|
Plagegeister aller Art und deren Bekämpfung: iexplore.exe,msagent,bse.exe... wie entfernt man die?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.11.2009, 21:18 | #1 |
| iexplore.exe,msagent,bse.exe... wie entfernt man die? Hallo! Ich habe die oben genannten Viren auf meinem Computer und wollte euch um Hilfe bitten, da ich keine Ahnung habe, wie man die wieder los wird... (Ich bitte auch um eine ganz genaue Erklärung, da ich sowas noch nie machen musste...) :) Hier noch die Daten, die ihr dazu ja haben wolltet. Malwarebytes sagt folgendes: Malwarebytes' Anti-Malware 1.41 Datenbank Version: 3202 Windows 5.1.2600 Service Pack 3 20.11.2009 20:34:56 mbam-log-2009-11-20 (20-34-56).txt Scan-Methode: Vollständiger Scan (C:\|D:\|E:\|F:\|) Durchsuchte Objekte: 141070 Laufzeit: 28 minute(s), 10 second(s) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 8 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 2 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Partner\partner.dll (Trojan.BHO) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\TypeLib\{86676e13-d6d8-4652-9fcf-f2047f1fb000} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\kt_bho.KettleBho (Trojan.BHO) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Partner\partner.dll (Trojan.BHO) -> Delete on reboot. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Partner\partner.exe (Trojan.BHO) -> Quarantined and deleted successfully. bei RSIT steht: Logfile of random's system information tool 1.06 (written by random/random) Run by Raphael Bezler at 2009-11-20 20:42:25 Microsoft Windows XP Home Edition Service Pack 3 System drive C: has 63 GB (87%) free of 73 GB Total RAM: 1014 MB (61% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:42:32, on 20.11.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir Desktop\sched.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\Explorer.EXE C:\Programme\Java\jre1.5.0\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Programme\Synaptics\SynTP\SynTPEnh.exe C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Programme\Samsung\Samsung Update Plus\SUPBackGround.exe C:\Programme\Samsung\Samsung Battery Manager\BatteryManager.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Virtual CD v10\System\VC10Play.exe C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe C:\Programme\Avira\AntiVir Desktop\avgnt.exe C:\Programme\SAMSUNG\MagicKBD\MagicKBD.exe C:\Programme\SAMSUNG\MagicKBD\PerformanceManager.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Programme\Gemeinsame Dateien\AccSys\AccVSSvc.exe C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe C:\Programme\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Virtual CD v10\System\VC10SecS.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\system32\wuauclt.exe C:\Programme\Virtual CD v10\System\VC10Tray.exe C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\igfxext.exe C:\WINDOWS\system32\wscntfy.exe C:\Dokumente und Einstellungen\***\Desktop\RSIT.exe C:\Programme\Trend Micro\HijackThis\***.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0\bin\jusched.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SUPBackGround] C:\Programme\Samsung\Samsung Update Plus\SUPBackGround.exe O4 - HKLM\..\Run: [BatteryManager] C:\Programme\Samsung\Samsung Battery Manager\BatteryManager.exe O4 - HKLM\..\Run: [DMHotKey] C:\Programme\Samsung\Easy Display Manager\DMLoader.exe O4 - HKLM\..\Run: [MagicKeyboard] C:\Programme\SAMSUNG\MagicKBD\PreMKBD.exe O4 - HKLM\..\Run: [UCam_Menu] "C:\Programme\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Programme\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [VC10Player] C:\Programme\Virtual CD v10\System\VC10Play.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [o2DSLConnectionManager] "C:\Programme\DSL Connection Manager\o2DSLConnectionManager.exe" -autostart O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware (reboot)] "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BatteryLifeExtender] C:\Programme\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe /2 O4 - HKCU\..\Run: [swg] "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O23 - Service: AccSys WLAN Control Service (accvssvc) - AccSys GmbH - C:\Programme\Gemeinsame Dateien\AccSys\AccVSSvc.exe O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Programme\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe O23 - Service: Virtual CD v10 Management Service (VC10SecS) - H+H Software GmbH - C:\Programme\Virtual CD v10\System\VC10SecS.exe -- End of file - 8720 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}] RealPlayer Download and Record Plugin for Internet Explorer - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-11-17 329312] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-16 256112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Programme\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-11-17 762864] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}] Google Dictionary Compression sdch - C:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-11-16 458736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-16 256112] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=C:\Programme\Java\jre1.5.0\bin\jusched.exe [2009-05-19 36972] "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-02-13 17508864] "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344] "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2009-02-18 141848] "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2009-02-18 166424] "Persistence"=C:\WINDOWS\system32\igfxpers.exe [2009-02-18 137752] "SynTPEnh"=C:\Programme\Synaptics\SynTP\SynTPEnh.exe [2008-08-28 1044480] "Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-11 34672] "SUPBackGround"=C:\Programme\Samsung\Samsung Update Plus\SUPBackGround.exe [2008-12-03 298664] "BatteryManager"=C:\Programme\Samsung\Samsung Battery Manager\BatteryManager.exe [2008-11-26 2768896] "DMHotKey"=C:\Programme\Samsung\Easy Display Manager\DMLoader.exe [2006-12-27 466944] "MagicKeyboard"=C:\Programme\SAMSUNG\MagicKBD\PreMKBD.exe [2006-05-14 151552] "UCam_Menu"=C:\Programme\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2008-12-03 218408] "TkBellExe"=C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe [2009-11-17 198160] "VC10Player"=C:\Programme\Virtual CD v10\System\VC10Play.exe [2009-10-08 375112] "GrooveMonitor"=C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016] "o2DSLConnectionManager"=C:\Programme\DSL Connection Manager\o2DSLConnectionManager.exe [2008-07-10 707952] "avgnt"=C:\Programme\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] " Malwarebytes Anti-Malware (reboot)"=C:\Programme\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360] "BatteryLifeExtender"=C:\Programme\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-03-13 550912] "swg"=C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-19 39408] C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart BTTray.lnk - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Programme\Internet Explorer\IEXPLORE.EXE"="C:\Programme\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer" "C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test" "C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook" "C:\Programme\Microsoft Office\Office12\GROOVE.EXE"="C:\Programme\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove" "C:\Programme\Microsoft Office\Office12\ONENOTE.EXE"="C:\Programme\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{71c005a4-d3d8-11de-b1de-001377fdecd5}] shell\AutoRun\command - E:\SETUP.EXE shell\configure\command - E:\SETUP.EXE shell\install\command - E:\SETUP.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c8d5068-45e4-11de-98b3-001377b682bf}] shell\1\command - Recycle.exe shell\2\command - Recycle.exe shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bed37d16-d416-11de-b1e1-001377fdecd5}] shell\AutoRun\command - ajcmiy.exe shell\explore\command - ajcmiy.exe shell\open\command - ajcmiy.exe |
20.11.2009, 21:19 | #2 |
| iexplore.exe,msagent,bse.exe... wie entfernt man die? Hier geht es noch weiter:
__________________======List of files/folders created in the last 1 months====== 2009-11-20 20:42:25 ----D---- C:\rsit 2009-11-20 20:03:44 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes 2009-11-20 20:03:35 ----D---- C:\Programme\Malwarebytes' Anti-Malware 2009-11-20 20:03:35 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-11-20 19:47:24 ----D---- C:\Programme\CCleaner 2009-11-20 19:38:54 ----D---- C:\Programme\Trend Micro 2009-11-20 17:52:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$ 2009-11-20 17:52:40 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$ 2009-11-20 17:52:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$ 2009-11-20 17:52:26 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$ 2009-11-20 17:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$ 2009-11-20 17:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$ 2009-11-20 17:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$ 2009-11-20 17:52:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$ 2009-11-20 17:51:55 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$ 2009-11-20 17:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$ 2009-11-20 17:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$ 2009-11-20 17:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$ 2009-11-20 17:51:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$ 2009-11-20 17:51:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$ 2009-11-20 17:51:13 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$ 2009-11-20 17:51:06 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$ 2009-11-20 17:50:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$ 2009-11-20 17:50:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$ 2009-11-20 17:50:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$ 2009-11-20 17:50:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$ 2009-11-20 17:50:27 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$ 2009-11-20 17:50:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$ 2009-11-20 17:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$ 2009-11-20 17:50:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$ 2009-11-20 17:49:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$ 2009-11-20 17:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$ 2009-11-20 17:49:46 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$ 2009-11-20 17:49:40 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$ 2009-11-20 17:49:35 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$ 2009-11-20 17:49:28 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$ 2009-11-20 17:49:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$ 2009-11-20 17:49:10 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$ 2009-11-20 17:48:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$ 2009-11-20 17:48:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$ 2009-11-20 17:48:29 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$ 2009-11-20 17:48:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$ 2009-11-20 17:48:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$ 2009-11-20 17:48:09 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$ 2009-11-20 17:48:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$ 2009-11-20 17:47:54 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$ 2009-11-20 17:47:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$ 2009-11-20 17:47:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$ 2009-11-20 17:47:31 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$ 2009-11-20 17:47:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$ 2009-11-20 17:47:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$ 2009-11-20 17:47:03 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$ 2009-11-20 17:46:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$ 2009-11-20 17:46:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$ 2009-11-20 17:46:41 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$ 2009-11-19 23:28:22 ----D---- C:\Programme\Avira 2009-11-19 23:28:22 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 2009-11-19 23:13:57 ----D---- C:\Programme\Windows Live Safety Center 2009-11-19 22:38:36 ----A---- C:\WINDOWS\system32\MPFServiceFailureCount.txt 2009-11-19 19:05:52 ----D---- C:\WINDOWS\system32\PreInstall 2009-11-19 19:05:47 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$ 2009-11-17 15:10:39 ----RSD---- C:\WINDOWS\assembly 2009-11-17 15:09:21 ----D---- C:\WINDOWS\Microsoft.NET 2009-11-17 15:08:06 ----A---- C:\WINDOWS\system32\wpcap.dll 2009-11-17 15:08:06 ----A---- C:\WINDOWS\system32\WanPacket.dll 2009-11-17 15:08:06 ----A---- C:\WINDOWS\system32\pthreadVC.dll 2009-11-17 15:08:06 ----A---- C:\WINDOWS\system32\Packet.dll 2009-11-17 15:08:02 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AccSys 2009-11-17 15:08:00 ----D---- C:\Programme\Gemeinsame Dateien\AccSys 2009-11-17 15:08:00 ----D---- C:\Programme\DSL Connection Manager 2009-11-17 12:40:47 ----A---- C:\WINDOWS\system32\msonpmon.dll 2009-11-17 12:38:58 ----D---- C:\Programme\Microsoft Works 2009-11-17 12:38:43 ----D---- C:\Programme\MSBuild 2009-11-17 12:37:56 ----D---- C:\Programme\Microsoft Visual Studio 2009-11-17 12:37:55 ----D---- C:\Programme\Gemeinsame Dateien\DESIGNER 2009-11-17 12:33:31 ----D---- C:\WINDOWS\SHELLNEW 2009-11-17 12:32:35 ----D---- C:\Programme\Microsoft Office 2009-11-17 12:32:31 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help 2009-11-17 12:32:02 ----RHD---- C:\MSOCache 2009-11-17 12:27:35 ----SD---- C:\Dokumente und Einstellungen\Raphael Bezler\Anwendungsdaten\Virtual CD v10 2009-11-17 12:27:09 ----A---- C:\WINDOWS\system32\NCTAudioPlayer2.dll 2009-11-17 12:27:09 ----A---- C:\WINDOWS\system32\NCTAudioFile2.dll 2009-11-17 12:27:06 ----D---- C:\Programme\Virtual CD v10 2009-11-17 12:20:19 ----D---- C:\WINDOWS\ie8updates 2009-11-17 12:18:24 ----HDC---- C:\WINDOWS\ie8 2009-11-17 12:15:19 ----A---- C:\WINDOWS\system32\MRT.exe 2009-11-17 11:13:13 ----A---- C:\WINDOWS\system32\rmoc3260.dll 2009-11-17 11:12:56 ----A---- C:\WINDOWS\system32\pndx5032.dll 2009-11-17 11:12:56 ----A---- C:\WINDOWS\system32\pndx5016.dll 2009-11-17 11:12:51 ----D---- C:\Programme\Gemeinsame Dateien\xing shared 2009-11-17 11:12:14 ----A---- C:\WINDOWS\system32\pncrt.dll 2009-11-17 11:12:14 ----A---- C:\WINDOWS\system32\msvcr71.dll 2009-11-17 11:12:14 ----A---- C:\WINDOWS\system32\msvcp71.dll 2009-11-17 11:12:12 ----D---- C:\Programme\Real 2009-11-17 11:12:10 ----D---- C:\Programme\Gemeinsame Dateien\Real 2009-11-17 11:12:09 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real 2009-11-17 11:12:04 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Real 2009-11-17 11:09:29 ----D---- C:\WINDOWS\WBEM 2009-11-17 11:08:55 ----A---- C:\WINDOWS\system32\spupdsvc.exe 2009-11-17 11:07:42 ----D---- C:\WINDOWS\system32\en-US 2009-11-17 10:30:27 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Google 2009-11-16 22:03:01 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Macromedia 2009-11-16 21:31:31 ----D---- C:\WINDOWS\system32\SoftwareDistribution ======List of files/folders modified in the last 1 months====== 2009-11-20 20:39:10 ----D---- C:\WINDOWS\Temp 2009-11-20 20:39:07 ----D---- C:\WINDOWS\system32\CatRoot2 2009-11-20 20:39:04 ----D---- C:\WINDOWS 2009-11-20 20:38:44 ----D---- C:\WINDOWS\system32 2009-11-20 20:38:01 ----RSHDC---- C:\WINDOWS\system32\dllcache 2009-11-20 20:38:01 ----D---- C:\WINDOWS\system32\wbem 2009-11-20 20:38:01 ----D---- C:\WINDOWS\AppPatch 2009-11-20 20:37:31 ----A---- C:\WINDOWS\SchedLgU.Txt 2009-11-20 20:34:56 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Partner 2009-11-20 20:03:39 ----D---- C:\WINDOWS\system32\drivers 2009-11-20 20:03:35 ----RD---- C:\Programme 2009-11-20 19:50:48 ----D---- C:\WINDOWS\Debug 2009-11-20 17:52:59 ----HD---- C:\WINDOWS\inf 2009-11-20 17:52:45 ----HD---- C:\WINDOWS\$hf_mig$ 2009-11-20 17:52:28 ----D---- C:\Programme\Messenger 2009-11-20 17:52:10 ----D---- C:\WINDOWS\WinSxS 2009-11-20 17:49:24 ----D---- C:\Programme\Outlook Express 2009-11-20 17:47:23 ----SHD---- C:\WINDOWS\Installer 2009-11-19 23:18:02 ----D---- C:\WINDOWS\msagent 2009-11-19 23:13:57 ----SD---- C:\WINDOWS\Downloaded Program Files 2009-11-19 23:08:38 ----D---- C:\Programme\Gemeinsame Dateien 2009-11-19 23:08:38 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee 2009-11-19 23:08:30 ----D---- C:\Programme\McAfee 2009-11-19 23:05:15 ----SD---- C:\WINDOWS\Tasks 2009-11-19 22:57:07 ----AD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Temp 2009-11-19 22:10:09 ----D---- C:\WINDOWS\Prefetch 2009-11-19 19:58:07 ----SD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft 2009-11-19 19:05:37 ----SD---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Microsoft 2009-11-17 20:55:13 ----SHD---- C:\RECYCLER 2009-11-17 15:47:01 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2009-11-17 15:09:43 ----D---- C:\WINDOWS\system32\mui 2009-11-17 15:09:43 ----D---- C:\Programme\Internet Explorer 2009-11-17 15:08:54 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe 2009-11-17 15:07:34 ----HD---- C:\Programme\InstallShield Installation Information 2009-11-17 13:04:21 ----D---- C:\WINDOWS\system32\CatRoot 2009-11-17 12:40:30 ----D---- C:\WINDOWS\system32\config 2009-11-17 12:38:51 ----D---- C:\Programme\Gemeinsame Dateien\Microsoft Shared 2009-11-17 12:37:13 ----RSD---- C:\WINDOWS\Fonts 2009-11-17 12:33:57 ----A---- C:\WINDOWS\win.ini 2009-11-17 12:33:54 ----D---- C:\Programme\Gemeinsame Dateien\System 2009-11-17 12:21:58 ----D---- C:\WINDOWS\system32\de-de 2009-11-17 12:21:57 ----D---- C:\WINDOWS\Help 2009-11-17 12:19:35 ----D---- C:\WINDOWS\Media 2009-11-17 06:15:53 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinClon 2009-11-16 21:31:42 ----D---- C:\WINDOWS\SoftwareDistribution 2009-10-21 21:16:22 ----A---- C:\WINDOWS\system32\mshtml.dll ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgio;avgio; \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys [] R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104] R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448] R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520] R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28 55656] R2 DOSMEMIO;MEMIO; \??\C:\WINDOWS\system32\MEMIO.SYS [] R2 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-06-05 42000] R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-10-07 1334432] R3 BTKRNL;Bluetooth-Bus-Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2009-03-19 991136] R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-10-31 47272] R3 CmBatt;Treiber für Microsoft-ACPI-Kontrollmethodenkompatible Batterie; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952] R3 HDAudBus;Microsoft UAA-Bustreiber für High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384] R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-02-13 5029376] R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-08-28 224736] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208] R3 usbhub;USB2-aktivierter Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520] R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608] R3 VMC326;Vimicro Camera Service VMC326; C:\WINDOWS\System32\Drivers\VMC326.sys [2008-11-21 238464] R3 wowfilter;WOW XT Filter Driver; C:\WINDOWS\system32\drivers\wowfilter.sys [2009-02-18 25560] R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2009-04-08 296320] S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736] S3 CCDECODE;Untertiteldecoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024] S3 HH10Help.sys;HH10Help.sys; \??\C:\WINDOWS\system32\drivers\HH10Help.sys [] S3 HidUsb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368] S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056] S3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12288] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504] S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248] S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136] S3 streamip;BDA-IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232] S3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128] S3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368] S3 usbvideo;USB-Videogerät (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984] S3 WSTCODEC;World Standard Teletext-Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 accvssvc;AccSys WLAN Control Service; C:\Programme\Gemeinsame Dateien\AccSys\AccVSSvc.exe [2008-07-09 131072] R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Programme\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289] R2 AntiVirService;Avira AntiVir Guard; C:\Programme\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089] R2 btwdins;Bluetooth Service; C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2009-03-23 349528] R2 SRS_PostInstaller;SRS PostInstaller Service; C:\Programme\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe [2009-02-18 74992] R2 VC10SecS;Virtual CD v10 Management Service; C:\Programme\Virtual CD v10\System\VC10SecS.exe [2009-10-08 145224] R2 yksvc;Marvell Yukon Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240] S3 gusvc;Google Software Updater; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-16 182768] S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824] S3 odserv;Microsoft Office Diagnostics Service; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136] S3 ose;Office Source Engine; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] -----------------EOF----------------- |
Themen zu iexplore.exe,msagent,bse.exe... wie entfernt man die? |
adobe, antivir, antivir guard, avira, browser, c:\windows\system32\rundll32.exe, computer, desktop, einstellungen, google, helper, hijack, hijackthis, hkus\s-1-5-18, home, iexplore.exe, internet, internet explorer, malwarebytes anti-malware, menu.exe, registrierungsschlüssel, registry, rundll, senden, shell32.dll, software, system, viren, windows xp, wlan |