Here is the combofix log.
ComboFix 10-09-27.05 - Marijus 09/28/2010 19:59:33.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3061.1631 [GMT -4:00]
Running from: c:\users\Marijus\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\logs
J:\Autorun.inf
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-29 00:13 . 2010-09-29 00:14 -------- d-----w- c:\users\Marijus\AppData\Local\temp
2010-09-29 00:13 . 2010-09-29 00:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-22 00:48 . 2010-09-22 00:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-09-22 00:46 . 2010-07-09 22:37 56936 ----a-w- c:\windows\system32\OpenCL.dll
2010-09-22 00:46 . 2010-07-09 22:37 5107816 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-09-22 00:46 . 2010-07-09 22:37 11008040 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-09-22 00:46 . 2010-07-09 22:37 14092904 ----a-w- c:\windows\system32\nvoglv32.dll
2010-09-22 00:46 . 2010-07-09 22:37 4553832 ----a-w- c:\windows\system32\nvcuda.dll
2010-09-22 00:46 . 2010-07-09 22:37 2892904 ----a-w- c:\windows\system32\nvcuvid.dll
2010-09-22 00:46 . 2010-07-09 22:37 2506344 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-09-22 00:46 . 2010-07-09 22:37 236136 ----a-w- c:\windows\system32\nvcod1922.dll
2010-09-22 00:46 . 2010-07-09 22:37 236136 ----a-w- c:\windows\system32\nvcod.dll
2010-09-22 00:46 . 2010-07-09 22:37 10267240 ----a-w- c:\windows\system32\nvcompiler.dll
2010-09-21 19:03 . 2010-09-21 19:03 47876 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-09-16 23:29 . 2010-09-16 23:29 -------- d-----w- c:\users\Marijus\AppData\Roaming\LucasArts
2010-09-16 08:46 . 2010-09-16 08:46 4 ----a-w- c:\program files\75457.dat
2010-09-16 08:22 . 2010-09-16 08:22 4 ----a-w- c:\program files\75176.dat
2010-09-15 18:54 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 18:54 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 18:53 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 18:53 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-14 20:06 . 2010-09-14 20:06 -------- d-----w- c:\users\Marijus\AppData\Roaming\RayV
2010-09-14 20:06 . 2010-09-14 20:06 -------- d-----w- c:\program files\RayV
2010-09-08 00:02 . 2010-09-08 00:02 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-08 00:01 . 2010-09-07 23:54 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-08 00:01 . 2010-09-07 23:54 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-08 00:01 . 2010-09-07 23:53 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-08 00:01 . 2010-09-08 00:01 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-08 00:01 . 2010-09-08 00:01 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-08 00:00 . 2010-09-08 00:00 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-09-08 00:00 . 2010-09-08 00:00 57691 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-09-07 23:59 . 2010-09-09 15:04 -------- d-----w- c:\users\Marijus\AppData\Roaming\DivX
2010-09-07 23:59 . 2010-09-07 23:59 84063 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-09-07 23:59 . 2010-09-07 23:59 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-09-07 23:59 . 2010-09-07 23:59 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-09-07 23:59 . 2010-09-07 23:59 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-09-07 23:58 . 2010-09-07 23:58 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-09-07 23:57 . 2010-09-07 23:57 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-09-07 23:57 . 2010-09-07 23:57 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-07 23:57 . 2010-09-07 23:57 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-09-07 23:55 . 2010-09-08 00:01 -------- d-----w- c:\program files\DivX
2010-09-07 23:54 . 2010-09-07 23:54 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-07 23:54 . 2010-09-08 00:01 -------- d-----w- c:\programdata\DivX
2010-09-06 01:40 . 2010-09-06 01:40 -------- d-----w- c:\program files\iPod
2010-09-06 01:40 . 2010-09-06 01:41 -------- d-----w- c:\program files\iTunes
2010-09-06 01:37 . 2010-09-06 01:37 -------- d-----w- c:\program files\QuickTime
2010-09-06 01:31 . 2010-09-06 01:31 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 23:56 . 2009-12-12 21:40 -------- d-----w- c:\programdata\NVIDIA
2010-09-28 23:51 . 2009-12-14 08:43 81984 ----a-w- c:\windows\system32\bdod.bin
2010-09-28 16:29 . 2010-02-06 20:18 -------- d-----w- c:\users\Marijus\AppData\Roaming\Skype
2010-09-28 16:26 . 2010-02-06 20:27 -------- d-----w- c:\users\Marijus\AppData\Roaming\skypePM
2010-09-28 16:26 . 2009-12-12 21:40 37869 ----a-w- c:\programdata\nvModes.dat
2010-09-28 06:05 . 2010-07-27 13:04 -------- d-----w- c:\program files\StarCraft II
2010-09-27 16:45 . 2010-04-23 17:56 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-09-22 01:37 . 2009-12-12 21:50 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-09-22 00:50 . 2009-12-12 21:39 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-16 23:30 . 2010-06-03 21:13 -------- d-----w- c:\users\Marijus\AppData\Roaming\Petroglyph
2010-09-16 07:05 . 2009-12-11 05:01 -------- d-----w- c:\programdata\Microsoft Help
2010-09-16 07:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-13 20:43 . 2009-12-20 04:22 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-06 01:40 . 2009-12-23 20:22 -------- d-----w- c:\program files\Common Files\Apple
2010-08-29 05:41 . 2009-12-26 00:51 -------- d-----w- c:\users\Marijus\AppData\Roaming\BitTorrent
2010-08-10 15:55 . 2010-03-21 16:10 -------- d-----w- c:\program files\Java
2010-08-10 04:45 . 2010-08-10 04:45 -------- d-----w- c:\users\Marijus\AppData\Roaming\NetSarang
2010-08-05 07:55 . 2010-08-05 07:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-05 07:34 . 2010-08-05 07:34 388096 ----a-r- c:\users\Marijus\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-05 07:34 . 2010-08-05 07:34 -------- d-----w- c:\program files\Trend Micro
2010-08-03 00:50 . 2010-08-03 00:50 -------- d-----w- c:\users\Marijus\AppData\Roaming\dvdcss
2010-08-02 04:37 . 2010-08-02 04:37 100432 ----a-w- c:\users\Marijus\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-17 09:00 . 2010-08-05 07:46 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-09 22:37 . 2009-12-12 21:37 9818728 ----a-w- c:\windows\system32\nvd3dum.dll
2010-07-09 22:37 . 2009-12-12 21:37 1625192 ----a-w- c:\windows\system32\nvapi.dll
2010-07-09 22:37 . 2009-09-28 04:12 604776 ----a-w- c:\windows\system32\nvudisp.exe
2010-07-09 20:37 . 2010-07-09 20:37 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 20:37 . 2010-07-09 20:37 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 20:37 . 2010-07-09 20:37 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 20:37 . 2010-07-09 20:37 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-07 17:46 . 2009-12-11 04:15 604776 ----a-w- c:\windows\system32\nvuninst.exe
2009-12-12 23:20 . 2008-08-14 00:02 65536 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Steam"="j:\steam\steam.exe" [2010-08-23 1242448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]
"RayV"="c:\program files\RayV\RayV\RayV.exe" [2010-06-28 2561320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-02 524632]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-11-22 4352832]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-11-22 960528]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-11-22 165144]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-12-12 782336]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-12-12 69632]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Lycosa"="c:\program files\Razer\Lycosa\razerhid.exe" [2007-11-20 147456]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2007-12-10 323584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10d.exe" [2009-11-03 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2163585369-2416861267-2377926666-1000]
"EnableNotificationsRef"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;j:\games\Dragon Age Origins\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-12-11 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-12-11 64160]
S2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2009-12-12 82696]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-02 1029456]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
S3 bdfm;bdfm;c:\windows\system32\drivers\bdfm.sys [2009-12-12 111112]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2009-12-12 104456]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\Drivers\Lycosa.sys [2008-01-18 16128]
S3 PAC207;PC
Camer@;c:\windows\system32\DRIVERS\PFC027.SYS [2008-02-13 618112]
S3 rt61x86;RT61 Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr61.sys [2008-11-26 333824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bdx REG_MULTI_SZ scan
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-09-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://blizzard.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Marijus\AppData\Roaming\Mozilla\Firefox\Profiles\8feo2crc.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://us.blizzard.com/en-us/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.2&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\RayV\RayV\plugins\nprayvplugin.dll
FF - plugin: c:\users\Marijus\AppData\Roaming\Mozilla\Firefox\Profiles\8feo2crc.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Half-Life Dedicated Server Update Tool - c:\progra~1\Valve\HLServer\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-28 20:13
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,62,b3,91,6d,86,4a,10,4d,94,3d,85,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,62,b3,91,6d,86,4a,10,4d,94,3d,85,\
[HKEY_USERS\S-1-5-21-2163585369-2416861267-2377926666-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:bc,2c,0c,73,19,90,e9,96,01,cb,b7,5e,61,78,e0,4e,4f,da,22,32,6e,99,f5,
c7,17,ec,33,fe,30,59,b5,d6,4b,30,bf,bb,c4,53,93,35,14,ac,c4,03,bc,f8,e8,04,\
"??"=hex:18,21,db,9b,42,82,55,92,68,34,1c,ef,81,9b,0e,e3
[HKEY_USERS\S-1-5-21-2163585369-2416861267-2377926666-1000\Software\SecuROM\License information*]
"datasecu"=hex:85,92,3b,75,01,f9,99,07,59,55,03,9b,32,1b,2c,74,9e,3d,7b,ab,ba,
f2,b7,ca,ed,2d,a4,e9,8b,30,d7,e6,42,59,4c,cc,f7,44,73,5c,ac,c3,be,81,06,6c,\
"rkeysecu"=hex:e2,b5,0b,06,cb,4c,8b,f9,dc,9e,45,f7,9f,5a,41,b8
.
Completion time: 2010-09-28 20:18:34
ComboFix-quarantined-files.txt 2010-09-29 00:18
Pre-Run: 26,456,289,280 bytes free
Post-Run: 26,407,981,056 bytes free
- - End Of File - - 63DA4B052590AD0CFE4056630330D24F