Here are the logs from all 3 apps
ComboFix:
ComboFix 09-04-27.02 - Student 04/28/2009 17:00.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.447.156 [GMT -7:00]
Running from: c:\documents and settings\Student\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Student\Desktop\CFScript.txt
FW: COMODO Firewall *enabled*
* Created a new restore point
FILE ::
c:\docume~1\Student\LOCALS~1\Temp\189101462.exe
c:\windows\Cfagazuyufom.dat
c:\windows\system32\dajufiwe.dll
c:\windows\system32\duputiva.dll
c:\windows\system32\hsf73ikmdf3f.dll
c:\windows\system32\vogekohe.dll
c:\windows\system32\zesiyaza.dll
c:\windows\TEMP\kfihi7v6.exe
c:\windows\Xwofiwam.bin
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
c:\windows\Cfagazuyufom.dat
c:\windows\system32\cas
c:\windows\system32\cas\call.bat
c:\windows\system32\cas\caok.com
c:\windows\system32\cas\caok2.com
c:\windows\system32\cas\check.vbs
c:\windows\system32\cas\checkdateKW.vbs
c:\windows\system32\cas\delregkey.vbs
c:\windows\system32\cas\invisible.vbs
c:\windows\system32\cas\Locked.vbs
c:\windows\system32\cas\message.vbs
c:\windows\system32\cas\Mime.pl
c:\windows\system32\cas\msname.vbs
c:\windows\system32\cas\shut.bat
c:\windows\system32\cas\shutdown2.vbs
c:\windows\system32\cas\sn.vbs
c:\windows\system32\cas\StartShut.bat
c:\windows\Xwofiwam.bin
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FCI
-------\Service_FCI
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.
2009-04-28 07:20 . 2009-04-28 07:20 -------- d-----w c:\program files\Sanny Builder 3
2009-04-28 04:32 . 2009-04-28 04:32 -------- d-----w c:\documents and settings\Student\Application Data\Havok
2009-04-28 03:56 . 2009-04-28 04:39 -------- d-----w c:\program files\Havok
2009-04-27 20:23 . 2009-04-27 20:48 -------- d-----w c:\documents and settings\Student\Application Data\Desktop Sidebar
2009-04-27 20:05 . 2009-04-27 20:05 -------- d-----w c:\program files\Desktop Sidebar
2009-04-25 06:05 . 2005-11-14 05:40 89360 ----a-w c:\windows\system32\VB5DB.DLL
2009-04-25 06:05 . 2009-04-25 06:17 -------- d-----w C:\Unreal Anthology
2009-04-25 00:51 . 2009-04-27 07:52 -------- d-----w C:\Quake2
2009-04-25 00:32 . 2009-04-25 00:32 -------- d--h--w c:\windows\PIF
2009-04-25 00:03 . 2009-04-25 00:03 -------- d-----w c:\program files\Nufsoft
2009-04-22 20:08 . 2009-04-22 20:08 155384 ----a-w c:\windows\system32\guard32.dll
2009-04-22 20:08 . 2009-04-22 20:08 24336 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2009-04-22 20:08 . 2009-04-22 20:08 110992 ----a-w c:\windows\system32\drivers\cmdguard.sys
2009-04-22 06:18 . 2009-04-25 06:47 -------- d-----w c:\program files\PSP Wallpaper Maker
2009-04-21 04:42 . 2009-04-21 05:19 -------- d-----w c:\program files\Rockstar Custom Tracks
2009-04-21 00:07 . 2009-04-28 07:34 -------- d-----w c:\documents and settings\Student\Application Data\Skype
2009-04-21 00:07 . 2009-04-21 00:07 -------- d-----r c:\program files\Skype
2009-04-21 00:07 . 2009-04-21 00:07 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-19 04:08 . 2009-04-19 04:08 -------- d-----w c:\program files\Pcsx2
2009-04-19 02:25 . 2009-04-19 02:30 -------- d-----w c:\documents and settings\Student\Application Data\SoundSpectrum
2009-04-19 02:23 . 2009-04-19 02:23 -------- d-----w c:\program files\SoundSpectrum
2009-04-17 05:47 . 2009-04-17 05:47 -------- d-----w c:\documents and settings\Student\Application Data\Sony
2009-04-17 05:47 . 2009-04-17 05:47 -------- d-----w c:\documents and settings\All Users\Application Data\Sony
2009-04-17 05:47 . 2009-04-17 05:47 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\Sony
2009-04-17 05:46 . 2009-04-17 05:46 -------- d-----w c:\program files\Common Files\Sony Shared
2009-04-17 05:45 . 2009-04-17 05:45 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\Downloaded Installations
2009-04-17 05:44 . 2009-04-21 06:27 -------- d-----w c:\program files\Sony
2009-04-17 05:44 . 2009-04-17 05:44 -------- d-----w c:\documents and settings\All Users\Application Data\Sony Corporation
2009-04-17 05:43 . 2009-04-17 05:43 -------- d-----w c:\program files\Sony Setup
2009-04-16 21:17 . 2009-04-16 21:17 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\{AF69389A-FCD4-4ADE-AA55-2047887F4793}
2009-04-15 08:03 . 2009-04-25 09:52 -------- d-----w c:\documents and settings\Student\Application Data\Stardock
2009-04-15 08:03 . 2009-04-15 08:03 -------- dc-h--w c:\documents and settings\All Users\Application Data\{62902F53-D725-44F9-B385-979CC0E00E8A}
2009-04-15 08:02 . 2009-04-15 08:02 -------- d-----w c:\documents and settings\All Users\Application Data\Stardock
2009-04-15 08:02 . 2009-04-15 08:04 -------- d-----w c:\program files\Stardock
2009-04-13 05:18 . 2009-04-13 05:18 -------- d-----w c:\program files\ffdshow
2009-04-13 05:18 . 2009-04-14 00:45 -------- d-----w c:\documents and settings\Student\Application Data\Sp4rkMod
2009-04-12 01:50 . 2009-04-12 01:50 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-11 21:36 . 2009-04-27 20:02 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\Stardock
2009-04-11 21:29 . 2003-02-27 05:27 36864 ----a-w c:\windows\system32\wbsys.dll
2009-04-11 21:29 . 2009-04-11 21:29 -------- d-----w c:\program files\Common Files\Stardock
2009-04-11 21:29 . 2009-04-16 07:23 -------- d-----w c:\program files\AlienGUIse
2009-04-11 19:49 . 2009-04-11 19:49 -------- d-----w c:\program files\Crytek
2009-04-11 06:01 . 2009-04-11 06:01 -------- d-----w c:\documents and settings\Student\Application Data\Thinking Minds Budiling Bytes
2009-04-10 01:18 . 2009-04-10 01:18 -------- d-----w c:\documents and settings\Student\Application Data\URSoft
2009-04-10 01:18 . 2009-04-25 00:46 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-10 01:18 . 2009-04-11 21:42 -------- d-----w c:\program files\Your Uninstaller 2008
2009-04-10 00:01 . 2009-04-10 00:05 -------- d-----w c:\program files\SystemRequirementsLab
2009-04-10 00:01 . 2009-04-10 00:01 -------- d-----w c:\documents and settings\Student\Application Data\SystemRequirementsLab
2009-04-08 05:40 . 2009-04-08 05:40 4096 ----a-w c:\windows\d3dx.dat
2009-04-07 19:13 . 2009-04-07 19:13 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-04-07 05:09 . 2009-04-25 03:56 -------- d-----w c:\windows\system32\Adobe
2009-04-04 22:42 . 2009-04-04 22:42 -------- d-----w c:\program files\JanSoft
2009-04-04 22:33 . 2004-01-08 18:38 208896 ----a-w c:\windows\system\lame_enc.dll
2009-04-04 21:42 . 2009-04-04 21:42 -------- d-----w c:\documents and settings\Student\Application Data\dvdcss
2009-04-04 18:55 . 2007-06-29 21:47 34304 ----a-w c:\windows\system32\drivers\AmdLLD.sys
2009-04-04 18:55 . 2009-04-04 18:55 -------- d-----w c:\program files\AMD
2009-04-04 18:50 . 2009-04-04 18:51 -------- d-----w c:\windows\system32\The Future Is Fusion dir
2009-04-04 18:50 . 2009-04-04 18:50 520192 ----a-w c:\windows\system32\The Future Is Fusion.scr
2009-04-04 02:12 . 2009-04-04 02:12 -------- d-----w c:\program files\Ubisoft
2009-04-03 06:51 . 2004-08-04 07:56 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-03 06:51 . 2004-08-04 07:56 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-02 23:01 . 2009-04-04 02:01 -------- d-----w c:\program files\the Rosenrot Screensaver
2009-03-31 21:42 . 2009-03-31 21:51 -------- d-----w c:\documents and settings\Student\Application Data\vlc
2009-03-31 21:41 . 2009-03-31 21:41 -------- d-----w c:\program files\VideoLAN
2009-03-31 21:18 . 2008-12-20 23:15 52224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-31 21:18 . 2008-12-20 23:15 459264 -c----w c:\windows\system32\dllcache\msfeeds.dll
2009-03-31 21:18 . 2008-12-19 09:10 13824 -c----w c:\windows\system32\dllcache\ieudinit.exe
2009-03-31 21:18 . 2008-12-20 23:15 267776 -c----w c:\windows\system32\dllcache\iertutil.dll
2009-03-31 21:18 . 2008-12-20 23:15 6066688 -c----w c:\windows\system32\dllcache\ieframe.dll
2009-03-31 21:18 . 2008-12-20 23:15 383488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
2009-03-31 21:18 . 2007-04-17 09:32 2455488 -c----w c:\windows\system32\dllcache\ieapfltr.dat
2009-03-31 21:18 . 2008-12-20 23:15 63488 -c----w c:\windows\system32\dllcache\icardie.dll
2009-03-31 20:30 . 2009-03-31 20:30 253688 ----a-w c:\windows\system32\cssdll32.dll.vir
2009-03-31 20:30 . 2009-04-01 08:07 -------- d-----w c:\program files\AskBarDis
2009-03-31 20:26 . 2009-04-22 20:15 -------- d-----w c:\documents and settings\All Users\Application Data\Comodo
2009-03-31 20:26 . 2009-04-22 20:08 -------- d-----w c:\program files\COMODO
2009-03-31 20:24 . 2009-03-31 20:24 -------- d-----w c:\windows\system32\CatRoot_bak
2009-03-31 00:33 . 2009-03-31 00:33 -------- d-----w c:\program files\PQDVD
2009-03-30 22:36 . 2009-03-30 22:36 -------- d-----w c:\program files\Xiph.Org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 00:05 . 2007-06-08 21:46 -------- d-----w c:\program files\OfficeScan NT
2009-04-28 00:11 . 2009-03-15 02:47 -------- d-----w c:\program files\YouTube Downloader
2009-04-28 00:10 . 2009-03-17 08:24 -------- d-----w c:\program files\Isotope244 Graphics
2009-04-25 06:05 . 2006-07-11 05:39 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-24 22:14 . 2009-03-13 03:56 46472 ----a-w c:\documents and settings\Student\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 00:25 . 2009-03-25 09:10 -------- d-----w c:\program files\the FarCry River Screensaver
2009-04-19 01:13 . 2009-03-19 20:57 -------- d-----w c:\program files\ZMatrix
2009-04-14 08:46 . 2006-02-28 12:00 182912 ----a-w c:\windows\system32\drivers\ndis.sys
2009-04-13 02:10 . 2006-07-11 05:47 -------- d-----w c:\program files\Java
2009-04-12 20:08 . 2006-02-28 12:00 14336 ----a-w c:\windows\system32\svchost.exe
2009-04-11 20:33 . 2009-03-21 06:16 -------- d-----w c:\program files\SCi Games
2009-04-10 07:21 . 2009-03-20 04:00 -------- d-----w c:\program files\OgreDemo
2009-04-10 07:13 . 2009-03-14 05:54 -------- d-----w c:\program files\Extension Changer
2009-04-10 01:24 . 2009-03-14 01:39 -------- d-----w c:\program files\Common Files\Apple
2009-03-31 22:15 . 2009-03-29 02:25 -------- d-----w c:\program files\Peretek
2009-03-31 22:15 . 2009-03-25 09:08 -------- d-----w c:\program files\the FarCry Slideshow
2009-03-29 00:16 . 2009-03-29 00:16 -------- d-----w c:\program files\SRS Labs
2009-03-25 09:06 . 2009-03-25 09:06 818753 ----a-w c:\windows\system32\My Screensaver.scr
2009-03-25 02:41 . 2009-03-25 02:41 -------- d-----w c:\program files\Audacity
2009-03-21 06:18 . 2009-03-21 06:18 -------- d-----w c:\program files\Common Files\DirectX
2009-03-21 02:56 . 2009-03-21 02:56 -------- d-----w c:\program files\Trend Micro
2009-03-21 02:05 . 2009-03-14 01:42 -------- d-----w c:\program files\Bonjour
2009-03-21 02:03 . 2009-03-21 01:57 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-21 01:28 . 2009-03-14 01:40 -------- d-----w c:\program files\QuickTime
2009-03-19 20:54 . 2009-03-19 20:54 -------- d-----w c:\program files\KellySoftware
2009-03-19 01:18 . 2009-03-19 00:00 -------- d-----w c:\program files\MyBot
2009-03-18 23:57 . 2009-03-18 23:56 -------- d-----w c:\program files\Buddy Icon Maker
2009-03-18 13:17 . 2009-03-18 13:17 231424 ----a-w C:\WhiteCap_JMC.dll
2009-03-18 06:11 . 2009-03-13 02:12 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-16 23:42 . 2009-03-16 23:42 0 ----a-w c:\windows\nsreg.dat
2009-03-16 09:36 . 2009-03-16 09:18 103509 ----a-w c:\windows\hpoins04.dat
2009-03-16 09:36 . 2009-03-16 09:36 -------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-03-16 09:36 . 2006-07-11 05:39 -------- d-----w c:\program files\Hewlett-Packard
2009-03-16 09:34 . 2006-07-11 05:56 -------- d-----w c:\program files\Hp
2009-03-15 00:30 . 2009-03-15 00:30 98304 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-14 23:55 . 2009-03-14 23:55 -------- d-----w c:\program files\Rockstar Games
2009-03-14 04:09 . 2009-03-14 04:08 -------- d-----w c:\program files\Paint.NET
2009-03-14 01:40 . 2009-03-14 01:40 -------- d-----w c:\program files\Apple Software Update
2009-03-13 03:53 . 2009-03-13 03:53 0 ----a-w c:\windows\ativpsrm.bin
2009-03-13 02:09 . 2006-07-11 06:10 -------- d-----w c:\program files\Windows Media Connect
2009-03-13 02:01 . 2009-03-13 02:00 -------- d-----w c:\program files\AIM6
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\program files\Viewpoint
2009-03-13 02:00 . 2009-03-13 02:00 -------- d-----w c:\program files\Common Files\AOL
2009-03-12 22:29 . 2006-07-11 05:54 -------- d-----w c:\program files\ATI Technologies
2009-03-12 22:07 . 2009-03-12 21:32 -------- d-----w c:\program files\Microsoft Games
2009-03-12 21:40 . 2009-03-12 21:40 109208 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-03-12 21:39 . 2009-03-12 21:39 -------- d-----w c:\program files\MSBuild
2009-03-12 21:39 . 2009-03-12 21:39 -------- d-----w c:\program files\Reference Assemblies
2009-03-12 21:34 . 2009-03-12 21:34 -------- d-----w c:\program files\MSXML 6.0
2009-03-12 21:19 . 2009-03-12 21:19 -------- d-----w c:\program files\RADVideo
2009-03-12 21:19 . 2009-03-12 21:19 -------- d-----w c:\program files\Opera
2009-03-09 12:19 . 2009-03-16 22:56 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-10 07:46 . 2009-02-10 07:46 3013120 ----a-w c:\windows\Matrix_ks.SCR
2009-02-09 10:19 . 2006-02-28 12:00 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-04 05:03 . 2009-02-04 05:03 290816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-04 04:56 . 2009-02-04 04:56 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-04 04:44 . 2009-02-04 04:44 155648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-04 04:13 . 2009-02-04 04:13 887724 ----a-w c:\windows\system32\ativva6x.dat
2009-02-04 04:13 . 2009-02-04 04:13 3107788 ----a-w c:\windows\system32\ativva5x.dat
2009-02-04 04:05 . 2009-03-12 22:17 593920 ------w c:\windows\system32\ati2sgag.exe
2009-02-04 03:58 . 2009-02-04 03:58 49664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-04 03:53 . 2009-02-04 03:53 122880 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-04 02:43 . 2009-02-04 02:43 45056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-04 02:42 . 2009-02-04 02:42 45056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-04 02:40 . 2009-02-04 02:40 3244032 ----a-w c:\windows\system32\aticaldd.dll
2009-01-11 20:08 . 2009-01-11 20:08 71680 --sha-w c:\windows\system32\watekaho.dll.vir
.
((((((((((((((((((((((((((((( SnapShot_2009-04-28_01.26.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-29 00:04 . 2009-04-29 00:04 16384 c:\windows\temp\Perflib_Perfdata_1c4.dat
- 2009-03-13 03:33 . 2009-03-13 03:33 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2006-12-02 05:54 . 2006-12-02 05:54 1175552 c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_5490cd9f\msvcr80d.dll
+ 2006-12-02 05:54 . 2006-12-02 05:54 1036288 c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_5490cd9f\msvcp80d.dll
+ 2006-12-02 05:54 . 2006-12-02 05:54 1015808 c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_5490cd9f\msvcm80d.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-03-13 03:33 . 2009-03-13 03:33 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-28 04:34 . 2009-04-28 04:34 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4c39ece2-e0cf-4110-affc-c119de4ce517}]
c:\windows\system32\duputiva.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2BA40A2-74F3-42BD-F434-2604812C8954}]
c:\windows\system32\hsf73ikmdf3f.dll [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
c:\documents and settings\Student\Start Menu\Programs\Startup\
ImpulseNow.lnk - c:\program files\Stardock\Impulse\Now\ImpulseNow.exe [2009-4-7 323584]
Stardock ObjectDock.lnk - c:\program files\Stardock\Object Desktop\ObjectDock\ObjectDock.exe [2009-4-15 3446512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2007-5-9 184320]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableChangePassword"= 1 (0x1)
"DisableLockWorkstation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
"NoNetConnectDisconnect"= 1 (0x1)
"NoManageMyComputerVerb"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoStartMenuNetworkPlaces"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoThemesTab"= 1 (0x1)
"NoPropertiesRecycleBin"= 1 (0x1)
"NoFolderOptions"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{B2BA40A2-74F3-42BD-F434-2604812C8954}"= "c:\windows\system32\hsf73ikmdf3f.dll" [BU]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\zesiyaza.dll" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zesiyaza.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 06:34 24576 ----a-w c:\program files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli mshpoce.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Student\\Desktop\\Black & White\\Black and White\\runblack.exe"=
"c:\\Program Files\\Internet Explorer\\iexplore.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Documents and Settings\\Student\\Application Data\\Sp4rkMod\\armorsurf.exe"=
"c:\\Program Files\\Sony\\Media Manager for PSP\\MediaManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Quake2\\QUAKE2.EXE"=
"c:\\Program Files\\Havok\\Havok Behavior\\bin\\Release\\HBT.exe"=
"c:\\Documents and Settings\\Student\\Desktop\\New Folder\\RedFaction.exe"=
"c:\\Documents and Settings\\Student\\Desktop\\New Folder\\rf.exe"=
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-04-22 110992]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-04-22 24336]
S2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\TmXPFlt.sys [2008-11-27 205328]
S2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\TmPreFlt.sys [2008-11-27 36368]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2005-10-21 36352]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1003ad07-1bb1-11de-949c-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - f:\resycled\ntldr.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4191f182-22ea-11de-94a3-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - f:\resycled\ntldr.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ae2a78f-10f2-11de-9491-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - f:\resycled\ntldr.com g:
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://schools.connectionsacademy.com/
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aim.com\www
Trusted Zone: aol.com\iknowthat.school
Trusted Zone: aolatschool.com\www
Trusted Zone: atwola.com\ar
Trusted Zone: atwola.com\
www.ar
Trusted Zone: brainpop.com\www
Trusted Zone: connectionsacademy.com\schools
Trusted Zone: D
Trusted Zone: edgate.com\www
Trusted Zone: letsgolearn.com\www
Trusted Zone: msnbc.com
Trusted Zone: passport.net\login
Trusted Zone: schoolnotes.com
Trusted Zone: teacherweb.com
Trusted Zone: worldbookonline.com\www
FF - ProfilePath - c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\qhfqqwfy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.isotope244.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-28 14:06
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????,?@? ???0k??????R?@?????,?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1787410411-2529828033-874725645-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_USERS\S-1-5-21-1787410411-2529828033-874725645-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8AC8B27C-6EA8-21A2-D08F-827F395DFF83}*]
"jaendkkcgdhfgkbhnogg"=hex:66,61,6e,68,6e,62,69,70,6c,6b,62,69,00,2f
"pamnpofglimiajhlfhebfnnjfohndgka"=hex:65,61,6e,68,6d,62,6e,70,6a,6b,00,69
"haendkkcgdhfgkbh"=hex:6e,62,6e,68,70,62,6a,62,61,63,61,61,61,63,62,63,6b,64,
69,6a,6e,61,65,6d,6d,66,61,6e,70,67,68,66,69,61,6e,62,69,6d,62,6b,61,70,69,\
[HKEY_USERS\S-1-5-21-1787410411-2529828033-874725645-1007\Software\Sony Creative Software\M*e*d*i*a* *M*a*n*a*g*e*r* *f*o*r* *P*S*P*"!\3.0]
"FRT"="nlEdzWfcJFrUmEmxsa9oCPawQylv7p/C/eSuI8cv4Dkno/0/Xy8YDA=="
"PLCK"="egG6NwC6vxDNFG1a3atYpRoj9w27s2mq"
"Percents"="0 0.1465 0.3362 0.6169 0.8131 0.8961 0.9105 "
"Increment"=".003003"
"PHSH"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\AlienGUIse\fastload.dll
- - - - - - - > 'lsass.exe'(988)
c:\windows\system32\guard32.dll
c:\windows\mshpoce.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\OfficeScan NT\ntrtscan.exe
c:\program files\OfficeScan NT\tmlisten.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Analog Devices\Core\smax4pnp.exe
c:\program files\Hp\HP Software Update\hpwuSchd2.exe
c:\windows\system32\DLA\DLACTRLW.EXE
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
c:\program files\OfficeScan NT\PccNTMon.exe
c:\program files\OfficeScan NT\RAUAgent.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Java\jre6\bin\jusched.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\OfficeScan NT\OfcDog.exe
c:\program files\OfficeScan NT\PccNTUpd.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-04-28 14:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-28 21:11
ComboFix2.txt 2009-04-28 01:30
ComboFix3.txt 2009-04-16 22:39
ComboFix4.txt 2009-04-16 21:21
ComboFix5.txt 2009-04-28 23:58
Pre-Run: 19,307,249,664 bytes free
Post-Run: 19,306,303,488 bytes free
434 --- E O F --- 2009-04-02 10:01
Mbam:
Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 2
4/28/2009 3:27:11 PM
mbam-log-2009-04-28 (15-27-02).txt
Scan type: Full Scan (C:\|)
Objects scanned: 163837
Time elapsed: 52 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b2ba40a2-74f3-42bd-f434-2604812c8954} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fci (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Seekapp (Adware.Seekapp) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Seekapp Service (Adware.Seekapp) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: mshpoce.dll -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\mshpoce.dll (Trojan.Vundo.H) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hsf73ikmdf3f.dll.vir (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP63\A0019068.exe (Adware.SeekApp) -> No action taken.
C:\WINDOWS\system32\cssdll32.dll.vir (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\watekaho.dll.vir (Trojan.Vundo) -> No action taken.
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:44 PM, on 4/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\OfficeScan NT\RAUAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\OfficeScan NT\ofcdog.exe
C:\Program Files\OfficeScan NT\pccntupd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://schools.connectionsacademy.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [RemoteAgent] C:\Program Files\OfficeScan NT\RAUAgent.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ImpulseNow.lnk = C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\Object Desktop\ObjectDock\ObjectDock.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://schools.connectionsacademy.com
O15 - Trusted Zone:
www.aim.com
O15 - Trusted Zone:
www.aolatschool.com
O15 - Trusted Zone:
www.brainpop.com
O15 - Trusted Zone:
http://schools.connectionsacademy.com
O15 - Trusted Zone:
www.edgate.com
O15 - Trusted Zone:
www.letsgolearn.com
O15 - Trusted Zone: login.passport.net
O15 - Trusted Zone:
http://*.schoolnotes.com
O15 - Trusted Zone:
http://*.teacherweb.com
O15 - Trusted Zone:
www.worldbookonline.com
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) -
http://10.1.0.17:8180/officescan/ClientInstall/WinNTChk.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupIniCtrl Class) -
http://10.1.0.17:8180/officescan/clientinstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
http://10.1.0.17:8180/officescan/clientinstall/setup.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.8.110.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) -
http://10.1.0.17:8180/officescan/clientinstall/RemoveCtrl.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 9422 bytes