Here is combo fix log
ComboFix 13-11-23.02 - abowman 11/24/2013 9:21.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1330 [GMT -7:00]
Running from: \\server2\Users BkUp\Desktop\ABowman\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\documents and settings\ABowman\WINDOWS
d:\windows\system32\FlashPlayerApp.exe
d:\windows\system32\ijl11.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-10-24 to 2013-11-24 )))))))))))))))))))))))))))))))
.
.
2013-11-22 22:52 . 2013-11-22 22:52 -------- d-----w- D:\FRST
2013-11-22 18:35 . 2013-11-22 18:35 -------- d-----w- d:\program files\HitmanPro
2013-11-22 17:15 . 2013-11-22 17:15 -------- d-----w- d:\documents and settings\Administrator\Application Data\Malwarebytes
2013-11-22 17:15 . 2013-11-22 17:15 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2013-11-22 17:15 . 2013-11-22 17:15 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2013-11-22 17:15 . 2013-04-04 21:50 22856 ----a-w- d:\windows\system32\drivers\mbam.sys
2013-11-21 01:38 . 2013-11-22 18:33 -------- d-----w- d:\documents and settings\All Users\Application Data\HitmanPro
2013-11-21 01:01 . 2013-11-21 01:01 -------- d-sh--w- d:\documents and settings\administrator.RIOGRANDESALES\PrivacIE
2013-11-21 00:49 . 2013-11-21 00:49 -------- d-----w- d:\documents and settings\administrator.RIOGRANDESALES\Local Settings\Application Data\Temp
2013-11-21 00:49 . 2013-11-21 00:49 -------- d-----w- d:\documents and settings\administrator.RIOGRANDESALES\Local Settings\Application Data\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-15 17:19 . 2012-01-27 23:58 71048 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 07:25 . 2008-04-14 12:42 920064 ----a-w- d:\windows\system32\wininet.dll
2013-10-13 07:25 . 2008-04-14 12:41 43520 ----a-w- d:\windows\system32\licmgr10.dll
2013-10-13 07:25 . 2008-04-14 12:42 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2013-10-13 07:24 . 2008-04-14 12:41 18944 ----a-w- d:\windows\system32\corpol.dll
2013-10-13 06:57 . 2008-04-14 07:07 385024 ----a-w- d:\windows\system32\html.iec
2013-10-12 15:56 . 2008-04-14 12:42 278528 ----a-w- d:\windows\system32\oakley.dll
2013-10-09 13:12 . 2008-04-14 12:41 287744 ----a-w- d:\windows\system32\gdi32.dll
2013-10-07 10:59 . 2008-04-14 12:41 603136 ----a-w- d:\windows\system32\crypt32.dll
2013-10-05 01:14 . 2012-01-20 21:40 7168 ----a-w- d:\windows\system32\xpsp4res.dll
2013-08-29 01:31 . 2008-04-14 08:00 1878656 ----a-w- d:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Synchronization Manager"="d:\windows\system32\mobsync.exe" [2008-04-14 143360]
"CanonSolutionMenu"="d:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-12-11 115560]
"RTHDCPL"="RTHDCPL.EXE" [2012-02-01 18789920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableVirtualization"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP
xpsp2res.dll,-22009
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)
.
R2 HitmanProScheduler;HitmanPro Scheduler;d:\program files\HitmanPro\hmpsched.exe [11/22/2013 11:35 AM 106280]
R3 COH_Mon;COH_Mon;d:\windows\system32\drivers\COH_Mon.sys [12/11/2009 10:11 AM 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;d:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/21/2013 9:53 AM 108120]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [1/31/2012 5:02 PM 1691480]
S3 TRCDR;TriCoder High-Speed USB Driver;d:\windows\system32\drivers\trcdr.sys [12/20/2012 12:44 PM 32092]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - HITMANPROSCHEDULER
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-24 d:\windows\Tasks\Adobe Flash Player Updater.job
- d:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:19]
.
2013-11-24 d:\windows\Tasks\User_Feed_Synchronization-{E19F1FCB-8C97-4D2C-A1A1-951C031EDCBC}.job
- d:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{F7750B09-3B95-43F6-BC22-58ADEAF8F74D}: NameServer = 192.168.254.11,68.94.156.1
FF - ProfilePath - d:\documents and settings\ABowman\Application Data\Mozilla\Firefox\Profiles\msothoo6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - ExtSQL: 2013-10-17 18:04; {20a82645-c095-46ed-80e3-08825760534b}; d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Symantec Antvirus
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-24 09:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-11-24 09:24:56
ComboFix-quarantined-files.txt 2013-11-24 16:24
.
Pre-Run: 128,814,780,416 bytes free
Post-Run: 129,045,729,280 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(4)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(4)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2139D775ACC347914E84D88817153715
8F558EB6672622401DA993E1E865C861