Heylo.
That worked. Here is the combofix log, a new uninstall list and a new hijackthis log.
----------------
Combofix Log
----------------
ComboFix 10-01-04.01 - Leona 01/05/2010 9:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.728 [GMT -8:00]
Running from: c:\documents and settings\Leona\Desktop\somethingElse.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Leona\Application Data\Microsoft\svchost.exe
C:\LOG16F.tmp
C:\LOG183.tmp
C:\LOG186.tmp
C:\LOG189.tmp
c:\windows\system32\drivers\H8SRTrvtedpjklw.sys
c:\windows\system32\h8srtcfg.dat
c:\windows\system32\H8SRTckjsrdlrbe.dll
c:\windows\system32\H8SRTigupkysyfh.dll
c:\windows\system32\H8SRTryfxkmbxio.dat
c:\windows\system32\srcr.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-05 15:27 . 2010-01-05 15:27 -------- d-sh--w- c:\documents and settings\Leona\IECompatCache
2009-12-31 02:30 . 2009-12-31 02:30 -------- d-----w- c:\program files\ERUNT
2009-12-31 02:29 . 2009-12-31 02:29 -------- d-----w- c:\program files\TrendMicro
2009-12-30 21:42 . 2009-12-30 21:42 -------- d-----w- C:\Rooter$
2009-12-30 21:31 . 2009-12-30 21:31 -------- d-----w- C:\VundoFix Backups
2009-12-30 21:12 . 2009-12-30 21:12 -------- d-----w- c:\documents and settings\Leona\Local Settings\Application Data\Tific
2009-12-30 21:01 . 2009-12-30 21:01 -------- d-----w- c:\documents and settings\Leona\Application Data\Tific
2009-12-30 20:48 . 2009-12-30 20:48 -------- d-----w- c:\windows\system32\drivers\NAV
2009-12-30 20:48 . 2009-12-30 20:48 -------- d-----w- c:\program files\Windows Sidebar
2009-12-30 20:48 . 2009-12-30 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-12-30 20:36 . 2009-12-30 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-19 22:36 . 2009-12-19 22:36 -------- d-----w- c:\windows\Sun
2009-12-19 22:06 . 2009-12-19 22:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-19 22:06 . 2009-12-19 22:06 -------- d-----w- c:\program files\Java
2009-12-14 04:23 . 2009-12-14 04:24 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Adobe
2009-12-14 03:01 . 2009-12-14 03:01 -------- d-----w- c:\program files\CCleaner
2009-12-14 02:38 . 2009-12-14 02:38 56756 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-14 00:49 . 2009-12-14 00:49 -------- d-----w- c:\documents and settings\Leona\Application Data\Webroot
2009-12-14 00:49 . 2009-12-14 00:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Geek Squad
2009-12-13 05:51 . 2009-12-13 05:51 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-12-13 03:36 . 2009-12-13 03:36 -------- d-----w- c:\documents and settings\Leona\Local Settings\Application Data\Mozilla
2009-12-12 23:57 . 2009-12-12 23:57 -------- d-----w- c:\documents and settings\Guest\Application Data\Office Genuine Advantage
2009-12-12 23:50 . 2009-12-12 23:50 -------- d-sh--w- c:\documents and settings\Guest\PrivacIE
2009-12-12 23:49 . 2009-12-12 23:49 -------- d-sh--w- c:\documents and settings\Guest\IETldCache
2009-12-12 23:44 . 2009-12-12 23:44 -------- d-sh--w- c:\documents and settings\Leona\PrivacIE
2009-12-12 23:37 . 2009-12-12 23:37 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-12 23:31 . 2009-12-12 23:31 -------- d-sh--w- c:\documents and settings\Leona\IETldCache
2009-12-12 23:17 . 2009-10-29 07:45 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-12 23:17 . 2009-10-29 07:45 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-12 23:17 . 2009-12-12 23:17 -------- d-----w- c:\windows\ie8updates
2009-12-12 23:16 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-12-12 23:15 . 2009-12-12 23:16 -------- dc-h--w- c:\windows\ie8
2009-12-12 23:13 . 2009-12-12 23:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-12-12 23:13 . 2009-12-12 23:13 -------- d-----w- c:\documents and settings\Leona\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 02:29 . 2009-12-31 02:29 388096 ----a-r- c:\documents and settings\Leona\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-12-30 21:26 . 2006-01-30 22:14 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-30 21:18 . 2006-01-30 22:13 -------- d-----w- c:\program files\Google
2009-12-19 22:34 . 2009-12-19 22:06 152576 ----a-w- c:\documents and settings\Leona\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-19 22:34 . 2009-12-19 22:06 79488 ----a-w- c:\documents and settings\Leona\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-19 22:22 . 2009-12-19 22:22 152576 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-12-19 22:19 . 2009-12-19 22:02 152576 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-19 22:18 . 2009-12-19 22:01 79488 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-13 04:12 . 2007-10-08 18:51 2858 -c--a-w- c:\documents and settings\Leona\Application Data\wklnhst.dat
2009-12-13 03:35 . 2009-11-09 05:43 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-12-12 22:43 . 2008-02-18 09:29 70248 -c--a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-06 02:18 . 2007-09-20 02:50 -------- d-----w- c:\documents and settings\Leona\Application Data\Ruckus Network
2009-11-28 07:43 . 2007-08-12 20:59 -------- d-----w- c:\documents and settings\Leona\Application Data\Apple Computer
2009-11-23 00:18 . 2008-12-02 05:48 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 15:51 . 2006-01-30 17:57 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-19 23:23 . 2007-10-22 03:09 -------- d-----w- c:\documents and settings\Leona\Application Data\Move Networks
2009-11-19 22:35 . 2009-09-21 17:02 143976 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\uninstall.exe
2009-11-19 22:35 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\plugins\npqmp071701000002.dll
2009-11-19 22:35 . 2009-11-19 22:35 1794456 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
2009-11-13 07:23 . 2008-08-27 06:49 -------- d-----w- c:\program files\Safari
2009-11-13 07:20 . 2009-11-13 07:20 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-11-13 07:18 . 2009-11-13 07:17 -------- d-----w- c:\program files\iTunes
2009-11-13 07:18 . 2009-11-13 07:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-13 07:18 . 2009-11-13 07:18 -------- d-----w- c:\program files\iPod
2009-11-13 07:18 . 2007-09-18 23:37 -------- d-----w- c:\program files\Common Files\Apple
2009-11-13 07:14 . 2007-12-15 05:58 -------- d-----w- c:\program files\QuickTime
2009-11-13 07:05 . 2009-11-13 07:05 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:45 . 2006-01-30 18:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 01:55 . 2009-08-03 21:48 4187512 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\plugins\npqmp071505000010.dll
2009-10-29 01:55 . 2009-10-29 01:54 1407680 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\MoveMediaPlayerWin_071505000010.exe
2009-10-21 05:38 . 2006-01-30 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-01-30 17:59 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-15 00:50 . 2009-10-15 00:50 97216 ----a-w- c:\documents and settings\Leona\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-10-13 10:30 . 2006-01-30 17:59 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-01-30 18:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-01-30 18:00 79872 ----a-w- c:\windows\system32\raschap.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-04-27 21:17 . 2007-04-27 21:17 50736 c:\program files\AIM6\bak\aim6.exe
2008-01-03 16:15 . 2008-01-03 16:15 50528 c:\program files\AIM6\aim6.exe
2006-01-30 22:09 . 2005-11-01 19:11 242688 c:\program files\Fujitsu\Application Panel\bak\QuickTouch.exe
2006-01-30 22:09 . 2008-01-29 01:22 242688 c:\program files\Fujitsu\Application Panel\QuickTouch.exe
2006-01-30 22:09 . 2005-11-01 19:06 61440 c:\program files\Fujitsu\BtnHnd\bak\BtnHnd.exe
2006-01-30 22:09 . 2008-01-29 01:22 61440 c:\program files\Fujitsu\BtnHnd\BtnHnd.exe
2006-01-30 22:08 . 2005-06-08 17:20 69632 c:\program files\Fujitsu\FUJ02E3\bak\FUJ02E3.exe
2006-01-30 22:08 . 2008-01-29 01:22 69632 c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe
2006-02-06 19:22 . 2005-09-10 08:12 81920 c:\program files\Fujitsu\Fujitsu Hotkey Utility\bak\IndicatorUty.exe
2006-02-06 19:22 . 2008-01-29 01:22 81920 c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
2006-02-19 09:41 . 2006-02-19 09:41 49152 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe
2008-12-08 22:50 . 2008-12-08 22:50 54576 c:\program files\HP\HP Software Update\hpwuschd2.exe
2007-12-11 18:56 . 2007-12-11 18:56 286720 c:\program files\QuickTime\bak\QTTask.exe
2009-09-05 09:54 . 2009-09-05 09:54 417792 c:\program files\QuickTime\QTTask.exe
2006-01-30 21:42 . 2006-01-05 09:03 761946 c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
2006-01-30 21:42 . 2008-01-29 01:22 761946 c:\program files\Synaptics\SynTP\SynTPEnh.exe
2006-01-30 18:00 . 2004-08-04 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-01-30 18:00 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATSwpNav"="c:\program files\Fingerprint Sensor\ATSwpNav -run" [X]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2008-01-29 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2008-01-29 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-29 761946]
"LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2008-01-29 69632]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2008-01-29 242688]
"LoadBtnHnd"="c:\program files\Fujitsu\BtnHnd\BtnHnd.exe" [2008-01-29 61440]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2008-01-29 81920]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-07 16010240]
"AGRSMMSG"="AGRSMMSG.exe" [2006-01-17 88365]
"msnappau"="c:\program files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe" [N/A]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-19 149280]
c:\documents and settings\Leona\Start Menu\Programs\Startup\MRI_DISABLED
TrayIt!.lnk - c:\program files\Trayit\TrayIt!.exe [2007-8-12 172032]
c:\documents and settings\All Users\Start Menu\Programs\Startup\MRI_DISABLED
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2009-08-13 23:51 177440 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 22:50 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 04:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 09:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 FJGPNV;FJGPNV;c:\windows\system32\drivers\FJGPNV.SYS [1/30/2006 1:56 PM 10496]
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2/21/2006 2:05 PM 36352]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [9/23/2005 6:48 AM 28544]
R2 FlashDrv;FlashDrv;c:\progra~1\Fujitsu\FlashAid\FlashDrv.sys [1/30/2006 2:12 PM 7196]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [1/30/2006 11:22 AM 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [1/30/2006 11:22 AM 4864]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/14/2008 12:18 AM 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]
2010-01-05 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 23:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Leona\Application Data\Mozilla\Firefox\Profiles\qthoqifq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\documents and settings\Leona\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Leona\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\documents and settings\Leona\Desktop\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-05 09:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{06D662EF-1B18-9E0A-C7540872BBA4B266}\{EBB6626D-026A-B870-36A2109435AC20FE}\{EDFF6A5F-75C2-5A8A-3FBA9ED6355C20B5}*]
"JWOYTVPITEDJCHYUGDR5XL6BSC1"=hex:01,00,01,00,00,00,00,00,b1,dc,8a,ef,e5,23,43,
80,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0FE9758D-999D-5364-A982D9FF5B788FED}\{C0BD10EF-72B8-B20F-55BDE04C7FD39C0B}\{292331AE-173A-E499-B30D8FE5870ABBF2}*]
"JWOYTVPITEDJCHYUGDR5XL6BSC1"=hex:01,00,01,00,00,00,00,00,b1,dc,8a,ef,e5,23,43,
80,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1068)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3028)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Fingerprint Sensor\ATSwpNav.exe
c:\windows\RTHDCPL.EXE
c:\windows\AGRSMMSG.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\o2flash.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-01-05 10:02:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-05 18:02
Pre-Run: 75,427,143,680 bytes free
Post-Run: 75,697,913,856 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B88D891DE27F281201903A4D2E5880C3
--------------------------
Hijackthis Uninstall List
--------------------------
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.1.0
Agere Systems HDA Modem
AIM 6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Bonjour Core for Windows
CCleaner
Combined Community Codec Pack 2007-02-22
Compatibility Pack for the 2007 Office system
Critical Update for Windows Media Player 11 (KB959772)
ERUNT 1.1j
Fingerprint Sensor Minimum Install
FlashAid
Fujitsu Driver Update
Fujitsu Hotkey Utility
Fujitsu System Extension Utility
Goombah Partner COM Server
High Definition Audio Driver Package - KB888111
HiJackThis
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HP Update
iTunes
Java(TM) 6 Update 17
LifeBook Application Panel
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
Minitab 15 English
MobileMe Control Panel
Mozilla Firefox (3.5.5)
MSN
MSN Toolbar
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
O2Micro Flash Memory Card Windows Driver
O2Micro Smartcard Driver
OCR Software by I.R.I.S 7.0
Office 2003 Trial Assistant
OGA Notifier 2.0.0048.0
PowerDVD
Quicken 2006
QuickTime
Realtek High Definition Audio Driver
Ruckus Player
Safari
Security Panel Application
Security Panel Application for Supervisor
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Spybot - Search & Destroy 1.4
Synaptics Pointing Device Driver
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
Windows Internet Explorer 8
Windows Live installer
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix [See KB887626 for more information]
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
-----------------
Hijackthis Log
-----------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:12 AM, on 1/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Leona\Desktop\HiJackThis_v2.exe
C:\WINDOWS\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MRI_DISABLED
O4 - Global Startup: MRI_DISABLED
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} (FixItClient Class) -
https://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 6401 bytes