here's combofix's log
ComboFix 08-01-04.1 - satisfied customer 2008-01-04 21:46:47.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.130 [GMT -6:00]
Running from: C:\Documents and Settings\satisfied customer\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\satisfied customer\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\atcfiunr.ini
C:\WINDOWS\system32\kbdmap.dll
C:\WINDOWS\system32\pmnmlii.dll
C:\WINDOWS\system32\pmnnm.dll
C:\WINDOWS\system32\urgxfgvn.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\config.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\
0D1DFEA95445055F106B97A3E1A9ED3587B353FD.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\1370BA437EF5D05D058A24D054D8F5229852A4F4.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\25E530C0266043F06DDBF19083992C55D506A67D.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\552D2A66059C7009AF463B0B4E21D126E8F71E8D.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5D77D966848120E827ECF25D743E9AEA6B68CC1D.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5EF86C9EF2B49B00BBD097D27CCD2A19FBFD899C.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\cache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\cache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\contents\Exec.exe
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\contents\options.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\contents\updates.html
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\prompt.mtj
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\ViewpointManager\update.mtj
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\history.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate-akamai.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate.mtz
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\policy-akamai.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\policy.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\ServicesRegistry.xml
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\updates-akamai.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\updates.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\updates.mtz
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\vdt.dat
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\vmgrconfig-akamai.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\vmgrconfig.mtz
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Manager\NotifyData\header.gif
C:\Program Files\Viewpoint\Viewpoint Manager\NotifyData\no.gif
C:\Program Files\Viewpoint\Viewpoint Manager\NotifyData\options.ini
C:\Program Files\Viewpoint\Viewpoint Manager\NotifyData\updates.html
C:\Program Files\Viewpoint\Viewpoint Manager\NotifyData\yes.gif
C:\Program Files\Viewpoint\Viewpoint Manager\Read_Me.txt
C:\Program Files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCP.cpl
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
C:\WINDOWS\system32\atcfiunr.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-04 21:46 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-03 18:51 . 2001-08-23 06:00 50,620 --a------ C:\WINDOWS\system32\command.com.bak
2008-01-03 18:51 . 2004-07-06 11:59 2,577 --a------ C:\WINDOWS\system32\config.nt.bak
2008-01-03 18:51 . 2001-08-17 19:00 1,688 --a------ C:\WINDOWS\system32\AUTOEXEC.NT
2008-01-03 17:56 . 2008-01-04 18:11 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-29 10:23 . 2007-12-29 10:23 <DIR> d-------- C:\Documents and Settings\satisfied customer\Application Data\Leadertech
2007-12-27 18:54 . 2007-12-27 18:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-27 18:36 . 2007-12-27 18:36 <DIR> d-------- C:\Documents and Settings\satisfied customer\Application Data\TomTom
2007-12-25 22:09 . 2008-01-04 18:11 <DIR> d-------- C:\Program Files\Norman
2007-12-25 22:09 . 2007-09-17 15:24 212,024 --a------ C:\WINDOWS\system32\nscrnsav.scr
2007-12-25 22:09 . 2007-09-06 09:45 19,000 --a------ C:\WINDOWS\system32\drivers\nvcw32mf.sys
2007-12-23 23:01 . 2007-12-23 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-22 21:48 . 2007-09-18 00:29 138,512 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-22 21:48 . 2007-09-18 00:29 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2007-12-22 21:48 . 2007-09-18 00:29 52,368 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2007-12-22 21:33 . 2007-12-22 21:48 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-21 21:04 . 2007-12-21 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-20 22:13 . 2008-01-03 17:55 121 --a------ C:\WINDOWS\bdagent.INI
2007-12-20 21:33 . 2008-01-03 17:56 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2007-12-19 20:08 . 2007-12-19 21:38 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2007-12-17 13:25 . 2007-12-17 13:25 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2007-12-09 15:13 . 2007-12-09 15:13 <DIR> d-------- C:\Documents and Settings\satisfied customer\Contacts
2007-12-09 09:11 . 2007-12-09 09:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 02:27 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-04 02:27 --------- d-----w C:\Program Files\QuickTime
2008-01-04 02:27 --------- d-----w C:\Program Files\iTunes
2008-01-04 02:27 --------- d-----w C:\Program Files\Avvenu
2008-01-03 23:57 --------- d-----w C:\Program Files\PCPitstop
2007-12-28 00:54 --------- d-----w C:\Program Files\Lavasoft
2007-12-28 00:54 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 03:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2007-12-21 12:59 --------- d-----w C:\Program Files\a-squared Free
2007-12-21 03:33 --------- d-----w C:\Documents and Settings\satisfied customer\Application Data\Lavasoft
2007-12-20 02:04 --------- d-----w C:\Documents and Settings\amber\Application Data\SUPERAntiSpyware.com
2007-12-17 19:25 --------- d-----w C:\Program Files\Labtec
2007-12-09 20:16 --------- d-----w C:\Program Files\epson
2007-12-09 20:16 --------- d-----w C:\Program Files\Common Files\Labtec
2007-12-09 20:13 --------- d-----w C:\Program Files\NCH Swift Sound
2007-12-09 20:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-09 20:10 --------- d-----w C:\Program Files\Smart Panel
2007-11-30 23:22 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-30 23:21 --------- d-----w C:\Program Files\Windows Live Favorites
2007-11-30 23:21 --------- d-----w C:\Program Files\Real
2007-11-30 23:21 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-11-24 00:52 --------- d-----w C:\Program Files\TomTom HOME 2
2007-11-24 00:50 --------- d-----w C:\Documents and Settings\amber\Application Data\TomTom
2007-11-24 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2007-11-24 00:48 --------- d-----w C:\Documents and Settings\amber\Application Data\InstallShield
2007-11-24 00:47 --------- d-----w C:\Program Files\TomTom DesktopSuite
2007-11-16 01:14 --------- d-----w C:\Program Files\Yahoo!
2007-11-16 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-16 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-11-15 05:34 --------- d-----w C:\Documents and Settings\amber\Application Data\HP
2007-11-15 05:22 --------- d-----w C:\Program Files\HP
2007-11-15 05:22 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-11-15 05:22 --------- d-----w C:\Program Files\Common Files\HP
2007-11-15 05:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2007-11-15 05:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-11-15 05:20 --------- d-----w C:\Program Files\Hewlett-Packard
2007-11-15 04:05 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2005-05-12 05:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 19,968 2006-10-23 23:08:50 C:\Program Files\Avvenu\bak\Avvenu_updater.exe
----a-w 19,968 2006-10-23 23:08:50 C:\Program Files\Avvenu\Avvenu_updater.exe
----a-w 267,840 2007-02-12 15:17:02 C:\Program Files\BillP Studios\WinPatrol\bak\WinPatrol.exe
----a-w 267,840 2007-02-12 15:17:02 C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
----a-w 256,576 2006-10-30 15:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2006-10-30 15:36:36 C:\Program Files\iTunes\iTunesHelper.exe
----a-w 98,304 2004-07-07 16:46:09 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 98,304 2004-07-07 16:46:09 C:\Program Files\QuickTime\qttask.exe
----a-w 1,310,720 2007-02-27 17:39:26 C:\Program Files\SUPERAntiSpyware\bak\SUPERAntiSpyware.exe
----a-w 1,310,720 2007-02-27 17:39:26 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
----a-w 4,662,776 2006-12-01 03:49:04 C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59 224248]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-10-31 10:19 378784]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 17:48 488984]
"LogitechQuickCamRibbon"="C:\Program Files\Labtec\WebCam10\WebCam10.exe" [2007-03-06 17:58 1060376]
"Norman ZANDA"="C:\Program Files\Norman\Npm\bin\ZLH.exe" [2007-12-10 09:22 273520]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-23 10:50 185632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-05-02 01:19 49152]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmlii]
pmnmlii.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinScheduler.lnk
backup=C:\WINDOWS\pss\InterVideo WinScheduler.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^amber^Start Menu^Programs^Startup^Epson all-in-one Registration.lnk]
path=C:\Documents and Settings\amber\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk
backup=C:\WINDOWS\pss\Epson all-in-one Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^amber^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\amber\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
Mixer.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX4600 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 EPSON Stylus CX4600 Series /O6 USB002 /M Stylus CX4600
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-11-10 13:03 36975 --a------ C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
R0 si3112r;Silicon Image SiI 3512 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2004-08-27 15:18]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2004-05-20 16:35]
R2 CX23880;MSI 8606 Video Capture;C:\WINDOWS\system32\drivers\CX88Vid.SYS [2005-12-26 21:57]
R2 CX88XBAR;MSI 8606 Crossbar;C:\WINDOWS\system32\drivers\CX88XBar.SYS [2005-12-26 21:57]
R2 CXTUNE;MSI 8606 Tuner;C:\WINDOWS\system32\drivers\CX88Tune.SYS [2005-12-26 21:57]
R2 ETDrv;ETDrv;C:\WINDOWS\system32\drivers\ETDrv.sys [2003-08-07 11:39]
R2 Ndiskio;Ndiskio;C:\Program Files\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 09:55]
R2 NVOY;Norman's Very Own supplY of resources;"C:\Program Files\Norman\npm\bin\nvoy.exe" [2007-09-18 11:01]
R2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2003-04-14 18:58]
R3 MdpPortVDD;MdpPortVDD;C:\WINDOWS\System32\Drivers\MDP_VDD.SYS [2002-02-08 01:24]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-09-06 09:45]
R3 nvcoas;Norman Virus Control on-access component;"C:\Program Files\Norman\Nvc\bin\nvcoas.exe" [2007-12-10 14:36]
R3 NVCScheduler;Norman Virus Control Scheduler;"C:\Program Files\Norman\Npm\bin\NVCSCHED.EXE" [2007-09-18 11:41]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2003-04-14 18:58]
S3 MPCSYS;MPCSYS;C:\WINDOWS\System32\DRIVERS\mpcsys.sys [2006-05-10 16:48]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2004-03-30 11:29]
S3 XIRLINK;Veo PC Camera;C:\WINDOWS\system32\DRIVERS\ucdnt.sys [2002-04-08 10:57]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{add196b7-9315-11dc-b103-000d616ea853}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Microsoft Webcam Enhance V2.1]
C:\WINDOWS\runtfs32.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 03:15:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-05 03:05:00 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-04 21:49:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 21:49:55
ComboFix-quarantined-files.txt 2008-01-05 03:49:52