More google link redirecion issues

  1. #1
    bilbobaggins is offline Newbie

    More google link redirecion issues

    Like other folks, I've recently started having issues having links I click on google searches redirect me to other sites, usually random advertisement pages. Sometimes when in firefox, random tabs will open themselves, and pop ups will appear. I've also been getting windows messages about generic host processes needing to be shut down pretty often. I tried using chrome, but it just said it encountered an error before I could see my homepage

    I've installed spybot, and malwarebytes, and I've got AVG on my computer, but after running scans the issues haven't gone away. Any help is much appreciated. Here's the hijack this log:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 11:36:54 PM, on 6/19/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\system32\gearsec.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    c:\program files\lenovo\system update\suservice.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
    C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\WINDOWS\Philips\SPC230NC\Monitor.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\FlashMute\FlashMute.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Philips\Philips SPC230NC Webcam\TrayMin230.exe
    C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Documents and Settings\Mike\Desktop\HijackThis.exe
    C:\Program Files\AVG\AVG9\avgupd.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Customize Your Settings
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrB kGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBa ttLog
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe"
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [SPC230NC_Monitor] C:\WINDOWS\Philips\SPC230NC\Monitor.exe
    O4 - HKLM\..\Run: [SPC_Monitor] C:\WINDOWS\Philips\SPC230NC\Monitor.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [FlashMute] C:\Program Files\FlashMute\FlashMute.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: TrayMin230.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://drm1.reelsurvey.com/ePlayer/V...ACNePlayer.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
    O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 14712 bytes

  2. #2
    broni is offline Senior Member
    STEP 1. Download Malwarebytes' Anti-Malware: Malwarebytes' Anti-Malware: Malwarebytes to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 2. Download GMER: GMER - Rootkit Detector and Remover, by clicking on Download EXE button.
    Alternative downloads:
    - |MG| GMER 1.0.15.15281 Download
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    Do NOT use the computer while GMER is running!
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.

    RESTART COMPUTER


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  3. #3
    bilbobaggins is offline Newbie
    Thanks for taking a look at this. The situation has been deteriorating a bit, I no longer seem to be able to connect to my wireless network, so I used a friends computer to copy over GMER, and the logs back over, with a USB drive.

    Malwarebytes--Already had this installed, and had scanned recently, so the log below looks pretty empty. I can try to find an old log if that is helpful.

    GMER--Had some issues with this. I got BSOD on first try, then tried again with Devices unchecked. It went well for a while, but towards the end of scanning the filesystem the system locked up. The log below is from running in safe mode. There were definitely more things that came up when I first ran it, not in safe mode, but hopefully this is still useful.

    Malwarebytes' Anti-Malware 1.46
    Malwarebytes

    Database version: 4211

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    6/20/2010 6:41:16 PM
    mbam-log-2010-06-20 (18-41-16).txt

    Scan type: Quick scan
    Objects scanned: 139056
    Time elapsed: 17 minute(s), 28 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    ------------------------------------------------

    GMER 1.0.15.15281 - GMER - Rootkit Detector and Remover
    Rootkit scan 2010-06-21 01:54:30
    Windows 5.1.2600 Service Pack 2
    Running: bwcp7oe5.exe; Driver: C:\DOCUME~1\Mike\LOCALS~1\Temp\aftyaaod.sys


    ---- System - GMER 1.0.15 ----

    SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF763387E]
    SSDT spcf.sys ZwEnumerateKey [0xF74E3CA2]
    SSDT spcf.sys ZwEnumerateValueKey [0xF74E4030]
    SSDT spcf.sys ZwOpenKey [0xF74C60C0]
    SSDT spcf.sys ZwQueryKey [0xF74E4108]
    SSDT spcf.sys ZwQueryValueKey [0xF74E3F88]
    SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF7633BFE]

    INT 0x62 ? 86FD4BF8
    INT 0x74 ? 86ED2F00
    INT 0x83 ? 86F62BF8
    INT 0x83 ? 86ED2F00
    INT 0x84 ? 86ED2F00

    ---- Kernel code sections - GMER 1.0.15 ----

    ? spcf.sys The system cannot find the file specified. !
    .rsrc C:\WINDOWS\system32\drivers\ACPIEC.sys entry point in ".rsrc" section [0xF7A01194]
    .text USBPORT.SYS!DllUnload F70DF7AE 5 Bytes JMP 86ED24E0
    .text afdh6ko2.SYS F6FEB384 1 Byte [20]
    .text afdh6ko2.SYS F6FEB384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
    .text afdh6ko2.SYS F6FEB3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
    .text afdh6ko2.SYS F6FEB3C4 3 Bytes [00, 00, 00]
    .text afdh6ko2.SYS F6FEB3C9 1 Byte [00]
    .text ...

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\svchost.exe[816] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
    .text C:\WINDOWS\system32\svchost.exe[816] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
    .text C:\WINDOWS\system32\svchost.exe[816] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
    .text C:\WINDOWS\system32\svchost.exe[816] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 009E000A
    .text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
    .text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
    .text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 86F655E0
    IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74F693C] spcf.sys
    IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74F6990] spcf.sys
    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74C7040] spcf.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74C713C] spcf.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74C70BE] spcf.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74C77FC] spcf.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74C76D2] spcf.sys
    IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 86ED25E0
    IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74D6D92] spcf.sys
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlInitUnicodeString] 9252D2DB
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!swprintf] [804FC5C0] \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeSetEvent] 8E44C8C9
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoCreateSymbolicLink] A475EBF6
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoGetConfigurationInformation] AA7EE6FF
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] B863F1E4
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmFreeMappingAddress] B668FCED
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 0CB1670A
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 02BA6A03
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmUnmapIoSpace] 10A77D18
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 1EAC7011
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IofCompleteRequest] 349D532E
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 3A965E27
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IofCallDriver] 288B493C
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 26804435
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 7CE90F42
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoConnectInterrupt] 72E2024B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoDetachDevice] 60FF1550
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeWaitForSingleObject] 6EF41859
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInitializeEvent] 44C53B66
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 4ACE366F
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlInitAnsiString] 58D32174
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 56D82C7D
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoQueueWorkItem] 377A0CA1
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmMapIoSpace] 397101A8
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 2B6C16B3
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoReportDetectedDevice] 25671BBA
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0F563885
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 015D358C
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!NlsMbCodePageTag] 13402297
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!PoRequestPowerIrp] 1D4B2F9E
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 472264E9
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 492969E0
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!sprintf] 5B347EFB
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 553F73F2
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ObfDereferenceObject] 7F0E50CD
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 71055DC4
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 63184ADF
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ZwClose] 6D1347D6
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] D7CADC31
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] D9C1D138
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] CBDCC623
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!PoStartNextPowerIrp] C5D7CB2A
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!PoCallDriver] EFE6E815
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoCreateDevice] E1EDE51C
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] F3F0F207
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlQueryRegistryValues] FDFBFF0E
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ZwOpenKey] A792B479
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlFreeUnicodeString] A999B970
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoStartTimer] BB84AE6B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInitializeTimer] B58FA362
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoInitializeTimer] 9FBE805D
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInitializeDpc] 91B58D54
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInitializeSpinLock] 83A89A4F
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoInitializeIrp] 8DA39746
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ZwCreateKey] 00000063
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 0000007C
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 00000077
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ZwSetValueKey] 0000007B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeInsertQueueDpc] 000000F2
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 0000006B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoStartPacket] 0000006F
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 000000C5
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 00000030
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoFreeMdl] 00000001
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmUnlockPages] 00000067
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000002B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 000000FE
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000D7
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000AB
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000076
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoStartNextPacket] 000000CA
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeBugCheckEx] 00000082
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 000000C9
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeSetTimer] 0000007D
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeCancelTimer] 000000FA
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!_allmul] 00000059
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000047
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!_except_handler3] 000000F0
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!PoSetPowerState] 000000AD
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000D4
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000A2
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!_aulldiv] 000000AF
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!strstr] 0000009C
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!_strupr] 000000A4
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeQuerySystemTime] 00000072
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000C0
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!KeTickCount] 000000B7
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 000000FD
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoDeleteDevice] 00000093
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000026
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000036
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAllocateIrp] 0000003F
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoAllocateMdl] 000000F7
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000CC
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmLockPagableDataSection] 00000034
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 000000A5
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 000000E5
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!ExFreePoolWithTag] 000000F1
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoFreeIrp] 00000071
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000D8
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!InitSafeBootMode] 00000031
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlCompareMemory] 00000015
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000004
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!memmove] 000000C7
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[ntoskrnl.exe!MmHighestUserAddress] 00000023
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KfAcquireSpinLock] 0A64D90F
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!READ_PORT_UCHAR] 046FD406
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KeGetCurrentIrql] 1672C31D
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KfRaiseIrql] 1879CE14
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KfLowerIrql] 3248ED2B
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!HalGetInterruptVector] 3C43E022
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!HalTranslateBusAddress] 2E5EF739
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KeStallExecutionProcessor] 2055FA30
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!KfReleaseSpinLock] EC01B79A
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] E20ABA93
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!READ_PORT_USHORT] F017AD88
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] FE1CA081
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[HAL.dll!WRITE_PORT_UCHAR] D42D83BE
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[WMILIB.SYS!WmiSystemControl] C83B99AC
    IAT \SystemRoot\System32\Drivers\afdh6ko2.SYS[WMILIB.SYS!WmiCompleteRequest] C63094A5

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4@khjeh 0xE1 0x7C 0x1F 0x60 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0x6E 0xF8 0x27 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4\00000001\0Jf40
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19 659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khje h 0xFF 0x32 0xCB 0x67 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4@khjeh 0xE1 0x7C 0x1F 0x60 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4\00000001@khjeh 0xF8 0x6E 0xF8 0x27 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\196592 39224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xFF 0x32 0xCB 0x67 ...

    ---- Files - GMER 1.0.15 ----

    File C:\WINDOWS\system32\drivers\ACPIEC.sys suspicious modification

    ---- EOF - GMER 1.0.15 ----

  4. #4
    broni is offline Senior Member
    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  5. #5
    bilbobaggins is offline Newbie
    Thanks! Managed to run combofix not in safe mode, my internet connection seems to work ok again, I haven't tried too much yet but I didn't get redirected from the first couple links I clicked.

    ComboFix 10-06-21.01 - Mike 06/22/2010 0:43.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.441 [GMT -4:00]
    Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\windows\system32\geyekrbyikkcvt.dat
    c:\windows\system32\UACjkatmhycdywlcjfir.db

    ----- BITS: Possible infected sites -----

    hxxp://au.download.windowsupdatj+|Cv+@J:NGD_DQ{zGD_DQ{zGD _DQ{zGD_DQ{z+@J:Nj+|Cv000-7B44-A93200000932}
    Infected copy of c:\windows\system32\drivers\acpiec.sys was found and disinfected
    Restored copy from - Kitty had a snack
    .
    ((((((((((((((((((((((((( Files Created from 2010-05-22 to 2010-06-22 )))))))))))))))))))))))))))))))
    .

    2010-06-15 03:22 . 2010-06-16 03:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-06-15 03:22 . 2010-06-15 12:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-06-15 02:56 . 2010-06-18 00:46 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-06-15 01:18 . 2010-06-15 01:17 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-06-15 01:17 . 2010-06-15 01:17 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-06-15 01:07 . 2010-06-15 01:08 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
    2010-06-15 01:06 . 2010-06-15 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-06-15 01:06 . 2010-06-15 01:08 -------- d-----w- c:\program files\Lavasoft
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
    2010-06-12 18:03 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-06-12 18:03 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-06-11 23:39 . 2010-06-11 23:39 -------- d-----w- c:\program files\AVG
    2010-06-06 18:32 . 2010-06-11 23:12 -------- d-----w- c:\documents and settings\Mike\Local Settings\Application Data\ogyquyabd
    2010-05-28 01:05 . 2010-05-28 01:06 -------- d-----w- c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2010-06-22 04:11 . 2007-07-25 00:37 76288 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-20 04:59 . 2007-07-25 00:23 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
    2010-06-19 20:24 . 2007-07-25 00:15 -------- d-----w- c:\program files\PCDR5
    2010-06-19 18:18 . 2007-08-13 14:56 -------- d-----w- c:\program files\Windows Live Toolbar
    2010-06-11 23:10 . 2007-08-13 14:56 76288 -c--a-w- c:\documents and settings\Mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-11 23:09 . 2008-08-11 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-05-28 06:31 . 2010-02-02 02:29 -------- d-----w- c:\program files\Common Files\Intuit
    2010-05-21 04:58 . 2010-04-21 22:51 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-05-06 06:42 . 2009-02-24 02:46 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
    2010-05-03 01:27 . 2008-10-13 23:07 -------- d-----w- c:\documents and settings\Mike\Application Data\dvdcss
    2010-05-02 08:48 . 2008-07-10 05:16 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\1T ortoiseNormal]
    @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\2T ortoiseModified]
    @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\3T ortoiseConflict]
    @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\4T ortoiseLocked]
    @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\5T ortoiseReadOnly]
    @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\6T ortoiseDeleted]
    @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\7T ortoiseAdded]
    @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\8T ortoiseIgnored]
    @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\9T ortoiseUnversioned]
    @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Google Update"="c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
    "FlashMute"="c:\program files\FlashMute\FlashMute.exe" [2006-03-11 221184]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR .DLL" [2006-05-25 151552]
    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL " [2006-05-25 208896]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp .Exe" [2006-02-23 237568]
    "TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-03 856064]
    "TpShocks"="TpShocks.exe" [2006-03-16 106496]
    "TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKM GR.exe" [2006-07-25 94208]
    "TP4EX"="tp4ex.exe" [2005-10-17 65536]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
    "LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe " [2006-07-04 110592]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\I SUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
    "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-15 503808]
    "DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
    "PDService.exe"="c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 41472]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-15 2341632]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-20 286720]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
    "SPC230NC_Monitor"="c:\windows\Philips\SPC230NC\Mo nitor.exe" [2007-12-10 323584]
    "SPC_Monitor"="c:\windows\Philips\SPC230NC\Monitor .exe" [2007-12-10 323584]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-7-24 24576]
    TrayMin230.lnk - c:\program files\Philips\Philips SPC230NC Webcam\TrayMin230.exe [2008-12-15 241664]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
    2006-08-16 17:07 49152 ------w- c:\program files\Lenovo\AwayTask\AwayNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2006-04-26 02:20 40448 ------w- c:\windows\system32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
    2005-07-05 14:45 28672 ------w- c:\windows\system32\notifyf2.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
    2005-11-30 11:16 24576 ------w- c:\windows\system32\tphklock.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Dropbox.lnk]
    path=c:\documents and settings\Mike\Start Menu\Programs\Startup\Dropbox.lnk
    backup=c:\windows\pss\Dropbox.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    2008-01-17 16:51 486856 -c----w- c:\program files\DAEMON Tools Lite\daemon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    2008-11-07 19:31 21633320 ------r- c:\program files\Skype\Phone\Skype.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Philips\\Intelligent Agent\\Philips Intelligent Agent.exe"=
    "c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
    "c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
    "c:\\Program Files\\Eclipse\\eclipse\\eclipse.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\cygwin\\bin\\XWin.exe"=
    "c:\\Program Files\\Foxit Software\\Foxit Reader\\Foxit Reader.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
    "11476:TCP"= 11476:TCP:BitComet 11476 TCP
    "11476:UDP"= 11476:UDP:BitComet 11476 UDP

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/14/2010 9:18 PM 64288]
    R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 7:27 PM 53248]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]
    R2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [3/13/2006 7:05 PM 58368]
    R2 smi2;smi2;c:\program files\SMI2\smi2.sys [7/14/2006 6:55 PM 3968]
    R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [4/25/2006 10:00 PM 3456]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/8/2007 2:09 PM 24652]
    S3 PAEAFLT.sys;USB Composite Device;c:\windows\system32\drivers\PAEAFLT.sys [12/15/2008 11:45 PM 8576]
    S3 SPC230NC;Philips SPC230NC Webcam;c:\windows\system32\drivers\SPC230NC.SYS [12/15/2008 11:45 PM 461056]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/4/2008 1:15 AM 716272]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    getPlusHelper REG_MULTI_SZ getPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 00:46]

    2010-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 22:57]

    2010-06-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3848391195-2397763145-3297269932-1008Core.job
    - c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 04:26]

    2010-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3848391195-2397763145-3297269932-1008UA.job
    - c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 04:26]

    2010-06-22 c:\windows\Tasks\PMTask.job
    - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-07-25 16:13]

    2010-06-22 c:\windows\Tasks\WGASetup.job
    - c:\windows\system32\KB905474\wgasetup.exe [2009-03-25 02:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
    FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\6lalxtmu.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
    FF - plugin: c:\documents and settings\Mike\Application Data\Mozilla\plugins\npgoogletalk.dll
    FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dl l
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint_.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_every where__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_bro ken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    .
    - - - - ORPHANS REMOVED - - - -

    Notify-ACNotify - ACNotify.dll
    Notify-avgrsstarter - (no file)
    Notify-NavLogon - (no file)



    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2010-06-22 01:05
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, GMER - Rootkit Detector and Remover

    device: opened successfully
    user: MBR read successfully
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86E94EC5]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\Disk -> CLASSPNP.SYS @ 0xf75f7fc3
    \Driver\ACPI -> ACPI.sys @ 0xf748acb8
    \Driver\atapi -> atapi.sys @ 0xf73e87b4
    \Driver\iaStor -> iaStor.sys @ 0xf731eb58
    IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf71f5bb0
    PacketIndicateHandler -> NDIS.sys @ 0xf7202a21
    SendHandler -> NDIS.sys @ 0xf71e087b
    user & kernel MBR OK

    ************************************************** ************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1348)
    c:\windows\system32\WININET.dll
    c:\windows\system32\vrlogon.dll
    c:\windows\system32\tvt_gina.dll
    c:\program files\Lenovo\Client Security Solution\css_gina_plugin.dll
    c:\program files\Lenovo\Client Security Solution\css_wait_bar.dll
    c:\program files\Lenovo\Client Security Solution\cssuserdatadispatcher.dll
    c:\program files\Lenovo\Client Security Solution\csswait.dll
    c:\program files\Common Files\Lenovo\tvt_banner.dll
    c:\program files\Lenovo\Client Security Solution\cssdlgpwentry.dll
    c:\program files\Lenovo\Client Security Solution\dlganswerprompt.dll
    c:\program files\Lenovo\Client Security Solution\tvttsp.dll
    c:\program files\Lenovo\Client Security Solution\tcsrpc.dll
    c:\program files\Common Files\Lenovo\tvt_res.dll
    c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
    c:\program files\ThinkVantage Fingerprint Software\infra.dll
    c:\program files\ThinkVantage Fingerprint Software\VTI.DLL
    c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
    c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
    c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\psqlpwd.dll
    c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
    c:\windows\system32\biologon.dll
    c:\program files\ThinkVantage Fingerprint Software\homepass.dll
    c:\program files\ThinkVantage Fingerprint Software\bio.dll
    c:\program files\ThinkVantage Fingerprint Software\remote.dll
    c:\program files\ThinkVantage Fingerprint Software\crypto.dll
    c:\windows\system32\tphklock.dll
    c:\program files\Lenovo\AwayTask\AwayNotify.dll

    - - - - - - - > 'lsass.exe'(1408)
    c:\windows\system32\WININET.dll
    c:\windows\system32\psqlpwd.dll
    c:\program files\ThinkVantage Fingerprint Software\infra.dll
    c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

    - - - - - - - > 'explorer.exe'(4728)
    c:\windows\system32\WININET.dll
    c:\windows\system32\PROCHLP.DLL
    c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    c:\program files\TortoiseSVN\bin\TortoiseStub.dll
    c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
    c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
    c:\program files\FlashMute\mutelib.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\btncopy.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ibmpmsvc.exe
    c:\windows\system32\Ati2evxx.exe
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\windows\system32\IPSSVC.EXE
    c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\lenovo\system update\suservice.exe
    c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    c:\windows\System32\TPHDEXLG.EXE
    c:\windows\system32\TpKmpSVC.exe
    c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
    c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
    c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
    c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    c:\program files\Common Files\Lenovo\Logger\logmon.exe
    c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\windows\system32\Ati2evxx.exe
    c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\TortoiseSVN\bin\TSVNCache.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\TpShocks.exe
    c:\program files\ThinkPad\UltraNav Wizard\UNavTray.EXE
    c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
    c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
    c:\program files\ATI Technologies\ATI.ACE\cli.exe
    .
    ************************************************** ************************
    .
    Completion time: 2010-06-22 01:18:45 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-06-22 05:18

    Pre-Run: 12,883,910,656 bytes free
    Post-Run: 13,208,092,672 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - F59948ACF19DF86ABC8A4F90D88649BF

  6. #6
    broni is offline Senior Member
    Very good

    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOl, AIM, Compuserve, etc.

    ================================================== ===========

    Note: If you have a previous version of TDSSKiller downloaded please delete it now and download a fresh copy using the links provided below

    Download TDSSKiller and save it to your Desktop.
    Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
    Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
    When it is done, a log file should be created on your C: drive called TDSSKiller.txt please copy and paste the contents of that file here.

  7. #7
    bilbobaggins is offline Newbie
    Thanks for the fast reply! TDSSKiller log is below.

    01:36:10:828 1520 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
    01:36:10:828 1520 ================================================== ==============================
    01:36:10:828 1520 SystemInfo:

    01:36:10:828 1520 OS Version: 5.1.2600 ServicePack: 2.0
    01:36:10:828 1520 Product type: Workstation
    01:36:10:828 1520 ComputerName: LENOVO-D7E6262E
    01:36:10:828 1520 UserName: Mike
    01:36:10:828 1520 Windows directory: C:\WINDOWS
    01:36:10:828 1520 Processor architecture: Intel x86
    01:36:10:828 1520 Number of processors: 2
    01:36:10:828 1520 Page size: 0x1000
    01:36:10:828 1520 Boot type: Normal boot
    01:36:10:828 1520 ================================================== ==============================
    01:36:11:375 1520 Initialize success
    01:36:11:375 1520
    01:36:11:375 1520 Scanning Services ...
    01:36:11:500 1520 Raw services enum returned 413 services
    01:36:11:515 1520
    01:36:11:531 1520 Scanning Drivers ...
    01:36:13:468 1520 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
    01:36:13:625 1520 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys
    01:36:13:718 1520 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    01:36:13:734 1520 ACPIEC (a1fb4da3cea32ee9d798402f06040b01) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
    01:36:13:734 1520 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ACPIEC.sys. Real md5: a1fb4da3cea32ee9d798402f06040b01, Fake md5: 9859c0f6936e723e4892d7141b1327d5
    01:36:13:734 1520 File "C:\WINDOWS\system32\DRIVERS\ACPIEC.sys" infected by TDSS rootkit ... 01:36:15:500 1520 Backup copy found, using it..
    01:36:15:515 1520 will be cured on next reboot
    01:36:15:734 1520 ADIHdAudAddService (66614b9fdc7e74ab736a84d89f7b06b6) C:\WINDOWS\system32\drivers\ADIHdAud.sys
    01:36:15:796 1520 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
    01:36:15:890 1520 AEAudioService (03be587e90c8b37c7ff1fe2e9c1d1c90) C:\WINDOWS\system32\drivers\AEAudio.sys
    01:36:15:968 1520 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
    01:36:16:031 1520 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys
    01:36:16:218 1520 AFD (6a0397376853e604de8e1e7a87fc08ac) C:\WINDOWS\System32\drivers\afd.sys
    01:36:16:265 1520 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
    01:36:16:281 1520 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    01:36:16:296 1520 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
    01:36:16:328 1520 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
    01:36:16:390 1520 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
    01:36:16:406 1520 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
    01:36:16:421 1520 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
    01:36:16:437 1520 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
    01:36:16:468 1520 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
    01:36:16:500 1520 ANC (11ab185a7af224800bbfb5b836974a17) C:\WINDOWS\system32\drivers\ANC.SYS
    01:36:16:546 1520 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
    01:36:16:562 1520 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
    01:36:16:578 1520 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
    01:36:16:593 1520 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    01:36:16:656 1520 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
    01:36:16:796 1520 ati2mtag (e150424208c8a91deed8c45019a6cdd2) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
    01:36:16:968 1520 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    01:36:17:031 1520 atmeltpm (dbf0d7e2df33b469eb55406fea759350) C:\WINDOWS\system32\DRIVERS\atmeltpm.sys
    01:36:17:046 1520 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    01:36:17:062 1520 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    01:36:17:156 1520 BTKRNL (dbd408226b00c20158864f30a5a84451) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
    01:36:17:218 1520 BTWUSB (7cd8e4303fda5b11da325340778d99d9) C:\WINDOWS\system32\Drivers\btwusb.sys
    01:36:17:234 1520 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
    01:36:17:250 1520 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    01:36:17:296 1520 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    01:36:17:328 1520 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
    01:36:17:343 1520 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    01:36:17:406 1520 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
    01:36:17:468 1520 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    01:36:17:515 1520 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
    01:36:17:562 1520 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
    01:36:17:593 1520 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
    01:36:17:625 1520 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
    01:36:17:656 1520 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
    01:36:17:671 1520 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
    01:36:17:718 1520 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
    01:36:17:796 1520 DLABOIOM (35cbc02546335ea41a5d516da6626c8a) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
    01:36:17:828 1520 DLACDBHM (ec6ae8bc9f773382d2eed49e4dfdae2a) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
    01:36:17:875 1520 DLADResN (19e3db16de2bb3db81b172a78d140b03) C:\WINDOWS\system32\DLA\DLADResN.SYS
    01:36:17:890 1520 DLAIFS_M (e4859ca5bd8412a9a60d62067a653522) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
    01:36:17:921 1520 DLAOPIOM (20c24a3d1cf0825487c93f806625805e) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
    01:36:17:937 1520 DLAPoolM (8a530da5dc81954bcf1966813f699b49) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
    01:36:17:984 1520 DLARTL_N (0605b66052f82b6f07204dbdb61c13ff) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
    01:36:18:015 1520 DLAUDFAM (7eda68af6a91bf64af6f301e39928ebf) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
    01:36:18:031 1520 DLAUDF_M (a18423bbc6d92b01fdf3c51e7510ee70) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
    01:36:18:109 1520 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
    01:36:18:203 1520 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
    01:36:18:218 1520 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    01:36:18:265 1520 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
    01:36:18:281 1520 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
    01:36:18:296 1520 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
    01:36:18:343 1520 DRVMCDB (48c7008d23dcfce0d0232f49307efced) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
    01:36:18:406 1520 DRVNDDM (05467e44a42c777dd1534bb4539b16d1) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
    01:36:18:468 1520 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    01:36:18:546 1520 e1express (00560c3fedf8958fcdc7c68b7906f66f) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
    01:36:18:609 1520 EGATHDRV (2d0fc676d159525f6cd74c3302c7a61c) C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
    01:36:18:671 1520 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
    01:36:18:703 1520 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
    01:36:18:703 1520 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
    01:36:18:734 1520 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    01:36:18:812 1520 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
    01:36:18:859 1520 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    01:36:18:921 1520 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    01:36:18:937 1520 GEARAspiWDM (32a73a8952580b284a47290adb62032a) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    01:36:18:984 1520 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    01:36:19:046 1520 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    01:36:19:109 1520 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    01:36:19:125 1520 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
    01:36:19:234 1520 HSF_DPV (b1fc0b027df4374f9e5b796cfdf797b3) C:\WINDOWS\system32\DRIVERS\hsx_dpv.sys
    01:36:19:296 1520 HSXHWAZL (3af45f5b4157c88ffae24d89ba408302) C:\WINDOWS\system32\DRIVERS\hsxhwazl.sys
    01:36:19:421 1520 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
    01:36:19:500 1520 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
    01:36:19:515 1520 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
    01:36:19:578 1520 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    01:36:19:718 1520 iaStor (309c4d86d989fb1fcf64bd30dc81c51b) C:\WINDOWS\system32\DRIVERS\iaStor.sys
    01:36:19:890 1520 IBMPMDRV (067a88764593b1f46a6cfb00c69c11eb) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
    01:36:19:937 1520 IBMTPCHK (bfc9f3adaad74e13f9ce16c8bd336f95) C:\WINDOWS\system32\Drivers\IBMBLDID.sys
    01:36:19:984 1520 Imapi (12c59b8929121ace2f55acc86682cf12) C:\WINDOWS\system32\DRIVERS\imapi.sys
    01:36:20:031 1520 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
    01:36:20:046 1520 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
    01:36:20:093 1520 intelppm (db8a1859cf9e48914dcc0a7206d87be5) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    01:36:20:125 1520 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
    01:36:20:171 1520 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    01:36:20:187 1520 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    01:36:20:218 1520 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    01:36:20:625 1520 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    01:36:20:796 1520 irda (86c204836feec22510d434982d4221b8) C:\WINDOWS\system32\DRIVERS\irda.sys
    01:36078 1520 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
    01:36375 1520 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    01:36578 1520 Iviaspi (f59c3569a2f2c464bb78cb1bdcdca55e) C:\WINDOWS\system32\drivers\iviaspi.sys
    01:36718 1520 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    01:36875 1520 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
    01:36968 1520 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
    01:36:22:062 1520 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys
    01:36:22:140 1520 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
    01:36:22:265 1520 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
    01:36:22:562 1520 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    01:36:22:593 1520 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
    01:36:22:640 1520 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    01:36:22:687 1520 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    01:36:22:718 1520 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
    01:36:22:734 1520 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    01:36:22:781 1520 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    01:36:22:859 1520 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    01:36:22:906 1520 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
    01:36:22:937 1520 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    01:36:22:953 1520 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    01:36:22:968 1520 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
    01:36:22:984 1520 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    01:36:23:046 1520 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
    01:36:23:062 1520 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
    01:36:23:093 1520 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    01:36:23:156 1520 NDIS (bc84c4f67d0e880b0c46dc0ce2b8cbaa) C:\WINDOWS\system32\drivers\NDIS.sys
    01:36:23:187 1520 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    01:36:23:234 1520 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    01:36:23:296 1520 Ndisuio (8d3ce6b579cde8d37acc690b67dc2106) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    01:36:23:312 1520 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    01:36:23:328 1520 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
    01:36:23:390 1520 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
    01:36:23:453 1520 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
    01:36:23:625 1520 NETw3x32 (e2f396f71a793a04839dbb6af304a026) C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
    01:36:23:796 1520 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
    01:36:23:859 1520 NSCIRDA (6216798d29c3ba9d0d6f40bbbab694a5) C:\WINDOWS\system32\DRIVERS\nscirda.sys
    01:36:23:937 1520 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
    01:36:23:968 1520 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    01:36:24:062 1520 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    01:36:24:171 1520 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    01:36:24:187 1520 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    01:36:24:250 1520 PAEAFLT.sys (301e92ce7fb606f94f124a76d8145622) C:\WINDOWS\system32\DRIVERS\PAEAFLT.sys
    01:36:24:296 1520 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
    01:36:24:328 1520 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
    01:36:24:390 1520 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    01:36:24:453 1520 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
    01:36:24:484 1520 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    01:36:24:562 1520 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
    01:36:24:656 1520 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
    01:36:24:687 1520 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
    01:36:24:734 1520 pmem (dedef40e1d05842639491365cb2c069e) C:\WINDOWS\System32\drivers\pmemnt.sys
    01:36:24:781 1520 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    01:36:24:953 1520 PrivateDisk (ebe579425ccb8377bfc7c0b50c05eb56) C:\Program Files\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys
    01:36:24:984 1520 PROCDD (6f9e6e874fd74ee6dd0bbecde9d3f795) C:\WINDOWS\system32\DRIVERS\PROCDD.SYS
    01:36:25:031 1520 Processor (9e372a156f92425a1904b84589093a37) C:\WINDOWS\system32\DRIVERS\processr.sys
    01:36:25:062 1520 psadd (fb4c54f3a168b178dabf15eebaed8276) C:\WINDOWS\system32\Drivers\psadd.sys
    01:36:25:125 1520 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
    01:36:25:156 1520 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    01:36:25:234 1520 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    01:36:25:265 1520 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
    01:36:25:281 1520 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
    01:36:25:312 1520 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
    01:36:25:328 1520 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
    01:36:25:343 1520 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
    01:36:25:390 1520 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    01:36:25:437 1520 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
    01:36:25:531 1520 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    01:36:25:562 1520 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    01:36:25:578 1520 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    01:36:25:640 1520 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    01:36:25:671 1520 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    01:36:25:734 1520 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    01:36:25:765 1520 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
    01:36:25:828 1520 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
    01:36:25:875 1520 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
    01:36:25:937 1520 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
    01:36:25:984 1520 s24trans (2862adb14481ac28f98105ff33a99eb0) C:\WINDOWS\system32\DRIVERS\s24trans.sys
    01:36:26:031 1520 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    01:36:26:046 1520 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
    01:36:26:062 1520 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
    01:36:26:093 1520 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
    01:36:26:125 1520 ShockMgr (1a9b76c8e0d77bcaca24fdf36781b59d) C:\WINDOWS\system32\drivers\ShockMgr.sys
    01:36:26:156 1520 Shockprf (cb0c065af3ac9ac307408ea021cdd20e) C:\WINDOWS\system32\drivers\Shockprf.sys
    01:36:26:187 1520 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
    01:36:26:250 1520 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    01:36:26:296 1520 Smapint (26341d0dd225d19fd50e0ee3c3c77502) C:\WINDOWS\system32\drivers\Smapint.sys
    01:36:26:343 1520 smi2 (3ba9d0c8a0fbd9fb4029b6cd87c8ce0b) C:\Program Files\SMI2\smi2.sys
    01:36:26:390 1520 smihlp (01a4388e45ba272082bfc35b0c8dbf8a) C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys
    01:36:26:453 1520 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
    01:36:26:515 1520 SPC230NC (2265d43d44cf9695c050e3b58f05295b) C:\WINDOWS\system32\DRIVERS\SPC230NC.SYS
    01:36:26:578 1520 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
    01:36:26:671 1520 sptd (7f1b7c4d446cd3f926af45b8c48bd593) C:\WINDOWS\system32\Drivers\sptd.sys
    01:36:26:796 1520 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
    01:36:26:859 1520 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
    01:36:26:921 1520 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    01:36:26:984 1520 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
    01:36:27:015 1520 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
    01:36:27:031 1520 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
    01:36:27:078 1520 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
    01:36:27:109 1520 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
    01:36:27:125 1520 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
    01:36:27:187 1520 SynTP (7c02db7416d52c02b131d0e3a8d2337c) C:\WINDOWS\system32\DRIVERS\SynTP.sys
    01:36:27:203 1520 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
    01:36:27:296 1520 Tcpip (744e57c99232201ae98c49168b918f48) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    01:36:27:359 1520 TcUsb (fc6fe02f400308606a911640e72326b5) C:\WINDOWS\system32\Drivers\tcusb.sys
    01:36:27:421 1520 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
    01:36:27:468 1520 TDSMAPI (564b337034271b7bddcabfddc91c6b7a) C:\WINDOWS\system32\drivers\TDSMAPI.SYS
    01:36:27:500 1520 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
    01:36:27:546 1520 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
    01:36:27:578 1520 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
    01:36:27:640 1520 TPHKDRV (29f3601d4233a53f819010fee8c04a60) C:\WINDOWS\system32\drivers\TPHKDRV.sys
    01:36:27:671 1520 TPPWRIF (44672de6cea9569c21c4b7a8d2560750) C:\WINDOWS\system32\drivers\Tppwrif.sys
    01:36:27:687 1520 TSMAPIP (f2aba3066d7921d7fcdbd66dea88be11) C:\WINDOWS\system32\drivers\TSMAPIP.SYS
    01:36:27:750 1520 tvtfilter (dd957007df98aecffaaa2656d4b981e4) C:\WINDOWS\system32\drivers\tvtfilter.sys
    01:36:27:843 1520 TVTPktFilter (0727cce3ff1a4446f4a1d507361567ab) C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys
    01:36:27:906 1520 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
    01:36:27:937 1520 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
    01:36:28:015 1520 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
    01:36:28:078 1520 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
    01:36:28:125 1520 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    01:36:28:171 1520 usbehci (b0d7020386c7187ef9c5a9643f289cd3) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    01:36:28:171 1520 usbhub (d31e07bf822c7f2bd32714e9ddca8be2) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    01:36:28:218 1520 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    01:36:28:281 1520 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    01:36:28:343 1520 usbuhci (ff6e4fdeb82dc228efa490336409c6bd) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    01:36:28:406 1520 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
    01:36:28:437 1520 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
    01:36:28:500 1520 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
    01:36:28:531 1520 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
    01:36:28:562 1520 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
    01:36:28:593 1520 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    01:36:28:671 1520 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
    01:36:28:765 1520 winachsf (11ec1afceb5c917ce73d3c301ff4291e) C:\WINDOWS\system32\DRIVERS\hsx_cnxt.sys
    01:36:28:859 1520 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
    01:36:28:906 1520 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    01:36:28:984 1520 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    01:36:29:015 1520 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    01:36:29:031 1520 Reboot required for cure complete..
    01:36:29:062 1520 Cure on reboot scheduled successfully
    01:36:29:062 1520
    01:36:29:062 1520 Completed
    01:36:29:062 1520
    01:36:29:062 1520 Results:
    01:36:29:062 1520 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
    01:36:29:062 1520 File objects infected / cured / cured on reboot: 1 / 0 / 1
    01:36:29:062 1520
    01:36:29:078 1520 KLMD(ARK) unloaded successfully

  8. #8
    broni is offline Senior Member
    Please, delete your Combofix file, download fresh one, run it and post new log.

  9. #9
    bilbobaggins is offline Newbie
    Here's the new log:

    ComboFix 10-06-22.02 - Mike 06/22/2010 22:57:32.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.443 [GMT -4:00]
    Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
    .

    2010-06-23 02:27 . 2010-06-23 02:27 -------- d-----w- c:\windows\LastGood
    2010-06-15 03:22 . 2010-06-16 03:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-06-15 03:22 . 2010-06-15 12:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-06-15 02:56 . 2010-06-18 00:46 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-06-15 01:18 . 2010-06-15 01:17 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-06-15 01:17 . 2010-06-15 01:17 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-06-15 01:07 . 2010-06-15 01:08 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
    2010-06-15 01:07 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
    2010-06-15 01:06 . 2010-06-15 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-06-15 01:06 . 2010-06-15 01:08 -------- d-----w- c:\program files\Lavasoft
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
    2010-06-12 18:03 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-06-12 18:03 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-06-12 18:03 . 2010-06-12 18:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-06-11 23:39 . 2010-06-11 23:39 -------- d-----w- c:\program files\AVG
    2010-06-06 18:32 . 2010-06-11 23:12 -------- d-----w- c:\documents and settings\Mike\Local Settings\Application Data\ogyquyabd
    2010-05-28 01:05 . 2010-05-28 01:06 -------- d-----w- c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2010-06-22 05:37 . 2001-08-17 13:57 11648 ----a-w- c:\windows\system32\drivers\ACPIEC.sys
    2010-06-22 05:33 . 2007-08-22 19:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
    2010-06-22 04:11 . 2007-07-25 00:37 76288 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-20 04:59 . 2007-07-25 00:23 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
    2010-06-19 20:24 . 2007-07-25 00:15 -------- d-----w- c:\program files\PCDR5
    2010-06-19 18:18 . 2007-08-13 14:56 -------- d-----w- c:\program files\Windows Live Toolbar
    2010-06-11 23:10 . 2007-08-13 14:56 76288 -c--a-w- c:\documents and settings\Mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-11 23:09 . 2008-08-11 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-05-28 06:31 . 2010-02-02 02:29 -------- d-----w- c:\program files\Common Files\Intuit
    2010-05-21 04:58 . 2010-04-21 22:51 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-05-07 16:55 . 2010-05-07 16:55 255472 ----a-w- c:\documents and settings\Mike\Application Data\Mozilla\plugins\npgoogletalk.dll
    2010-05-06 06:42 . 2009-02-24 02:46 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
    2010-05-03 01:27 . 2008-10-13 23:07 -------- d-----w- c:\documents and settings\Mike\Application Data\dvdcss
    2010-05-02 08:48 . 2008-07-10 05:16 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
    2010-04-01 17:50 . 2010-04-01 17:50 532480 ----a-w- c:\documents and settings\Mike\Application Data\Notepad++\plugins\config\plugin_install_temp\ plugin1\plugins\PluginManager.dll
    2010-04-01 17:50 . 2010-04-01 17:50 401408 ----a-w- c:\documents and settings\Mike\Application Data\Notepad++\plugins\config\plugin_install_temp\ plugin1\updater\gpup.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\1T ortoiseNormal]
    @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\2T ortoiseModified]
    @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\3T ortoiseConflict]
    @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\4T ortoiseLocked]
    @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\5T ortoiseReadOnly]
    @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\6T ortoiseDeleted]
    @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\7T ortoiseAdded]
    @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\8T ortoiseIgnored]
    @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\9T ortoiseUnversioned]
    @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
    2008-01-16 22:52 80384 ------w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Google Update"="c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
    "FlashMute"="c:\program files\FlashMute\FlashMute.exe" [2006-03-11 221184]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR .DLL" [2006-05-25 151552]
    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL " [2006-05-25 208896]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp .Exe" [2006-02-23 237568]
    "TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-03 856064]
    "TpShocks"="TpShocks.exe" [2006-03-16 106496]
    "TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKM GR.exe" [2006-07-25 94208]
    "TP4EX"="tp4ex.exe" [2005-10-17 65536]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
    "LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe " [2006-07-04 110592]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\I SUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
    "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-15 503808]
    "DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
    "PDService.exe"="c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 41472]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-15 2341632]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-20 286720]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
    "SPC230NC_Monitor"="c:\windows\Philips\SPC230NC\Mo nitor.exe" [2007-12-10 323584]
    "SPC_Monitor"="c:\windows\Philips\SPC230NC\Monitor .exe" [2007-12-10 323584]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-7-24 24576]
    TrayMin230.lnk - c:\program files\Philips\Philips SPC230NC Webcam\TrayMin230.exe [2008-12-15 241664]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
    [BU]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    [BU]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
    2006-08-16 17:07 49152 ------w- c:\program files\Lenovo\AwayTask\AwayNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
    [BU]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2006-04-26 02:20 40448 ------w- c:\windows\system32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
    2005-07-05 14:45 28672 ------w- c:\windows\system32\notifyf2.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
    2005-11-30 11:16 24576 ------w- c:\windows\system32\tphklock.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Dropbox.lnk]
    path=c:\documents and settings\Mike\Start Menu\Programs\Startup\Dropbox.lnk
    backup=c:\windows\pss\Dropbox.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    2008-01-17 16:51 486856 -c----w- c:\program files\DAEMON Tools Lite\daemon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    2008-11-07 19:31 21633320 ------r- c:\program files\Skype\Phone\Skype.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Philips\\Intelligent Agent\\Philips Intelligent Agent.exe"=
    "c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
    "c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
    "c:\\Program Files\\Eclipse\\eclipse\\eclipse.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\cygwin\\bin\\XWin.exe"=
    "c:\\Program Files\\Foxit Software\\Foxit Reader\\Foxit Reader.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
    "11476:TCP"= 11476:TCP:BitComet 11476 TCP
    "11476:UDP"= 11476:UDP:BitComet 11476 UDP

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/14/2010 9:18 PM 64288]
    R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 7:27 PM 53248]
    R2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [3/13/2006 7:05 PM 58368]
    R2 smi2;smi2;c:\program files\SMI2\smi2.sys [7/14/2006 6:55 PM 3968]
    R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [4/25/2006 10:00 PM 3456]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]
    S3 PAEAFLT.sys;USB Composite Device;c:\windows\system32\drivers\PAEAFLT.sys [12/15/2008 11:45 PM 8576]
    S3 SPC230NC;Philips SPC230NC Webcam;c:\windows\system32\drivers\SPC230NC.SYS [12/15/2008 11:45 PM 461056]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/4/2008 1:15 AM 716272]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - KLMDB
    *Deregistered* - klmdb

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    getPlusHelper REG_MULTI_SZ getPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 00:46]

    2010-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 22:57]

    2010-06-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3848391195-2397763145-3297269932-1008Core.job
    - c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 04:26]

    2010-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3848391195-2397763145-3297269932-1008UA.job
    - c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 04:26]

    2010-06-23 c:\windows\Tasks\PMTask.job
    - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-07-25 16:13]

    2010-06-22 c:\windows\Tasks\WGASetup.job
    - c:\windows\system32\KB905474\wgasetup.exe [2009-03-25 02:18]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
    FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\6lalxtmu.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
    FF - plugin: c:\documents and settings\Mike\Application Data\Mozilla\plugins\npgoogletalk.dll
    FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dl l
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_every where__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_bro ken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    .
    - - - - ORPHANS REMOVED - - - -

    SafeBoot-klmdb.sys



    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2010-06-22 23:05
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1344)
    c:\windows\system32\vrlogon.dll
    c:\windows\system32\tvt_gina.dll
    c:\program files\Lenovo\Client Security Solution\css_gina_plugin.dll
    c:\program files\Lenovo\Client Security Solution\css_wait_bar.dll
    c:\program files\Lenovo\Client Security Solution\cssuserdatadispatcher.dll
    c:\program files\Lenovo\Client Security Solution\csswait.dll
    c:\program files\Common Files\Lenovo\tvt_banner.dll
    c:\program files\Lenovo\Client Security Solution\cssdlgpwentry.dll
    c:\program files\Lenovo\Client Security Solution\dlganswerprompt.dll
    c:\program files\Lenovo\Client Security Solution\tvttsp.dll
    c:\program files\Lenovo\Client Security Solution\tcsrpc.dll
    c:\program files\Common Files\Lenovo\tvt_res.dll
    c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
    c:\program files\ThinkVantage Fingerprint Software\infra.dll
    c:\program files\ThinkVantage Fingerprint Software\VTI.DLL
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\psqlpwd.dll
    c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
    c:\windows\system32\biologon.dll
    c:\program files\ThinkVantage Fingerprint Software\homepass.dll
    c:\program files\ThinkVantage Fingerprint Software\bio.dll
    c:\program files\ThinkVantage Fingerprint Software\remote.dll
    c:\program files\ThinkVantage Fingerprint Software\crypto.dll
    c:\windows\system32\tphklock.dll
    c:\program files\Lenovo\AwayTask\AwayNotify.dll
    c:\windows\system32\notifyf2.dll

    - - - - - - - > 'lsass.exe'(1400)
    c:\windows\system32\psqlpwd.dll
    c:\program files\ThinkVantage Fingerprint Software\infra.dll
    c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

    - - - - - - - > 'explorer.exe'(3580)
    c:\windows\system32\WININET.dll
    c:\windows\system32\PROCHLP.DLL
    c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    c:\program files\TortoiseSVN\bin\TortoiseStub.dll
    c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
    c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2010-06-22 23:09:25
    ComboFix-quarantined-files.txt 2010-06-23 03:09
    ComboFix2.txt 2010-06-22 05:18

    Pre-Run: 13,035,917,312 bytes free
    Post-Run: 13,027,418,112 bytes free

    - - End Of File - - 31769DAEB6D3DCBBC04E5F9DC54E0DA1

  10. #10
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Good

    How is your computer doing at the moment?

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start>"Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall"
    Click OK (Vista users - press Enter).
    Restart computer.

    ================================================== =============

    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:



    netsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT



    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

+ Reply to Thread
Page 1 of 2 1 2 LastLast