No worries Mike, again, appreciate your help.
New ComboFix Log
ComboFix 08-07-04.6 - Lawrence Wang 2008-07-06 10:49:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.536 [GMT -7:00]
Running from: C:\Documents and Settings\Lawrence Wang\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lawrence Wang\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\Lawrence Wang\Start Menu\Programs\Startup\DW_Start.lnk
C:\WINDOWS\kgqfwelteax.dll
C:\WINDOWS\system32\{0b1672fc-5caf-8767-cabe-817b9b4b9333}.dll-uninst.exe
C:\WINDOWS\system32\ohuhawqd.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Lawrence Wang\Desktop\Error Cleaner.url
C:\Documents and Settings\Lawrence Wang\Desktop\Privacy Protector.url
C:\Documents and Settings\Lawrence Wang\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Lawrence Wang\Favorites\Error Cleaner.url
C:\Documents and Settings\Lawrence Wang\Favorites\Privacy Protector.url
C:\Documents and Settings\Lawrence Wang\Favorites\Spyware&Malware Protection.url
C:\Temp\itmp4
C:\Temp\itmp4\mkbv4i.log
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfwelteax.dll
C:\WINDOWS\nqgpedlr.dll
C:\WINDOWS\okmdepgb.dll
C:\WINDOWS\system32\{0b1672fc-5caf-8767-cabe-817b9b4b9333}.dll-uninst.exe
C:\WINDOWS\system32\1049a
C:\WINDOWS\system32\axc
C:\WINDOWS\system32\bgi
C:\WINDOWS\system32\dqjefmmk.dll
C:\WINDOWS\system32\dqwahuho.dll
C:\WINDOWS\system32\eb10
C:\WINDOWS\system32\netrax06
C:\WINDOWS\system32\ohuhawqd.ini
C:\WINDOWS\system32\vebcnqbm.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSPQMM
-------\Service_MSPQMM
((((((((((((((((((((((((( Files Created from 2008-06-06 to 2008-07-06 )))))))))))))))))))))))))))))))
.
2008-07-05 11:37 . 2008-07-05 11:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-04 18:09 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-04 18:09 . 2008-07-04 18:09 376 --a------ C:\WINDOWS\ODBC.INI
2008-07-04 18:08 . 2008-07-04 18:08 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-04 18:06 . 2008-07-04 18:06 <DIR> dr-h----- C:\MSOCache
2008-07-04 16:33 . 2008-07-04 16:34 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-04 16:19 . 2008-07-04 16:29 401 --a------ C:\WINDOWS\wininit.ini
2008-07-04 15:34 . 2008-07-04 15:34 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-04 15:34 . 2008-07-04 15:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-04 15:32 . 2008-07-04 15:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-04 15:10 . 2008-07-04 19:02 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-04 15:06 . 2008-07-04 16:07 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-04 15:06 . 2008-07-04 15:06 <DIR> d-------- C:\Program Files\AVG
2008-07-04 15:06 . 2008-07-04 16:19 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\AVGTOOLBAR
2008-07-04 15:06 . 2008-07-04 15:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-04 15:06 . 2008-07-04 16:15 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-04 15:06 . 2008-07-04 16:16 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-04 15:06 . 2008-07-04 15:06 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old
2008-07-04 15:06 . 2008-07-04 16:15 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-04 14:34 . 2008-07-06 10:49 <DIR> d-------- C:\Temp
2008-07-04 00:06 . 2008-07-04 00:06 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-06-29 13:03 . 2008-06-29 13:03 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-06-29 13:03 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-29 13:03 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-29 13:03 . 2008-05-08 05:28 202,752 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-29 13:02 . 2006-08-21 02:14 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-06-29 13:02 . 2006-08-21 02:14 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-06-29 13:02 . 2006-08-21 05:21 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-06-19 19:09 . 2008-06-19 19:25 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\ppstream
2008-06-18 21:25 . 2008-06-18 21:25 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-06-16 23:16 . 2008-07-04 16:23 65,404 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-06-16 22:59 . 2008-07-04 18:27 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-16 22:54 . 2008-06-16 22:54 <DIR> d-------- C:\WINDOWS\Sun
2008-06-16 22:48 . 2008-06-16 22:48 <DIR> d-------- C:\Program Files\uTorrent
2008-06-16 22:48 . 2008-07-04 16:13 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\uTorrent
2008-06-16 22:24 . 2008-06-16 22:25 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\Corel
2008-06-16 22:24 . 2008-06-16 22:24 2,828 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-16 22:24 . 2008-06-16 22:24 88 -rahs---- C:\WINDOWS\system32\
09E831A509.sys
2008-06-16 22:11 . 2008-06-16 22:11 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\Apple Computer
2008-06-16 22:10 . 2008-06-16 22:10 <DIR> d-------- C:\Program Files\Safari
2008-06-16 22:09 . 2008-06-16 22:10 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-16 22:09 . 2008-06-16 22:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-16 22:01 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-16 21:58 . 2008-07-04 01:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-16 21:53 . 2008-06-16 22:39 <DIR> d-------- C:\Documents and Settings\Lawrence Wang\Application Data\U3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 01:43 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-05 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Corel
2008-07-05 01:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Borland
2008-07-04 21:41 --------- d-----w C:\Program Files\PCDR5
2008-07-04 21:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-29 06:07 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-06-29 04:18 --------- d-----w C:\Program Files\Google
2008-06-17 05:59 --------- d-----w C:\Program Files\Picasa2
2008-06-17 05:25 --------- d-----w C:\Program Files\Corel
2008-06-17 05:01 --------- d-----w C:\Program Files\Java
2008-05-29 05:43 --------- d-----w C:\Documents and Settings\Lawrence Wang\Application Data\Ahead
2008-05-29 05:42 --------- d-----w C:\Program Files\Nero
2008-05-29 05:42 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-28 20:55 --------- d-----w C:\Program Files\DAEMON Tools
2008-05-28 20:36 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-05-28 19:42 --------- d-----w C:\Program Files\Prime95
2008-05-25 04:29 --------- d-----w C:\Documents and Settings\Lawrence Wang\Application Data\Sonic
2008-05-25 04:29 --------- d-----w C:\Documents and Settings\Lawrence Wang\Application Data\Leadertech
2008-05-19 04:04 --------- d-----w C:\Documents and Settings\Lawrence Wang\Application Data\Lenovo
2008-05-19 01:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lenovo
2008-05-19 01:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Lenovo
2008-05-11 20:25 50 ----a-w C:\WINDOWS\system32\drivers\LENOVO_0769_AUU.MRK
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-17 18:54 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-05_13.57.24.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-05 18:34:33 64,774 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-06 17:42:47 64,774 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-07-05 18:34:33 409,800 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-06 17:42:47 409,800 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-06 17:52:30 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_408.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1421B799-C4AA-4F81-89D9-01E1FBFA29FE}]
C:\WINDOWS\system32\geBroopp.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE99EB12-A2D7-42D7-8BC2-754431199E2F}]
C:\WINDOWS\system32\fcccdbcc.dll [BU]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-16 21:58 68856]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 15:29 165784]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 16:25 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-02-08 13:19 536576]
"TPWAUDAP"="C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-09-06 00:38 54824]
"TPFNF7"="C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 11:03 58416]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-18 22:51 774233]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PMHandler"="C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe" [2007-03-16 05:26 31840]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:00 455168]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-23 00:32 138008]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 15:42 321088]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00 59392]
"LPManager"="C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-04-26 10:10 120368]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 05:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 05:00 44032]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-23 00:32 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-23 00:32 162584]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 16:24 196696]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-03 16:35 2630968]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-10-12 00:28 1282048]
"AzMixerSel"="C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2007-08-23 00:36 53248]
"AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 03:51 91688]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-04 15:06 1177368]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 11:00 439856]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-07-05 14:51 126976]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-07-05 14:58 413696]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 00:21 16384000 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 00:40 89542 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{AE99EB12-A2D7-42D7-8BC2-754431199E2F}"= "C:\WINDOWS\system32\fcccdbcc.dll" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2007-05-31 13:57 155648 C:\WINDOWS\system32\FpWinlogonNp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-13 19:06 28672 C:\Program Files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2007-07-05 14:52 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FingerPrintSoftware]
--a------ 2007-05-31 13:07 946176 C:\Program Files\Lenovo Fingerprint Software\fpapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 09:27]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-04 16:15]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2007-04-02 11:24]
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys [2006-05-24 11:48]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-04 15:06]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-04 15:06]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-04 16:16]
R2 FNF5SVC;Fn+F5 Service;C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe [2007-04-08 18:24]
R2 TVT Backup Protection Service;TVT Backup Protection Service;C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-02-08 13:11]
R3 TVTI2C;Lenovo SM bus driver;C:\WINDOWS\system32\DRIVERS\Tvti2c.sys [2007-05-22 15:59]
S3 FingerprintServer;Fingerprint Server;C:\WINDOWS\system32\FpLogonServ.exe [2007-06-22 11:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ebd41f4e-2546-11dd-adb6-001eec08d55b}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-moptfjwk - C:\WINDOWS\system32\vebcnqbm.exe
HKLM-Run-30ff45b6 - C:\WINDOWS\system32\dqwahuho.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-06 10:53:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Lenovo\HOTKEY\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2008-07-06 10:56:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-06 17:56:07
ComboFix2.txt 2008-07-05 21:59:58
Pre-Run: 97,726,054,400 bytes free
Post-Run: 97,710,039,040 bytes free
256 --- E O F --- 2008-07-03 07:05:42
Edited by timzerofive, 06 July 2008 - 12:02 PM.