Here is the log file from the ComboFix process."Eric King" - 2007-05-10 20:14:23 Service Pack 2
ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\Eric King\Desktop\"
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-10 ))))))))))))))))))))))))))))))))))
2007-05-10 19:34 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-05-10 19:34 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-05-10 19:34 3,572 --a------ C:\WINDOWS\system32\tmp.reg
2007-05-10 19:34 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-05-10 00:43 1,308,216 --a------ C:\Program Files\HiJackThis_v2.exe
2007-05-09 17:04 <DIR> d-------- C:\WINDOWS\Prefetch
2007-05-09 16:36 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-09 16:36 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-09 15:40 <DIR> d-------- C:\WINDOWS\setup.pss
2007-05-09 14:48 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-05-09 12:45 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-05-09 12:23 <DIR> d-------- C:\WINDOWS\dell
2007-05-09 10:41 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-05-09 10:40 <DIR> d-------- C:\Program Files\SpyNoMore
2007-05-09 04:26 <DIR> d-------- C:\Program Files\MalwareBot
2007-05-09 03:48 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-05-09 03:14 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-08 21:51 <DIR> d-------- C:\Program Files\XoftSpySE
2007-05-08 18:17 <DIR> d-------- C:\WINDOWS\pss
2007-05-08 17:57 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-05-08 16:25 <DIR> d-------- C:\Program Files\CheckIt
2007-05-08 16:12 <DIR> d-------- C:\Program Files\Norton SystemWorks
2007-05-08 03:53 <DIR> d-------- C:\DOCUME~1\ERICKI~1\NSW2006
2007-05-07 15:45 <DIR> d-------- C:\Program Files\NoAdware5.0
2007-05-07 01:58 81,924 --a------ C:\WINDOWS\system32\msorcl32.exe
2007-04-21 15:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-04-18 10:37 <DIR> d-------- C:\Downloads
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-10 23:54:42 -------- d-----w C:\Program Files\Norton Internet Security
2007-05-10 05:03:26 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-05-09 20:49:20 34,380 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-05-09 18:49:05 -------- d-----w C:\Program Files\Mozilla Thunderbird
2007-05-09 14:28:46 -------- d-----w C:\Program Files\Yahoo!
2007-05-09 14:26:44 -------- d-----w C:\Program Files\MySpace
2007-05-09 06:27:22 -------- d-----w C:\Program Files\EarthLink Setup
2007-05-08 21:55:00 -------- d-----w C:\Program Files\Common Files\AOL
2007-05-08 21:54:44 -------- d-----w C:\DOCUME~1\ERICKI~1\APPLIC~1\AOL
2007-05-08 20:40:16 -------- d-----w C:\DOCUME~1\ERICKI~1\APPLIC~1\Symantec
2007-05-08 20:24:01 -------- d-----w C:\Program Files\Symantec
2007-05-08 20:23:59 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-08 20:23:59 115,000 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-03-28 22:51:54 538,256 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-03-28 22:51:52 161,424 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-03-28 22:51:48 189,584 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-03-28 22:51:42 24,208 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-03-28 22:51:36 31,888 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-03-28 22:51:32 28,304 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-03-28 22:51:26 97,936 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-03-28 22:51:20 12,944 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-03-28 07:31:41 -------- d-----w C:\DOCUME~1\ERICKI~1\APPLIC~1\MySpace
2007-03-22 05:24:15 -------- d-----w C:\Program Files\RegistryFix
2007-03-20 16:12:33 -------- d-----w C:\Program Files\Google
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-08 17:54:45 4,895 ----a-w C:\WINDOWS\mozver.dat
2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll"
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll"
"{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"="C:\Program Files\Yahoo!\Common\yiesrvc.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll"
"{9ECB9560-04F9-4bbc-943D-298DDF1699E1}"="C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll"
"{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}"="C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll"
"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\program files\google\googletoolbar2.dll"
"{CA6319C0-31B7-401E-A518-A07C3DB8F777}"="C:\Program Files\BAE\BAE.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"MalwareBot"="C:\\Program Files\\MalwareBot\\MalwareBot.exe -boot"
"SNM"="C:\\Program Files\\SpyNoMore\\SNM.exe /startup"
"SigmatelSysTrayApp"="stsystra.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ModemOnHold"="C:\\Program Files\\NetWaiting\\netWaiting.exe"
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\0\0
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
DcomLaunch DcomLaunch\0TermService\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
WudfServiceGroup WUDFSvc\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Shell\AutoRun\command E:\setup.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Eric King.job
C:\WINDOWS\tasks\norton system scan.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec Drmc.job
C:\WINDOWS\tasks\XoftSpySE 2.job
C:\WINDOWS\tasks\XoftSpySE.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-10 20:16:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-10 20:16:48
C:\ComboFix-quarantined-files.txt ... 2007-05-10 20:16