.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.stern.de/
uInternet Settings,ProxyServer = www-cache.fh-jena.de:8080
uInternet Settings,ProxyOverride = <local>;*.local
IE: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Auswahl in Adobe PDF konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Auswahl in vorhandene PDF-Datei konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: In vorhandene PDF-Datei konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Nach Microsoft &Excel exportieren - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Verknüpfungsziel in Adobe PDF konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - d:\programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\dokumente und einstellungen\Peter\Anwendungsdaten\Mozilla\Firefox\Profiles\kqvg1ln9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.wiwo.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programme\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: d:\programme\Adobe\Acrobat 7.0\Acrobat\browser\nppdf32.dll
FF - plugin: d:\programme\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: d:\programme\DivX\DivX Web Player\npdivx32.dll
FF - plugin: d:\programme\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: d:\programme\QuickTime\Plugins\npqtplugin7.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url]http://www.gmer.net[/url]
Rootkit scan 2009-02-28 17:24:12
Windows 5.1.2600 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RaidTool = c:\programme\VIA\RAID\raid_tool.exe??}@?
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
cd042efbbd7f7af1647644e76e06692b=hex:e2,63,26,f1,3f,c8,ff,68,a5,b9,75,32,b8,
db,04,fc,c8,28,51,af,b0,29,a3,98,b8,f5,ec,03,32,02,08,d1,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
bca643cdc5c2726b20d2ecedcc62c59b=hex:6a,9c,d6,61,af,45,84,18,e0,a7,83,6b,cb,
6d,35,e3,71,3b,04,66,8b,46,0d,96,ef,df,38,cd,98,25,12,0c,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
2c81e34222e8052573023a60d06dd016=hex:25,da,ec,7e,55,20,c9,26,c3,5c,2f,b4,36,
13,b4,6c,25,da,ec,7e,55,20,c9,26,af,d3,58,de,06,75,a2,8d,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
2582ae41fb52324423be06337561aa48=hex:86,8c,21,01,be,91,eb,e7,09,42,e6,36,90,
ba,28,89,3e,1e,9e,e0,57,5a,93,61,d3,c2,70,cd,81,fb,08,79,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
caaeda5fd7a9ed7697d9686d4b818472=hex:cd,44,cd,b9,a6,33,6c,cd,2e,49,92,ae,07,
fa,78,c2,cd,44,cd,b9,a6,33,6c,cd,89,79,5d,81,17,9d,bb,95,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
a4a1bcf2cc2b8bc3716b74b2b4522f5d=hex:df,20,58,62,78,6b,cf,c8,43,4a,d5,08,b4,
09,c8,39,b0,18,ed,a7,3f,8d,37,a4,6b,22,a6,12,50,7d,dc,30,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
4d370831d2c43cd13623e232fed27b7b=hex:31,77,e1,ba,b1,f8,68,02,cc,c2,af,8d,d0,
a5,76,f0,31,77,e1,ba,b1,f8,68,02,7c,e6,b9,47,46,07,ba,7f,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
1d68fe701cdea33e477eb204b76f993d=hex:83,6c,56,8b,a0,85,96,ab,1b,db,eb,dc,72,
d9,82,6b,83,6c,56,8b,a0,85,96,ab,4c,71,c7,db,fc,a2,83,60,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
1fac81b91d8e3c5aa4b0a51804d844a3=hex:f6,0f,4e,58,98,5b,89,c9,1a,cd,1e,94,9d,
ec,43,dd,51,fa,6e,91,28,9e,14,cc,fb,e7,07,6b,e2,1f,ee,44,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
f5f62a6129303efb32fbe080bb27835b=hex:b1,cd,45,5a,a8,c4,f8,b9,3a,d4,f9,a2,ef,
49,05,ba,b1,cd,45,5a,a8,c4,f8,b9,9b,a5,a1,29,25,07,29,bf,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
fd4e2e1a3940b94dceb5a6a021f2e3c6=hex:2a,b7,cc,b5,b9,7f,41,e7,7a,3e,fc,de,35,
61,78,67,e3,0e,66,d5,eb,bc,2f,6b,93,02,a0,1e,42,19,64,ea,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
ThreadingModel=Apartment
@=c:\\WINDOWS\\system32\\OLE32.DLL
8a8aec57dd6508a385616fbc86791ec2=hex:fa,ea,66,7f,d4,3b,6b,70,d4,c6,5d,16,10,
51,70,6b,fa,ea,66,7f,d4,3b,6b,70,b8,fd,5d,9c,1c,1d,4a,17,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
OODEFRAG08.00.00.01WORKSTATION=D77A9CCE8ABB38A3B5D2CAE31B286D84C1A0BAA6526304A6EABB5307F8C84A88751DF0231B749032DD9A230D3FB3F3DBD6FB7E5D1F35AD71D354759B051A7ED7233ACC6AA544A50E954497191787661940D8C569D3209A3F3DD13E41C97960170FE79814FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6675D575E7D6A3B9808A6171C11EC38DE3D5D575E7D6A3B9808B33FE5D3EF7B33CC1A242692C1B30D2FB3CF06EF56960D0271057369D1E020874E7A5E8A84489B6D631ADFF3CEEC61B608A07037889928880A04AB8878D3423BE6A92BB6E2BB80BE28F16C77A2419FD0BD104208561CC5FDF5AF619693A3147BFCF3F47DB7EDBFC8F038C3D243BB4520032D67C33F3FA543AD411241BBA8B5896F56E8F9D608F847A64D652C5C7C1580EC5F4D3DE8B64B708DC0BC27AEC98CD8069EB6B9B4C713AC1967519D3A36147F72DFE7BB9ACB7CCD568D64DF4D85BF8FE8F114BE6C00379BF98D8EB7D12F0EDDEDBC2E7C3F5945DB2D5C12749BECBB0AA5C7387EBA18D06DDF9DA57CB9C411119F5698AEE7D1754D98B14FE044A331D7AD6C6164828813ADC44825642D65EDC2AB6427F7C7379E07066A2D959166133D55FE4FCDC8E0F01F86111FD70A93BAD017EF5D6D37A218A446B33F78F5FE9AB0D7F2C60DB843A53469D2A73853E7544C50D6BF1E3241FDF38C101DE287D044DD539110661E65AC1713B8D958B18CD47A244BDB09D751AF7773D761217C50CE2446F478166C91C8230DC4D1FC6E41A256C7D1BD226CA9CEE67535AE743486BE97978DD04A3A277D68C6CAB2E3F7D85F0CD1C5F850D83044AC722625922E12DC7F909FEC23BF17152C917422BB633C797D3D5324F02762B965B07EEDA210A23558DE4126B75BE71DE725BCC825E5641D3F6A7DDA5489D01FE5D76435C4217E974F946059918FB3E4C69AF6D3B95AE13B1D9C99B93C519F2733F353A98650FE984AA43C662F82AA0429F0C576833F580D13FAD0E5647806C909F59800EFAD111160EBE7B1037C8C51258B236602397D895390A283F41A5242553259EFF7ED351BDA24CAA4F2ECB16B022FDADB288E9E70424D5F3F1176628EB96089B30D6A81973CF122AC57E503323C870F95DBA999C47A84AC46CAEF2CF28D1D760B8F9FA0ABB6597CB8801CFECC052233D4F89A62CBC86E854CAB9036F4DB6A3CBAD32F4D3F32423F3E2FE9B723C0F1125F4F127F0FAF243608AE039FE1E2AAD08AA3DD597DC97C20B59A4DD4E1074C46FEA0688C5CE3A66233C318164714A678C43C13ABD7CCB8AB9C6B688E7A25EC400124183A47CED9FD8DCEC260F8970C50BACE5D3C01BF0C41F1BF8035A31CF147B6064149260F83D3D8291CD30F47E8C4BFFE6D1872D870963CA900A9D39F5D727664
.
Zeit der Fertigstellung: 2009-02-28 17:26:09
ComboFix-quarantined-files.txt 2009-02-28 16:25:45
Vor Suchlauf: 231.084.032 Bytes frei
Nach Suchlauf: 761,008,128 Bytes frei
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=Microsoft Windows Recovery Console /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=Microsoft Windows XP Home Edition /noexecute=optin /fastdetect
259 --- E O F --- 2009-02-27 08:25:56