PDA

View Full Version : Hekbots malware removal



hekbot-99
2009-02-24, 10:38
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:28 AM, on 24-Feb-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: (no name) - {49B95C66-B248-4232-81C6-BE716F78707C} - c:\windows\system32\fzqfeji.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AntiSpyware Pro Site Blocker Button - {66B643BE-5E94-4569-B93E-CE2636848AC8} - C:\Program Files\AntiSpyware Pro\ASProSB.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - .DEFAULT Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1234281315156
O20 - AppInit_DLLs: C:\WINDOWS\System32\dfrgres32.dll
O20 - Winlogon Notify: a092e28e530 - C:\WINDOWS\System32\dfrgres32.dll (file missing)
O20 - Winlogon Notify: qwrnibgi - C:\WINDOWS\SYSTEM32\fzqfeji.dll
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

--
End of file - 7885 bytes

pskelley
2009-02-25, 22:51
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

Make sure you read and follow the directions, anything else will slow the process and waste both of our time. I suggest you keep this computer offline except when troubleshooting, the junk may download more. If you have any tool I use, delete it and download it new from the link I provide. Read and follow the directions carefully, the tools will not work unless you do.
The junk can be tough to remove, so do not expect fast or easy.

For your benefit, the instructions are pinned (sticky) to the top of the Malware Removal forum, please read and be sure you have followed those instructions. I have also posted the "Before you Post" instructions at the top of this thread.

1) C:\Program Files\uTorrent <<< uninstall all p2p programs.
http://forums.spybot.info/showthread.php?t=282

If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.

2) Please DO NOT ENABLE Spybot S&D TeaTimer while we work together.

3) A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use

Download ComboFix from here:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


http://i24.photobucket.com/albums/c30/ken545/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://i24.photobucket.com/albums/c30/ken545/whatnext.jpg

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Tutorial if needed
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

4) Post also an uninstall list: Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.
(You may edit out Microsoft, Hotfixes, Security Update for Windows XP,
Update for Windows XP and Windows XP Hotfix to shorten the list)
Image: http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

Thanks

hekbot-99
2009-03-02, 12:34
ComboFix 09-03-01.01 - Hekmat A. Anwari 2009-03-02 12:45:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.947 [GMT 2:00]
Running from: c:\documents and settings\Hekmat A. Anwari\Desktop\ComboFix.exe
AV: Avanquest VirusScanner Pro *On-access scanning disabled* (Updated)
FW: Avanquest NetDefense Firewall *enabled*
* Created a new restore point
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Hekmat A. Anwari\Application Data\020000003188c2c7530C.manifest
c:\documents and settings\Hekmat A. Anwari\Application Data\020000003188c2c7530O.manifest
c:\documents and settings\Hekmat A. Anwari\Application Data\020000003188c2c7530P.manifest
c:\documents and settings\Hekmat A. Anwari\Application Data\020000003188c2c7530S.manifest
c:\documents and settings\Hekmat A. Anwari\Application Data\inst.exe
c:\documents and settings\Hekmat Anwari\Application Data\inst.exe
c:\program files\AntiSpyware Pro
c:\program files\AntiSpyware Pro\ASProSB.dll
c:\windows\GnuHashes.ini
c:\windows\system32\api.dat
c:\windows\system32\bwuowtuusa.dll
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\Pncrt.dll
c:\windows\system32\systeminfo3.dll
c:\windows\system32\zndugepqaxine.dll

.
((((((((((((((((((((((((( Files Created from 2009-02-02 to 2009-03-02 )))))))))))))))))))))))))))))))
.

2009-02-27 15:45 . 2009-02-27 15:46 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Canon
2009-02-26 08:06 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-25 11:46 . 2009-02-25 11:51 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-24 16:42 . 2009-02-24 16:42 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\dwhelper
2009-02-24 13:30 . 2009-02-24 13:30 <DIR> d--hs---- c:\documents and settings\LocalService.NT AUTHORITY\PrivacIE
2009-02-24 13:30 . 2009-02-24 13:30 <DIR> d--hs---- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2009-02-24 11:27 . 2009-02-24 11:27 <DIR> d-------- c:\program files\Trend Micro
2009-02-24 11:23 . 2009-02-24 11:23 <DIR> d-------- c:\program files\ERUNT
2009-02-23 13:18 . 2009-02-23 13:18 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Malwarebytes
2009-02-23 13:18 . 2009-02-23 13:18 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-02-21 12:18 . 2009-02-21 12:18 <DIR> d-------- c:\program files\CDBurnerXP
2009-02-21 12:18 . 2009-02-21 12:18 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Canneverbe_Limited
2009-02-20 17:50 . 2009-02-20 17:50 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\CD-LabelPrint
2009-02-20 17:47 . 2009-02-20 17:47 <DIR> d-------- C:\e38cf388653a7303389cbe74
2009-02-20 17:47 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-20 17:47 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-20 17:47 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-20 17:47 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-20 17:47 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-20 17:47 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-20 17:47 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-20 17:45 . 2009-02-20 17:45 <DIR> d-------- c:\program files\MSXML 6.0
2009-02-20 16:49 . 2009-02-20 16:49 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Safer Networking
2009-02-20 09:14 . 2009-02-27 09:01 633 --a------ c:\windows\wininit.ini
2009-02-20 08:47 . 2009-02-20 08:47 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-20 08:47 . 2009-02-20 09:19 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-02-19 16:07 . 2009-02-19 16:07 <DIR> d-------- C:\88524cff5c53808360
2009-02-17 15:19 . 2009-03-02 11:03 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-02-17 15:11 . 2009-02-17 15:11 <DIR> d-------- c:\program files\MagicDisc
2009-02-17 15:11 . 2008-07-13 21:10 101,120 --a------ c:\windows\system32\drivers\mcdbus.sys
2009-02-17 14:42 . 2009-02-17 14:42 <DIR> d-------- C:\Inetpub
2009-02-17 13:46 . 2009-02-17 13:46 <DIR> d-------- c:\program files\MagicISO
2009-02-16 11:34 . 2009-02-24 08:48 <DIR> d-------- c:\program files\DivX
2009-02-16 08:21 . 2009-02-16 09:44 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\VCOMAntiSpam
2009-02-14 10:51 . 2009-02-14 10:51 <DIR> d-------- c:\program files\SlySoft
2009-02-14 08:51 . 2009-02-14 08:51 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\DivX
2009-02-13 13:37 . 2009-02-13 13:37 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\vsosdk
2009-02-13 10:01 . 2009-02-13 10:03 111,132 --a------ c:\windows\HPBMP.$CH
2009-02-13 09:53 . 1998-08-19 13:49 281,088 --a------ c:\windows\system32\hpp2100c.exe
2009-02-13 09:53 . 1998-08-25 18:36 68,096 --a------ c:\windows\system32\hpplm.dll
2009-02-13 09:53 . 1997-09-07 12:00 20,523 --a------ c:\windows\system32\HPBPIODC.HLP
2009-02-13 09:53 . 1998-02-03 15:31 6,821 --a------ c:\windows\system32\testpage.hlp
2009-02-13 09:49 . 2009-02-13 09:49 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\WINDOWS
2009-02-13 09:20 . 2009-02-13 10:01 1,969,317 --a------ c:\windows\HPFNT.$CH
2009-02-13 09:20 . 2009-02-13 10:03 4,234 --a------ c:\windows\FONTSMRT.INI
2009-02-12 12:48 . 2009-02-12 13:26 <DIR> d-------- c:\program files\CloneDVD
2009-02-12 12:48 . 2009-02-12 12:48 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\DVDXStudio
2009-02-12 11:06 . 2009-02-12 11:06 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Elaborate Bytes
2009-02-12 08:25 . 2006-02-28 14:00 221,184 --a------ c:\windows\system32\wmpns.dll
2009-02-11 15:34 . 2009-02-11 15:34 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Macrovision
2009-02-11 14:48 . 2009-02-11 14:48 0 --a------ c:\windows\nsreg.dat
2009-02-11 13:16 . 2009-02-11 13:16 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\ArcSoft
2009-02-11 13:06 . 2009-02-11 15:10 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\ArcSoft
2009-02-11 12:38 . 2009-02-11 12:38 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\ScanSoft
2009-02-11 12:38 . 2009-02-11 12:38 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\ScanSoft
2009-02-11 12:38 . 2009-02-11 12:38 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\InstallShield
2009-02-11 12:38 . 2009-02-11 12:38 416 --a------ c:\windows\MAXLINK.INI
2009-02-11 12:36 . 2009-02-11 13:16 <DIR> d-------- c:\program files\ArcSoft
2009-02-11 12:36 . 1995-07-31 13:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2009-02-11 12:33 . 2003-09-18 14:32 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-02-11 12:33 . 2003-09-18 14:32 499,712 --a------ c:\windows\system32\msvcp71.dll
2009-02-11 12:33 . 2003-09-18 14:32 348,160 --a------ c:\windows\system32\msvcr71.dll
2009-02-11 12:05 . 2009-02-11 12:05 <DIR> d--h----- c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ
2009-02-11 12:04 . 2006-09-12 22:00 197,632 --a------ c:\windows\system32\CNMLM87.DLL
2009-02-11 12:04 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-02-11 12:04 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2009-02-11 12:03 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-11 12:03 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-02-11 10:22 . 2009-02-11 10:22 <DIR> d-------- c:\windows\Sun
2009-02-11 02:56 . 2009-02-11 02:56 69,170 --a------ c:\windows\system32\bwuowtuusa.dll-uninst.exe
2009-02-11 02:27 . 2009-02-11 02:27 <DIR> d--hs---- c:\windows\system32\LocalService32
2009-02-11 02:27 . 2009-02-11 02:27 135,168 --a------ c:\windows\system32\dfrgres32.dll.1
2009-02-11 02:20 . 2009-03-02 10:09 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\dvdcss
2009-02-11 00:14 . 2009-02-11 10:33 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-11 00:00 . 2009-02-12 12:19 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\SlySoft
2009-02-10 23:44 . 2009-03-02 10:08 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Vso
2009-02-10 23:44 . 2009-02-10 23:44 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2009-02-10 23:44 . 2009-02-10 23:44 47,360 --a------ c:\documents and settings\Hekmat A. Anwari\Application Data\pcouffin.sys
2009-02-10 23:43 . 2006-05-11 19:21 626,688 --a------ c:\windows\system32\vp7vfw.dll
2009-02-10 23:43 . 2006-09-29 12:24 217,127 --a------ c:\windows\system32\drv43260.dll
2009-02-10 23:43 . 2006-09-29 12:25 208,935 --a------ c:\windows\system32\drv33260.dll
2009-02-10 23:43 . 2006-09-29 12:26 176,165 --a------ c:\windows\system32\drv23260.dll
2009-02-10 23:43 . 2002-12-10 02:20 102,439 --a------ c:\windows\system32\sipr3260.dll
2009-02-10 23:43 . 2007-03-18 20:37 65,602 --a------ c:\windows\system32\cook3260.dll
2009-02-10 23:29 . 2009-02-27 09:07 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\FrostWire
2009-02-10 23:27 . 2009-02-11 10:33 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-10 23:25 . 2009-02-10 23:25 <DIR> d-------- c:\program files\Common Files\Java
2009-02-10 23:20 . 2009-02-21 12:26 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\vlc
2009-02-10 23:04 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\uTorrent
2009-02-10 22:56 . 2009-02-10 22:56 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\nView_Profiles
2009-02-10 22:50 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2009-02-10 22:32 . 2009-02-10 22:32 1,071 --a------ c:\windows\AWMODEM.INF
2009-02-10 21:33 . 2004-08-04 00:56 363,520 --a------ c:\windows\system32\PsisDecd.dll
2009-02-10 21:33 . 2004-08-04 00:56 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-02-10 21:33 . 2004-08-04 00:56 56,832 --a------ c:\windows\system32\MSDvbNP.ax
2009-02-10 21:33 . 2004-08-04 00:56 56,832 --a--c--- c:\windows\system32\dllcache\msdvbnp.ax
2009-02-10 21:33 . 2004-08-04 00:56 33,280 --a------ c:\windows\system32\PsisRndr.ax
2009-02-10 21:33 . 2004-08-04 00:56 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-02-10 21:33 . 2004-08-04 00:56 18,432 --a--c--- c:\windows\system32\dllcache\bdaplgin.ax
2009-02-10 21:33 . 2004-08-04 00:56 18,432 --a------ c:\windows\system32\BdaPlgIn.ax
2009-02-10 21:33 . 2004-08-03 23:10 15,360 --a------ c:\windows\system32\drivers\MPE.sys
2009-02-10 21:33 . 2004-08-03 23:10 15,360 --a--c--- c:\windows\system32\dllcache\mpe.sys
2009-02-10 21:33 . 2004-08-03 23:10 11,776 --a------ c:\windows\system32\drivers\BdaSup.sys
2009-02-10 21:33 . 2004-08-03 23:10 11,776 --a--c--- c:\windows\system32\dllcache\bdasup.sys
2009-02-10 21:26 . 2005-01-31 16:30 16,176 --------- c:\windows\system32\drivers\NVXBAR.SYS
2009-02-10 21:25 . 2009-02-10 21:25 <DIR> d-------- C:\NVIDIA
2009-02-10 21:25 . 2005-01-31 16:30 141,246 --------- c:\windows\system32\drivers\NVCAP.SYS
2009-02-10 21:25 . 2005-01-31 16:30 29,696 --------- c:\windows\system32\FILTER.AX
2009-02-10 21:21 . 2009-02-10 21:21 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Windows Search
2009-02-10 21:02 . 2009-02-10 21:02 <DIR> d-------- c:\program files\Windows Desktop Search
2009-02-10 21:02 . 2009-02-10 21:02 <DIR> d-------- c:\documents and settings\Hekmat A. Anwari\Application Data\Windows Desktop Search
2009-02-10 20:04 . 2009-02-27 09:07 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-10 19:30 . 2009-02-10 19:30 664 --a------ c:\windows\system32\d3d9caps.dat
2009-02-10 19:29 . 2006-02-28 14:00 31,744 --a--c--- c:\windows\system32\dllcache\fxsroute.dll
2009-02-10 19:29 . 2006-02-28 14:00 15,872 --a--c--- c:\windows\system32\dllcache\smierrsm.dll
2009-02-10 19:29 . 2006-02-28 14:00 11,264 --a--c--- c:\windows\system32\dllcache\fxssend.exe
2009-02-10 19:29 . 2006-02-28 14:00 10,240 --a--c--- c:\windows\system32\dllcache\snmpstup.dll
2009-02-10 19:29 . 2006-02-28 14:00 5,632 --a--c--- c:\windows\system32\dllcache\smimsgif.dll
2009-02-10 19:29 . 2006-02-28 14:00 5,632 --a--c--- c:\windows\system32\dllcache\smierrsy.dll
2009-02-10 19:29 . 2009-02-19 08:45 57 --a------ c:\windows\system32\mapisvc.inf
2009-02-10 19:27 . 2008-09-17 23:55 453,152 --a------ c:\windows\system32\nvuninst.exe
2009-02-10 19:27 . 2008-09-17 23:55 453,152 --a------ c:\windows\system32\nvudisp.exe
2009-02-10 19:27 . 2009-03-02 08:03 201,044 --a------ c:\windows\system32\nvapps.xml
2009-02-10 19:27 . 2008-09-17 23:55 18,394 --a------ c:\windows\system32\nvdisp.nvu
2009-02-10 19:26 . 2009-02-10 19:26 <DIR> d-------- c:\program files\CONEXANT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 05:59 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-25 09:46 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-23 11:12 --------- d-----w c:\program files\Windows Defender
2009-02-17 13:22 --------- d-----w c:\program files\MSBuild
2009-02-12 05:41 --------- d-----w c:\program files\Google
2009-02-11 13:30 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\uTorrent
2009-02-11 10:39 --------- d-----w c:\program files\Canon
2009-02-11 08:32 --------- d-----w c:\program files\Java
2009-02-10 19:46 --------- d-----w c:\program files\Microsoft IntelliPoint
2009-02-10 19:45 --------- d-----w c:\program files\Microsoft IntelliType Pro
2009-02-10 17:27 --------- d-----w c:\program files\Common Files\logishrd
2009-02-10 12:54 --------- d-----w c:\program files\Common Files\Adobe
2009-02-10 11:48 --------- d-----w c:\program files\Realtek AC97
2009-02-05 14:04 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\VCOMAntiSpam
2009-02-05 12:12 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\Any Video Converter
2009-02-05 07:48 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\Vso
2009-02-05 07:30 47,360 ----a-w c:\documents and settings\Hekmat Anwari\Application Data\pcouffin.sys
2009-02-04 18:35 81,920 ----a-w c:\documents and settings\Hekmat Anwari\Application Data\ezpinst.exe
2009-02-02 14:02 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\dvdcss
2009-01-30 15:02 --------- d-----w c:\program files\Games
2009-01-29 23:02 103,488 ----a-w c:\windows\system32\drivers\AnyDVD.sys
2009-01-29 22:57 23,976 ----a-w c:\windows\system32\drivers\ElbyCDIO.sys
2009-01-29 21:54 89,256 ----a-w c:\windows\system32\ElbyCDIO.dll
2009-01-24 05:59 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\ArcSoft
2009-01-23 15:48 --------- d-----w c:\program files\Common Files\ArcSoft
2009-01-23 06:20 --------- d-----w c:\documents and settings\Hekmat Anwari\Application Data\vlc
2009-01-15 00:05 911,872 ----a-w c:\windows\system32\wininet.dll
2009-01-15 00:05 43,008 ----a-w c:\windows\system32\licmgr10.dll
2009-01-15 00:04 18,944 ----a-w c:\windows\system32\corpol.dll
2009-01-15 00:03 72,704 ----a-w c:\windows\system32\admparse.dll
2009-01-15 00:03 71,680 ----a-w c:\windows\system32\iesetup.dll
2009-01-15 00:03 420,352 ----a-w c:\windows\system32\vbscript.dll
2009-01-15 00:01 34,304 ----a-w c:\windows\system32\imgutil.dll
2009-01-15 00:00 48,128 ----a-w c:\windows\system32\mshtmler.dll
2009-01-15 00:00 45,568 ----a-w c:\windows\system32\mshta.exe
2009-01-14 23:50 156,160 ----a-w c:\windows\system32\msls31.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49B95C66-B248-4232-81C6-BE716F78707C}]
2006-02-28 14:00 106496 --a------ c:\windows\system32\fzqfeji.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2009-02-14 2542528]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 196608]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-06-10 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-11 148888]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"VirusScannerPro"="c:\progra~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2008-04-14 173312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"SoundMan"="SOUNDMAN.EXE" [2005-12-23 c:\windows\soundman.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 c:\windows\system32\narrator.exe]

c:\documents and settings\Hekmat A. Anwari\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-02-17 565248]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qwrnibgi]
2006-02-28 14:00 106496 c:\windows\system32\fzqfeji.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 votinvyh;votinvyh;c:\windows\system32\drivers\votinvyh.sys [2006-02-28 23424]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-02-10 13696]
R2 tmpreflt;tmpreflt;c:\progra~1\AVANQU~1\SYSTEM~1\tmpreflt.sys [2008-04-07 32528]
R3 KFilter;KFilter;c:\progra~1\AVANQU~1\SYSTEM~1\KFilter.sys [2008-04-07 53329]
R3 LVHybrid;LVHybrid service;c:\windows\system32\drivers\LVHybrid.sys [2007-04-03 795776]
R3 MailScan;MailScan;c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [2008-04-14 20464]
R3 TFilter;TFilter;c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [2008-04-07 20225]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wemxiaao

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-02-28 c:\windows\Tasks\At1.job
- c:\windows\system32\fzqfeji.dll [2006-02-28 14:00]
.
- - - - ORPHANS REMOVED - - - -

BHO-{66B643BE-5E94-4569-B93E-CE2636848AC8} - c:\program files\AntiSpyware Pro\ASProSB.dll
HKLM-RunOnce-<NO NAME> - (no file)


.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 12:47:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,70,17,d2,29,13,e7,4d,b5,c6,03,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,70,17,d2,29,13,e7,4d,b5,c6,03,\
.
Completion time: 2009-03-02 12:48:53
ComboFix-quarantined-files.txt 2009-03-02 10:48:51

Pre-Run: 77,238,894,592 bytes free
Post-Run: 77,272,449,024 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin

292 --- E O F --- 2009-02-26 07:00:25

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:15:36 PM, on 02-Mar-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\WINDOWS\system32\defrag.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: (no name) - {49B95C66-B248-4232-81C6-BE716F78707C} - c:\windows\system32\fzqfeji.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {66B643BE-5E94-4569-B93E-CE2636848AC8} - (no file)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA77] command.com /c del "C:\WINDOWS\system32\nwhcynqw.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9344] cmd.exe /c del "C:\WINDOWS\system32\nwhcynqw.dll"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB9943] command.com /c del "C:\WINDOWS\system32\nwhcynqw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5493] cmd.exe /c del "C:\WINDOWS\system32\nwhcynqw.dll"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - .DEFAULT Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: qwrnibgi - C:\WINDOWS\SYSTEM32\fzqfeji.dll
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

--
End of file - 7207 bytes

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Acrobat 5.0
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
AnyDVD
ArcSoft PhotoStudio 5.5
Canon MP Navigator 3.0
Canon MP600
Canon Utilities Easy-PhotoPrint
CDBurnerXP
CD-LabelPrint
CloneDVD 4.1.0.23
ConvertXtoDVD 3.4.7.121
Easy-WebPrint
ERUNT 1.1j
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
HP LaserJet 2100 Software
Java(TM) 6 Update 12
Java(TM) 6 Update 7
Magic ISO Maker v5.5 (build 0273)
MagicDisc 2.7.101
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 6 Service Pack 2 (KB954459)
NVIDIA Drivers
NVIDIA WDM Drivers
PCI SoftV92 Modem
QSuite Ver2.1
Realtek AC'97 Audio
REALTEK Gigabit and Fast Ethernet NIC Driver
Runtime 8.0 Libraries
ScanSoft OmniPage SE 4.0
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB958439)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB958437)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960715)
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
SystemSuite 8 Professional
T-Utility BIOS Live Update
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb959634)
Update for Windows Internet Explorer 8 (KB961813)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VLC media player 0.9.8a
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8 Release Candidate 1
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Search 4.0
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781