Here are the Logs:
ComboFix 12-01-03.07 - Owner 01/03/2012 17:23:53.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.367.113 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-12-03 to 2012-01-03 )))))))))))))))))))))))))))))))
.
.
2012-01-01 18:35 . 2004-08-04 19:00 162816 -c--a-w- c:\windows\system32\dllcache\netbt.sys
2012-01-01 18:35 . 2004-08-04 19:00 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-12-11 16:09 . 2011-12-11 16:09 -------- d-----w- c:\documents and settings\All Users\Application Data\ashampoo
2011-12-11 16:09 . 2011-12-11 16:09 -------- d-----w- c:\program files\Ashampoo
2011-12-11 15:41 . 2011-12-11 15:41 -------- d-----w- c:\documents and settings\Administrator
2011-12-10 00:11 . 2011-12-10 00:11 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2011-12-09 23:42 . 2011-12-09 23:37 79872 ----a-w- c:\windows\system32\3Rb1l2O7d.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-16 14:20 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP6ddd.tmp
2011-12-16 14:17 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP001c.tmp
2011-12-16 14:13 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0099.tmp
2011-12-16 14:10 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP002c.tmp
2011-12-16 14:07 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP005d.tmp
2011-12-16 14:04 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00fa.tmp
2011-12-16 14:01 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0191.tmp
2011-12-16 13:58 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00d8.tmp
2011-12-16 13:55 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP029b.tmp
2011-12-16 13:52 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00b8.tmp
2011-12-16 13:49 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0162.tmp
2011-12-16 13:46 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP008d.tmp
2011-12-16 13:43 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0109.tmp
2011-12-16 13:39 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0098.tmp
2011-12-16 13:36 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0134.tmp
2011-12-16 13:33 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0133.tmp
2011-12-16 13:30 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP008c.tmp
2011-12-16 13:27 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00d7.tmp
2011-12-16 13:24 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0143.tmp
2011-12-16 13:21 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP05c7.tmp
2011-12-16 13:18 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP01c0.tmp
2011-12-16 13:15 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffef.tmp
2011-12-16 13:11 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP001b.tmp
2011-12-16 13:08 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00aa.tmp
2011-12-16 13:05 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPff9f.tmp
2011-12-16 13:02 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00c8.tmp
2011-12-16 12:59 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP008b.tmp
2011-12-16 12:56 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00b7.tmp
2011-12-16 12:53 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0115.tmp
2011-12-16 12:50 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPfffc.tmp
2011-12-16 12:47 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP006c.tmp
2011-12-16 12:44 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0124.tmp
2011-12-16 12:41 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00f9.tmp
2011-12-16 12:37 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00a9.tmp
2011-12-16 12:34 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00c7.tmp
2011-12-16 12:31 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0108.tmp
2011-12-16 12:28 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP005c.tmp
2011-12-16 12:25 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0154.tmp
2011-12-16 12:22 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP003b.tmp
2011-12-16 12:19 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0579.tmp
2011-12-16 12:16 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0181.tmp
2011-12-16 12:13 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP01a2.tmp
2011-12-16 12:09 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP024d.tmp
2011-12-16 12:06 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffce.tmp
2011-12-16 12:03 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0114.tmp
2011-12-16 12:00 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP003a.tmp
2011-12-16 11:57 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00f8.tmp
2011-12-16 11:54 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007f.tmp
2011-12-16 11:51 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007e.tmp
2011-12-16 11:48 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007d.tmp
2011-12-16 11:45 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffee.tmp
2011-12-16 11:42 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00e6.tmp
2011-12-16 11:39 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP008a.tmp
2011-12-16 11:36 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP000e.tmp
2011-12-16 11:32 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP006b.tmp
2011-12-16 11:29 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffcd.tmp
2011-12-16 11:26 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP005b.tmp
2011-12-16 11:23 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007c.tmp
2011-12-16 11:20 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0153.tmp
2011-12-16 11:17 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP054a.tmp
2011-12-16 11:14 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00e5.tmp
2011-12-16 11:11 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffde.tmp
2011-12-16 11:08 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0089.tmp
2011-12-16 11:04 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP000d.tmp
2011-12-16 11:01 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPff9e.tmp
2011-12-16 10:58 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007b.tmp
2011-12-16 10:55 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP004b.tmp
2011-12-16 10:52 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00f7.tmp
2011-12-16 10:49 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0107.tmp
2011-12-16 10:46 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP006a.tmp
2011-12-16 10:43 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0106.tmp
2011-12-16 10:40 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP007a.tmp
2011-12-16 10:37 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00d6.tmp
2011-12-16 10:34 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0079.tmp
2011-12-16 10:31 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00a8.tmp
2011-12-16 10:27 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0105.tmp
2011-12-16 10:24 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP01ef.tmp
2011-12-16 10:21 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0088.tmp
2011-12-16 10:18 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP021e.tmp
2011-12-16 10:15 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0598.tmp
2011-12-16 10:12 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP02ba.tmp
2011-12-16 10:09 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP005a.tmp
2011-12-16 10:06 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00c6.tmp
2011-12-16 04:58 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0059.tmp
2011-12-16 04:55 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0069.tmp
2011-12-16 04:52 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffdd.tmp
2011-12-16 04:49 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP002b.tmp
2011-12-16 04:46 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffed.tmp
2011-12-16 04:43 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPff21.tmp
2011-12-16 04:40 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPff20.tmp
2011-12-16 04:37 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPffec.tmp
2011-12-16 04:34 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0104.tmp
2011-12-16 04:30 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP000c.tmp
2011-12-16 04:27 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP004a.tmp
2011-12-16 04:24 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP00b6.tmp
2011-12-16 04:21 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP001a.tmp
2011-12-16 04:18 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0087.tmp
2011-12-16 04:15 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP000b.tmp
2011-12-16 04:12 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMPfffb.tmp
2011-12-16 04:09 . 2006-05-16 15:28 94208 ----a-w- c:\windows\DUMP0327.tmp
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-01_19.50.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-03 22:06 . 2012-01-03 22:06 16384 c:\windows\Temp\Perflib_Perfdata_790.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16120832]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"HostManager"="c:\program files\Common Files\AOL\1147794822\EE\AOLHostManager.exe" [2004-11-03 125528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-05-16 98304]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10u_ActiveX.exe" [2011-07-18 243360]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Event Minder Reminders.lnk - c:\hallmark\EMREMIND.EXE [2010-3-16 6240]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2006-5-16 2168360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1147794822\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\At1.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At10.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At11.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At12.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At13.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At14.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At15.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At16.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-10 c:\windows\Tasks\At17.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-10 c:\windows\Tasks\At18.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At19.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At2.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At20.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At21.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At22.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At23.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At24.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2012-01-01 c:\windows\Tasks\At25.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2012-01-01 c:\windows\Tasks\At26.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At27.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At28.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At29.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At3.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At30.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-15 c:\windows\Tasks\At31.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-15 c:\windows\Tasks\At32.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-15 c:\windows\Tasks\At33.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-15 c:\windows\Tasks\At34.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At35.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At36.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At37.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-10 c:\windows\Tasks\At38.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-10 c:\windows\Tasks\At39.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At4.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-10 c:\windows\Tasks\At40.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At41.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At42.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At43.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At44.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At45.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At46.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At47.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At48.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At5.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At6.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At7.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At8.job
- c:\windows\system32\3Rb1l2O7d.com_ [2011-12-09 23:37]
.
2011-12-09 c:\windows\Tasks\At9.job
- c:\windows\system32\3Rb1l2O7d.com [2011-12-09 23:37]
.
2011-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-726758628-2395302696-704199521-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-12-11 15:47]
.
2006-08-04 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 19:00]
.
2006-08-04 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 19:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://frontier.my.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-03 17:46
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1340)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-01-03 17:56:50
ComboFix-quarantined-files.txt 2012-01-03 22:56
.
Pre-Run: 143,083,200,512 bytes free
Post-Run: 143,076,794,368 bytes free
.
- - End Of File - - AE158363BC8B5CCE43A6B0AF9DB8422E
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.03.05
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: TERRY [administrator]
1/3/2012 7:08:58 PM
mbam-log-2012-01-03 (19-08-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 172837
Time elapsed: 25 minute(s), 59 second(s)
Memory Processes Detected: 1
C:\WINDOWS\system32\3Rb1l2O7d.com (Trojan.Email) -> 184 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\WINDOWS\system32\3Rb1l2O7d.com (Trojan.Email) -> Delete on reboot.
C:\WINDOWS\system32\3Rb1l2O7d.com_ (Trojan.Email) -> Quarantined and deleted successfully.
(end)