Interesting (and very annoying) Keyboard mapping problem

#1 JimNS


Posted 09 November 2009 - 12:35 PM

ThinkPad R40 27225JU
ThinkPad Embedded Controller 1.14

XP Professional SP3
System and ThinkVantage software and updates are completely current.

Upgraded to 2GB RAM
Replaced original Chicony 08K4757 keyboard with NMB 08K4729
Replaced original Hitachi Travelstar 08K1089 HD with Hitachi Travelstar 7K100 100GB ATA-6 2.5in 7200RPM HD w/8MB

For the past 12 to 18 months I have been suffering with a keyboard key mapping problem. The problem occurs anytime I reboot and, since I didn’t have to do that too often until recently, I’ve been able to live with it (until now, that is).

When I reboot, some keyboard keys do not map correctly. Some keys do seem to mismap more often than others (for instance ESC, F7, F8, C, X, M, N, Q, D, 3, 1, comma, period, etc, etc) but the problem is not restricted to these keys, there’s no pattern to the keys they mis-map to, and I am unable to discern any pattern, binary or otherwise.

I have PassMark Keyboard Test 3.0 which shows me the BIOS and Windows key codes. When I hit a mis-mapped key, both the BIOS and the Windows key codes accurately reflect the wrong key. For instance, if the “1” key mismaps to the “3” key, both the BIOS and the Windows key codes reflect the key codes for “3” when I press “1”. The mis-maps occur even when I boot into Safe mode and run the PassMark Keyboard Test.

If I reboot repeatedly, perhaps three to six times, I will eventually have a “clean” keyboard. I now teach and have to get to class an hour and a half early to be sure I have enough time to get my ThinkPad up and working – very annoying.

This is not a hardware problem. I have replaced the keyboard as noted above. I have an extra hard drive which I reformatted with a new XP image. There’s no problem when I boot from that hard drive. When I install an external keyboard, it has the same problem as the ThinkPad keyboard – same keys, same mis-maps. I have uninstalled the keyboards and all HID interfaces in device manager, rebooted and still have the problem.

I worked with one of the top techs at PlumChoice off and on over a week and he and I put about four hours into playing with this (he was remote of course). We ran several utilities looking for registry or virus problems – ComboFix, DialaFix, CCCleaner. By the way, PlumChoice loads a remote keyboard utility on my system and when that is active I have no problem even on my laptop keyboard. I can reboot repeatedly and no problem. Unfortunately, that’s gone once PlumChoice drops out. I have up-to-date Symantec Antivirus and WinpatrolPlus running on my system.

Until recently I was getting the following Service Control Manager Event ID: 7000 errors in the event viewer:

PMEM service failed to start due to the following error: The system cannot find the file specified.
The ABS PortIO Service service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

To stop these services from attempting to start, I changed their registry START values to 4 based on a forum I read somewhere that suggested that.

Finally, suspecting the keyboard drivers, I manually replaced i8042prt.sys and kbdclass.sys at C:\WINDOWS\system32\drivers with those from a new XP Pro image I had on another hard drive. Not sure about self healing and whether this actually replaced anything, but manually replacing these drivers didn’t change anything.

The reason I am posting to this forum is to see if anyone has any ideas and because ComboFix gave me the following message which I don’t understand:

------- Sigcheck -------

[7] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\kbdclass.sys
[7] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
[7] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys
[-] 2001-08-23 . 9C30CD464D87102497FD7C32910E6253 . 23424 . . [5.1.2600.0] . . c:\windows\system32\drivers\kbdclass.sys

Not sure if this means anything (or even what Sigcheck even means) but 4/13/2008 may have been around the time this keyboard mapping horror began and kbdclass.sys is one of the keyboard drivers.

Personally, I suspect some sort of corruption in the keyboard bootup process or a particularly diabolical virus and that’s ultimately why I am posting to this forum.

Thanks in advance to anyone willing to help me with this head scratcher.


DDS (Ver_09-10-26.01) - NTFSx86
Run by Jim at 11:24:02.08 on Mon 11/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1371 [GMT -6:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Jim Schneringer\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp:///
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp:///
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy.verizon.com:80
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchURL = hxxp:///
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [TPKMAPMN] c:\program files\thinkpad\utilities\TpKmapMn.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [MXOBG] c:\windows\MXOALDR.EXE
mRun: [Message Center Plus] c:\program files\lenovo\message center plus\MCPLaunch.exe /start
mRun: [MaxtorOneTouch] c:\program files\maxtor\onetouch\utils\Onetouch.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [HPWH myPrintMileage Agent] c:\program files\hewlett-packard\hp business inkjet 1100 series\toolbox\mpm.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [ADU] "c:\program files\cisco aironet\ADU.exe" -nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe
mRun: [RoxioDragToDisc] c:\program files\lenovo\drag-to-disc\DrgToDsc.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Trusted Zone: ibm.com\icm1.teleweb.ca
Trusted Zone: lenovo.com\chat.lel
Trusted Zone: lenovo.com\expertslive
Trusted Zone: lenovo.com\rto1.lel
Trusted Zone: lenovo.com\rto2.lel
Trusted Zone: motive.com\pattta.att
Trusted Zone: motive.com\patttbc.att
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0FB028C2-2704-40F6-A983-2A2405027A19} - hxxps://epresent.sungard.com/ws/dropslot.cab
DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - hxxp://www.alternatiff.com/install/00/alttiff.cab
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/authorware/awswaxd.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxps://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-
DPF: {4BEE3896-4820-48D1-85EA-5A9A9ECD3D95} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - hxxp://www.vectorvest.com/install/vvonlineus/setup.exe
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228722756109
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1256538757904
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-3.ibm.com/pc/support/IbmEgath.cab
DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} - hxxp://starcoons.selfip.com:1024/img/LinksysViewer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://demo.xiden.com.ar/activex/AxisCamControl.cab
DPF: {96AD66E6-8375-4864-8F4D-0F15023C2AF6} - hxxp://www.wunderground.com/windowsinstall/weather.cab
DPF: {975BA4C8-C5A7-4CFD-9F42-10CF4B75F580} - hxxps://expertslive.lenovo.com/home/activex/actx.cab
DPF: {BE415DD9-C50D-46AA-9B5D-37F2EEBBBFE6} - hxxps://www-307.ibm.com/pc/support/access/aslibmain/content/AcpControl.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://utdvpn.utdallas.edu/dana-cached/setup/,DanaInfo=.auufytsF11mkwxn6OuuA,SSL+JuniperSetupSP1.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://utdvpn.utdallas.edu/dana-cached/sc/JuniperSetupClient.cab
TCP: {500DC2A3-A099-4209-88A9-5AAD03BDA209} =,
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll
Notify: ACNotify - ACNotify.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: tpfnf2 - notifyf2.dll
Notify: tphotkey - tphklock.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
LSA: Notification Packages = ACGina scecli

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jimsch~1\applic~1\mozilla\firefox\profiles\eolykcg5.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-6 64160]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2008-9-29 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2008-9-29 4224]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2003-7-8 15360]
R2 CVPNDRV;Cisco Systems IPsec Driver;c:\windows\system32\drivers\CVPNDrv.sys [2003-8-21 263751]
R3 CSCO21;Cisco Aironet 802.11a/b/g Wireless Adapter Service;c:\windows\system32\drivers\csco21.sys [2007-8-1 1320960]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2007-8-1 55840]
S3 DM_1USB;DM_1USB Device;c:\windows\system32\drivers\DM_1USB.sys [2004-3-19 27326]
S3 DSSUSB1;DSSUSB1 Device;c:\windows\system32\drivers\DSSUSB1.SYS [2004-3-19 39071]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
S3 PCX504;Cisco Systems Wireless LAN Adapter Driver;c:\windows\system32\drivers\PCX504.sys [2004-2-25 96256]
S3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [2003-8-16 27088]
S3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\pelusblf.sys [2003-8-16 8704]
S4 portD;ABS PortIO Service;c:\windows\system32\drivers\portd2k.sys [2004-4-12 7296]
S4 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]

=============== Created Last 30 ================

2009-11-08 16:47:09 0 d-----w- C:\Diskeeper
2009-11-08 16:42:27 0 d-----w- c:\program files\common files\Diskeeper Corporation
2009-11-08 16:42:27 0 d-----w- c:\docume~1\alluse~1\applic~1\Diskeeper Corporation
2009-11-08 08:09:48 262144 ----a-w- c:\windows\system32\default_user_class.dat
2009-11-08 07:56:04 0 d-----w- c:\program files\Trend Micro
2009-11-08 06:45:43 0 d-----w- c:\program files\UPHClean
2009-11-08 03:16:38 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters
2009-11-07 23:49:35 0 d-----w- c:\program files\Alex Feinman
2009-11-07 15:28:27 0 d-sh--r- C:\cmdcons
2009-11-07 15:27:15 98816 ----a-w- c:\windows\sed.exe
2009-11-07 15:27:15 77312 ----a-w- c:\windows\MBR.exe
2009-11-07 15:27:15 267264 ----a-w- c:\windows\PEV.exe
2009-11-07 15:27:15 161792 ----a-w- c:\windows\SWREG.exe
2009-10-28 18:20:01 0 d-----w- c:\program files\Lenovo Hard Drive Quick Test
2009-10-28 18:15:15 99848 ------w- c:\windows\system32\drivers\DRVMCDB.SYS
2009-10-28 18:15:15 92920 ------w- c:\windows\DLA.EXE
2009-10-28 18:15:15 56056 ------w- c:\windows\system32\DLAAPI_W.DLL
2009-10-28 18:15:15 51768 ------w- c:\windows\system32\drivers\DRVNDDM.SYS
2009-10-28 18:15:15 28120 ------w- c:\windows\system32\drivers\DLARTL_M.SYS
2009-10-28 18:15:15 12856 ------w- c:\windows\system32\drivers\DLACDBHM.SYS
2009-10-28 18:14:40 0 d-----w- C:\swtools
2009-10-28 16:23:32 1112288 ------w- c:\windows\system32\WdfCoInstaller01007.dll
2009-10-28 16:08:23 877 ------w- c:\windows\HKLM_Symantec_InstalledApps.dat
2009-10-28 16:08:23 104 ------w- c:\windows\HKLM_RNR_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_Utimaco.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_TVTCmn_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_Symantec_InstalledApps.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_RNR_Policies_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_RNR_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_Policies_TVTCmn_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_Policies_MND_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_MND_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_CSS_Policies_Lenovo.dat
2009-10-28 16:08:23 0 d-----w- c:\windows\system32\HKLM_CSS_Lenovo.dat
2009-10-28 15:53:46 0 d-----w- c:\windows\system32\CatRoot2
2009-10-28 15:53:17 0 d--h--w- c:\program files\WindowsUpdate
2009-10-28 15:47:04 18882560 ------w- c:\windows\sectest.db
2009-10-26 18:22:46 0 d-----w- c:\docume~1\alluse~1\applic~1\Bomgar-SCC-4AE5E8F6
2009-10-26 15:21:22 0 d-----w- c:\docume~1\alluse~1\applic~1\PassMark
2009-10-26 15:21:18 0 d-----w- c:\program files\KeyboardTest
2009-10-22 13:17:52 0 d-----w- c:\docume~1\jimsch~1\applic~1\EMCO
2009-10-22 13:17:10 0 d-----w- c:\program files\EMCO
2009-10-22 11:53:56 0 d-----w- c:\docume~1\jimsch~1\applic~1\Malwarebytes
2009-10-22 06:52:56 38224 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-22 06:52:55 19160 ------w- c:\windows\system32\drivers\mbam.sys
2009-10-22 06:52:55 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-22 06:52:54 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-22 05:47:49 2855 ------w- c:\windows\system32\sdra64.PIF
2009-10-17 02:08:29 6772 ------w- C:\BAIIPlus.clc
2009-10-16 17:52:50 0 d-----w- c:\program files\RespondusCampus40
2009-10-15 06:36:16 0 d-----w- c:\program files\Respondus Equation Editor

==================== Find3M ====================

2009-10-28 16:27:24 0 ---h--w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2009-10-28 16:27:17 0 ---h--w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 22:44:40 69464 ------w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 22:44:40 515416 ------w- c:\windows\system32\XAudio2_5.dll
2009-09-04 22:44:40 238936 ------w- c:\windows\system32\xactengine3_5.dll
2009-09-04 22:29:34 453456 ------w- c:\windows\system32\d3dx10_42.dll
2009-09-04 22:29:34 235344 ------w- c:\windows\system32\d3dx11_42.dll
2009-09-04 22:29:32 5501792 ------w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 22:29:32 1974616 ------w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 22:29:30 1892184 ------w- c:\windows\system32\D3DX9_42.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-08-24 18:43:54 38176 ------w- c:\windows\system32\ibmpmsvc.exe
2009-08-24 18:43:54 35104 ------w- c:\windows\system32\tpinspm.dll
2009-08-18 04:33:52 1193832 ------w- c:\windows\system32\FM20.DLL
2009-08-12 22:20:30 398632 ------w- c:\windows\system32\dsNcSmartCardProv.dll
2009-08-12 22:20:28 345384 ------w- c:\windows\system32\dsNcCredProv.dll
2009-08-12 22:18:10 221184 ------w- c:\windows\system32\dsGinaLoader.dll
2008-05-14 00:54:34 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008051320080514\index.dat

============= FINISH: 11:24:14.06 ===============

#2 etavares


Posted 15 November 2009 - 06:41 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Also, please subscribe to this topic, so you are notified when someone replies. Please continue to check manually on occasion, as every now and then the email may be caught by your spam filter.
To enable topic notifications you should do the following:
  • Click on the My Controls link at the top of the page to enter your control panel.
  • Scroll down to the Options category in the left hand side menu bar and click on the Email Settings link.
  • Put a checkmark in the checkbox labeled Enable 'Email Notification' by default?.
  • Set the If ticked, choose default type: menu option to Immediate Email Notification to have an email sent immediately when someone replied.
Information on A/V control HERE

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

#3 JimNS

Posted 15 November 2009 - 11:22 AM

Nothing has changed. I have carefully maintained everything exactly as it was when I posted the problem and logs six days ago.

IMHO, solving this may require the attention of someone with special knowledge and skills, especially with regard to keyboard make/break codes and the keyboard boot process - possibly not something that the staff at bleepingcomputer is even going to be able to help me with.

Regardless, this is a genuine headscratcher and thanks in advance to anyone with the curiousity and tenacity to dig into it a bit with me.


Posted 17 November 2009 - 12:57 PM

Hi JimNS,

Welcome to BleepingComputer HijackThis Logs and Malware Removal, :(
My name is sundavis, I will be helping you to deal with your Malware problems today.


Please download GMER Rootkit Scanner from Here or Here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish. For more info, go to Here for your reference.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" , and copy and paste the contents in your next reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Due to the warning from the developer of combofix, this tool should not run by oneself for being unsupervised. Sometimes, it will result into an unbootable machine.

If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:


Note: CombFix has recently been updated to include the option for installing the Recovery Console automatically. The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
  • Close any open browsers
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Go to Here for your reference.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text inside the code box below:
c:\windows\ServicePackFiles\i386\kbdclass.sys | c:\windows\system32\drivers\kbdclass.sys
uDefault_Search_URL = hxxp:///
mSearch Bar = hxxp:///
uInternet Connection Wizard,ShellNext = iexplore
mSearchURL = hxxp:///
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File

Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop

Posted Image

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


We need to create an OTL Report
  • Please OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the OTL icon on your desktop.
  • Click the "Scan All Users" checkbox. .
  • Push the Run Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTListIt.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

In your next reply, please post back:

1.Gmer log
2.Combofix log
3.OTListIt.txt and Extra.txt Thanks.

Posted 03 December 2009 - 11:49 AM

Due to Lack of feedback, this topic is now Closed.

Everyone else please start a new topic in the Hijackthis-Malware Removal forum.

