Hier nun nóchmals Combofix: Code:
ComboFix 08-06-10.5 - **** 2008-06-12 5:23:27.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.182 [GMT 2:00]
Running from: C:\Documents and Settings\****\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-12 to 2008-06-12 )))))))))))))))))))))))))))))))
.
2008-06-12 03:59 . 2008-06-12 03:59 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 03:59 . 2008-06-12 03:59 <DIR> d-------- C:\Documents and Settings\MELA\Application Data\Malwarebytes
2008-06-12 03:59 . 2008-06-12 03:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 03:59 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 03:59 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 01:38 . 2008-06-12 01:42 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-12 01:38 . 2008-06-12 01:42 <DIR> d-------- C:\Program Files\CCleaner
2008-06-11 18:18 . 2008-06-11 18:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-11 14:50 . 2008-04-14 13:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 12:17 . 2006-12-28 01:02 7,031 -ra------ C:\WINDOWS\instwcli.inf
2008-06-11 12:16 . 2007-01-26 01:00 74,752 --a------ C:\WINDOWS\system32\fwlanci.org
2008-06-11 10:30 . 2006-12-28 01:02 74,240 -ra------ C:\WINDOWS\system32\fwlanci.dll
2008-06-11 10:30 . 2006-12-28 01:02 4,352 -ra------ C:\WINDOWS\system32\drivers\avmeject.sys
2008-05-27 17:08 . 2008-05-27 17:08 <DIR> d-------- C:\Program Files\HSM Informatik AG
2008-05-21 17:43 . 2006-12-01 22:54 1,175,552 --a------ C:\WINDOWS\system32\msvcr80d.dll
2008-05-21 17:43 . 2005-09-22 23:28 1,097,728 --a------ C:\WINDOWS\system32\msvcp80.dll
2008-05-21 17:43 . 2006-12-01 22:54 1,036,288 --a------ C:\WINDOWS\system32\msvcp80d.dll
2008-05-21 17:43 . 2006-12-01 22:54 1,015,808 --a------ C:\WINDOWS\system32\msvcm80d.dll
2008-05-21 17:43 . 2005-09-22 23:26 822,784 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-05-21 17:43 . 2005-09-22 23:27 516,096 --a------ C:\WINDOWS\system32\msvcm80.dll
2008-05-16 21:09 . 2008-05-16 21:09 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-16 21:08 . 2008-05-16 21:08 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-16 20:28 . 2008-05-16 20:28 <DIR> d-------- C:\Documents and Settings\HSM\Application Data\1&1
2008-05-16 14:35 . 2004-09-15 17:20 61,440 -ra------ C:\WINDOWS\scrub2k.exe
2008-05-16 14:35 . 2004-09-15 18:18 83 -ra------ C:\WINDOWS\hpw1280k.ini
2008-05-16 14:34 . 2008-05-16 14:34 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-05-16 14:33 . 2008-05-16 14:33 103 --a------ C:\WINDOWS\system32\hptrace.ini
2008-05-16 14:32 . 2008-05-16 14:36 408,697 --a------ C:\WINDOWS\hpdj1280.his
2008-05-16 14:32 . 2008-05-16 14:36 17,091 --a------ C:\WINDOWS\hpdj1280.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-11 10:17 --------- d-----w C:\Program Files\avmwlanstick
2008-05-21 14:11 491,520 ----a-w C:\WINDOWS\ii4file.exe
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-22 20:19 --------- d-----w C:\Program Files\HSM
2008-04-14 11:01 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-12_ 2.03.18.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-11 23:58:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-12 03:08:34 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-06-11 23:58:50 214,890 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-06-12 03:12:43 214,890 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-04 00:16 401491]
"1&1 EasyLogin"="C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe" [2007-06-12 17:51 1313792]
"SoundMan"=" SOUNDMAN.EXE" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Tray"="C:\WINDOWS\system32\sistray.EXE" [2002-05-09 03:19 303104]
"SiSUSBRG"="C:\WINDOWS\sisUSBrg.exe" [2002-04-25 18:06 32768]
"untray"="C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe" [2005-06-14 12:44 97360]
"CSAV_CheckViruses"="C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe" [2005-06-14 12:44 56400]
"dvprpt"="C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe" [2005-06-14 12:44 68688]
"avtray"="C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe" [2005-06-14 12:44 52304]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-09-28 13:30 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-02 13:04 185896]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-24 20:50 262401]
"SMSTray"="D:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 09:23 132624]
"HPWS myPrintMileage Agent"="C:\Program Files\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe" [2004-10-31 05:47 102400]
"AVMWlanClient"="C:\Program Files\avmwlanstick\wlangui.exe" [2006-12-28 01:02 1454080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
C:\Documents and Settings\MELA\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= E:\Hunde\Homepage\lane\images\Lynn\Lynn8M1.jpg
FriendlyName=
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 17:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WcesMgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\Programme\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\muzapp.exe"=
"D:\\Program Files\\FileZilla\\FileZilla.exe"=
"E:\\HSM\\Programme\\FilePrint\\FilePrint\\FilePrint.exe"=
"C:\\Program Files\\avmwlanstick\\FRITZWLanMini.exe"=
"C:\\Program Files\\1&1\\1&1 EasyLogin\\EasyLogin.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3587:TCP"= 3587:TCP:Windows-Peer-zu-Peer-Gruppierung
"3540:UDP"= 3540:UDP:Peer Name Resolution-Protokoll (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-18 00:36]
R3 AVMWAN;AVM NDIS WAN CAPI Driver;C:\WINDOWS\system32\DRIVERS\avmwan.sys [2001-08-17 12:13]
R3 ENE;ENE;C:\WINDOWS\system32\DRIVERS\EMCR7SK.sys [2003-02-11 03:12]
R3 FWLANUSB;AVM FRITZ!WLAN;C:\WINDOWS\system32\DRIVERS\fwlanusb.sys [2006-12-28 01:02]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 15:28]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2002-11-04 09:39]
S3 avmeject;AVM Eject;C:\WINDOWS\system32\drivers\avmeject.sys [2006-12-28 01:02]
S3 fus2base;AVM ISDN-Controller FRITZ!Card USB v2.0;C:\WINDOWS\system32\DRIVERS\fus2base.sys [2001-08-17 12:15]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
S3 PRISM_USB;D-Link Air Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\PRISMUSB.sys [2003-10-02 16:47]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1d42b3e-a51a-11dc-88fa-000ea6367ac6}]
\Shell\AutoRun\command - G:\pushinst.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-12 05:24:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-12 5:26:07
ComboFix-quarantined-files.txt 2008-06-12 03:25:51
ComboFix2.txt 2008-06-12 03:21:54
ComboFix3.txt 2008-06-12 00:53:22
ComboFix4.txt 2008-06-12 00:04:33
Pre-Run: 7,783,100,416 bytes free
Post-Run: 7,770,931,200 bytes free
149 --- E O F --- 2008-06-11 15:44:52 Kann das hier die Urasche des ganzen sein: Code:
2008-05-16 14:35 . 2004-09-15 17:20 61,440 -ra------ C:\WINDOWS\scrub2k.exe danach kamen dann diese Aktionen, die ich nicht nachvollziehen kann: Code:
2008-05-16 21:09 . 2008-05-16 21:09 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-16 21:08 . 2008-05-16 21:08 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-16 20:28 . 2008-05-16 20:28 <DIR> d-------- C:\Documents and Settings\HSM\Application Data\1&1 und dann hier: Code:
2008-06-11 14:50 . 2008-04-14 13:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 12:17 . 2006-12-28 01:02 7,031 -ra------ C:\WINDOWS\instwcli.inf
2008-06-11 12:16 . 2007-01-26 01:00 74,752 --a------ C:\WINDOWS\system32\fwlanci.org
2008-06-11 10:30 . 2006-12-28 01:02 74,240 -ra------ C:\WINDOWS\system32\fwlanci.dll hmmmmm..... was nun als nächstes?
LG
Ness |