OK hers the Combo Fix with CFScript Log…….
All seems ok, but I still can't get windows or antivirus updates…
ComboFix 08-12-06.01 - Owner 2008-12-06 13:40:27.2 - NTFSx86
Running from: c:\documents and settings\[removed]\My Documents\Dougs Stuff\downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FILE ::
c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
c:\program files\ErrorRepairTool\ErrorRepairTool.exe
c:\program files\Grisoft\AVG Free\bak\avgcc.exe
c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
c:\program files\HP\Digital Imaging\bin\BackupNotify.exe
c:\program files\HP\Digital Imaging\bin\bak\backupnotify.exe
c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
c:\program files\SymNetDrv\bak\SNDMon.exe
c:\windows\bak\SM1BG.EXE
c:\windows\CREATOR\bak\Remind_XP.exe
c:\windows\SMINST\bak\RECGUARD.EXE
c:\windows\system\bak\hpsysdrv.exe
c:\windows\system32\bak\hphmon05.exe
c:\windows\system32\spool\drivers\w32x86\3\bak\E_S10IC2.EXE
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
c:\program files\Grisoft\AVG Free\bak\avgcc.exe
c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
c:\program files\HP\Digital Imaging\bin\BackupNotify.exe
c:\program files\HP\Digital Imaging\bin\bak\backupnotify.exe
c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
c:\program files\SymNetDrv\bak\SNDMon.exe
c:\program files\Viewpoint
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\Components\Atmosphere.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\BlueStreak.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\ExtremeShot.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts2Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VETsdk.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
c:\windows\bak\SM1BG.EXE
c:\windows\CREATOR\bak\Remind_XP.exe
c:\windows\SMINST\bak\RECGUARD.EXE
c:\windows\system\bak\hpsysdrv.exe
c:\windows\system32\bak\hphmon05.exe
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\kwave.sys
c:\windows\system32\spool\drivers\w32x86\3\bak\E_S10IC2.EXE
.
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-06 10:47 . 2008-12-06 10:47 d——– c:\program files\Trend Micro
2008-12-06 09:22 . 2008-12-06 11:20 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-06 09:22 . 2008-12-06 09:22 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-06 09:22 . 2008-12-06 09:22 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-06 09:22 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-06 09:22 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-06 09:06 . 2008-12-06 09:06 d——– c:\program files\ERUNT
2008-12-02 23:40 . 2008-12-02 23:40 d——– c:\documents and settings\Owner\Application Data\F-Secure
2008-12-02 23:05 . 2008-12-02 23:05 d——– c:\documents and settings\All Users\Application Data\f-secure
2008-12-02 23:05 . 2008-04-23 11:12 57,824 –a—— c:\windows\system32\drivers\fsdfw.sys
2008-12-02 23:05 . 2008-04-23 11:12 36,768 –a—— c:\windows\system32\drivers\fsndis5.sys
2008-12-02 23:04 . 2008-12-02 23:07 d——– c:\program files\F-Secure PC Protection Plus
2008-12-02 22:07 . 2008-12-02 22:46 d——– c:\windows\SxsCaPendDel
2008-12-02 21:15 . 2008-12-02 22:54 d——– c:\documents and settings\All Users\Application Data\fssg
2008-12-02 18:55 . 2008-12-02 20:52 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-12-02 18:54 . 2008-12-02 18:54 d——– c:\program files\Common Files\iS3
2008-12-02 18:54 . 2008-12-02 21:38 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-12-02 08:09 . 2008-12-02 08:09 d–h—– c:\windows\system32\GroupPolicy
2008-12-02 07:46 . 2008-12-02 07:48 d——– c:\documents and settings\Owner\Application Data\ErrorRepairTool
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 03:36 ——— d—–w c:\program files\a-squared Free
2008-11-30 19:55 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2008-11-30 19:54 ——— d—–w c:\program files\SpywareGuard
2008-11-30 19:26 ——— d—–w c:\program files\Google
2008-11-30 19:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-30 19:25 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-30 19:23 ——— d—–w c:\program files\Click'N Design 3D
2008-11-30 17:31 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-19 12:50 ——— d—–w c:\program files\Mozilla Thunderbird
2003-08-27 19:19 36,963 —-a-r c:\program files\Common Files\SM1updtr.dll
2007-04-07 11:09 44,624 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2007-04-07 11:09 108,184 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-06_12.49.17.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-06 17:44:19 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-06 18:43:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-06 17:44:19 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-06 18:43:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-06 17:44:19 163,840 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-06 18:44:39 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-06 17:40:40 262,144 —-a-w c:\windows\system32\config\systemprofile\NTUSER.DAT
+ 2008-12-06 18:40:21 262,144 —-a-w c:\windows\system32\config\systemprofile\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-02-19 438272]
"F-Secure Manager"="c:\program files\F-Secure PC Protection Plus\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"VTTimer"="VTTimer.exe" [2004-09-01 c:\windows\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-01-16 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-01-11 4898816]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-01 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
HotSync Manager.lnk - c:\palm\HOTSYNC.EXE [2004-07-31 282624]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PopSubtract.lnk - c:\program files\InterMute\PopSubtract\PopSub.exe [2004-08-30 233472]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2004-04-01 16384]
.
Contents of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\ErrorRepairTool Scheduled Scan.job
- c:\program files\ErrorRepairTool\ErrorRepairTool.exe []
2008-12-02 c:\windows\Tasks\ErrorRepairTool Scheduled Scan.job
- c:\program files\ErrorRepairTool []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AIM - c:\progra~1\AIM\aim.exe
HKCU-Run-BackupNotify - c:\program files\HP\Digital Imaging\bin\backupnotify.exe
HKLM-Run-KBD - c:\hp\KBD\KBD.EXE
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://portal.wowway.com/index.php
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = localhost
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\F-Secure PC Protection Plus\FSPS\program\FSLSP.DLL
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\7bmrjicx.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://portal.wowway.com/index.php
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-06 13:43:37
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\docume~1\Owner\LOCALS~1\Temp\DIO4.tmp 46713 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(684)
c:\windows\System32\ODBC32.dll
- - - - - - - > 'lsass.exe'(740)
c:\program files\F-Secure PC Protection Plus\FSPS\program\FSLSP.DLL
c:\windows\System32\dssenh.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
c:\program files\a-squared Free\a2service.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\F-Secure PC Protection Plus\Common\FSMA32.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
c:\program files\F-Secure PC Protection Plus\Common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2008-12-06 13:50:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 18:50:15
ComboFix2.txt 2008-12-06 17:50:51
Pre-Run: 122,763,218,944 bytes free
Post-Run: 122,736,119,808 bytes free
235