##################################################################
[!][!][!] Welcome to SharpEDRChecker by @PwnDexter [!][!][!]
[+][+][+] Running as admin, all checks will be performed [+][+][+]
##################################################################
######################################
[!][!][!] Checking processes [!][!][!]
######################################
[-] Suspicious process found:
Name: MsMpEng.exe
Description: MsMpEng.exe
Caption: MsMpEng.exe
Binary:
Process ID: 6184
Parent Process: 1140
Process CmdLine:
File Metadata:
[!] Matched on: msmpeng
[-] Suspicious process found:
Name: SecurityHealthService.exe
Description: SecurityHealthService.exe
Caption: SecurityHealthService.exe
Binary:
Process ID: 9352
Parent Process: 1140
Process CmdLine:
File Metadata:
[!] Matched on: securityhealthservice
###################################################################
[!][!][!] Checking modules loaded in your current process [!][!][!]
###################################################################
[-] Suspicious modload found in your process:
Suspicious Module: C:\Windows\SYSTEM32\amsi.dll
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: C:\Windows\SYSTEM32\amsi.dll
Original Filename: amsi.dll
Internal Name: amsi.dll
Company Name: Microsoft Corporation
File Description: Anti-Malware Scan Interface
Product Version: 10.0.19041.746
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: amsi.dll, anti-malware, malware
[-] Suspicious modload found in your process:
Suspicious Module: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpOav.dll
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpOav.dll
Original Filename: MpOAV.dll
Internal Name: MpOAV
Company Name: Microsoft Corporation
File Description: IOfficeAntiVirus Module
Product Version: 4.18.2011.6
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: antivirus, defender
########################################
[!][!][!] Checking Directories [!][!][!]
########################################
[-] Suspicious directory found: C:\Program Files\Windows Defender
[!] Matched on: defender
[-] Suspicious directory found: C:\Program Files\Wireshark
[!] Matched on: wireshark
[-] Suspicious directory found: C:\Program Files (x86)\Windows Defender
[!] Matched on: defender
[-] Suspicious directory found: C:\ProgramData\Malwarebytes
[!] Matched on: malware
[-] Suspicious directory found: C:\ProgramData\McAfee
[!] Matched on: mcafee
#####################################
[!][!][!] Checking Services [!][!][!]
#####################################
[-] Suspicious service found:
Name: mpssvc
DisplayName: Windows Defender Firewall
Description: Die Windows Defender Firewall trägt zum Schutz des Computers bei, indem der Zugriff durch nicht autorisierte Benutzer auf den Computer über das Internet bzw. ein Netzwerk verhindert wird.
Caption: Windows Defender Firewall
Binary: C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
Status: Running
Process ID: 2072
File Metadata:
Product Name: Betriebssystem Microsoft® Windows®
Filename: C:\Windows\system32\svchost.exe
Original Filename: svchost.exe.mui
Internal Name: svchost.exe
Company Name: Microsoft Corporation
File Description: Hostprozess f├╝r Windows-Dienste
Product Version: 10.0.19041.561
Comments:
Legal Copyright: ┬® Microsoft Corporation. Alle Rechte vorbehalten.
Legal Trademarks:
[!] Matched on: defender
[-] Suspicious service found:
Name: PolicyAgent
DisplayName: IPsec-Richtlinien-Agent
Description: IPsec (Internet Protocol Security) unterst├╝tzt die Peerauthentifizierung auf Netzwerkebene, Datenursprungsauthentifizierung, Datenvertraulichkeit (Verschl├╝sselung) und Schutz vor Wiedergabeangriffen. Dieser Dienst erzwingt die IPsec-Richtlinien, die mit dem Snap-In "IP-Sicherheitsrichtlinien" oder mit dem Befehlszeilentool "netsh ipsec" erstellt wurden. Wenn Sie diesen Dienst beenden, k├Ânnen Probleme mit der Netzwerkkonnektivit├ñt auftreten, wenn die Richtlinie IPsec-Verbindungen erfordert. Zudem ist die Remoteverwaltung der Windows Defender Firewall nicht verf├╝gbar, wenn dieser Dienst beendet wird.
Caption: IPsec-Richtlinien-Agent
Binary: C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p
Status: Running
Process ID: 4284
File Metadata:
Product Name: Betriebssystem Microsoft® Windows®
Filename: C:\Windows\system32\svchost.exe
Original Filename: svchost.exe.mui
Internal Name: svchost.exe
Company Name: Microsoft Corporation
File Description: Hostprozess f├╝r Windows-Dienste
Product Version: 10.0.19041.561
Comments:
Legal Copyright: ┬® Microsoft Corporation. Alle Rechte vorbehalten.
Legal Trademarks:
[!] Matched on: defender
[-] Suspicious service found:
Name: SecurityHealthService
DisplayName: Windows-Sicherheitsdienst
Description: Der Windows-Sicherheitsdienst sorgt für den einheitlichen Geräteschutz und für Integritätsinformationen
Caption: Windows-Sicherheitsdienst
Binary: C:\Windows\system32\SecurityHealthService.exe
Status: Running
Process ID: 9352
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: C:\Windows\system32\SecurityHealthService.exe
Original Filename: SecurityHealthService.exe
Internal Name: SecurityHealthService
Company Name: Microsoft Corporation
File Description: Windows Security Health Service
Product Version: 4.18.1907.16384
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: securityhealthservice
[-] Suspicious service found:
Name: WdNisSvc
DisplayName: Microsoft Defender Antivirus-Netzwerkinspektionsdienst
Description: Sch├╝tzt gegen Eindringversuche bei bekannten und neu erkannten Sicherheitsrisiken von Netzwerkprotokollen.
Caption: Microsoft Defender Antivirus-Netzwerkinspektionsdienst
Binary: "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe"
Status: Stopped
Process ID: 0
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe
Original Filename: NisSrv.exe
Internal Name: NisSrv.exe
Company Name: Microsoft Corporation
File Description: Microsoft Network Realtime Inspection Service
Product Version: 4.18.2011.6
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: antivirus, defender, nissrv
[-] Suspicious service found:
Name: WinDefend
DisplayName: Microsoft Defender Antivirus-Dienst
Description: Sch├╝tzt Benutzer vor Schadsoftware und weiterer potenziell unerw├╝nschter Software.
Caption: Microsoft Defender Antivirus-Dienst
Binary: "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe"
Status: Running
Process ID: 6184
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe
Original Filename: MsMpEng.exe
Internal Name: MsMpEng.exe
Company Name: Microsoft Corporation
File Description: Antimalware Service Executable
Product Version: 4.18.2011.6
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: antimalware, antivirus, defender, malware, msmpeng
[!] Could not get file info for: C:
[-] Suspicious service found:
Name: SDScannerService
DisplayName: Spybot-S&D 2 Scanner Service
Description: Offers malware scanning services to Spybot-S&D modules
Caption: Spybot-S&D 2 Scanner Service
Binary: "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
Status: Running
Process ID: 6696
File Metadata:
Product Name: Spybot - Search & Destroy
Filename: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
Original Filename: SDFSSvc.exe
Internal Name:
Company Name: Safer-Networking Ltd.
File Description: Spybot-S&D 2 Scanner Service
Product Version: 2.7.64.0
Comments:
Legal Copyright: ┬® 2009-2018 Safer-Networking Ltd. All rights reserved.
Legal Trademarks: Spybot® and Spybot - Search & Destroy® are registered trademarks.
[!] Matched on: malware
####################################
[!][!][!] Checking drivers [!][!][!]
####################################
[-] Suspicious driver found:
Suspicious Module: WdFilter.sys
File Metadata:
Product Name: Microsoft® Windows® Operating System
Filename: c:\windows\system32\drivers\wd\wdfilter.sys
Original Filename: WdFilter.sys
Internal Name: WdFilter
Company Name: Microsoft Corporation
File Description: Microsoft antimalware file system filter driver
Product Version: 4.18.2011.6
Comments:
Legal Copyright: ┬® Microsoft Corporation. All rights reserved.
Legal Trademarks:
[!] Matched on: antimalware, malware
[!] Could not get file info for: c:\Windows\Sysnative\drivers\dump_diskdump.sys
[!] Could not get file info for: c:\Windows\Sysnative\drivers\dump_iastorac.sys
[!] Could not get file info for: c:\Windows\Sysnative\drivers\dump_dumpfve.sys
################################
[!][!][!] TLDR Summary [!][!][!]
################################
[!] Process Summary:
[-] MsMpEng.exe : msmpeng
[-] SecurityHealthService.exe : securityhealthservice
[!] Modload Summary:
[-] C:\Windows\SYSTEM32\amsi.dll : amsi.dll, anti-malware, malware
[-] C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpOav.dll : antivirus, defender
[!] Directory Summary:
[-] C:\Program Files\Windows Defender : defender
[-] C:\Program Files\Wireshark : wireshark
[-] C:\Program Files (x86)\Windows Defender : defender
[-] C:\ProgramData\Malwarebytes : malware
[-] C:\ProgramData\McAfee : mcafee
[!] Service Summary:
[-] mpssvc : defender
[-] PolicyAgent : defender
[-] SecurityHealthService : securityhealthservice
[-] WdNisSvc : antivirus, defender, nissrv
[-] WinDefend : antimalware, antivirus, defender, malware, msmpeng
[-] SDScannerService : malware
[!] Driver Summary:
[-] WdFilter.sys : antimalware, malware
#######################################
[!][!][!] EDR Checks Complete [!][!][!]
#######################################
Comments