This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] please examine my Hijack This log!

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Oh sorry, missed your post from above on the files you couldn't find. Did you enable hidden files and folders? * Click Start. * Open My Computer. * Select the Tools menu and click Folder Options. * Select the View Tab. * Under the Hidden files and folders heading select Show hidden files and folders. * Uncheck the Hide protected operating system files (recommended) option. * Click Yes to confirm. * Click OK.
C:\main.vbs
C:\WINDOWS\system32\drivers\video.exe ..
above files removed..
but following file giving me strange behaviours.. everytime i go and uncheck Hide protected operating system files (recommended) option. , it gets checked again as i fail to see RECYLE folder.. tried several times but only seen it twice and that two dissappered before i could go into it.. dont know it s me who is going mad or my computer lol

C:\Documents and Settings\aadil8\Recycled\deskinf.pif
thanks heavens.. finally removed that file deskinf.pif inside recycled folder.. lol.. i would like to say thank you very much for helping me all the way and sorting my problem out.. DAVE You Are a Star!
C:\Documents and Settings\aadil8\Recycled\deskinf.pif
C:\main.vbs
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip
C:\WINDOWS\system32\drivers\video.exe
C:\WINDOWS\system32\main.txt
C:\WINDOWS\system32\main.vbe
C:\WINDOWS\system32temp2.exe
I:\Keygens 26-01-2008\Keygens\Opera Keygen.zip

I was advised to remove all the above files in order to cean my pc so i did that but now i am facing a problem that is , whenever i try to open my "System Partition" i.e C .. it gives me following error

Windows Script Host
Can not find script file "C:\main.vbs".


how can i get rid of this problem.. will i have to reinstall windows again or what?
Hi,

After you deleted the file did you empty out your recycle bin? If not then it should still be in there. You can restore it back to the C:\ drive. I have no idea and can find very little on what that file is or does. Does you computer run normally otherwise?

Let me know if you can restore it. Also, let's get another scan here too.

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Dave bro when i deleted the recommended files then i pressed shift + delete so they were deleted without going into recylcle bin.. so i cant retrieve back any file.. My Document folder on my desktop is without any name , it just shows a folder without a name.. otherwise my pc is so far running normally except for the fact that i cant go into my system partition C..

following is the main.txt

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-02-23 10:50:44
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
23: 2008-02-23 05:50:50 UTC - RP188 - Deckard's System Scanner Restore Point
22: 2008-02-22 18:21:54 UTC - RP187 - System Checkpoint
21: 2008-02-21 16:26:44 UTC - RP186 - Removed Sunbelt CounterSpy.
20: 2008-02-20 17:56:12 UTC - RP185 - System Checkpoint
19: 2008-02-19 14:07:24 UTC - RP184 - Installed Sunbelt CounterSpy.


– First Restore Point –
1: 2008-02-09 00:15:21 UTC - RP166 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 504 MiB (512 MiB recommended).


– HijackThis (run as aadil8.exe) ———————————————-

Logfile of HijackThis v1.99.1
Scan saved at 10:51:40 AM, on 2/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\drivers\svchost.exe
C:\WINDOWS\SYSTEM32\drivers\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\aadil8\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\aadil8.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\SYSTEM32\drivers\svchost.exe,C:\WINDOWS\SYSTEM32\drivers\svchost.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: 2nd &Speech; Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon; - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R3 EPPSCSIx (EPPSCSI Driver) - c:\windows\system32\drivers\eppscan.sys
Ahhh….you were re-infected, likely from one of your flash drives. Let's try this first, if this doesn't help then we'll go after it manually.

Download Flash_Disinfector from here and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.


Run Deckards again and post the log.
hope you are well dave bro.. thanks for your patience with me.. when i first used deckards then it gave me two logs, main.txt and extra.txt but now when i run it then it only gave me following log

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-02-24 21:43:29
Computer is in Normal Mode.
——————————————————————————–

Total Physical Memory: 504 MiB (512 MiB recommended).


– HijackThis (run as aadil8.exe) ———————————————-

Logfile of HijackThis v1.99.1
Scan saved at 9:43:32 PM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\drivers\svchost.exe
C:\WINDOWS\SYSTEM32\drivers\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\aadil8\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\aadil8.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: 2nd &Speech Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


– Files created between 2008-01-24 and 2008-02-24 —————————–

2008-02-24 02:01:04 0 d——– C:\Program Files\GetData
2008-02-24 01:03:52 0 d——– C:\Documents and Settings\aadil8\Application Data\Nokia Multimedia Player
2008-02-22 07:36:35 4608 –a—— C:\WINDOWS\system32temp2.exe
2008-02-22 07:13:26 4608 –a—— C:\WINDOWS\system32\drivers\svchost.exe
2008-02-22 03:29:40 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-22 03:29:36 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-21 21:31:55 0 d——– C:\Documents and Settings\aadil8\Application Data\Grisoft
2008-02-21 21:31:30 0 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-20 14:24:32 0 d——– C:\WINDOWS\ERUNT
2008-02-19 16:00:14 0 –a—— C:\WINDOWS\system32\SBRC.dat
2008-02-19 16:00:14 0 –a—— C:\WINDOWS\system32\SBFC.dat
2008-02-19 15:57:23 0 d——– C:\Documents and Settings\aadil8\Application Data\Sunbelt Software
2008-02-18 21:29:54 0 d——– C:\Program Files\Belarc
2008-02-18 17:11:14 0 d——– C:\Program Files\Common Files\PCSuite
2008-02-18 17:11:14 0 d——– C:\Program Files\Common Files\Nokia
2008-02-18 13:50:17 0 d——– C:\WINDOWS\system32\ZoneLabs
2008-02-18 12:32:25 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2008-02-18 12:31:14 0 d——– C:\WINDOWS\Internet Logs
2008-02-18 08:28:13 0 d——– C:\WINDOWS\pss
2008-02-18 06:12:57 153088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2008-02-16 15:25:51 0 d——– C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-02-16 15:15:59 0 dr——- C:\Documents and Settings\LocalService\Favorites
2008-02-16 14:57:28 0 d——– C:\Documents and Settings\LocalService\Application Data\Opera
2008-02-16 14:25:13 0 d——– C:\Program Files\Spyware Doctor
2008-02-16 14:12:33 0 d——– C:\Program Files\Lavasoft
2008-02-14 13:44:21 0 d——– C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-02-14 13:44:19 0 d——– C:\Program Files\ACD Systems
2008-02-13 09:18:32 38160 –a—— C:\WINDOWS\system32\LMRTREND.dll
Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02-25.3 - aadil8 2008-02-26 22:13:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223 [GMT 5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\infopsvEV67s.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-24 01:03 . 2008-02-24 01:03 d——– C:\Documents and Settings\aadil8\Application Data\Nokia Multimedia Player
2008-02-24 00:50 . 2008-02-24 00:51 11 –a—— C:\trace.ini
2008-02-23 14:15 . 2008-02-26 22:09 335 –a—— C:\WINDOWS\system32\vsconfig.xml
2008-02-22 20:05 . 2008-02-22 20:05 536 –a—— C:\WINDOWS\system32\wbrifkpc.rif
2008-02-22 07:36 . 2008-02-22 08:40 4,608 –a—— C:\WINDOWS\system32temp2.exe
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\aadil8\Application Data\Grisoft
2008-02-21 21:31 . 2007-05-30 17:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-20 14:24 . 2008-02-20 14:24 d——– C:\WINDOWS\ERUNT
2008-02-20 14:17 . 2008-02-20 14:31 d——– C:\SDFix
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBRC.dat
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBFC.dat
2008-02-19 15:57 . 2008-02-19 15:57 d——– C:\Documents and Settings\aadil8\Application Data\Sunbelt Software
2008-02-18 21:29 . 2008-02-18 21:29 d——– C:\Program Files\Belarc
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\PCSuite
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\Nokia
2008-02-18 13:50 . 2008-02-18 13:50 d——– C:\Program Files\Zone Labs
2008-02-18 12:32 . 2008-02-23 23:08 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2008-02-18 12:31 . 2008-02-26 22:10 d——– C:\WINDOWS\Internet Logs
2008-02-18 06:12 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2008-02-16 14:25 . 2008-02-19 16:46 d——– C:\Program Files\Spyware Doctor
2008-02-16 14:12 . 2008-02-16 14:12 d——– C:\Program Files\Lavasoft
2008-02-14 14:10 . 2008-02-14 14:10 4,709 –a—— C:\Pakistani+JF17.jpg
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Program Files\ACD Systems
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-02-13 09:18 . 2008-02-13 09:18 d——– C:\Program Files\Auralog
2008-02-13 09:18 . 2008-02-22 08:57 d–hs—- C:\Documents and Settings\aadil8\Recycled
2008-02-13 09:18 . 1998-09-02 13:02 194,320 –a—— C:\WINDOWS\system32\qcut.dll
2008-02-13 09:18 . 1998-08-27 09:51 182,032 –a—— C:\WINDOWS\system32\dxtmsft3.dll
2008-02-13 09:18 . 1998-08-20 16:02 140,800 –a—— C:\WINDOWS\system32\tm20dec.ax
2008-02-13 09:18 . 1998-09-02 13:28 63,488 –a—— C:\WINDOWS\system32\unam4ie.exe
2008-02-13 09:18 . 1998-09-02 13:28 38,160 –a—— C:\WINDOWS\system32\LMRTREND.dll
2008-02-13 09:18 . 1998-08-17 14:21 11,776 –a—— C:\WINDOWS\system32\mciqtz.drv
2008-02-13 09:18 . 1998-08-17 14:21 10,240 –a—— C:\WINDOWS\system32\vidx16.dll
2008-02-13 09:18 . 1998-08-17 14:21 5,672 –a—— C:\WINDOWS\system32\quartz.vxd
2008-02-13 09:18 . 2008-02-13 09:18 4,608 –a—— C:\WINDOWS\system32\w95inf32.dll
2008-02-13 09:18 . 2008-02-13 09:18 2,272 –a—— C:\WINDOWS\system32\w95inf16.dll
2008-02-05 02:12 . 2008-02-05 02:55 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-02-05 01:39 . 2008-02-05 01:39 d——– C:\Program Files\KARI2
2008-02-05 01:39 . 2008-02-05 01:39 172,489 –a—— C:\WINDOWS\KARI2 Uninstaller.exe
2008-02-04 23:24 . 2008-02-04 23:24 d——– C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-04 23:22 . 2008-02-04 23:22 d——– C:\Program Files\Common Files\LightScribe
2008-02-04 23:21 . 2008-02-04 23:27 d——– C:\Documents and Settings\aadil8\Application Data\Ahead
2008-02-04 23:14 . 2008-02-05 07:49 d——– C:\Program Files\Common Files\Ahead
2008-02-04 06:35 . 2008-02-10 06:00 d——– C:\Program Files\Dvd-cloner
2008-02-03 01:55 . 2008-02-03 01:55 d——– C:\Program Files\Windows Media Connect 2
2008-02-03 01:53 . 2008-02-03 01:53 d——– C:\WINDOWS\system32\LogFiles
2008-02-03 01:53 . 2008-02-18 23:32 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-03 01:53 . 2006-09-16 03:02 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-02-01 01:56 . 2008-02-01 01:56 d——– C:\Documents and Settings\aadil8\Application Data\CyberLink
2008-02-01 01:48 . 2008-02-01 01:48 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-02-01 01:47 . 2008-02-01 01:48 d——– C:\Program Files\CyberLink
2008-01-31 18:41 . 2008-01-31 18:42 d——– C:\F-16 Multi Role Fighter
2008-01-31 03:10 . 2008-01-31 03:11 d——– C:\Program Files\K-Lite Codec Pack
2008-01-31 03:10 . 2007-12-04 02:33 682,496 –a—— C:\WINDOWS\system32\divx.dll
2008-01-31 03:10 . 2007-12-24 13:49 7,680 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-01-31 03:10 . 2007-07-10 17:10 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-01-29 18:24 . 2008-01-29 18:24 172 –a—— C:\WINDOWS\pdf2word.INI
2008-01-27 05:18 . 2008-01-27 05:18 d——– C:\Program Files\MyNotesKeeper
2008-01-27 05:18 . 2008-01-27 05:19 d——– C:\Documents and Settings\aadil8\Application Data\MyNotesKeeper
2008-01-26 02:45 . 2008-01-26 02:45 d——– C:\Program Files\PC Connectivity Solution
2008-01-26 02:44 . 2007-02-22 10:15 137,216 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2008-01-26 02:44 . 2007-02-22 10:15 65,536 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-01-26 02:44 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-01-26 02:44 . 2007-02-22 10:15 12,288 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-01-26 02:44 . 2007-02-22 10:15 8,320 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 09:05 ——— d—–w C:\Program Files\Opera
2008-02-19 10:42 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-18 12:11 ——— d—–w C:\Program Files\Nokia
2008-02-18 08:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-14 08:44 10,368 —-a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-02-14 08:44 ——— d—–w C:\Program Files\Common Files\ACD Systems
2008-02-07 23:24 ——— d—–w C:\Program Files\ESET
2008-02-05 02:56 ——— d—–w C:\Program Files\Oxford
2008-02-04 23:53 ——— d—–w C:\Program Files\Video Snapshots Genius
2008-02-02 22:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-01-31 20:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-29 03:18 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Babylon
2008-01-26 23:31 ——— d—–r C:\Program Files\TypingMaster
2008-01-25 21:48 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Nokia
2008-01-25 21:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-01-25 01:46 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Winamp
2008-01-25 01:42 ——— d—–w C:\Program Files\Winamp
2008-01-22 22:15 ——— d—–w C:\Program Files\Text to Speech Maker
2008-01-22 22:05 ——— d—–w C:\Program Files\2nd Speech Center
2008-01-19 16:57 ——— d—–w C:\Documents and Settings\aadil8\Application Data\PC Suite
2008-01-17 22:48 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-15 21:27 ——— d–h–r C:\Documents and Settings\aadil8\Application Data\SecuROM
2008-01-15 21:26 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-09 02:03 ——— d—–w C:\Documents and Settings\aadil8\Application Data\uTorrent
2008-01-07 11:48 ——— d—–w C:\Program Files\Total Video Converter
2008-01-01 15:53 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-01 15:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-31 23:43 ——— d—–w C:\Program Files\NCT
2007-12-22 07:21 339,328 —-a-w C:\WINDOWS\system32\_AxShlEx.dll
2007-12-16 21:57 17,536 —-a-w C:\Documents and Settings\aadil8\Application Data\GDIPFONTCACHEV1.DAT
2007-11-29 18:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 18:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-01-18 03:53 4608]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44 126976]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 11:34 69632]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-07 00:46 950664]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-11-05 19:12 2841824]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-16 19:20 91432]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"explorer"= main.vbe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 00:12]
R3 EPPSCSIx;EPPSCSI Driver;C:\WINDOWS\system32\DRIVERS\EPPSCAN.sys [2002-03-06 14:20]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3670a585-c810-11dc-999e-c253c004962d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69ec68c1-50d8-11dc-97b8-d0739d76546e}]
\Shell\AutoRun\command - WScript.exe .\main.vbs
\Shell\open\Command - WScript.exe .\main.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4dc1e29-b169-11dc-992b-ff81648f284d}]
\Shell\AutoRun\command - L:\pntihmcg.exe
\Shell\explore\Command - L:\pntihmcg.exe
\Shell\open\Command - L:\pntihmcg.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 22:15:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-26 22:15:31
ComboFix-quarantined-files.txt 2008-02-26 17:15:22
Logfile of HijackThis v1.99.1
Scan saved at 10:19:13 PM, on 2/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Nokia\Nokia PC Suite 6\OneTouchAccess.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: 2nd &Speech Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE46E33-A43F-4BD9-A584-928AFA10E66C}: NameServer = 221.132.112.8 202.163.96.3
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
Alcohol 120%, is a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs* and CDs. In addition, the program lets you store your most used CDs as images on your computer, so you can call them up at the click of a button..

Now this Alcohol 120% has created a virtual optical drive on my pc named L:.. when i copied L:\pntihmcg.exe to run to check what it is then it promted me to insert a disk into drive L: .. i have created image files of the cds of some movies and softwares so whenever i want to play that particular movie or software , i choose an option by right clicking on that file mount on drive and they are opened with that L:drive.. DAVE did you get your answer?
Yes, that answers the question and that entry is ok I believe.

Let's go forward here.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"explorer"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69ec68c1-50d8-11dc-97b8-d0739d76546e}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please also let me know how it's running.
ComboFix 08-02-25.3 - aadil8 2008-02-28 16:11:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.222 [GMT 5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\aadil8\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.

2008-02-24 01:03 . 2008-02-24 01:03 d——– C:\Documents and Settings\aadil8\Application Data\Nokia Multimedia Player
2008-02-24 00:50 . 2008-02-24 00:51 11 –a—— C:\trace.ini
2008-02-23 14:15 . 2008-02-28 16:07 335 –a—— C:\WINDOWS\system32\vsconfig.xml
2008-02-22 20:05 . 2008-02-22 20:05 536 –a—— C:\WINDOWS\system32\wbrifkpc.rif
2008-02-22 07:36 . 2008-02-22 08:40 4,608 –a—— C:\WINDOWS\system32temp2.exe
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 03:29 . 2008-02-22 03:29 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-21 21:31 . 2008-02-21 21:31 d——– C:\Documents and Settings\aadil8\Application Data\Grisoft
2008-02-21 21:31 . 2007-05-30 17:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-20 14:24 . 2008-02-20 14:24 d——– C:\WINDOWS\ERUNT
2008-02-20 14:17 . 2008-02-20 14:31 d——– C:\SDFix
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBRC.dat
2008-02-19 16:00 . 2008-02-19 16:00 0 –a—— C:\WINDOWS\system32\SBFC.dat
2008-02-19 15:57 . 2008-02-19 15:57 d——– C:\Documents and Settings\aadil8\Application Data\Sunbelt Software
2008-02-18 21:29 . 2008-02-18 21:29 d——– C:\Program Files\Belarc
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\PCSuite
2008-02-18 17:11 . 2008-02-18 17:11 d——– C:\Program Files\Common Files\Nokia
2008-02-18 13:50 . 2008-02-18 13:50 d——– C:\Program Files\Zone Labs
2008-02-18 12:32 . 2008-02-23 23:08 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2008-02-18 12:31 . 2008-02-28 16:07 d——– C:\WINDOWS\Internet Logs
2008-02-18 06:12 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2008-02-16 14:25 . 2008-02-19 16:46 d——– C:\Program Files\Spyware Doctor
2008-02-16 14:12 . 2008-02-16 14:12 d——– C:\Program Files\Lavasoft
2008-02-14 14:10 . 2008-02-14 14:10 4,709 –a—— C:\Pakistani+JF17.jpg
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Program Files\ACD Systems
2008-02-14 13:44 . 2008-02-14 13:44 d——– C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-02-13 09:18 . 2008-02-13 09:18 d——– C:\Program Files\Auralog
2008-02-13 09:18 . 2008-02-22 08:57 d–hs—- C:\Documents and Settings\aadil8\Recycled
2008-02-13 09:18 . 1998-09-02 13:02 194,320 –a—— C:\WINDOWS\system32\qcut.dll
2008-02-13 09:18 . 1998-08-27 09:51 182,032 –a—— C:\WINDOWS\system32\dxtmsft3.dll
2008-02-13 09:18 . 1998-08-20 16:02 140,800 –a—— C:\WINDOWS\system32\tm20dec.ax
2008-02-13 09:18 . 1998-09-02 13:28 63,488 –a—— C:\WINDOWS\system32\unam4ie.exe
2008-02-13 09:18 . 1998-09-02 13:28 38,160 –a—— C:\WINDOWS\system32\LMRTREND.dll
2008-02-13 09:18 . 1998-08-17 14:21 11,776 –a—— C:\WINDOWS\system32\mciqtz.drv
2008-02-13 09:18 . 1998-08-17 14:21 10,240 –a—— C:\WINDOWS\system32\vidx16.dll
2008-02-13 09:18 . 1998-08-17 14:21 5,672 –a—— C:\WINDOWS\system32\quartz.vxd
2008-02-13 09:18 . 2008-02-13 09:18 4,608 –a—— C:\WINDOWS\system32\w95inf32.dll
2008-02-13 09:18 . 2008-02-13 09:18 2,272 –a—— C:\WINDOWS\system32\w95inf16.dll
2008-02-05 02:12 . 2008-02-05 02:55 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-02-05 01:39 . 2008-02-05 01:39 d——– C:\Program Files\KARI2
2008-02-05 01:39 . 2008-02-05 01:39 172,489 –a—— C:\WINDOWS\KARI2 Uninstaller.exe
2008-02-04 23:24 . 2008-02-04 23:24 d——– C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-04 23:22 . 2008-02-04 23:22 d——– C:\Program Files\Common Files\LightScribe
2008-02-04 23:21 . 2008-02-04 23:27 d——– C:\Documents and Settings\aadil8\Application Data\Ahead
2008-02-04 23:14 . 2008-02-05 07:49 d——– C:\Program Files\Common Files\Ahead
2008-02-04 06:35 . 2008-02-10 06:00 d——– C:\Program Files\Dvd-cloner
2008-02-03 01:55 . 2008-02-03 01:55 d——– C:\Program Files\Windows Media Connect 2
2008-02-03 01:53 . 2008-02-03 01:53 d——– C:\WINDOWS\system32\LogFiles
2008-02-03 01:53 . 2008-02-18 23:32 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-03 01:53 . 2006-09-16 03:02 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-02-01 01:56 . 2008-02-01 01:56 d——– C:\Documents and Settings\aadil8\Application Data\CyberLink
2008-02-01 01:48 . 2008-02-01 01:48 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-02-01 01:47 . 2008-02-01 01:48 d——– C:\Program Files\CyberLink
2008-01-31 18:41 . 2008-01-31 18:42 d——– C:\F-16 Multi Role Fighter
2008-01-31 03:10 . 2008-01-31 03:11 d——– C:\Program Files\K-Lite Codec Pack
2008-01-31 03:10 . 2007-12-04 02:33 682,496 –a—— C:\WINDOWS\system32\divx.dll
2008-01-31 03:10 . 2007-12-24 13:49 7,680 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-01-31 03:10 . 2007-07-10 17:10 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-01-29 18:24 . 2008-01-29 18:24 172 –a—— C:\WINDOWS\pdf2word.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 09:05 ——— d—–w C:\Program Files\Opera
2008-02-19 10:42 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-18 12:11 ——— d—–w C:\Program Files\Nokia
2008-02-18 08:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-14 08:44 10,368 —-a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-02-14 08:44 ——— d—–w C:\Program Files\Common Files\ACD Systems
2008-02-07 23:24 ——— d—–w C:\Program Files\ESET
2008-02-05 02:56 ——— d—–w C:\Program Files\Oxford
2008-02-04 23:53 ——— d—–w C:\Program Files\Video Snapshots Genius
2008-02-02 22:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-01-31 20:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-29 03:18 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Babylon
2008-01-27 00:19 ——— d—–w C:\Documents and Settings\aadil8\Application Data\MyNotesKeeper
2008-01-27 00:18 ——— d—–w C:\Program Files\MyNotesKeeper
2008-01-26 23:31 ——— d—–r C:\Program Files\TypingMaster
2008-01-25 21:48 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Nokia
2008-01-25 21:45 ——— d—–w C:\Program Files\PC Connectivity Solution
2008-01-25 21:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-01-25 01:46 ——— d—–w C:\Documents and Settings\aadil8\Application Data\Winamp
2008-01-25 01:42 ——— d—–w C:\Program Files\Winamp
2008-01-22 22:15 ——— d—–w C:\Program Files\Text to Speech Maker
2008-01-22 22:05 ——— d—–w C:\Program Files\2nd Speech Center
2008-01-19 16:57 ——— d—–w C:\Documents and Settings\aadil8\Application Data\PC Suite
2008-01-17 22:48 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-15 21:27 ——— d–h–r C:\Documents and Settings\aadil8\Application Data\SecuROM
2008-01-15 21:26 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-09 02:03 ——— d—–w C:\Documents and Settings\aadil8\Application Data\uTorrent
2008-01-07 11:48 ——— d—–w C:\Program Files\Total Video Converter
2008-01-01 15:53 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-01 15:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-31 23:43 ——— d—–w C:\Program Files\NCT
2007-12-22 07:21 339,328 —-a-w C:\WINDOWS\system32\_AxShlEx.dll
2007-12-16 21:57 17,536 —-a-w C:\Documents and Settings\aadil8\Application Data\GDIPFONTCACHEV1.DAT
2007-11-29 18:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 18:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-01-18 03:53 4608]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44 126976]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 11:34 69632]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-07 00:46 950664]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-11-05 19:12 2841824]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-16 19:20 91432]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 00:12]
R3 EPPSCSIx;EPPSCSI Driver;C:\WINDOWS\system32\DRIVERS\EPPSCAN.sys [2002-03-06 14:20]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3670a585-c810-11dc-999e-c253c004962d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4dc1e29-b169-11dc-992b-ff81648f284d}]
\Shell\AutoRun\command - L:\pntihmcg.exe
\Shell\explore\Command - L:\pntihmcg.exe
\Shell\open\Command - L:\pntihmcg.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 16:12:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-28 16:13:11
ComboFix-quarantined-files.txt 2008-02-28 11:13:02
ComboFix2.txt 2008-02-26 17:15:32

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI