Here you go. Need anything else let me know.
------------------------------------------------------------------
ComboFix 09-10-30.01 - Owner 11/01/2009 22:13.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.399 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Owner\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Owner\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\recycler\S-1-5-21-2846970920-2938027396-4193320068-1003
c:\recycler\S-1-5-21-4254032958-3633240100-2296491676-1003
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\jestertb.dll
c:\windows\system32\bahaboho.dll
c:\windows\system32\bolapuno.dll
c:\windows\system32\bsfusxsd.ini
c:\windows\system32\camhkfty.ini
c:\windows\system32\cyawxtjg.ini
c:\windows\system32\eKRXyccf.ini2
c:\windows\system32\fnvytlep.ini
c:\windows\system32\fozojati.dll
c:\windows\system32\fqtdhtrl.ini
c:\windows\system32\gejapifo.dll
c:\windows\system32\gmoersnh.ini
c:\windows\system32\gmseivjm.ini
c:\windows\system32\gujavujo.dll.tmp
c:\windows\system32\guyohimu.dll
c:\windows\system32\haporapu.dll
c:\windows\system32\hekomuno.dll
c:\windows\system32\heoltnjq.ini
c:\windows\system32\hiyuvubo.dll
c:\windows\system32\iumpygka.ini
c:\windows\system32\jadegada.dll
c:\windows\system32\jaxtaiys.ini
c:\windows\system32\jevaziji.dll
c:\windows\system32\jewipaje.dll
c:\windows\system32\jibepobo.dll
c:\windows\system32\jijuwajo.dll
c:\windows\system32\kveneorp.ini
c:\windows\system32\libopeke.dll
c:\windows\system32\lijujuto.dll
c:\windows\system32\lymgygng.ini
c:\windows\system32\mivusufu.dll
c:\windows\system32\muyonuvu.dll.tmp
c:\windows\system32\nnbsxtnj.ini
c:\windows\system32\nunuluna.dll.tmp
c:\windows\system32\pinigalo.dll
c:\windows\system32\puleluro.dll.tmp
c:\windows\system32\qkwtpqpw.ini
c:\windows\system32\qqicpqkd.ini
c:\windows\system32\rizilipi.dll
c:\windows\system32\rujisovo.dll
c:\windows\system32\sabadobe.dll
c:\windows\system32\sorofita.dll
c:\windows\system32\soyifafi.dll.tmp
c:\windows\system32\suroteto.dll
c:\windows\system32\tatetimo.dll
c:\windows\system32\tehenupo.dll
c:\windows\system32\tupkcrug.ini
c:\windows\system32\vemewofo.dll
c:\windows\system32\vlduhhqg.ini
c:\windows\system32\vnojeopw.ini
c:\windows\system32\voriduzi.dll
c:\windows\system32\vovamoba.dll.tmp
c:\windows\system32\wxIRtDMp.ini2
c:\windows\system32\xkqrkbof.ini
c:\windows\system32\yilinetu.dll
c:\windows\system32\yjpjajlv.ini
c:\windows\system32\yoyiriku.dll
c:\windows\system32\zabanalu.dll
c:\windows\system32\zofisuvu.dll
c:\windows\Tasks\omjyxrsp.job
c:\windows\Tasks\zzqppvco.job
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2009-10-02 to 2009-11-02 )))))))))))))))))))))))))))))))
.
2009-11-02 04:10 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-02 04:10 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-02 00:16 . 2009-11-02 00:17 -------- d-----w- c:\program files\iTunes
2009-11-02 00:16 . 2009-11-02 00:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-02 00:13 . 2009-11-02 00:13 -------- d-----w- c:\program files\QuickTime
2009-11-02 00:11 . 2009-11-02 00:17 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-02 04:10 . 2009-02-26 16:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-02 00:21 . 2006-12-25 14:52 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-11-02 00:16 . 2006-12-25 14:48 -------- d-----w- c:\program files\iPod
2009-11-02 00:16 . 2007-12-25 14:12 -------- d-----w- c:\program files\Common Files\Apple
2009-11-02 00:11 . 2007-12-25 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-27 22:17 . 2009-06-24 19:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Cabos
2009-10-27 20:48 . 2009-10-27 20:48 73728 ---ha-w- c:\documents and settings\Owner\Application Data\RBRegEx550.dll
2009-10-27 20:48 . 2009-10-27 20:48 39936 ---ha-w- c:\documents and settings\Owner\Application Data\RBShell555.dll
2009-10-27 20:47 . 2006-09-13 23:08 93008 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-06 16:38 . 2006-09-13 23:08 13402 ----a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-09-05 01:44 . 2009-09-05 01:44 -------- d-----w- c:\program files\Audacity
2009-08-29 01:42 . 2009-04-04 00:35 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-29 01:42 . 2007-12-25 14:13 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-30 20:45 . 2009-07-30 20:45 60928 --sha-w- c:\windows\system32\bikehizi.dll
2009-07-31 16:34 . 2009-07-31 16:34 89088 --sha-w- c:\windows\system32\fazotene.dll
2009-08-01 04:35 . 2009-08-01 04:35 89600 --sha-w- c:\windows\system32\hisakite.dll
2009-07-30 20:45 . 2009-07-30 20:45 89088 --sha-w- c:\windows\system32\tijayefe.dll
2009-08-01 16:35 . 2009-08-01 16:35 89088 --sha-w- c:\windows\system32\viwadefo.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\documents and settings\Owner\My Documents\My Pictures\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"gagehokah"="c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-6-11 245760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{e5dd95c5-ddb5-4bfb-af7c-62fced274337}"= "c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"{87b59fa5-8a82-4609-8042-56fd0fc50762}"= "c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"{413f0a90-469a-44e0-ac55-2534858a2282}"= "c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"{14fe8fbb-7a06-4215-8e00-9d7b38662bdc}"= "c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"{61238692-df6d-4d78-a15f-cd48f9991f60}"= "c:\windows\system32\tijayefe.dll" [2009-07-30 89088]
"{0c35cdec-f50f-4c9e-93a4-0ef26441ed77}"= "c:\windows\system32\viwadefo.dll" [2009-08-01 89088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"nonomohev"= {e5dd95c5-ddb5-4bfb-af7c-62fced274337} - c:\windows\system32\tijayefe.dll [2009-07-30 89088]
"tavanasag"= {87b59fa5-8a82-4609-8042-56fd0fc50762} - c:\windows\system32\tijayefe.dll [2009-07-30 89088]
"kobuguhof"= {413f0a90-469a-44e0-ac55-2534858a2282} - c:\windows\system32\tijayefe.dll [2009-07-30 89088]
"dibofehen"= {14fe8fbb-7a06-4215-8e00-9d7b38662bdc} - c:\windows\system32\tijayefe.dll [2009-07-30 89088]
"soyerebog"= {61238692-df6d-4d78-a15f-cd48f9991f60} - c:\windows\system32\tijayefe.dll [2009-07-30 89088]
"rivuzizum"= {0c35cdec-f50f-4c9e-93a4-0ef26441ed77} - c:\windows\system32\viwadefo.dll [2009-08-01 89088]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=c:\windows\pss\AutoUpdate Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 1000 series.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [9/6/2008 12:33 PM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [9/6/2008 12:33 PM 38528]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [10/5/2009 5:22 AM 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [8/21/2008 6:04 AM 98304]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [6/29/2006 12:19 PM 200576]
S3 DzlUsb;Dazzle DVC USB Device;c:\windows\system32\drivers\DzlUsb.sys [2/12/2009 10:07 PM 62800]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [9/30/2008 5:56 PM 14976]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:34]
2008-08-06 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8210036949.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 05:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} - hxxp://www.shockwave.com/content/fashiondash/sis/fashiondashweb.1.0.0.21.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\odolpp8q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\odolpp8q.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
BHO-{571d9660-bab1-4729-aa62-1f17d27c60cc} - bahaboho.dll
BHO-{7FE54E07-2F72-42D8-96C9-E7128D6A07D0} - c:\windows\system32\fccyXRKe.dll
HKCU-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-zipikobusi - jibepobo.dll
SharedTaskScheduler-{6676b59e-ea1a-436b-82d8-e8cfaa8b3072} - c:\windows\system32\gejapifo.dll
SSODL-fifidunod-{6676b59e-ea1a-436b-82d8-e8cfaa8b3072} - c:\windows\system32\gejapifo.dll
AddRemove-Picasa 3 - c:\documents and settings\Owner\My Documents\My Pictures\Google\Picasa3\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-01 22:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spaa.sys >>UNKNOWN [0x86588938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF73B4B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF73B4B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF73B4B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF73B4B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF73B4B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF73B4B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(648)
c:\windows\system32\BCMLogon.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2880)
c:\windows\system32\viwadefo.dll
c:\windows\system32\tijayefe.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Microsoft Shared\OFFICE11\MSOXEV.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WLTRAY.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-11-02 22:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-02 04:48
Pre-Run: 2,599,698,432 bytes free
Post-Run: 10,353,078,272 bytes free
- - End Of File - - 6DE53CB9F135A344F92F25F29F5CC28C