Ok evilfantasy, thanks. Here goes......
The Autoplay box appeared for about 20 to 30 times whilst the AutoScan programme was running. At one stage the task bar showed windows explorer with a 6 in front of it. Presumably the number of instances the Autoplay was running.
Hope it makes sense to you.....Cheers Frank
ComboFix 07-11-08.3 - Cliffnook 2007-11-14 6:18:40.1 - NTFSx86
Running from: C:\Documents and Settings\Cliffnook\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files.\hotbar.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 )))))))))))))))))))))))))))))))
.
2007-11-14 06:16 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-14 05:54 <DIR> d-------- C:\WINDOWS\LastGood
2007-11-14 05:54 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-14 05:54 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-11-13 09:54 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2007-11-13 09:52 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-11-13 09:48 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-11-13 06:57 <DIR> d-------- C:\Documents and Settings\Cliffnook\SecurityScans
2007-11-13 06:56 <DIR> d-------- C:\Program Files\Microsoft Baseline Security Analyzer 2
2007-11-12 07:09 <DIR> d-------- C:\Documents and Settings\Cliffnook\Application Data\Oberon Media
2007-11-12 06:49 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-09 09:40 <DIR> d-------- C:\Documents and Settings\Cliffnook\Application Data\VSRevoGroup
2007-11-09 09:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\RFA_Backups
2007-11-07 06:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MinigolfAdventures
2007-11-05 06:50 <DIR> d-------- C:\Documents and Settings\Cliffnook\Application Data\ForgottenRiddles
2007-11-01 09:39 <DIR> d-------- C:\Program Files\NovaLogic
2007-10-31 06:22 <DIR> d-------- C:\Program Files\Oberon Media
2007-10-23 05:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Innovative Solutions
2007-10-22 06:14 <DIR> d-------- C:\Program Files\VS Revo Group
2007-10-22 06:11 <DIR> d-------- C:\Program Files\Your Uninstaller 2006
2007-10-22 06:11 <DIR> d-------- C:\Documents and Settings\Cliffnook\Application Data\URSoft
2007-10-19 06:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2007-10-18 09:36 <DIR> d-------- C:\Program Files\CCleaner
2007-10-16 06:19 <DIR> d-------- C:\Program Files\Croteam
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 10:46 --------- d-----w C:\Program Files\SpywareBlaster
2007-11-13 10:41 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-12 07:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-12 07:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Oberon Media
2007-11-09 10:29 --------- d-----w C:\Program Files\Betfred Poker
2007-11-09 09:34 --------- d-----w C:\Program Files\Common Files\Oberon Media
2007-11-09 09:34 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\Pogo Games
2007-11-09 09:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-11-07 08:07 --------- d-----w C:\Program Files\Microsoft Money
2007-11-05 06:13 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\PlayFirst
2007-10-23 08:44 --------- d-----w C:\Program Files\PhotoDeluxe 2.0
2007-10-23 08:44 --------- d-----w C:\Program Files\Classic PhoneTools
2007-10-22 08:43 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\PokerChamps
2007-10-22 03:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll
2007-10-12 15:14 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll
2007-10-12 15:14 1,374,232 ----a-w C:\WINDOWS\system32\D3DCompiler_36.dll
2007-10-12 10:31 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\AstroMenace
2007-10-02 09:56 444,776 ----a-w C:\WINDOWS\system32\d3dx10_36.dll
2007-10-02 07:56 --------- d-----w C:\Program Files\Google
2007-10-01 05:47 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\VeniceMysteryData
2007-09-28 08:25 --------- d-----w C:\Program Files\Family Tree Maker 2006
2007-09-24 07:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SugarGames
2007-09-20 12:16 --------- d-----w C:\Program Files\PacificPoker4
2007-09-20 12:12 --------- d-----w C:\Program Files\PacificPoker
2007-09-14 06:36 --------- d-----w C:\Documents and Settings\Cliffnook\Application Data\Big Fish Games
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-01 13:25 7,802 ----a-w C:\Documents and Settings\Cliffnook\Application Data\wklnhst.dat
2006-08-25 08:24 1,388 ----a-w C:\Documents and Settings\Cliffnook\Application Data\ViewerApp.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 14:16]
"nwiz"="nwiz.exe" [2003-10-06 14:16 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2002-08-15 10:46 C:\WINDOWS\SOUNDMAN.EXE]
"Dit"="Dit.exe" [2002-08-28 12:43 C:\WINDOWS\Dit.exe]
"NeroCheck"="C:\WINDOWS\System32\NeroCheck.exe" [2001-07-09 09:50]
"Agent"="C:\Program Files\Medion\PowerCinema\My_TV\Agent.exe" [2002-09-26 15:49]
"CapFax"="C:\Program Files\Classic PhoneTools\CapFax.EXE" [2001-12-10 16:34]
"POINTER"="point32.exe" []
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-09 23:11]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-26 05:37]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-12-17 23:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-12 08:54]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 13:25]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 13:45]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 06:46]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 17:02]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 11:18]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 14:16]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 11:00]
"STManager"="C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" [2003-10-16 13:25]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
C:\Documents and Settings\Cliffnook\Start Menu\Programs\Startup\
FAXRX.lnk - C:\Program Files\Brother\Brmfl06a\FAXRX.exe [2007-09-05 07:43:46]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\
02.05.0001.1119\en-gb\bin\WindowsSearch.exe [2005-09-20 17:10:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2003-07-22 10:39:53]
R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys
R3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys
S2 UMAXPCLS;Print Port Scanner Driver;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe"
S3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys
S3 IIUSBISP;USB Mass Storage for USB ISP;C:\WINDOWS\system32\Drivers\iiusbisp.sys
S3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys
S3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-14 06:21:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 6:22:09
.
--- E O F ---