سأحاول انا ارفع لكم بعض من ملفات الفيرس وهذا تقريير رن سكانر
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : USER
Creation time : 4/12/2011 3:34:27 PM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 6.0.2900.2180
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 2
RunScanner Version : 2.0.0.50
User Language : Arabic (Saudi Arabia)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
* C:\WINDOWS\system32\alg.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
* C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
C:\Documents and Settings\All Users\Application Data\DatacardService\DCService.exe
C:\Program Files\Etisalat 3.5G USB Modem\Etisalat 3.5G USB Modem.exe
* C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
C:\Program Files\Alfa Programs\Alfa Autorun Killer 3.0\Alfa Autorun Killer 3.exe (Alfa Programs ®)
C:\Documents and Settings\XPPRESP3\hddd.exe
* C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
* C:\Program Files\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
* C:\WINDOWS\system32\PnkBstrA.exe
* C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
* C:\Zyzoom_Forum_Tools\zRunScanner.com (Runscanner.net)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
* C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
* C:\WINDOWS\explorer.exe (Microsoft Corporation)
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\smss.exe (Microsoft Corporation)
* C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
C:\Zyzoom_Forum_Tools\zyzoom.exe
Unrated items
-------------
002 C:\Program Files\Alfa Programs\Alfa Autorun Killer 3.0\Alfa Autorun Killer 3.exe (Alfa Programs ®)
002 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
002 C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
010 C:\Documents and Settings\All Users\Application Data\DatacardService\DCService.exe (DCService.exe)
010 C:\WINDOWS\System32\dmadmin.exe (Logical Disk Manager Administrative Service)
010 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Windows CardSpace)
011 C:\WINDOWS\system32\DRIVERS\secdrv.sys (Secdrv)
011 C:\WINDOWS\system32\DRIVERS\tcpip.sys (TCP/IP Protocol Driver)
038 c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\vcleaner.exe
052 C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (Sun Microsystems, Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
061 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll (Advanced Micro Devices, Inc.) {5E2121EE-0300-11D4-8D3B-444553540000}
061 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
061 C:\WINDOWS\system32\ShellExt\TTFExtNT.dll (Microsoft Corporation) {afc638f0-e8a4-11ce-9ade-00aa00a42d2e}
061 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
064 C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
069 C:\WINDOWS\system32\tbtmon.dll (TOSHIBA CORPORATION.)
104 C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93}
104 C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll (Sun Microsystems, Inc.) {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
104 C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll (Sun Microsystems, Inc.) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
105 Download all links with IDM : C:\Program Files\Internet Download Manager\IEGetAll.htm
105 Download FLV video content with IDM : C:\Program Files\Internet Download Manager\IEGetVL.htm
105 Download with IDM : C:\Program Files\Internet Download Manager\IEExt.htm
170 {7ffc5b7a-6449-11e0-9c42-c5fd8b6c19ef} : F:\AutoRun.exe
170 {7ffc5b7d-6449-11e0-9c42-f5e90efa5e94} : F:\AutoRun.exe
170 F : F:\AutoRun.exe
173 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
173 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\TosBtShell.dll (TOSHIBA) {6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1}
173 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
221 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\TosBtShell.dll (TOSHIBA) {6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1}
221 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
225 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 C:\WINDOWS\system32\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
227 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\TosBtShell.dll (TOSHIBA) {6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1}
227 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll (Advanced Micro Devices, Inc.) {5E2121EE-0300-11D4-8D3B-444553540000}
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
002 C:\WINDOWS\ghdrive32.exe
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 c:\windows\system32\DRIVERS\Rts516xIR.sys
011 c:\windows\system32\DRIVERS\RtsUCcid.sys
011 System32\Drivers\RtsUStor.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\ViaIde.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
061 deskpan.dll
063 aswBoot.exe
138 UnHackMe
167 C:\WINDOWS\ghdrive32.exe