ComboFix 10-03-27.02 - NanaB32 03/27/2010 19:36:27.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.958.425 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\NanaB32\FAVORI~1\_favdata.dat
c:\users\NanaB32\Favorites\_favdata.dat
.
((((((((((((((((((((((((( Files Created from 2010-02-27 to 2010-03-27 )))))))))))))))))))))))))))))))
.
2010-03-27 23:53 . 2010-03-27 23:54 ——– d—–w- c:\users\NanaB32\AppData\Local\temp
2010-03-27 23:53 . 2010-03-27 23:53 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-03-27 23:53 . 2010-03-27 23:53 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-21 06:03 . 2010-03-21 06:03 ——– d—–w- c:\windows\OvtCam
2010-03-21 06:01 . 2003-10-15 21:52 307200 —-a-w- c:\windows\vidcap32.exe
2010-03-21 06:01 . 2003-10-15 21:52 200704 —-a-w- c:\windows\sel3110.exe
2010-03-21 06:01 . 2003-10-15 21:52 174530 —-a-w- c:\windows\system32\drivers\ov519vid.sys
2010-03-21 06:01 . 2003-10-15 21:52 40960 —-a-w- c:\windows\system32\ov519ext.dll
2010-03-21 06:01 . 2003-10-15 21:52 25211 —-a-w- c:\windows\system32\drivers\ov519cmd.sys
2010-03-21 06:01 . 2003-10-15 21:52 40960 —-a-w- c:\windows\CleanDev.exe
2010-03-21 06:01 . 2003-10-15 21:52 32528 —-a-w- c:\windows\amcap.exe
2010-03-21 06:01 . 2003-10-15 21:52 16426 —-a-w- c:\windows\system32\ov519usd.dll
2010-03-21 06:01 . 2003-10-15 21:52 61440 —-a-w- c:\windows\ov519dib.dll
2010-03-21 06:01 . 2003-10-15 21:52 135168 —-a-w- c:\windows\ov519cap.exe
2010-03-13 17:57 . 2010-03-13 17:57 ——– d—–w- c:\users\NanaB32\AppData\Local\Apple
2010-03-13 17:55 . 2010-03-13 17:55 ——– d—–w- c:\users\NanaB32\AppData\Local\Apple Computer
2010-03-11 23:53 . 2005-04-20 20:28 225280 —-a-r- c:\windows\system32\ReWire.dll
2010-03-11 23:53 . 2010-03-23 00:52 ——– d—–w- c:\program files\MadTracker
2010-03-11 23:53 . 2005-12-26 02:25 774144 —-a-w- c:\windows\MTUn402.exe
2010-03-11 22:38 . 2010-03-11 22:38 ——– d—–w- c:\users\NanaB32\AppData\Local\Adobe
2010-03-11 08:01 . 2010-02-20 23:06 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-03-11 08:01 . 2010-02-20 20:53 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-03-11 08:01 . 2010-02-20 23:05 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-03-10 22:45 . 2010-03-10 22:45 ——– d—–w- c:\program files\Trend Micro
2010-03-04 13:13 . 2010-03-05 00:11 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-03-04 13:13 . 2010-03-04 13:20 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-01 02:04 . 2010-03-01 02:07 1911424 —-a-w- C:\ezfla_up.bin
2010-02-26 13:05 . 2010-02-27 01:29 731 —-a-w- c:\windows\gooption4.dat
2010-02-26 13:05 . 2010-02-27 01:29 1767 —-a-w- c:\windows\gogoomba.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-27 22:09 . 2009-03-03 16:04 32061 —-a-w- c:\programdata\nvModes.dat
2010-03-27 17:12 . 2009-11-15 04:01 ——– d—–w- c:\program files\Steam
2010-03-26 05:48 . 2009-11-03 17:56 ——– d—–w- c:\users\NanaB32\AppData\Roaming\uTorrent
2010-03-25 01:17 . 2009-11-03 09:24 1 —-a-w- c:\users\NanaB32\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-23 21:32 . 2007-08-05 01:09 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-03-21 06:45 . 2009-10-24 01:57 ——– d—–w- c:\users\NanaB32\AppData\Roaming\foobar2000
2010-03-21 06:04 . 2007-08-05 01:31 ——– d—–w- c:\programdata\CyberLink
2010-03-11 08:23 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-03-10 16:27 . 2009-11-15 04:01 ——– d—–w- c:\program files\Common Files\Steam
2010-03-09 22:10 . 2010-03-09 22:10 388096 —-a-r- c:\users\NanaB32\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-03-06 16:06 . 2009-10-14 00:52 ——– d—–w- c:\programdata\PMB Files
2010-03-04 12:46 . 2007-10-24 20:58 680 —-a-w- c:\users\NanaB32\AppData\Local\d3d9caps.dat
2010-03-04 04:20 . 2007-10-10 14:12 97560 —-a-w- c:\users\NanaB32\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-26 22:13 . 2010-03-15 19:14 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-02-24 20:52 . 2009-11-20 12:48 ——– d—–w- c:\programdata\YoYoGames
2010-02-24 20:52 . 2009-11-20 12:48 495616 —-a-w- c:\programdata\YoYoGames\d3dx8.dll
2010-02-24 20:52 . 2010-02-24 20:52 1431872 —-a-w- c:\programdata\YoYoGames\yoyo60.exe
2010-02-24 08:33 . 2010-02-24 08:32 97560 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-02-22 20:19 . 2007-08-05 02:20 ——– d—–w- c:\programdata\Hewlett-Packard
2010-02-22 18:28 . 2010-03-08 20:11 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-21 23:56 . 2008-01-03 01:08 ——– d—–w- c:\program files\Google
2010-02-21 23:54 . 2010-02-21 23:53 ——– d—–w- c:\program files\DivX
2010-02-21 23:53 . 2010-02-21 23:53 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-02-21 01:53 . 2010-02-21 01:53 ——– d—–w- c:\users\NanaB32\AppData\Roaming\Malwarebytes
2010-02-21 01:53 . 2010-02-21 01:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-21 01:53 . 2010-02-21 01:53 ——– d—–w- c:\programdata\Malwarebytes
2010-02-18 00:17 . 2010-02-18 00:17 ——– d—–w- c:\users\NanaB32\AppData\Roaming\Xilisoft Corporation
2010-02-16 18:09 . 2010-02-16 18:09 ——– d—–w- c:\program files\Elaborate Bytes
2010-02-16 18:02 . 2010-02-16 18:02 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-02-16 09:00 . 2010-03-23 21:31 84912 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100323.002\NAVENG.SYS
2010-02-16 09:00 . 2010-03-23 21:31 1324720 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100323.002\NAVEX15.SYS
2010-02-16 09:00 . 2010-02-16 09:00 84912 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\NAVENG.SYS
2010-02-16 09:00 . 2010-02-16 09:00 1324720 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\NAVEX15.SYS
2010-02-15 21:49 . 2007-08-05 00:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-15 21:49 . 2007-08-05 00:41 ——– d—–w- c:\program files\Hewlett-Packard
2010-02-04 21:51 . 2010-03-08 20:11 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2010-02-04 10:44 . 2010-02-04 10:44 ——– d—–w- c:\program files\Celebrity Toolbar
2010-01-25 12:00 . 2010-02-24 04:34 471552 —-a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 04:33 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 04:33 152064 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 04:34 471552 —-a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 04:33 332288 —-a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 04:34 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 04:34 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 04:34 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-25 08:21 . 2010-02-24 04:34 518144 —-a-w- c:\windows\system32\RMActivate.exe
2010-01-23 09:26 . 2010-02-24 04:35 2048 —-a-w- c:\windows\system32\tzres.dll
2010-01-15 00:05 . 2007-10-10 02:07 606 —-a-w- c:\users\NanaB32\AppData\Roaming\wklnhst.dat
2010-01-07 21:07 . 2010-02-21 01:53 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2010-02-21 01:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 15:39 . 2010-02-24 04:39 1696256 —-a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-24 04:39 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-24 04:39 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 04:39 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 04:39 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 15:38 . 2010-02-24 04:39 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 13:30 . 2010-02-24 04:39 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-01-22 10:58 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 10:58 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-22 10:58 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-22 10:58 133632 —-a-w- c:\windows\system32\ieUnatt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Celebrity Toolbar\tbhelper.dll" [2009-05-07 355840]
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Celebrity Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Celebrity Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-03 171448]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-06 2937528]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-01-24 289584]
"Steam"="c:\program files\steam\steam.exe" [2010-02-20 1217872]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1152602.exe" [2009-10-29 464312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\NanaB32\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:fe,ee,5b,d6,31,6d,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-01 691696]
R2 gupdate1cab3512f58e3f0;Google Update Service (gupdate1cab3512f58e3f0);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 133104]
R3 XDva276;XDva276;c:\windows\system32\XDva276.sys [x]
R3 XDva285;XDva285;c:\windows\system32\XDva285.sys [x]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-12-08 93320]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 23:53]
2010-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 23:53]
2010-03-04 c:\windows\Tasks\HPCeeScheduleForNanaB32.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-08-05 21:23]
2010-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-19 15:53]
2010-03-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-19 15:53]
2010-03-27 c:\windows\Tasks\Norton Security Scan for NanaB32.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-11 16:50]
2010-03-27 c:\windows\Tasks\User_Feed_Synchronization-{480A8354-09B5-4DD3-A641-10203E5D14E5}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://att.my.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=PRESARIO&pf;=laptop
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {2D52AF9C-51C9-4EF5-B98C-A64997635235} - hxxp://windygame.nefficient.co.kr/patch/cui/cab/20080909/windyMngrAx.cab
DPF: {6FC19219-C47E-4880-9A79-D218A1C374F9} - hxxp://www.netmarble.jp/_common/cab/NMJTransX.cab
DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
.
- - - - ORPHANS REMOVED - - - -
AddRemove-WildTangent hplaptop Master Uninstall - c:\program files\HP Games\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-27 19:54
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3154913152-1125276273-524354568-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:74,59,43,f7,f8,78,a9,d0,a1,92,0f,ac,ba,b6,64,48,97,ab,b4,4a,2f,46,6d,
95,11,f7,15,38,d0,de,51,21,cf,2d,cb,f4,61,ae,9b,5e,d1,30,3e,e4,c4,22,29,18,\
"??"=hex:bc,49,24,79,79,6f,dd,12,a4,4d,6a,39,0c,c4,39,71
[HKEY_USERS\S-1-5-21-3154913152-1125276273-524354568-1000\Software\ V* R* f**Þ*\eXceed3rd-JADE PENETRATE-BP]
"instdrv"="f:\\"
"exepath"="c:\\Users\\NanaB32\\Desktop\\Games\\eXceed3rd JADE PENETRATE BP\\eXceed3rd-JADE PENETRATE-BP\\eXceed3rd-BP.exe"
"instopt"="0"
"gamedir"="c:\\Users\\NanaB32\\Desktop\\Games\\eXceed3rd JADE PENETRATE BP\\eXceed3rd-JADE PENETRATE-BP\\"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-03-27 20:01:21
ComboFix-quarantined-files.txt 2010-03-28 00:01
ComboFix2.txt 2010-03-23 21:13
ComboFix3.txt 2010-03-15 12:30
Pre-Run: 58,611,089,408 bytes free
Post-Run: 58,611,625,984 bytes free
- - End Of File - - 5ADF873B2097A96DC05FEBF129A9CCEF