SunBelt's
CounterSpy has been discontinued. It appears that you downloaded the setup executable. It was at one time an excellent piece of software but today, I wouldn't even consider it now that it's support will end in just over a month.
The log indicates that combofix has been run for a total (so far) of 4 times on that machine. I'd like to see the other logs produced, which would be located in the
qoobox folder at the root of c:\.
You have ERUNT installed. Combofix will install it if you haven't. One of the combofix findings, is of an unsigned file copy (well, a couple of them).
Combofix found a suitable copy from which to correct this. That copy was found in one of your ERUNT backup copies made...years ago. The ERUNT copy that combofix found was made on 1/31/09. You should locate the copy that ERUNT made from that date and delete it. Ask me if you need instructions how to do that...otherwise, please read on.
I should also ask, when you installed it (if you did), did you opt to allow ERUNT to create a backup with each reboot? I might point out, that if you did do that, then you should also monitor the number of backup copies that ERUNT has made and make it a habit to delete old copies much quicker than the nearly three years since it made the file in question. Allowing ERUNT to make copies with each reboot is something that, if left alone, could cause a serious "free space" shortage that will most certainly affect performance...specifically, one would complain of slow performance issues. If you in fact did not install ERUNT, then we need to assume the copy was made when combofix was run way back then. If that's the case, you can disregard the request for the other combofix logs in the qoobox folder.
Next, please open a blank Notepad by clicking start-->run...Then, in the run box type
Notepad.exe and click "OK".
Copy the below text in
Bold and paste it into the blank Notepad. Save it as
CFScript.txt...Change the "Save as type" to
All Files and save it to your desktop. Now drag the text document over to your Combofix.exe
Combofix will run again automatically. Please post back the new log that will be generated. Thanks!
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
KILLALL::
FCopy::
c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll | c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
c:\windows\SYSTEM32\DLLCACHE\mspmsnsv.dll | c:\windows\SYSTEM32\mspmsnsv.dll
Folder::
c:\program files\Yontoo Layers Client
c:\program files\Florida Sea Sm\screen saver
c:\documents and settings\Chuck\Application Data\Imixmi
c:\program files\Common Files\McAfee
Driver::
mfetdi2k
mfendisk
diwfadgf
mfevtp
cfwids
mfefirek
mfendisk
mferkdet
Rootkit::
c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys
c:\windows\SYSTEM32\DRIVERS\mfendisk.sys
c:\windows\system32\drivers\diwfadgf.sys
c:\windows\SYSTEM32\DRIVERS\cfwids.sys
c:\windows\SYSTEM32\DRIVERS\mfefirek.sys
c:\windows\SYSTEM32\DRIVERS\mfendisk.sys
c:\windows\SYSTEM32\DRIVERS\mferkdet.sys
File::
c:\program files\VNC.exe
c:\program files\counterspy-setup.exe
c:\program files\Common Files\SM1updtr.dll
DDS::
Trusted Zone:
Reglock::
[HKEY_USERS\S-1-5-21-2031567766-2786617065-2852452587-1006\Software\Microsoft\SystemCertificates\AddressBook*]
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Florida Sea Sm screen saver"=-
"Florida Sea Sm web link"=-
"{AF3B420A-1581-F3AD-3394-2621EA86BB85}"=-