This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Outerinfo

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

Download OTViewIt to your desktop.
  • Close all windows and open it
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here.
  • You may need to use two posts to get it all on the forum
Hello.
ComboFix installed an update and is now working, so I was able to drop CFScript onto it, and has produced a log:

ComboFix 08-08-23.03 - Jenny Luther Thomas 2008-08-24 16:01:15.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.119 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny Luther Thomas\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\drivers\c546e0dd.sys
.

((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.

2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-08-23 19:11 . 2004-08-09 00:54 d—s—- C:\Documents and Settings\Administrator\UserData
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-08-23 19:11 . 2008-08-23 19:12 d——– C:\Documents and Settings\Administrator
2008-08-19 20:46 . 2008-08-19 20:46 d——– C:\Program Files\Trend Micro
2008-08-19 18:38 . 2008-08-19 18:38 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\skypePM
2008-08-19 18:38 . 2008-08-19 18:38 56 –ah—– C:\WINDOWS\system32\ezsidmv.dat
2008-08-19 18:36 . 2008-08-19 18:36 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-08-18 19:42 . 2003-04-21 13:09 245,408 –a—— C:\WINDOWS\Unicows.dll
2008-08-18 19:42 . 2004-02-16 17:15 15,541 –a—— C:\WINDOWS\snpstd.ini
2008-08-18 19:42 . 2003-01-17 16:35 13,023 –a—— C:\WINDOWS\snpstd.src
2008-08-16 22:16 . 2008-08-16 23:09 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Skinux
2008-08-16 22:16 . 2008-08-16 22:16 d——– C:\Documents and Settings\All Users\Application Data\BT
2008-08-08 14:21 . 2008-08-08 14:21 13,502 –a—— C:\WINDOWS\system32\JambaIconFR.ico
2008-08-08 14:21 . 2008-08-08 14:21 4,286 –a—— C:\WINDOWS\system32\Jamster.ico
2008-08-06 17:45 . 2008-08-06 17:45 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-08-06 17:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 17:44 . 2008-08-06 17:44 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-07-30 20:14 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 17:44 . 2008-07-30 20:14 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 15:03 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Onfolio
2008-08-24 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-18 18:42 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-16 21:57 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Yahoo!
2008-08-16 21:16 ——— d—–w C:\Program Files\BT Broadband Talk Softphone
2008-08-16 21:12 ——— d—–w C:\Program Files\FinePixViewer
2008-08-16 15:12 ——— d—–w C:\Program Files\Yahoo!
2008-08-16 14:46 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-15 16:52 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Onfolio
2008-07-19 11:04 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Onfolio
2008-07-19 10:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-07-18 18:54 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia Multimedia Player
2008-07-18 18:32 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia
2008-07-17 08:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\PC Suite
2008-07-08 15:02 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-07-08 15:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\UDL
2008-07-08 14:59 ——— d—–w C:\Program Files\epson
2008-07-08 14:58 ——— d—–w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-07-08 14:55 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\InstallShield
2008-07-08 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\EPSON
2008-07-04 00:11 ——— d—–w C:\Program Files\Google
2008-07-03 23:47 ——— d—–w C:\Program Files\RegCure
2008-06-27 14:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Yahoo!
2008-06-24 18:28 ——— d—–w C:\Program Files\Belkin
2006-04-11 15:22 774,144 -c–a-w C:\Program Files\RngInterstitial.dll
2005-10-02 10:49 315 -c–a-w C:\Program Files\Myopoly5.log
2005-10-02 10:41 30,054 -c–a-w C:\Program Files\GOODNEWS.4BMP
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.6bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.5bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.4bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\GoodNews.0bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\badnews.2bmp
2005-10-02 10:33 249 -c–a-w C:\Program Files\Myopoly5.ini
2005-02-02 23:28 1,544 -c–a-w C:\Program Files\Common Files\highlight.rew
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-07 00:49 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"BTAgile"="C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe" [2008-05-22 20:22 61440]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-03-01 19:11 4670968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15 106496]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22 249856]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2003-12-31 17:39 40960]
"OnfolioStorage"="C:\Program Files\Onfolio\onfserv.exe" [2006-03-07 14:53 51928]
"JobHisInit"="C:\Program Files\RDS\RMClient\JobHisInit.exe" [2005-11-01 10:52 151552]
"MplSetUp"="C:\Program Files\RDS\RMClient\MplSetUp.exe" [2005-06-01 01:59 40960]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-08-08 12:40 652528]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-15 23:37 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 08:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BT Broadband Desktop Help.lnk - C:\Program Files\BTHomeHub\Help\bin\matcli.exe [2008-01-13 22:27:43 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-01 22:06 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=C:\WINDOWS\pss\Exif Launcher 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartDeviceMonitor for Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartDeviceMonitor for Client.lnk
backup=C:\WINDOWS\pss\SmartDeviceMonitor for Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
–a—— 2006-12-08 07:45 543232 C:\Program Files\btbb_wcm\McciTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-02-06 19:52 462935 C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
——— 2002-02-04 22:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-06-15 23:37 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-03-01 19:11 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
——— 2004-08-04 08:56 110592 C:\WINDOWS\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-14 15:47 67072 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Caplio Software\\RGateLXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"=

S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2005-05-09 20:22]
.
Contents of the 'Scheduled Tasks' folder

2008-05-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2008-08-15 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-19 00:42]

2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]

2008-07-10 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 16:06:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-24 16:16:15
ComboFix-quarantined-files.txt 2008-08-24 15:16:06
ComboFix2.txt 2008-08-24 14:55:12
ComboFix3.txt 2008-08-21 01:18:50

Pre-Run: 162,258,137,088 bytes free
Post-Run: 162,223,960,064 bytes free

206 — E O F — 2008-08-15 18:36:33


I'm currently scanning with Kapersky, but it's taking a very long time and will post that log when it's completed.
Do this as well please

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Sunday, August 24, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, August 24, 2008 16:20:21 Records in database: 1140664 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Files scanned: 143729 Threat name: 5 Infected objects: 6 Suspicious objects: 0 Duration of the scan: 02:03:48 File name / Threat name / Threats count C:\Program Files\Visp\RyDial.dll Infected: not-a-virus:Dialer.Win32.RyDial.a 1 C:\Program Files\Visp\Upgrade.exe Infected: not-a-virus:Dialer.Win32.RyDial.a 1 C:\QooBox\Quarantine\C\WINDOWS\ASEMBL~1\υserinit.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.id 1 C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\c546e0dd.sys.vir Infected: Trojan.Win32.Multis.cp 1 C:\QooBox\Quarantine\C\WINDOWS\system32\RACLE~1\rundll.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.ek 1 C:\WINDOWS\system32\oins.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ho 1 The selected area was scanned.
Ok do the SDFix step then do this

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Outerinfo_t9…15&start=15

File::
C:\Program Files\Visp\RyDial.dll
C:\Program Files\Visp\Upgrade.exe
C:\WINDOWS\system32\oins.exe


Collect::
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\c546e0dd.sys.vir

Suspect::


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.
SDFix: Version 1.219
Run by [removed] on 24/08/2008 at 20:01

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\oins.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 20:13:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\000a3a64e7a7]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a64e7a7]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a64e7a7]

scanning hidden registry entries …

scanning hidden files …

C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:RTC App Sharing"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\Caplio Software\\RGateLXP.exe"="C:\\Program Files\\Caplio Software\\RGateLXP.exe:*:Enabled:RICOH Gate La for DSC"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"="C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe:*:Enabled:BTSoftphone"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 16 Oct 2004 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 12 Mar 2005 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Sat 16 Oct 2004 401 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv12.bak"
Wed 14 Jun 2006 41,472 …H. — "C:\Documents and Settings\Jenny Luther Thomas\My Documents\~WRL0001.tmp"
Mon 18 Jun 2007 22,528 …H. — "C:\Documents and Settings\Jenny Luther Thomas\My Documents\~WRL0666.tmp"
Mon 18 Jun 2007 23,552 …H. — "C:\Documents and Settings\Jenny Luther Thomas\My Documents\~WRL2610.tmp"
Thu 27 Sep 2007 73,728 …H. — "C:\Program Files\BTHomeHub\Launcher\BTCommon.dll"
Thu 27 Sep 2007 376,832 …H. — "C:\Program Files\BTHomeHub\Launcher\ThomsonSupport.dll"
Wed 6 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sat 18 Feb 2006 30,208 …H. — "C:\Documents and Settings\Jenny Luther Thomas\My Documents\General\~WRL0004.tmp"
Fri 9 May 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT5BE.tmp"
Thu 24 Aug 2006 40,960 …H. — "C:\Documents and Settings\David Luther Thomas\Application Data\Microsoft\Word\~WRL0004.tmp"
Thu 24 Aug 2006 39,936 …H. — "C:\Documents and Settings\David Luther Thomas\Application Data\Microsoft\Word\~WRL3223.tmp"
Mon 12 Dec 2005 27,136 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Application Data\Microsoft\Templates\~WRL2692.tmp"
Sat 20 May 2006 23,552 …H. — "C:\Documents and Settings\Marc Luther Thomas\Application Data\Microsoft\Word\~WRL0003.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0001.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0002.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0003.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0004.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0005.tmp"
Fri 17 Jun 2005 19,456 …H. — "C:\Documents and Settings\Jenny Luther Thomas\Local Settings\Application Data\Macromedia\Macromedia FlashPaper\OfficeTemplates\~WRL0006.tmp"

Finished!




That's the log from SDFix
ComboFix 08-08-23.03 - Jenny Luther Thomas 2008-08-24 20:52:47.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.110 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny Luther Thomas\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\drivers\c546e0dd.sys
.

((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.

2008-08-24 19:55 . 2008-08-24 19:55 d——– C:\WINDOWS\ERUNT
2008-08-24 19:45 . 2008-08-24 20:17 d——– C:\SDFix
2008-08-24 16:34 . 2008-08-24 16:34 d——– C:\WINDOWS\Sun
2008-08-24 16:29 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-24 16:28 . 2008-08-24 16:29 d——– C:\Program Files\Java
2008-08-24 16:25 . 2008-08-24 16:25 d——– C:\Program Files\Common Files\Java
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-08-23 19:11 . 2004-08-09 00:54 d—s—- C:\Documents and Settings\Administrator\UserData
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-08-23 19:11 . 2008-08-23 19:12 d——– C:\Documents and Settings\Administrator
2008-08-19 20:46 . 2008-08-19 20:46 d——– C:\Program Files\Trend Micro
2008-08-19 18:38 . 2008-08-19 18:38 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\skypePM
2008-08-19 18:38 . 2008-08-19 18:38 56 –ah—– C:\WINDOWS\system32\ezsidmv.dat
2008-08-19 18:36 . 2008-08-19 18:36 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-08-18 19:42 . 2003-04-21 13:09 245,408 –a—— C:\WINDOWS\Unicows.dll
2008-08-18 19:42 . 2004-02-16 17:15 15,541 –a—— C:\WINDOWS\snpstd.ini
2008-08-18 19:42 . 2003-01-17 16:35 13,023 –a—— C:\WINDOWS\snpstd.src
2008-08-16 22:16 . 2008-08-16 23:09 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Skinux
2008-08-16 22:16 . 2008-08-16 22:16 d——– C:\Documents and Settings\All Users\Application Data\BT
2008-08-08 14:21 . 2008-08-08 14:21 13,502 –a—— C:\WINDOWS\system32\JambaIconFR.ico
2008-08-08 14:21 . 2008-08-08 14:21 4,286 –a—— C:\WINDOWS\system32\Jamster.ico
2008-08-06 17:45 . 2008-08-06 17:45 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-08-06 17:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 17:44 . 2008-08-06 17:44 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-07-30 20:14 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 17:44 . 2008-07-30 20:14 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 19:48 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Onfolio
2008-08-24 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-18 18:42 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-16 21:57 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Yahoo!
2008-08-16 21:16 ——— d—–w C:\Program Files\BT Broadband Talk Softphone
2008-08-16 21:12 ——— d—–w C:\Program Files\FinePixViewer
2008-08-16 15:12 ——— d—–w C:\Program Files\Yahoo!
2008-08-16 14:46 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-15 16:52 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Onfolio
2008-07-19 11:04 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Onfolio
2008-07-19 10:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-07-18 18:54 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia Multimedia Player
2008-07-18 18:32 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia
2008-07-17 08:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\PC Suite
2008-07-08 15:02 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-07-08 15:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\UDL
2008-07-08 14:59 ——— d—–w C:\Program Files\epson
2008-07-08 14:58 ——— d—–w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-07-08 14:55 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\InstallShield
2008-07-08 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\EPSON
2008-07-04 00:11 ——— d—–w C:\Program Files\Google
2008-07-03 23:47 ——— d—–w C:\Program Files\RegCure
2008-06-27 14:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Yahoo!
2008-06-24 18:28 ——— d—–w C:\Program Files\Belkin
2006-04-11 15:22 774,144 -c–a-w C:\Program Files\RngInterstitial.dll
2005-10-02 10:49 315 -c–a-w C:\Program Files\Myopoly5.log
2005-10-02 10:41 30,054 -c–a-w C:\Program Files\GOODNEWS.4BMP
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.6bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.5bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.4bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\GoodNews.0bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\badnews.2bmp
2005-10-02 10:33 249 -c–a-w C:\Program Files\Myopoly5.ini
2005-02-02 23:28 1,544 -c–a-w C:\Program Files\Common Files\highlight.rew
.

((((((((((((((((((((((((((((( snapshot@2008-08-21_ 2.18.16.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-24 18:56:12 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-08-24 18:56:13 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-08-24 18:55:58 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-08-24 18:55:58 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-06-10 00:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 00:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 01:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-07 00:49 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"BTAgile"="C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe" [2008-05-22 20:22 61440]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-03-01 19:11 4670968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15 106496]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22 249856]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2003-12-31 17:39 40960]
"OnfolioStorage"="C:\Program Files\Onfolio\onfserv.exe" [2006-03-07 14:53 51928]
"JobHisInit"="C:\Program Files\RDS\RMClient\JobHisInit.exe" [2005-11-01 10:52 151552]
"MplSetUp"="C:\Program Files\RDS\RMClient\MplSetUp.exe" [2005-06-01 01:59 40960]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-08-08 12:40 652528]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-15 23:37 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 08:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BT Broadband Desktop Help.lnk - C:\Program Files\BTHomeHub\Help\bin\matcli.exe [2008-01-13 22:27:43 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-01 22:06 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=C:\WINDOWS\pss\Exif Launcher 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartDeviceMonitor for Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartDeviceMonitor for Client.lnk
backup=C:\WINDOWS\pss\SmartDeviceMonitor for Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
–a—— 2006-12-08 07:45 543232 C:\Program Files\btbb_wcm\McciTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-02-06 19:52 462935 C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
——— 2002-02-04 22:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-06-15 23:37 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-03-01 19:11 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
——— 2004-08-04 08:56 110592 C:\WINDOWS\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-14 15:47 67072 C:\WINDOWS\SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Caplio Software\\RGateLXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"=

S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2005-05-09 20:22]
.
Contents of the 'Scheduled Tasks' folder

2008-05-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2008-08-15 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-19 00:42]

2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]

2008-07-10 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 20:57:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-24 21:07:43
ComboFix-quarantined-files.txt 2008-08-24 20:07:38
ComboFix2.txt 2008-08-24 15:16:16
ComboFix3.txt 2008-08-24 14:55:12
ComboFix4.txt 2008-08-21 01:18:50

Pre-Run: 161,954,852,864 bytes free
Post-Run: 161,921,069,056 bytes free

224 — E O F — 2008-08-15 18:36:33
ComboFix 08-08-23.03 - Jenny Luther Thomas 2008-08-24 22:44:22.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.177 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny Luther Thomas\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Program Files\Visp\RyDial.dll
C:\Program Files\Visp\Upgrade.exe
C:\WINDOWS\system32\oins.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Visp\RyDial.dll
C:\Program Files\Visp\Upgrade.exe

.
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.

2008-08-24 19:55 . 2008-08-24 19:55 d——– C:\WINDOWS\ERUNT
2008-08-24 19:45 . 2008-08-24 20:17 d——– C:\SDFix
2008-08-24 16:34 . 2008-08-24 16:34 d——– C:\WINDOWS\Sun
2008-08-24 16:29 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-24 16:28 . 2008-08-24 16:29 d——– C:\Program Files\Java
2008-08-24 16:25 . 2008-08-24 16:25 d——– C:\Program Files\Common Files\Java
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-08-23 19:11 . 2004-08-09 00:54 d—s—- C:\Documents and Settings\Administrator\UserData
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-08-23 19:11 . 2008-08-23 19:12 d——– C:\Documents and Settings\Administrator
2008-08-19 20:46 . 2008-08-19 20:46 d——– C:\Program Files\Trend Micro
2008-08-19 18:38 . 2008-08-19 18:38 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\skypePM
2008-08-19 18:38 . 2008-08-19 18:38 56 –ah—– C:\WINDOWS\system32\ezsidmv.dat
2008-08-19 18:36 . 2008-08-19 18:36 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-08-18 19:42 . 2003-04-21 13:09 245,408 –a—— C:\WINDOWS\Unicows.dll
2008-08-18 19:42 . 2004-02-16 17:15 15,541 –a—— C:\WINDOWS\snpstd.ini
2008-08-18 19:42 . 2003-01-17 16:35 13,023 –a—— C:\WINDOWS\snpstd.src
2008-08-16 22:16 . 2008-08-16 23:09 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Skinux
2008-08-16 22:16 . 2008-08-16 22:16 d——– C:\Documents and Settings\All Users\Application Data\BT
2008-08-08 14:21 . 2008-08-08 14:21 13,502 –a—— C:\WINDOWS\system32\JambaIconFR.ico
2008-08-08 14:21 . 2008-08-08 14:21 4,286 –a—— C:\WINDOWS\system32\Jamster.ico
2008-08-06 17:45 . 2008-08-06 17:45 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-08-06 17:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 17:44 . 2008-08-06 17:44 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-07-30 20:14 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 17:44 . 2008-07-30 20:14 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 21:44 ——— d—–w C:\Program Files\Visp
2008-08-24 21:18 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Onfolio
2008-08-24 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-18 18:42 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-16 21:57 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Yahoo!
2008-08-16 21:16 ——— d—–w C:\Program Files\BT Broadband Talk Softphone
2008-08-16 21:12 ——— d—–w C:\Program Files\FinePixViewer
2008-08-16 15:12 ——— d—–w C:\Program Files\Yahoo!
2008-08-16 14:46 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-15 16:52 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Onfolio
2008-07-19 11:04 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Onfolio
2008-07-19 10:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-07-18 18:54 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia Multimedia Player
2008-07-18 18:32 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia
2008-07-17 08:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\PC Suite
2008-07-08 15:02 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-07-08 15:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\UDL
2008-07-08 14:59 ——— d—–w C:\Program Files\epson
2008-07-08 14:58 ——— d—–w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-07-08 14:55 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\InstallShield
2008-07-08 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\EPSON
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 00:11 ——— d—–w C:\Program Files\Google
2008-07-03 23:47 ——— d—–w C:\Program Files\RegCure
2008-06-27 14:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Yahoo!
2008-06-24 18:28 ——— d—–w C:\Program Files\Belkin
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2006-04-11 15:22 774,144 -c–a-w C:\Program Files\RngInterstitial.dll
2005-10-02 10:49 315 -c–a-w C:\Program Files\Myopoly5.log
2005-10-02 10:41 30,054 -c–a-w C:\Program Files\GOODNEWS.4BMP
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.6bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.5bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.4bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\GoodNews.0bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\badnews.2bmp
2005-10-02 10:33 249 -c–a-w C:\Program Files\Myopoly5.ini
2005-02-02 23:28 1,544 -c–a-w C:\Program Files\Common Files\highlight.rew
.

((((((((((((((((((((((((((((( snapshot@2008-08-21_ 2.18.16.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-24 18:56:12 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-08-24 18:56:13 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-08-24 18:55:58 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-08-24 18:55:58 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-06-10 00:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 00:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 01:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-07 00:49 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"BTAgile"="C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe" [2008-05-22 20:22 61440]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-03-01 19:11 4670968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15 106496]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22 249856]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2003-12-31 17:39 40960]
"OnfolioStorage"="C:\Program Files\Onfolio\onfserv.exe" [2006-03-07 14:53 51928]
"JobHisInit"="C:\Program Files\RDS\RMClient\JobHisInit.exe" [2005-11-01 10:52 151552]
"MplSetUp"="C:\Program Files\RDS\RMClient\MplSetUp.exe" [2005-06-01 01:59 40960]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-08-08 12:40 652528]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-15 23:37 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 08:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BT Broadband Desktop Help.lnk - C:\Program Files\BTHomeHub\Help\bin\matcli.exe [2008-01-13 22:27:43 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-01 22:06 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=C:\WINDOWS\pss\Exif Launcher 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartDeviceMonitor for Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartDeviceMonitor for Client.lnk
backup=C:\WINDOWS\pss\SmartDeviceMonitor for Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
–a—— 2006-12-08 07:45 543232 C:\Program Files\btbb_wcm\McciTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-02-06 19:52 462935 C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
——— 2002-02-04 22:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-06-15 23:37 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-03-01 19:11 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
——— 2004-08-04 08:56 110592 C:\WINDOWS\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-14 15:47 67072 C:\WINDOWS\SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Caplio Software\\RGateLXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"=

S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2005-05-09 20:22]
.
Contents of the 'Scheduled Tasks' folder

2008-05-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2008-08-15 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-19 00:42]

2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]

2008-07-10 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 22:49:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-24 22:57:53
ComboFix-quarantined-files.txt 2008-08-24 21:57:46
ComboFix2.txt 2008-08-24 20:07:43
ComboFix3.txt 2008-08-24 15:16:16
ComboFix4.txt 2008-08-24 14:55:12
ComboFix5.txt 2008-08-24 21:43:40

Pre-Run: 161,914,970,112 bytes free
Post-Run: 161,880,559,616 bytes free

237 — E O F — 2008-08-15 18:36:33


When the browser opened it said it couldn't find a file.
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

Folder::

DirLook::
C:\Program Files\Visp

SkipFix::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
ComboFix 08-08-23.03 - Jenny Luther Thomas 2008-08-24 23:21:07.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.157 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny Luther Thomas\Desktop\CFScript.txt
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.

2008-08-24 19:55 . 2008-08-24 19:55 d——– C:\WINDOWS\ERUNT
2008-08-24 19:45 . 2008-08-24 20:17 d——– C:\SDFix
2008-08-24 16:34 . 2008-08-24 16:34 d——– C:\WINDOWS\Sun
2008-08-24 16:29 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-24 16:28 . 2008-08-24 16:29 d——– C:\Program Files\Java
2008-08-24 16:25 . 2008-08-24 16:25 d——– C:\Program Files\Common Files\Java
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-08-23 19:11 . 2004-08-09 00:54 d—s—- C:\Documents and Settings\Administrator\UserData
2008-08-23 19:11 . 2004-08-09 00:54 d——– C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-08-23 19:11 . 2008-08-23 19:12 d——– C:\Documents and Settings\Administrator
2008-08-19 20:46 . 2008-08-19 20:46 d——– C:\Program Files\Trend Micro
2008-08-19 18:38 . 2008-08-19 18:38 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\skypePM
2008-08-19 18:38 . 2008-08-19 18:38 56 –ah—– C:\WINDOWS\system32\ezsidmv.dat
2008-08-19 18:36 . 2008-08-19 18:36 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-08-18 19:42 . 2003-04-21 13:09 245,408 –a—— C:\WINDOWS\Unicows.dll
2008-08-18 19:42 . 2004-02-16 17:15 15,541 –a—— C:\WINDOWS\snpstd.ini
2008-08-18 19:42 . 2003-01-17 16:35 13,023 –a—— C:\WINDOWS\snpstd.src
2008-08-16 22:16 . 2008-08-16 23:09 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Skinux
2008-08-16 22:16 . 2008-08-16 22:16 d——– C:\Documents and Settings\All Users\Application Data\BT
2008-08-08 14:21 . 2008-08-08 14:21 13,502 –a—— C:\WINDOWS\system32\JambaIconFR.ico
2008-08-08 14:21 . 2008-08-08 14:21 4,286 –a—— C:\WINDOWS\system32\Jamster.ico
2008-08-06 17:45 . 2008-08-06 17:45 d——– C:\Documents and Settings\Jenny Luther Thomas\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-08-06 17:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 17:44 . 2008-08-06 17:44 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-06 17:44 . 2008-07-30 20:14 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-06 17:44 . 2008-07-30 20:14 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 21:55 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Onfolio
2008-08-24 21:44 ——— d—–w C:\Program Files\Visp
2008-08-24 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-18 18:42 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-16 21:57 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\Yahoo!
2008-08-16 21:16 ——— d—–w C:\Program Files\BT Broadband Talk Softphone
2008-08-16 21:12 ——— d—–w C:\Program Files\FinePixViewer
2008-08-16 15:12 ——— d—–w C:\Program Files\Yahoo!
2008-08-16 14:46 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-15 16:52 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Onfolio
2008-07-19 11:04 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Onfolio
2008-07-19 10:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-07-18 18:54 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia Multimedia Player
2008-07-18 18:32 ——— d—–w C:\Documents and Settings\Marc Luther Thomas\Application Data\Nokia
2008-07-17 08:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\PC Suite
2008-07-08 15:02 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-07-08 15:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\UDL
2008-07-08 14:59 ——— d—–w C:\Program Files\epson
2008-07-08 14:58 ——— d—–w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-07-08 14:55 ——— d—–w C:\Documents and Settings\Jenny Luther Thomas\Application Data\InstallShield
2008-07-08 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\EPSON
2008-07-04 00:11 ——— d—–w C:\Program Files\Google
2008-07-03 23:47 ——— d—–w C:\Program Files\RegCure
2008-06-27 14:45 ——— d—–w C:\Documents and Settings\David Luther Thomas\Application Data\Yahoo!
2008-06-24 18:28 ——— d—–w C:\Program Files\Belkin
2006-04-11 15:22 774,144 -c–a-w C:\Program Files\RngInterstitial.dll
2005-10-02 10:49 315 -c–a-w C:\Program Files\Myopoly5.log
2005-10-02 10:41 30,054 -c–a-w C:\Program Files\GOODNEWS.4BMP
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.6bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.5bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\image.4bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\GoodNews.0bmp
2005-10-02 10:33 30,054 -c–a-w C:\Program Files\badnews.2bmp
2005-10-02 10:33 249 -c–a-w C:\Program Files\Myopoly5.ini
2005-02-02 23:28 1,544 -c–a-w C:\Program Files\Common Files\highlight.rew
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\Visp —-

2008-08-15 11:12 336 –a—— C:\Program Files\Visp\Rydial.cfg
2003-05-24 15:48 601 –a—— C:\Program Files\Visp\RyDial.ini
2003-05-22 15:01 7876 –a–c— C:\Program Files\Visp\Dialler.HTM
2003-05-20 22:20 176 –a–c— C:\Program Files\Visp\RyRas.dta
2003-05-15 13:51 18552 –a–c— C:\Program Files\Visp\logo.bmp
2003-05-09 16:33 2998 –a–c— C:\Program Files\Visp\RyDial.ico
2003-04-30 16:57 1556 –a—— C:\Program Files\Visp\DialPlan.dta


((((((((((((((((((((((((((((( snapshot@2008-08-21_ 2.18.16.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-24 18:56:12 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-08-24 18:56:13 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-08-24 18:55:58 9,310,208 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-08-24 18:55:58 749,568 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-06-10 00:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 00:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 01:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-07 00:49 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"BTAgile"="C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe" [2008-05-22 20:22 61440]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-03-01 19:11 4670968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15 106496]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22 249856]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2003-12-31 17:39 40960]
"OnfolioStorage"="C:\Program Files\Onfolio\onfserv.exe" [2006-03-07 14:53 51928]
"JobHisInit"="C:\Program Files\RDS\RMClient\JobHisInit.exe" [2005-11-01 10:52 151552]
"MplSetUp"="C:\Program Files\RDS\RMClient\MplSetUp.exe" [2005-06-01 01:59 40960]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-08-08 12:40 652528]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-15 23:37 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 08:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BT Broadband Desktop Help.lnk - C:\Program Files\BTHomeHub\Help\bin\matcli.exe [2008-01-13 22:27:43 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-01 22:06 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=C:\WINDOWS\pss\Exif Launcher 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartDeviceMonitor for Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartDeviceMonitor for Client.lnk
backup=C:\WINDOWS\pss\SmartDeviceMonitor for Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
–a—— 2006-12-08 07:45 543232 C:\Program Files\btbb_wcm\McciTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-02-06 19:52 462935 C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
——— 2002-02-04 22:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-06-15 23:37 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-03-01 19:11 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
——— 2004-08-04 08:56 110592 C:\WINDOWS\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-14 15:47 67072 C:\WINDOWS\SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Caplio Software\\RGateLXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"=

S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2005-05-09 20:22]
.
Contents of the 'Scheduled Tasks' folder

2008-05-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2008-08-15 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-19 00:42]

2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]

2008-07-10 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 22:21]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 23:21:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-24 23:31:34
ComboFix-quarantined-files.txt 2008-08-24 22:31:31
ComboFix2.txt 2008-08-24 21:57:54
ComboFix3.txt 2008-08-24 20:07:43
ComboFix4.txt 2008-08-24 15:16:16
ComboFix5.txt 2008-08-24 22:20:33

Pre-Run: 161,872,564,224 bytes free
Post-Run: 161,841,975,296 bytes free

236 — E O F — 2008-08-15 18:36:33








Just waiting for MBAM

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI