Suspicious files ____________________________________________________________
C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsisos.dll
Size . . . . . . . : 5,632 bytes
Age . . . . . . . : 12.9 days (2013-03-08 08:19:57)
Entropy . . . . . : 3.1
SHA-256 . . . . . : BA79AB7F63F02ED5D5D46B82B11D97DAC5B7EF7E9B9A4DF926B43CEAC18483B6
Fuzzy . . . . . . : 23.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\StdUtils.dll
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsislog.dll
0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsisos.dll
0.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\System.dll
0.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\UserInfo.dll
18.4s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\ExecDos.dll
20.9s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\scs.exe
21.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\CleanChromePrefs.vbs
22.2s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\CleanFirefoxPrefs.vbs
24.0s C:\Users\George\AppData\Local\Temp\nsx31BB.tmp\System.dll
C:\Windows\SysWOW64\GameMon.des
Size . . . . . . . : 4,703,728 bytes
Age . . . . . . . : 104.8 days (2012-12-06 11:31:46)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 61AE426A4259588CBD46C1117BCC989A32C12A682F3EF5ED6EFD269936DA563E
Product . . . . . : nProtect Game Monitor
Publisher . . . . : INCA Internet Co., Ltd.
Description . . . : nProtect Game Monitor Rev 1914
Version . . . . . : 2012.11.15.1
Copyright . . . . : Copyright ⓒ 2000-2011 INCA Internet
Service . . . . . : npggsvc
Fuzzy . . . . . . : 29.0
The file name extension of this program is not common.
Starts automatically as a service during system bootup.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Startup
HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
Malware remnants ____________________________________________________________
HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato)
Potential Unwanted Programs _________________________________________________
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data (Claro)
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences (Claro)
HKLM\SOFTWARE\Classes\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\b\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd.1\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr\ (Babylon)
HKLM\SOFTWARE\Classes\c\ (Claro)
HKLM\SOFTWARE\Classes\claro.claroappCore.1\ (Claro)
HKLM\SOFTWARE\Classes\claro.claroappCore\ (Claro)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1\ (Babylon)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc\ (Babylon)
HKLM\SOFTWARE\Classes\esrv.claroESrvc.1\ (Claro)
HKLM\SOFTWARE\Classes\esrv.claroESrvc\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)
HKLM\SOFTWARE\Classes\Prod.cap\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{A903AC15-686E-4D67-A355-86FCBE9F60DA}\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{05340575-7D2A-4266-9A84-7EEBDC476884}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{EE4FC43F-84CE-4E20-88C2-2188525B47FB}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F398D871-ED00-42A8-BEAA-0209E9E59FCC}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{A903AC15-686E-4D67-A355-86FCBE9F60DA}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers\ (Yontoo)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Babylon\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\Claro LTD\ (Claro)
HKLM\SOFTWARE\Wow6432Node\DataMngr\ (SearchQU)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}\ (Claro)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\DataMngr\ (SearchQU)
HKU\.DEFAULT\Software\DataMngr_Toolbar\ (SearchQU)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-18\Software\DataMngr\ (SearchQU)
HKU\S-1-5-18\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Claro LTD\ (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\DataMngr\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings\ (Claro)
I also do not know much about computers, only the basics,
Thanks
C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsisos.dll
Size . . . . . . . : 5,632 bytes
Age . . . . . . . : 12.9 days (2013-03-08 08:19:57)
Entropy . . . . . : 3.1
SHA-256 . . . . . : BA79AB7F63F02ED5D5D46B82B11D97DAC5B7EF7E9B9A4DF926B43CEAC18483B6
Fuzzy . . . . . . : 23.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\StdUtils.dll
-0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsislog.dll
0.0s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\nsisos.dll
0.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\System.dll
0.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\UserInfo.dll
18.4s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\ExecDos.dll
20.9s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\scs.exe
21.1s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\CleanChromePrefs.vbs
22.2s C:\Users\George\AppData\Local\Temp\nsyAB9C.tmp\CleanFirefoxPrefs.vbs
24.0s C:\Users\George\AppData\Local\Temp\nsx31BB.tmp\System.dll
C:\Windows\SysWOW64\GameMon.des
Size . . . . . . . : 4,703,728 bytes
Age . . . . . . . : 104.8 days (2012-12-06 11:31:46)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 61AE426A4259588CBD46C1117BCC989A32C12A682F3EF5ED6EFD269936DA563E
Product . . . . . : nProtect Game Monitor
Publisher . . . . : INCA Internet Co., Ltd.
Description . . . : nProtect Game Monitor Rev 1914
Version . . . . . : 2012.11.15.1
Copyright . . . . : Copyright ⓒ 2000-2011 INCA Internet
Service . . . . . : npggsvc
Fuzzy . . . . . . : 29.0
The file name extension of this program is not common.
Starts automatically as a service during system bootup.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Startup
HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
Malware remnants ____________________________________________________________
HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato)
Potential Unwanted Programs _________________________________________________
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data (Claro)
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences (Claro)
HKLM\SOFTWARE\Classes\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\b\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd.1\ (Babylon)
HKLM\SOFTWARE\Classes\Babylon.dskBnd\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylnApp.appCore\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1\ (Babylon)
HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr\ (Babylon)
HKLM\SOFTWARE\Classes\c\ (Claro)
HKLM\SOFTWARE\Classes\claro.claroappCore.1\ (Claro)
HKLM\SOFTWARE\Classes\claro.claroappCore\ (Claro)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1\ (Babylon)
HKLM\SOFTWARE\Classes\esrv.BabylonESrvc\ (Babylon)
HKLM\SOFTWARE\Classes\esrv.claroESrvc.1\ (Claro)
HKLM\SOFTWARE\Classes\esrv.claroESrvc\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}\ (Claro)
HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)
HKLM\SOFTWARE\Classes\Prod.cap\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\TypeLib\{A903AC15-686E-4D67-A355-86FCBE9F60DA}\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{05340575-7D2A-4266-9A84-7EEBDC476884}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{EE4FC43F-84CE-4E20-88C2-2188525B47FB}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F398D871-ED00-42A8-BEAA-0209E9E59FCC}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{A903AC15-686E-4D67-A355-86FCBE9F60DA}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers\ (Yontoo)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Babylon\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\Claro LTD\ (Claro)
HKLM\SOFTWARE\Wow6432Node\DataMngr\ (SearchQU)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}\ (Claro)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\DataMngr\ (SearchQU)
HKU\.DEFAULT\Software\DataMngr_Toolbar\ (SearchQU)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-18\Software\DataMngr\ (SearchQU)
HKU\S-1-5-18\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Claro LTD\ (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\DataMngr\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings\ (Claro)
I also do not know much about computers, only the basics,
Thanks