لاهنت ماكس .. التقرير :
ComboFix 09-06-20.02 - user 06/21/2009 3:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1270.861 [GMT 3:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\MicPhone
c:\windows\dhcp
c:\windows\system32\drivers\39fc7de8.sys
c:\windows\TEMP\mta81877.dll
c:\documents and settings\Administrator\Start Menu\Programs\Startup\userinit.exe
c:\documents and settings\Administrator\svchost.exe
c:\documents and settings\user\Application Data\wiaserva.log
c:\documents and settings\user\Application Data\wiaservg.log
c:\documents and settings\user\Start Menu\Programs\Startup\fmnupd32.exe
c:\documents and settings\user\Start Menu\Programs\Startup\zqosys32.exe
c:\program files\MicPhone\antit.dll
c:\program files\MicPhone\antit.exe
c:\windows\dhcp\svchost.exe
c:\windows\Install.txt
c:\windows\irc.txt
c:\windows\KBPK090606.log
c:\windows\KBPK090607.log
c:\windows\KBPK090609.log
c:\windows\KBPK090620.log
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\comsa32.sys
c:\windows\system32\dncyool32.sys
c:\windows\system32\FInstall.sys
c:\windows\system32\msncache.dll
c:\windows\system32\sndintd.sys
c:\windows\system32\sopidkc.exe
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\tpszxyd.sys
c:\windows\system32\wtukd32.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6to4
-------\Legacy_dhcpsrv
-------\Legacy_msncache
-------\Legacy_sndintd
-------\Legacy_sopidkc
-------\Service_39fc7de8
-------\Service_6to4
-------\Service_dhcpsrv
-------\Service_msncache
-------\Service_sndintd
-------\Service_sopidkc
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.
2009-06-20 18:46 . 2009-06-20 18:46 437760 ----a-w- c:\documents and settings\user\system.exe
2009-06-19 12:11 . 2004-08-03 21:56 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2009-06-19 12:11 . 2004-08-03 21:56 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-06-19 12:11 . 2004-08-03 20:07 59264 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-06-19 12:11 . 2004-08-03 20:07 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-06-19 12:11 . 2004-08-03 20:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-06-19 12:11 . 2004-08-03 20:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-06-16 09:34 . 2009-06-16 09:34 -------- d-----w- c:\program files\AxBx
2009-06-16 05:40 . 2008-02-27 10:15 28416 ----a-w- c:\windows\system32\uxtuneup.dll
2009-06-16 05:40 . 2009-06-16 05:40 307968 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-16 05:40 . 2009-06-16 05:40 -------- d-----w- c:\documents and settings\user\Application Data\TuneUp Software
2009-06-16 05:39 . 2009-06-16 05:39 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-06-16 05:39 . 2009-06-16 05:40 -------- d-----w- c:\program files\TuneUp Utilities 2008
2009-06-07 03:26 . 2008-01-21 15:12 41792 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-07 03:26 . 2008-01-21 15:11 22336 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-07 03:26 . 2008-03-04 10:28 79424 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-07 03:26 . 2009-06-07 03:26 -------- d-----w- c:\program files\Avira
2009-06-05 23:08 . 2009-06-06 02:27 -------- d-----w- c:\program files\Risk 2
2009-06-05 23:01 . 2009-06-08 03:23 -------- d-----w- c:\program files\Risk
2009-06-05 22:35 . 2009-06-05 22:35 20480 ----a-w- C:\yseoeenc.exe
2009-06-05 11:00 . 2009-06-05 11:00 -------- d-----w- c:\documents and settings\user\Application Data\iWin
2009-06-05 10:00 . 2009-06-05 10:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2009-06-05 09:55 . 2009-06-05 09:55 -------- d-----w- c:\program files\ReflexiveArcade
2009-06-05 01:17 . 2009-06-05 01:17 -------- d-----w- C:\Hotspot Shield
2009-06-02 11:07 . 2009-06-02 11:07 390664 ----a-w- c:\documents and settings\user\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 18:40 . 2009-02-09 17:50 -------- d-----w- c:\program files\QuickTime
2009-06-20 18:39 . 2009-02-10 23:38 -------- d-----w- c:\documents and settings\user\Application Data\BitTorrent
2009-06-07 16:42 . 2008-05-07 08:40 -------- d-----w- c:\documents and settings\user\Application Data\GigaTribe
2009-06-07 03:38 . 2009-02-09 17:40 -------- d-----w- c:\program files\Circle Developement
2009-06-07 03:26 . 2009-02-17 11:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-05 01:17 . 2009-02-11 10:33 -------- d-----w- c:\program files\Hotspot Shield
2009-06-01 18:13 . 2009-02-11 11:08 33840 ----a-w- c:\windows\system32\drivers\hssdrv.sys
2009-05-17 18:50 . 2009-05-17 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-04-17 13:14 . 2009-04-17 13:14 15240 ----a-w- c:\documents and settings\user\Application Data\Microsoft\IdentityCRL\PROD\ppcrlconfig.dll
1990-01-01 01:01 . 1990-01-01 01:01 53248 --sh--r- c:\windows\system32\wbem\HB32.dll
.
------- Sigcheck -------
[-] 2008-02-27 12:59 1580544 9F960FAC5166F8626B9CDE4DD9A0EB84 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-02-11 11:08 204248 ----a-w- c:\program files\Hotspot Shield\HssIE\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-09 5728112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-09 185896]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\user\Start Menu\Programs\Startup\
GigaTribe.lnk - c:\program files\GigaTribe\gigatribe.exe [2008-5-7 1071104]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDCB0AE8-833C-C1D2-29E1-2A8A1A35D25A}"= "c:\windows\system32\wbem\HB32.dll" [1990-01-01 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-21 18:42 40448 ----a-w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Ela-Salaty.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\Ela-Salaty.lnk
backup=c:\windows\pss\Ela-Salaty.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [7/31/2008 8:45 PM 20616]
R1 TMEI3E;TMEI3E;c:\windows\system32\drivers\TMEI3E.sys [2/9/2009 9:37 PM 5888]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [12/21/2005 9:55 PM 13568]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [12/21/2005 9:55 PM 33024]
R2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [6/1/2009 9:13 PM 331312]
R2 smihlp;SMI helper driver;c:\program files\Protector Suite QL\smihlp.sys [12/21/2005 9:25 PM 3456]
R2 Tmesrv;Tmesrv3;c:\program files\TOSHIBA\TME3\TMESRV31.exe [2/9/2009 9:37 PM 126976]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\hssdrv.sys [2/11/2009 2:08 PM 33840]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [6/10/2005 1:26 PM 35968]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [6/1/2009 9:58 PM 34352]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [7/2/2008 2:58 PM 26248]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-06-21 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 11:24]
2009-06-06 c:\windows\Tasks\ADE5E8D7918A9C17.job
- c:\docume~1\user\applic~1\bonede~1\THATBOOBMFCD.exe [2009-02-09 17:42]
2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:57]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-shv - c:\program files\MicPhone\antit.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-21 03:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1648)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\bio.dll
c:\program files\Protector Suite QL\remote.dll
- - - - - - - > 'lsass.exe'(1704)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus2.dll
- - - - - - - > 'explorer.exe'(180)
c:\windows\system32\wbem\HB32.dll
c:\program files\TOSHIBA\TME3\TMEEJMD.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\program files\TOSHIBA\TME3\TMEEJME.exe
c:\program files\Hotspot Shield\bin\openvpntray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-21 3:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-21 00:10
Pre-Run: 4,370,427,904 bytes free
Post-Run: 4,764,364,800 bytes free
222