Oh, yeah. Oops. Sorry about that. Here is the ComboFix log.
ComboFix 09-03-10.03 - Jim 2009-03-14 16:29:43.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.1977 [GMT -7:00]
Running from: c:\documents and settings\Jim\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jim\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
C:\537925202
C:\cyieqw.exe
C:\mfvse.exe
c:\program files\Common Files\bfyxdl.dll
C:\tcrnwc.exe
C:\ucpdcu.exe
c:\windows\instsp1.exe
c:\windows\Jmudukogevus.dll
c:\windows\olimizuf.dll
c:\windows\oyananiy.dll
c:\windows\system32\drivers\e55263f7.sys
c:\windows\system32\kjr3iorojdnbfi43unjfd.dll
C:\yiar.exe
.
The following files were disabled during the run:
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\537925202
C:\cyieqw.exe
C:\mfvse.exe
c:\program files\Common Files\bfyxdl.dll
C:\tcrnwc.exe
C:\ucpdcu.exe
c:\windows\instsp1.exe
c:\windows\Jmudukogevus.dll
c:\windows\olimizuf.dll
c:\windows\oyananiy.dll
c:\windows\system32\drivers\e55263f7.sys
c:\windows\system32\kjr3iorojdnbfi43unjfd.dll
c:\windows\TEMP\ntdll64.dll
C:\yiar.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_yciwaovpxez
-------\Service_e55263f7
-------\Service_yciwaovpxez
((((((((((((((((((((((((( Files Created from 2009-02-14 to 2009-03-14 )))))))))))))))))))))))))))))))
.
2009-03-13 12:03 . 2009-03-13 12:03 <DIR> d-------- c:\documents and settings\Jim\Application Data\Ahead
2009-03-13 12:01 . 2009-03-13 12:01 <DIR> d-------- c:\program files\Nero
2009-03-13 12:01 . 2009-03-13 12:06 <DIR> d-------- c:\program files\Common Files\Ahead
2009-03-09 17:39 . 2009-03-09 17:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-03-09 15:07 . 2009-03-09 15:07 <DIR> d-------- c:\program files\Trend Micro
2009-03-09 15:04 . 2009-03-09 15:05 <DIR> d-------- c:\program files\ERUNT
2009-02-18 14:56 . 2009-02-18 14:56 <DIR> d-------- c:\windows\PrimoPDF4
2009-02-18 14:56 . 2009-02-18 14:56 <DIR> d-------- c:\program files\activePDF
2009-02-18 14:56 . 2006-12-11 14:12 176,235 --a------ c:\windows\system32\Primomonnt.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 23:37 --------- d-----w c:\program files\Symantec AntiVirus
2009-03-14 23:36 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-13 09:01 --------- d-----w c:\program files\Trillian
2009-03-12 23:16 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 23:16 --------- d-----w c:\program files\CyberLink
2009-03-10 00:39 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-07 20:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-07 07:12 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-14 06:41 --------- d-----w c:\documents and settings\Jim\Application Data\HP
2009-02-13 06:43 --------- d-----w c:\documents and settings\Jim\Application Data\Move Networks
2009-02-12 10:04 --------- d-----w c:\program files\AskBarDis
2009-02-12 03:52 --------- d-----w c:\program files\HP
2009-02-12 03:52 --------- d-----w c:\program files\Common Files\HP
2009-02-12 03:52 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2009-02-12 03:50 --------- d-----w c:\program files\Hewlett-Packard
2009-02-12 03:49 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-02-10 08:50 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-02-03 01:50 --------- d-----w c:\program files\Audacity
2009-02-02 07:01 --------- d-----w c:\program files\GameSpy
2009-02-02 06:59 --------- d-----w c:\documents and settings\Jim\Application Data\InstallShield
2009-02-02 06:21 --------- d-----w c:\documents and settings\Jim\Application Data\My Games
2009-02-02 04:21 --------- d-----w c:\program files\7-Zip
2009-01-31 03:23 --------- d-----w c:\program files\QuickTime
2009-01-14 09:52 --------- d-----w c:\program files\Google
2009-01-14 08:19 --------- d-s---w c:\program files\Xfire
2009-01-14 08:19 --------- d-----w c:\documents and settings\Jim\Application Data\Xfire
2009-01-14 07:19 --------- d-----w c:\program files\Firaxis Games
2009-01-14 06:07 --------- d-----w c:\program files\HWiNFO32
.
((((((((((((((((((((((((((((( SnapShot@2009-03-11_14.48.21.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\NuNInst.exe
- 2009-03-10 23:14:35 104,960 -c--a-w c:\windows\system32\dllcache\userinit.exe
+ 2008-04-14 00:12:38 26,112 -c--a-w c:\windows\system32\dllcache\userinit.exe
+ 2005-08-15 19:08:26 5,888 ----a-w c:\windows\system32\drivers\imagedrv.sys
+ 2005-08-15 19:08:26 127,488 ----a-w c:\windows\system32\drivers\imagesrv.sys
+ 2006-04-05 18:34:04 102,016 ----a-w c:\windows\system32\drivers\InCDfs.sys
+ 2006-04-05 18:34:22 29,568 ----a-w c:\windows\system32\drivers\InCDPass.sys
+ 2006-04-05 18:34:56 8,832 ----a-w c:\windows\system32\drivers\InCDrec.sys
+ 2006-04-05 18:34:36 33,792 ----a-w c:\windows\system32\drivers\InCDRm.sys
+ 2004-07-27 00:16:10 1,568,768 ----a-w c:\windows\system32\imagX7.dll
+ 2004-07-27 00:16:10 476,320 ----a-w c:\windows\system32\imagXpr7.dll
+ 2004-07-27 00:16:10 262,144 ----a-w c:\windows\system32\imagXR7.dll
+ 2004-07-27 00:16:10 471,040 ----a-w c:\windows\system32\imagXRA7.dll
+ 2005-02-16 22:18:04 90,184 ----a-w c:\windows\system32\NeroCo.dll
- 2009-03-11 21:16:06 58,613 ----a-w c:\windows\system32\nvModes.dat
+ 2009-03-14 23:27:10 63,253 ----a-w c:\windows\system32\nvModes.dat
+ 2004-07-09 16:43:56 364,544 ----a-w c:\windows\system32\TwnLib4.dll
- 2009-03-10 23:14:35 104,960 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-14 00:12:38 26,112 ----a-w c:\windows\system32\userinit.exe
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\UNNeroBackItUp.exe
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\UNNeroMediaHome.exe
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\UNNeroShowTime.exe
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\UNNeroVision.exe
+ 2005-09-12 23:13:46 233,472 ----a-w c:\windows\UNRecode.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-14 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-01 7561216]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-05-04 237568]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-11-07 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-06-14 124656]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2006-04-05 518144]
"nwiz"="nwiz.exe" [2006-05-01 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\Jim\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Jim\\My Documents\\Games\\Inspiration v3\\Inspiration v3\\Inspiration v3.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Documents and Settings\\Jim\\My Documents\\Games\\Inspiration v3\\Inspiration v3\\Inspiration v3\\Inspiration v3.exe"=
R2 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [2009-01-13 16616]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [2009-02-26 101936]
R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [2006-03-08 77952]
R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [2006-03-08 77952]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-06-14 115952]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa1e3a16-dbf4-11dd-b1e4-0016cfd78dfb}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{c5bf40a2-94f3-42bd-f434-1604812c8955} - c:\windows\system32\kjr3iorojdnbfi43unjfd.dll
HKLM-Run-Sjafiro - c:\windows\Jmudukogevus.dll
HKLM-Run-Jhakosita - c:\windows\oyananiy.dll
SharedTaskScheduler-{C5BF40A2-94F3-42BD-F434-1604812C8955} - c:\windows\system32\kjr3iorojdnbfi43unjfd.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://hotmail.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: c:\windows\TEMP\ntdll64.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-14 16:37:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
c:\windows\system32\rundll32.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\stacsv.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-14 16:42:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-14 23:42:16
ComboFix2.txt 2009-03-13 04:59:36
ComboFix3.txt 2009-03-11 21:49:16
Pre-Run: 37,587,746,816 bytes free
Post-Run: 38,130,147,328 bytes free
251 --- E O F --- 2009-03-08 11:01:15