Volledige versie bekijken : Defence center



Emtec
3 July 2010, 21:23
Al enkele weken last van een steeds terugkerende infectie. Het gaat om Defence center en ook al enkele vermeldingen van Vundo tegengekomen...

Internet explorer crasht bij het opstarten. MBAM kan enkel opstarten indien de exe hernoemd wordt naar iets random. Na een volledige scan vindt hij 3 registerwaarden, die hij zogezegd telkens succesvol kan verwijderen. Maar na een nieuwe scan blijven die 3 waarden terugkeren. Na enkele dagen komt de hele infectie terug.

Alvast vermelden dat het om een bedrijfslaptop gaat. De windowsversie en ie versie is hopeloos verouderd... maar daar kan ik zelf niets aan veranderen.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:05:07, on 3/07/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PrnWizSvc_serv.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.ex e
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Klbe\Bureaublad\hjt\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet.lafosse.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:1356
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [hgfcyysys] rundll32.exe "qopnon.dll",DllRegisterServer
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-299502267-1770027372-682003330-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Java 6u7.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://intranet.lafosse.com
O15 - Trusted Zone: http://aannemer.liander.nl (HKLM)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = officenet.lafosse.com
O17 - HKLM\Software\..\Telephony: DomainName = officenet.lafosse.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B5DABB4-D20F-40E5-BD2E-079082827E8A}: NameServer = 91.188.60.223,8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B6FD08C-2C54-4033-94E7-EF459F4A1A4F}: NameServer = 91.188.60.223,8.8.8.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = officenet.lafosse.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = officenet.lafosse.com
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: PrnWizSvc (PrnWizSvc_serv) - Everstrike Software - C:\WINDOWS\system32\PrnWizSvc_serv.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 7391 bytes


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Databaseversie: 4269

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

3/07/2010 20:58:16
mbam-log-2010-07-03 (20-58-16).txt

Scantype: Volledige scan (C:\|)
Objecten gescand: 204624
Verstreken tijd: 43 minuut/minuten, 13 seconde(n)

Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 0
Registersleutels geïnfecteerd: 0
Registerwaarden geïnfecteerd: 3
Registerdata geïnfecteerd: 0
Mappen geïnfecteerd: 0
Bestanden geïnfecteerd: 0

Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Registersleutels geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\hgfcyysys (Trojan.Vundo) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\Run\vttsqnsys (Trojan.Vundo) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\v ttsqnsys (Trojan.Vundo) -> No action taken.

Registerdata geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Mappen geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Bestanden geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)

Hopelijk kan ik het zelf oplossen zodat ik mijn laptop geen weken moet missen (nogal trage it)
Alvast bedankt!

Rosty
3 July 2010, 21:58
Download ComboFix van één van deze locaties:
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:
Klik hier (http://www.bleepingcomputer.com/forums/topic114351.html)
Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap. Dubbeklik op ComboFix.exe en volg de meldingen op het scherm. ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.
**Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware. Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.http://www.bleepstatic.com/combofix/nl/cf-rc-auto.jpg

Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:
http://www.bleepstatic.com/combofix/nl/rc-auto-done.jpg

Klik op Ja om verder te gaan met het scannen naar malware.

NOTE: Wanneer ComboFix start, kan het zijn dat je een Error melding krijgt dat de “contents of the ComboFix package has been compromised”
Ga niet verder met de instructies, maar download ComboFix opnieuw. Deze melding kan verschijnen wanneer een file-infector (Virut) actief is op de computer.

http://www.imgdumper.nl/uploads2/4ac516149f83c/4ac516149830d-ComboFix_Virut.jpg
Blijf je die melding krijgen dan meld je dit.
Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Emtec
4 July 2010, 11:08
Bedankt voor de snelle reactie
Ie start al terug op... McAfee kon ik niet uitschakelen omdat ik te beperkte rechten heb.

ComboFix 10-07-03.06 - Administrator 04/07/2010 10:44:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.31.1043.18.3319.1068 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Klbe\Bureaublad\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Aanwezig AV is actief
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Local Settings\Application Data\Windows Server
c:\documents and settings\Administrator\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Administrator\Local Settings\Application Data\Windows Server\uses32.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\feed.txt
c:\windows\system32\hlp.dat
c:\windows\system32\qopnon.dll
----- BITS: Mogelijk geïnfecteerde sites -----
hxxp://nlhe1027.officenet.Lafosse.com:80
c:\windows\system32\ws2_32.dll . . . is geïnfecteerd!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS

(((((((((((((((((((( Bestanden Gemaakt van 2010-06-04 to 2010-07-04 ))))))))))))))))))))))))))))))
.
2010-07-04 08:57 . 2010-07-04 08:57 53248 ----a-w- c:\temp\catchme.dll
2010-07-04 08:57 . 2010-07-04 08:57 -------- d-----w- c:\temp\nai5
2010-07-03 13:52 . 2010-07-03 13:52 -------- d-----w- c:\documents and settings\LocalService\Bureaublad
2010-07-03 13:36 . 2010-01-27 11:51 767952 ----a-w- c:\windows\BDTSupport.dll
2010-07-03 13:36 . 2010-01-22 06:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-07-03 13:36 . 2010-01-22 06:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-07-03 13:36 . 2010-01-22 06:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-07-03 13:36 . 2009-10-27 22:36 1152444 ----a-w- c:\windows\UDB.zip
2010-07-03 13:36 . 2008-11-26 09:08 131 ----a-w- c:\windows\IDB.zip
2010-07-03 13:31 . 2010-02-05 07:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-07-03 13:31 . 2010-03-29 08:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-07-03 13:31 . 2009-11-23 11:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-07-03 13:31 . 2010-04-08 12:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-07-03 13:31 . 2010-07-04 08:39 -------- d-----w- c:\program files\Spyware Doctor
2010-07-03 13:31 . 2010-07-03 13:36 -------- d-----w- c:\program files\Common Files\PC Tools
2010-07-03 13:31 . 2010-07-03 13:31 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-07-03 13:31 . 2010-07-03 13:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2010-07-03 13:31 . 2010-07-04 08:52 -------- d-----w- c:\temp\is-PBU9U.tmp
2010-07-03 13:27 . 2010-07-04 08:52 -------- d-----w- c:\temp\is-03CL8.tmp
2010-07-03 13:20 . 2010-07-04 08:52 -------- d-----w- c:\temp\is-ESENB.tmp
2010-07-03 12:43 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-03 12:43 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-30 07:29 . 2010-07-04 08:52 -------- d-----w- c:\temp\McAfeeLogs
2010-06-27 20:39 . 2010-06-27 20:39 -------- d-----w- c:\temp\TestEngDat64
2010-06-27 20:36 . 2010-07-04 08:52 -------- d-s---w- c:\temp\Cookies
2010-06-27 20:36 . 2010-06-27 20:36 -------- d-s---w- c:\temp\Temporary Internet Files
2010-06-27 20:36 . 2010-06-27 20:36 -------- d-s---w- c:\temp\Geschiedenis
2010-06-26 15:34 . 2010-07-04 08:52 -------- d-----w- c:\temp\1.tmp
2010-06-26 15:12 . 2010-07-04 08:52 -------- d-----w- c:\temp\54.tmp
2010-06-26 14:10 . 2010-07-03 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-26 09:35 . 2010-07-04 08:52 -------- d-----w- c:\temp\PCTInstaller
2010-06-26 09:35 . 2010-07-04 08:52 -------- d-----w- c:\temp\is-9OTNM.tmp
2010-06-26 09:20 . 2010-07-04 08:57 -------- d--h--r- c:\documents and settings\Administrator\Onlangs geopend
2010-06-16 21:56 . 2010-06-16 21:56 -------- d-sh--w- c:\documents and settings\All Users\Application Data\SMHGKLCGBIAV
2010-06-16 21:56 . 2010-06-26 09:27 -------- d-sh--w- c:\documents and settings\All Users\Application Data\3744e95
2010-06-13 14:53 . 2010-06-13 14:53 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Threat Expert
2010-06-13 14:24 . 2010-07-04 08:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-13 10:55 . 2010-06-26 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-13 10:49 . 2010-06-13 10:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-06-13 10:47 . 2010-06-13 10:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-13 05:58 . 2010-06-13 05:58 -------- d-----w- c:\windows\LastGood
2010-06-13 05:57 . 2007-11-13 10:25 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-06-13 05:56 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-06-13 05:56 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-06-13 05:56 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-06-13 05:56 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-06-13 05:56 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-06-13 05:56 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\Changer.sys
2010-06-13 05:54 . 2010-06-26 13:52 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\pofkpwwly
2010-06-13 05:50 . 2010-06-13 05:50 -------- d-s---w- c:\documents and settings\LocalService\UserData
2010-06-13 05:46 . 2010-06-13 14:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\6AE6C13F4454B6F31FF225F86DFE8F75
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2010-06-26 09:49 . 2008-09-09 12:33 5632 ----a-w- c:\windows\system32\drivers\intelide.sys
2010-06-13 14:11 . 2009-04-24 18:15 83032 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-13 05:57 . 2005-12-13 14:43 85630 ----a-w- c:\windows\system32\perfc013.dat
2010-06-13 05:57 . 2005-12-13 14:43 475444 ----a-w- c:\windows\system32\perfh013.dat
2010-04-29 21:18 . 2010-04-29 21:18 1956808 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdatea x.exe
.
------- Sigcheck -------
[-] 2004-08-04 . 9DD9A76DDAFE1CF6B5B146AF1BBF3DB1 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-04 . 341D8E2815747DB60CB4D654E508800C . 19968 . . [5.1.2600.2180] . . c:\windows\system32\ws2help.dll
[-] 2004-08-04 . 341D8E2815747DB60CB4D654E508800C . 19968 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ws2help.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-15 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 761946]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88203]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2008-07-17 136512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 144384]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-07-16 111952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
Java 6u7.lnk - c:\windows\Installer\{3248F0A8-6813-11D6-A77B-00B0D0160070}\Icon3248F0A8.vbs [2008-12-9 5120]
VPN Client.lnk - c:\windows\Installer\{6DC47739-3BB0-4494-A43D-193BF54070AE}\Icon3E5562ED7.ico [2008-9-9 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"MaxGPOScriptWait"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\win dows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logoff\0\0]
"Script"=Local PST backup v3.8.hta
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logon\0\0]
"Script"=PST to Local v1.8.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logon\1\0]
"Script"=User & Computer Inventory v2.3.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logon\2\0]
"Script"=login.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logon\3\0]
"Script"=UserMappingsBE v1.3.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-1275210071-764733703-839522115-347277\Scripts\Logon\4\0]
"Script"=PowerPointLafosse.vbs
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/07/2010 15:31 218592]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/07/2010 15:36 112592]
R2 PrnWizSvc_serv;PrnWizSvc;c:\windows\system32\PrnWi zSvc_serv.exe [10/04/2008 17:56 69632]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.s ys [7/02/2007 8:05 36352]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/07/2010 15:31 366840]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2004-08-04 12:00 100864 -c--a-w- c:\windows\system32\advpack.dll
.
Inhoud van de 'Gedeelde Taken' map
2010-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.be/
uInternet Settings,ProxyServer = http=127.0.0.1:1356
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: bolero.net\es
Trusted Zone: boleroserve.net\boleroconnect
Trusted Zone: boleroserve.net\boleroconnect.test
Trusted Zone: boleroserve.net\cert-management
Trusted Zone: boleroserve.net\cert-management.test
Trusted Zone: liander.nl\aannemer
TCP: {8B5DABB4-D20F-40E5-BD2E-079082827E8A} = 91.188.60.223,8.8.8.8
TCP: {8B6FD08C-2C54-4033-94E7-EF459F4A1A4F} = 91.188.60.223,8.8.8.8
.
- - - - ORPHANS VERWIJDERD - - - -
HKLM-Run-POINTER - point32.exe
HKLM-Run-opmjifsys - qopnon.dll
HKU-Default-Run-pmkllmsys - qopnon.dll
SafeBoot-klmdb.sys
AddRemove-HijackThis - E:\HijackThis.exe

************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-04 10:57
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
************************************************** ************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\ DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00, 72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00 ,5c,00,53,00,79,00,73,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Driver Signing]
@Denied: (2) (Administrators)
"Policy"=hex:00,00,00,00
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'lsass.exe'(936)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
- - - - - - - > 'explorer.exe'(2988)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\McAfee\Common Framework\McScript_InUse.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wscript.exe
c:\windows\system32\CCM\CLICOMP\RemCtrl\Wuser32.ex e
c:\windows\system32\CCM\CcmExec.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\sessmgr.exe
.
************************************************** ************************
.
Voltooingstijd: 2010-07-04 10:59:54 - machine werd herstart
ComboFix-quarantined-files.txt 2010-07-04 08:59
Pre-Run: 20.761.591.808 bytes beschikbaar
Post-Run: 20.800.114.688 bytes beschikbaar
WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /3GB /userva=2900 /noexecute=optin /fastdetect
- - End Of File - - 89C3337B5349E8D2DAFE247CFAAF29B2

Rosty
5 July 2010, 11:36
Hoi,

ga naar http://update.microsoft.com/windowsupdate/v6/default.aspx en download en instaleer SP3. Ook zou ik IE8 downloaden en instaleren! Na instalatie van SP3 de PC heropstarten, maak een nieuwe scan met ComboFix en post deze log hier voor mij.

Emtec
5 July 2010, 12:06
Updates worden beheerd door het bedrijf en zij verkiezen op dit moment blijkbaar sp2 en ie6... Maar ik denk toch dat ze er stilaan niet meer onderuit kunnen om deze bij te werken. Ik zal eens navraag doen hieromtrent.

Bedankt voor je hulp Rosty!