جزاكم الله خير
وهذا التقرير للاداءة الاولى
ComboFix 08-08-31.01 - alharbi1 09/02/2008 3:51:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.479 [GMT 3:00]
Running from: C:\Documents and Settings\B\Desktop\zyzoom-support\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\as.txt
C:\Documents and Settings\B\Application Data\inst.exe
C:\Documents and Settings\B\s\index.dat.del
C:\Documents and Settings\LocalService\s\index.dat.del
.
((((((((((((((((((((((((( Files Created from 2008-08-02 to 2008-09-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-02 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-02 00:59 614,432 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-02 00:59 5,276 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-02 00:59 3,189,792 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-02 00:59 28,096 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-01 03:52 --------- d-----w C:\Program Files\Common Files\delet
2008-09-01 03:52 --------- d-----w C:\Program Files\Common Files\bronz
2008-09-01 01:07 --------- d-----w C:\Program Files\LtUcx
2008-08-31 23:48 --------- d-----w C:\Program Files\Avira
2008-08-30 19:25 --------- d-----w C:\Program Files\Kelk 2000
2008-08-30 01:21 --------- d-----w C:\Documents and Settings\B\Application Data\Uniblue
2008-08-30 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-27 22:46 --------- d-----w C:\Documents and Settings\B\Application Data\Thinstall
2008-08-25 03:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-08-24 20:17 --------- d-----w C:\Program Files\MSXML 6.0
2008-08-24 20:16 --------- d-----w C:\Program Files\Nokia
2008-08-24 20:16 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-21 03:08 --------- d-----w C:\Program Files\zyzoom
2008-08-21 03:08 --------- d-----w C:\Program Files\Conduit
2008-08-16 15:34 --------- d-----w C:\Program Files\Dell
2008-08-12 14:15 --------- d-----w C:\Program Files\Anvsoft Flash to 3GP Converter
2008-08-11 21:04 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-10 01:26 --------- d-----w C:\Program Files\UltraISO
2008-08-10 01:26 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-08-07 12:27 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-04 03:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-08-01 02:26 --------- d-----w C:\Program Files\Nero
2008-08-01 01:49 2,368 ----a-w C:\WINDOWS\system32\SVKP.sys
2008-07-29 19:48 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-29 19:41 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-29 19:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-29 17:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-07-29 16:34 --------- d-----w C:\Program Files\SWiSHmax
2008-07-29 16:34 --------- d-----w C:\Program Files\Real_SC
2008-07-29 16:34 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-07-29 16:34 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-07-29 15:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2008-07-29 15:23 --------- d-----w C:\Program Files\Java
2008-07-29 12:43 --------- d-----w C:\Documents and Settings\B\Application Data\TeamViewer
2008-07-26 15:27 --------- d-----w C:\Documents and Settings\B\Application Data\cvzsa
2008-07-26 13:07 4,278,675 ----a-w C:\WINDOWS\java\Packages\F1NJJR5Z.ZIP
2008-07-26 13:04 --------- d-----w C:\Program Files\Google
2008-07-26 12:52 --------- d-----w C:\Documents and Settings\B\Application Data\cleaner
2008-07-26 12:30 5,749,698 ----a-w C:\WINDOWS\java\Packages\KUB93VX3.ZIP
2008-07-26 12:29 --------- d-----w C:\Program Files\Common Files\Real
2008-07-26 03:33 --------- d-----w C:\Documents and Settings\B\Application Data\Vso
2008-07-26 03:32 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-07-26 03:32 47,360 ----a-w C:\Documents and Settings\B\Application Data\pcouffin.sys
2008-07-24 07:36 --------- d-----w C:\Documents and Settings\B\Application Data\MixMeister Technology
2008-07-24 07:33 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-24 07:10 --------- d-----w C:\Documents and Settings\B\Application Data\Ahead
2008-07-22 00:15 --------- d-----w C:\Program Files\WMPBurn
2008-07-22 00:15 --------- d-----w C:\Program Files\Nero Wave Editor
2008-07-22 00:15 --------- d-----w C:\Program Files\Nero Toolkit
2008-07-22 00:15 --------- d-----w C:\Program Files\Nero StartSmart
2008-07-22 00:15 --------- d-----w C:\Program Files\Nero SoundTrax
2008-07-22 00:15 --------- d-----w C:\Program Files\Nero BackItUp
2008-07-22 00:15 --------- d-----w C:\Program Files\ImageDrive
2008-07-22 00:15 --------- d-----w C:\Program Files\CoverDesigner
2008-07-12 05:59 --------- d-----w C:\Documents and Settings\B\Application Data\DMCache
2008-01-09 15:07 440,842 ----a-w C:\Program Files\Common Files\wafi_msg.bmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{3aaa6ede-0f45-43da-8b81-608a1d8108a2}"= "C:\Program Files\zyzoom\tbzyz1.dll" [08/21/2008 06:08 AM 1569304]
[HKEY_CLASSES_ROOT\clsid\{3aaa6ede-0f45-43da-8b81-608a1d8108a2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{3aaa6ede-0f45-43da-8b81-608a1d8108a2}]
08/21/2008 06:08 AM 1569304 --a------ C:\Program Files\zyzoom\tbzyz1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3aaa6ede-0f45-43da-8b81-608a1d8108a2}"= "C:\Program Files\zyzoom\tbzyz1.dll" [08/21/2008 06:08 AM 1569304]
[HKEY_CLASSES_ROOT\clsid\{3aaa6ede-0f45-43da-8b81-608a1d8108a2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3AAA6EDE-0F45-43DA-8B81-608A1D8108A2}"= "C:\Program Files\zyzoom\tbzyz1.dll" [08/21/2008 06:08 AM 1569304]
[HKEY_CLASSES_ROOT\clsid\{3aaa6ede-0f45-43da-8b81-608a1d8108a2}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [01/26/2008 06:57 AM 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [01/26/2008 06:57 AM 1695232]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [06/26/2008 03:46 PM 171448]
"PC Suite Tray"="D:\Nokia PC Suite 6\PCSuite.exe" [11/09/2007 01:16 PM 688128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [12/13/2005 05:44 PM 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [12/13/2005 05:45 PM 118784]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [11/01/2006 12:48 PM 1392640]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/08/2006 12:48 PM 761947]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [08/03/2006 06:51 PM 1032192]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [02/23/2005 03:57 PM 57344]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/02/2004 08:24 PM 32768]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/26/2008 08:02 PM 185896]
"pdfFactory Pro Dispatcher v2"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [04/06/2006 09:40 AM 499712]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [06/12/2008 02:28 PM 266497]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"SigmatelSysTrayApp"="stsystra.exe" [03/24/2006 05:30 PM 282624 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [01/26/2008 06:57 AM 15360]
"Nokia.PCSync"="D:\Nokia PC Suite 6\PcSync2.exe" [11/07/2007 05:35 PM 1294336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [10/30/2007 03:36 PM 13801]
"TSClientAXDisabler"="C:\WINDOWS\Installer\TSClientMsiTrans\tscdsbl.bat" [01/18/2008 08:43 PM 2247]
C:\Documents and Settings\B\Start Menu\Programs\Startup\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 01:05:02 630784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-26 20:18:02 113664]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 11:11:48 6395464]
WinZip Quick Pick.lnk - E:\WZQKPICK.EXE [2008-02-08 11:10:00 394856]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R2 gearsec;gearsec;C:\WINDOWS\system32\gearsec.exe [12/02/2003 08:49 AM]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [08/01/2008 04:49 AM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKU-Default-RunOnce-nltide2 - rundll32 advpack.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyOverride = local
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 -: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
C:\WINDOWS\Downloaded Program Files\ewidoOnlineScan.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413} - hxxp://74.53.65.232/cp/files/talk3.cab
C:\WINDOWS\Downloaded Program Files\talk.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\Authenticatedll.dll
C:\WINDOWS\Downloaded Program Files\imcv1.dll
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_2_0_4_13.cab
C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf
.
.
------- File Associations (Beta) -------
.
txtfile=C:\WINDOWS\notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-02 04:06:27
Windows 5.1.2600 Service Pack 3, v.3300 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\apache\Apache.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\Crypserv.exe
D:\mysql\bin\mysqld-nt.exe
D:\apache\Apache.exe
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\TechSmith\SnagIt 8\TscHelp.exe
C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 09/02/2008 4:11:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-02 01:11:41
Pre-Run: 19,492,306,944 bytes free
Post-Run: 19,429,826,560 bytes free
231 --- E O F --- 2008-07-11 21:13:38