cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Report of ZHPDiag v2014.9.10.132 - Nicolas Coolman (9/10/2014)
~ Launched by Mo'ath (9/12/2014 10:42:14 AM)
~ Web site address : http://nicolascoolman.fr
~ Web forum address : http://forum.nicolascoolman.fr
~ Translated by
~ Version State : Updated version.
~ White List : Activate by program
~ Elevation of privilege : OK
~ User Account Control : Deactivate by user


---\\ Internet browsers
MSIE: Internet Explorer v11.0.9600.17239
GCIE: Google Chrome v37.0.2062.103 (Defaut)

---\\ Windows product information
~ Langage: Anglais
Windows 8.1 Pro, 64-bit (Build 9600)
Windows Server License Manager Script : OK
~ Windows(R) Operating System, VOLUME_KMSCLIENT channel
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System protection software
Malwarebytes Anti-Malware version 2.0.2.1012
Windows Defender W8 (Deactivate)

---\\ System optimization software

---\\ Sharing software PeerToPeer

---\\ Surveillance software

---\\ Information on the system
~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3994.4 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 232 GB (85%) free of 270 GB

---\\ Connection to the system mode
~ Computer Name: MOATH
~ User Name: Mo'ath
~ All Users Names: Mo'ath, Guest, Administrator,
~ Unselected Option: O45,O61
Logged in as Administrator

---\\ Environment variables
~ System Unit : C:\
~ %AppZHP% : C:\Users\Mo'ath\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Mo'ath\AppData\Roaming\
~ %Desktop% : C:\Users\Mo'ath\Desktop\
~ %Favorites% : C:\Users\Mo'ath\Favorites\
~ %LocalAppData% : C:\Users\Mo'ath\AppData\Local\
~ %StartMenu% : C:\Users\Mo'ath\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumeration of the disk units
C: Hard drive, Flash drive, Thumb drive (Free 232 Go of 270 Go)
D: Hard drive, Flash drive, Thumb drive (Free 182 Go of 195 Go)
G: CD-ROM drive (Not Inserted)



---\\ State of the Windows Security Center
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 40 Legitimates Filtered in 00mn AMs



---\\ Search Generic System Files
[MD5.4CE0C733CDCF1D2F78532BBD9CE3441D] - (.Microsoft Corporation - Windows Explorer.) (.2/22/2014 - 6:50:32 PM.) -- C:\Windows\Explorer.exe [2373784]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Windows Start-Up Application.) (.8/22/2013 - 12:58:29 PM.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.8E71A5CB5312B8392D4DA4CA37BB5868] - (.Microsoft Corporation - Internet Extensions for Win32.) (.7/25/2014 - 1:52:06 PM.) -- C:\Windows\System32\wininet.dll [2266624]
[MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Windows Logon Application.) (.2/22/2014 - 12:45:48 PM.) -- C:\Windows\System32\Winlogon.exe [562176]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Software Licensing Library.) (.12/21/2013 - 11:54:07 AM.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.5/30/2014 - 6:03:03 AM.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.8/22/2013 - 3:43:41 PM.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.8/22/2013 - 2:40:15 PM.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.8/22/2013 - 11:46:35 AM.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.414686EF104910BA41DF66E83BDCD495] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.1/16/2014 - 10:32:01 AM.) -- C:\Windows\system32\Drivers\DfsC.sys [134656]
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.8/22/2013 - 2:38:38 PM.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - i8042 Port Driver.) (.8/22/2013 - 2:39:15 PM.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.11/27/2013 - 3:02:29 PM.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
[MD5.16FFC07D36FD83ACA189A641385168B3] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.2/2/2014 - 3:19:07 PM.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402944]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.8/22/2013 - 2:37:02 PM.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.9AEB38B451A7B84ACB7CD3D664F87BF0] - (.Microsoft Corporation - NT File System Driver.) (.2/22/2014 - 6:44:11 PM.) -- C:\Windows\system32\Drivers\ntfs.sys [2013016]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Parallel Port Driver.) (.8/22/2013 - 2:40:02 PM.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.8/22/2013 - 2:35:51 PM.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.8/22/2013 - 10:11:17 PM.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.8/22/2013 - 4:25:35 PM.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.3595FBDF25F8BA6256072D103937D7D6] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.2/22/2014 - 6:44:13 PM.) -- C:\Windows\system32\Drivers\volsnap.sys [311640]
~ Generic Processes: Scanned in 00mn AMs



---\\ Hidden files state (Hidden/Total)
~ Mes images (My Pictures) : 1/1741
~ Mes Videos (My Videos) : 1/5
~ Mes Favoris (My Favorites) : 1/3
~ Mes Documents (My Documents) : 1/700
~ Mon Bureau (My Desktop) : 1/389
~ Menu demarrer (Programs) : 1/38
~ Hidden Files: Scanned in 02mn AMs



---\\ Process running
[MD5.4FBC630768570E6AC35C3DE8F6EC79F5] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [6970168] [PID.2252]
[MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.2484]
[MD5.87C93C18DDEF79BAE09EB12D1106B902] - (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe [514048] [PID.684]
[MD5.0706DDBD4EA0D122CA069FF2552E20FD] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808] [PID.4156]
[MD5.80B582A109C0E361408409183D18FDEB] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8102400] [PID.4788]
~ Processes Running: Scanned in 00mn AMs



---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2)
C:\Users\Mo'ath\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default][StartupURLs] http://google.jo/
G2 - GCE: Preference [User Data\Default] [eehpibjfkijipalplliffcgkhhmecjgi] ط¨ط·ظˆظ„ط§طھ ظƒط±ط© ط§ظ„ظ‚ط¯ظ… v.0.56 (Activé)
G2 - GCE: Preference [User Data\Default] [hlhbmnfdcklajeaeikfinieljfegamko] ط§ط®طھط¨ط§ط± ط³ط±ط¹ط© v.2.2 (Activé)
G2 - GCE: Preference [User Data\Default] [jpfbieopdmepaolggioebjmedmclkbap] Cache Killer v. ()
G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
G2 - GCE: Preference [User Data\Default] [nccllfnllopfpcbjdgjdlfmomnfgnnbk] MultiLogin v.0.1620 (Activé)
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pfpeapihoiogbcmdmnibeplnikfnhoge] Outlook.com v.1.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [pinjeagflheledfiihhbilplepebhhcn] Facebook Covers v.3.888 (Activé)

---\\ Google Chrome Extension Folder
~ Google Lines Browser: 28 Legitimates Filtered in 04mn AMs



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn AMs



---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn AMs



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn AMs



---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [Andy] . (...) -- C:\Program Files\Andy\HandyAndy.exe
O4 - HKCU\..\Run: [Mobile Partner] . (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Mo'ath\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Creative Cloud] . (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
O4 - HKLM\..\Wow6432Node\Run: [QHSafeTray] . (.Qihu Software Co. Limited - 360 Total Security.) -- C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe
O4 - HKUS\S-1-5-21-1780214637-3531778011-2012122408-1001\..\Run: [Mobile Partner] . (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe
O4 - HKUS\S-1-5-21-1780214637-3531778011-2012122408-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Mo'ath\AppData\Local\Facebook\Update\FacebookUpdate.exe
~ Application: Scanned in 00mn AMs



---\\ Lop.com/Domain Hijackers (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{D69BE18D-E5BE-4B77-A601-6B2AAAAF79B6}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CCS\Services\Tcpip\..\{E77ED4B4-E610-4B2E-8E07-EC4BB9BF2C1F}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5AC5FE7-7611-47DE-9489-39820C5595A7}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2E20604-E1D1-480B-A727-63C2AD8BC39D}: DhcpNameServer = 192.168.43.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{D69BE18D-E5BE-4B77-A601-6B2AAAAF79B6}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{E77ED4B4-E610-4B2E-8E07-EC4BB9BF2C1F}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{F5AC5FE7-7611-47DE-9489-39820C5595A7}: NameServer = 188.247.86.10 188.247.86.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{F2E20604-E1D1-480B-A727-63C2AD8BC39D}: DhcpNameServer = 192.168.43.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.43.1
~ Domain: Scanned in 00mn AMs



---\\ Extra protocols (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn AMs



---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23)
O23 - Service: HWDeviceService64.exe (HWDeviceService64.exe) . (.No owner - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService64.exe
O23 - Service: 360 Total Security (QHActiveDefense) . (.No owner - 360 Total Security.) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
O23 - Service: Zain Broadband. OUC (Zain Broadband. RunOuc) . (...) - C:\Program Files (x86)\Zain Broadband\UpdateDog\ouc.exe
~ Services: 13 Legitimates Filtered in 03mn AMs



---\\ Task Planned Automatically (039)
O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1780214637-3531778011-2012122408-1001Core [922]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1780214637-3531778011-2012122408-1001UA [944]
~ Scheduled Task: 11 Legitimates Filtered in 01mn AMs



---\\ Drivers launched at startup (O41)
O41 - Driver: (360Box64) . (.360.cn - 360Box64.) - C:\Windows\System32\DRIVERS\360Box64.sys
O41 - Driver: (360Camera) . (.360.cn - 360安全卫士 木马防火墙模块.) - C:\Windows\System32\Drivers\360Camera64.sys
O41 - Driver: (360FsFlt) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) - C:\Windows\System32\DRIVERS\360FsFlt.sys
O41 - Driver: (BAPIDRV) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) - C:\Windows\System32\DRIVERS\BAPIDRV64.sys
~ Drivers: 48 Legitimates Filtered in 00mn AMs



---\\ Software installed (O42)
O42 - Logiciel: ANDY OS - (.andyroid.net.) [HKLM][64Bits] -- ANDY OS
~ Logic: 25 Legitimates Filtered in 00mn AMs



---\\ HKCU & HKLM Software Keys
[HKCU\Software\360]
[HKCU\Software\AdsFix]
[HKCU\Software\Andy]
[HKCU\Software\Project07]
[HKLM\Software\AdsFix]
[HKLM\Software\Wow6432Node\360Safe]
[HKLM\Software\Wow6432Node\360TotalSecurity]
[HKLM\Software\Wow6432Node\360softmgr]
[HKLM\Software\Wow6432Node\AdsFix]
[HKLM\Software\Wow6432Node\ND]
[HKLM\Software\Wow6432Node\SOSVirus]
~ Key Software: 182 Legitimates Filtered in 00mn AMs



---\\ Contents of the Common Files folders (O43)
O43 - CFD: 9/4/2014 - 10:47:06 PM - [] ----D C:\Program Files (x86)\360
O43 - CFD: 8/11/2014 - 3:31:51 AM - [] ----D C:\Program Files (x86)\Remove Logo Now!
O43 - CFD: 8/6/2014 - 5:28:16 AM - [] ----D C:\Program Files (x86)\Zain Broadband
O43 - CFD: 9/12/2014 - 3:04:43 AM - [] ----D C:\ProgramData\360safe
O43 - CFD: 8/19/2014 - 8:02:29 PM - [] ----D C:\ProgramData\KMSAutoS =>Trojan.AutoKMS
O43 - CFD: 8/6/2014 - 5:28:16 AM - [] ----D C:\ProgramData\Zain Broadband
O43 - CFD: 9/12/2014 - 10:38:39 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\360safe
O43 - CFD: 8/20/2014 - 12:40:10 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\rmi
O43 - CFD: 9/8/2014 - 12:11:57 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy
~ Program Folder: 119 Legitimates Filtered in 00mn AMs



---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.09FA608B4845F4EB06A77636602800E5] - 9/12/2014 - 2:16:03 AM ---A- . (...) -- C:\AdsFix_12_09_2014_02_16_06.txt [30199]
O44 - LFC:[MD5.4D3CECDF094C65D999E6CFDF8DED2339] - 9/12/2014 - 3:03:50 AM ---A- . (...) -- C:\AdsFix_12_09_2014_03_03_51.txt [22015]
O44 - LFC:[MD5.A583F4DAAA4DB87BF92FD033966ABC4B] - 9/4/2014 - 10:47:30 PM ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
O44 - LFC:[MD5.15FE196A71357AC9FF6E5A4B360BDB20] - 9/4/2014 - 10:47:32 PM ---A- . (.360.cn - 360安全卫士 网络防黑模块.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
O44 - LFC:[MD5.D33811D3113C05B8485BF497B6CB50A9] - 9/4/2014 - 10:47:32 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) -- C:\Windows\System32\Drivers\BAPIDRV64.SYS [180816]
O44 - LFC:[MD5.D31541708A595BCA380105D44C2C2AD5] - 9/4/2014 - 10:47:33 PM ---A- . (.360.cn - 360安全卫士 木马防火墙模块.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
O44 - LFC:[MD5.3AA0D07082BF4B4EFF8BAE9F4EDF783B] - 9/4/2014 - 10:47:37 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
O44 - LFC:[MD5.0AABA03736666B85AC37C01467E89578] - 9/4/2014 - 10:47:48 PM ---A- . (.360.cn - 360杀毒 文件监控驱动.) -- C:\Windows\System32\Drivers\360AvFlt.sys [77896]
O44 - LFC:[MD5.1EE5F9F327D19074DA82B58D8252A749] - 9/4/2014 - 10:47:50 PM ---A- . (.360安全中心 - 360Efimon Driver.) -- C:\Windows\System32\Drivers\efimon.sys [23752]
~ Files: 82 Legitimates Filtered in 04mn AMs



---\\ Local Security Authority-LSA Deny (O48)
~ LSA: 3 Legitimates Filtered in 00mn AMs



---\\ MountPoints2 Shell Key (MPKS) (O51)
O51 - MPSK:{bad66ca3-1cf2-11e4-824c-806e6f6e6963}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{ccd4ac93-2868-11e4-8254-a02bb8210ac1}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.)
O51 - MPSK:{d8f965ce-1d10-11e4-824f-9cd21e1f66bd}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.)
O51 - MPSK:{f43a79bd-1d55-11e4-8251-001e101f9689}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.)
~ Keys: Scanned in 00mn AMs



---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn AMs



---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn AMs



---\\ System Drivers List (SDL) (O58)
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360安全卫士 网络防黑模块.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360杀毒 文件监控驱动.) -- C:\Windows\System32\Drivers\360AvFlt.sys [77896]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360安全卫士 木马防火墙模块.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) -- C:\Windows\System32\Drivers\BAPIDRV64.SYS [180816]
O58 - SDL:8/13/2013 - 2:25:46 AM ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360安全中心 - 360Efimon Driver.) -- C:\Windows\System32\Drivers\efimon.sys [23752]
O58 - SDL:8/6/2014 - 5:27:43 AM ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [32768]
O58 - SDL:6/9/2014 - 11:41:00 AM ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [180136]
O58 - SDL:8/6/2014 - 5:27:43 AM ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [1001472]
O58 - SDL:1/22/2014 - 6:52:10 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [108800]
O58 - SDL:1/22/2014 - 6:52:10 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [206080]
O58 - SDL:1/22/2014 - 6:52:12 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudserd.sys [206080]
O58 - SDL:8/22/2013 - 3:43:32 PM ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072]
O58 - SDL:8/13/2014 - 3:07:22 AM ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys [61584] =>PUP.LinkiDoo
O58 - SDL:7/31/2014 - 4:56:44 PM ---A- . (...) -- C:\Windows\SysWOW64\drivers\MoborobAssDriver64.sys [13304]
~ Drivers: 73 Legitimates Filtered in 04mn AMs



---\\ Alternate Data Stream File (ADS) (O62)
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\ig7icd32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igd10iumd32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdail32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdbcl32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdde32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdfcl32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdmd32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdrcl32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdumdim32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdusc32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfx11cmrt32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxcmjit32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxcmrt32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxexps32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\iglhcp32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\iglhsip32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\IntelCpHeciSvc.exe:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\IntelOpenCL32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\Intel_OpenCL_ICD32.dll:Zone.Identifier
O62 - ADS:Alternate Data Stream File - C:\Windows\System32\OpenCL.DLL:Zone.Identifier
~ ADS: Scanned in 01mn AMs



---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: UsbFix - (.El Desaparecido - www.usbfix.net - www.sosvirus.net.) [HKLM] -- Usbfix
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn AMs



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn AMs



---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn AMs



---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn AMs



---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.B67230A0FC91A977F9E398C609FEC10B] [SPRF][8/22/2014] (...) -- C:\Users\Mo'ath\AppData\Roaming\AndyCleanupTool.exe [1177208]
[MD5.8D05C7AF64CF79A366C1844C39A8FC1D] [SPRF][8/22/2014] (...) -- C:\Users\Mo'ath\AppData\Roaming\AndyCleanVM.exe [1176696]
[MD5.388DE0500C3375F3FC2B2D49A33AA58E] [SPRF][9/12/2014] (.No owner - AdsFix.) -- C:\Users\Mo'ath\Desktop\AdsFix.exe [2696192]
[MD5.E8F746CD86EFBCD5AB43F01A59CFE49D] [SPRF][10/8/2013] (.No owner - CPU temperature and system information utility.) -- C:\Users\Mo'ath\Desktop\Core Temp.exe [890016]
~ Files: 4 Legitimates Filtered in 00mn AMs



---\\ MyComputer Name Space (MNS) (O92)
O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE}
O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B}
O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}
O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C}
O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}
O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
~ MNS: 6 Legitimates Filtered in 00mn AMs



---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Auto 5/1/2014 402192 | (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe
SS - | Demand 5/23/2014 279024 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe
SS - | Demand 8/6/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 8/6/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 4/25/2012 169752 | (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
SS - | Demand 7/11/1658 0 | (IePluginServices) . (...) - C:\ProgramData\IePluginServices\PluginService.exe =>PUP.IePluginService
SS - | Demand 7/11/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SS - | Auto 8/6/2014 246112 | (Zain Broadband. RunOuc) . (...) - C:\Program Files (x86)\Zain Broadband\UpdateDog\ouc.exe
SR - | Auto 8/6/2014 98208 | (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
SR - | Auto 8/31/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 5/1/2014 385808 | (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
SR - | Auto 5/1/2014 774928 | (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
SR - | Auto 8/26/2014 78088 | (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
SR - | Auto 3/14/2011 346976 | (HWDeviceService64.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService64.exe
SR - | Auto 5/23/2014 282096 | (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe
SR - | Auto 5/12/2014 1809720 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 5/12/2014 860472 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 8/21/2014 707184 | (QHActiveDefense) . (...) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
SR - | Auto 8/6/2014 290520 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
SR - | Demand 7/11/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
SR - | Demand 7/11/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
SR - | Demand 8/22/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 07mn AMs



---\\ Search Master Boot Record Infection (MBR)(O80)
Run by Mo'ath at 9/12/2014 10:43:34 AM
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn AMs



---\\ Search Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Mo'ath at 9/12/2014 10:43:36 AM
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 02mn AMs



---\\ Scan Additionnel (O88)
Database Version : 13026 - (9/10/2014)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0

[HKLM\Software\Wow6432Node\360Safe] =>Trojan.Lozavita
C:\ProgramData\KMSAutoS =>Trojan.AutoKMS^
~ Additionnel Scan: 169590 Items scanned in 11mn AMs



---\\ Additional information about modules
~ http://nicolascoolman.fr/g0-page-de-demarrage-google-chrome/ =>.Google Chrome, Start,Search,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Start,Search,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.MountPoints2 Shell Key (MPKS) (O51)
~ AMI: 5 Legitimates Filtered in 00mn AMs



---\\ Summary of the detections found on your workstation
http://nicolascoolman.fr/trojan-autokms =>Trojan.AutoKMS
http://nicolascoolman.fr/pup-linkidoo =>PUP.LinkiDoo
http://nicolascoolman.fr/trojan-lozavita =>Trojan.Lozavita
~ MSI: 3 link(s) detected in 00mn AMs



~ 620 Legitimates filtered by white list
End of the scan (472 lines in 34mn AMs)(0)

Publicité


Signaler le contenu de ce document

Publicité