ان شاء المولى اخي
وهاي التقرير من الاداة الاخرى اخي عبودي
ComboFix 08-09-24.09 - AHMED 09/25/2008 12:43:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.1707 [GMT 2:00]
Running from: C:\Documents and Settings\AHMED\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 10:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-25 10:31 17,408 ----a-w C:\WINDOWS\system32\drivers\pxark.sys
2008-09-25 10:31 --------- d-----w C:\Program Files\PrevxCSI
2008-09-25 10:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-25 10:08 --------- d-----w C:\Program Files\Realtek
2008-09-25 10:05 --------- d-----w C:\Program Files\Conexant
2008-09-25 10:04 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-25 09:51 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-25 09:47 --------- d-----w C:\Program Files\Windows Media Connect 2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 01:41 AM 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 01:41 AM 81920]
"DSLSTATEXE"="C:\Program Files\Conexant\Adsl\dslstat.exe" [02/28/2005 01:47 PM 450560]
"DSLAGENTEXE"="C:\Program Files\Conexant\Adsl\dslagent.exe" [02/28/2005 01:45 PM 159744]
"nwiz"="nwiz.exe" [12/05/2007 01:41 AM 1699840 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\AHMED\\Desktop\\Avast.Pro.v4.8.1169.Incl.Keymaker.Working-CORE\\setupengpro.exe"=
"C:\\Program Files\\Conexant\\Adsl\\dslstat.exe"=
"C:\\WINDOWS\\system32\\nwiz.exe"=
"C:\\WINDOWS\\system32\\userinit.exe"=
"C:\\Program Files\\PrevxCSI\\prevxcsi.exe"=
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [09/25/2008 12:31 PM 17408]
R2 CSIScanner;CSIScanner;C:\Program Files\PrevxCSI\prevxcsi.exe [09/25/2008 12:31 PM 618040]
R3 RTSTOR;USB Mass Stroage Device;C:\WINDOWS\system32\drivers\RTSTOR.SYS [08/31/2007 06:02 PM 41728]
*Newly Created Service* - ASC3360PR
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\AHMED\Application Data\Mozilla\Firefox\Profiles\o1zpuj7v.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-25 12:46:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3360pr]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\kfsnr.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 09/25/2008 12:47:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 10:47:40
Pre-Run: 16,072,458,240 bytes free
Post-Run: 16,022,470,656 bytes free
90