I was able to run ComboFix in safe mode. After it launched and began to run it stopped and gave me the following:
"You are infected with Rootkit.ZeroAccess! It has inserted itself into the tcp/ip stack. This is a particulary difficult infection."
It went on further but it blipped up two more rapid screens that I was unable to read and then stated that it needed to reboot. I was able to get it back into safe mode for it to finish the scan. It then rebooted again before giving me a log. I was unable to catch it and it rebooted in regular mode. The log appeared and it listed below. The only problem I'm encountering so far is that ComboFix seems to have wiped out my wireless internet access. I am directly plugged in now to be able to get online, otherwise I have no means to access the internet. We have an encrypted router and I do not know how to get back into it. This is a Lenovo machine and used ThinkVantage Access Connections and that protocol is gone from the machine.
Here is the ComboFix log.
ComboFix 11-09-12.02 - Jennifer E. Olson 09/12/2011 12:38:58.2.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.826 [GMT -5:00]
Running from: c:\documents and settings\Jennifer E. Olson\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleCrashHandler.exe
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdate.exe
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdateBroker.exe
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdateOnDemand.exe
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdate.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_am.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ar.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_bg.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_bn.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ca.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_cs.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_da.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_de.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_el.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_en-GB.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_en.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_es-419.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_es.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_et.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fa.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fi.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fil.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fr.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_gu.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hi.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hr.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hu.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_id.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_is.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_it.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_iw.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ja.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_kn.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ko.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_lt.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_lv.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ml.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_mr.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ms.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_nl.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_no.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pl.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pt-BR.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pt-PT.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ro.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ru.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sk.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sl.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sr.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sv.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sw.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ta.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_te.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_th.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_tr.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_uk.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ur.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_vi.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_zh-CN.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_zh-TW.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\npGoogleUpdate3.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\psmachine.dll
c:\docume~1\JENNIF~1.OLS\LOCALS~1\Temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\psuser.dll
c:\documents and settings\Administrator\Start Menu\Programs\Startup\gaobib.exe
c:\documents and settings\Administrator\Start Menu\Programs\Startup\imnaxy.exe
c:\documents and settings\Administrator\Start Menu\Programs\Startup\tiito.exe
c:\documents and settings\Default User\Start Menu\Programs\Startup\ceriev.exe
c:\documents and settings\Default User\Start Menu\Programs\Startup\fewe.exe
c:\documents and settings\Default User\Start Menu\Programs\Startup\tiito.exe
c:\documents and settings\Family\Application Data\Agcyky
c:\documents and settings\Family\Application Data\Agcyky\qiumm.sug
c:\documents and settings\Family\Application Data\Albys
c:\documents and settings\Family\Application Data\Albys\pyduz.tmp
c:\documents and settings\Family\Application Data\Kokydo
c:\documents and settings\Family\Application Data\Kokydo\elydo.exe
c:\documents and settings\Jennifer E. Olson\Application Data\Oqdeyg
c:\documents and settings\Jennifer E. Olson\Application Data\Oqdeyg\ehpou.exe
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleCrashHandler.exe
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdate.exe
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdateBroker.exe
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\GoogleUpdateOnDemand.exe
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdate.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_am.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ar.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_bg.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_bn.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ca.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_cs.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_da.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_de.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_el.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_en-GB.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_en.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_es-419.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_es.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_et.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fa.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fi.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fil.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_fr.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_gu.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hi.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hr.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_hu.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_id.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_is.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_it.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_iw.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ja.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_kn.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ko.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_lt.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_lv.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ml.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_mr.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ms.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_nl.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_no.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pl.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pt-BR.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_pt-PT.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ro.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ru.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sk.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sl.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sr.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sv.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_sw.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ta.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_te.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_th.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_tr.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_uk.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_ur.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_vi.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_zh-CN.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\goopdateres_zh-TW.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\npGoogleUpdate3.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\psmachine.dll
c:\documents and settings\Jennifer E. Olson\Local Settings\temp\{51F1AB80-D82C-4548-B248-BB8CC1B00C33}\psuser.dll
c:\windows\$NtUninstallKB52032$\1534778459
c:\windows\2426613655
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\system32\Dll.dll
c:\windows\system32\shimg.dll
c:\windows\$NtUninstallKB52032$ . . . . Failed to delete
.
Infected copy of c:\windows\system32\wuauclt.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wuauclt.exe
.
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe . . . is infected!!
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe . . . is infected!!
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe . . . is infected!!
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\windows\system32\Ati2evxx.exe . . . is infected!!
c:\windows\system32\Ati2evxx.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Bonjour\mDNSResponder.exe . . . is infected!!
c:\program files\Bonjour\mDNSResponder.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Intel\WiFi\bin\EvtEng.exe . . . is infected!!
c:\program files\Intel\WiFi\bin\EvtEng.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\windows\system32\ibmpmsvc.exe . . . is infected!!
c:\windows\system32\ibmpmsvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Java\jre6\bin\jqs.exe . . . is infected!!
c:\program files\Java\jre6\bin\jqs.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE . . . is infected!!
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe . . . is infected!!
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe . . . is infected!!
c:\program files\Intel\WiFi\bin\S24EvMon.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Analog Devices\SoundMAX\SMAgent.exe . . . is infected!!
c:\program files\Analog Devices\SoundMAX\SMAgent.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Viewpoint\Common\ViewpointService.exe . . . is infected!!
c:\program files\Viewpoint\Common\ViewpointService.exe . . . was deleted!! You should re-install the program it pertains to
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_972fa390
.
.
((((((((((((((((((((((((( Files Created from 2011-08-12 to 2011-09-12 )))))))))))))))))))))))))))))))
.
.
2011-09-12 17:20 . 2011-09-12 17:20 -------- d-----w- C:\d039f2ec59f35d1d02
2011-09-12 17:17 . 2011-09-12 17:17 -------- d-----w- C:\5594995e1f7ac02457c2261d00b0
2011-09-12 17:17 . 2011-09-12 17:17 -------- d-----w- C:\d0934c2aa034db2ae4
2011-09-12 13:32 . 2011-09-12 13:32 -------- d--h--w- c:\windows\PIF
2011-09-12 13:02 . 2011-09-12 17:27 50112 --sha-w- c:\windows\system32\c_07600.nl_
2011-09-10 21:12 . 2011-09-10 21:12 -------- d-----w- c:\program files\Runtime Software
2011-09-10 20:23 . 2011-07-07 00:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-10 20:23 . 2011-09-10 20:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-10 20:23 . 2011-07-07 00:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-10 18:54 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-09-10 18:46 . 2010-12-09 13:42 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-09-10 18:46 . 2010-12-09 13:38 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-09-10 18:46 . 2010-12-09 13:07 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-09-10 18:46 . 2010-12-09 13:07 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-09-10 18:45 . 2011-02-17 12:32 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-09-10 18:33 . 2007-11-30 11:18 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-09-10 18:33 . 2011-09-12 10:59 -------- d--h--w- c:\windows\$hf_mig$
2011-09-10 11:47 . 2011-09-10 11:47 -------- d-----w- c:\program files\Lavasoft
2011-09-09 15:40 . 2011-09-09 15:40 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2011-09-09 15:40 . 2011-09-09 15:40 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-09-09 15:40 . 2011-09-09 15:40 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2011-09-09 15:40 . 2011-09-09 15:40 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2011-09-09 15:23 . 2011-09-09 15:23 -------- d-----w- c:\documents and settings\Jennifer E. Olson\Application Data\Poeceq
2011-09-09 15:23 . 2011-09-09 16:23 -------- d-----w- c:\documents and settings\Jennifer E. Olson\Application Data\Gyat
2011-09-09 15:18 . 2011-09-09 22:45 -------- d-----w- c:\documents and settings\Family\Application Data\Ebolo
2011-09-09 15:18 . 2011-09-09 16:23 -------- d-----w- c:\documents and settings\Family\Application Data\Upygxe
2011-09-07 21:15 . 2011-09-07 21:15 -------- d-s---w- c:\documents and settings\LocalService\UserData
2011-09-07 20:53 . 2011-09-07 21:24 -------- d-----w- c:\documents and settings\Jennifer E. Olson\Application Data\Vataba
2011-09-07 20:53 . 2011-09-07 21:14 -------- d-----w- c:\documents and settings\Jennifer E. Olson\Application Data\Hiityw
2011-09-07 01:53 . 2011-09-07 01:53 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-09-06 13:35 . 2011-09-06 13:35 -------- d-----w- c:\documents and settings\Family\Application Data\Malwarebytes
2011-09-05 20:15 . 2011-09-05 20:18 -------- d-----w- c:\program files\Spybot
2011-09-05 19:06 . 2011-09-05 19:06 -------- d-----w- C:\System Recovery
2011-09-03 19:14 . 2011-09-07 20:54 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-08-27 22:53 . 2011-08-27 22:53 -------- d-----w- C:\Adobe
2011-08-27 21:01 . 2011-08-27 21:01 -------- d-s---w- c:\documents and settings\NetworkService\UserData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-12 13:01 . 2008-04-14 00:48 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2011-09-03 10:17 . 2008-12-13 15:47 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-08-18 20:25 . 2009-05-13 23:43 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-07-15 13:29 . 2008-12-13 15:47 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2008-12-13 15:47 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-30 01:35 . 2010-10-14 01:26 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10 . 2008-12-13 16:58 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:18 . 2008-12-13 15:47 667136 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 18:18 . 2008-12-13 15:47 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-06-21 18:18 . 2008-12-13 15:47 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-06-21 12:58 . 2008-12-13 15:47 369664 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2008-12-13 15:47 293376 ----a-w- c:\windows\system32\winsrv.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-11-21 3289088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"PSQLLauncher"="c:\program files\ThinkVantage Fingerprint Software\launcher.exe" [2008-06-25 49928]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-08-16 425984]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-08-16 143360]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"Daemon for Mouse Suite"="c:\program files\Lenovo\Lenovo Mouse Suite\ICO.EXE" [2009-11-06 98304]
"SKDaemon.exe"="c:\program files\Lenovo\Productivity Keyboard\SKDaemon.exe" [2006-12-05 262144]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
.
c:\documents and settings\Family\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
.
c:\documents and settings\Jennifer E. Olson\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-06-25 01:31 95496 ----a-w- c:\windows\system32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Documents and Settings\\Jennifer E. Olson\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/13/2009 6:43 PM 64512]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [12/13/2008 10:47 AM 14336]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [6/24/2008 8:07 PM 12560]
R3 pelps2m;PS/2 Mouse Filter Driver;c:\windows\system32\drivers\PelPs2m.sys [7/12/2010 10:19 PM 19818]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/21/2011 9:44 PM 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [8/18/2011 3:25 PM 2151640]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/21/2011 9:44 PM 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [8/18/2011 3:25 PM 15232]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-08-18 20:25]
.
2011-06-06 c:\windows\Tasks\AdobeAAMUpdater-1.0-JENNIFER-Jennifer E. Olson.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-05-12 08:44]
.
2011-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-22 02:44]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-22 02:44]
.
2011-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2053719858-2472827367-994003569-1004Core.job
- c:\documents and settings\Jennifer E. Olson\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-10 21:59]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2053719858-2472827367-994003569-1004UA.job
- c:\documents and settings\Jennifer E. Olson\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-10 21:59]
.
2011-09-12 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-10 03:18]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 68.94.156.1 68.94.157.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-volmgr - c:\documents and settings\Jennifer E. Olson\Application Data\volmgr.exe
SafeBoot-05468349.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-12 12:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.imapi]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.redbook]
"ImagePath"="\*"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(896)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
.
- - - - - - - > 'explorer.exe'(2516)
c:\program files\Lenovo\Lenovo Mouse Suite\pelscrll.dll
c:\program files\Lenovo\Lenovo Mouse Suite\PELCOMM.dll
c:\program files\Lenovo\Lenovo Mouse Suite\PELHOOKS.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\Lenovo\Lenovo Mouse Suite\FSRremoS.EXE
c:\program files\Lenovo\Lenovo Mouse Suite\Pelmiced.exe
.
**************************************************************************
.
Completion time: 2011-09-12 12:59:46 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-12 17:59
ComboFix2.txt 2011-09-06 23:27
.
Pre-Run: 49,045,671,936 bytes free
Post-Run: 47,981,862,912 bytes free
.
- - End Of File - - 6ABA3477941E7108FC9AF5D9FD718203