here's my results.
3 Months Free NetZero.exe;C:\Documents and Settings\All Users\Desktop;Trojan.Click.1487;Deleted.;
3 Months Free NetZero.exe;C:\Documents and Settings\All Users\Start Menu;Trojan.Click.1487;Deleted.;
Install1376[1].exe;C:\Documents and Settings\Terry Ledford\Local Settings\Temporary Internet Files\Content.IE5\ALO7IXWP;Trojan.Fakealert;Delete d.;
qdiagd.ocx;C:\Program Files\DellSupport;Probably DLOADER.Trojan;Incurable.Moved.;
A0002765.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP28;Trojan.Packed.120;Deleted.;
A0006334.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP38;Trojan.Click.1487;Deleted.;
A0006335.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP38;Trojan.Click.1487;Deleted.;
gtdownde_110.ocx;C:\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Moved.;
ComboFix 07-08-09.3 - "Penny Ledford" 2007-08-12 15:46:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.443 [GMT -4:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup.\au torun.exe
C:\DOCUME~1\PENNYL~1\STARTM~1\Programs\Startup.\sy stem.exe
C:\WINDOWS\system32\printer.exe
((((((((((((((((((((((((( Files Created from 2007-07-12 to 2007-08-12 )))))))))))))))))))))))))))))))
2007-08-12 15:45 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-12 15:40 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-11 12:29 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-08-11 12:27 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-08-11 12:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-09 19:50 7,168 --a------ C:\WINDOWS\system32\DLPT64.sys
2007-08-09 19:50 5,632 --a------ C:\WINDOWS\system32\GPCIEn64.sys
2007-08-09 19:50 5,120 --a------ C:\WINDOWS\system32\GTKCMO64.sys
2007-08-09 19:50 4,608 --a------ C:\WINDOWS\system32\DDMI64.sys
2007-08-08 22:38 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-08 22:38 <DIR> d-------- C:\Program Files\Promosoft Corporation
2007-08-06 21:30 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-06 21:30 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-06 21:30 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-06 21:30 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-06 21:30 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-08-06 21:30 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-06 21:30 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-06 21:30 <DIR> d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\PC Tools
2007-07-29 19:22 <DIR> d---s---- C:\DOCUME~1\TERRYL~1\UserData
2007-07-27 22:20 <DIR> d-------- C:\DOCUME~1\EMILYL~1\APPLIC~1\AdobeUM
2007-07-22 22:30 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-08-10 21:03 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-01 13:52 664 --a------ C:\DOCUME~1\PENNYL~1\APPLIC~1\wklnhst.dat
2007-07-22 19:21 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\AdobeUM
2007-07-01 23:05 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\Template
2007-06-29 22:57 --------- d-------- C:\Program Files\MSXML 4.0
2007-06-29 07:49 --------- d-------- C:\Program Files\Google
2007-06-28 23:53 --------- d--h----- C:\DOCUME~1\PENNYL~1\APPLIC~1\Gtek
2007-06-28 23:50 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\Google
2007-06-28 23:25 --------- d-------- C:\Program Files\DellSupport
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcache\msoe.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 22:49]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 22:46]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 22:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-03-29 00:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-29 00:30]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\I SUSPM.exe" [2004-07-27 18:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-11-17 13:11]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-03-29 00:38]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-30 16:14]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-06-27 13:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-14 14:31]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-03-29 00:30:03]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-29 00:27:42]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\R oyale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale. theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\hrum135.txt C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdcoreservice"
R1 IKFileFlt;File Filter Driver;C:\WINDOWS\system32\drivers\ikfileflt.sys
R1 IKFileSec;File Security Driver;C:\WINDOWS\system32\drivers\ikfilesec.sys
R1 IkSysFlt;System Filter Driver;C:\WINDOWS\system32\drivers\iksysflt.sys
R1 IKSysSec;System Security Driver;C:\WINDOWS\system32\drivers\iksyssec.sys
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-08-11 01:03:45 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Penny Ledford.job
2007-08-12 19:49:14 C:\WINDOWS\Tasks\Symantec NetDetect.job
************************************************** ************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-12 15:48:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000004f6
scanning hidden files ...
Code:
2007-08-05 22:10 14848 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\autorun.exe.vir
2007-08-05 22:10 14848 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\PENNYL~1\STARTM~1\Programs\Startup\system.exe.vir
2007-08-05 22:10 14848 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\printer.exe.vir
Folder PATH listing
Volume serial number is DC6D-C343
C:\QOOBOX
\---Quarantine
+---C
| +---DOCUME~1
| | +---ALLUSE~1
| | | \---STARTM~1
| | | \---Programs
| | | \---Startup
| | | autorun.exe.vir
| | |
| | \---PENNYL~1
| | \---STARTM~1
| | \---Programs
| | \---Startup
| | system.exe.vir
| |
| \---WINDOWS
| \---system32
| printer.exe.vir
|
\---Registry_backups
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-08-12 15:50:07
C:\ComboFix-quarantined-files.txt ... 2007-08-12 15:50
--- E O F ---
ComboFix 07-08-09.3 - "Penny Ledford" 2007-08-12 15:46:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.443 [GMT -4:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup.\au torun.exe
C:\DOCUME~1\PENNYL~1\STARTM~1\Programs\Startup.\sy stem.exe
C:\WINDOWS\system32\printer.exe
((((((((((((((((((((((((( Files Created from 2007-07-12 to 2007-08-12 )))))))))))))))))))))))))))))))
2007-08-12 15:45 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-12 15:40 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-11 12:29 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-08-11 12:27 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-08-11 12:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-09 19:50 7,168 --a------ C:\WINDOWS\system32\DLPT64.sys
2007-08-09 19:50 5,632 --a------ C:\WINDOWS\system32\GPCIEn64.sys
2007-08-09 19:50 5,120 --a------ C:\WINDOWS\system32\GTKCMO64.sys
2007-08-09 19:50 4,608 --a------ C:\WINDOWS\system32\DDMI64.sys
2007-08-08 22:38 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-08 22:38 <DIR> d-------- C:\Program Files\Promosoft Corporation
2007-08-06 21:30 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-06 21:30 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-06 21:30 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-06 21:30 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-06 21:30 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-08-06 21:30 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-06 21:30 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-06 21:30 <DIR> d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\PC Tools
2007-07-29 19:22 <DIR> d---s---- C:\DOCUME~1\TERRYL~1\UserData
2007-07-27 22:20 <DIR> d-------- C:\DOCUME~1\EMILYL~1\APPLIC~1\AdobeUM
2007-07-22 22:30 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-08-10 21:03 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-01 13:52 664 --a------ C:\DOCUME~1\PENNYL~1\APPLIC~1\wklnhst.dat
2007-07-22 19:21 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\AdobeUM
2007-07-01 23:05 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\Template
2007-06-29 22:57 --------- d-------- C:\Program Files\MSXML 4.0
2007-06-29 07:49 --------- d-------- C:\Program Files\Google
2007-06-28 23:53 --------- d--h----- C:\DOCUME~1\PENNYL~1\APPLIC~1\Gtek
2007-06-28 23:50 --------- d-------- C:\DOCUME~1\PENNYL~1\APPLIC~1\Google
2007-06-28 23:25 --------- d-------- C:\Program Files\DellSupport
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcache\msoe.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 22:49]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 22:46]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 22:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-03-29 00:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-29 00:30]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\I SUSPM.exe" [2004-07-27 18:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-11-17 13:11]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-03-29 00:38]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-30 16:14]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-06-27 13:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-14 14:31]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-03-29 00:30:03]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-29 00:27:42]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\R oyale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale. theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\hrum135.txt C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdcoreservice"
R1 IKFileFlt;File Filter Driver;C:\WINDOWS\system32\drivers\ikfileflt.sys
R1 IKFileSec;File Security Driver;C:\WINDOWS\system32\drivers\ikfilesec.sys
R1 IkSysFlt;System Filter Driver;C:\WINDOWS\system32\drivers\iksysflt.sys
R1 IKSysSec;System Security Driver;C:\WINDOWS\system32\drivers\iksyssec.sys
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-08-11 01:03:45 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Penny Ledford.job
2007-08-12 19:49:14 C:\WINDOWS\Tasks\Symantec NetDetect.job
************************************************** ************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-12 15:48:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000004f6
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-08-12 15:50:07
C:\ComboFix-quarantined-files.txt ... 2007-08-12 15:50
--- E O F ---