Hhere is the ConboFix log. Let me know what this all means and what (if any more) I need to continue fixing. Thank you again.
ComboFix 09-01-01.02 - Jason Woods 2009-01-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.350 [GMT -5:00]
Running from: c:\documents and settings\Jason Woods\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jason Woods\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\_004197_.tmp.dll
c:\windows\system32\_004198_.tmp.dll
c:\windows\system32\_004199_.tmp.dll
c:\windows\system32\_004200_.tmp.dll
c:\windows\system32\_004207_.tmp.dll
c:\windows\system32\_004208_.tmp.dll
c:\windows\system32\_004209_.tmp.dll
c:\windows\system32\_004210_.tmp.dll
c:\windows\system32\_004212_.tmp.dll
c:\windows\system32\_004213_.tmp.dll
c:\windows\system32\_004216_.tmp.dll
c:\windows\system32\_004217_.tmp.dll
c:\windows\system32\_004219_.tmp.dll
c:\windows\system32\_004220_.tmp.dll
c:\windows\system32\_004221_.tmp.dll
c:\windows\system32\_004223_.tmp.dll
c:\windows\system32\_004226_.tmp.dll
c:\windows\system32\_004227_.tmp.dll
c:\windows\system32\_004229_.tmp.dll
c:\windows\system32\_004231_.tmp.dll
c:\windows\system32\_004232_.tmp.dll
c:\windows\system32\_004234_.tmp.dll
c:\windows\system32\_004237_.tmp.dll
c:\windows\system32\_004239_.tmp.dll
c:\windows\system32\_004240_.tmp.dll
c:\windows\system32\_004241_.tmp.dll
c:\windows\system32\_004242_.tmp.dll
c:\windows\system32\_004243_.tmp.dll
c:\windows\system32\_004246_.tmp.dll
c:\windows\system32\_004247_.tmp.dll
c:\windows\system32\_004248_.tmp.dll
c:\windows\system32\_004249_.tmp.dll
c:\windows\system32\_004250_.tmp.dll
c:\windows\system32\_004255_.tmp.dll
c:\windows\system32\_004257_.tmp.dll
c:\windows\system32\_004258_.tmp.dll
c:\windows\system32\adasolug.ini
c:\windows\system32\afinadeb.ini
c:\windows\system32\ajezukiv.ini
c:\windows\system32\ajililub.ini
c:\windows\system32\akinudoy.ini
c:\windows\system32\amasebep.ini
c:\windows\system32\anahekik.ini
c:\windows\system32\anofolut.ini
c:\windows\system32\asoyukat.ini
c:\windows\system32\avobopor.ini
c:\windows\system32\ayizirof.ini
c:\windows\system32\azipufik.ini
c:\windows\system32\efakunil.ini
c:\windows\system32\ekefotuj.ini
c:\windows\system32\elineror.ini
c:\windows\system32\eluwovik.ini
c:\windows\system32\enukifom.ini
c:\windows\system32\esokibog.ini
c:\windows\system32\evodahuj.ini
c:\windows\system32\eyekodov.ini
c:\windows\system32\ezumemag.ini
c:\windows\system32\ibinahey.ini
c:\windows\system32\idaholav.ini
c:\windows\system32\idezujur.ini
c:\windows\system32\idogotok.ini
c:\windows\system32\ifoyewig.ini
c:\windows\system32\igukugov.ini
c:\windows\system32\ihuvuvaz.ini
c:\windows\system32\imerurol.ini
c:\windows\system32\inapogob.ini
c:\windows\system32\izumorot.ini
c:\windows\system32\obamuveg.ini
c:\windows\system32\ohoragog.ini
c:\windows\system32\ohujudud.ini
c:\windows\system32\okubotub.ini
c:\windows\system32\orukijuv.ini
c:\windows\system32\owazehig.ini
c:\windows\system32\owihipak.ini
c:\windows\system32\sohezigu.dll
c:\windows\system32\ufivihud.ini
c:\windows\system32\ugomezit.ini
c:\windows\system32\uholunoh.ini
c:\windows\system32\ujowoyar.ini
c:\windows\system32\ukewuvep.ini
c:\windows\system32\ukoboger.ini
c:\windows\system32\uloputak.ini
c:\windows\system32\uteyewaf.ini
c:\windows\system32\uwafoweg.ini
c:\windows\system32\uwelazah.ini
c:\windows\system32\uwodilug.ini
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 10:09 . 2009-01-02 10:09 <DIR> d-------- c:\program files\Sun
2009-01-02 10:08 . 2009-01-02 10:07 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-02 10:08 . 2009-01-02 10:07 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-01 16:41 . 2009-01-01 19:24 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-01-01 15:14 . 2009-01-01 15:14 <DIR> d-------- c:\documents and settings\Jason Woods\Application Data\Malwarebytes
2009-01-01 15:13 . 2009-01-01 15:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-01 15:13 . 2009-01-01 15:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-01 15:13 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-01 15:13 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-01 15:03 . 2009-01-01 15:03 33,832 --a------ c:\windows\system32\jabhpwrg.exe
2009-01-01 10:10 . 2009-01-01 10:13 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-01-01 09:40 . 2009-01-01 09:40 <DIR> d-------- c:\program files\Trend Micro
2008-12-31 17:10 . 2008-12-31 17:10 <DIR> d-------- c:\windows\CF055C57A98842E6BDAFE3D94C6973A8.TMP
2008-12-31 17:10 . 2008-12-31 17:10 <DIR> d-------- c:\program files\DIFX
2008-12-31 16:56 . 2008-12-31 16:56 <DIR> d-------- c:\documents and settings\Jason Woods\.assistant
2008-12-31 16:34 . 2008-11-25 12:39 18,560 --a------ c:\windows\system32\drivers\FlyUsb.sys
2008-12-31 16:31 . 2008-12-31 16:33 110 --a------ c:\windows\{CF055C57-A988-42E6-BDAF-E3D94C6973A8}_WiseFW.ini
2008-12-31 16:30 . 2008-12-31 16:32 <DIR> d-------- c:\program files\LeapFrog
2008-12-31 16:30 . 2008-12-31 16:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Leapfrog
2008-12-30 13:55 . 2008-12-30 13:55 <DIR> d-------- c:\program files\Citrix
2008-12-30 13:55 . 2008-09-30 16:04 42,792 --a------ c:\windows\system32\gotomon.dll
2008-12-19 11:45 . 2008-12-19 11:45 <DIR> d-------- c:\program files\Lavasoft
2008-12-19 11:45 . 2008-12-19 11:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-17 11:33 . 2008-12-17 11:33 <DIR> d-------- c:\windows\system32\en
2008-12-17 11:33 . 2008-12-17 11:33 <DIR> d-------- c:\windows\system32\bits
2008-12-16 23:56 . 2008-12-16 23:56 2,763 --a------ c:\windows\system32\spupdsvc.inf
2008-12-16 23:47 . 2008-12-16 23:47 <DIR> d-------- c:\windows\system32\scripting
2008-12-16 23:47 . 2008-12-16 23:47 <DIR> d-------- c:\windows\l2schemas
2008-12-16 23:43 . 2008-12-16 23:48 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-16 23:01 . 2008-12-17 11:29 <DIR> d-------- c:\program files\Windows Defender
2008-12-08 20:54 . 2008-12-08 20:54 <DIR> d-------- c:\program files\iTunes
2008-12-08 20:54 . 2008-12-08 20:54 <DIR> d-------- c:\program files\iPod
2008-12-08 20:54 . 2008-12-08 20:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-08 20:50 . 2008-12-08 20:51 <DIR> d-------- c:\program files\QuickTime
2008-12-06 10:33 . 2008-12-31 17:09 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 15:07 --------- d-----w c:\program files\Java
2009-01-01 15:02 --------- d-----w c:\program files\Common Files\Apple
2009-01-01 15:02 --------- d-----w c:\documents and settings\Jason Woods\Application Data\Move Networks
2008-12-31 21:33 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-30 18:55 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-30 18:18 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-19 15:07 --------- d-----w c:\program files\McAfee
2008-12-10 18:50 --------- d-----w c:\program files\Google
2008-01-14 16:09 61,480 -c--a-w c:\documents and settings\Jason Woods\GoToAssistDownloadHelper.exe
2008-06-09 19:18 152 --sh--r c:\windows\system32\818F014236.sys
2008-06-09 19:18 8,456 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-10 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="" [X]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-07 168448]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-11-12 1347584]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-09-18 185632]
"SMSTray"="c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 132624]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 74672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"GoToMyPC"="c:\program files\Citrix\GoToMyPC\g2svc.exe" [2008-09-30 258856]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-11-25 356352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-02 136600]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-02-07 24576]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-10-03 54512]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2008-09-30 16:04 10536 c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\WINDOWS\\system32\\lxczcoms.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\Program Files\\Samsung\\Samsung Media Studio 5\\SMSTray.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\CommandService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service;"c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe" [2008-11-25 991232]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-09-26 206096]
R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
S3 FlyUsb;FLY Fusion;c:\windows\system32\DRIVERS\FlyUsb.sys [2008-12-31 18560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f8408f0-63da-11dd-905f-00038a000015}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
http://www.mgae.com/keylauncher/?code=3654264636448860
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2009-01-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BMUpdate - c:\windows\system32\BMUpdate.exe
HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
HKU-Default-Run-lolafegaku - c:\windows\system32\fomihari.dll
SharedTaskScheduler-SSODL - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*
http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 15:48:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\PAPI\DEV\W*NULL*I*NULL*N*NULL*B*NULL*O*NULL*N*NULL*D*NULL*_*NULL*C*NULL*D*NULL*-*NULL*R*NULL*O*NULL*M*NULL*_*NULL*D*NULL*R*NULL*I*NULL*V*NULL*E*NULL*

NULL*0*NULL*0*NULL*1*NULL*_*NULL*_*NULL**NULL*¬ ]
"Tested"=hex:00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(904)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
- - - - - - - > 'explorer.exe'(4460)
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Citrix\GoToMyPC\g2comm.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Citrix\GoToMyPC\g2pre.exe
c:\windows\system32\lxczcoms.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Citrix\GoToMyPC\g2tray.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Lexmark 1200 Series\LXCZbmon.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-01-02 15:57:17 - machine was rebooted [Jason Woods]
ComboFix-quarantined-files.txt 2009-01-02 20:56:28
Pre-Run: 31,127,199,744 bytes free
Post-Run: 31,111,041,024 bytes free
319 --- E O F --- 2008-11-13 03:27:36
Blessings,
Kim