Thank you, here's the ComboFix log:
ComboFix 08-11-26.03 - UMBuser 2008-11-26 9:29:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1382 [GMT -5:00]
Running from: c:\documents and settings\UMBuser\Desktop\Software\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\OG7Va02l.exe.a_a
.
((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.
2008-11-26 09:25 . 2008-11-26 09:25 388,608 --a------ c:\windows\system32\CF18005.exe
2008-11-23 16:35 . 2008-11-23 16:35 d-------- c:\documents and settings\UMBuser\LocalLow
2008-11-23 16:35 . 2008-11-23 16:35 d-------- c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-21 20:29 . 2008-11-25 10:10 41,474 --a------ c:\windows\system32\OG7Va02l.exe_
2008-11-21 20:29 . 2008-11-26 09:27 41,474 --a------ c:\windows\system32\OG7Va02l.exe
2008-11-15 17:10 . 2008-11-15 17:10 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-15 17:10 . 2008-11-15 17:10 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-15 16:40 . 2008-11-15 16:40 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-15 16:40 . 2008-11-15 16:40 d-------- c:\documents and settings\UMBuser\Application Data\Malwarebytes
2008-11-15 16:40 . 2008-11-15 16:40 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-15 16:40 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-15 16:40 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-14 17:27 . 2008-11-14 17:27 d-------- c:\program files\Trend Micro
2008-11-06 23:11 . 2008-11-06 23:11 d-------- c:\program files\Veoh Networks
2008-11-06 17:53 . 2008-11-06 17:53 d-------- c:\program files\Cool Rm to Mp3 Wav converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 13:42 --------- d-----w c:\program files\Plaxo
2008-11-26 13:40 --------- d-----w c:\program files\Symantec AntiVirus
2008-11-23 16:15 --------- d-----w c:\program files\Common Files\Adobe
2008-11-19 14:31 --------- d-----w c:\program files\Mozilla Thunderbird
2008-11-15 22:10 --------- d-----w c:\program files\Java
2008-11-15 20:22 --------- d-----w c:\documents and settings\UMBuser\Application Data\U3
2008-11-05 23:25 114,688 ----a-w c:\windows\system32\wmatimer.dll
2008-10-30 03:23 --------- d-----w c:\program files\dl_Cats
2008-10-26 01:55 --------- d-----w c:\program files\NCH Software
2008-10-26 01:51 --------- d-----w c:\documents and settings\UMBuser\Application Data\NCH Swift Sound
2008-10-26 01:51 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2008-10-26 01:50 --------- d-----w c:\program files\NCH Swift Sound
2008-10-25 05:49 --------- d-----w c:\program files\DivX
2008-10-23 05:21 --------- d-----w c:\program files\Mozilla Sunbird
2008-10-22 04:53 161,262 ----a-w c:\windows\Expstudio Audio Editor FREE Uninstaller.exe
2008-10-22 04:52 --------- d-----w c:\program files\Expstudio
2008-10-22 04:52 --------- d-----w c:\program files\Cool Record Edit Pro
2008-10-16 20:28 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-16 20:21 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-10-12 02:45 30,272 ----a-w c:\windows\system32\PjDck7I0.exe
2008-09-19 21:55 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-04-25 19:57 382,352 ----a-w c:\documents and settings\UMBuser\jre-6u6-windows-i586-p-iftw.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PlaxoUpdate"="c:\program files\Plaxo\3.16.0.49\PlaxoHelper_en.exe" [2008-10-04 369223]
"PlaxoSysTray"="c:\program files\Plaxo\3.14.0.44\PlaxoSysTray.exe" [2008-07-24 20480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-10-09 3502840]
"Google Update"="c:\documents and settings\UMBuser\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-17 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"LogonStudio"="c:\documents and settings\Default User\Desktop\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-23 185896]
"DLBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll" [2007-02-12 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-15 136600]
"nwiz"="nwiz.exe" [2007-04-28 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-04-28 c:\windows\system32\nvhotkey.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 c:\windows\stsystra.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 c:\windows\system32\nvmctray.dll]
c:\documents and settings\UMBuser\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Run Google Web Accelerator.lnk - c:\program files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 1134592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\WINDOWS\\system32\\dlbucoms.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Documents and Settings\\UMBuser\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\UMBuser\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-11-26 c:\windows\Tasks\At1.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-26 c:\windows\Tasks\At10.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At11.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At12.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-26 c:\windows\Tasks\At121.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At122.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At123.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At124.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At125.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At126.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-14 c:\windows\Tasks\At127.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-14 c:\windows\Tasks\At128.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-14 c:\windows\Tasks\At129.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At13.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-26 c:\windows\Tasks\At130.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At131.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At132.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At133.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At134.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At135.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-24 c:\windows\Tasks\At136.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At137.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-24 c:\windows\Tasks\At138.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-24 c:\windows\Tasks\At139.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At14.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At140.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At141.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At142.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-25 c:\windows\Tasks\At143.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-26 c:\windows\Tasks\At144.job
- c:\windows\system32\OG7Va02l.exe [2008-11-26 09:27]
2008-11-23 c:\windows\Tasks\At15.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-24 c:\windows\Tasks\At16.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At17.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-24 c:\windows\Tasks\At18.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-24 c:\windows\Tasks\At19.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At2.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At20.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At21.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At22.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\At23.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-26 c:\windows\Tasks\At24.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At3.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At4.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At5.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-23 c:\windows\Tasks\At6.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-14 c:\windows\Tasks\At7.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-14 c:\windows\Tasks\At8.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-14 c:\windows\Tasks\At9.job
- c:\windows\system32\PjDck7I0.exe [2008-10-11 21:45]
2008-11-25 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\UMBuser\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-17 23:27]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\UMBuser\Application Data\Mozilla\Firefox\Profiles\vq98f1x3.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.law.umaryland.edu/students/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-26 09:30:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-26 9:32:12
ComboFix-quarantined-files.txt 2008-11-26 14:31:33
Pre-Run: 56,936,513,536 bytes free
Post-Run: 57,059,102,720 bytes free
242 --- E O F --- 2008-04-10 16:03:57