1) Removed that entry as suggested. Let me know if you want to see the log.
2) Combofix log
ComboFix 12-07-21.01 - d 07/23/2012 11:26:04.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2968.1942 [GMT -4:00]
Running from: c:\documents and settings\d\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-23 04:46 . 2012-07-23 04:46 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-23 04:46 . 2012-07-23 04:46 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-23 01:33 . 2012-07-23 15:22 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-23 01:22 . 2012-07-23 01:22 -------- d-----w- c:\windows\system32\wbem\Repository
2012-07-23 00:39 . 2012-07-23 00:39 -------- d-----w- c:\program files\Common Files\Java
2012-07-23 00:38 . 2012-07-23 00:38 -------- d-----w- c:\program files\Oracle
2012-07-23 00:38 . 2012-07-23 00:37 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-07-23 00:36 . 2012-07-23 00:36 -------- d-----w- c:\program files\Java
2012-07-23 00:36 . 2012-07-23 00:36 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2012-07-22 22:12 . 2012-07-22 22:12 -------- d-----w- c:\documents and settings\d\Local Settings\Application Data\ESET
2012-07-22 20:42 . 2012-07-22 20:42 -------- d-----w- c:\program files\ESET
2012-07-22 20:42 . 2012-07-22 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2012-07-22 02:15 . 2012-07-22 02:15 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2012-07-20 23:30 . 2012-07-20 23:31 -------- d-----w- c:\documents and settings\d\Local Settings\Application Data\CutePDF Writer
2012-07-20 23:29 . 2012-07-20 23:29 -------- d-----w- c:\program files\GPLGS
2012-07-20 23:28 . 2012-03-11 18:55 88656 ----a-w- c:\windows\system32\cpwmon2k.dll
2012-07-20 23:28 . 2012-07-20 23:28 -------- d-----w- c:\program files\Acro Software
2012-07-17 22:44 . 2012-07-17 22:44 -------- d-----w- c:\program files\SystemRequirementsLab
2012-07-17 22:44 . 2012-07-17 22:44 -------- d-----w- c:\documents and settings\d\Application Data\SystemRequirementsLab
2012-07-17 22:22 . 2012-07-17 22:22 -------- d-----w- c:\program files\Lenovo USB Port Replicator
2012-07-15 08:13 . 2012-07-15 08:13 -------- d-s---w- c:\documents and settings\LocalService\UserData
2012-07-06 01:01 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-07-06 01:01 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-07-06 00:59 . 2012-06-02 19:19 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-07-05 23:29 . 2012-07-03 17:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 13:17 . 2012-07-03 13:17 770384 ----a-w- c:\program files\Mozilla Firefox\msvcr100.dll
2012-07-03 13:17 . 2012-07-03 13:17 421200 ----a-w- c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-23 00:37 . 2012-05-28 23:16 687600 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-13 13:19 . 2008-04-14 06:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-14 10:42 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 10:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 21:35 . 2010-09-20 16:02 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-04 04:32 . 2008-04-14 10:42 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 02:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2010-09-20 16:02 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2010-09-20 16:02 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 02:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2010-09-28 01:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2010-09-20 16:02 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2010-09-20 16:02 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-14 10:41 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 02:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2010-09-20 16:02 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2010-09-20 16:02 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 10:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-28 22:59 . 2012-05-28 22:59 1915071 ----a-w- C:\mini-adb_tbolt2.zip
2012-05-16 07:58 . 2008-04-14 10:42 667136 ----a-w- c:\windows\system32\wininet.dll
2012-05-04 13:16 . 2008-04-14 05:54 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2010-09-20 16:00 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-17 22:04 . 2011-12-28 06:56 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-22_20.06.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-23 07:24 . 2012-07-23 07:24 16384 c:\windows\Temp\Perflib_Perfdata_c50.dat
+ 2004-08-04 10:00 . 2012-07-23 01:10 90122 c:\windows\system32\perfc009.dat
+ 2010-02-22 20:51 . 2010-02-22 20:51 95872 c:\windows\system32\drivers\epfwtdir.sys
+ 2012-07-22 20:43 . 2012-07-22 20:43 10134 c:\windows\Installer\{87B8375F-AAC4-417D-BB00-2EE6FBF898E7}\callmsi.exe
+ 2012-07-05 16:56 . 2012-07-23 01:23 972968 c:\windows\system32\Restore\rstrlog.dat
+ 2004-08-04 10:00 . 2012-07-23 01:10 507488 c:\windows\system32\perfh009.dat
+ 2012-07-23 04:46 . 2012-07-23 04:46 686280 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_Plugin.exe
- 2012-04-10 13:41 . 2012-07-04 00:13 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-04-10 13:41 . 2012-07-23 04:46 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-07-23 00:38 . 2012-07-23 00:37 227824 c:\windows\system32\javaws.exe
+ 2012-07-23 00:38 . 2012-07-23 00:37 174064 c:\windows\system32\javaw.exe
+ 2012-07-23 00:38 . 2012-07-23 00:37 174064 c:\windows\system32\java.exe
+ 2010-09-20 08:49 . 2012-07-23 07:24 204120 c:\windows\system32\FNTCACHE.DAT
- 2010-09-20 08:49 . 2012-07-06 02:44 204120 c:\windows\system32\FNTCACHE.DAT
+ 2010-02-22 20:50 . 2010-02-22 20:50 114984 c:\windows\system32\drivers\ehdrv.sys
+ 2010-02-22 20:47 . 2010-02-22 20:47 139192 c:\windows\system32\drivers\eamon.sys
+ 2008-04-14 10:42 . 2012-06-04 04:32 152576 c:\windows\system32\dllcache\schannel.dll
+ 2010-09-20 16:01 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
- 2010-09-20 16:01 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2012-07-22 20:55 . 2012-07-22 20:55 500736 c:\windows\Installer\5aca2a.msi
+ 2012-07-22 20:43 . 2012-07-22 20:43 950272 c:\windows\Installer\5aca23.msi
+ 2012-07-23 00:38 . 2012-07-23 00:38 461312 c:\windows\Installer\503bbf.msi
+ 2012-07-23 00:36 . 2012-07-23 00:36 863744 c:\windows\Installer\503bbe.msi
+ 2012-07-22 20:43 . 2012-07-22 20:43 101480 c:\windows\Installer\{87B8375F-AAC4-417D-BB00-2EE6FBF898E7}\egui.exe
+ 2012-06-25 20:07 . 2012-06-25 20:07 1394248 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.30.2114.0_x-ww_ea694a9a\msxml4.dll
+ 2008-04-14 10:42 . 2012-06-08 14:26 8462848 c:\windows\system32\shell32.dll
+ 2012-07-23 04:46 . 2012-07-23 04:46 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll
+ 2008-04-14 06:00 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 10:42 . 2012-06-08 14:26 8462848 c:\windows\system32\dllcache\shell32.dll
- 2008-04-14 10:42 . 2009-07-31 17:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2008-04-14 10:42 . 2012-06-05 15:50 1372672 c:\windows\system32\dllcache\msxml6.dll
- 2008-04-14 10:42 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-04-14 10:42 . 2012-06-05 15:50 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2010-09-20 13:46 . 2012-07-03 07:13 57442464 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RotateImage"="c:\program files\RotateImage\RCIMGDIR.exe" [2008-10-30 31744]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-12-09 176128]
"TpShocks"="TpShocks.exe" [2009-12-11 337256]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-02-12 357400]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2010-08-25 517480]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2010-07-27 69560]
"LenovoAutoScrollUtility"="c:\program files\Lenovo\VIRTSCRL\virtscrl.exe" [2010-04-01 43960]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-17 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-17 170008]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-17 145432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2009-10-06 30264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"Lenovo dCute"="c:\program files\Lenovo\Lenovo USB Port Replicator with Digital Video\dCute.exe" [2011-05-16 676312]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-22 2140880]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2010-02-05 10:44 180224 ----a-w- c:\windows\system32\FpWinlogonNp.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2/5/2010 6:39 AM 1824064]
R2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [4/10/2011 4:06 PM 5240168]
R2 DozeSvc;Lenovo Doze Mode Service;c:\program files\ThinkPad\Utilities\DOZESVC.EXE [9/21/2010 2:22 AM 132456]
R2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2/5/2010 6:43 AM 98304]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/22/2010 4:50 PM 810120]
R2 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [2/5/2010 6:44 AM 118784]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/5/2012 7:30 PM 655944]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [3/23/2012 2:25 PM 87040]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [9/21/2010 2:22 AM 53248]
R2 ScrProj;Lenovo USB Display Screen Projector;c:\program files\Lenovo\Lenovo USB Port Replicator with Digital Video\dqscrproj.exe [5/16/2011 3:49 PM 85464]
R2 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [11/3/2010 7:19 PM 94024]
R2 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [9/27/2010 8:09 PM 63928]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [9/20/2010 2:58 PM 2058776]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [9/27/2010 8:09 PM 45496]
S3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2/5/2010 6:43 AM 106496]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/25/2012 8:13 AM 113120]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 00615313
*NewlyCreated* - 10270388
*NewlyCreated* - ASWMBR
*Deregistered* - 00615313
*Deregistered* - 10270388
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-23 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2010-09-21 05:28]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\documents and settings\d\Application Data\Mozilla\Firefox\Profiles\i2udtmcg.default\
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Wdf01000.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-07-23 11:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\04\01\1e\139\15?"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (Administrators)
"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
"LastWPAEventLogged"=hex:da,07,09,00,01,00,14,00,10,00,09,00,0b,00,5d,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\FpWinLogonNp.dll
c:\program files\Lenovo Fingerprint Software\ATCSSINT.dll
c:\program files\Lenovo Fingerprint Software\SharedResources.dll
c:\program files\Lenovo Fingerprint Software\FPResource.dll
c:\windows\system32\igfxdev.dll
.
- - - - - - - > 'explorer.exe'(492)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-07-23 11:32:06
ComboFix-quarantined-files.txt 2012-07-23 15:32
.
Pre-Run: 1,041,076,224 bytes free
Post-Run: 1,583,157,248 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - D79B831513B055057E737492EB28D003