[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader
"6999:TCP"= 6999:TCP:Blizzard Downloader
"8086:TCP"= 8086:TCP:World of Warcraft
"8087:TCP"= 8087:TCP:World of Warcraft
"9081:TCP"= 9081:TCP:World of Warcraft
"9090:TCP"= 9090:TCP:World of Warcraft
"9097:TCP"= 9097:TCP:World of Warcraft
"9100:TCP"= 9100:TCP:World of Warcraft
"6882:TCP"= 6882:TCP:Blizzard Downloader
"6883:TCP"= 6883:TCP:Blizzard Downloader
"6884:TCP"= 6884:TCP:Blizzard Downloader
"6885:TCP"= 6885:TCP:Blizzard Downloader
"6886:TCP"= 6886:TCP:Blizzard Downloader
"6887:TCP"= 6887:TCP:Blizzard Downloader
"6888:TCP"= 6888:TCP:Blizzard Downloader
"6889:TCP"= 6889:TCP:Blizzard Downloader
"6891:TCP"= 6891:TCP:Blizzard Downloader
"6892:TCP"= 6892:TCP:Blizzard Downloader
"6893:TCP"= 6893:TCP:Blizzard Downloader
"6894:TCP"= 6894:TCP:Blizzard Downloader
"6895:TCP"= 6895:TCP:Blizzard Downloader
"6890:TCP"= 6890:TCP:Blizzard Downloader
"6896:TCP"= 6896:TCP:Blizzard Downloader
"6897:TCP"= 6897:TCP:Blizzard Downloader
"6898:TCP"= 6898:TCP:Blizzard Downloader
"6899:TCP"= 6899:TCP:Blizzard Downloader
"6900:TCP"= 6900:TCP:Blizzard Downloader
"6901:TCP"= 6901:TCP:Blizzard Downloader
"6902:TCP"= 6902:TCP:Blizzard Downloader
"6903:TCP"= 6903:TCP:Blizzard Downloader
"6904:TCP"= 6904:TCP:Blizzard Downloader
"6905:TCP"= 6905:TCP:Blizzard Downloader
"6906:TCP"= 6906:TCP:Blizzard Downloader
"6907:TCP"= 6907:TCP:Blizzard Downloader
"6908:TCP"= 6908:TCP:Blizzard Downloader
"6909:TCP"= 6909:TCP:Blizzard Downloader
"6910:TCP"= 6910:TCP:Blizzard Downloader
"6911:TCP"= 6911:TCP:Blizzard Downloader
"6912:TCP"= 6912:TCP:Blizzard Downloader
"6913:TCP"= 6913:TCP:Blizzard Downloader
"6914:TCP"= 6914:TCP:Blizzard Downloader
"6915:TCP"= 6915:TCP:Blizzard Downloader
"6916:TCP"= 6916:TCP:Blizzard Downloader
"6917:TCP"= 6917:TCP:Blizzard Downloader
"6918:TCP"= 6918:TCP:Blizzard Downloader
"6919:TCP"= 6919:TCP:Blizzard Downloader
"6920:TCP"= 6920:TCP:Blizzard Downloader
"6921:TCP"= 6921:TCP:Blizzard Downloader
"6922:TCP"= 6922:TCP:Blizzard Downloader
"6923:TCP"= 6923:TCP:Blizzard Downloader
"6924:TCP"= 6924:TCP:Blizzard Downloader
"6925:TCP"= 6925:TCP:Blizzard Downloader
"6926:TCP"= 6926:TCP:Blizzard Downloader
"6927:TCP"= 6927:TCP:Blizzard Downloader
"6928:TCP"= 6928:TCP:Blizzard Downloader
"6929:TCP"= 6929:TCP:Blizzard Downloader
"6930:TCP"= 6930:TCP:Blizzard Downloader
"6931:TCP"= 6931:TCP:Blizzard Downloader
"6932:TCP"= 6932:TCP:Blizzard Downloader
"6933:TCP"= 6933:TCP:Blizzard Downloader
"6934:TCP"= 6934:TCP:Blizzard Downloader
"6935:TCP"= 6935:TCP:Blizzard Downloader
"6936:TCP"= 6936:TCP:Blizzard Downloader
"6937:TCP"= 6937:TCP:Blizzard Downloader
"6938:TCP"= 6938:TCP:Blizzard Downloader
"6939:TCP"= 6939:TCP:Blizzard Downloader
"6940:TCP"= 6940:TCP:Blizzard Downloader
"6941:TCP"= 6941:TCP:Blizzard Downloader
"6942:TCP"= 6942:TCP:Blizzard Downloader
"6943:TCP"= 6943:TCP:Blizzard Downloader
"6944:TCP"= 6944:TCP:Blizzard Downloader
"6945:TCP"= 6945:TCP:Blizzard Downloader
"6946:TCP"= 6946:TCP:Blizzard Downloader
"6947:TCP"= 6947:TCP:Blizzard Downloader
"6948:TCP"= 6948:TCP:Blizzard Downloader
"6949:TCP"= 6949:TCP:Blizzard Downloader
"6950:TCP"= 6950:TCP:Blizzard Downloader
"6951:TCP"= 6951:TCP:Blizzard Downloader
"6952:TCP"= 6952:TCP:Blizzard Downloader
"6953:TCP"= 6953:TCP:Blizzard Downloader
"6957:TCP"= 6957:TCP:Blizzard Downloader
"6958:TCP"= 6958:TCP:Blizzard Downloader
"6959:TCP"= 6959:TCP:Blizzard Downloader
"6960:TCP"= 6960:TCP:Blizzard Downloader
"6961:TCP"= 6961:TCP:Blizzard Downloader
"6962:TCP"= 6962:TCP:Blizzard Downloader
"6963:TCP"= 6963:TCP:Blizzard Downloader
"6964:TCP"= 6964:TCP:Blizzard Downloader
"6965:TCP"= 6965:TCP:Blizzard Downloader
"6966:TCP"= 6966:TCP:Blizzard Downloader
"6967:TCP"= 6967:TCP:Blizzard Downloader
"6968:TCP"= 6968:TCP:Blizzard Downloader
"6969:TCP"= 6969:TCP:Blizzard Downloader
"6970:TCP"= 6970:TCP:Blizzard Downloader
"6971:TCP"= 6971:TCP:Blizzard Downloader
"6972:TCP"= 6972:TCP:Blizzard Downloader
"6973:TCP"= 6973:TCP:Blizzard Downloader
"6974:TCP"= 6974:TCP:Blizzard Downloader
"6975:TCP"= 6975:TCP:Blizzard Downloader
"6976:TCP"= 6976:TCP:Blizzard Downloader
"6977:TCP"= 6977:TCP:Blizzard Downloader
"6978:TCP"= 6978:TCP:Blizzard Downloader
"6979:TCP"= 6979:TCP:Blizzard Downloader
"6980:TCP"= 6980:TCP:Blizzard Downloader
"6981:TCP"= 6981:TCP:Blizzard Downloader
"6982:TCP"= 6982:TCP:Blizzard Downloader
"6983:TCP"= 6983:TCP:Blizzard Downloader
"6984:TCP"= 6984:TCP:Blizzard Downloader
"6985:TCP"= 6985:TCP:Blizzard Downloader
"6986:TCP"= 6986:TCP:Blizzard Downloader
"6987:TCP"= 6987:TCP:Blizzard Downloader
"6988:TCP"= 6988:TCP:Blizzard Downloader
"6989:TCP"= 6989:TCP:Blizzard Downloader
"6990:TCP"= 6990:TCP:Blizzard Downloader
"6991:TCP"= 6991:TCP:Blizzard Downloader
"6992:TCP"= 6992:TCP:Blizzard Downloader
"6993:TCP"= 6993:TCP:Blizzard Downloader
"6994:TCP"= 6994:TCP:Blizzard Downloader
"6995:TCP"= 6995:TCP:Blizzard Downloader
"6996:TCP"= 6996:TCP:Blizzard Downloader
"6997:TCP"= 6997:TCP:Blizzard Downloader
"6998:TCP"= 6998:TCP:Blizzard Downloader
"6956:TCP"= 6956:TCP:Blizzard Downloader
"6955:TCP"= 6955:TCP:Blizzard Downloader
"6954:TCP"= 6954:TCP:Blizzard Downloader
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9105:TCP"= 9105:TCP:nhnsmdto
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [12/28/2008 6:38 PM 23200]
S2 sckjqlxr;Network Installer;c:\windows\system32\svchost.exe -k netsvcs [3/31/2003 8:00 AM 14336]
S3 bjsfos;bjsfos; [x]
S3 bzqpxwqc;bzqpxwqc;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 iywwnxomf;iywwnxomf;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 LSWL_USB;Instant Wireless USB Network Adapter ver.2.5 Driver;c:\windows\system32\drivers\LSWLUSB.sys [9/14/2006 5:47 PM 41232]
S3 mqxuqs;mqxuqs;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 parhjt;parhjt;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 qjhaennwj;qjhaennwj; [x]
S3 qweodvv;qweodvv; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 tsprpinf;tsprpinf;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 wpmpnri;wpmpnri; [x]
S3 xssdt;xssdt;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
S3 ympne;ympne; [x]
S3 zhzfyxs;zhzfyxs; [x]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wwslgodl
sckjqlxr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-08-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]
2009-08-16 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-02-14 03:20]
2009-08-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-02-14 03:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://google.com/mSearch Bar =
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/keyword/%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com\*.update
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\9863xxpq.default\
FF - prefs.js: browser.startup.homepage -
hxxps://my.johnshopkins.edu/uPortal/render.userLayoutRootNode.uPFF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-15 21:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bzqpxwqc]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iywwnxomf]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mqxuqs]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\parhjt]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tsprpinf]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xssdt]
"ImagePath"="\??\c:\windows\system32\02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sckjqlxr]
"ServiceDll"="c:\windows\system32\ucgkglr.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(7580)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\hnetcfg.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Ahead\InCD\incdsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\searchindexer.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-08-16 21:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-16 01:46
Pre-Run: 27,761,958,912 bytes free
Post-Run: 27,663,683,584 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
374