وهذا تقرير الكمبوفيكس:
ComboFix 08-07-15.4 - mmhabib 07/16/2008 19:19:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.79 [GMT -7:00]
Running from: C:\Documents and Settings\mmhabib\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-17 to 2008-07-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 02:23 6,944 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-17 02:23 1,171,488 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-17 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-16 19:34 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-16 19:34 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-16 19:33 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-16 19:33 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-16 19:32 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-16 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-09 22:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-09 10:38 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\LimeWire
2008-07-08 17:21 --------- d-----w C:\Program Files\Sun
2008-07-05 07:21 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\DivX
2008-07-05 07:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-24 21:35 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\skypePM
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 08:30 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\Talkback
2008-06-14 08:25 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-14 08:25 --------- d-----w C:\Program Files\Common Files\Real
2008-06-14 08:23 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 23:38 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\Yahoo!
2008-06-12 23:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-12 23:35 --------- d-----w C:\Program Files\Yahoo!
2008-05-29 22:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-29 22:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-17 04:16 --------- d-----w C:\Documents and Settings\mmhabib\Application Data\ArcSoft
2008-05-17 03:32 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 02:56 PM 15360]
"MsnMsgr"="C:\PROGRA~1\WINDOW~4\MESSEN~1\MsnMsgr.Exe" [10/18/2007 12:34 PM 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/12/2007 04:55 AM 68856]
"AFProg"="C:\Program Files\AnchorFree\bin\ctrl\AFController.exe" [11/20/2006 01:19 AM 81920]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [08/19/2005 07:34 PM 3084288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [04/17/2004 07:19 PM 1159168]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE" [03/23/2004 12:20 PM 147968]
"msnappau"="C:\Program Files\MSN Apps\Updater\
01.02.3000.1001\ar-xa\msnappau.exe" [08/13/2004 05:41 PM 86016]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/14/2008 01:23 AM 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 02:56 PM 15360]
C:\Documents and Settings\mmhabib\Start Menu\Programs\Startup\
Reboot.exe [2004-09-30 23:01:50 334336]
Thaker.lnk - C:\Program Files\êë ى ںé¨ںè©ïë\Thaker.exe [2007-08-02 08:01:01 1343488]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 08/19/2005 07:34 PM 3084288 C:\Program Files\Yahoo!\Messenger\YPager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\LimeWire\\LimeWire.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
R3 als4k;Avance Audio Miniport Driver (WDM);C:\WINDOWS\system32\drivers\als4000.sys [10/22/2001 01:46 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/07/2007 11:52 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50fcf91e-5229-11dd-acda-000e2eb11840}]
\Shell\AutoRun\command - F:\ino6.com
\Shell\explore\Command - F:\ino6.com
\Shell\open\Command - F:\ino6.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ea772a3-e714-11dc-abd6-000e2eb11840}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f375a6c1-e51e-11dc-abd2-000e2eb11840}]
\Shell\AutoRun\command - oufddh.exe
\Shell\explore\Command - oufddh.exe
\Shell\open\Command - oufddh.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-16 19:23:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 07/16/2008 19:26:52
ComboFix-quarantined-files.txt 2008-07-17 02:26:41
ComboFix2.txt 2008-07-17 02:01:32
ComboFix3.txt 2008-07-17 01:32:59
Pre-Run: 13,098,217,472 bytes free
Post-Run: 13,093,003,264 bytes free
119 --- E O F --- 2008-07-16 09:56:02