It worked when I tried again. Here is the killboot log
Pocket Killbox version 2.0.0.648
Running on Windows 2000 as sm(Administrator)
was started @ Saturday, August 26, 2006, 12:15 PM
# 1 [Delete on Reboot]
Path = C:\WINNT\system32\kafctmrd.exe
# 2 [Delete on Reboot]
Path = C:\WINNT\system32\kafctmrd.dat
# 3 [Delete on Reboot]
Path = C:\WINNT\system32\kafctmrd_navps.dat
# 4 [Delete on Reboot]
Path = C:\WINNT\system32\kafctmrd_nav.dat
I Rebooted @ 12:19:36 PM
Pocket Killbox version 2.0.0.648
Running on Windows 2000 as sm(Administrator)
was started @ Saturday, August 26, 2006, 12:24 PM
hERE IS COMBOFIX LOG
sm - Sat 2006-08-26 12:29:51.40
ComboFix 06.08.24 - Running from: C:\Documents and Settings\sm\Desktop
((((((((((((((((((((((((((((((( Files Created from 2006-07-26 to 2006-08-26 ))))))))))))))))))))))))))))))))))
2006-08-13 16:57 1,060,864 --a------ C:\WINNT\system32\mfc71.dll
2006-08-11 18:06 82,432 --a------ C:\WINNT\system32\drmstor.dll
2006-08-11 18:06 301,712 --a------ C:\WINNT\system32\drmclien.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-20 13:10 -------- d-------- C:\Program Files\Hijackthis
2006-08-17 12:01 28672 --a------ C:\WINNT\system32\drivers\CO_Mon.sys
2006-08-14 12:27 -------- d-------- C:\Documents and Settings\sm\Application Data\SystemDoctor 2006 Free
2006-08-13 16:57 -------- d-------- C:\Program Files\SystemDoctor 2006 Free
2006-07-29 16:57 -------- d-------- C:\Program Files\Real
2006-07-29 16:56 -------- d-------- C:\Documents and Settings\sm\Application Data\Real
2006-07-25 06:08 840976 --a------ C:\WINNT\system32\mmcndmgr.dll
2006-07-21 16:08 72704 --a------ C:\WINNT\system32\hlink.dll
2006-07-06 12:45 96528 --a------ C:\WINNT\system32\dnsrslvr.dll
2006-07-06 11:52 613648 --a------ C:\WINNT\system32\mmc.exe
2006-06-16 08:05 1713536 --a------ C:\WINNT\system32\NTKRNLPA.EXE
2006-06-16 08:04 1690880 --a------ C:\WINNT\system32\NTOSKRNL.EXE
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe /logon"
"IgfxTray"="C:\\WINNT\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINNT\\system32\\hkcmd.exe"
"ccApp"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"
"ccRegVfy"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"Easy-PrintToolBox"="C:\\Program Files\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon"
"WinFaxAppPortStarter"="wfxsnt40.exe"
"Motive SmartBridge"="C:\\PROGRA~1\\BTBROA~1\\HELP\\SMARTB~1\\BTHelpNotifier.exe"
"DSLAGENTEXE"="C:\\Program Files\\BT Voyager 205 ADSL Router\\Adsl\\dslagent.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"projselector"="\"C:\\Program Files\\Common Files\\Roxio Shared\\Project Selector\\projselector.exe\" -r"
"RoxioEngineUtility"="\"C:\\Program Files\\Common Files\\Roxio Shared\\System\\EngUtil.exe\""
"RoxioDragToDisc"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\DragToDisc\\DrgToDsc.exe\""
"SNPSTD2"="C:\\WINNT\\vsnpstd2.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"kafctmrd"="c:\\winnt\\system32\\kafctmrd.exe kafctmrd"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe"
"DrvMon.exe"="C:\\WINNT\\system32\\DrvMon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
"CDRAutoRun"=dword:00000000
"NoDrives"=dword:00000000
"NoViewOnDrive"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="
http://www.google.co...ges/t3h_en.gif"
"SubscribedURL"="
http://www.google.co...ges/t3h_en.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,44,02,00,00,21,01,00,00,3c,00,00,00,0f,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,68,02,00,00,e7,00,00,00,99,02,00,00,27,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,99,00,00,00,21,01,00,00,99,02,00,00,0f,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,58,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,1f,00,00,00,80,00,00,00,76,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe"
"Symantec NetDriver Warning"="C:\\PROGRA~1\\SYMNET~1\\SNDWarn.exe"
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]
"^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"=""
Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\Norton AntiVirus - Scan my computer.job
C:\WINNT\tasks\Symantec NetDetect.job
Completion time: Sat 2006-08-26 12:31:01.51
ComboFix2.txt
ComboFix.txt
tHANKS