 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:04:36 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:04:36 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 22:04:36 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:04:44 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:04:44 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 22:04:44 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:05:24 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 22:05:32 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:08:45 +0200 ***-PC *** IP-BLOCK 122.228.200.37 (Type: incoming, Port: 1433, Process: svchost.exe)
2012/07/02 22:20:22 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 22:20:23 +0200 ***-PC *** IP-BLOCK 83.128.124.178 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 23:07:09 +0200 ***-PC *** IP-BLOCK 93.114.45.80 (Type: incoming, Port: 7700, Process: svchost.exe)
2012/07/02 23:50:50 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 23:50:51 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 23:50:51 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 23:50:51 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/02 23:50:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 23:50:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/02 23:50:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/02 23:50:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
protection-log-2012-07-03.txt: Code:
2012/07/03 09:48:48 +0200 ***-PC *** IP-BLOCK 87.248.191.50 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 09:48:56 +0200 ***-PC *** IP-BLOCK 87.248.191.50 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 09:49:04 +0200 ***-PC *** IP-BLOCK 87.248.191.50 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:07:39 +0200 ***-PC *** IP-BLOCK 122.228.200.37 (Type: incoming, Port: 1433, Process: svchost.exe)
2012/07/03 10:07:39 +0200 ***-PC *** IP-BLOCK 122.228.200.37 (Type: incoming, Port: 1433, Process: svchost.exe)
2012/07/03 10:18:45 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:18:45 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 10:18:45 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 10:27:10 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:27:11 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:27:19 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:19 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:27:19 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:27:19 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:29:59 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:32:16 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:38:58 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 10:39:06 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 10:39:06 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 10:50:52 +0200 ***-PC *** IP-BLOCK 93.114.45.80 (Type: incoming, Port: 65056, Process: svchost.exe)
2012/07/03 10:50:52 +0200 ***-PC *** IP-BLOCK 93.114.45.80 (Type: incoming, Port: 65056, Process: svchost.exe)
2012/07/03 10:50:52 +0200 ***-PC *** IP-BLOCK 93.114.45.80 (Type: incoming, Port: 65056, Process: svchost.exe)
2012/07/03 10:50:52 +0200 ***-PC *** IP-BLOCK 93.114.45.80 (Type: incoming, Port: 65056, Process: svchost.exe)
2012/07/03 11:14:33 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:14:34 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:14:34 +0200 ***-PC *** IP-BLOCK 213.163.64.88 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:31:09 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:31:09 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:31:09 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 11:31:09 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 11:31:17 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:31:17 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:31:17 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 11:31:17 +0200 ***-PC *** IP-BLOCK 89.28.51.12 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 11:40:31 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 11:40:39 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 11:46:15 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:46:16 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:46:16 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:46:16 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:47:44 +0200 ***-PC *** IP-BLOCK 217.23.10.129 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 11:47:44 +0200 ***-PC *** IP-BLOCK 217.23.10.129 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:47:44 +0200 ***-PC *** IP-BLOCK 217.23.10.129 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 11:47:44 +0200 ***-PC *** IP-BLOCK 217.23.10.129 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 12:16:14 +0200 ***-PC *** IP-BLOCK 93.114.45.23 (Type: incoming, Port: 27456, Process: svchost.exe)
2012/07/03 12:16:14 +0200 ***-PC *** IP-BLOCK 93.114.45.23 (Type: incoming, Port: 27456, Process: svchost.exe)
2012/07/03 12:16:14 +0200 ***-PC *** IP-BLOCK 93.114.45.23 (Type: incoming, Port: 27456, Process: svchost.exe)
2012/07/03 12:18:55 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 12:19:03 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 12:19:03 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 12:19:03 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 80, Process: skype.exe)
2012/07/03 12:19:03 +0200 ***-PC *** IP-BLOCK 213.163.65.8 (Type: incoming, Port: 443, Process: skype.exe)
2012/07/03 12:34:57 +0200 ***-PC *** IP-BLOCK 79.142.74.10 (Type: incoming, Port: 2881, Process: skype.exe)
2012/07/03 12:34:58 +0200 ***-PC *** IP-BLOCK 79.142.74.10 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 12:34:58 +0200 ***-PC *** IP-BLOCK 79.142.74.10 (Type: incoming, Port: 2881, Process: svchost.exe)
2012/07/03 22:01:59 +0200 ***-PC *** MESSAGE Stopping IP protection
2012/07/03 22:04:33 +0200 ***-PC *** MESSAGE IP Protection stopped
protection-log-2012-07-04.txt: Code:
2012/07/04 11:45:23 +0200 ***-PC *** MESSAGE Executing scheduled update: Daily
2012/07/04 11:45:34 +0200 ***-PC *** MESSAGE Scheduled update executed successfully: database updated from version v2012.07.02.02 to version v2012.07.04.03
Danke nochmal, dass du dich meines Problemes angenommen hast, auch wenn es wohl etwas länger dauert.
Viele Grüße, Rumpel |