Thanks for the suggestions.
Here is the COMBOFIX log file and then I will post the HIJACKThis logfile in a new post.
ComboFix 08-05-28.4 - Eric Harvey 2008-05-31 8:17:59.3 - NTFSx86
Running from: F:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Eric Harvey\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\Eric Harvey\ftp34.dll
C:\Documents and Settings\Eric Harvey\Local Settings\Temp\cusbohcn.sys
C:\Documents and Settings\LocalService\ftp34.dll
C:\WINDOWS\oddogy.dll
C:\WINDOWS\system32\__c00285E0.dat
C:\WINDOWS\system32\1112.dat
C:\WINDOWS\system32\ftp34.dll
C:\WINDOWS\system32\rqRIbyYO.dll
C:\WINDOWS\system32\ssqNFYPJ.dll
C:\WINDOWS\system32\tacosvue.dll
E:\LaunchU3.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Eric Harvey\ftp34.dll
C:\Documents and Settings\LocalService\ftp34.dll
C:\WINDOWS\oddogy.dll
C:\WINDOWS\system32\1112.dat
C:\WINDOWS\system32\euvsocat.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\OYybIRqr.ini
C:\WINDOWS\system32\OYybIRqr.ini2
C:\WINDOWS\system32\qplnnxnu.dll
C:\WINDOWS\system32\rqRIbyYO.dll
C:\WINDOWS\system32\tacosvue.dll
E:\LaunchU3.exe . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CUSBOHCN
-------\Service_cusbohcn
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-31 )))))))))))))))))))))))))))))))
.
2008-05-29 18:49 . 2008-05-29 19:38 <DIR> d-------- C:\Combo-Fix
2008-05-28 18:34 . 2008-05-28 18:35 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-28 18:17 . 2008-05-28 20:34 <DIR> d-------- C:\SDFix
2008-05-26 16:40 . 2008-05-27 03:26 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-26 16:40 . 2008-05-26 16:40 <DIR> d-------- C:\Documents and Settings\Eric Harvey\Application Data\SUPERAntiSpyware.com
2008-05-26 16:40 . 2008-05-26 16:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-26 16:39 . 2008-05-26 16:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 15:53 . 2008-05-26 15:53 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-25 23:12 . 2008-05-25 23:12 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-05-25 23:12 . 2008-05-25 23:12 <DIR> d-------- C:\Documents and Settings\Eric Harvey\Application Data\PC Tools
2008-05-25 23:12 . 2008-05-26 14:35 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-25 23:12 . 2007-12-06 15:51 28,568 --a------ C:\WINDOWS\system32\drivers\AVHook.sys
2008-05-25 23:12 . 2007-12-06 15:51 21,912 --a------ C:\WINDOWS\system32\drivers\AVRec.sys
2008-05-25 23:12 . 2008-02-12 10:44 21,904 --a------ C:\WINDOWS\system32\drivers\AVFilter.sys
2008-05-25 23:11 . 2008-05-26 14:00 <DIR> d-------- C:\Program Files\PC Tools AntiVirus
2008-05-25 23:11 . 2008-05-25 23:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-05-25 21:59 . 2004-08-04 05:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-05-16 18:56 . 2008-05-23 17:53 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-05-09 00:14 . 2008-05-09 10:27 <DIR> d-------- C:\Program Files\DropBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-31 15:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-31 03:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-29 01:04 --------- d-----w C:\Documents and Settings\Eric Harvey\Application Data\U3
2008-05-26 05:47 --------- d-----w C:\Program Files\MSN Messenger
2008-05-23 17:05 --------- d-----w C:\Documents and Settings\Eric Harvey\Application Data\Move Networks
2008-05-06 04:00 --------- d-----w C:\Program Files\ProfileWatcher
2008-04-09 05:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
.
((((((((((((((((((((((((((((( snapshot@2008-05-29_19.29.08.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-30 02:13:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-31 15:26:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2006-12-29 20:49 20480]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 19:58 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 00:33 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-12-29 20:49:29 450560]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\system32\LgNotify.dll 2004-01-12 06:55 110592 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-05 18:09]
R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-05 18:09]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2002-11-22 20:01]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-05-21 22:15:27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-24 03:18:17 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Eric Harvey.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-31 08:28:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\SoftwareDistribution\Download\c286b650f35378bdc0c45de56f787772\update\update.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-31 8:44:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-31 15:42:40
ComboFix2.txt 2008-05-31 02:53:54
ComboFix3.txt 2008-05-30 02:36:56
Pre-Run: 34,686,537,728 bytes free
Post-Run: 34,643,066,880 bytes free
169 --- E O F --- 2008-05-16 07:16:36