Hi and thanks Fenzodal
Here are the TDSSkiller and combofix logs
2005/06/01 01:27:56.0875 TDSS rootkit removing tool 2.4.14.0 Jan 18 2011 09:33:51
2005/06/01 01:27:56.0875 ================================================================================
2005/06/01 01:27:56.0875 SystemInfo:
2005/06/01 01:27:56.0875
2005/06/01 01:27:56.0875 OS Version: 5.1.2600 ServicePack: 2.0
2005/06/01 01:27:56.0875 Product type: Workstation
2005/06/01 01:27:56.0875 ComputerName: KENNYS-LAPTOP
2005/06/01 01:27:56.0875 UserName: Kenny
2005/06/01 01:27:56.0875 Windows directory: C:\WINDOWS
2005/06/01 01:27:56.0875 System windows directory: C:\WINDOWS
2005/06/01 01:27:56.0875 Processor architecture: Intel x86
2005/06/01 01:27:56.0875 Number of processors: 2
2005/06/01 01:27:56.0875 Page size: 0x1000
2005/06/01 01:27:56.0875 Boot type: Normal boot
2005/06/01 01:27:56.0875 ================================================================================
2005/06/01 01:27:57.0390 Initialize success
2005/06/01 01:28:08.0609 ================================================================================
2005/06/01 01:28:08.0609 Scan started
2005/06/01 01:28:08.0609 Mode: Manual;
2005/06/01 01:28:08.0609 ================================================================================
2005/06/01 01:28:09.0062 Aavmker4 (479c9835b91147be1a92cb76fad9c6de) C:\WINDOWS\system32\drivers\Aavmker4.sys
2005/06/01 01:28:09.0156 acfva (426b4845468b690cfeeb268488d3aa0b) C:\WINDOWS\system32\DRIVERS\ACFVA32.sys
2005/06/01 01:28:09.0203 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2005/06/01 01:28:09.0250 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2005/06/01 01:28:09.0296 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\WINDOWS\system32\drivers\adfs.sys
2005/06/01 01:28:09.0375 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2005/06/01 01:28:09.0437 AFD (6a0397376853e604de8e1e7a87fc08ac) C:\WINDOWS\System32\drivers\afd.sys
2005/06/01 01:28:09.0703 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\WINDOWS\system32\drivers\aswFsBlk.sys
2005/06/01 01:28:09.0734 aswMon2 (a1c52b822b7b8a5c2162d38f579f97b7) C:\WINDOWS\system32\drivers\aswMon2.sys
2005/06/01 01:28:09.0765 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\WINDOWS\system32\drivers\aswRdr.sys
2005/06/01 01:28:09.0843 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\WINDOWS\system32\drivers\aswSP.sys
2005/06/01 01:28:09.0921 aswTdi (1408421505257846eb336feeef33352d) C:\WINDOWS\system32\drivers\aswTdi.sys
2005/06/01 01:28:09.0953 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2005/06/01 01:28:10.0000 atapi (14810d05efbbf1e5e4af54e813c30654) C:\WINDOWS\system32\DRIVERS\atapi.sys
2005/06/01 01:28:10.0000 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\atapi.sys. Real md5: 14810d05efbbf1e5e4af54e813c30654, Fake md5: cdfe4411a69c224bd1d11b2da92dac51
2005/06/01 01:28:10.0015 atapi - detected Rootkit.Win32.TDSS.tdl3 (0)
2005/06/01 01:28:10.0062 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2005/06/01 01:28:10.0109 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2005/06/01 01:28:10.0171 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2005/06/01 01:28:10.0250 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2005/06/01 01:28:10.0296 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2005/06/01 01:28:10.0328 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2005/06/01 01:28:10.0359 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
2005/06/01 01:28:10.0421 Cdrom (7b53584d94e9d8716b2de91d5f1cb42d) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2005/06/01 01:28:10.0468 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2005/06/01 01:28:10.0500 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2005/06/01 01:28:10.0609 dgcfltr (ff2cfb06e8019e5bed0497cd629a4bd5) C:\WINDOWS\system32\DRIVERS\ACFDCP32.sys
2005/06/01 01:28:10.0640 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
2005/06/01 01:28:10.0703 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
2005/06/01 01:28:10.0765 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
2005/06/01 01:28:10.0796 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2005/06/01 01:28:10.0859 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
2005/06/01 01:28:10.0921 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
2005/06/01 01:28:10.0984 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
2005/06/01 01:28:11.0031 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
2005/06/01 01:28:11.0062 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
2005/06/01 01:28:11.0109 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
2005/06/01 01:28:11.0156 FltMgr (6cc5181f718820861eeadae38f764b75) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2005/06/01 01:28:11.0187 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2005/06/01 01:28:11.0218 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2005/06/01 01:28:11.0265 GEARAspiWDM (df6e37b27a9a1a498c6d9f29995b7a03) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2005/06/01 01:28:11.0312 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2005/06/01 01:28:11.0343 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2005/06/01 01:28:11.0421 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2005/06/01 01:28:11.0484 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2005/06/01 01:28:11.0500 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2005/06/01 01:28:11.0546 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2005/06/01 01:28:11.0593 HTTP (261bf53e1d1c21f04b4e748a6ed3d055) C:\WINDOWS\system32\Drivers\HTTP.sys
2005/06/01 01:28:11.0718 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2005/06/01 01:28:11.0765 Imapi (12c59b8929121ace2f55acc86682cf12) C:\WINDOWS\system32\DRIVERS\imapi.sys
2005/06/01 01:28:12.0015 IntcAzAudAddService (909d03b3b7fb7c830b74f74f4d0ea7ce) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2005/06/01 01:28:12.0203 intelppm (db8a1859cf9e48914dcc0a7206d87be5) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2005/06/01 01:28:12.0234 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2005/06/01 01:28:12.0281 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2005/06/01 01:28:12.0296 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2005/06/01 01:28:12.0343 IpNat (472c75f85e631f8aa87d21c9fee6238d) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2005/06/01 01:28:12.0390 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2005/06/01 01:28:12.0437 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
2005/06/01 01:28:12.0500 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2005/06/01 01:28:12.0562 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2005/06/01 01:28:12.0593 kmixer (8531438246ce9474e41ee1599904c0c7) C:\WINDOWS\system32\drivers\kmixer.sys
2005/06/01 01:28:12.0671 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys
2005/06/01 01:28:12.0781 lusbaudio (081caf42d5db1fcf8794fd77befd1b11) C:\WINDOWS\system32\drivers\OVSound2.sys
2005/06/01 01:28:12.0812 LVUSBSta (23f8ef78bb9553e465a476f3cee5ca18) C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys
2005/06/01 01:28:12.0859 mdmxsdk (1968508adb20192a03a30c25f16db506) C:\WINDOWS\system32\DRIVERS\ACFSDK32.sys
2005/06/01 01:28:12.0890 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2005/06/01 01:28:12.0937 MobileAdapter (4a77f036f7234ed24351ac486d2a29b9) C:\WINDOWS\system32\DRIVERS\hmvmdm.sys
2005/06/01 01:28:12.0984 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
2005/06/01 01:28:13.0046 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2005/06/01 01:28:13.0078 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2005/06/01 01:28:13.0140 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2005/06/01 01:28:13.0156 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
2005/06/01 01:28:13.0218 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2005/06/01 01:28:13.0281 MRxSmb (3500e756812e716351f2d341ae1d5623) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2005/06/01 01:28:13.0312 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
2005/06/01 01:28:13.0359 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2005/06/01 01:28:13.0390 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2005/06/01 01:28:13.0406 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
2005/06/01 01:28:13.0437 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2005/06/01 01:28:13.0468 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
2005/06/01 01:28:13.0515 Mup (79a9c030299e8cc04f18d0765155d902) C:\WINDOWS\system32\drivers\Mup.sys
2005/06/01 01:28:13.0546 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2005/06/01 01:28:13.0578 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
2005/06/01 01:28:13.0609 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2005/06/01 01:28:13.0656 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2005/06/01 01:28:13.0687 Ndisuio (77d9bf86b912104c229d4f0d25be3c12) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2005/06/01 01:28:13.0703 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2005/06/01 01:28:13.0734 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
2005/06/01 01:28:13.0765 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
2005/06/01 01:28:13.0812 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
2005/06/01 01:28:13.0859 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
2005/06/01 01:28:13.0906 Ntfs (7179ac3f4258aec9627590a842fda1d6) C:\WINDOWS\system32\drivers\Ntfs.sys
2005/06/01 01:28:13.0968 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2005/06/01 01:28:14.0250 nv (b5a51353d8733b2d28055286e0f57f9c) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2005/06/01 01:28:14.0546 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2005/06/01 01:28:14.0562 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2005/06/01 01:28:14.0640 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\drivers\Parport.sys
2005/06/01 01:28:14.0687 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
2005/06/01 01:28:14.0750 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2005/06/01 01:28:14.0859 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
2005/06/01 01:28:14.0906 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2005/06/01 01:28:14.0953 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2005/06/01 01:28:15.0296 PID_PEPI (4bb5ac2dd485b8eefccb977ee66a68ad) C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
2005/06/01 01:28:15.0437 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2005/06/01 01:28:15.0468 PQNTDrv (4228630829c0e521c43d882a00533374) C:\WINDOWS\system32\drivers\PQNTDrv.sys
2005/06/01 01:28:15.0500 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
2005/06/01 01:28:15.0531 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2005/06/01 01:28:15.0578 QCAbsee (7835ccedeed078a8bc48fe91961ab9a6) C:\WINDOWS\system32\DRIVERS\OVCA.sys
2005/06/01 01:28:15.0687 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2005/06/01 01:28:15.0750 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2005/06/01 01:28:15.0781 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2005/06/01 01:28:15.0812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2005/06/01 01:28:15.0843 Rdbss (b48441a6dc703ee4c36db14ee51a189c) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2005/06/01 01:28:15.0875 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2005/06/01 01:28:15.0921 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2005/06/01 01:28:15.0968 RDPWD (047bea21274c8a4a233674a76c958c2c) C:\WINDOWS\system32\drivers\RDPWD.sys
2005/06/01 01:28:16.0046 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
2005/06/01 01:28:16.0125 rspndr (0e11b35e972796042044bc27ce13b065) C:\WINDOWS\system32\DRIVERS\rspndr.sys
2005/06/01 01:28:16.0187 sdbus (45c6411c6f9f911a9f1c8561b1fa1115) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2005/06/01 01:28:16.0234 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2005/06/01 01:28:16.0281 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys
2005/06/01 01:28:16.0328 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
2005/06/01 01:28:16.0406 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2005/06/01 01:28:16.0484 splitter (9bb1dd670cb7505a90fc4e61d4aa8227) C:\WINDOWS\system32\drivers\splitter.sys
2005/06/01 01:28:16.0531 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
2005/06/01 01:28:16.0593 Srv (d4af9861c3b6a2163d26dc6b9cf05e2a) C:\WINDOWS\system32\DRIVERS\srv.sys
2005/06/01 01:28:16.0656 ssm_bus (df5c19f053eff7f8ba25d73aea899656) C:\WINDOWS\system32\DRIVERS\ssm_bus.sys
2005/06/01 01:28:16.0828 ssm_mdfl (5347169fa449eabc4d0728ae39fab926) C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys
2005/06/01 01:28:16.0890 ssm_mdm (7aae23dd105eed15c4f45fc269fa42a9) C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys
2005/06/01 01:28:16.0937 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2005/06/01 01:28:16.0968 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2005/06/01 01:28:17.0046 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
2005/06/01 01:28:17.0093 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
2005/06/01 01:28:17.0250 SynTP (66f680409fc3bddf62741e3e920a8454) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2005/06/01 01:28:17.0296 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
2005/06/01 01:28:17.0390 Tcpip (744e57c99232201ae98c49168b918f48) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2005/06/01 01:28:17.0437 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
2005/06/01 01:28:17.0468 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
2005/06/01 01:28:17.0515 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
2005/06/01 01:28:17.0625 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
2005/06/01 01:28:17.0718 Update (7b2170ee3d858ce8fbe503904cc9b663) C:\WINDOWS\system32\DRIVERS\update.sys
2005/06/01 01:28:17.0828 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
2005/06/01 01:28:17.0875 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2005/06/01 01:28:17.0906 usbehci (4a84dd272df62be5739394b3f90f8ae2) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2005/06/01 01:28:17.0953 usbhub (a874d1629762019ceaf824ad8a8c5660) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2005/06/01 01:28:17.0984 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2005/06/01 01:28:18.0062 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2005/06/01 01:28:18.0125 usbser (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\DRIVERS\usbser.sys
2005/06/01 01:28:18.0140 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2005/06/01 01:28:18.0171 usbuhci (654c19d5ca14483be3c2384cddc09468) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2005/06/01 01:28:18.0218 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
2005/06/01 01:28:18.0250 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
2005/06/01 01:28:18.0343 w39n51 (c79918a5bd269035f3a34d157401b9df) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2005/06/01 01:28:18.0421 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2005/06/01 01:28:18.0500 wdmaud (0bfa8203b8148fb4e54bc212c41ce497) C:\WINDOWS\system32\drivers\wdmaud.sys
2005/06/01 01:28:18.0578 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2005/06/01 01:28:18.0671 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2005/06/01 01:28:18.0718 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2005/06/01 01:28:18.0750 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2005/06/01 01:28:18.0843 ================================================================================
2005/06/01 01:28:18.0843 Scan finished
2005/06/01 01:28:18.0843 ================================================================================
2005/06/01 01:28:18.0859 Detected object count: 1
2005/06/01 01:28:53.0406 atapi (14810d05efbbf1e5e4af54e813c30654) C:\WINDOWS\system32\DRIVERS\atapi.sys
2005/06/01 01:28:53.0406 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\atapi.sys. Real md5: 14810d05efbbf1e5e4af54e813c30654, Fake md5: cdfe4411a69c224bd1d11b2da92dac51
2005/06/01 01:28:54.0968 Backup copy found, using it..
2005/06/01 01:28:55.0109 C:\WINDOWS\system32\DRIVERS\atapi.sys - will be cured after reboot
2005/06/01 01:28:55.0109 Rootkit.Win32.TDSS.tdl3(atapi) - User select action: Cure
2005/06/01 01:29:00.0578 Deinitialize success
===============================================================================================================
ComboFix 11-01-20.03 - Kenny 01/06/2005 2:00.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1022.683 [GMT 1:00]
Running from: c:\documents and settings\Kenny\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((( Files Created from 2005-05-01 to 2005-06-01 )))))))))))))))))))))))))))))))
.
2010-12-19 15:56 . 2011-01-11 23:47 -------- d-----w- C:\FH backup
2009-12-28 17:13 . 2009-12-28 17:13 -------- d-----r- C:\MSOCache
2009-09-16 19:44 . 2009-09-16 19:45 -------- d-----w- C:\My Computer
2009-06-15 19:48 . 2009-06-15 19:48 -------- d-----w- C:\cygwin
2009-03-03 13:13 . 2009-03-03 13:13 -------- d-----w- C:\ConvertTemp
2008-11-06 13:39 . 2008-12-28 00:20 -------- d-----w- C:\TEMP
2008-05-20 21:12 . 2008-05-20 21:12 -------- d-----w- C:\logs3
2008-04-22 19:02 . 2008-04-22 19:02 -------- d-----w- C:\WinZip
2007-12-24 16:05 . 2008-03-15 09:48 -------- d-----w- C:\CAVEDOG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-14 15:13 . 2007-09-08 16:52 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-04-20 05:51 . 2004-08-04 01:56 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-03-05 14:57 . 2004-08-04 01:56 65536 ----a-w- c:\windows\system32\asycfilt.dll
2010-01-29 14:43 . 2004-08-04 01:56 307260 ----a-w- c:\windows\system32\l3codeca.acm
2010-01-29 14:43 . 2001-08-23 14:00 143422 ----a-w- c:\windows\system32\l3codecx.ax
2010-01-13 14:10 . 2004-08-04 01:56 85504 ----a-w- c:\windows\system32\cabview.dll
2009-12-24 07:05 . 2004-08-04 01:56 177664 ----a-w- c:\windows\system32\wintrust.dll
2009-12-14 07:35 . 2004-08-04 01:56 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-11-27 17:33 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2004-08-04 01:56 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2004-08-04 01:56 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2001-08-23 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-21 16:24 . 2007-07-22 13:13 470528 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-21 05:50 . 2004-08-04 01:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:50 . 2004-08-04 01:56 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-12 13:54 . 2004-08-04 01:56 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-04 01:56 112128 ----a-w- c:\windows\system32\rastls.dll
2009-09-11 14:03 . 2004-08-04 01:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2004-08-04 01:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 14:32 . 2004-08-04 01:56 282654 ----a-w- c:\windows\system32\msaud32.acm
2009-08-25 09:47 . 2004-08-04 01:56 352256 ----a-w- c:\windows\system32\winhttp.dll
2009-08-05 09:11 . 2004-08-04 01:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2004-08-04 01:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-06-25 18:36 . 2004-08-04 01:56 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-04 01:56 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-04 01:56 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-04 01:56 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-04 01:56 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-04 01:56 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-04 01:56 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-04 01:56 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-04 01:56 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-04 01:56 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-04 01:56 138240 ----a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-04 01:56 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:17 . 2004-08-04 01:56 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-22 11:49 . 2004-08-04 01:56 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-04 01:56 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-04 01:56 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-03 23:58 91776 -c--a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 2004-08-03 23:59 92544 -c--a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-12 11:49 . 2004-08-04 01:56 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-05-07 15:44 . 2004-08-04 01:56 344064 ----a-w- c:\windows\system32\localspl.dll
2009-03-25 05:54 . 2007-07-22 13:31 39424 ----a-w- c:\windows\apppatch\acadproc.dll
2009-03-06 14:00 . 2004-08-04 01:56 284160 ----a-w- c:\windows\system32\pdh.dll
2009-02-09 10:01 . 2004-08-04 01:56 617984 ----a-w- c:\windows\system32\advapi32.dll
2009-02-09 10:01 . 2004-08-04 01:56 715264 ----a-w- c:\windows\system32\ntdll.dll
2009-02-06 18:46 . 2004-08-04 01:56 408064 ----a-w- c:\windows\system32\netlogon.dll
2009-02-06 10:22 . 2004-08-04 01:56 110592 ----a-w- c:\windows\system32\services.exe
2009-02-06 09:54 . 2001-08-23 14:00 35328 ----a-w- c:\windows\system32\sc.exe
2008-11-07 04:18 . 2004-08-04 01:56 1386496 ----a-w- c:\windows\system32\msvbvm60.dll
2008-08-14 09:48 . 2004-08-04 00:14 138368 ----a-w- c:\windows\system32\drivers\afd.sys
2008-06-20 17:36 . 2004-08-04 01:56 245248 ----a-w- c:\windows\system32\mswsock.dll
2007-12-18 09:51 . 2004-08-04 00:00 179584 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2007-12-04 18:38 . 2004-08-04 01:56 550912 ----a-w- c:\windows\system32\oleaut32.dll
2007-07-22 13:37 . 2004-08-27 23:42 35456 -c--a-w- c:\windows\system32\drivers\processr.sys
2007-07-22 13:37 . 2004-08-04 00:56 35328 ----a-w- c:\windows\system32\pid.dll
2007-07-22 13:37 . 2004-08-04 00:56 15360 ----a-w- c:\windows\system32\pjlmon.dll
2007-07-22 13:37 . 2004-08-04 00:56 52224 ----a-w- c:\windows\system32\dmutil.dll
2007-07-22 13:37 . 2004-08-04 00:56 20992 ----a-w- c:\windows\system32\hid.dll
2007-07-22 13:37 . 2004-08-04 00:56 47104 ----a-w- c:\windows\system32\cnbjmon.dll
2007-07-22 13:37 . 2004-08-03 23:09 25472 -c--a-w- c:\windows\system32\drivers\sonydcam.sys
2007-07-22 13:37 . 2004-08-03 23:08 16000 -c--a-w- c:\windows\system32\drivers\usbintel.sys
2007-07-22 13:37 . 2004-08-03 23:08 30080 -c--a-w- c:\windows\system32\drivers\modem.sys
2007-07-22 13:37 . 2004-08-03 23:07 15488 ----a-w- c:\windows\system32\drivers\mssmbios.sys
2007-07-22 13:37 . 2004-08-03 23:07 63744 -c--a-w- c:\windows\system32\drivers\mf.sys
2007-07-22 13:37 . 2004-08-03 23:03 12416 -c--a-w- c:\windows\system32\drivers\tunmp.sys
2007-07-22 13:37 . 2004-08-03 22:59 37376 -c--a-w- c:\windows\system32\drivers\amdk7.sys
2007-07-22 13:37 . 2004-08-03 22:59 36480 -c--a-w- c:\windows\system32\drivers\crusoe.sys
2007-07-22 13:37 . 2004-08-03 22:59 42496 -c--a-w- c:\windows\system32\drivers\p3.sys
2007-07-22 13:37 . 2004-08-03 22:59 36992 -c--a-w- c:\windows\system32\drivers\amdk6.sys
2007-07-22 13:37 . 2004-08-03 22:59 80128 ----a-w- c:\windows\system32\drivers\parport.sys
2007-07-22 13:37 . 2004-08-03 22:58 4352 ----a-w- c:\windows\system32\drivers\swenum.sys
2007-07-22 13:37 . 2004-08-03 22:58 23040 ----a-w- c:\windows\system32\drivers\mouclass.sys
2007-07-22 13:37 . 2004-08-03 22:58 61824 -c--a-w- c:\windows\system32\drivers\nic1394.sys
2007-07-22 13:37 . 2004-08-03 22:58 60800 -c--a-w- c:\windows\system32\drivers\arp1394.sys
2007-07-22 13:37 . 2001-08-17 22:37 77891 ----a-w- c:\windows\system32\usrmlnka.exe
2007-07-22 13:37 . 2001-08-17 22:37 69700 ----a-w- c:\windows\system32\usrshuta.exe
2007-07-22 13:37 . 2001-08-17 22:37 61508 ----a-w- c:\windows\system32\usrprbda.exe
2007-07-22 13:37 . 2001-08-17 22:36 55296 ----a-w- c:\windows\system32\dvdplay.exe
2007-07-22 13:37 . 2001-08-17 22:36 3200 ----a-w- c:\windows\system32\wowfax.dll
2007-07-22 13:37 . 2001-08-17 22:36 13824 ----a-w- c:\windows\system32\wowfaxui.dll
2007-07-22 13:37 . 2001-08-17 22:36 86073 ----a-w- c:\windows\system32\usrfaxa.dll
2007-07-22 13:37 . 2001-08-17 22:36 77890 ----a-w- c:\windows\system32\usrdpa.dll
2007-07-22 13:37 . 2001-08-17 22:36 77883 ----a-w- c:\windows\system32\usrrtosa.dll
2007-07-22 13:37 . 2001-08-17 22:36 69699 ----a-w- c:\windows\system32\usrcoina.dll
2007-07-22 13:37 . 2001-08-17 22:36 61500 ----a-w- c:\windows\system32\usrcntra.dll
2007-07-22 13:37 . 2001-08-17 22:36 53305 ----a-w- c:\windows\system32\usrlbva.dll
2007-07-22 13:37 . 2001-08-17 22:36 49211 ----a-w- c:\windows\system32\usrvpa.dll
2007-07-22 13:37 . 2001-08-17 22:36 49211 ----a-w- c:\windows\system32\usrsdpia.dll
2007-07-22 13:37 . 2001-08-17 22:36 49209 ----a-w- c:\windows\system32\usrv80a.dll
2007-07-22 13:37 . 2001-08-17 22:36 45116 ----a-w- c:\windows\system32\usrvoica.dll
2007-07-22 13:37 . 2001-08-17 22:36 41019 ----a-w- c:\windows\system32\usrsvpia.dll
2007-07-22 13:37 . 2001-08-17 22:36 323641 ----a-w- c:\windows\system32\usrdtea.dll
2007-07-22 13:37 . 2001-08-17 22:36 102457 ----a-w- c:\windows\system32\usrv42a.dll
2007-07-22 13:37 . 2001-08-17 22:36 8192 ----a-w- c:\windows\system32\streamci.dll
2007-07-22 13:37 . 2001-08-17 22:36 72192 ----a-w- c:\windows\system32\sprio800.dll
2007-07-22 13:37 . 2001-08-17 22:36 70656 ----a-w- c:\windows\system32\sprio600.dll
2008-07-21 16:49 . 2008-07-21 16:49 44360 -c--a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-07-21 16:49 . 2008-07-21 16:49 107928 -c--a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((( SnapShot_2011-01-18_21.14.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-06-01 00:58 . 2005-06-01 00:58 16384 c:\windows\Temp\Perflib_Perfdata_7a0.dat
- 2001-08-23 14:00 . 2011-01-18 19:15 69008 c:\windows\system32\perfc009.dat
+ 2001-08-23 14:00 . 2005-06-01 01:03 69008 c:\windows\system32\perfc009.dat
+ 2011-01-18 23:08 . 2010-12-20 18:09 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2011-01-18 23:08 . 2010-12-20 18:08 20952 c:\windows\system32\drivers\mbam.sys
+ 2004-08-03 23:59 . 2005-06-01 00:30 95360 c:\windows\system32\drivers\atapi.sys
- 2004-08-03 23:59 . 2004-08-03 21:59 95360 c:\windows\system32\drivers\atapi.sys
- 2001-08-23 14:00 . 2011-01-18 19:15 436470 c:\windows\system32\perfh009.dat
+ 2001-08-23 14:00 . 2005-06-01 01:03 436470 c:\windows\system32\perfh009.dat
+ 2011-01-18 21:58 . 2011-01-18 21:58 2283008 c:\windows\Installer\9a4d7e.msi
+ 2011-01-18 22:24 . 2011-01-18 22:24 1094656 c:\windows\Installer\3a83a.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-14 8429568]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-16 16248320]
"SkyTel"="SkyTel.EXE" [2006-08-16 2879488]
"EPSON Stylus Photo RX420 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE" [2004-04-09 98304]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-08 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
c:\documents and settings\Kenny\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2009-8-27 95232]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
backup=c:\windows\pss\BBC iPlayer Desktop.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 12:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2006-08-16 10:20 53248 ----a-w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-07 18:52 323392 ----a-w- c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2007-08-24 07:00 33648 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-11 23:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-03-12 20:56 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-05-14 15:38 1626112 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 16:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-11-18 16:31 21633320 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-03-08 01:25 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\WinSCP\\WinSCP.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17/09/2005 21:21 294608]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [04/08/2004 02:56 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17/09/2005 21:21 17744]
S2 aregse;Server Time;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 dolhnzdo;Security Time;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 gikvuyq;Windows Task;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 gupdate1ca4904a224d4a0;Google Update Service (gupdate1ca4904a224d4a0);c:\program files\Google\Update\GoogleUpdate.exe [09/10/2009 18:19 133104]
S2 jwnio;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 pmwnob;Network Config;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 pwvzvpvg;Boot Windows;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 qimskjxc;Manager Update;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 vylsgys;Manager Monitor;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 wskkii;Manager Windows;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 wsrer;Task Boot;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S2 yweabxh;Driver Center;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 02:56 14336]
S3 acfva;acfva;c:\windows\system32\drivers\ACFVA32.sys [28/02/2008 10:55 86656]
S3 dgcfltr;DGC Filter Driver;c:\windows\system32\drivers\ACFDCP32.sys [28/02/2008 10:55 28928]
S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\hmvmdm.sys [20/05/2009 18:24 101120]
S3 QCAbsee;Logitech QuickCam Web (0801);c:\windows\system32\drivers\OVCA.sys [27/10/2008 21:26 25088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vylsgys
pwvzvpvg
dolhnzdo
gikvuyq
wsrer
pmwnob
wskkii
yweabxh
qimskjxc
aregse
jwnio
.
Contents of the 'Scheduled Tasks' folder
2005-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 17:19]
2011-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 17:19]
2005-06-01 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-01-07 22:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.orange.co.uk/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - f:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Kenny\Application Data\Mozilla\Firefox\Profiles\bn9yh03m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: DOM Inspector: inspector@mozilla.org - %profile%\extensions\inspector@mozilla.org
FF - Ext: Zotero: zotero@chnm.gmu.edu - %profile%\extensions\zotero@chnm.gmu.edu
.
.
------- File Associations -------
.
.reg=Regedit.Document
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
SafeBoot-klmdb.sys
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2005-06-01 02:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2005-06-01 02:13:08
ComboFix-quarantined-files.txt 2005-06-01 01:13
ComboFix2.txt 2011-01-18 21:17
ComboFix3.txt 2011-01-05 23:06
ComboFix4.txt 2011-01-05 22:20
Pre-Run: 596,594,688 bytes free
Post-Run: 599,101,440 bytes free
- - End Of File - - 4580F50C818B07B006D3BCF4EE77B764