هذا تقرير ComboFix
ComboFix 08-11-10.01 - anas 11/11/2008 17:21:31.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.266 [GMT 2:00]
Running from: c:\documents and settings\anas\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 15:24 --------- d-----w c:\program files\microsoft frontpage
2008-11-11 15:23 557,056 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-11 15:23 11,756 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-11 15:23 1,568 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-11 15:23 1,220 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-11 12:26 --------- d-----w c:\program files\Flash Banner Creator
2008-11-11 12:20 --------- d-----w c:\program files\Pronunciation Power
2008-11-11 12:10 --------- d-----w c:\documents and settings\anas\Application Data\Media Player Classic
2008-11-11 12:03 --------- d-----w c:\program files\Microsoft.NET
2008-11-11 11:21 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-11-11 11:07 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-11-11 11:06 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-11 11:06 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-11 10:12 --------- d-----w c:\program files\Zend
2008-11-11 08:55 --------- d-----w c:\program files\Kaspersky Lab
2008-11-11 08:55 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-11 08:20 720,896 ----a-w c:\windows\iun6002.exe
2008-11-11 08:18 --------- d-----w c:\program files\Nero
2008-11-11 08:18 --------- d-----w c:\program files\Common Files\Nero
2008-11-11 08:18 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-11-11 08:16 --------- d-----w c:\program files\zyzoom_filters
2008-11-11 08:14 --------- d-----w c:\program files\QuickTime
2008-11-11 08:14 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-11 08:13 --------- d-----w c:\program files\3GP Player
2008-11-11 08:08 --------- d-----w c:\program files\Winamp
2008-11-11 08:08 --------- d-----w c:\documents and settings\anas\Application Data\Winamp
2008-11-11 08:07 --------- d-----w c:\program files\Common Files\xing shared
2008-11-11 07:53 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-11 07:53 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-11 07:53 --------- d-----w c:\program files\Real
2008-11-11 07:53 --------- d-----w c:\program files\Common Files\Real
2008-11-11 07:51 --------- d-----w c:\program files\YouTube Downloader
2008-11-11 07:48 --------- d-----w c:\program files\FlashGet
2008-11-11 07:45 --------- d-----w c:\program files\Products Flash & Media Capture
2008-11-11 07:45 --------- d-----w c:\program files\Common Files\Products
2008-11-11 07:42 --------- d-----w c:\program files\Java
2008-11-11 07:42 --------- d-----w c:\program files\Common Files\Java
2008-11-11 07:38 --------- d-----w c:\program files\Opera
2008-11-11 07:34 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-11 07:34 --------- d-----w c:\program files\ANI
2008-11-11 07:33 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-11 07:33 --------- d-----w c:\program files\D-Link
2008-11-11 07:33 --------- d-----w c:\documents and settings\anas\Application Data\InstallShield
2008-11-11 07:20 --------- d-----w c:\program files\mDSL
2008-11-11 07:20 --------- d-----w c:\documents and settings\anas\Application Data\ZTEEVDO
2008-11-11 07:12 --------- d-----w c:\program files\RocketDock
2008-11-11 07:11 --------- d-----w c:\program files\Company
2008-11-11 07:10 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-11 07:08 --------- d-----w c:\program files\Windows Live
2008-11-11 07:06 --------- d-----w c:\program files\K-Lite Codec Pack
.
------- Sigcheck -------
02/12/2008 02:25 PM 2163712 a8b6c84ca67197bd45a78d985fe0419e c:\windows\system32\ntkrnlpa.exe
02/12/2008 02:10 PM 2285056 88df50b01155178fae28cf0f95572a2d c:\windows\system32\ntoskrnl.exe
02/03/2008 08:51 PM 1840128 f0d1a9d147e3722c4636fbb74a76723e c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [01/26/2008 03:57 AM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [01/13/2007 03:47 AM 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [01/13/2007 03:47 AM 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [01/13/2007 03:46 AM 135168]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [01/19/2007 11:49 AM 49152]
"D-Link D-Link Wireless 108G DWA-520"="c:\program files\D-Link\D-Link Wireless 108G DWA-520\AirPlusCFG.exe" [05/04/2007 10:27 AM 1662976]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/11/2008 09:53 AM 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [01/31/2008 10:13 PM 385024]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [12/18/2007 12:43 AM 227856]
"Resume copy"="copyfstq.exe" [03/24/2002 01:54 PM 46080 c:\windows\COPYFSTQ.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [01/26/2008 03:57 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [08/13/2007 06:39 PM 123904 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RocketDock.lnk - c:\program files\RocketDock\RocketDock.exe [11/11/2008 9:12:02 AM 495616]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [11/11/2008 1:21:01 PM 389120]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\DRIVERS\A3AB.sys [10/16/2006 03:58 PM 472832]
R3 ev19x8mp;Creative SB AudioPCI Audio Driver (WDM);c:\windows\system32\drivers\ev19x8mp.sys [11/24/2000 08:10 PM 522268]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM 24592]
R3 zteusbser;ZTE USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\ZTEUsbser.sys [02/06/2007 10:21 AM 97920]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 -: Save &image with Flash and Media Capture - c:\program files\Common Files\Products\FMCapt.dll/saveimg.htm
O8 -: Save &media files with Flash and Media Capture - c:\program files\Common Files\Products\FMCapt.dll/savemedia.htm
O9 -: {F6F76DF4-FD65-4DE7-942F-4BD5DE9B1C6B} - {B3DA38C9-7C7B-4C32-8A65-8745B3B6085E} - c:\program files\Common Files\Products\FMCapt.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-11 17:25:02
Windows 5.1.2600 Service Pack 3, v.3300 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\explorer.exe
-> c:\program files\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\MSIEXEC.EXE
.
**************************************************************************
.
Completion time: 11/11/2008 17:28:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-11 15:28:10
Pre-Run: 15,468,052,480 bytes free
Post-Run: 15,465,676,800 bytes free
153