ComboFix 08-09-30.03 - Administrator 10/01/2008 10:16:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1585 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
G:\autorun.inf
G:\hibx.pif
.
((((((((((((((((((((((((( Files Created from 2008-09-01 to 2008-10-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-01 09:17 995,360 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-01 09:17 14,880 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-01 09:17 105,437 ----a-w C:\Documents and Settings\Administrator\catchme.zip
2008-10-01 08:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-01 08:52 --------- d-----w C:\Program Files\Ventrilo
2008-10-01 08:52 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-01 08:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-10-01 08:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-10-01 08:24 --------- d-----w C:\Program Files\Avira
2008-10-01 08:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-10-01 07:51 75,932 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-01 07:51 74,396 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-01 07:50 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-01 07:50 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-01 07:50 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-01 07:09 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-10-01 06:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-01 05:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ventrilo
2008-10-01 05:56 --------- d-----w C:\Program Files\Realtek
2008-10-01 05:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-10-01 05:54 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-01 05:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ESET
2008-10-01 05:51 --------- d-----w C:\Program Files\Intel
2008-10-01 05:51 --------- d-----w C:\Program Files\GIGABYTE
2008-10-01 05:51 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-01 05:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-10-01 05:45 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [06/28/2007 05:43 PM 8466432]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [06/28/2007 05:43 PM 81920]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [02/12/2008 10:06 AM 262401]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6809136]
"RTHDCPL"="RTHDCPL.EXE" [09/19/2007 11:14 AM 16844800 C:\WINDOWS\RTHDCPL.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\userinit.exe"=
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqrjf.exe"=
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windoqo.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [06/05/2008 01:25 PM 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [04/09/2008 03:57 PM 254209]
R3 abp470n5;abp470n5;C:\WINDOWS\system32\drivers\jjlhgr.sys [ ]
S2 AVEService;Avira AntiVir Premium MailGuard helper service;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [02/07/2008 10:06 AM 41217]
S3 GEST Service;GEST Service for program management.;C:\Program Files\GIGABYTE\GEST\GSvr.exe [12/14/2007 11:46 AM 47624]
*Newly Created Service* - AVGASCLN
*Newly Created Service* - KL1
*Newly Created Service* - SSMDRV
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-nodenable - C:\Program Files\eset\nodenable.exe
HKLM-Run-GEST - C:\Program Files\GIGABYTE\GEST\RUN.exe
HKLM-Run-JMB36X IDE Setup - C:\WINDOWS\RaidTool\xInsIDE.exe
HKLM-Run-36X Raid Configurer - C:\WINDOWS\system32\xRaidSetup.exe
HKLM-Run-RRT-Auto - C:\Documents and Settings\Administrator\سطح المكتب\RRT.exe
HKLM-Run-nwiz - nwiz.exe
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.progms.net/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-01 10:20:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\winqrjf.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\yumtfi.exe
.
**************************************************************************
.
Completion time: 10/01/2008 10:24:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-01 09:24:03
Pre-Run: 50,082,181,120 bytes free
Post-Run: 50,033,713,152 bytes free
130