Hi , Thanks for helping me !!!!
Here is the report from ComboFix
ComboFix 08-10-08.01 - Rozi 2008-10-08 15:46:25.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1913 [GMT -4:00]
Running from: C:\Users\Rozi\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
2008-10-07 10:21 . 2008-10-07 10:21 <DIR> d-------- C:\Users\Rozi\AppData\Roaming\Malwarebytes
2008-10-07 10:21 . 2008-10-07 10:21 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-07 10:21 . 2008-10-07 10:21 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-10-07 10:21 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-07 10:21 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-07 10:20 . 2008-10-07 10:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-07 08:38 . 2008-10-07 08:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-07 07:55 . 2008-10-07 07:55 <DIR> d-------- C:\Users\Rozi\AppData\Roaming\DataSafeOnline
2008-10-07 06:57 . 2008-10-07 06:57 813 --a------ C:\Windows\wininit.ini
2008-10-07 06:30 . 2008-10-07 08:34 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-10-07 06:30 . 2008-10-07 08:34 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-10-07 06:30 . 2008-10-07 08:26 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-06 20:19 . 2008-10-07 11:26 <DIR> d-------- C:\Program Files\Applications
2008-10-02 13:50 . 2008-10-02 13:50 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-09-23 13:42 . 2008-09-23 13:42 <DIR> d-------- C:\Users\Rozi\AppData\Roaming\Move Networks
2008-09-15 15:51 . 2008-09-20 11:47 <DIR> d-------- C:\Users\Rozi\AppData\Roaming\SPORE
2008-09-15 15:51 . 2008-09-15 15:51 <DIR> dr-h----- C:\Users\Rozi\AppData\Roaming\SecuROM
2008-09-12 16:04 . 2008-09-12 16:06 <DIR> d-------- C:\Users\Jason\AppData\Roaming\SPORE
2008-09-12 16:04 . 2008-09-12 16:04 <DIR> dr-h----- C:\Users\Jason\AppData\Roaming\SecuROM
2008-09-12 16:00 . 2008-09-12 16:00 <DIR> d-------- C:\Users\All Users\Electronic Arts
2008-09-12 16:00 . 2008-09-12 16:00 <DIR> d-------- C:\ProgramData\Electronic Arts
2008-09-12 16:00 . 2008-09-12 16:00 1,216 --a------ C:\Windows\System32\ealregsnapshot1.reg
2008-09-12 15:59 . 2008-09-12 15:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-09-12 15:59 . 2008-09-12 15:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-09-12 15:59 . 2008-09-12 15:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-09-12 15:59 . 2008-09-12 15:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-09-12 15:59 . 2008-09-12 15:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-09-12 15:49 . 2008-09-12 16:00 <DIR> d-------- C:\Program Files\Electronic Arts
2008-09-12 09:51 . 2008-09-12 09:51 <DIR> d-------- C:\Users\Jason\AppData\Roaming\Metacafe
2008-09-10 13:41 . 2008-09-10 13:41 <DIR> d-------- C:\Users\All Users\Citrix
2008-09-10 13:41 . 2008-09-10 13:41 <DIR> d-------- C:\ProgramData\Citrix
2008-09-10 13:40 . 2008-09-10 13:40 61,224 --a------ C:\Users\Rozi\GoToAssistDownloadHelper.exe
2008-09-10 13:19 . 2008-10-08 15:12 13,641 --a------ C:\Windows\System32\Config.MPF
2008-09-10 13:16 . 2007-11-22 06:44 201,320 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-09-10 13:16 . 2007-07-13 06:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-09-10 13:16 . 2007-11-22 06:44 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-09-10 13:16 . 2007-12-02 12:51 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-09-10 13:16 . 2007-11-22 06:44 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-09-10 13:16 . 2007-11-22 06:44 33,832 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-09-09 23:20 . 2008-07-30 21:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-09 23:20 . 2008-06-25 23:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-09 23:20 . 2008-07-30 23:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-09 23:19 . 2008-08-01 21:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-09 23:19 . 2008-05-08 15:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-09 23:19 . 2008-05-19 22:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-09 23:19 . 2008-06-25 23:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-09 23:19 . 2008-08-01 23:26 36,864 --a------ C:\Windows\System32\cdd.dll
2008-09-09 18:54 . 2008-09-10 13:24 <DIR> d-------- C:\Users\All Users\SiteAdvisor
2008-09-09 18:54 . 2008-09-10 13:24 <DIR> d-------- C:\ProgramData\SiteAdvisor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 19:48 --------- d-----w C:\Users\Rozi\AppData\Roaming\Skype
2008-10-08 19:43 --------- d-----w C:\Users\Rozi\AppData\Roaming\OpenOffice.org2
2008-10-08 18:19 --------- d-----w C:\Users\Rozi\AppData\Roaming\skypePM
2008-10-08 09:14 --------- d-----w C:\ProgramData\Google Updater
2008-09-29 02:39 --------- d-----w C:\Program Files\McAfee
2008-09-15 13:55 632 ----a-w C:\Users\Rozi\AppData\Roaming\wklnhst.dat
2008-09-12 20:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-12 19:59 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-10 17:18 --------- d-----w C:\ProgramData\McAfee
2008-09-10 17:16 --------- d-----w C:\Program Files\Common Files\McAfee
2008-09-09 02:30 --------- d-----w C:\Program Files\Java
2008-08-28 18:49 --------- d-----w C:\Program Files\AICPASampleTest
2008-08-28 18:48 --------- d-----w C:\Users\Rozi\AppData\Roaming\AICPA
2008-08-17 22:18 --------- d-----w C:\Program Files\Coupons
2008-08-16 16:12 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-13 14:49 --------- d-----w C:\Program Files\Windows Mail
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-19 02:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-19 00:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 20:00 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-07-16 20:00 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-07-16 19:59 988,216 ----a-w C:\Windows\System32\winload.exe
2008-07-16 19:59 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-07-16 19:59 615,992 ----a-w C:\Windows\System32\ci.dll
2008-07-16 19:59 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-07-16 19:59 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-07-16 19:59 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-07-16 19:59 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-07-16 19:59 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-07-16 19:59 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-07-16 19:59 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-07-16 17:16 409,600 ----a-w C:\Windows\System32\wrap_oal.dll
2008-07-16 17:16 114,688 ----a-w C:\Windows\System32\OpenAL32.dll
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DELL Webcam Manager"="C:\Program Files\DELL\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 118784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-16 68856]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-20 125952]
"Google Update"="C:\Users\Rozi\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-06 133104]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-04-22 133656]
"VolPanel"="C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-11 90112]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-16 29744]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"OEM03Mon.exe"="C:\Windows\OEM03Mon.exe" [2007-06-18 36864]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 C:\Windows\RtHDVCpl.exe]
C:\Users\Jason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\DELL\DellDock\DellDock.exe [2008-05-13 1058088]
C:\Users\Mcx1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\DELL\DellDock\DellDock.exe [2008-05-13 1058088]
C:\Users\Rozi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\DELL\DellDock\DellDock.exe [2008-05-13 1058088]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-16 13:32 10536 C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1E59A3BB-C055-4741-91AB-79304618566C}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{2B19B535-EF1A-42A1-8783-810D5A565111}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{99CA32B3-1D33-48A2-B39E-6DEC79C5C79B}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{5B6C60EE-8A66-4D70-9D93-DD731FBC8FC2}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{367C29AC-C3C3-40FB-BF7E-F2CF784FD798}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{51D32B0C-2CFD-4870-8DB2-E8620DD4045C}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{A5070817-1FA4-4063-97EA-6A76CE44F104}"= UDP:9420:Akamai Network Manager
"{003CE23E-5D40-4021-A42E-F22A28DBDC98}"= TCP:5000:Akamai Network Manager
"{BA3D7AB3-F9D6-4735-A899-6F3C9065C1EB}"= UDP:9420:Akamai Network Manager
"{CC039DD8-9634-4315-BC8E-302E901F7F24}"= TCP:5000:Akamai Network Manager
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-04-28 161048]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R3 OEM03Afx;Provides a software interface to control audio effects of OEM003 camera.;C:\Windows\system32\Drivers\OEM03Afx.sys [2007-06-18 141376]
R3 OEM03Vfx;Creative Camera OEM003 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM03Vfx.sys [2007-06-18 7424]
R3 OEM03Vid;Creative Camera OEM003 Driver;C:\Windows\system32\DRIVERS\OEM03Vid.sys [2007-06-18 235808]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\system32\DRIVERS\livecamv.sys [2007-01-15 31616]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe Start=service [ ]
S3 UMPass;Microsoft UMPass Driver;C:\Windows\system32\DRIVERS\umpass.sys [2008-01-20 7680]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22ab1610-532f-11dd-acb9-806e6f6e6963}]
\shell\AutoRun\command - E:\autorun.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-10-08 C:\Windows\Tasks\GoogleUpdateTaskUser.job
- C:\Users\Rozi\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-06 20:37]
2008-09-15 C:\Windows\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-10-01 C:\Windows\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
BHO-{BE1A344F-9FF5-4024-949B-52205E6DB2D0} - (no file)
HKCU-Run-AdobeUpdater - C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Rozi\AppData\Roaming\Mozilla\Firefox\Profiles\gx657ahs.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.google.com
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1273.1045\npCIDetect12.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF -: plugin - C:\Users\Rozi\AppData\Local\Google\Update\1.2.131.19\npGoogleOneClick6.dll
FF -: plugin - C:\Users\Rozi\AppData\Roaming\Mozilla\Firefox\Profiles\gx657ahs.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-08 15:48:42
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2008-10-08 15:49:47
ComboFix-quarantined-files.txt 2008-10-08 19:49:44
Pre-Run: 387,661,361,152 bytes free
Post-Run: 387,689,381,888 bytes free
217 --- E O F --- 2008-09-10 07:02:23