Teil II Code:
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [14.07.2009 17:01 108289]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [06.05.2009 21:17 604416]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [15.03.2009 20:57 666368]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [12.05.2005 15:39 1287296]
R3 wbscr;Winbond Smartcard Reader for I/O;c:\windows\system32\drivers\wbscr.sys [15.03.2009 21:01 19928]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [10.03.2009 20:35 17408]
S3 PDNMp50;PDNMp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNMp50.sys [28.11.2006 21:46 28224]
S3 PDNSp50;PDNSp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNSp50.sys [28.11.2006 21:46 27072]
S3 USBAV191;Instant VideoXpress;c:\windows\system32\drivers\USBAV191.SYS [15.03.2009 18:20 120128]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://alice.aol.de
mStart Page = hxxp://alice.aol.de
IE: An vorhandenes PDF anfügen - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Auswahl in Adobe PDF konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Auswahl in vorhandene PDF-Datei konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Verknüpfungsziel in Adobe PDF konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - c:\programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\dokume~1\***\ANWEND~1\Mozilla\Firefox\Profiles\69nj4pze.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - plugin: c:\dokumente und einstellungen\All Users\Anwendungsdaten\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\dokumente und einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\69nj4pze.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: d:\programme\plugins\npzylomgamesplayer.dll
---- FIREFOX Richtlinien ----
FF - user.js: yahoo.homepage.dontask - trued:\programme\greprefs\all.js - pref("media.enforce_same_site_origin", false);
d:\programme\greprefs\all.js - pref("media.cache_size", 51200);
d:\programme\greprefs\all.js - pref("media.ogg.enabled", true);
d:\programme\greprefs\all.js - pref("media.wave.enabled", true);
d:\programme\greprefs\all.js - pref("media.autoplay.enabled", true);
d:\programme\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
d:\programme\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
d:\programme\greprefs\all.js - pref("dom.storage.default_quota", 5120);
d:\programme\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
d:\programme\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
d:\programme\greprefs\all.js - pref("layout.css.dpi", -1);
d:\programme\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
d:\programme\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
d:\programme\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
d:\programme\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
d:\programme\greprefs\all.js - pref("geo.enabled", true);
d:\programme\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
d:\programme\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
d:\programme\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
d:\programme\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
d:\programme\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
d:\programme\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
d:\programme\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
d:\programme\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
d:\programme\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
d:\programme\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
d:\programme\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
d:\programme\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 11:10
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,c3,b1,95,56,c6,
a2,e2,f9,e2,63,26,f1,3f,c8,ff,68,6b,5e,a4,a7,0a,3c,80,3c,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,4f,eb,34,55,b9,
7f,7d,b1,6a,9c,d6,61,af,45,84,18,fb,a9,a3,77,0b,8f,73,9a,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,f1,af,23,23,ef,
12,f6,03,ff,7c,85,e0,43,d4,0e,fe,7d,4b,23,ce,2e,75,80,45,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,06,b9,1d,27,ba,
e6,ec,23,86,8c,21,01,be,91,eb,e7,57,8a,6c,6a,fc,6b,10,b9,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,c2,21,62,a5,24,
bb,9f,01,f5,1d,4d,73,a8,13,5c,05,8e,ed,ae,0b,d1,04,46,0f,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,d5,e0,68,f1,37,
21,d9,74,df,20,58,62,78,6b,cf,c8,85,28,6b,1f,c4,f5,44,35,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,1a,85,85,a0,56,
3e,6b,73,fb,a7,78,e6,12,2f,9a,ea,9a,4f,66,9b,36,2e,12,ec,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,4b,35,55,8c,ee,
06,29,4f,01,3a,48,fc,e8,04,4a,f1,82,b8,b2,cf,6a,e9,4c,23,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,e9,54,0f,c8,cb,
86,b9,c7,f6,0f,4e,58,98,5b,89,c9,1c,3a,97,02,97,12,b3,f4,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,33,60,58,16,0d,
87,56,6e,3d,ce,ea,26,2d,45,aa,78,48,b1,e9,55,ca,68,03,7a,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,73,ce,37,da,25,
dd,16,88,2a,b7,cc,b5,b9,7f,41,e7,2e,f9,25,9f,07,52,54,8c,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,9e,46,7f,3e,a0,
e1,0e,f6,6c,43,2d,1e,aa,22,2f,9c,f8,ec,80,28,83,d0,ef,e2,6c,43,2d,1e,aa,22,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2009-08-24 11:11
ComboFix-quarantined-files.txt 2009-08-24 09:11
Vor Suchlauf: 12 Verzeichnis(se), 436.881.760.256 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 436.882.034.688 Bytes frei
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
359 --- E O F --- 2009-08-24 05:58 Google funktioniert jetzt nach Combofix wieder ganz normal!!
Linda |