Here is the ComboFix Log
ComboFix 08-02-23.2 - Wade 2008-02-23 8:45:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1484 [GMT -6:00]
Running from: C:\Documents and Settings\Wade\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\apyoluoq.ini
C:\WINDOWS\system32\awtstrr.dll
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\fparcuek.ini
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\ggjlm.ini
C:\WINDOWS\system32\ggjlm.ini2
C:\WINDOWS\system32\ghyhaokh.ini
C:\WINDOWS\system32\gjkkj.ini
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\gpcsalct.dll
C:\WINDOWS\system32\hsvrutql.ini
C:\WINDOWS\system32\ietathsa.dll
C:\WINDOWS\system32\jkpnmgap.ini
C:\WINDOWS\system32\jlnmp.ini
C:\WINDOWS\system32\jlnmp.ini2
C:\WINDOWS\system32\jpinqybc.ini
C:\WINDOWS\system32\keucrapf.dll
C:\WINDOWS\system32\kjkmp.ini
C:\WINDOWS\system32\kjkmp.ini2
C:\WINDOWS\system32\lbkmswwm.ini
C:\WINDOWS\system32\lcnvxjev.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mgwlnfld.ini
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mvafjlaw.ini
C:\WINDOWS\system32\nirdtvot.ini
C:\WINDOWS\system32\nuwelsdp.ini
C:\WINDOWS\system32\pwxtoguu.dll
C:\WINDOWS\system32\qpphivww.ini
C:\WINDOWS\system32\qpqss.ini
C:\WINDOWS\system32\qpqss.ini2
C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\rqstv.ini
C:\WINDOWS\system32\rqstv.ini2
C:\WINDOWS\system32\sabqkcbs.dll
C:\WINDOWS\system32\ssqrphoq.ini
C:\WINDOWS\system32\ttutv.ini
C:\WINDOWS\system32\ttutv.ini2
C:\WINDOWS\system32\ufsgaigc.ini
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utvwa.ini2
C:\WINDOWS\system32\vceqoalw.ini
C:\WINDOWS\system32\waljfavm.dll
C:\WINDOWS\system32\windoqwd.ini
C:\WINDOWS\system32\wwvihppq.dll
C:\WINDOWS\system32\ybeeg.ini
C:\WINDOWS\system32\ybeeg.ini2
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.
2008-02-18 18:18 . 2008-02-22 17:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-18 12:28 . 2008-02-18 12:28 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-18 12:28 . 2008-02-18 12:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-18 12:15 . 2008-02-18 12:12 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-18 12:15 . 2008-02-18 12:15 3,444 --a------ C:\WINDOWS\unins000.dat
2008-02-14 19:44 . 2008-02-14 19:46 <DIR> d-------- C:\Documents and Settings\Anaise\Application Data\Creative
2008-02-14 08:42 . 2008-02-14 11:41 354 --ahs---- C:\WINDOWS\system32\pmhohixn.ini
2008-02-12 08:57 . 2008-02-12 08:57 2,443,359 --ahs---- C:\WINDOWS\system32\ygjqtdwf.ini
2008-02-11 10:21 . 2008-02-11 10:21 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-11 09:55 . 2008-02-11 09:55 <DIR> d-------- C:\Documents and Settings\Wade\Application Data\Talkback
2008-02-11 09:55 . 2008-02-11 09:55 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-01 13:02 . 2008-02-02 13:02 354 --ahs---- C:\WINDOWS\system32\dljhvudb.ini
2008-01-31 21:31 . 2008-01-31 21:32 354 --ahs---- C:\WINDOWS\system32\hxllfwxc.ini
2008-01-31 20:31 . 2008-01-31 20:31 294 --ahs---- C:\WINDOWS\system32\trygfnji.ini
2008-01-31 19:45 . 2008-01-30 19:47 414 --ahs---- C:\WINDOWS\system32\kvbwodho.ini
2008-01-31 11:57 . 2008-01-30 15:56 294 --ahs---- C:\WINDOWS\system32\excfbeeh.ini
2008-01-30 20:03 . 2008-01-31 11:50 294 --ahs---- C:\WINDOWS\system32\pscqewxh.ini
2008-01-30 17:39 . 2008-01-29 17:41 294 --ahs---- C:\WINDOWS\system32\dvuhhtxe.ini
2008-01-30 16:06 . 2008-01-31 19:44 354 --ahs---- C:\WINDOWS\system32\trtphpva.ini
2008-01-30 16:06 . 2008-01-30 16:06 294 --ahs---- C:\WINDOWS\system32\excfbeeh.tmp
2008-01-30 08:27 . 2008-02-18 12:17 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-30 08:27 . 2008-02-18 12:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-30 07:02 . 2008-01-30 07:02 294 --ahs---- C:\WINDOWS\system32\qrqjgtsy.ini
2008-01-29 20:51 . 2008-01-29 23:08 294 --ahs---- C:\WINDOWS\system32\jcdmwtbt.ini
2008-01-29 17:53 . 2008-01-29 17:54 354 --ahs---- C:\WINDOWS\system32\enqowbme.ini
2008-01-29 13:28 . 2008-02-23 08:55 31,056 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx
2008-01-29 13:28 . 2008-02-23 08:55 31,056 --a------ C:\WINDOWS\system32\BMXState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx
2008-01-29 13:28 . 2008-02-23 08:55 30,528 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx
2008-01-29 13:28 . 2008-02-23 08:55 30,528 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx
2008-01-29 13:28 . 2008-02-23 08:56 2,148 --a------ C:\WINDOWS\system32\wpa.dbl
2008-01-29 13:28 . 2008-02-23 08:55 384 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-20061102}.dat
2008-01-29 13:28 . 2008-02-23 08:55 384 --a------ C:\WINDOWS\system32\DVCState-{00000004-00000000-00000002-00001102-00000004-20061102}.dat
2008-01-29 12:56 . 2008-02-08 11:35 22 --a------ C:\WINDOWS\pskt.ini
2008-01-24 13:58 . 2008-01-24 13:58 <DIR> d-------- C:\Program Files\UnH Solutions
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-13 23:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-04 16:54 --------- d-----w C:\Program Files\Norton 360
2008-01-19 16:12 --------- d-----w C:\Documents and Settings\Wade\Application Data\LimeWire
2008-01-15 15:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 11:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 00:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-14 23:15 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-28 11:09 83,440 ----a-w C:\WINDOWS\system32\dwabho.dll
2007-11-10 02:10 58,728 ----a-w C:\WINDOWS\Fonts\scriptina.zip
2007-11-10 02:10 27,040 ----a-w C:\WINDOWS\Fonts\brankovic.zip
2007-11-10 02:10 18,062 ----a-w C:\WINDOWS\Fonts\cheri.zip
2002-05-20 13:19 61,440 ----a-w C:\WINDOWS\inf\i386\onetUSD.dll
2002-05-16 13:22 36,864 ----a-w C:\WINDOWS\inf\i386\Vizmicro.dll
2002-05-16 13:21 286,720 ----a-w C:\WINDOWS\inf\i386\rtscan.dll
2002-05-16 13:20 172,032 ----a-w C:\WINDOWS\inf\i386\viceo.dll
2001-08-03 23:29 13,824 ----a-w C:\WINDOWS\inf\i386\Usbscan.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C9C5C6E-DA28-4F37-89C4-2E30284562FB}]
C:\WINDOWS\system32\geeby.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A6781B4-3DBE-4A9A-95B3-CA561198F83D}]
C:\WINDOWS\system32\vtsqr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E776592-7B14-4F2E-9AAE-5E40D12A5F6B}]
C:\WINDOWS\system32\ssqpq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7109C48-773A-4472-B991-09A694331587}]
C:\WINDOWS\system32\ddcyy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCD6B05D-5281-4D66-92EC-89159B441BED}]
C:\WINDOWS\system32\vtutu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA3A28AA-C658-41F2-BF92-1DAC83133118}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 19:55 68856]
"TivoTransfer"="C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" [2007-08-06 10:12 1192960]
"TivoServer"="C:\Program Files\TiVo\Desktop\TiVoServer.exe" [2007-08-06 10:14 1492480]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 09:43 57344]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 00:00 45056]
"CTHelper"="CTHELPER.EXE" [2004-03-10 19:50 28672 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]
"WD Button Manager"="WDBtnMgr.exe" [2007-04-10 20:37 335872 C:\WINDOWS\system32\WDBtnMgr.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-11-11 16:11 4612096]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-22 13:49 188416]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2002-11-22 13:48 348160]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-11-22 13:50 49152]
"OneTouch Monitor"="C:\Program Files\Visioneer OneTouch\OneTouchMon.exe" [2002-05-20 07:17 86016]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 00:05 122939]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 00:01 110592]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 04:50 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30 517768]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42 267064]
"BMbf20e593"="C:\WINDOWS\system32\baihentp.dll" [ ]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bc13d60f]
C:\WINDOWS\system32\wylahnty.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMbf20e593]
C:\WINDOWS\system32\baihentp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 05:24 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-14 19:55 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"TivoNotify"="C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"bc13d60f"=rundll32.exe "C:\WINDOWS\system32\wylahnty.dll",b
"SetIcon"=\Program Files\WDC\SetIcon.exe
"BMbf20e593"=Rundll32.exe "C:\WINDOWS\system32\baihentp.dll",s
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe

xpsp2res.dll,-22019
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\\Network Diagnostic\\xpnetdiag.exe

xpsp3res.dll,-20000
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41793:TCP"= 41793:TCP:Gnutella OUT
"41793:UDP"= 41793:UDP:Gnutella IN
"23688:TCP"= 23688:TCP:BitComet 23688 TCP
"23688:UDP"= 23688:UDP:BitComet 23688 UDP
R2 TivoBeacon2;TiVo Beacon;"C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" [2007-08-06 10:12]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 13:37:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-23 14:56:32 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2008-02-23 14:56:33 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2008-01-29 18:56:41 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-23 08:57:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\system32\HPHipm11.exe
.
**************************************************************************
.
Completion time: 2008-02-23 9:03:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 15:03:33
.
2008-01-24 16:04:04 --- E O F ---