ComboFix log
ComboFix 10-05-08.02 - DCT Kramp 05/09/2010 10:59:01.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1202 [GMT 2:00]
Running from: c:\documents and settings\DCT Kramp\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\DCT Kramp\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((( Files Created from 2010-04-09 to 2010-05-09 )))))))))))))))))))))))))))))))
.
2010-05-04 22:22 . 2010-05-04 22:29 -------- d-----w- C:\rsit
2010-05-04 21:52 . 2010-05-04 21:52 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Malwarebytes
2010-05-04 21:51 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-04 21:51 . 2010-05-04 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-04 21:51 . 2010-05-04 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-04 21:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-03 16:46 . 2010-05-03 16:50 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\DAEMON Tools Lite
2010-05-03 16:46 . 2010-05-03 16:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-04-28 21:47 . 2010-04-28 21:48 -------- d-----w- c:\program files\ERUNT
2010-04-28 21:04 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-22 21:44 . 2010-04-23 14:43 -------- d-----w- c:\documents and settings\DCT Kramp\DoctorWeb
2010-04-11 10:04 . 2010-04-11 10:04 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\StarBurn
2010-04-11 10:03 . 2010-04-11 10:03 -------- d-----w- c:\program files\Save Tube Video Company
2010-04-11 10:03 . 2009-03-02 12:00 95592 ----a-w- c:\windows\system32\drivers\StarPortLite.sys
2010-04-11 10:03 . 2010-04-11 10:03 -------- d-----w- c:\program files\Rocket Division Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-09 08:56 . 2009-07-16 16:37 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Skype
2010-05-09 08:13 . 2009-07-16 17:32 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\skypePM
2010-05-09 08:12 . 2010-01-09 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-05-05 06:28 . 2010-01-10 13:43 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 06:28 . 2010-01-10 13:43 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-04 23:08 . 2009-05-21 17:40 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\uTorrent
2010-05-03 17:01 . 2008-10-16 02:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-23 20:00 . 2008-10-16 03:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-13 05:46 . 2008-10-16 02:51 -------- d-----w- c:\program files\Google
2010-03-28 19:39 . 2009-09-07 12:52 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Belastingdienst
2010-03-28 11:12 . 2010-03-28 10:02 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Command & Conquer 3 Tiberium Wars
2010-03-24 15:52 . 2009-12-15 18:13 139456 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-24 15:52 . 2009-09-19 19:40 190160 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-16 12:32 . 2010-03-16 12:32 15086 ----a-r- c:\documents and settings\DCT Kramp\Application Data\Microsoft\Installer\{B39DA0C8-3110-4B0F-9BF7-25B053BA2BE7}\icoon-startmen-V2.exe
2010-03-16 12:32 . 2010-03-16 12:32 -------- d-----w- c:\program files\Oefenexamens inburgering
2010-03-10 06:15 . 2008-04-14 22:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-05 16:45 . 2009-10-17 12:03 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-03 17:58 . 2009-12-15 18:13 2407792 ----a-w- c:\windows\system32\pbsvc_heroes.exe
2010-02-26 19:39 . 2009-09-19 19:40 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-25 06:24 . 2007-08-14 01:54 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-14 22:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-04-14 22:00 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 22:00 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-14 22:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-14 22:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-08 20:34 . 2009-07-30 19:17 60664 ----a-w- c:\documents and settings\kirill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-08 19:11 . 2010-02-08 19:11 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000007100002h\ODSERV.EXE
2010-02-08 15:36 . 2010-02-08 15:36 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000008c00002h\offlb.exe
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000005700002h\WINWORD.EXE
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000002ca00002h\OffDiag.exe
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\30000000d900002h\DW20.EXE
2003-07-28 22:15 . 2009-07-22 02:20 307200 ----a-w- c:\program files\internet explorer\plugins\djvu0407.dll
2003-07-28 22:15 . 2009-07-22 02:20 303104 ----a-w- c:\program files\internet explorer\plugins\djvu0409.dll
2003-07-28 22:15 . 2009-07-22 02:20 311296 ----a-w- c:\program files\internet explorer\plugins\djvu040c.dll
2003-07-28 22:15 . 2009-07-22 02:20 299008 ----a-w- c:\program files\internet explorer\plugins\djvu0411.dll
2003-07-28 22:15 . 2009-07-22 02:20 299008 ----a-w- c:\program files\internet explorer\plugins\djvu0412.dll
2003-07-28 22:15 . 2009-07-22 02:20 290816 ----a-w- c:\program files\internet explorer\plugins\djvu0804.dll
2003-07-28 22:15 . 2009-07-22 02:20 122880 ----a-w- c:\program files\internet explorer\plugins\DjVuCntl.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-05-04_23.53.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-09 08:07 . 2010-05-09 08:07 16384 c:\windows\Temp\Perflib_Perfdata_604.dat
+ 2008-10-16 03:19 . 2010-05-09 08:13 72080 c:\windows\system32\perfc009.dat
- 2008-10-16 03:19 . 2010-05-04 23:37 72080 c:\windows\system32\perfc009.dat
+ 2008-10-16 03:19 . 2010-05-09 08:13 442798 c:\windows\system32\perfh009.dat
- 2008-10-16 03:19 . 2010-05-04 23:37 442798 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-16 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe" [2009-06-05 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-10-20 340456]
"nwiz"="nwiz.exe" [2008-02-25 1626112]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WN111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WN111v2\WN111V2.exe [2009-3-25 1503290]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"MSPY2002"=c:\windows\system32\IME\PINTLGNT\ImScInst.exe /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\DCT Kramp\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\_Temp\\CS\\hl -dev -console.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\_Temp\\cf\\Doomsday\\bin\\Doomsday.exe"=
"c:\\_Temp\\Generals\\game.dat"=
"c:\\_Temp\\Generals\\Generals.exe"=
"c:\\_Temp\\c&c3\\RetailExe\\1.0\\cnc3game.dat"=
"c:\\_Temp\\GSC Game World\\Cossacks II\\Data\\engine.exe"=
"c:\\Program Files\\Save Tube Video Company\\SaveTubeVideo\\downloader.exe"=
"c:\\_Temp\\soul\\Soulstorm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58530:TCP"= 58530:TCP
ando Media Booster
"58530:UDP"= 58530:UDP
ando Media Booster
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [10/14/2009 9:18 PM 36880]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [4/11/2010 12:03 PM 95592]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 10:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 7:42 AM 50424]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 1:10 PM 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [10/1/2008 5:45 PM 57440]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [1/14/2009 3:23 AM 458752]
S2 gupdate1c9ed8859e93c44;Google Update Service (gupdate1c9ed8859e93c44);c:\program files\Google\Update\GoogleUpdate.exe [6/15/2009 9:10 AM 133104]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 12:03 PM 131072]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\NETGEAR\WN111v2\jswpsapi.exe [2/27/2008 12:54 PM 360547]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 XDva317;XDva317;\??\c:\windows\system32\XDva317.sys --> c:\windows\system32\XDva317.sys [?]
S3 XDva327;XDva327;\??\c:\windows\system32\XDva327.sys --> c:\windows\system32\XDva327.sys [?]
S3 XDva337;XDva337;\??\c:\windows\system32\XDva337.sys --> c:\windows\system32\XDva337.sys [?]
S3 XDva341;XDva341;\??\c:\windows\system32\XDva341.sys --> c:\windows\system32\XDva341.sys [?]
S3 XDva343;XDva343;\??\c:\windows\system32\XDva343.sys --> c:\windows\system32\XDva343.sys [?]
S3 XDva346;XDva346;\??\c:\windows\system32\XDva346.sys --> c:\windows\system32\XDva346.sys [?]
S3 XDva347;XDva347;\??\c:\windows\system32\XDva347.sys --> c:\windows\system32\XDva347.sys [?]
S3 XDva348;XDva348;\??\c:\windows\system32\XDva348.sys --> c:\windows\system32\XDva348.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/17/2009 2:03 PM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-05-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-16 07:08]
2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-15 07:10]
2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-15 07:10]
2009-12-16 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX1000_exe.job
- c:\windows\vVX1000.exe [2009-07-17 21:46]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://powersoccer.com/common/applet/PowerLoader.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-09 11:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2010-05-09 11:07:25
ComboFix-quarantined-files.txt 2010-05-09 09:07
ComboFix2.txt 2010-05-04 23:58
Pre-Run: 16,551,706,624 bytes free
Post-Run: 16,565,551,104 bytes free
- - End Of File - - 97AFEE96A2EE9049394A70B9A61CFF22
ComboFix 10-05-08.02 - DCT Kramp 05/09/2010 10:59:01.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1202 [GMT 2:00]
Running from: c:\documents and settings\DCT Kramp\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\DCT Kramp\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((( Files Created from 2010-04-09 to 2010-05-09 )))))))))))))))))))))))))))))))
.
2010-05-04 22:22 . 2010-05-04 22:29 -------- d-----w- C:\rsit
2010-05-04 21:52 . 2010-05-04 21:52 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Malwarebytes
2010-05-04 21:51 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-04 21:51 . 2010-05-04 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-04 21:51 . 2010-05-04 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-04 21:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-03 16:46 . 2010-05-03 16:50 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\DAEMON Tools Lite
2010-05-03 16:46 . 2010-05-03 16:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-04-28 21:47 . 2010-04-28 21:48 -------- d-----w- c:\program files\ERUNT
2010-04-28 21:04 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-22 21:44 . 2010-04-23 14:43 -------- d-----w- c:\documents and settings\DCT Kramp\DoctorWeb
2010-04-11 10:04 . 2010-04-11 10:04 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\StarBurn
2010-04-11 10:03 . 2010-04-11 10:03 -------- d-----w- c:\program files\Save Tube Video Company
2010-04-11 10:03 . 2009-03-02 12:00 95592 ----a-w- c:\windows\system32\drivers\StarPortLite.sys
2010-04-11 10:03 . 2010-04-11 10:03 -------- d-----w- c:\program files\Rocket Division Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-09 08:56 . 2009-07-16 16:37 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Skype
2010-05-09 08:13 . 2009-07-16 17:32 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\skypePM
2010-05-09 08:12 . 2010-01-09 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-05-05 06:28 . 2010-01-10 13:43 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 06:28 . 2010-01-10 13:43 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-04 23:08 . 2009-05-21 17:40 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\uTorrent
2010-05-03 17:01 . 2008-10-16 02:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-23 20:00 . 2008-10-16 03:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-13 05:46 . 2008-10-16 02:51 -------- d-----w- c:\program files\Google
2010-03-28 19:39 . 2009-09-07 12:52 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Belastingdienst
2010-03-28 11:12 . 2010-03-28 10:02 -------- d-----w- c:\documents and settings\DCT Kramp\Application Data\Command & Conquer 3 Tiberium Wars
2010-03-24 15:52 . 2009-12-15 18:13 139456 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-24 15:52 . 2009-09-19 19:40 190160 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-16 12:32 . 2010-03-16 12:32 15086 ----a-r- c:\documents and settings\DCT Kramp\Application Data\Microsoft\Installer\{B39DA0C8-3110-4B0F-9BF7-25B053BA2BE7}\icoon-startmen-V2.exe
2010-03-16 12:32 . 2010-03-16 12:32 -------- d-----w- c:\program files\Oefenexamens inburgering
2010-03-10 06:15 . 2008-04-14 22:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-05 16:45 . 2009-10-17 12:03 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-03 17:58 . 2009-12-15 18:13 2407792 ----a-w- c:\windows\system32\pbsvc_heroes.exe
2010-02-26 19:39 . 2009-09-19 19:40 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-25 06:24 . 2007-08-14 01:54 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-14 22:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-04-14 22:00 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 22:00 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-14 22:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-14 22:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-08 20:34 . 2009-07-30 19:17 60664 ----a-w- c:\documents and settings\kirill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-08 19:11 . 2010-02-08 19:11 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000007100002h\ODSERV.EXE
2010-02-08 15:36 . 2010-02-08 15:36 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000008c00002h\offlb.exe
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000005700002h\WINWORD.EXE
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\300000002ca00002h\OffDiag.exe
2010-02-08 15:24 . 2010-02-08 15:24 53248 ----a-w- c:\documents and settings\DCT Kramp\Application Data\Thinstall\Microsoft Office Enterprise 2007.EMACHINE-C8A040\30000000d900002h\DW20.EXE
2003-07-28 22:15 . 2009-07-22 02:20 307200 ----a-w- c:\program files\internet explorer\plugins\djvu0407.dll
2003-07-28 22:15 . 2009-07-22 02:20 303104 ----a-w- c:\program files\internet explorer\plugins\djvu0409.dll
2003-07-28 22:15 . 2009-07-22 02:20 311296 ----a-w- c:\program files\internet explorer\plugins\djvu040c.dll
2003-07-28 22:15 . 2009-07-22 02:20 299008 ----a-w- c:\program files\internet explorer\plugins\djvu0411.dll
2003-07-28 22:15 . 2009-07-22 02:20 299008 ----a-w- c:\program files\internet explorer\plugins\djvu0412.dll
2003-07-28 22:15 . 2009-07-22 02:20 290816 ----a-w- c:\program files\internet explorer\plugins\djvu0804.dll
2003-07-28 22:15 . 2009-07-22 02:20 122880 ----a-w- c:\program files\internet explorer\plugins\DjVuCntl.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-05-04_23.53.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-09 08:07 . 2010-05-09 08:07 16384 c:\windows\Temp\Perflib_Perfdata_604.dat
+ 2008-10-16 03:19 . 2010-05-09 08:13 72080 c:\windows\system32\perfc009.dat
- 2008-10-16 03:19 . 2010-05-04 23:37 72080 c:\windows\system32\perfc009.dat
+ 2008-10-16 03:19 . 2010-05-09 08:13 442798 c:\windows\system32\perfh009.dat
- 2008-10-16 03:19 . 2010-05-04 23:37 442798 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-16 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe" [2009-06-05 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-10-20 340456]
"nwiz"="nwiz.exe" [2008-02-25 1626112]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WN111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WN111v2\WN111V2.exe [2009-3-25 1503290]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"MSPY2002"=c:\windows\system32\IME\PINTLGNT\ImScInst.exe /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\DCT Kramp\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\_Temp\\CS\\hl -dev -console.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\_Temp\\cf\\Doomsday\\bin\\Doomsday.exe"=
"c:\\_Temp\\Generals\\game.dat"=
"c:\\_Temp\\Generals\\Generals.exe"=
"c:\\_Temp\\c&c3\\RetailExe\\1.0\\cnc3game.dat"=
"c:\\_Temp\\GSC Game World\\Cossacks II\\Data\\engine.exe"=
"c:\\Program Files\\Save Tube Video Company\\SaveTubeVideo\\downloader.exe"=
"c:\\_Temp\\soul\\Soulstorm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58530:TCP"= 58530:TCP

"58530:UDP"= 58530:UDP

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [10/14/2009 9:18 PM 36880]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [4/11/2010 12:03 PM 95592]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 10:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 7:42 AM 50424]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 1:10 PM 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [10/1/2008 5:45 PM 57440]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [1/14/2009 3:23 AM 458752]
S2 gupdate1c9ed8859e93c44;Google Update Service (gupdate1c9ed8859e93c44);c:\program files\Google\Update\GoogleUpdate.exe [6/15/2009 9:10 AM 133104]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 12:03 PM 131072]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\NETGEAR\WN111v2\jswpsapi.exe [2/27/2008 12:54 PM 360547]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 XDva317;XDva317;\??\c:\windows\system32\XDva317.sys --> c:\windows\system32\XDva317.sys [?]
S3 XDva327;XDva327;\??\c:\windows\system32\XDva327.sys --> c:\windows\system32\XDva327.sys [?]
S3 XDva337;XDva337;\??\c:\windows\system32\XDva337.sys --> c:\windows\system32\XDva337.sys [?]
S3 XDva341;XDva341;\??\c:\windows\system32\XDva341.sys --> c:\windows\system32\XDva341.sys [?]
S3 XDva343;XDva343;\??\c:\windows\system32\XDva343.sys --> c:\windows\system32\XDva343.sys [?]
S3 XDva346;XDva346;\??\c:\windows\system32\XDva346.sys --> c:\windows\system32\XDva346.sys [?]
S3 XDva347;XDva347;\??\c:\windows\system32\XDva347.sys --> c:\windows\system32\XDva347.sys [?]
S3 XDva348;XDva348;\??\c:\windows\system32\XDva348.sys --> c:\windows\system32\XDva348.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/17/2009 2:03 PM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-05-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-16 07:08]
2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-15 07:10]
2010-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-15 07:10]
2009-12-16 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX1000_exe.job
- c:\windows\vVX1000.exe [2009-07-17 21:46]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://powersoccer.com/common/applet/PowerLoader.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-09 11:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2010-05-09 11:07:25
ComboFix-quarantined-files.txt 2010-05-09 09:07
ComboFix2.txt 2010-05-04 23:58
Pre-Run: 16,551,706,624 bytes free
Post-Run: 16,565,551,104 bytes free
- - End Of File - - 97AFEE96A2EE9049394A70B9A61CFF22