Here is the BitDefender report
BitDefender Online Scanner
Scan report generated at: Thu, Feb 14, 2008 - 13:47:22
Scan path: C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;
Statistics
Time
02:33:08
Files
584440
Folders
21079
Boot Sectors
5
Archives
4625
Packed Files
71216
Results
Identified Viruses
6
Infected Files
15
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
15
Engines Info
Virus Definitions
980832
Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Scan plugins
16
Archive plugins
41
Unpack plugins
7
E-mail plugins
6
System plugins
5
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Rotator.Gen
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Disinfection failed
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)
Update failed
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Fotomoto.Gen
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Disinfection failed
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)
Update failed
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Detected with: Adware.Fotomoto.Gen
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Disinfection failed
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Deleted
C:\Downloads\setup.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)
Update failed
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\fcrqhihc.dll.vir
Infected with: Trojan.Otuboh.Gen
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\fcrqhihc.dll.vir
Disinfection failed
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\fcrqhihc.dll.vir
Deleted
C:\QooBox\Quarantine\C\WINDOWS\nsjytgzc.dll.vir
Infected with: Trojan.Otuboh.Gen
C:\QooBox\Quarantine\C\WINDOWS\nsjytgzc.dll.vir
Disinfection failed
C:\QooBox\Quarantine\C\WINDOWS\nsjytgzc.dll.vir
Deleted
C:\RECYCLER\S-1-5-21-1341125938-1084467919-1090065079-1006\Dc1.exe
Infected with: Trojan.VB.NMF
C:\RECYCLER\S-1-5-21-1341125938-1084467919-1090065079-1006\Dc1.exe
Disinfection failed
C:\RECYCLER\S-1-5-21-1341125938-1084467919-1090065079-1006\Dc1.exe
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP300\A0042206.dll
Detected with: Application.Viewpoint.F
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP300\A0042206.dll
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP300\A0042206.dll
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045895.dll
Infected with: Trojan.Otuboh.Gen
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045895.dll
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045895.dll
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045896.dll
Infected with: Trojan.Otuboh.Gen
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045896.dll
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0045896.dll
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Rotator.Gen
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0004=>(NSIS o)
Update failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Fotomoto.Gen
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)
Update failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Detected with: Adware.Fotomoto.Gen
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)=>lzma_solid_nsis0005
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0046387.exe=>(NSIS o)=>lzma_nsis0005=>(NSIS o)
Update failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0049480.dll
Infected with: Backdoor.Agobot.PAI
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0049480.dll
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0050748.exe
Infected with: Trojan.VB.NMF
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0050748.exe
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0050748.exe
Deleted
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP349\A0050996.exe
Infected with: Trojan.VB.NMF
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP349\A0050996.exe
Disinfection failed
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP349\A0050996.exe
Deleted
and this is the combofix log
ComboFix 08-02.05.3 - Justin Gaines 2008-02-14 22:27:33.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.156 [GMT -5:00]
Running from: C:\Documents and Settings\Justin Gaines\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\default.htm
.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.
2008-02-14 11:10 . 2008-02-14 11:10 <DIR> d-------- C:\WINDOWS\LastGood
2008-02-14 11:10 . 2008-02-14 13:47 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-02-12 20:05 . 2008-02-12 20:05 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-02-12 19:21 . 2004-08-10 04:00 388,608 --a------ C:\kmd.exe
2008-02-12 15:51 . 2008-02-12 17:15 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware(2)
2008-02-12 15:50 . 2008-02-12 15:50 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-02-12 14:30 . 2008-02-12 14:30 <DIR> d-------- C:\Documents and Settings\Justin Gaines\Application Data\Malwarebytes
2008-02-12 14:30 . 2008-02-12 14:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-11 15:16 . 2008-02-11 15:16 <DIR> d-------- C:\Documents and Settings\Justin Gaines\Application Data\Grisoft
2008-02-10 23:29 . 2008-02-12 17:16 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-10 23:29 . 2008-02-12 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 21:40 . 2008-02-10 21:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-10 18:34 . 2008-02-10 18:34 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-09 20:18 . 2008-02-10 20:20 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-02-09 20:17 . 2008-02-14 11:05 <DIR> d-------- C:\WINDOWS\ggcpwmfh
2008-02-09 16:06 . 2008-02-09 16:06 54,764 --a------ C:\WINDOWS\system32\4fdw.dll
2008-02-09 15:17 . 2008-02-09 15:17 244 --ah----- C:\sqmnoopt06.sqm
2008-02-09 15:17 . 2008-02-09 15:17 232 --ah----- C:\sqmdata06.sqm
2008-02-09 15:16 . 2008-02-09 15:16 244 --ah----- C:\sqmnoopt05.sqm
2008-02-09 15:16 . 2008-02-09 15:16 232 --ah----- C:\sqmdata05.sqm
2008-02-09 15:09 . 2008-02-09 15:09 244 --ah----- C:\sqmnoopt04.sqm
2008-02-09 15:09 . 2008-02-09 15:09 244 --ah----- C:\sqmnoopt03.sqm
2008-02-09 15:09 . 2008-02-09 15:09 232 --ah----- C:\sqmdata04.sqm
2008-02-09 15:09 . 2008-02-09 15:09 232 --ah----- C:\sqmdata03.sqm
2008-02-09 14:27 . 2008-02-09 14:27 244 --ah----- C:\sqmnoopt02.sqm
2008-02-09 14:27 . 2008-02-09 14:27 232 --ah----- C:\sqmdata02.sqm
2008-02-09 14:06 . 2008-02-09 14:06 244 --ah----- C:\sqmnoopt01.sqm
2008-02-09 14:06 . 2008-02-09 14:06 232 --ah----- C:\sqmdata01.sqm
2008-01-18 20:43 . 2008-01-18 20:43 65,848 --a------ C:\Documents and Settings\Justin Gaines\g2ax_customer_downloadhelper_win32_x86.exe
2008-01-16 11:26 . 2008-01-16 11:26 <DIR> d-------- C:\Program Files\iPod
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 03:34 --------- d-----w C:\Documents and Settings\Justin Gaines\Application Data\Skype
2008-02-10 02:56 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-09 19:58 --------- d-----w C:\Program Files\World of Warcraft
2008-02-01 18:35 --------- d-----w C:\Program Files\DIGStream
2008-01-30 06:13 --------- d-----w C:\Program Files\DivX
2008-01-19 03:04 --------- d-----w C:\Program Files\McAfee
2008-01-19 01:43 --------- d-----w C:\Program Files\Citrix
2008-01-16 16:26 --------- d-----w C:\Program Files\iTunes
2008-01-16 16:23 --------- d-----w C:\Program Files\QuickTime
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-09 20:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2008-01-09 11:18 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-09 11:18 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-09 11:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-09 11:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-01-09 11:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-09 11:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-09 11:16 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-09 11:16 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-09 11:16 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-09 11:16 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-08 17:59 --------- d-----w C:\Program Files\Game_Maker7
2007-12-26 21:37 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-11 19:44 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-12-11 19:44 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-12-11 19:44 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-12-11 19:44 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-12-11 19:44 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-12-11 19:44 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-12-11 19:44 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-11 19:43 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-08 05:21 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 02:21 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 02:21 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-07 02:21 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-07 02:21 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-07 02:21 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 02:21 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-07 02:21 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-12-07 02:21 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-12-07 02:21 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-07 02:21 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 02:21 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-07 02:21 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-12-07 02:21 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-12-07 02:21 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 02:21 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-07 02:21 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-12-07 02:21 133,120 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 02:21 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-12-07 02:21 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-12-07 02:21 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-12-07 02:21 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
1999-07-07 00:00 6 --sh--r C:\WINDOWS\@@desktop.dat
2007-11-08 05:16 88 --sh--r C:\WINDOWS\system32\18113F8536.sys
2007-11-08 05:16 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-13 17:20 20058152]
"Aim6"="" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 01:28 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 13:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 19:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 19:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 19:50 114688]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-13 14:30 58992]
"Norton Ghost 10.0"="C:\Program Files\Norton Ghost\Agent\GhostTray.exe" [2005-12-07 15:05 1537696]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 09:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 09:44 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-09-08 23:35 169984]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" [2006-06-13 21:58 167936]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2006-06-13 04:20 127036]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 14:49 1121280]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2006-11-01 00:04 321088]
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49 86100]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 21:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 15:40 1884160]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 13:21 198184]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-09-08 23:22:56 24576]
Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 18:55:40 18432]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 21:07:32 81920]
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\CineTray.exe [2006-05-26 01:01:00 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist Express Customer]
C:\Program Files\Citrix\GoToAssist Express Customer\48\g2ax_winlogon.dll 2008-01-18 20:43 45368 C:\Program Files\Citrix\GoToAssist Express Customer\48\g2ax_winlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll 2005-01-31 15:13 49152 C:\PROGRA~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 18:55]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
S3 GoToAssist Express Customer;GoToAssist Express Customer;"C:\Program Files\Citrix\GoToAssist Express Customer\48\g2ax_service.exe" Start=service []
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 04:00]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-04 20:30:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-15 06:29:36 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-01 06:00:55 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-02-14 06:58:39 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-14 22:34:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Citrix\GoToAssist Express Customer\48\g2ax_winlogon.dll
.
Completion time: 2008-02-14 22:38:31
ComboFix-quarantined-files.txt 2008-02-15 03:38:26
ComboFix2.txt 2008-02-13 00:33:19
ComboFix3.txt 2008-02-11 19:20:11
ComboFix4.txt 2008-02-11 03:41:05
ComboFix5.txt 2008-02-11 03:16:52
.
2008-02-13 08:07:00 --- E O F ---