rogerg73 | 14.09.2008 13:01 | hier die combofix logfile Code:
ComboFix 08-09-13.05 - RXXXr 2008-09-14 13:45:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.570 [GMT 2:00]
Running from: C:\Documents and Settings\RXXXr\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\RXXXr\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-13 23:30 . 2008-09-13 23:30 318,369 --a------ C:\Program Files\HiJackThis.zip
2008-09-13 20:39 . 2008-09-13 20:39 2,849,424 -ra------ C:\Program Files\antispy-ComboFix.exe
2008-09-13 19:52 . 2008-09-13 19:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-13 19:52 . 2008-09-13 19:52 <DIR> d-------- C:\Documents and Settings\RXXXr\Application Data\Malwarebytes
2008-09-13 19:52 . 2008-09-13 19:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-13 19:52 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-13 19:52 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-13 19:51 . 2008-09-13 19:51 2,164,216 --a------ C:\Program Files\antispy-mbam-setup.exe
2008-09-13 19:17 . 2008-09-13 19:17 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-13 19:01 . 2008-09-13 19:01 <DIR> d-------- C:\Program Files\CCleaner
2008-09-13 19:01 . 2008-09-13 19:01 867,080 --a------ C:\Program Files\anitspy-ccsetup211_slim.exe
2008-09-13 18:12 . 2008-09-13 18:12 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-08-25 20:14 . 2008-08-25 20:14 <DIR> d-------- C:\Program Files\Movie Download Manager
2008-08-25 20:14 . 2005-12-03 23:54 873,472 --a------ C:\WINDOWS\system32\DCUninstall.exe
2008-08-25 20:06 . 2008-08-25 20:14 6,525,440 --a------ C:\Program Files\DCInstall.exe
2008-08-19 20:35 . 2008-08-19 20:35 <DIR> d-------- C:\Program Files\QuickTime
2008-08-19 20:35 . 2008-08-19 20:35 <DIR> d-------- C:\Program Files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 17:38 --------- d-----w C:\Program Files\Trend Micro
2008-09-13 17:12 --------- d-----w C:\Documents and Settings\RXXXr\Application Data\Yahoo!
2008-09-13 17:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-13 16:14 --------- d-----w C:\Program Files\Java
2008-08-29 21:57 --------- d-----w C:\Documents and Settings\RXXXr\Application Data\Skype
2008-08-21 18:57 --------- d-----w C:\Program Files\Trillian
2008-08-19 18:59 --------- d-----w C:\Program Files\DivX
2008-08-19 18:36 --------- d-----w C:\Program Files\iTunes
2008-08-19 18:36 --------- d-----w C:\Program Files\iPod
2008-08-19 11:03 --------- d-----w C:\Program Files\Opera
2008-07-29 18:10 23,816,192 ----a-w C:\Program Files\mysql-essential-5.0.51b-win32.msi
2008-07-29 18:10 --------- d-----w C:\Program Files\MySQL
2008-07-27 19:52 --------- d-----w C:\Documents and Settings\RXXXr\Application Data\Canon
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-20 09:24 --------- d-----w C:\Program Files\Zattoo
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 16:12 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 08:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 21:11 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 13:22 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-04 05:35 1,495,112 ----a-w C:\Program Files\install_flash_player.exe
2008-04-28 19:47 17,678,018 ----a-w C:\Program Files\Zattoo-3.1.1beta.exe
2008-02-05 21:00 35,397,592 ----a-w C:\Program Files\vaudtax.exe
2008-01-27 16:52 2,404,880 ----a-w C:\Program Files\WLinstaller.exe
2007-12-05 11:12 1,513,930 ----a-w C:\Program Files\webmediaplayer_setup.exe
2007-11-22 17:48 6,581,792 ----a-w C:\Program Files\sj540en.hqx
2007-10-24 19:12 28,868,320 ----a-w C:\Program Files\FileFormatConverters.exe
2007-08-19 13:09 7,886,336 ----a-w C:\Program Files\setup.msi
2007-08-18 16:45 24,048,424 ----a-w C:\Program Files\SkypeSetup.exe
2007-08-03 18:40 11,035,132 ----a-w C:\Program Files\WSFTP_ProT128_Install.exe
2007-07-05 19:36 795 ----a-w C:\Program Files\hefr-cert.zip
2007-04-22 11:12 1,024 ----a-w C:\Documents and Settings\All Users\Application Data\imgdoc2.dll
2007-04-22 11:08 3,420,605 ----a-w C:\Program Files\doc2img2_setup.exe
2007-03-17 20:05 11,027,270 ----a-w C:\Program Files\WSFTP_HomeT128_Install.exe
2007-01-09 21:59 324 ----a-w C:\Program Files\win424win.tac
2006-10-23 19:39 8,282,187 ----a-w C:\Program Files\vlc-0.8.4a-win32.exe
2006-10-22 19:14 1,304,184 ----a-w C:\Program Files\ppstreamsetup.exe
2006-09-29 19:09 3,870,719 ----a-w C:\Program Files\pcc.exe
2006-09-29 19:09 3,584 ----a-w C:\Program Files\1033.mst
2006-09-29 19:09 2,487,652 ----a-w C:\Program Files\tmpcc.msi
2006-09-29 18:31 244 ----a-w C:\Program Files\setup.ini
2006-09-27 21:27 91,361 ----a-w C:\Program Files\license.rtf
2006-09-27 17:16 7,383,552 ----a-w C:\Program Files\TMASOLDL.msi
2006-09-27 17:09 7,956,992 ----a-w C:\Program Files\TMASOEDL.msi
2006-08-25 14:53 36,155 ----a-w C:\Program Files\db_pcc.dat
2006-07-13 19:41 251 ----a-w C:\Program Files\wt3d.ini
2006-04-26 19:02 1,791 ----a-w C:\Program Files\XP2K_MskBkup.bat
2006-04-26 19:00 116,079 ----a-w C:\Program Files\isum_hotfix.exe
2006-04-17 20:31 3,034,728 ----a-w C:\Program Files\SFTPMSI.exe
2006-03-30 21:03 2,067,702 ----a-w C:\Program Files\fotolabo.exe
2006-02-08 19:33 375,848 ----a-w C:\Program Files\msgr7us.exe
2006-01-28 19:09 12,690,848 ----a-w C:\Program Files\RealPlayer10-5GOLD_bb.exe
2006-01-27 20:19 9,000,234 ----a-w C:\Program Files\trillian-v3.1.exe
2006-01-25 22:56 14,795,136 ----a-w C:\Program Files\DivXPlay.exe
2006-01-25 21:28 2,452,023 ----a-w C:\Program Files\Cdivx.exe
2006-01-25 21:09 1,014,477 ----a-w C:\Program Files\wrar351.exe
2006-01-25 20:22 3,843,584 ----a-w C:\Program Files\ow32enen851.exe
2006-01-13 09:33 64 ----a-w C:\Program Files\Tmsrl.dat
2008-04-07 19:01 104 --sh--r C:\WINDOWS\system32\82CD12A2EF.sys
2008-04-07 19:01 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-09-13_21.03.02.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-14 08:36:49 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_670.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-24 67128]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 67584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-13 136600]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 122880]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"CTHelper"="CTHELPER.EXE" [2005-09-20 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-11-11 C:\WINDOWS\system32\CTXFIHLP.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-09 110592]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-24 67128]
m-trip Launcher.lnk - C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe [2006-03-31 61440]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Zattoo\\Zattoo1.exe"=
"C:\\Program Files\\Zattoo\\zattood.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"18978:TCP"= 18978:TCP:NortonAV
"13110:TCP"= 13110:TCP:NortonAV
"16459:TCP"= 16459:TCP:NortonAV
"15122:TCP"= 15122:TCP:NortonAV
"15244:TCP"= 15244:TCP:NortonAV
"14519:TCP"= 14519:TCP:NortonAV
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-13 152984]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2005-09-20 1093632]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92fe8b94-6ccd-11db-9c90-00123f76be6a}]
\Shell\Auto\command - RavMon.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMon.exe e
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\RXXXr\Application Data\Mozilla\Firefox\Profiles\k8iujzhf.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-14 13:47:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
Completion time: 2008-09-14 13:50:14
ComboFix-quarantined-files.txt 2008-09-14 11:50:09
ComboFix2.txt 2008-09-13 19:03:26
Pre-Run: 213,302,710,272 bytes free
Post-Run: 213,274,230,784 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
229 --- E O F --- 2008-09-13 15:40:42 |