Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Firefox leitet mich auf andere Seiten um! (https://www.trojaner-board.de/72692-firefox-leitet-mich-andere-seiten-um.html)

myrtille 04.05.2009 17:59

Hi,

stecke den Stick bitte nohcmal ein und führe Combofix nochmal aus.
Poste das Ergebnis hier.

Wenn die Malware noch aktiv war, dann hat einstecken gereicht um den Stick zu infizieren.

lg myrtille

Neandertaler 04.05.2009 18:15

Ok,soll ich den Log nochmal posten?

myrtille 04.05.2009 18:36

Ja bitte :)

lg myrtille

Neandertaler 04.05.2009 19:32

Code:

ComboFix 09-05-03.6 - Christopher 04.05.2009 20:26.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium  6.0.6001.1.1252.49.1031.18.2047.1321 [GMT 2:00]
ausgeführt von:: c:\users\Christopher\Desktop\ComboFix.exe
.

(((((((((((((((((((((((  Dateien erstellt von 2009-04-04 bis 2009-05-04  ))))))))))))))))))))))))))))))
.

2009-05-04 15:23 . 2009-03-24 14:08        55640        ----a-w        c:\windows\system32\drivers\avgntflt.sys
2009-05-04 15:23 . 2009-05-04 15:23        --------        d-----w        c:\programdata\Avira
2009-05-04 15:23 . 2009-05-04 15:23        --------        d-----w        c:\program files\Avira
2009-05-04 13:32 . 2009-05-04 16:45        --------        d-----w        c:\programdata\TrackMania
2009-05-04 12:43 . 2009-05-04 12:44        --------        d-----w        c:\program files\TmNationsForever
2009-05-02 15:21 . 2009-05-02 15:21        --------        d-----w        c:\program files\CCleaner
2009-05-02 10:41 . 2009-05-02 10:41        --------        d-----w        c:\users\Christopher\AppData\Roaming\Malwarebytes
2009-05-02 09:55 . 2009-04-06 13:32        15504        ----a-w        c:\windows\system32\drivers\mbam.sys
2009-05-02 09:55 . 2009-04-06 13:32        38496        ----a-w        c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 09:55 . 2009-05-02 09:55        --------        d-----w        c:\programdata\Malwarebytes
2009-05-02 09:55 . 2009-05-02 10:41        --------        d-----w        c:\program files\Malwarebytes' Anti-Malware
2009-04-30 14:44 . 2009-05-04 17:20        --------        d-----w        c:\program files\Silkroad
2009-04-29 08:44 . 2009-04-29 09:44        --------        d-----w        c:\users\Christopher\AppData\Roaming\Bioshock
2009-04-27 16:37 . 2009-04-27 16:37        --------        d-----w        c:\program files\Monte Cristo
2009-04-25 12:21 . 2009-04-28 20:58        --------        d-----w        c:\program files\World of Warcraft
2009-04-22 16:12 . 2009-04-27 14:36        --------        d-----w        c:\users\Christopher\Nachhilfe
2009-04-20 13:07 . 2009-05-04 17:20        --------        d-----w        c:\users\Christopher\Spiele
2009-04-15 15:44 . 2009-04-15 15:44        --------        d-----w        c:\users\Christopher\AppData\Local\Fallout3
2009-04-15 15:21 . 2009-04-15 15:21        --------        d-----w        c:\program files\Bethesda Softworks
2009-04-14 16:26 . 2009-04-15 10:09        --------        d-----w        c:\users\Christopher\AppData\Roaming\temp

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-04 17:19 . 2009-02-20 11:11        --------        d-----w        c:\program files\Ubisoft
2009-05-04 17:19 . 2008-01-10 16:04        --------        d--h--w        c:\program files\InstallShield Installation Information
2009-05-04 17:19 . 2008-07-21 14:08        --------        d-----w        c:\program files\Google
2009-05-04 17:18 . 2008-09-30 18:19        --------        d-----w        c:\program files\Game Cam V2
2009-05-04 14:57 . 2008-01-10 16:59        --------        d-----w        c:\program files\Norton Internet Security
2009-05-04 14:57 . 2008-01-10 16:57        --------        d-----w        c:\program files\Common Files\Symantec Shared
2009-05-04 14:42 . 2006-11-02 10:25        86016        ----a-w        c:\windows\inf\infstor.dat
2009-05-04 14:42 . 2006-11-02 10:25        51200        ----a-w        c:\windows\inf\infpub.dat
2009-05-04 14:42 . 2006-11-02 10:25        143360        ----a-w        c:\windows\inf\infstrng.dat
2009-05-04 07:56 . 2006-11-02 15:33        664044        ----a-w        c:\windows\system32\perfh007.dat
2009-05-04 07:56 . 2006-11-02 15:33        142222        ----a-w        c:\windows\system32\perfc007.dat
2009-04-29 18:23 . 2008-12-17 14:52        --------        d-----w        c:\program files\Fraps
2009-04-29 11:50 . 2008-09-11 11:25        --------        d-----w        c:\program files\Runes of Magic
2009-04-29 08:14 . 2008-10-02 15:19        --------        d-----w        c:\program files\2K Games
2009-04-26 17:45 . 2006-11-02 12:37        --------        d-----w        c:\program files\Microsoft Games
2009-04-25 14:54 . 2009-03-18 19:16        --------        d-----w        c:\program files\Diablo II
2009-04-25 14:44 . 2009-02-23 16:27        --------        d-----w        c:\program files\Common Files\Blizzard Entertainment
2009-04-25 10:46 . 2008-04-04 14:32        90568        ----a-w        c:\users\Christopher\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-24 20:25 . 2008-12-01 13:47        --------        d-----w        c:\program files\Bethesda
2009-04-24 20:23 . 2009-03-27 18:21        --------        d-----w        c:\program files\OnkoS
2009-04-24 20:11 . 2009-03-01 18:08        --------        d-----w        c:\program files\Anno 1602 Königs-Edition
2009-04-20 13:04 . 2009-03-23 10:00        --------        d-----w        c:\program files\DNA
2009-04-16 14:53 . 2006-11-02 11:18        --------        d-----w        c:\program files\Windows Mail
2009-04-14 16:27 . 2008-10-05 12:32        --------        d-----w        c:\program files\EA GAMES
2009-04-07 15:34 . 2008-04-04 19:47        --------        d-----w        c:\program files\Warcraft III
2009-04-07 10:49 . 2009-02-21 17:31        --------        d-----w        c:\program files\Steam
2009-04-06 23:19 . 2008-04-23 13:19        --------        d-----w        c:\program files\Valve
2009-04-06 16:34 . 2008-04-04 19:51        133409        ----a-w        c:\windows\War3Unin.dat
2009-04-04 16:55 . 2008-08-14 17:50        --------        d-----w        c:\program files\ICQ6
2009-04-04 15:11 . 2008-12-05 14:41        --------        d-----w        c:\program files\Electronic Arts
2009-04-02 14:42 . 2009-04-02 14:42        5434        ----a-w        c:\windows\system32\ealregsnapshot1.reg
2009-03-31 16:32 . 2008-05-05 15:37        98304        ----a-w        c:\windows\system32\CmdLineExt.dll
2009-03-29 08:17 . 2009-03-29 08:16        --------        d-----w        c:\program files\Unechtes Turnier
2009-03-28 18:00 . 2008-05-16 19:30        --------        d-----w        c:\program files\WarRock
2009-03-27 15:18 . 2009-03-23 17:07        --------        d-----w        c:\program files\RouterControl
2009-03-25 15:06 . 2008-08-19 17:56        --------        d-----w        c:\program files\THQ
2009-03-23 13:41 . 2009-03-23 13:14        614        ----a-w        c:\windows\eReg.dat
2009-03-21 18:30 . 2009-03-21 18:08        --------        d-----w        c:\program files\Starcraft
2009-03-20 16:52 . 2009-03-20 16:52        --------        d-----w        c:\program files\DivX
2009-03-20 16:52 . 2009-03-20 16:52        --------        d-----w        c:\program files\Common Files\PX Storage Engine
2009-03-20 16:52 . 2009-03-20 16:52        --------        d-----w        c:\program files\Common Files\DivX Shared
2009-03-18 19:29 . 2009-03-18 19:19        19284        ----a-w        c:\windows\DIIUnin.dat
2009-03-18 19:19 . 2009-03-18 19:19        2829        ----a-w        c:\windows\DIIUnin.pif
2009-03-18 19:19 . 2009-03-18 19:19        102400        ----a-w        c:\windows\DIIUnin.exe
2009-03-17 03:38 . 2009-04-15 10:06        13824        ----a-w        c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 10:06        24064        ----a-w        c:\windows\system32\amxread.dll
2009-03-16 19:58 . 2009-03-16 19:58        --------        d-----w        c:\program files\directx
2009-03-15 16:47 . 2009-03-15 16:47        --------        d-----w        c:\program files\SweetIM
2009-03-12 18:20 . 2009-03-12 18:20        --------        d-----w        c:\program files\VisionGS PE
2009-03-11 15:38 . 2009-02-21 17:31        --------        d-----w        c:\program files\Common Files\Steam
2009-03-08 13:25 . 2008-11-09 13:14        --------        d-----w        c:\program files\Common Files\Wise Installation Wizard
2009-03-08 11:35 . 2009-03-08 11:35        56        ---ha-w        c:\windows\system32\ezsidmv.dat
2009-03-08 11:32 . 2009-03-08 11:32        --------        d-----w        c:\program files\Common Files\Skype
2009-03-08 11:32 . 2009-03-08 11:32        --------        d-----r        c:\program files\Skype
2009-03-03 04:46 . 2009-04-15 10:06 3599328        ----a-w        c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 10:06        3547632        ----a-w        c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-15 10:06 827392        ----a-w        c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-15 10:06 183296        ----a-w        c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 10:06 551424        ----a-w        c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 10:06        26112        ----a-w        c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 10:06        78336        ----a-w        c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-15 10:06        98304        ----a-w        c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 10:06        54784        ----a-w        c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 10:06        44032        ----a-w        c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 10:06 666624        ----a-w        c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 10:06        17408        ----a-w        c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-15 10:06        26624        ----a-w        c:\windows\system32\ieUnatt.exe
2009-02-25 17:55 . 2009-03-27 20:22        4224        ----a-w        c:\windows\system32\drivers\NVStrap.sys
2009-02-13 08:49 . 2009-04-15 10:06        72704        ----a-w        c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 10:06        1255936        ----a-w        c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 05:59        2033152        ----a-w        c:\windows\system32\win32k.sys
2008-05-29 15:45 . 2006-11-02 12:50        174        --sha-w        c:\program files\desktop.ini
2009-01-27 01:34 . 2009-01-27 01:34        1044480        ----a-w        c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34        200704        ----a-w        c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-09-28 17:01 . 2008-09-28 16:50        24        --sh--w        c:\windows\SE2D238D6.tmp
2008-10-24 19:12 . 2008-08-26 19:44        168        --sh--r        c:\windows\System32\F125D974EB.sys
2006-05-03 10:06 . 2009-01-11 19:29        163328        --sh--r        c:\windows\System32\flvDX.dll
2008-10-24 19:12 . 2008-08-26 19:34        2516        --sha-w        c:\windows\System32\KGyGaAvL.sys
2007-02-21 11:47 . 2009-01-11 19:29        31232        --sh--r        c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-01-11 19:29        216064        --sh--r        c:\windows\System32\nbDX.dll
.

(((((((((((((((((((((((((((((  SnapShot@2009-05-04_15.03.39  )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-04 15:22 . 2009-05-04 15:22        62976              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90RUS.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        46080              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90KOR.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        46592              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90JPN.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        64512              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ITA.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        66048              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90FRA.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        65024              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESP.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        65024              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESN.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        56832              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ENU.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        66560              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90DEU.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        39936              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHT.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        38912              c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHS.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22        59904              c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22        59904              c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
- 2008-01-10 15:25 . 2009-05-04 14:59        52920              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-10 15:25 . 2009-05-04 15:16        52920              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-04 18:21 . 2009-05-04 15:16        13030              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-759913723-362470790-2232644708-1000_UserData.bin
+ 2009-05-04 15:23 . 2009-02-13 10:49        28376              c:\windows\System32\drivers\ssmdrv.sys
+ 2009-05-04 15:23 . 2009-03-30 08:33        96104              c:\windows\System32\drivers\avipbb.sys
- 2008-04-04 14:29 . 2009-05-04 12:29        16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28        16384              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-04 14:29 . 2009-05-04 12:29        32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28        32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-04 14:29 . 2009-05-04 12:29        16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28        16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-06 16:10 . 2009-05-04 15:10        4882              c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-05-04 15:13 . 2009-05-04 15:13        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-04 14:57 . 2009-05-04 14:57        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-05-04 15:13 . 2009-05-04 15:13        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-05-04 14:57 . 2009-05-04 14:57        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-04 15:22 . 2009-05-04 15:22        655872              c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22        572928              c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22        225280              c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22        161784              c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2006-11-02 13:05 . 2009-05-04 15:16        106432              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-01-11 08:52 . 2009-05-04 14:59        262144              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-11 08:52 . 2009-05-04 18:24        262144              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-11 08:51 . 2009-05-04 15:03 262144              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-11 08:51 . 2009-05-04 18:29        262144              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-05-04 15:22 . 2009-05-04 15:22        3783672              c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22        3768312              c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
+ 2006-11-02 10:22 . 2009-05-04 15:23        6553600              c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-04-16 19:05 6553600              c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-05-04 18:25 . 2009-05-04 18:25        6402048              c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2008-04-04 18:23 . 2009-05-04 15:23        217821837              c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin


Neandertaler 04.05.2009 19:34

[code]
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 11:22 1172792 ----a-w c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 92704]
"Diamondback"="c:\program files\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-12-13 4710400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0209C1EB-BEE2-42D5-824A-8F96C8B8FB66}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{981582D9-84D6-401A-8333-F849B43EF022}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7168CAD2-EDA5-4760-B7C5-D172F6D2F463}"= UDP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne
"{B45A25CC-46A3-4E17-9229-7D1DF3FC5EB7}"= TCP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne
"{903E5ED0-F469-46E1-BBD8-9987A8BD16E6}"= UDP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III
"{770F760E-4416-4C4D-B122-FF42EE201C65}"= TCP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III
"TCP Query User{502672C6-3C9F-4910-B8AB-8C10B3F3C470}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{783160AC-7616-4765-AA68-3FC6198D056C}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{E9AC9D13-7A3A-4667-98C6-F20B0233EA73}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{79BB1CFA-1308-4F12-88F7-9381D14DA49C}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{CCE7C36B-172F-4C09-94FD-8205E31CD9EF}"= UDP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline
"{F0D56D46-4573-429B-BA1C-372D341AB254}"= TCP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline
"{5DCD25B3-36E5-4593-B768-93BEC8D23299}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B1B5526B-81F3-4717-B43F-783B78EF06E2}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C4250CFD-B2A1-455C-8635-77C580970467}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A7E19DE2-CAF4-4191-BE9C-8AA23B10920D}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{920FC360-1281-41FE-8E02-D908132D5BD7}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{5D60376C-D259-4CBF-AAEF-8127EC898087}"= UDP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.dat:Die Schlacht um Mittelerde (tm)
"{B129296A-85E7-4E73-B8BA-13F180C177FC}"= TCP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.dat:Die Schlacht um Mittelerde (tm)
"{54B5772C-44E5-4FC5-AE6B-576F46CEAC30}"= UDP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701
"{127BF77D-7984-4C61-9B29-AC9BBFA67F8C}"= TCP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701
"{73387CB1-9A13-458F-9147-4AACE55090D3}"= UDP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager
"{AF2A47B5-85BF-42C9-AD34-FE0887BD6831}"= TCP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager
"{0F341A35-09C9-4FE7-86E1-446D50403311}"= UDP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core
"{1FD873DC-A4A2-443C-B815-A492C3720F78}"= TCP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core
"{76362B2A-86D2-47EA-BC59-2F812D9E1641}"= UDP:c:\program files\Hamachi\hamachi.exe:Hamachi
"{94CDBE7C-75CC-43FE-9228-0045DC6A0DCC}"= TCP:c:\program files\Hamachi\hamachi.exe:Hamachi
"{11097455-858D-49B1-9E1D-EFE3580E4E06}"= UDP:6112:Warcraft 3
"{A31F1B1A-3347-4182-B5B5-8FD70113BF1B}"= UDP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.dat:Die Schlacht um Mittelerde™ II
"{DFBCCF8D-441E-4B05-804B-928DBBF53C26}"= TCP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.dat:Die Schlacht um Mittelerde™ II
"{55B99994-13AA-4A1C-AB46-A2065ECFFC66}"= UDP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (TCP-In)
"{C1A16C7A-0F18-4609-8CC5-70653567F561}"= TCP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (UDP-In)
"TCP Query User{35D944C3-0A16-4CE4-852A-FA14238A4D7D}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= UDP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando
"UDP Query User{DC725E17-DF88-4158-817D-839826F1E697}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= TCP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando
"{69BBAEC1-7557-412C-8411-A970511CB0B8}"= UDP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL-
"{992CB4AA-6147-4E5F-8D30-F52BC6F6FB53}"= TCP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL-
"{88CC8670-3611-4FFF-BD7D-39EED605FA48}"= UDP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server
"{098D56CC-53E4-4DBF-B2F5-B122091AAC41}"= TCP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server
"{383100EE-015B-46FF-A79A-8119899F6C8B}"= UDP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2
"{1DC0F295-31C1-42FB-8326-13F00210BBC2}"= TCP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2
"{EF80FDD8-E576-4C71-8336-2EDC2571B46E}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{C5741607-E847-486A-A49C-B17D28B23D35}"= UDP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (TCP-In)
"{264CCE17-3A75-4E0B-BD00-DA644775D075}"= TCP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (UDP-In)
"{FB123311-4F78-452F-97D0-3201D18619DE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{AAA930F9-3906-4A03-A843-BF34A64588F5}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{FFC98B26-81CE-481B-AEF4-85564B97ED03}"= UDP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3
"{C17CAB19-D678-4C41-AB09-F10E9847CD9F}"= TCP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3
"{28925910-40BE-4DB9-A120-1403EFC7550B}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{34ECB7B2-FBC9-4AD9-A08A-4241FC471100}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{2DE0C830-039F-409C-8AED-A884DC463E2D}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{A1E7526F-3BB0-4623-8274-1EF086D2C535}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{7A9FFA39-F02C-42F8-AC48-4C837BEFD612}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{D3A46323-6870-4066-890F-E405A3C23BC8}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{DED357B9-FD3A-4E08-A69E-6FC424FB3751}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{6A51C871-1A21-4BB6-87C0-68B519C80459}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{E306C1C9-48AB-469C-A6C1-98B3509705DA}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box
"{53A0367B-3A1D-422C-B7B3-CA1F654B8902}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box
"{E3EBAB2E-DBAA-4187-83AF-EC0628CBBBA3}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box
"{F7EC7937-140A-49EF-BCD6-08544E9F809E}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box
"{36F3976B-E8A3-46B5-B2FD-83FB1A6CD16C}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box
"{58690264-8D22-4AE8-AA50-5600EC979C75}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box
"TCP Query User{195B7CB4-9846-4B1B-858C-8460EACD6F97}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{D5CC90BC-F547-4124-A71E-E24218FC9274}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever

R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-02-17 2736890]
R3 XDva092;XDva092; [x]
R3 XDva190;XDva190; [x]
R4 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-08-05 34144]
R4 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704]
S3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\Drivers\DB3G.sys [2005-04-24 13225]
S3 SPC520;Philips SPC520NC PC Camera;c:\windows\system32\drivers\SPC520.sys [2007-10-01 483328]
S3 SPC520m;Philips SPC520NC PC Cameram;c:\windows\system32\drivers\SPC520m.sys [2007-10-01 7680]


--- Andere Dienste/Treiber im Speicher ---

*NewlyCreated* - AVGIO
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb93-8d76-11dd-b7ef-001e8c906253}]
\shell\AutoRun\command - K:\LaunchRC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb95-8d76-11dd-b7ef-001e8c906253}]
\shell\AutoRun\command - L:\LaunchBFII.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb97-8d76-11dd-b7ef-001e8c906253}]
\shell\AutoRun\command - M:\autorun.exe -auto

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c074acdd-4438-11dd-9024-806e6f6e6963}]
\shell\AutoRun\command - E:\Start.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.icq.com/online/online2/zuma/popcaploader_v6.cab
FF - ProfilePath - c:\users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\ud4o5gfb.default\
FF - prefs.js: browser.startup.homepage - www.google.de
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programdata\NexonEU\NGM\npNxGameeu.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-04 20:29
Windows 6.0.6001 Service Pack 1 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...


c:\users\CHRIST~1\AppData\Local\Temp\catchme.dll 53248 bytes executable

Scan erfolgreich abgeschlossen
versteckte Dateien: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2d,fb,54,94,2b,97,59,32,ed,06,4d,31,92,4a,9d,2a,30,e4,80,2d,44,a2,7f,
de,98,d0,06,44,f5,b3,83,3b,dd,20,a8,23,41,40,1a,03,1a,ee,0b,b4,38,70,90,dc,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\License information*]
"datasecu"=hex:41,4c,f4,29,d1,92,15,fe,82,71,c5,d5,a8,ed,2f,28,16,4e,32,03,c9,
fb,20,26,41,a3,24,3e,6b,8e,c6,1e,fe,b8,0d,26,be,ea,73,a2,50,13,c0,ad,50,7c,\
"rkeysecu"=hex:ae,1f,71,ba,90,aa,7c,d2,dd,49,4d,96,2e,c0,e8,08
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------

- - - - - - - > 'Explorer.exe'(888)
c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll
.
Zeit der Fertigstellung: 2009-05-04 20:30
ComboFix-quarantined-files.txt 2009-05-04 18:30
ComboFix2.txt 2009-05-04 15:04

Vor Suchlauf: 25 Verzeichnis(se), 117.885.911.040 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 117.856.190.464 Bytes frei

336 --- E O F --- 2009-05-01 14:32[code]

myrtille 04.05.2009 22:25

Hi,

das sieht gut aus :)

Du kannst dann Combofix deinstallieren, wenn keine Probleme mehr existieren.

Einfach combofix /u unter Start->ausführen eingeben.

lg myrtille

Neandertaler 05.05.2009 13:13

Viiellen Dank myrtille,du hast mir sehr geholfen!
Das Forum kann ich nur empfehlen!


-CLOSED-


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:26 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131