"Owner" - 2007-05-08 13:18:53 Service Pack 2
ComboFix 07-05.07.3.V - Running from: "C:\Program Files\Mozilla Firefox\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ltydpuci.dll
C:\WINDOWS\system32\icupdytl.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\1.txt
C:\WINDOWS\system32\2.txt
C:\DOCUME~1\Owner\APPLIC~1\Microsoft\classes.dat
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\WINDOWS\system32\imas3r
C:\WINDOWS\services.dll
C:\WINDOWS\system32.dll
C:\Documents and Settings\All Users.\documents\settings
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NWSAPAGENT
-------\NwSapAgent
((((((((((((((((((((((((((((((( Files Created from 2007-04-08 to 2007-05-08 ))))))))))))))))))))))))))))))))))
2007-05-06 16:44 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-05-05 12:51 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-05-05 11:12 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-03 21:29 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-05-03 21:29 0 --a------ C:\WINDOWS\ORUN32.EXE
2007-05-03 21:28 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-05-03 21:19 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-05-03 21:19 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\SUPERAntiSpyware.com
2007-05-03 21:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-03 21:18 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-05-03 20:34 609,653 ---hs---- C:\WINDOWS\system32\cccdd.ini2
2007-04-29 13:05 <DIR> d----c--- C:\9041e20f7b9138e20c
2007-04-29 11:31 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Nokia Multimedia Player
2007-04-29 11:13 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2007-04-29 11:13 <DIR> d-------- C:\Program Files\Common Files\Nokia
2007-04-29 11:06 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-04-29 11:04 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-04-29 11:04 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-04-29 11:04 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-04-29 11:04 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-04-29 11:04 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-04-29 11:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
2007-04-27 21:24 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\AdobeAUM
2007-04-25 22:44 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-04-23 07:22 609,801 ---hs---- C:\WINDOWS\system32\cccdd.bak2
2007-04-21 00:32 <DIR> d--hs---- C:\DOCUME~1\Owner\Phone Browser
2007-04-20 21:13 1,040,384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-04-20 21:08 196,608 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-04-19 21:46 7,206,509 --a------ C:\DOCUME~1\Owner\ie_updater.exe
2007-04-14 16:56 <DIR> d-------- C:\Program Files\DIFX
2007-04-14 16:56 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\PC Suite
2007-04-14 16:56 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Nokia
2007-04-14 16:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
2007-04-14 16:54 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-04-14 16:54 <DIR> d-------- C:\Program Files\Nokia
2007-04-14 16:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-08 03:25:46 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\uTorrent
2007-05-06 07:48:27 -------- d-----w C:\Program Files\MSN Messenger
2007-05-06 07:38:06 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
2007-05-03 11:29:16 -------- d-----w C:\Program Files\PC-Doctor for Windows
2007-05-03 11:19:07 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\SUPERAntiSpyware.com
2007-04-29 02:22:46 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\Nokia
2007-04-29 01:31:29 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\Nokia Multimedia Player
2007-04-27 11:24:01 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\AdobeAUM
2007-04-20 14:19:15 -------- d-----w C:\Program Files\SpywareBlaster
2007-04-14 06:56:11 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\PC Suite
2007-03-28 11:18:56 -------- d-----w C:\Program Files\iTunes
2007-03-28 11:18:46 -------- d-----w C:\Program Files\iPod
2007-03-28 11:17:42 -------- d-----w C:\Program Files\QuickTime
2007-03-28 11:16:04 -------- d-----w C:\Program Files\Apple Software Update
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-16 03:37:09 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1.\AdobeUM
2007-03-12 02:03:55 -------- d-----w C:\Program Files\Momento
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-08 07:51:24 19,959 ----a-w C:\WINDOWS\tmp.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"PCSuiteTrayApplication"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -startup"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"Nokia.PCSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe photo downloader
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\agrsmmsg
AGRSMMSG.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alcxmonitor
ALCXMNTR.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmonitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crvc32.exe
C:\WINDOWS\system32\crvc32.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
C:\WINDOWS\System32\CTFMON.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc6_check
C:\Program Files\SystemDoctor 2006 Free\dcmon.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hbtools
C:\Program Files\HbTools\Bin\4.7.7.0\HbtOEAddOn.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hp component manager
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hp software update
"C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hphmon05
C:\WINDOWS\System32\hphmon05.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hphupd05
c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\imjpmig8.1
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ituneshelper
"C:\Program Files\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagentexe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcupdateexe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcyx.exe
C:\WINDOWS\system32\mfcyx.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmsgs
"C:\Program Files\Messenger\msmsgs.exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mspy2002
C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netrz.exe
C:\WINDOWS\netrz.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pas_check
C:\Program Files\SystemDoctor 2006 Free\pasmon.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pcsuitetrayapplication
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phime2002a
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phime2002async
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\printdrive
rundll32.exe "C:\WINDOWS\system32\llfonrvm.dll",setvm
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\psguard spyware remover
C:\Program Files\PSGuard\PSGuard.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
"C:\Program Files\QuickTime\qttask.exe" -atboottime
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\recguard
C:\WINDOWS\SMINST\RECGUARD.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\reminder
"C:\Windows\Creator\Remind_XP.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runonce1upd
"C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunkist2k
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\systemdoctor 2006 free
C:\Program Files\SystemDoctor 2006 Free\sd2006.exe -scan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\usdr6cw
C:\Program Files\SystemDoctor 2006 Free\USDR6cw.exe -c
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\weatherontray
C:\Program Files\HbTools\Bin\4.7.7.0\HbtWeatherOnTray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winampagent
C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=dword:00000003
"PavPrSrv"=dword:00000002
"iPod Service"=dword:00000003
"CWShredder Service"=dword:00000002
"Pml Driver HPZ12"=dword:00000003
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"AresChatServer"=dword:00000003
"ewido anti-spyware 4.0 guard"=dword:00000002
"ServiceLayer"=dword:00000003
"MsaSvc"=dword:00000002
"IDriverT"=dword:00000003
"NVSvc"=dword:00000002
"dmadmin"=dword:00000003
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HTTPFilter HTTPFilter\0\0
DcomLaunch DcomLaunch\0TermService\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\Info.exe folder.htt 480 480
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\McAfee.com Update Check (COMPUTIN-Owner).job
C:\WINDOWS\tasks\McAfee.com Update Check (YOUR-MXV0URM8HA-Owner).job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-08 13:28:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-08 13:32:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-08 13:32
Logfile of HijackThis v1.99.1
Scan saved at 1:35:01 PM, on 8/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\Antivirus\hj\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://qau10.hpwis.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitd...can8/oscan8.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe