ComboFix 08-02-25.3 - aadil8 2008-02-26 22:13:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223 [GMT 5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\infopsvEV67s.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-24 01:03 . 2008-02-24 01:03 d——– C:\Documents and Settings\aadil8\Application Data\Nokia Multimedia Player
2008-02-24 00:50 . 2008-02-24 00:51 11 –a—— C:\trace.ini
2008-02-23 14:15 . 2008-02-26 22:09 335 –a—— C:\WINDOWS\system32\vsconfig.xml
2008-02-22 20:05 . 2008-02-22 20:05 536 –a—— C:\WINDOWS\system32\wbrifkpc.rif
2008-02-22 07:36 . 2008-02-22 08:40 4,608 –a—— C:\WINDOWS\system32temp2.exe
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\aadil8\Application Data\Grisoft
2008-02-21 21:31 . 2007-05-30 17:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-20 14:24 . 2008-02-20 14:24 d——– C:\WINDOWS\ERUNT
2008-02-20 14:17 . 2008-02-20 14:31 d——– C:\SDFix
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBRC.dat
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBFC.dat
2008-02-19 15:57 . 2008-02-19 15:57 d——– C:\Documents and Settings\aadil8\Application Data\Sunbelt Software
2008-02-18 21:29 . 2008-02-18 21:29 d——– C:\Program Files\Belarc
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\PCSuite
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\Nokia
2008-02-18 13:50 . 2008-02-18 13:50 d——– C:\Program Files\Zone Labs
2008-02-18 12:32 . 2008-02-23 23:08 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2008-02-18 12:31 . 2008-02-26 22:10 d——– C:\WINDOWS\Internet Logs
2008-02-18 06:12 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2008-02-16 14:25 . 2008-02-19 16:46 d——– C:\Program Files\Spyware Doctor
2008-02-16 14:12 . 2008-02-16 14:12 d——– C:\Program Files\Lavasoft
2008-02-14 14:10 . 2008-02-14 14:10 4,709 –a—— C:\Pakistani+JF17.jpg
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Program Files\ACD Systems
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-02-13 09:18 . 2008-02-13 09:18 d——– C:\Program Files\Auralog
2008-02-13 09:18 . 2008-02-22 08:57 d–hs—- C:\Documents and Settings\aadil8\Recycled
2008-02-13 09:18 . 1998-09-02 13:02 194,320 –a—— C:\WINDOWS\system32\qcut.dll
2008-02-13 09:18 . 1998-08-27 09:51 182,032 –a—— C:\WINDOWS\system32\dxtmsft3.dll
2008-02-13 09:18 . 1998-08-20 16:02 140,800 –a—— C:\WINDOWS\system32\tm20dec.ax
2008-02-13 09:18 . 1998-09-02 13:28 63,488 –a—— C:\WINDOWS\system32\unam4ie.exe
2008-02-13 09:18 . 1998-09-02 13:28 38,160 –a—— C:\WINDOWS\system32\LMRTREND.dll
2008-02-13 09:18 . 1998-08-17 14:21 11,776 –a—— C:\WINDOWS\system32\mciqtz.drv
2008-02-13 09:18 . 1998-08-17 14:21 10,240 –a—— C:\WINDOWS\system32\vidx16.dll
2008-02-13 09:18 . 1998-08-17 14:21 5,672 –a—— C:\WINDOWS\system32\quartz.vxd
2008-02-13 09:18 . 2008-02-13 09:18 4,608 –a—— C:\WINDOWS\system32\w95inf32.dll
2008-02-13 09:18 . 2008-02-13 09:18 2,272 –a—— C:\WINDOWS\system32\w95inf16.dll
2008-02-05 02:12 . 2008-02-05 02:55 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-02-05 01:39 . 2008-02-05 01:39 d——– C:\Program Files\KARI2
2008-02-05 01:39 . 2008-02-05 01:39 172,489 –a—— C:\WINDOWS\KARI2 Uninstaller.exe
2008-02-04 23:24 . 2008-02-04 23:24 d——– C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-04 23:22 . 2008-02-04 23:22 d——– C:\Program Files\Common Files\LightScribe
2008-02-04 23:21 . 2008-02-04 23:27 d——– C:\Documents and Settings\aadil8\Application Data\Ahead
2008-02-04 23:14 . 2008-02-05 07:49 d——– C:\Program Files\Common Files\Ahead
2008-02-04 06:35 . 2008-02-10 06:00 d——– C:\Program Files\Dvd-cloner
2008-02-03 01:55 . 2008-02-03 01:55 d——– C:\Program Files\Windows Media Connect 2
2008-02-03 01:53 . 2008-02-03 01:53 d——– C:\WINDOWS\system32\LogFiles
2008-02-03 01:53 . 2008-02-18 23:32 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-03 01:53 . 2006-09-16 03:02 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-02-01 01:56 . 2008-02-01 01:56 d——– C:\Documents and Settings\aadil8\Application Data\CyberLink
2008-02-01 01:48 . 2008-02-01 01:48 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-02-01 01:47 . 2008-02-01 01:48 d——– C:\Program Files\CyberLink
2008-01-31 18:41 . 2008-01-31 18:42 d——– C:\F-16 Multi Role Fighter
2008-01-31 03:10 . 2008-01-31 03:11 d——– C:\Program Files\K-Lite Codec Pack
2008-01-31 03:10 . 2007-12-04 02:33 682,496 –a—— C:\WINDOWS\system32\divx.dll
2008-01-31 03:10 . 2007-12-24 13:49 7,680 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-01-31 03:10 . 2007-07-10 17:10 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-01-29 18:24 . 2008-01-29 18:24 172 –a—— C:\WINDOWS\pdf2word.INI
2008-01-27 05:18 . 2008-01-27 05:18 d——– C:\Program Files\MyNotesKeeper
2008-01-27 05:18 . 2008-01-27 05:19 d——– C:\Documents and Settings\aadil8\Application Data\MyNotesKeeper
2008-01-26 02:45 . 2008-01-26 02:45 d——– C:\Program Files\PC Connectivity Solution
2008-01-26 02:44 . 2007-02-22 10:15 137,216 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2008-01-26 02:44 . 2007-02-22 10:15 65,536 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-01-26 02:44 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-01-26 02:44 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-01-26 02:44 . 2007-02-22 10:15 8,320 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 09:05 ——— d—–w C:\Program Files\Opera
2008-02-19 10:42 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-18 12:11 ——— d—–w C:\Program Files\Nokia
2008-02-18 08:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-14 08:44 10,368 —-a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-02-14 08:44 ——— d—–w C:\Program Files\Common Files\ACD Systems
2008-02-07 23:24 ——— d—–w C:\Program Files\ESET
2008-02-05 02:56 ——— d—–w C:\Program Files\Oxford
2008-02-04 23:53 ——— d—–w C:\Program Files\Video Snapshots Genius
2008-02-02 22:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-01-31 20:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-29 03:18 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Babylon
2008-01-26 23:31 ——— d—–r C:\Program Files\TypingMaster
2008-01-25 21:48 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Nokia
2008-01-25 21:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-01-25 01:46 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Winamp
2008-01-25 01:42 ——— d—–w C:\Program Files\Winamp
2008-01-22 22:15 ——— d—–w C:\Program Files\Text to Speech Maker
2008-01-22 22:05 ——— d—–w C:\Program Files\2nd Speech Center
2008-01-19 16:57 ——— d—–w C:\Documents and Settings\aadil8\Application Data\PC Suite
2008-01-17 22:48 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-15 21:27 ——— d–h–r C:\Documents and Settings\aadil8\Application Data\SecuROM
2008-01-15 21:26 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-09 02:03 ——— d—–w C:\Documents and Settings\aadil8\Application Data\uTorrent
2008-01-07 11:48 ——— d—–w C:\Program Files\Total Video Converter
2008-01-01 15:53 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-01 15:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-31 23:43 ——— d—–w C:\Program Files\NCT
2007-12-22 07:21 339,328 —-a-w C:\WINDOWS\system32\_AxShlEx.dll
2007-12-16 21:57 17,536 —-a-w C:\Documents and Settings\aadil8\Application Data\GDIPFONTCACHEV1.DAT
2007-11-29 18:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 18:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-01-18 03:53 4608]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44 126976]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 11:34 69632]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-07 00:46 950664]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-11-05 19:12 2841824]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-16 19:20 91432]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"explorer"= main.vbe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2007-11-03 00:12]
R3 EPPSCSIx;EPPSCSI Driver;C:\WINDOWS\system32\DRIVERS\EPPSCAN.sys [2002-03-06 14:20]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3670a585-c810-11dc-999e-c253c004962d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69ec68c1-50d8-11dc-97b8-d0739d76546e}]
\Shell\AutoRun\command - WScript.exe .\main.vbs
\Shell\open\Command - WScript.exe .\main.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4dc1e29-b169-11dc-992b-ff81648f284d}]
\Shell\AutoRun\command - L:\pntihmcg.exe
\Shell\explore\Command - L:\pntihmcg.exe
\Shell\open\Command - L:\pntihmcg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-26 22:15:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-26 22:15:31
ComboFix-quarantined-files.txt 2008-02-26 17:15:22