....وعليكم السلام ورحمة الله وبركاته أخي "اAl jNtEeL" وشكرًا جزيلًا لاهتمامك..
:
والشكر موصول للأخ فارس الملاك..فقد سعدت جدًا بسرعة مبادرته وقد استبشرت خيرًا أن مشكلتي ستحل عندكم..
المشكلة أني تسببت بنقل الفيروس لجهاز آخر وظهرت نفس المشكلة بعد فحص الكاسبر !!
:
:
وإليك أخي التقارير التي طلبت:
ComboFix 08-06-20.4 - xp 06/29/2008 23:36:58.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.86 [GMT 3:00]
Running from: C:\Documents and Settings\xp\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-29 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-29 20:43 7,015,712 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-29 20:42 301,600 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-29 16:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-29 16:39 94,340 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-29 16:39 29,036 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-26 13:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-26 13:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-22 05:44 524,288 ----a-w C:\WINDOWS\system32\drivers\CnxE2FS.bin
2008-06-21 07:47 --------- d-----w C:\Documents and Settings\xp\Application Data\U3
2008-06-17 10:59 --------- d-----w C:\Documents and Settings\Guest\Application Data\U3
2008-06-14 17:24 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-05 04:54 --------- d-----w C:\Program Files\iVocalize Web Conference 4
2008-06-03 03:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-29 17:28 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-28 15:47 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-28 15:47 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-27 13:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-05-20 04:17 --------- d-----w C:\Program Files\Zoom
2008-05-14 20:02 --------- d-----w C:\Documents and Settings\xp\Application Data\AdobeUM
2008-05-14 11:35 --------- d-----w C:\Program Files\Google
2008-05-13 18:11 --------- d-----w C:\Documents and Settings\xp\Application Data\Elluminate
2008-05-13 17:04 --------- d-----w C:\Program Files\MSN Messenger
2008-05-13 17:04 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-13 17:04 --------- d-----w C:\Program Files\Circle Developement
2008-05-13 16:23 --------- d-----w C:\Program Files\Admiresoft
2008-05-13 00:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 16:26 --------- d-----w C:\Program Files\Microsoft Works
2008-05-12 16:25 --------- d-----w C:\Program Files\MSBuild
2008-05-12 14:18 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-05-12 14:18 172,032 ------w C:\WINDOWS\Setup1.exe
2008-05-12 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-12 14:08 --------- d-----w C:\Program Files\Windows Live
2008-05-12 14:00 --------- d-----w C:\Program Files\Real
2008-05-12 14:00 --------- d-----w C:\Program Files\Common Files\xing shared
2008-05-12 13:59 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-12 13:59 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-12 13:59 --------- d-----w C:\Program Files\Common Files\Real
2008-05-12 13:49 --------- d-----w C:\Program Files\Sun
2008-05-12 13:48 --------- d-----w C:\Program Files\Java
2008-05-12 13:32 --------- d-----w C:\Program Files\Common Files\Java
2008-05-12 05:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2008-05-12 03:27 --------- d-----w C:\Program Files\Kaspersky Lab
2008-05-12 02:32 --------- d-----w C:\Program Files\Realtek AC97
2008-05-12 02:32 --------- d-----w C:\Program Files\AvRack
2008-05-12 02:30 --------- d-----w C:\Program Files\Intel
2008-05-12 02:30 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-12 01:33 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-05-12 00:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 10:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [07/01/2004 10:02 PM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [07/01/2004 09:58 PM 118784]
"SoundMan"="SOUNDMAN.EXE" [08/03/2006 03:12 PM 577536 C:\WINDOWS\soundman.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/12/2008 04:59 PM 185896]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 10:56 AM 15360]
C:\Documents and Settings\xp\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-26 16:32:56 113664]
«©م، ¢¬نïé Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [08/04/2004 01:31 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88622668-2ee8-11dd-9c7c-0000e870404b}]
\Shell\AutoRun\command - rgjkmy3p.exe
\Shell\explore\Command - rgjkmy3p.exe
\Shell\open\Command - rgjkmy3p.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce6d6cf1-2622-11dd-9c63-0000e870404b}]
\Shell\AutoRun\command - r.cmd
\Shell\explore\Command - r.cmd
\Shell\open\Command - r.cmd
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-29 23:42:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\PROCEXP90]
.
Completion time: 06/29/2008 23:46:05
ComboFix-quarantined-files.txt 2008-06-29 20:45:57
Pre-Run: 7,526,645,760 bytes free
Post-Run: 7,988,723,712 bytes free
134 --- E O F --- 2008-06-20 17:24:27