New comboFix Reports
ComboFix 09-09-10.03 - Erik 09/11/2009 7:01.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.553 [GMT -5:00]
Running from: c:\documents and settings\Erik\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Erik\Desktop\CFScript.txt
file zipped: c:\windows\ex23567.dat
file zipped: c:\windows\fdgg34353edfgdfdf
file zipped: c:\windows\mmsmark2.dat
file zipped: c:\windows\system32\drivers\Filter.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Erik\Application Data\LimeWire
c:\documents and settings\Erik\Application Data\LimeWire\.NetworkShare\LimeWireWin4.16.6.exe
c:\documents and settings\Erik\Application Data\LimeWire\bugs.data
c:\documents and settings\Erik\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Erik\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Erik\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Erik\Application Data\LimeWire\filters.props
c:\documents and settings\Erik\Application Data\LimeWire\gnutella.net
c:\documents and settings\Erik\Application Data\LimeWire\installation.props
c:\documents and settings\Erik\Application Data\LimeWire\library.dat
c:\documents and settings\Erik\Application Data\LimeWire\limewire.props
c:\documents and settings\Erik\Application Data\LimeWire\mojito.props
c:\documents and settings\Erik\Application Data\LimeWire\questions.props
c:\documents and settings\Erik\Application Data\LimeWire\responses.cache
c:\documents and settings\Erik\Application Data\LimeWire\simpp.xml
c:\documents and settings\Erik\Application Data\LimeWire\spam.dat
c:\documents and settings\Erik\Application Data\LimeWire\tables.props
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme.lwtp
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\01_star.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\02_star.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\03_star.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\04_star.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\05_star.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\chat.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\dir_closed.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\dir_open.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\forward_dn.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\forward_up.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\kill.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\kill_on.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\lime.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\logo.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\notsearching.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\pause_dn.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\pause_up.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\play_dn.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\play_up.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\question.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\rewind_dn.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\rewind_up.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\searching.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\stop_dn.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\stop_up.gif
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\theme.txt
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\version.txt
c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\warning.gif
c:\documents and settings\Erik\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Erik\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Erik\Application Data\LimeWire\version.xml
c:\documents and settings\Erik\Application Data\LimeWire\xml\data\audio.sxml
c:\documents and settings\Erik\Application Data\uTorrent
c:\documents and settings\Erik\Application Data\uTorrent\dht.dat
c:\documents and settings\Erik\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Erik\Application Data\uTorrent\resume.dat
c:\documents and settings\Erik\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Erik\Application Data\uTorrent\rss.dat
c:\documents and settings\Erik\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Erik\Application Data\uTorrent\settings.dat
c:\documents and settings\Erik\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Erik\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Erik\Application Data\uTorrent\Winrar 3.80 Professional [blaze69].torrent
c:\program files\LimeWire
c:\program files\LimeWire\Thumbs.db
c:\windows\0535251103110107106.yux
c:\windows\ex23567.dat
c:\windows\fdgg34353edfgdfdf
c:\windows\mmsmark2.dat
c:\windows\system32\drivers\Filter.sys
c:\windows\system32\ulncaqh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FILTER
-------\Legacy_HELPSERVICE
-------\Service_Filter
-------\Service_helpService
((((((((((((((((((((((((( Files Created from 2009-08-11 to 2009-09-11 )))))))))))))))))))))))))))))))
.
2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\Erik\Application Data\Malwarebytes
2009-09-06 04:00 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-06 04:00 . 2009-09-06 04:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-06 04:00 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-06 01:34 . 2009-09-06 01:34 -------- d-----w- c:\program files\Safer Networking
2009-09-05 23:52 . 2009-09-06 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-05 23:52 . 2009-09-06 00:30 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-05 23:52 . 2009-09-05 23:52 -------- d-----w- c:\program files\Common Files\iS3
2009-08-16 21:17 . 2009-08-16 21:18 -------- d-----w- c:\documents and settings\Erik\Application Data\HpUpdate
2009-08-16 21:17 . 2009-08-16 21:17 -------- d-----w- c:\windows\Hewlett-Packard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 12:59 . 2009-01-07 22:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-09 03:40 . 2006-12-06 00:46 -------- d-----w- c:\documents and settings\Erik\Application Data\U3
2009-09-06 00:52 . 2006-12-01 08:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-09-06 00:00 . 2009-09-05 23:58 688 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-09-05 23:59 . 2009-09-05 23:59 128 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-16 21:18 . 2007-03-19 19:39 -------- d-----w- c:\program files\HP
2008-12-11 00:44 . 2008-12-11 00:44 3340 ----a-w- c:\program files\uninstal.log
.
((((((((((((((((((((((((((((( SnapShot@2009-09-10_01.44.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-11 12:09 . 2009-09-11 12:09 16384 c:\windows\temp\Perflib_Perfdata_198.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-15 7573504]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-08-12 380928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-07 136600]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-15 1519616]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk.disabled [2007-3-19 1808]
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"39386:TCP"= 39386:TCP

ebugService 64Definitions
"55520:UDP"= 55520:UDP

ebugService DistributionGallery
"54561:UDP"= 54561:UDP

ebugService HelpProgram
"14057:TCP"= 14057:TCP

ebugService SoftwareComponents
"7213:TCP"= 7213:TCP

ebugService MobileLogs
"26771:UDP"= 26771:UDP

ebugService ModemNET
"50823:TCP"= 50823:TCP

ebugService InstallerSecurity
"24867:UDP"= 24867:UDP

ebugService AgentApp
"30444:UDP"= 30444:UDP

ebugService IMEReports
"47434:TCP"= 47434:TCP

ebugService MicrosoftNET
"27975:UDP"= 27975:UDP

ebugService AgentPLA
"53939:TCP"= 53939:TCP

ebugService JavaOffline
"30872:TCP"= 30872:TCP

ebugService PublishUS
"30181:UDP"= 30181:UDP

ebugService WebUS
"60788:UDP"= 60788:UDP

ebugService msdownldSoftware
"18443:TCP"= 18443:TCP

ebugService PhotoGames
"60935:TCP"= 60935:TCP

ebugService ZxTasks
"52414:UDP"= 52414:UDP

ebugService JavaPages
"33124:UDP"= 33124:UDP

ebugService ExplorerGlobalization
"4306:TCP"= 4306:TCP

ebugService IntelIME
"54609:TCP"= 54609:TCP

ebugService Softwareassembly
"39544:UDP"= 39544:UDP

ebugService DebugExplorer
"56495:UDP"= 56495:UDP

ebugService Serviceen
"44629:TCP"= 44629:TCP

ebugService SecurityGames
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/16/2007 10:28 AM 24652]
S2 pciinfo;HP Pci Information;\??\c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [10/5/2008 4:36 PM 27072]
.
Contents of the 'Scheduled Tasks' folder
2009-09-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]
2009-09-10 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-07 20:31]
2009-09-06 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-01-07 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Erik\Application Data\Mozilla\Firefox\Profiles\zmynrlwf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-11 07:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1177238915-1060284298-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(904)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3456)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\windows\system32\netdde.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\borland\INTERB~1\Bin\ibguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\msiexec.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\borland\INTERB~1\Bin\ibserver.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\SoftwareDistribution\Download\bf65315470cb5ca5b60a434e42ef37a4\update\update.exe
.
**************************************************************************
.
Completion time: 2009-09-11 7:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-11 12:12
ComboFix2.txt 2009-09-10 01:46
Pre-Run: 22,001,467,392 bytes free
Post-Run: 21,896,511,488 bytes free
255 --- E O F --- 2009-02-16 04:43