هذه النتيجة أخي الكريم أبو ريما
وأشكرك على تفاعلك
ComboFix 09-04-21.A1 - user 04/21/2009 12:51.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.100 [GMT 3:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-03-21 to 2009-04-21 )))))))))))))))))))))))))))))))
.
2009-04-20 21:48 . 2009-04-20 21:48 -------- d-----w c:\documents and settings\user\DoctorWeb
2009-04-20 20:31 . 2009-02-06 17:22 2136064 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-20 20:31 . 2009-02-06 17:24 2180480 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-20 20:31 . 2009-02-06 16:49 2015744 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-20 20:31 . 2009-02-06 16:49 2057728 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-20 19:23 . 2008-10-24 11:10 453632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-20 18:45 . 2009-04-20 20:07 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-20 16:57 . 2009-04-20 16:57 -------- d-----w c:\documents and settings\user\Contacts
2009-04-20 16:57 . 2009-04-20 16:57 268 ---ha-w C:\sqmdata04.sqm
2009-04-20 16:57 . 2009-04-20 16:57 244 ---ha-w C:\sqmnoopt04.sqm
2009-04-20 16:47 . 2009-04-20 16:47 268 ---ha-w C:\sqmdata03.sqm
2009-04-20 16:47 . 2009-04-20 16:47 244 ---ha-w C:\sqmnoopt03.sqm
2009-04-19 20:19 . 2009-04-19 11:13 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-19 20:19 . 2009-04-19 11:13 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-19 20:18 . 2009-04-21 09:54 8224 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-19 20:18 . 2009-04-21 09:54 3616 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-19 20:18 . 2009-04-21 09:54 1108 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-19 20:18 . 2009-04-21 09:54 1108 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-19 20:18 . 2009-04-19 20:18 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-19 20:17 . 2009-04-19 20:17 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-19 20:15 . 2009-04-19 20:15 -------- d-----w C:\Intel
2009-04-19 20:15 . 2009-04-21 09:54 12 ----a-w c:\windows\bthservsdp.dat
2009-04-19 20:14 . 2009-04-19 20:14 -------- d-----w c:\documents and settings\user\Bluetooth Software
2009-04-19 20:13 . 2004-08-04 02:00 100992 ----a-w c:\windows\system32\drivers\bthpan.sys
2009-04-19 20:13 . 2004-08-04 02:00 100992 ----a-w c:\windows\system32\dllcache\bthpan.sys
2009-04-19 20:13 . 2004-08-04 02:00 59648 ----a-w c:\windows\system32\drivers\rfcomm.sys
2009-04-19 20:13 . 2004-08-04 02:00 59648 ----a-w c:\windows\system32\dllcache\rfcomm.sys
2009-04-19 20:13 . 2004-08-04 02:00 17024 ----a-w c:\windows\system32\drivers\BthEnum.sys
2009-04-19 20:13 . 2004-08-04 02:00 17024 ----a-w c:\windows\system32\dllcache\bthenum.sys
2009-04-19 20:12 . 2008-06-13 13:10 272128 ----a-w c:\windows\system32\drivers\bthport.sys
2009-04-19 20:12 . 2008-06-13 13:10 272128 ----a-w c:\windows\system32\dllcache\bthport.sys
2009-04-19 20:12 . 2004-08-04 02:00 18944 ----a-w c:\windows\system32\drivers\BTHUSB.SYS
2009-04-19 20:12 . 2004-08-04 02:00 18944 ----a-w c:\windows\system32\dllcache\bthusb.sys
2009-04-19 20:04 . 2001-07-05 16:19 164 ------w c:\windows\avrack.ini
2009-04-19 20:00 . 2009-04-19 20:00 34232 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-19 19:57 . 2009-04-19 19:57 -------- d-----w c:\windows\Downloaded Installations
2009-04-19 19:56 . 2005-03-23 07:01 245760 ----a-w c:\windows\system32\Check.exe
2009-04-19 19:56 . 2009-04-19 19:56 83 ----a-w c:\windows\LManager.UNI
2009-04-19 19:56 . 2004-12-09 09:04 5120 ----a-w c:\windows\system32\FILTRCOI.DLL
2009-04-19 19:56 . 2004-12-08 11:10 16896 ----a-w c:\windows\system32\drivers\DKbFltr.SYS
2009-04-19 19:56 . 2003-10-20 08:38 126976 ----a-w c:\windows\UNINST32.EXE
2009-04-19 19:55 . 2009-04-19 19:55 -------- d-----w C:\Acer
2009-04-19 19:55 . 2005-01-03 08:51 78208 ----a-w c:\windows\system32\drivers\epm-shd.sys
2009-04-19 19:55 . 2004-09-01 20:57 221258 ----a-w c:\windows\system32\Epm-Po.dll
2009-04-19 19:55 . 2004-07-19 10:10 4096 ----a-w c:\windows\system32\drivers\epm-psd.sys
2009-04-19 19:54 . 2009-04-19 20:10 6 ----a-w C:\ISACER.ID
2009-04-19 19:53 . 2005-01-23 03:30 163840 ----a-r c:\windows\system32\igfxres.dll
2009-04-19 15:41 . 2008-07-09 07:38 26488 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-19 15:41 . 2009-04-19 15:41 -------- d--h--w c:\windows\$hf_mig$
2009-04-19 15:24 . 2009-04-19 15:24 268 ---ha-w C:\sqmdata02.sqm
2009-04-19 15:24 . 2009-04-19 15:24 244 ---ha-w C:\sqmnoopt02.sqm
2009-04-19 15:13 . 2009-04-19 15:13 268 ---ha-w C:\sqmdata01.sqm
2009-04-19 15:13 . 2009-04-19 15:13 244 ---ha-w C:\sqmnoopt01.sqm
2009-04-19 12:37 . 2009-04-19 12:37 268 ---ha-w C:\sqmdata00.sqm
2009-04-19 12:37 . 2009-04-19 12:37 244 ---ha-w C:\sqmnoopt00.sqm
2009-04-19 12:01 . 2009-04-19 12:01 -------- d-----w c:\windows\system32\DRVSTORE
2009-04-19 11:45 . 2004-08-04 02:00 26496 ----a-w c:\windows\system32\dllcache\usbstor.sys
2009-04-19 09:47 . 2009-04-19 09:47 8192 ----a-w c:\windows\REGLOCS.OLD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 17:53 . 2005-03-16 16:10 76487 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-19 20:18 . 2009-04-19 20:18 -------- d-----w c:\program files\Kaspersky Lab
2009-04-19 20:09 . 2009-04-19 20:09 -------- d-----w c:\program files\WIDCOMM
2009-04-19 20:07 . 2009-04-19 20:07 -------- d-----w c:\program files\Broadcom
2009-04-19 19:56 . 2009-04-19 19:56 -------- d-----w c:\program files\acer
2009-04-19 19:56 . 2009-04-19 19:56 -------- d-----w c:\program files\Launch Manager
2009-04-19 12:01 . 2009-04-19 12:01 -------- d-----w c:\program files\MSN Messenger
2009-04-19 08:44 . 1979-12-31 21:00 4094 ----a-w c:\windows\CLEANUP.CMD
2009-03-21 14:18 . 1979-12-31 21:00 986112 ----a-w c:\windows\system32\dllcache\kernel32.dll
2009-03-06 14:44 . 1979-12-31 21:00 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-06 14:44 . 1979-12-31 21:00 283648 ----a-w c:\windows\system32\dllcache\pdh.dll
2009-03-02 23:52 . 1979-12-31 21:00 1495552 ----a-w c:\windows\system32\dllcache\shdocvw.dll
2009-02-19 09:58 . 2005-03-16 16:09 18432 ----a-w c:\windows\system32\dllcache\iedw.exe
2009-02-09 10:20 . 2005-03-16 16:08 473088 ----a-w c:\windows\system32\dllcache\fastprox.dll
2009-02-09 10:20 . 1979-12-31 21:00 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 1979-12-31 21:00 723456 ----a-w c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 10:20 . 1979-12-31 21:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:20 . 1979-12-31 21:00 714752 ----a-w c:\windows\system32\dllcache\ntdll.dll
2009-02-09 10:20 . 1979-12-31 21:00 616960 ----a-w c:\windows\system32\dllcache\advapi32.dll
2009-02-09 10:20 . 1979-12-31 21:00 616960 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:20 . 1979-12-31 21:00 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 1979-12-31 21:00 399360 ----a-w c:\windows\system32\dllcache\rpcss.dll
2009-02-09 10:20 . 2005-03-16 16:08 453120 ----a-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 10:19 . 1979-12-31 21:00 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 10:19 . 1979-12-31 21:00 1846272 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-06 17:24 . 1979-12-31 21:00 2180480 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 17:14 . 1979-12-31 21:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 17:14 . 1979-12-31 21:00 110592 ----a-w c:\windows\system32\dllcache\services.exe
2009-02-06 16:54 . 1979-12-31 21:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 16:54 . 1979-12-31 21:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 16:49 . 2004-08-03 19:59 2057728 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 16:39 . 2005-03-16 16:08 227840 ----a-w c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:08 . 1979-12-31 21:00 55808 ----a-w c:\windows\system32\secur32.dll
2009-02-03 20:08 . 1979-12-31 21:00 55808 ----a-w c:\windows\system32\dllcache\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-02-22 180224]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-02-22 2889216]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2005-03-14 466944]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-19 206088]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2004-12-01 77824]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-5-25 565309]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-20 33808]
S2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-07-19 4096]
S2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2005-01-03 78208]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fd8a7e8-2cd7-11de-90db-0012f03df5e2}]
\Shell\AutoplaY\COMmand - vamjgy.pif
\Shell\AutoRun\command - vamjgy.pif
\Shell\eXpLOre\CommAnd - vamjgy.pif
\Shell\oPeN\commanD - vamjgy.pif
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {B357F231-4378-425F-906F-0F95855F225F} = 195.226.228.72 195.226.228.74
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-21 12:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\acer\eManager\anbmServ.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\SYSTEM32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2009-04-21 12:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-21 09:58
Pre-Run: 14,365,671,424 bytes free
Post-Run: 14,374,141,952 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
186 --- E O F --- 2009-04-21 09:11