Here's the text from the ComboFix log:
**************
ComboFix 09-06-22.0E - Kurt Zwald 06/23/2009 8:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1563 [GMT -10:00]
Running from: c:\documents and settings\Kurt Zwald\Desktop\Combo-Fix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\recycler\S-1-5-21-1550191824-2395574329-975625510-500
c:\windows\system32\drivers\SKYNETdtlbcqux.sys
c:\windows\system32\SKYNETcvafhbmm.dat
c:\windows\system32\SKYNETdanhnhag.dat
c:\windows\system32\SKYNETobprhufa.dll
c:\windows\system32\SKYNETvojhhvol.dll
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\recycler\S-1-5-21-1550191824-2395574329-975625510-500\desktop.ini
c:\recycler\S-1-5-21-1550191824-2395574329-975625510-500\INFO2
c:\windows\Install.txt
c:\windows\jsr468ijdfghfjsw3rw3i6tjag81.exe
c:\windows\system32\drivers\SKYNETdtlbcqux.sys
c:\windows\system32\Install.txt
c:\windows\system32\SKYNETcvafhbmm.dat
c:\windows\system32\SKYNETdanhnhag.dat
c:\windows\system32\SKYNETobprhufa.dll
c:\windows\system32\SKYNETvojhhvol.dll
c:\windows\system32\wiawow32.sys
----- BITS: Possible infected sites -----
hxxp://au.download.windoj+|Cv+@J:NGD_DQ{zcxLJS@_ONaJ0WU Client DownloadS-1-5-18`HT4?? 6VwoQZCDHM6VwoQZCDHMXuBn1Bn1Bn1Bn1W:cxLJS@GD_DQ{zGD_DQ{zGD_DQ{z+@J:Nj+|Cvupdate.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETplvqaecm
-------\Legacy_MSNCACHE
-------\Legacy_SOPIDKC
-------\Legacy_jsr468ijdfghfjsw3rw3i6tjag80
-------\Service_jsr468ijdfghfjsw3rw3i6tjag80
((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.
2009-06-23 18:18 . 2008-10-17 00:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-06-23 08:29 . 2009-06-23 08:29 -------- d-sh--w- c:\documents and settings\Kurt Zwald\PrivacIE
2009-06-23 08:22 . 2009-06-23 08:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-23 08:22 . 2009-06-23 08:22 -------- d-sh--w- c:\documents and settings\Kurt Zwald\IETldCache
2009-06-23 08:11 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-23 08:11 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-23 08:11 . 2009-06-23 08:11 -------- d-----w- c:\windows\ie8updates
2009-06-23 08:11 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-06-23 08:10 . 2009-06-23 08:10 -------- dc-h--w- c:\windows\ie8
2009-06-23 07:59 . 2009-06-23 07:59 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-23 07:42 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-06-23 07:42 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-06-23 07:40 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-23 07:38 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-06-23 07:36 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-23 07:36 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-06-23 07:36 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-06-23 07:34 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-06-23 07:22 . 2009-06-23 07:22 -------- d-----w- c:\windows\ServicePackFiles
2009-06-23 07:11 . 2009-06-23 07:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-06-22 10:38 . 2009-06-22 10:38 93 ----a-w- c:\windows\system32\SKYNET.dat
2009-06-22 10:35 . 2009-06-22 10:35 565096 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-21 11:34 . 2009-06-21 11:34 -------- d-----w- c:\program files\Trend Micro
2009-06-21 11:06 . 2009-06-23 18:42 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-21 11:06 . 2009-06-21 11:06 -------- d-----w- c:\program files\SpywareBlaster
2009-06-21 10:57 . 2009-06-23 07:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-21 10:57 . 2009-06-21 10:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-21 10:54 . 2009-03-09 19:06 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-21 10:49 . 2009-06-21 10:49 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-21 10:49 . 2009-06-21 10:49 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-21 10:49 . 2009-06-21 10:49 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-21 10:49 . 2009-06-21 10:49 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-21 10:49 . 2009-06-21 10:49 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-21 10:49 . 2009-06-21 10:49 296800 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-21 10:49 . 2009-06-21 10:49 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-21 10:28 . 2009-06-21 10:28 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-21 10:28 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-21 10:28 . 2009-06-21 10:28 -------- d-----w- c:\program files\Lavasoft
2009-06-21 10:28 . 2009-06-21 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-21 09:31 . 2007-02-28 00:31 21504 ----a-w- c:\windows\system32\drivers\motmodem.sys
2009-06-21 09:31 . 2006-11-14 00:45 1419232 ----a-w- c:\windows\system32\wdfcoinstaller01005.dll
2009-06-21 09:19 . 2009-06-21 09:21 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-06-21 00:52 . 2009-06-21 00:52 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\Malwarebytes
2009-06-21 00:52 . 2009-06-17 21:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-21 00:52 . 2009-06-21 00:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-21 00:52 . 2009-06-21 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-21 00:52 . 2009-06-17 21:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 08:12 . 2009-06-10 08:13 -------- d-----w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\Google
2009-06-10 08:12 . 2009-06-10 08:12 -------- d-----w- c:\program files\Google
2009-06-07 09:23 . 2004-02-19 00:46 815104 ----a-w- c:\documents and settings\Kurt Zwald\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\FlashPlayerW.dll
2009-06-07 09:23 . 2004-02-19 00:46 757760 ----a-w- c:\documents and settings\Kurt Zwald\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\NPSWF32.dll
2009-06-07 09:21 . 2009-06-07 09:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-06-07 09:20 . 2009-06-07 09:20 -------- d-----w- c:\program files\Common Files\Macromedia Shared
2009-06-07 09:19 . 2009-06-07 09:20 -------- d-----w- c:\program files\Common Files\Macromedia
2009-06-07 09:17 . 2009-06-07 09:20 -------- d-----w- c:\program files\Macromedia
2009-06-07 08:21 . 2009-06-07 08:21 -------- d--h--w- c:\windows\PIF
2009-06-07 05:08 . 2009-06-07 05:08 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\Canon
2009-06-07 05:06 . 2006-03-27 05:00 73728 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0409\CNMsr83.dll
2009-06-07 05:06 . 2006-03-27 05:00 69632 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0411\CNMlr83.dll
2009-06-07 05:06 . 2006-03-27 05:00 42496 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0411\CNMsr83.dll
2009-06-07 05:06 . 2006-03-27 05:00 322048 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0409\CNMur83.dll
2009-06-07 05:06 . 2006-03-27 05:00 241152 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0411\CNMur83.dll
2009-06-07 05:06 . 2006-03-27 05:00 122368 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP160 Printer\LanguageModules\0409\CNMlr83.dll
2009-06-07 05:06 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-07 05:05 . 2009-06-07 05:05 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\ScanSoft
2009-06-07 05:05 . 2009-06-07 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-06-07 05:05 . 2009-06-07 05:05 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-06-07 05:03 . 2009-06-07 05:03 -------- d-----w- c:\program files\ScanSoft
2009-06-07 05:02 . 2009-06-07 05:02 -------- d-----w- c:\program files\ArcSoft
2009-06-07 05:02 . 1995-08-01 14:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
2009-06-07 05:01 . 2009-06-07 05:01 -------- d-----w- c:\program files\Common Files\CANON
2009-06-07 04:58 . 2009-06-07 04:58 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-06-07 04:58 . 2006-03-27 05:00 161792 ----a-w- c:\windows\system32\CNMLM83.DLL
2009-06-07 04:58 . 2009-06-07 04:58 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2009-06-07 04:58 . 2006-02-17 15:44 106496 ----a-w- c:\windows\system32\cnco160.dll
2009-06-07 04:58 . 2006-03-24 15:29 135168 ----a-w- c:\windows\system32\CNCL160.DLL
2009-06-07 04:58 . 2006-03-15 15:27 57344 ----a-w- c:\windows\system32\CNCI160.DLL
2009-06-07 04:58 . 2006-03-15 15:27 1134592 ----a-w- c:\windows\system32\CNCC160.DLL
2009-06-07 04:57 . 2009-06-07 04:57 -------- d--h--w- c:\program files\CanonBJ
2009-06-07 04:56 . 2009-06-07 05:07 -------- d-----w- c:\program files\Canon
2009-06-07 04:55 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-07 04:53 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-06-06 22:09 . 2009-06-06 22:09 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\Apple Computer
2009-06-02 11:21 . 2009-06-02 11:21 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\Windows Search
2009-06-02 11:05 . 2009-06-02 11:05 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\Windows Desktop Search
2009-06-01 19:20 . 2009-06-01 19:20 -------- d-----w- c:\windows\Sun
2009-06-01 19:19 . 2009-06-01 19:19 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-01 19:18 . 2009-06-01 19:18 152576 ----a-w- c:\documents and settings\Kurt Zwald\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-01 19:14 . 2009-06-21 00:36 -------- d-----w- C:\QUARANTINE
2009-06-01 11:47 . 2009-06-01 11:47 0 ----a-w- c:\windows\nsreg.dat
2009-06-01 11:47 . 2009-06-01 11:47 -------- d-----w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\Mozilla
2009-06-01 10:04 . 2009-06-01 10:04 -------- d-----w- c:\program files\Common Files\Supportsoft
2009-06-01 09:30 . 2009-06-01 09:30 -------- d-----w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\Identities
2009-06-01 09:30 . 2009-06-23 08:21 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-01 09:30 . 2009-06-01 09:30 -------- d-----w- c:\windows\system32\GroupPolicy
2009-06-01 09:29 . 2008-03-07 17:02 98304 ------w- c:\windows\system32\dllcache\nlhtml.dll
2009-06-01 09:29 . 2008-03-07 17:02 29696 ------w- c:\windows\system32\dllcache\mimefilt.dll
2009-06-01 09:29 . 2008-03-07 17:02 192000 ------w- c:\windows\system32\dllcache\offfilt.dll
2009-06-01 07:53 . 2009-06-23 07:24 -------- d-----w- c:\windows\system32\scripting
2009-06-01 07:53 . 2009-06-23 07:24 -------- d-----w- c:\windows\l2schemas
2009-06-01 07:53 . 2009-06-23 07:24 -------- d-----w- c:\windows\system32\en
2009-06-01 07:53 . 2009-06-23 07:24 -------- d-----w- c:\windows\system32\bits
2009-06-01 07:51 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-06-01 07:46 . 2009-02-09 12:10 473600 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-06-01 07:40 . 2004-08-04 08:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2009-06-01 07:39 . 2004-08-04 08:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2009-06-01 07:36 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-06-01 07:27 . 2008-10-03 10:15 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-06-01 07:26 . 2008-09-04 16:42 1106944 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-06-01 07:19 . 2009-06-23 08:30 69232 ----a-w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-01 07:00 . 2009-06-01 07:00 -------- d-----w- c:\program files\Common Files\Cisco Systems
2009-06-01 07:00 . 2009-06-01 07:00 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-01 07:00 . 2006-11-17 10:06 1495552 ----a-w- c:\windows\system32\epoPGPsdk.dll
2009-06-01 06:59 . 2008-07-17 03:50 72936 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-06-01 06:59 . 2008-07-17 03:50 64232 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-06-01 06:59 . 2008-07-17 03:50 52104 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-06-01 06:59 . 2008-07-17 03:50 33960 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-06-01 06:59 . 2008-07-17 03:50 174952 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-06-01 06:59 . 2009-06-01 07:00 -------- d-----w- c:\program files\McAfee
2009-06-01 06:59 . 2009-06-01 06:59 -------- d-----w- c:\program files\Common Files\McAfee
2009-06-01 06:57 . 2009-06-01 06:57 -------- d-----w- c:\documents and settings\Kurt Zwald\Application Data\AdobeUM
2009-06-01 06:56 . 2009-06-01 06:56 -------- d-----w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\Adobe
2009-06-01 06:56 . 2009-06-01 06:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-01 06:50 . 2009-06-23 08:16 -------- d-----w- c:\program files\Microsoft Works
2009-06-01 06:49 . 2009-06-01 06:49 -------- d-----w- c:\program files\MSBuild
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 07:25 . 2006-04-30 07:12 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-21 10:47 . 2009-06-21 10:47 1630048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-21 10:47 . 2009-06-21 10:47 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-21 10:47 . 2009-06-21 10:47 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-21 10:47 . 2009-06-21 10:47 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-21 10:47 . 2009-06-21 10:29 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-21 10:47 . 2009-06-21 10:47 72704 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-21 10:47 . 2009-06-21 10:47 640360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-21 10:47 . 2009-06-21 10:47 561016 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-21 10:47 . 2009-06-21 10:47 2349384 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-21 10:46 . 2009-06-21 10:46 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-21 10:46 . 2009-06-21 10:46 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-21 10:46 . 2009-06-21 10:46 1003344 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-21 10:31 . 2009-06-21 10:31 -------- d-----w- c:\program files\CCleaner
2009-06-21 09:33 . 2009-06-21 09:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-21 09:33 . 2009-06-21 09:33 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-21 09:31 . 2009-06-21 09:19 -------- d-----w- c:\program files\Motorola Phone Tools
2009-06-21 09:31 . 2009-06-21 09:31 -------- d-----w- c:\program files\Common Files\Motorola Shared
2009-06-21 09:22 . 2009-06-21 09:21 -------- d-----w- c:\program files\Avanquest update
2009-06-21 09:19 . 2009-06-21 09:19 9232 ----a-w- c:\documents and settings\Kurt Zwald\mqdmmdfl.sys
2009-06-21 09:19 . 2009-06-21 09:19 92064 ----a-w- c:\documents and settings\Kurt Zwald\mqdmmdm.sys
2009-06-21 09:19 . 2009-06-21 09:19 79328 ----a-w- c:\documents and settings\Kurt Zwald\mqdmserd.sys
2009-06-21 09:19 . 2009-06-21 09:19 6208 ----a-w- c:\documents and settings\Kurt Zwald\mqdmcmnt.sys
2009-06-21 09:19 . 2009-06-21 09:19 5936 ----a-w- c:\documents and settings\Kurt Zwald\mqdmwhnt.sys
2009-06-21 09:19 . 2009-06-21 09:19 4048 ----a-w- c:\documents and settings\Kurt Zwald\mqdmcr.sys
2009-06-21 09:19 . 2009-06-21 09:19 66656 ----a-w- c:\documents and settings\Kurt Zwald\mqdmbus.sys
2009-06-21 09:19 . 2009-06-21 09:19 25600 ----a-w- c:\documents and settings\Kurt Zwald\usbsermptxp.sys
2009-06-21 09:19 . 2009-06-21 09:19 22768 ----a-w- c:\documents and settings\Kurt Zwald\usbsermpt.sys
2009-06-06 22:09 . 2009-06-06 22:09 -------- d-----w- c:\program files\iTunes
2009-06-06 22:09 . 2009-06-06 22:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-06 22:09 . 2009-06-06 22:09 -------- d-----w- c:\program files\iPod
2009-06-06 22:09 . 2009-06-06 22:07 -------- d-----w- c:\program files\Common Files\Apple
2009-06-06 22:09 . 2009-06-06 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-06 22:08 . 2009-06-06 22:08 -------- d-----w- c:\program files\Bonjour
2009-06-06 22:08 . 2009-06-06 22:08 -------- d-----w- c:\program files\QuickTime
2009-06-06 22:08 . 2009-06-06 22:08 -------- d-----w- c:\program files\Apple Software Update
2009-06-06 22:07 . 2009-06-06 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-01 19:18 . 2009-06-01 01:42 -------- d-----w- c:\program files\Java
2009-06-01 10:31 . 2009-06-01 03:38 -------- d-----w- c:\program files\Windows Live Toolbar
2009-06-01 03:39 . 2009-06-01 03:38 133 ----a-w- c:\documents and settings\Kurt Zwald\Local Settings\Application Data\fusioncache.dat
2009-06-01 01:37 . 2009-06-01 01:37 -------- d-----w- c:\program files\ATI Technologies
2009-06-01 01:37 . 2009-06-01 01:37 -------- d-----w- c:\program files\Digital Line Detect
2009-06-01 01:37 . 2009-06-01 01:37 -------- d-----w- c:\program files\NetWaiting
2009-06-01 01:37 . 2009-06-01 01:37 -------- d-----w- c:\program files\CONEXANT
2009-06-01 01:35 . 2009-06-01 01:35 0 ---ha-r- c:\windows\system32\drivers\IBM_8743_CTO_TP.MRK
2009-06-01 01:33 . 2009-06-01 01:33 -------- d-----w- c:\program files\Synaptics
2009-05-25 10:24 . 2008-05-27 08:18 350208 ----a-w- c:\windows\system32\mssph.dll
2009-05-13 05:15 . 2006-04-30 06:56 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-13 01:12 . 2006-04-30 07:28 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 15:32 . 2009-06-01 07:46 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 04:55 . 2009-04-29 04:55 78336 ------w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2009-06-01 07:46 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2009-06-01 07:46 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-02-23 237568]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-03 856064]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-07-04 110592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-01 148888]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 487424]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-15 503808]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-02-19 409600]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-02-19 110592]
"PDService.exe"="c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 41472]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-15 2341632]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-07-17 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-21 518488]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2006-03-16 106496]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2006-5-31 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-5-31 24576]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
2006-08-16 17:07 49152 ----a-w- c:\program files\Lenovo\AwayTask\AwayNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2007-02-19 23:03 32768 ----a-w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 14:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 11:16 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/21/2009 12:29 AM 64160]
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [5/31/2009 3:33 PM 88576]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [5/31/2009 3:33 PM 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [5/31/2009 3:32 PM 4442]
R2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [3/13/2006 1:05 PM 58368]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [7/14/2006 12:55 PM 3968]
S3 Irdnbedsd;Irdnbedsd;c:\windows\system32\drivers\i2omgmt.sys [5/31/2009 9:46 PM 8576]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 9:06 AM 1003344]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 10:35]
2009-06-23 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-06-01 16:13]
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://lenovo.live.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-23 08:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1340)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll
c:\program files\Lenovo\AwayTask\AwayNotify.dll
- - - - - - - > 'explorer.exe'(6120)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\searchindexer.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
.
**************************************************************************
.
Completion time: 2009-06-23 9:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-23 19:01
Pre-Run: 80,462,045,184 bytes free
Post-Run: 80,387,985,408 bytes free
403 --- E O F --- 2009-06-01 09:09