Here are the results from my combo fix scan.
ComboFix 07-12-20.1 - Rob 2007-12-19 19:55:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.577 [GMT -6:00]
Running from: C:\Documents and Settings\Rob\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
.
((((((((((((((((((((((((( Files Created from 2007-11-20 to 2007-12-20 )))))))))))))))))))))))))))))))
.
2007-12-19 00:57 . 2007-12-19 00:57 <DIR> d-------- C:\Program Files\PC Wizard 2008
2007-12-19 00:57 . 2007-09-15 15:11 27,136 --a------ C:\WINDOWS\system32\PCWizard.cpl
2007-12-18 05:31 . 2007-12-18 05:33 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2007-12-18 01:08 . 2007-12-18 01:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-18 01:08 . 2007-12-18 01:08 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-17 22:35 . 2007-12-17 22:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-17 22:33 . 2007-12-17 22:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-17 21:24 . 2007-09-18 00:29 138,512 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-17 21:24 . 2007-09-18 00:29 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2007-12-17 21:24 . 2007-09-18 00:29 52,368 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2007-12-17 09:04 . 2007-12-17 09:56 38,224 --a------ C:\WINDOWS\system32\drivers\neokdss.sys
2007-12-17 08:53 . 2007-12-17 08:53 <DIR> d-------- C:\WINDOWS\kdefense
2007-12-17 08:53 . 2007-12-17 08:53 849,920 --a------ C:\WINDOWS\system32\kdfinj.dll
2007-12-17 08:53 . 2007-12-17 08:53 726,568 --a------ C:\WINDOWS\system32\kdfmgr.exe
2007-12-17 08:53 . 2007-12-17 08:53 192,512 --a------ C:\WINDOWS\system32\kdfvmgr.exe
2007-12-17 08:53 . 2007-12-17 08:53 77,824 --a------ C:\WINDOWS\system32\kdfapi.dll
2007-12-17 08:53 . 2007-12-17 08:53 53,248 --a------ C:\WINDOWS\system32\Kdfhok.dll
2007-12-17 08:41 . 2007-12-17 08:41 <DIR> d-------- C:\WINDOWS\LocalSSL
2007-12-17 05:50 . 2007-12-17 05:50 <DIR> d-------- C:\Program Files\CCleaner
2007-12-17 03:34 . 2007-12-17 03:42 <DIR> d-------- C:\Documents and Settings\Rob\Application Data\eMail ID
2007-12-17 03:34 . 2007-12-17 03:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\eMail ID
2007-12-17 03:33 . 2007-12-17 03:35 <DIR> d-------- C:\Program Files\eMail ID
2007-12-17 03:33 . 2007-12-17 03:33 <DIR> d-------- C:\Program Files\Common Files\eMail ID
2007-12-17 02:26 . 2007-12-17 03:28 <DIR> d-------- C:\Documents and Settings\Rob\Application Data\HouseCall 6.6
2007-12-12 21:06 . 2007-12-17 21:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2007-12-12 21:05 . 2007-12-17 21:24 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-12 19:45 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-12 19:19 . 2007-12-12 19:19 340 --a------ C:\WINDOWS\system32\SDRemoveDB.db
2007-12-12 19:18 . 2007-12-12 19:18 63 --a------ C:\WINDOWS\system\SysSD.dll
2007-12-12 10:11 . 2007-12-12 10:11 <DIR> d-------- C:\Program Files\AskSBar
2007-12-12 10:06 . 2007-12-12 10:06 164 --a--c--- C:\install.dat
2007-12-12 08:54 . 2007-12-12 08:54 <DIR> d-------- C:\WINDOWS\system32\Dell
2007-12-12 04:33 . 2007-12-12 04:33 <DIR> d-------- C:\Documents and Settings\Rob\Application Data\eBay
2007-12-12 04:33 . 2007-12-15 02:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WholeSecurity
2007-12-12 04:33 . 2007-12-12 04:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\eBay
2007-12-12 04:31 . 2007-12-12 04:31 <DIR> d-------- C:\Program Files\eBay
2007-12-12 04:31 . 2007-12-12 04:31 <DIR> d-------- C:\Documents and Settings\Rob\Application Data\InstallShield
2007-12-12 04:06 . 2007-12-12 04:06 <DIR> d-------- C:\WINDOWS\cache
2007-12-12 04:06 . 2007-12-12 04:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-12 03:06 . 2007-10-04 18:16 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-12 03:05 . 2007-12-12 03:05 <DIR> d----c--- C:\NVIDIA
2007-12-11 13:54 . 2007-12-11 13:54 <DIR> d-------- C:\Documents and Settings\Rob\Application Data\Yahoo!
2007-12-11 13:48 . 2007-12-18 05:31 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-22 03:06 . 2007-11-22 03:07 <DIR> d-------- C:\Program Files\iTunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-12-18 15:02 --------- d-----w C:\Program Files\Program Files
2007-12-18 11:31 --------- d-----w C:\Program Files\Common Files\Scanner
2007-12-18 04:35 --------- d-----w C:\Program Files\Lavasoft
2007-12-13 02:43 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-13 02:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-12 17:13 --------- d-----w C:\Documents and Settings\Rob\Application Data\Lavasoft
2007-12-12 11:58 --------- d-----w C:\Program Files\Dell
2007-12-12 10:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-11 03:26 --------- d-----w C:\Documents and Settings\Jan\Application Data\COMCASTTOOLBAR
2007-12-07 14:32 --------- d-----w C:\Program Files\Norton SystemWorks
2007-12-05 11:02 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-05 11:02 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-05 11:02 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-05 11:02 --------- d-----w C:\Program Files\Symantec
2007-12-04 00:10 --------- d-----w C:\Documents and Settings\Rob\Application Data\U3
2007-11-22 09:18 --------- d-----w C:\Program Files\QuickTime
2007-11-15 09:51 --------- d-----w C:\Documents and Settings\Rob\Application Data\Reasonable Software House Ltd
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 08:02 --------- d-----w C:\Documents and Settings\Jan\Application Data\CyberLink
2007-11-09 22:59 --------- d-----w C:\Program Files\Real
2007-11-08 07:37 --------- d-----w C:\Program Files\Java
2007-11-07 06:23 --------- d-----w C:\Program Files\Common Files\Real
2007-11-07 00:51 --------- d-----w C:\Program Files\Google
2007-11-06 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-29 19:51 --------- d-----w C:\Program Files\Microsoft SQL Server
2007-10-28 10:19 --------- d-----w C:\Documents and Settings\Jan\Application Data\Reasonable Software House Ltd
2007-10-28 10:09 --------- d-----w C:\Program Files\Reasonable NoClone 2007 Home
2007-10-28 09:36 --------- d-----w C:\Documents and Settings\Jan\Application Data\Grisoft
2007-10-28 09:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-28 09:19 --------- d-----w C:\Program Files\Dell Support
2007-10-24 04:32 --------- d-----w C:\Documents and Settings\Rob\Application Data\Windows Desktop Search
2007-10-24 04:14 --------- d-----w C:\Documents and Settings\Jan\Application Data\Windows Desktop Search
2007-10-24 04:12 --------- d-----w C:\Program Files\Windows Desktop Search
2007-10-24 03:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-10-24 03:19 --------- d-----w C:\Documents and Settings\Rob\Application Data\MP3Rocket
2007-10-22 19:23 --------- d-----w C:\Program Files\IncrediMail
2007-10-20 16:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky lab
2007-10-20 15:49 --------- d-----w C:\Program Files\Support.com
2007-06-17 05:28 4,153,528 ----a-w C:\Program Files\ComcastToolbar.exe
2007-01-18 23:13 1 ----a-w C:\Documents and Settings\Rob\SI.bin
2007-04-19 07:07 88 --sh--r C:\WINDOWS\system32\2C3A1136B4.sys
2007-04-19 07:07 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2007-12-12 10:11 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-12-12 10:11 267592 --a------ C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}
{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}
{C4069E3A-68F1-403E-B40E-20066696354B}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
{92085AD4-F48A-450D-BD93-B28CC7DF67CE}
{E7620C98-FCCC-40E5-92EC-C7685D2E1E40}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-12-12 10:11 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 03:00 C:\WINDOWS\system32\rundll32.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 08:44]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-11-07 04:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 08:44]
"NSWosCheck"="C:\Program Files\Norton SystemWorks\osCheck.exe" [2007-12-03 01:41]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 03:00 C:\WINDOWS\system32\rundll32.exe]
"IconixOEAddOn"="C:\Program Files\eMail ID\OEAddOn\OEdmn_2.exe" [2007-12-11 05:40]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2007-09-18 00:29]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 18:29]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 14:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\Dell Support\DSAgnt.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]
2007-10-31 10:51 599280 --a------ C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-07 18:51 68856 --a------ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"Fax"=2 (0x2)
"WZCSVC"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
R3 NPDriver;Norton UnErase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2006-10-10 07:17]
S1 prcmondrv;prcmondrv;C:\WINDOWS\system32\drivers\
pr cmondrv1041.sys []
S3 cpuz128;cpuz128;C:\Program Files\PC Wizard 2008\pcwiz32.sys [2007-07-14 11:54]
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 SDdriver;SDdriver;C:\WINDOWS\system32\Drivers\sddr iver.sys [2005-11-03 20:43]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{53ef3e9b-8cc5-11dc-9314-0013722ffb51}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{6c9c113a-73dd-11dc-92fe-0013722ffb51}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-12-19 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-11 03:59:03 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
.
************************************************** ************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-19 20:18:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-12-19 20:19:32 - machine was rebooted
.
2007-12-13 05:16:21 --- E O F ---