![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Antimalware Doc entfernen klappt nciht ganzWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #1 |
![]() | Antimalware Doc entfernen klappt nciht ganz Hallo, da dies mein erste post hier ist, hoffe ich dass ich mich den forenregeln entsprechend verhalte. ich beziehe mich auf die anleitung zur entfernung des antimalware doc : http://www.trojaner-board.de/83172-a...entfernen.html in dem thread steht, dass ich sowieso nochmal hier posten soll. bei mir geht er allerdings nicht weg. der virus trat zum ersten mal gesten in erscheinung, nachdem mein rechner mehrere stunden unbenutzt und angeschaltet war, mein windows security essentials hat wohl was erkannt, es waren allerdings auch schon fenster von antimalware doc offen. hier das was security essentials gemacht hat (ich sah keine andere möglichkeit als einen sceenshot zu machen): ![]() da ich gemerkt habe dass irgendwas sehr im argen ist habe ich den computer direkt im abgesicherten modus gestartet und meinen router ausgeschaltet. dort habe ich mbam ccscanner und auch viren scanns gemacht: mbam log: Code:
ATTFilter Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3930
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
19.07.2010 00:10:37
mbam-log-2010-07-19 (00-10-37).txt
Scan type: Quick scan
Objects scanned: 118910
Time elapsed: 5 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\halo2 (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\i\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Code:
ATTFilter Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4325
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
19.07.2010 09:14:57
mbam-log-2010-07-19 (09-14-57).txt
Scan type: Full scan (C:\|D:\|F:\|)
Objects scanned: 339881
Time elapsed: 1 hour(s), 34 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\W34BCG2GRJ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\JDK5SWFMZY (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Code:
ATTFilter Logfile of random's system information tool 1.08 (written by random/random)
Run by i at 2010-07-19 11:54:49
Microsoft Windows 7 Professional
System drive C: has 18 GB (30%) free of 60 GB
Total RAM: 2047 MB (64% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
" Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"Google Update"=C:\Users\i\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-03 135664]
"AdobeBridge"= []
"EPSON Stylus Photo R2400"=C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATI9SE.EXE [2007-01-10 177664]
C:\Users\i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 months======
2010-07-19 11:09:47 ----D---- C:\Users\i\AppData\Roaming\Yahoo!
2010-07-19 11:09:47 ----D---- C:\ProgramData\Yahoo! Companion
2010-07-19 11:09:45 ----D---- C:\Program Files\Yahoo!
2010-07-19 11:08:35 ----D---- C:\rsit
2010-07-19 11:08:35 ----D---- C:\Program Files\trend micro
2010-07-19 01:04:42 ----A---- C:\mbam-error.txt
2010-07-13 11:52:22 ----D---- C:\REFlex
2010-07-12 10:13:50 ----A---- C:\Windows\_MSRSTRT.EXE
2010-07-11 23:58:39 ----D---- C:\Program Files\Sigma_Team
2010-07-11 23:55:16 ----D---- C:\Program Files\Sigma Team
2010-07-09 10:07:57 ----D---- C:\Program Files\MSXML 4.0
2010-07-08 23:50:54 ----D---- C:\Users\i\AppData\Roaming\Nokia Ovi Suite
2010-07-08 23:02:16 ----D---- C:\Program Files\PC Connectivity Solution
2010-07-08 23:00:42 ----D---- C:\ProgramData\NokiaInstallerCache
2010-07-08 22:39:04 ----D---- C:\Users\i\AppData\Roaming\Nokia
2010-07-08 22:38:02 ----D---- C:\Program Files\Common Files\PCSuite
2010-07-08 22:36:53 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-07-08 22:28:16 ----D---- C:\ProgramData\PC Suite
2010-07-08 22:28:07 ----D---- C:\Users\i\AppData\Roaming\PC Suite
2010-07-08 21:49:34 ----D---- C:\ProgramData\Nokia
2010-07-08 21:48:20 ----D---- C:\Program Files\DIFX
2010-07-08 21:47:47 ----DC---- C:\Windows\system32\DRVSTORE
2010-07-08 21:45:22 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-07-08 21:42:49 ----D---- C:\Program Files\Common Files\Nokia
2010-07-08 21:42:46 ----D---- C:\Program Files\Nokia
2010-07-08 21:40:50 ----D---- C:\ProgramData\Installations
2010-07-06 10:23:01 ----D---- C:\Program Files\Codemasters
2010-07-02 00:28:36 ----D---- C:\Users\i\AppData\Roaming\Turbine
2010-07-02 00:25:26 ----D---- C:\Windows\system32\URTTEMP
2010-07-02 00:14:45 ----D---- C:\Program Files\Turbine
2010-07-01 21:27:20 ----D---- C:\ProgramData\PMB Files
2010-07-01 21:27:07 ----D---- C:\Program Files\Pando Networks
2010-07-01 11:28:46 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys
2010-07-01 11:28:46 ----A---- C:\Users\i\AppData\Roaming\PnkBstrK.sys
2010-07-01 11:28:17 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-07-01 11:28:15 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-07-01 11:28:12 ----A---- C:\Windows\system32\pbsvc_heroes.exe
2010-07-01 11:15:32 ----D---- C:\Program Files\EA Games
2010-06-26 12:00:27 ----D---- C:\Program Files\IronPython 2.6 for .NET 4.0
2010-06-24 03:00:42 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-06-24 03:00:42 ----A---- C:\Windows\system32\PresentationHost.exe
2010-06-24 03:00:42 ----A---- C:\Windows\system32\netfxperf.dll
2010-06-24 03:00:42 ----A---- C:\Windows\system32\mscoree.dll
2010-06-24 03:00:42 ----A---- C:\Windows\system32\dfshim.dll
2010-06-23 10:38:10 ----A---- C:\Windows\system32\ntdll.dll
2010-06-23 10:38:09 ----A---- C:\Windows\system32\CPFilters.dll
2010-06-23 10:38:07 ----A---- C:\Windows\system32\msdri.dll
======List of files/folders modified in the last 1 months======
2010-07-19 11:54:02 ----D---- C:\Windows\Temp
2010-07-19 11:53:53 ----D---- C:\Windows\Prefetch
2010-07-19 11:24:36 ----D---- C:\Users\i\AppData\Roaming\Media Player Classic
2010-07-19 11:24:36 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-07-19 11:24:35 ----D---- C:\Windows\system32\LogFiles
2010-07-19 11:24:35 ----D---- C:\Windows
2010-07-19 11:09:47 ----HD---- C:\ProgramData
2010-07-19 11:09:45 ----RD---- C:\Program Files
2010-07-19 11:09:37 ----D---- C:\Program Files\CCleaner
2010-07-19 11:03:18 ----D---- C:\Windows\System32
2010-07-19 11:03:18 ----D---- C:\Windows\inf
2010-07-19 11:03:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-19 04:05:17 ----D---- C:\Windows\system32\config
2010-07-19 01:29:22 ----SHD---- C:\System Volume Information
2010-07-19 01:14:29 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-19 01:14:25 ----D---- C:\Windows\system32\drivers
2010-07-19 00:53:09 ----D---- C:\Users\i\AppData\Roaming\Skype
2010-07-19 00:53:04 ----D---- C:\Users\i\AppData\Roaming\skypePM
2010-07-19 00:52:43 ----D---- C:\Windows\Tasks
2010-07-19 00:30:35 ----D---- C:\Users\i\AppData\Roaming\QuickScan
2010-07-19 00:17:27 ----D---- C:\Windows\Branding
2010-07-19 00:10:21 ----D---- C:\Users\i\AppData\Roaming\foobar2000
2010-07-18 23:57:20 ----D---- C:\Windows\system32\drivers\etc
2010-07-18 23:54:23 ----D---- C:\Windows\debug
2010-07-18 23:50:49 ----D---- C:\Windows\system32\Tasks
2010-07-17 20:44:09 ----D---- C:\Users\i\AppData\Roaming\vlc
2010-07-17 17:50:00 ----D---- C:\Program Files\JDownloader
2010-07-16 17:50:24 ----SHD---- C:\Windows\Installer
2010-07-14 19:19:06 ----D---- C:\ProgramData\Microsoft Help
2010-07-14 19:18:05 ----D---- C:\Windows\system32\catroot2
2010-07-09 10:08:15 ----D---- C:\Windows\winsxs
2010-07-08 23:06:32 ----D---- C:\Windows\system32\catroot
2010-07-08 23:02:20 ----D---- C:\Windows\system32\DriverStore
2010-07-08 22:38:02 ----D---- C:\Program Files\Common Files
2010-07-04 12:36:31 ----D---- C:\Program Files\Adobe
2010-07-04 12:36:29 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-07-02 21:39:05 ----A---- C:\Windows\system32\MRT.exe
2010-07-02 00:42:17 ----D---- C:\Users\i\AppData\Roaming\Mozilla
2010-07-02 00:27:59 ----RSD---- C:\Windows\assembly
2010-07-02 00:27:18 ----D---- C:\Windows\Registration
2010-07-02 00:26:53 ----D---- C:\Program Files\Internet Explorer
2010-07-01 10:32:25 ----D---- C:\AdobeTemp
2010-06-29 08:52:18 ----D---- C:\Program Files\Microsoft Security Essentials
2010-06-28 23:58:19 ----D---- C:\Program Files\Mozilla Firefox
2010-06-26 12:45:37 ----D---- C:\Windows\Microsoft.NET
2010-06-25 17:20:17 ----D---- C:\Users\i\AppData\Roaming\dvdcss
2010-06-25 14:46:33 ----D---- C:\Users\i\AppData\Roaming\.purple
2010-06-24 23:23:22 ----D---- C:\Windows\system32\en-US
2010-06-24 23:23:20 ----D---- C:\Program Files\Microsoft.NET
2010-06-24 03:00:36 ----D---- C:\Windows\ehome
2010-06-24 03:00:26 ----D---- C:\Windows\AppPatch
2010-06-22 16:32:29 ----D---- C:\Windows\system32\NDF
2010-06-21 23:19:51 ----D---- C:\Program Files\Common Files\microsoft shared
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2008-02-06 44608]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-01 691696]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2005-12-22 51840]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-10-10 84992]
R3 SMSCIRDA;SMSC Infrared Device Driver; C:\Windows\system32\DRIVERS\SMSCirda.sys [2007-04-25 31232]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-10-26 1095936]
R3 usbvm321;USB2.0 0.35M WebCam; C:\Windows\System32\Drivers\usbvm321.sys [2009-11-01 205568]
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 46976]
S3 a1dplurs;a1dplurs; C:\Windows\system32\drivers\a1dplurs.sys []
S3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 Avc;AVC Device; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 40320]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2009-07-14 52608]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 scsiscan;SCSI Scanner Driver; C:\Windows\system32\DRIVERS\scsiscan.sys [2009-07-14 14848]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 USBPNPA;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM108.sys [2007-06-28 1310720]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-30 203296]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-07-01 75064]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [2007-01-11 113664]
S2 NIHardwareService;NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe []
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-02 655624]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-30 1343400]
S4 AppMgmt;Application Management; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 CscService;Offline Files; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S4 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 PeerDistSvc;BranchCache; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
vielen dank im vorraus. werde jetzt nochmla mbam laufen lassen mal sehen was passiert. |
| Themen zu Antimalware Doc entfernen klappt nciht ganz |
| .dll, 32 bit, avsolution, browser, computer, device driver, diagnostics, ekrn.exe, entfernen, eset nod32, explorer, geliefert, generic, google, helper, infected, local\temp, logfile, malware protection, microsoft fix it, microsoft security, microsoft security essentials, neustart, notepad.exe, nvidia, pdf, plug-in, programdata, prozesse, realtek, rogue.antimalwaredoctor, router, security, skype.exe, software, sptd.sys, start menu, svchost.exe, system, temp, viren, virus, vista, vista 32, vista 32 bit, windows, windows security |