MKA Posted November 19, 2014 Report Share Posted November 19, 2014 Hallo, ich habe seit gestern Probleme mit immer wieder erscheinenden Meldungen von NOD32 AV 7 und 8(habe heute auf 8 geupdated) bezüglich Dateien die sich im Windows\Temp Ordner befinden. Die Ordner und die Dateien haben einen Zufalls?generierten Namen. Im Log von NOD32 steht, dass die Dateien von EAM Service erstellt wurden. Ich habe beide Programme schon seit über einem Jahr im Betrieb und natürlich auch die jeweiligen Ausnahmen beidseitig gesetzt. 19.11.2014 08:27:08 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp000000bb a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:49 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp000000b4 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:43 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp000000aa a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:33 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp000000a8 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:26 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp000000a0 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:22 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp0000009a a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:16 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp00000089 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:04 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp0000002e a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:04 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp00000013 a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:26:04 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:25:45 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp0000002c Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:25:45 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp0000002c Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:25:45 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp00000020 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 08:25:45 Real-time file system protection file C:\Windows\TEMP\tmp000016f3\tmp00000020 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:05:20 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp0000006b a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:05:07 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000066 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:56 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp0000005e a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:43 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp0000005c a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:36 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000056 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:32 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000050 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:26 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000041 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:15 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000028 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:09 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp0000000f a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:09 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:03 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:03 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 07:04:03 Real-time file system protection file C:\Windows\TEMP\tmp00005872\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:53 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000067 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:42 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000062 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:30 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000005a a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:19 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000058 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:12 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000052 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:07 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000004c a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:02 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000028 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:02 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:02 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000000f a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:02:02 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000003d a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:01:25 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:01:25 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 19.11.2014 00:01:25 Real-time file system protection file C:\Windows\TEMP\tmp000014fd\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:52:38 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000067 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:52:38 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000062 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:52:04 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp0000005a a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:51 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000058 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:43 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000052 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:38 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp0000004c a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:33 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp0000000f a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:33 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp0000003d a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:33 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000028 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:51:33 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:50:52 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:50:52 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 22:50:52 Real-time file system protection file C:\Windows\TEMP\tmp00005ee0\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:49:51 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000067 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:49:38 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000062 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:49:26 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000005a a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:49:13 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000058 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:49:04 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000052 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:59 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000004c a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:52 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000003d a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:50 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000000f a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:50 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000028 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:50 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:16 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:16 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp00000026 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:16 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:48:16 Real-time file system protection file C:\Windows\TEMP\tmp00000114\tmp0000001a Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 20:40:56 Real-time file system protection file F:\!SABnzbd\Complete\_UNPACK_Far.Cry.4.Proper.Crack.Only-RELOADED\Crack\bin\steam_api.dll Win32/HackTool.Crack.CS potentially unsafe application unable to clean PRANDTL\Corellion Event occurred on a new file created by the application: E:\NZBApps\SABnzbd\win\unrar\x64\UnRAR.exe. 18.11.2014 18:48:18 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000006a a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:48:07 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000065 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:54 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000005d a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:43 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000005b a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:35 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000055 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:30 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000004f a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:20 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000012 a variant of Win32/AdWare.iBryte.V.gen application cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:20 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000002b a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:20 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000040 a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:47:20 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000001 a variant of Win32/Packed.VMProtect.ABD trojan cleaned by deleting - quarantined NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:46:44 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp00000029 Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:46:43 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000001d Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. 18.11.2014 18:46:43 Real-time file system protection file C:\Windows\TEMP\tmp0000241d\tmp0000001d Win32/HackTool.Patcher.A potentially unsafe application unable to clean NT-AUTORITÄT\SYSTEM Event occurred on a new file created by the application: C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe. Sind das irgendwelche Dateien aus der Quarantäne von EAM? Die tmp FIles exisitieren nach der Säuberung durch NOD32 noch, haben aber eine Größe von null bytes. EAM habe ich in der Version 9.0.0.4570 installiert. Über Tipps und Hinweise wäre ich sehr erfreut. Vielen Dank Grüße Link to comment Share on other sites More sharing options...
Christian Peters Posted November 19, 2014 Report Share Posted November 19, 2014 Hallo, das sieht fast so aus als würde NOD32 unsere Signaturen anmahnen wenn ein Onlineupdate in EAM läuft. Kommt das von den Zeiten hin das gerade ein Onlineupdate in EAM lief? Bitte mal die Ausnahme zur a2service.exe in NOD32 löschen, dann den Rechner ruhig mal neustarten und die Ausnahme erneut setzen. Kommt es dann immer noch zu diesen NOD32 Meldungen? Link to comment Share on other sites More sharing options...
Recommended Posts