![]() |
|
Plagegeister aller Art und deren Bekämpfung: Antimalware Doc entfernen klappt nciht ganzWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
|
![]() | #1 |
![]() | ![]() Antimalware Doc entfernen klappt nciht ganz Hallo, da dies mein erste post hier ist, hoffe ich dass ich mich den forenregeln entsprechend verhalte. ich beziehe mich auf die anleitung zur entfernung des antimalware doc : http://www.trojaner-board.de/83172-a...entfernen.html in dem thread steht, dass ich sowieso nochmal hier posten soll. bei mir geht er allerdings nicht weg. der virus trat zum ersten mal gesten in erscheinung, nachdem mein rechner mehrere stunden unbenutzt und angeschaltet war, mein windows security essentials hat wohl was erkannt, es waren allerdings auch schon fenster von antimalware doc offen. hier das was security essentials gemacht hat (ich sah keine andere möglichkeit als einen sceenshot zu machen): ![]() da ich gemerkt habe dass irgendwas sehr im argen ist habe ich den computer direkt im abgesicherten modus gestartet und meinen router ausgeschaltet. dort habe ich mbam ccscanner und auch viren scanns gemacht: mbam log: Code:
ATTFilter Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3930 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 19.07.2010 00:10:37 mbam-log-2010-07-19 (00-10-37).txt Scan type: Quick scan Objects scanned: 118910 Time elapsed: 5 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\halo2 (Trojan.Downloader) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Users\i\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. Code:
ATTFilter Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4325 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 19.07.2010 09:14:57 mbam-log-2010-07-19 (09-14-57).txt Scan type: Full scan (C:\|D:\|F:\|) Objects scanned: 339881 Time elapsed: 1 hour(s), 34 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\W34BCG2GRJ (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\JDK5SWFMZY (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Code:
ATTFilter Logfile of random's system information tool 1.08 (written by random/random) Run by i at 2010-07-19 11:54:49 Microsoft Windows 7 Professional System drive C: has 18 GB (30%) free of 60 GB Total RAM: 2047 MB (64% free) HijackThis download failed ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}] &Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232] "AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712] "AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208] "AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992] "SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] "NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup [] " Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168] "Google Update"=C:\Users\i\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-03 135664] "AdobeBridge"= [] "EPSON Stylus Photo R2400"=C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATI9SE.EXE [2007-01-10 177664] C:\Users\i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - "C:\Program Files\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1" ======List of files/folders created in the last 1 months====== 2010-07-19 11:09:47 ----D---- C:\Users\i\AppData\Roaming\Yahoo! 2010-07-19 11:09:47 ----D---- C:\ProgramData\Yahoo! Companion 2010-07-19 11:09:45 ----D---- C:\Program Files\Yahoo! 2010-07-19 11:08:35 ----D---- C:\rsit 2010-07-19 11:08:35 ----D---- C:\Program Files\trend micro 2010-07-19 01:04:42 ----A---- C:\mbam-error.txt 2010-07-13 11:52:22 ----D---- C:\REFlex 2010-07-12 10:13:50 ----A---- C:\Windows\_MSRSTRT.EXE 2010-07-11 23:58:39 ----D---- C:\Program Files\Sigma_Team 2010-07-11 23:55:16 ----D---- C:\Program Files\Sigma Team 2010-07-09 10:07:57 ----D---- C:\Program Files\MSXML 4.0 2010-07-08 23:50:54 ----D---- C:\Users\i\AppData\Roaming\Nokia Ovi Suite 2010-07-08 23:02:16 ----D---- C:\Program Files\PC Connectivity Solution 2010-07-08 23:00:42 ----D---- C:\ProgramData\NokiaInstallerCache 2010-07-08 22:39:04 ----D---- C:\Users\i\AppData\Roaming\Nokia 2010-07-08 22:38:02 ----D---- C:\Program Files\Common Files\PCSuite 2010-07-08 22:36:53 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys 2010-07-08 22:28:16 ----D---- C:\ProgramData\PC Suite 2010-07-08 22:28:07 ----D---- C:\Users\i\AppData\Roaming\PC Suite 2010-07-08 21:49:34 ----D---- C:\ProgramData\Nokia 2010-07-08 21:48:20 ----D---- C:\Program Files\DIFX 2010-07-08 21:47:47 ----DC---- C:\Windows\system32\DRVSTORE 2010-07-08 21:45:22 ----A---- C:\Windows\system32\nmwcdcls.dll 2010-07-08 21:42:49 ----D---- C:\Program Files\Common Files\Nokia 2010-07-08 21:42:46 ----D---- C:\Program Files\Nokia 2010-07-08 21:40:50 ----D---- C:\ProgramData\Installations 2010-07-06 10:23:01 ----D---- C:\Program Files\Codemasters 2010-07-02 00:28:36 ----D---- C:\Users\i\AppData\Roaming\Turbine 2010-07-02 00:25:26 ----D---- C:\Windows\system32\URTTEMP 2010-07-02 00:14:45 ----D---- C:\Program Files\Turbine 2010-07-01 21:27:20 ----D---- C:\ProgramData\PMB Files 2010-07-01 21:27:07 ----D---- C:\Program Files\Pando Networks 2010-07-01 11:28:46 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys 2010-07-01 11:28:46 ----A---- C:\Users\i\AppData\Roaming\PnkBstrK.sys 2010-07-01 11:28:17 ----A---- C:\Windows\system32\PnkBstrB.exe 2010-07-01 11:28:15 ----A---- C:\Windows\system32\PnkBstrA.exe 2010-07-01 11:28:12 ----A---- C:\Windows\system32\pbsvc_heroes.exe 2010-07-01 11:15:32 ----D---- C:\Program Files\EA Games 2010-06-26 12:00:27 ----D---- C:\Program Files\IronPython 2.6 for .NET 4.0 2010-06-24 03:00:42 ----A---- C:\Windows\system32\PresentationHostProxy.dll 2010-06-24 03:00:42 ----A---- C:\Windows\system32\PresentationHost.exe 2010-06-24 03:00:42 ----A---- C:\Windows\system32\netfxperf.dll 2010-06-24 03:00:42 ----A---- C:\Windows\system32\mscoree.dll 2010-06-24 03:00:42 ----A---- C:\Windows\system32\dfshim.dll 2010-06-23 10:38:10 ----A---- C:\Windows\system32\ntdll.dll 2010-06-23 10:38:09 ----A---- C:\Windows\system32\CPFilters.dll 2010-06-23 10:38:07 ----A---- C:\Windows\system32\msdri.dll ======List of files/folders modified in the last 1 months====== 2010-07-19 11:54:02 ----D---- C:\Windows\Temp 2010-07-19 11:53:53 ----D---- C:\Windows\Prefetch 2010-07-19 11:24:36 ----D---- C:\Users\i\AppData\Roaming\Media Player Classic 2010-07-19 11:24:36 ----D---- C:\ProgramData\Spybot - Search & Destroy 2010-07-19 11:24:35 ----D---- C:\Windows\system32\LogFiles 2010-07-19 11:24:35 ----D---- C:\Windows 2010-07-19 11:09:47 ----HD---- C:\ProgramData 2010-07-19 11:09:45 ----RD---- C:\Program Files 2010-07-19 11:09:37 ----D---- C:\Program Files\CCleaner 2010-07-19 11:03:18 ----D---- C:\Windows\System32 2010-07-19 11:03:18 ----D---- C:\Windows\inf 2010-07-19 11:03:18 ----A---- C:\Windows\system32\PerfStringBackup.INI 2010-07-19 04:05:17 ----D---- C:\Windows\system32\config 2010-07-19 01:29:22 ----SHD---- C:\System Volume Information 2010-07-19 01:14:29 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2010-07-19 01:14:25 ----D---- C:\Windows\system32\drivers 2010-07-19 00:53:09 ----D---- C:\Users\i\AppData\Roaming\Skype 2010-07-19 00:53:04 ----D---- C:\Users\i\AppData\Roaming\skypePM 2010-07-19 00:52:43 ----D---- C:\Windows\Tasks 2010-07-19 00:30:35 ----D---- C:\Users\i\AppData\Roaming\QuickScan 2010-07-19 00:17:27 ----D---- C:\Windows\Branding 2010-07-19 00:10:21 ----D---- C:\Users\i\AppData\Roaming\foobar2000 2010-07-18 23:57:20 ----D---- C:\Windows\system32\drivers\etc 2010-07-18 23:54:23 ----D---- C:\Windows\debug 2010-07-18 23:50:49 ----D---- C:\Windows\system32\Tasks 2010-07-17 20:44:09 ----D---- C:\Users\i\AppData\Roaming\vlc 2010-07-17 17:50:00 ----D---- C:\Program Files\JDownloader 2010-07-16 17:50:24 ----SHD---- C:\Windows\Installer 2010-07-14 19:19:06 ----D---- C:\ProgramData\Microsoft Help 2010-07-14 19:18:05 ----D---- C:\Windows\system32\catroot2 2010-07-09 10:08:15 ----D---- C:\Windows\winsxs 2010-07-08 23:06:32 ----D---- C:\Windows\system32\catroot 2010-07-08 23:02:20 ----D---- C:\Windows\system32\DriverStore 2010-07-08 22:38:02 ----D---- C:\Program Files\Common Files 2010-07-04 12:36:31 ----D---- C:\Program Files\Adobe 2010-07-04 12:36:29 ----D---- C:\Program Files\Common Files\Adobe AIR 2010-07-02 21:39:05 ----A---- C:\Windows\system32\MRT.exe 2010-07-02 00:42:17 ----D---- C:\Users\i\AppData\Roaming\Mozilla 2010-07-02 00:27:59 ----RSD---- C:\Windows\assembly 2010-07-02 00:27:18 ----D---- C:\Windows\Registration 2010-07-02 00:26:53 ----D---- C:\Program Files\Internet Explorer 2010-07-01 10:32:25 ----D---- C:\AdobeTemp 2010-06-29 08:52:18 ----D---- C:\Program Files\Microsoft Security Essentials 2010-06-28 23:58:19 ----D---- C:\Program Files\Mozilla Firefox 2010-06-26 12:45:37 ----D---- C:\Windows\Microsoft.NET 2010-06-25 17:20:17 ----D---- C:\Users\i\AppData\Roaming\dvdcss 2010-06-25 14:46:33 ----D---- C:\Users\i\AppData\Roaming\.purple 2010-06-24 23:23:22 ----D---- C:\Windows\system32\en-US 2010-06-24 23:23:20 ----D---- C:\Program Files\Microsoft.NET 2010-06-24 03:00:36 ----D---- C:\Windows\ehome 2010-06-24 03:00:26 ----D---- C:\Windows\AppPatch 2010-06-22 16:32:29 ----D---- C:\Windows\system32\NDF 2010-06-21 23:19:51 ----D---- C:\Program Files\Common Files\microsoft shared ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2008-02-06 44608] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648] R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-01 691696] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584] R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216] R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768] R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376] R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816] R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696] R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880] R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432] R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680] R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168] R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536] R3 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928] R3 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2005-12-22 51840] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536] R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-10-10 84992] R3 SMSCIRDA;SMSC Infrared Device Driver; C:\Windows\system32\DRIVERS\SMSCirda.sys [2007-04-25 31232] R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-10-26 1095936] R3 usbvm321;USB2.0 0.35M WebCam; C:\Windows\System32\Drivers\usbvm321.sys [2009-11-01 205568] S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [] S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 46976] S3 a1dplurs;a1dplurs; C:\Windows\system32\drivers\a1dplurs.sys [] S3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312] S3 Avc;AVC Device; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 40320] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888] S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704] S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176] S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2009-07-14 52608] S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176] S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528] S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816] S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120] S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632] S3 scsiscan;SCSI Scanner Driver; C:\Windows\system32\DRIVERS\scsiscan.sys [2009-07-14 14848] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304] S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224] S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192] S3 USBPNPA;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM108.sys [2007-06-28 1310720] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840] S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648] S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824] S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992] R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-30 203296] R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-07-01 75064] R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [2007-01-11 113664] S2 NIHardwareService;NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [] S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-02 655624] S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936] S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-30 1343400] S4 AppMgmt;Application Management; C:\Windows\system32\svchost.exe [2009-07-14 20992] S4 CscService;Offline Files; C:\Windows\System32\svchost.exe [2009-07-14 20992] S4 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [] S4 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [] S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S4 PeerDistSvc;BranchCache; C:\Windows\System32\svchost.exe [2009-07-14 20992] -----------------EOF----------------- vielen dank im vorraus. werde jetzt nochmla mbam laufen lassen mal sehen was passiert. |
Themen zu Antimalware Doc entfernen klappt nciht ganz |
.dll, 32 bit, avsolution, browser, computer, device driver, diagnostics, ekrn.exe, entfernen, eset nod32, explorer, geliefert, generic, google, helper, infected, local\temp, logfile, malware protection, microsoft fix it, microsoft security, microsoft security essentials, neustart, notepad.exe, nvidia, pdf, plug-in, programdata, prozesse, realtek, rogue.antimalwaredoctor, router, security, skype.exe, software, sptd.sys, start menu, svchost.exe, system, temp, viren, virus, vista, vista 32, vista 32 bit, windows, windows security |