Combo fix log
ComboFix 08-06-16.2 - srajan 2008-06-17 17:34:07.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.88 [GMT 5.5:30]
Running from: E:\Documents and Settings\srajan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
D:\Autorun.inf
E:\autorun.inf
E:\WINDOWS\BM43fe1884.xml
E:\WINDOWS\help\Other.exe
E:\WINDOWS\pskt.ini
E:\WINDOWS\system32\amvo.exe
E:\WINDOWS\system32\amvo0.dll
E:\WINDOWS\system32\amvo1.dll
E:\WINDOWS\system32\ayueuwen.dll
E:\WINDOWS\system32\bsxblfuw.dll
E:\WINDOWS\system32\cxesrqxu.dll
E:\WINDOWS\system32\drivers\Fjm71.sys
E:\WINDOWS\system32\dvosqkba.dll
E:\WINDOWS\system32\fmmgekqf.dll
E:\WINDOWS\system32\fpfsvbci.ini
E:\WINDOWS\system32\goeggiyj.ini
E:\WINDOWS\system32\gspboswc.dll
E:\WINDOWS\system32\hhOnnnpo.ini
E:\WINDOWS\system32\hhOnnnpo.ini2
E:\WINDOWS\system32\ifhhvmwg.ini
E:\WINDOWS\system32\ijsbtvhe.dll
E:\WINDOWS\system32\innticlv.ini
E:\WINDOWS\system32\jgmbvnwg.dll
E:\WINDOWS\system32\kkxgsrmj.dll
E:\WINDOWS\system32\lnxrrdgk.dll
E:\WINDOWS\system32\mcrh.tmp
E:\WINDOWS\system32\morokghq.dll
E:\WINDOWS\system32\opnnnOhh.dll
E:\WINDOWS\system32\pyxekomf.dll
E:\WINDOWS\system32\qhjfkiyp.ini
E:\WINDOWS\system32\RXHOonmp.ini
E:\WINDOWS\system32\RXHOonmp.ini2
E:\WINDOWS\system32\sxqfafhg.dll
E:\WINDOWS\system32\uFNWaGgh.ini
E:\WINDOWS\system32\uFNWaGgh.ini2
E:\WINDOWS\system32\upymskxq.ini
E:\WINDOWS\system32\vsonnvux.dll
E:\WINDOWS\system32\wglinubi.dll
E:\WINDOWS\system32\WinCtrl32.dll
E:\WINDOWS\system32\WinNt32.dll
E:\WINDOWS\system32\WLCtrl32.dll
E:\WINDOWS\system32\wwftxkhj.dll
E:\WINDOWS\system32\xkmiroak.dll
E:\WINDOWS\system32\xpoqmlxt.ini
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FJM71
-------\Service_Fjm71
((((((((((((((((((((((((( Files Created from 2008-05-17 to 2008-06-17 )))))))))))))))))))))))))))))))
.
2008-06-16 00:29 . 2004-08-03 22:58 14,848 --a------ E:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-16 00:29 . 2004-08-03 22:58 14,848 --a------ E:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-16 00:28 . 2004-08-03 23:08 31,616 --a------ E:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-16 00:28 . 2004-08-03 23:08 31,616 --a------ E:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-16 00:17 . 2008-06-16 00:17 <DIR> d--hs---- E:\FOUND.012
2008-06-15 21:48 . 2008-06-15 21:48 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\Yahoo!
2008-06-15 21:48 . 2008-06-15 21:48 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-15 19:58 . 2008-06-15 19:58 <DIR> d-------- E:\Program Files\Yahoo!
2008-06-15 19:40 . 2008-06-15 19:41 2,320,640 --a------ E:\WINDOWS\system32\TUKernel.exe
2008-06-15 19:08 . 2008-06-15 19:08 <DIR> d-------- E:\Program Files\Malwarebytes' Anti-Malware
2008-06-15 19:08 . 2008-06-15 19:08 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\Malwarebytes
2008-06-15 19:08 . 2008-06-15 19:08 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-15 19:08 . 2008-06-10 19:02 34,296 --a------ E:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-15 19:08 . 2008-06-10 19:02 15,864 --a------ E:\WINDOWS\system32\drivers\mbam.sys
2008-06-15 19:03 . 2008-06-15 19:03 <DIR> d-------- E:\_OTMoveIt
2008-06-15 18:13 . 2008-06-15 18:13 <DIR> d-------- E:\Documents and Settings\Administrator
2008-06-15 17:51 . 2008-06-15 17:51 <DIR> d-------- E:\WINDOWS\ERUNT
2008-06-15 17:50 . 2008-06-14 01:37 <DIR> d-------- E:\SDFix
2008-06-15 17:40 . 2008-06-15 17:40 <DIR> d--hs---- E:\FOUND.011
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- E:\Program Files\TuneUp Utilities 2007
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- E:\Program Files\Common Files\Wise Installation Wizard
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\TuneUp Software
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-06-15 11:20 . 2006-12-19 16:53 24,072 --a------ E:\WINDOWS\system32\uxtuneup.dll
2008-06-15 10:10 . 2008-06-15 10:10 <DIR> d-------- E:\Deckard
2008-06-15 09:21 . 2008-06-15 09:21 <DIR> d--hs---- E:\FOUND.010
2008-06-15 09:08 . 2008-06-15 09:08 <DIR> d-------- E:\WINDOWS\Sun
2008-06-15 09:05 . 2008-06-15 09:05 <DIR> d-------- E:\Program Files\Google
2008-06-15 09:04 . 2008-03-25 02:37 69,632 --a------ E:\WINDOWS\system32\javacpl.cpl
2008-06-15 09:03 . 2008-06-15 09:03 <DIR> d-------- E:\Program Files\Java
2008-06-15 08:56 . 2008-06-15 08:56 <DIR> d-------- E:\Program Files\Common Files\Java
2008-06-14 14:35 . 2008-06-14 14:35 <DIR> d--hs---- E:\FOUND.009
2008-06-14 11:22 . 2008-06-17 08:20 114,769 -r-hs---- E:\6x8be16.cmd
2008-06-13 16:20 . 2008-06-13 16:21 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\MahJong Suite
2008-06-13 14:53 . 2008-06-13 14:53 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\SolSuite
2008-06-12 19:26 . 2008-06-12 19:26 <DIR> d-------- E:\Program Files\Trend Micro
2008-06-12 13:38 . 2008-06-12 13:38 <DIR> d-------- E:\Program Files\Ballance
2008-06-12 13:32 . 2008-06-12 13:32 <DIR> d-------- E:\Program Files\Alcohol Soft
2008-06-12 13:29 . 2008-06-12 13:29 715,248 --a------ E:\WINDOWS\system32\drivers\sptd.sys
2008-06-09 13:27 . 2008-06-15 18:51 204 --a------ E:\WINDOWS\wininit.ini
2008-06-09 07:38 . 2008-06-09 07:38 <DIR> d--hs---- E:\FOUND.008
2008-06-06 17:39 . 2008-06-06 17:39 <DIR> d-------- E:\race
2008-06-06 16:58 . 2008-06-06 16:58 <DIR> d--hs---- E:\FOUND.007
2008-06-05 16:29 . 2006-05-15 19:15 97,184 -ra------ E:\WINDOWS\system32\drivers\SE30mdm.sys
2008-06-05 16:29 . 2006-05-15 19:15 9,360 -ra------ E:\WINDOWS\system32\drivers\SE30mdfl.sys
2008-06-05 16:29 . 2006-05-15 19:15 6,240 -ra------ E:\WINDOWS\system32\drivers\SE30cmnt.sys
2008-06-05 16:29 . 2006-05-15 19:15 6,240 -ra------ E:\WINDOWS\system32\drivers\SE30cm.sys
2008-06-05 16:28 . 2006-05-15 19:15 61,600 -ra------ E:\WINDOWS\system32\drivers\SE30bus.sys
2008-06-05 16:28 . 2006-05-15 19:15 5,872 -ra------ E:\WINDOWS\system32\drivers\SE30whnt.sys
2008-06-05 16:28 . 2006-05-15 19:15 5,872 -ra------ E:\WINDOWS\system32\drivers\SE30wh.sys
2008-06-05 16:25 . 2008-06-05 16:25 <DIR> d-------- E:\WINDOWS\system32\DRVSTORE
2008-06-05 16:23 . 2008-06-05 16:23 <DIR> d-------- E:\Program Files\Common Files\InstallShield
2008-06-05 09:49 . 2008-06-05 09:49 <DIR> d--hs---- E:\FOUND.006
2008-06-05 09:12 . 2008-06-05 09:12 <DIR> d-------- E:\Program Files\Microsoft Games
2008-06-05 09:05 . 2008-06-05 09:05 <DIR> d-------- E:\Program Files\Common Files\Adobe
2008-06-05 08:56 . 2008-06-05 08:56 <DIR> d-------- E:\Program Files\GameSpy Arcade
2008-06-05 08:46 . 2008-06-05 08:46 29 --a------ E:\WINDOWS\system32\retypogh.tmp
2008-06-05 08:37 . 2008-06-05 08:37 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\Microsoft Games
2008-06-04 22:52 . 2008-06-04 22:52 <DIR> d--hs---- E:\FOUND.005
2008-06-04 13:43 . 2008-06-04 13:43 11,689 --a------ E:\WINDOWS\cdplayer.ini
2008-06-04 12:32 . 2008-06-04 12:32 <DIR> d-------- E:\Program Files\Acoustica MP3 CD Burner
2008-06-04 12:32 . 2002-11-05 15:16 57,344 --a------ E:\WINDOWS\system32\Wnaspint.dll
2008-06-04 11:26 . 2004-08-03 23:08 26,496 --a------ E:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-04 09:34 . 2008-06-04 09:34 <DIR> d--hs---- E:\FOUND.004
2008-06-03 20:20 . 2008-06-03 20:20 <DIR> d--hs---- E:\FOUND.003
2008-05-31 23:30 . 2004-08-03 23:10 85,376 --a------ E:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-05-31 23:29 . 2004-08-04 00:56 90,624 --a------ E:\WINDOWS\system32\kswdmcap.ax
2008-05-31 23:29 . 2004-08-04 00:56 90,624 --a------ E:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-05-31 23:29 . 2004-08-04 00:56 61,952 --a------ E:\WINDOWS\system32\kstvtune.ax
2008-05-31 23:29 . 2004-08-04 00:56 61,952 --a------ E:\WINDOWS\system32\dllcache\kstvtune.ax
2008-05-31 23:29 . 2004-08-04 00:56 53,760 --a------ E:\WINDOWS\system32\vfwwdm32.dll
2008-05-31 23:29 . 2004-08-04 00:56 53,760 --a------ E:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-05-31 23:29 . 2004-08-04 00:56 43,008 --a------ E:\WINDOWS\system32\ksxbar.ax
2008-05-31 23:29 . 2004-08-04 00:56 43,008 --a------ E:\WINDOWS\system32\dllcache\ksxbar.ax
2008-05-31 23:29 . 2004-08-04 00:56 28,672 --a------ E:\WINDOWS\system32\vidcap.ax
2008-05-31 23:29 . 2004-08-04 00:56 28,672 --a------ E:\WINDOWS\system32\dllcache\vidcap.ax
2008-05-31 23:24 . 2008-05-31 23:24 <DIR> d-------- E:\Program Files\Common Files\snpstd3
2008-05-31 23:24 . 2008-05-31 23:24 <DIR> d-------- E:\Documents and Settings\srajan\Application Data\InstallShield
2008-05-31 23:24 . 2007-07-25 17:23 10,375,552 --a------ E:\WINDOWS\system32\drivers\snpstd3.sys
2008-05-31 23:24 . 2007-05-10 13:18 835,584 --a------ E:\WINDOWS\vsnpstd3.exe
2008-05-31 23:24 . 2007-04-21 09:32 270,336 --a------ E:\WINDOWS\tsnpstd3.exe
2008-05-31 23:24 . 2007-07-23 18:04 155,648 --a------ E:\WINDOWS\system32\rsnpstd3.dll
2008-05-31 23:24 . 2006-07-03 10:31 94,208 --a------ E:\WINDOWS\amcap.exe
2008-05-31 23:24 . 2007-07-23 18:09 57,344 --a------ E:\WINDOWS\system32\vsnpstd3.dll
2008-05-31 23:24 . 2005-11-23 13:55 53,248 --a------ E:\WINDOWS\system32\csnpstd3.dll
2008-05-31 23:24 . 2005-11-23 13:55 53,248 --a------ E:\WINDOWS\csnpstd3.dll
2008-05-31 23:24 . 2004-02-27 17:36 15,498 --a------ E:\WINDOWS\snpstd3.ini
2008-05-31 23:24 . 2004-02-27 17:36 13,023 --a------ E:\WINDOWS\snpstd3.src
2008-05-31 18:11 . 2001-08-17 13:48 12,160 --a------ E:\WINDOWS\system32\drivers\mouhid.sys
2008-05-31 18:11 . 2001-08-17 13:48 12,160 --a------ E:\WINDOWS\system32\dllcache\mouhid.sys
2008-05-31 18:11 . 2001-08-17 14:02 9,600 --a------ E:\WINDOWS\system32\drivers\hidusb.sys
2008-05-31 18:11 . 2001-08-17 14:02 9,600 --a------ E:\WINDOWS\system32\dllcache\hidusb.sys
2008-05-29 09:35 . 2008-05-29 09:35 <DIR> d-------- E:\Program Files\Home
2008-05-29 07:59 . 2007-10-29 10:34 <DIR> d-------- E:\Program Files\EA SPORTS
2008-05-28 13:57 . 2008-05-28 13:57 <DIR> d-------- E:\Program Files\Hasbro
2008-05-28 13:57 . 2008-05-28 13:57 <DIR> dr-h----- E:\Documents and Settings\srajan\Application Data\SecuROM
2008-05-28 13:57 . 2008-05-28 13:57 107,888 --a------ E:\WINDOWS\system32\CmdLineExt.dll
2008-05-28 10:51 . 2008-05-28 10:51 <DIR> d--hs---- E:\FOUND.002
2008-05-28 10:06 . 2008-05-28 10:06 <DIR> d-------- E:\Program Files\Smart Projects
2008-05-27 20:46 . 2008-05-27 20:46 300 --a------ E:\WINDOWS\EPSTPLOG.BAK
2008-05-27 13:23 . 2008-05-27 13:23 <DIR> d-------- E:\Pocket Tanks Deluxe
2008-05-26 15:38 . 2008-05-26 15:38 <DIR> d--h----- E:\Program Files\InstallShield Installation Information
2008-05-26 15:38 . 2008-05-26 15:39 0 --ah----- E:\WINDOWS\SwSys2.bmp
2008-05-26 15:38 . 2008-05-26 15:39 0 --ah----- E:\WINDOWS\SwSys1.bmp
2008-05-26 15:37 . 2008-05-26 15:37 <DIR> d-------- E:\WINDOWS\Downloaded Installations
2008-05-26 15:37 . 2008-05-26 15:37 <DIR> d-------- E:\Program Files\Xplosiv
2008-05-26 13:51 . 2008-05-26 13:51 <DIR> d-------- E:\Program Files\Gigabyte
2008-05-26 13:51 . 1998-10-02 19:00 327,168 --a------ E:\WINDOWS\IsUninst.exe
2008-05-26 13:51 . 2002-04-17 14:45 39,880 -ra------ E:\WINDOWS\system32\drivers\ETDrv.sys
2008-05-26 13:45 . 2003-02-11 11:37 1,663,488 -ra------ E:\WINDOWS\system32\ALSNDMGR.CPL
2008-05-26 13:45 . 2002-11-21 12:37 765,952 -ra------ E:\WINDOWS\system\crlds3d.dll
2008-05-26 13:45 . 2002-08-27 13:53 720,896 --a------ E:\WINDOWS\system32\dllcache\a3d.dll
2008-05-26 13:45 . 2002-08-27 13:53 720,896 -ra------ E:\WINDOWS\system32\Audio3D.dll
2008-05-26 13:45 . 2002-08-27 13:53 720,896 -ra------ E:\WINDOWS\system32\a3d.dll
2008-05-26 13:45 . 2003-02-11 13:04 696,284 -ra------ E:\WINDOWS\system32\drivers\ALCXWDM.SYS
2008-05-26 13:45 . 2002-02-05 11:24 141,016 -ra------ E:\WINDOWS\system32\ALSNDMGR.WAV
2008-05-26 13:45 . 2003-02-10 13:29 47,104 -ra------ E:\WINDOWS\SOUNDMAN.EXE
2008-05-26 13:16 . 2008-05-26 13:16 2,560 --a------ E:\WINDOWS\system32\bitcometres.dll
2008-05-26 12:32 . 2008-05-26 12:32 <DIR> d--h----- E:\WINDOWS\PIF
2008-05-26 12:01 . 2008-05-26 12:01 <DIR> d-------- E:\Program Files\Spybot - Search & Destroy
2008-05-26 12:01 . 2008-05-26 12:01 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 06:26 --------- d-----w E:\Program Files\Mozilla Firefox 3 Beta 2
2008-05-26 06:25 --------- d-----w E:\Program Files\ASL-25020
2008-05-26 05:36 --------- d-----w E:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="E:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 21:58 4269296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snpstd3"="E:\WINDOWS\vsnpstd3.exe" [2007-05-10 13:18 835584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2007-12-22 12:53 221568 E:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amva]
E:\WINDOWS\system32\amvo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM43fe1884]
E:\WINDOWS\system32\tjcyibvg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc]
E:\WINDOWS\dc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc2k5]
E:\WINDOWS\SVIQ.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e87446f1]
E:\WINDOWS\system32\aljvbqie.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneIV]
--a------ 2003-03-28 14:37 217088 E:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\ET4\et4Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
E:\WINDOWS\FixCamera.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fun]
E:\WINDOWS\system\Fun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JavaCore]
E:\Program Files\\JavaCore\\JavaCore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
E:\WINDOWS\inf\Other.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsass]
E:\Documents and Settings\srajan\Application Data\Microsoft\Windows\lsass.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 E:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
E:\WINDOWS\system32\config\Win.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
--a------ 2007-05-10 13:18 835584 E:\WINDOWS\vsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 2003-02-10 13:29 47104 E:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
--a------ 2007-04-21 09:32 270336 E:\WINDOWS\tsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WintelUpdate]
--a------ 2008-06-05 08:46 12800 C:\flciijjq.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"amva"=E:\WINDOWS\system32\amvo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM43fe1884"=Rundll32.exe "E:\WINDOWS\system32\tjcyibvg.dll",s
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"E:\\Program Files\\Microsoft Games\\Rise of Nations\\Thrones.exe"=
"E:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9144:TCP"= 9144:TCP:BitComet 9144 TCP
"9144:UDP"= 9144:UDP:BitComet 9144 UDP
R2 ETDrv;ETDrv;E:\WINDOWS\system32\drivers\ETDrv.sys [2002-04-17 14:45]
R2 UxTuneUp;TuneUp Design Expansion;E:\WINDOWS\System32\svchost.exe [2004-08-03 22:56]
R3 iadusb;ASL-25020;E:\WINDOWS\system32\DRIVERS\glauiad.sys [2004-07-02 13:50]
S3 SE30bus;Sony Ericsson Device 048 Driver driver (WDM);E:\WINDOWS\system32\DRIVERS\SE30bus.sys [2006-05-15 19:15]
S3 SE30mdfl;Sony Ericsson Device 048 USB WMC Modem Filter;E:\WINDOWS\system32\DRIVERS\SE30mdfl.sys [2006-05-15 19:15]
S3 SE30mdm;Sony Ericsson Device 048 USB WMC Modem Driver;E:\WINDOWS\system32\DRIVERS\SE30mdm.sys [2006-05-15 19:15]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\6x8be16.cmd
\Shell\explore\Command - C:\6x8be16.cmd
\Shell\open\Command - C:\6x8be16.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\6x8be16.cmd
\Shell\explore\Command - D:\6x8be16.cmd
\Shell\open\Command - D:\6x8be16.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\6x8be16.cmd
\Shell\explore\Command - F:\6x8be16.cmd
\Shell\open\Command - F:\6x8be16.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19fd750a-36b8-11dd-889e-ac35064d1481}]
\Shell\AutoRun\command - H:\x6.bat
\Shell\explore\Command - H:\x6.bat
\Shell\open\Command - H:\x6.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8aa9461c-32ee-11dd-8882-001802930af6}]
\Shell\AutoRun\command - H:\x6.bat
\Shell\explore\Command - H:\x6.bat
\Shell\open\Command - H:\x6.bat
.
Contents of the 'Scheduled Tasks' folder
"2008-06-15 05:50:50 E:\WINDOWS\Tasks\1-Click Maintenance.job"
- E:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-17 17:44:04
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
E:\WINDOWS\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2008-06-17 17:44:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-17 12:14:38
Pre-Run: 4,936,269,824 bytes free
Post-Run: 4,885,970,944 bytes free
306