Thank you for the very fast reply to my post. Here is the CombFix File Log
Thanks
Lambshots
ComboFix 09-01-10.03 - Marg Jackman 2009-01-11 11:21:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.439 [GMT -3.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus 2006 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Marg Jackman\Application Data\
020000009551c4a7515C.manifest
c:\documents and settings\Marg Jackman\Application Data\
020000009551c4a7515O.manifest
c:\documents and settings\Marg Jackman\Application Data\
020000009551c4a7515P.manifest
c:\documents and settings\Marg Jackman\Application Data\
020000009551c4a7515S.manifest
c:\windows\system32\msrdo20.dll
c:\windows\system32\rdocurs.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
.
2009-01-11 10:39 . 2009-01-11 10:39 d——– c:\program files\Trend Micro
2009-01-11 10:36 . 2009-01-11 10:36 d——– c:\program files\ERUNT
2009-01-11 10:26 . 2009-01-11 10:26 d——– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-11 10:23 . 2009-01-11 10:23 d——– c:\program files\MSXML 4.0
2009-01-10 22:44 . 2009-01-10 22:44 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-10 22:44 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-10 22:44 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-10 19:55 . 2009-01-10 20:06 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-10 19:54 . 2009-01-10 19:54 d——– c:\program files\Common Files\iS3
2009-01-10 19:54 . 2009-01-10 20:55 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-10 15:43 . 2009-01-10 16:16 169 –a—— c:\windows\wininit.ini
2009-01-10 14:35 . 2009-01-10 14:35 d——– c:\documents and settings\All Users\Application Data\Avg8
2009-01-10 14:28 . 2009-01-10 14:28 d——– c:\documents and settings\Marg Jackman\Application Data\Symantec
2009-01-10 14:22 . 2009-01-10 14:39 d——– c:\program files\Symantec
2009-01-10 14:22 . 2009-01-10 15:09 d——– c:\program files\Norton AntiVirus
2009-01-10 14:22 . 2009-01-10 14:27 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-01-10 14:22 . 2005-09-17 09:20 108,168 –a—— c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-10 14:22 . 2005-09-17 09:20 87,768 –a—— c:\windows\system32\S32EVNT1.DLL
2009-01-10 14:22 . 2009-01-10 14:22 10,344 –a—— c:\windows\system32\drivers\symlcbrd.sys
2009-01-10 14:21 . 2009-01-11 11:13 d——– c:\program files\Common Files\Symantec Shared
2009-01-10 11:08 . 2009-01-10 11:08 d——– c:\documents and settings\All Users\Application Data\CanonIJPLM
2009-01-10 11:06 . 2009-01-10 11:06 d——– c:\program files\Common Files\ScanSoft Shared
2009-01-10 11:06 . 2009-01-10 11:06 d——– c:\documents and settings\Marg Jackman\Application Data\ScanSoft
2009-01-10 11:06 . 2009-01-10 11:06 d——– c:\documents and settings\All Users\Application Data\ScanSoft
2009-01-10 11:06 . 2009-01-10 11:06 d——– c:\documents and settings\All Users\Application Data\InstallShield
2009-01-10 11:06 . 2009-01-10 11:06 412 –a—— c:\windows\MAXLINK.INI
2009-01-10 11:05 . 2009-01-10 11:05 d——– c:\program files\ScanSoft
2009-01-10 11:05 . 2009-01-10 11:06 d——– c:\program files\Common Files\InstallShield
2009-01-10 11:01 . 2009-01-10 11:01 d–h—– c:\windows\system32\CanonIJ Uninstaller Information
2009-01-10 11:01 . 2009-01-10 11:01 d–h—– c:\program files\CanonBJ
2009-01-10 11:01 . 2009-01-10 11:01 d–h—– c:\documents and settings\All Users\Application Data\CanonBJ
2009-01-10 11:01 . 2007-04-01 16:30 215,040 –a—— c:\windows\system32\CNMLM8U.DLL
2009-01-10 11:00 . 2009-01-10 11:08 d——– c:\program files\Canon
2009-01-10 10:57 . 2008-04-13 15:17 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2009-01-10 10:57 . 2008-04-13 15:17 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2009-01-10 10:57 . 2008-04-13 15:15 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2009-01-10 10:57 . 2008-04-13 15:15 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2009-01-10 10:56 . 2009-01-10 10:56 d——– c:\program files\Common Files\CANON
2009-01-10 10:56 . 2008-04-13 15:15 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2009-01-10 10:56 . 2008-04-13 15:15 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2009-01-10 10:53 . 2009-01-10 10:53 71 –a—— c:\windows\system\cmicnfg.ini
2009-01-10 01:35 . 2008-04-13 15:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-01-10 01:35 . 2008-04-13 15:49 146,048 –a–c— c:\windows\system32\dllcache\portcls.sys
2009-01-10 01:35 . 2008-04-13 20:42 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-01-10 01:35 . 2008-04-13 20:42 129,536 –a–c— c:\windows\system32\dllcache\ksproxy.ax
2009-01-10 01:35 . 2008-04-13 15:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-01-10 01:35 . 2008-04-13 15:15 60,160 –a–c— c:\windows\system32\dllcache\drmk.sys
2009-01-10 01:35 . 2008-04-13 20:41 4,096 –a—— c:\windows\system32\ksuser.dll
2009-01-10 01:35 . 2008-04-13 20:41 4,096 –a–c— c:\windows\system32\dllcache\ksuser.dll
2009-01-09 23:00 . 2009-01-09 23:00 d——– c:\program files\Panda Security
2009-01-09 23:00 . 2008-06-19 17:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys
2009-01-09 21:33 . 2009-01-09 21:33 d——– c:\documents and settings\Marg Jackman\Application Data\Malwarebytes
2009-01-09 21:33 . 2009-01-09 21:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 19:54 . 2007-04-09 13:23 28,040 –a—— c:\windows\system32\mdimon.dll
2009-01-09 19:54 . 2009-01-09 19:54 376 –a—— c:\windows\ODBC.INI
2009-01-09 19:53 . 2009-01-09 19:53 d——– c:\windows\SHELLNEW
2009-01-09 19:53 . 2009-01-09 19:53 d——– c:\program files\Microsoft ActiveSync
2009-01-09 19:50 . 2009-01-09 19:50 dr-h—– C:\MSOCache
2009-01-09 19:17 . 2009-01-09 19:17 d——– c:\documents and settings\Marg Jackman\Application Data\Acronis
2009-01-09 19:17 . 2009-01-09 19:17 d——– c:\documents and settings\All Users\Application Data\Acronis
2009-01-09 19:15 . 2009-01-09 19:15 971,552 –a—— c:\windows\system32\drivers\tdrpm174.sys
2009-01-09 19:15 . 2009-01-09 19:15 540,000 –a—— c:\windows\system32\drivers\timntr.sys
2009-01-09 19:15 . 2009-01-09 19:15 44,704 –a—— c:\windows\system32\drivers\tifsfilt.sys
2009-01-09 19:14 . 2009-01-09 21:20 d——– c:\program files\Common Files\Acronis
2009-01-09 18:24 . 2009-01-09 18:24 d——– c:\windows\Sun
2009-01-09 17:55 . 2009-01-09 17:55 d——– c:\documents and settings\Marg Jackman\Application Data\OpenOffice.org
2009-01-09 17:23 . 2009-01-09 17:23 d——– c:\windows\system32\LogFiles
2009-01-09 17:23 . 2009-01-10 21:08 d——– C:\unzipped
2009-01-09 08:56 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-09 08:56 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-08 23:35 . 2009-01-08 23:35 d——– c:\program files\Common Files\Adobe AIR
2009-01-08 23:34 . 2009-01-08 23:34 d——– c:\program files\Common Files\Adobe
2009-01-08 23:28 . 2009-01-09 07:45 d——– c:\program files\NOS
2009-01-08 23:28 . 2009-01-09 07:45 d——– c:\documents and settings\All Users\Application Data\NOS
2009-01-08 22:54 . 2008-04-13 20:42 221,184 –a—— c:\windows\system32\wmpns.dll
2009-01-08 22:19 . 2009-01-08 22:19 d——– c:\windows\system32\scripting
2009-01-08 22:19 . 2009-01-08 22:19 d——– c:\windows\system32\en
2009-01-08 22:19 . 2009-01-08 22:19 d——– c:\windows\system32\bits
2009-01-08 22:19 . 2009-01-08 22:19 d——– c:\windows\l2schemas
2009-01-08 22:15 . 2009-01-08 22:15 d——– c:\windows\ServicePackFiles
2009-01-08 21:55 . 2009-01-08 22:07 d——– c:\windows\system32\NtmsData
2009-01-08 21:32 . 2008-10-16 17:08 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2009-01-08 21:32 . 2007-04-17 06:02 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2009-01-08 21:32 . 2007-03-08 01:40 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-08 21:32 . 2008-10-16 17:08 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2009-01-08 21:32 . 2008-10-16 17:08 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2009-01-08 21:32 . 2008-10-16 17:08 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2009-01-08 21:32 . 2008-10-16 17:08 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2009-01-08 21:32 . 2008-10-16 17:08 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-08 21:32 . 2008-10-16 09:41 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2009-01-08 21:13 . 2004-03-09 00:00 1,081,616 –a—— c:\windows\system32\MSCOMCTL.OCX
2009-01-08 21:05 . 2004-08-03 22:29 327,040 ——— c:\windows\system32\drivers\ati2mtaa.sys
2009-01-08 20:42 . 2008-06-13 07:35 272,128 ——— c:\windows\system32\drivers\bthport.sys
2009-01-08 20:42 . 2008-06-13 07:35 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2009-01-08 20:42 . 2008-08-14 06:34 138,496 —–c— c:\windows\system32\dllcache\afd.sys
2009-01-08 20:41 . 2008-09-08 07:11 333,824 —–c— c:\windows\system32\dllcache\srv.sys
2009-01-08 20:39 . 2008-08-14 06:41 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2009-01-08 20:39 . 2008-08-14 06:39 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-01-08 20:39 . 2008-08-14 06:03 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-01-08 20:39 . 2008-08-14 06:03 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2009-01-08 20:39 . 2008-09-15 08:42 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2009-01-08 20:38 . 2008-04-11 15:34 691,712 —–c— c:\windows\system32\dllcache\inetcomm.dll
2009-01-08 20:38 . 2008-10-24 07:51 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2009-01-08 20:38 . 2008-05-08 10:32 203,136 —–c— c:\windows\system32\dllcache\rmcast.sys
2009-01-08 20:37 . 2008-10-15 13:04 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2009-01-08 20:36 . 2009-01-09 14:42 d–h—– c:\windows\$hf_mig$
2009-01-08 20:36 . 2007-08-10 20:46 26,488 –a—— c:\windows\system32\spupdsvc.exe
2009-01-08 20:35 . 2009-01-08 20:35 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-08 20:35 . 2009-01-08 20:35 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-08 20:17 . 2009-01-10 16:24 d——– c:\documents and settings\Marg Jackman\Shared
2009-01-08 20:16 . 2009-01-10 19:56 d——– c:\documents and settings\Marg Jackman\Incomplete
2009-01-08 20:15 . 2009-01-09 17:51 d——– c:\program files\Java
2009-01-08 20:15 . 2009-01-10 16:15 d——– c:\documents and settings\Marg Jackman\Application Data\LimeWire
2009-01-08 20:14 . 2009-01-10 16:16 d——– c:\program files\LimeWire
2009-01-08 20:14 . 2009-01-08 20:14 d——– c:\program files\Common Files\Java
2009-01-08 18:51 . 2009-01-08 22:53 d——– c:\program files\Google
2009-01-08 18:01 . 2009-01-08 18:04 d——– c:\program files\IncrediMail
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 19:18 ——— d—–w c:\program files\Microsoft
2009-01-08 19:17 ——— d—–w c:\program files\Windows Live SkyDrive
2009-01-08 19:17 ——— d—–w c:\program files\Windows Live
2009-01-08 19:13 ——— d—–w c:\program files\Common Files\Windows Live
2009-01-08 18:38 ——— d—–w c:\program files\microsoft frontpage
2008-12-03 02:07 49,480 —-a-w c:\windows\system32\sirenacm.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 17:43 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 17:43 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 17:42 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 17:42 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 17:39 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 17:39 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 17:39 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 17:38 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 17:37 208,744 —-a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0B014B81-4E12-46F9-806F-55867AF8FD3C}]
2004-08-04 08:30 309760 –a—— c:\windows\system32\winsystems.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-08 136600]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 52848]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\icfgnt532.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Marg Jackman^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Marg Jackman\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
–a—— 2007-04-03 13:20 1603152 c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
–a—— 2007-05-14 12:31 644696 c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 20:42 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
–a—— 2007-02-04 12:02 79400 c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
–a—— 2006-10-25 09:03 210472 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-01-09 28544]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-01-10 99376]
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Marg Jackman.job
- c:\progra~1\NORTON~1\Navw32.exe [2007-05-23 12:13]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-08657584685469838035001447992531 - c:\program files\Antivirus 2009\av2009.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
——- Supplementary Scan ——-
.
uStart Page = tv.yahoo.com/listings?showFavorites=true
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-11 11:23:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-11 11:24:22
ComboFix-quarantined-files.txt 2009-01-11 14:54:18
Pre-Run: 27,637,972,992 bytes free
Post-Run: 27,842,985,984 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
249 — E O F — 2009-01-11 13:59:32