Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System Integrity Scan Wizard, Security System Protection Control Panel


  • This topic is locked This topic is locked
37 replies to this topic

#1 ghoempie

ghoempie

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 17 April 2008 - 10:57 AM

I've had the System Integrity Scan Wizard, PC-Antispyware, and Security System Protection Control Panel popups and my backround change to a blue colour. After reading some of the posts here and running Spybot Search and Destroy, Ad-Aware 2007, RegCure and Malwarebytes Anti-Malware it seems as if that problem was solved, but now everytime I put my pc on I get these messages:
The first one says "rundll32.exe - Bad Image : The application or DLL C:\WINDOWS\system32\qpfrsnow.dll is not a valid Windows image. Please check this against your installation diskette" and the second one says "RUNDLL -Error loading C:\WINDOWS\system32\qpfrsnow.dll%1 is not a valid Win32 application".
The disk that I got when I bought my pc was Windows XP Home Edition SP1. I downloaded SP2 from the internet.
I'm attaching all of the logs you need to assist me, because I don't know if and how badly my pc is still infected.
I attached 4 log files: 1. DSS Main.txt
2. DSS Extra.txt
3. Kaspersky
4. DSS Main.txt - after the Kaspersky report

Thank you for taking the time to look into my problem.

DSS MAIN.TXT

Deckard's System Scanner v20071014.68
Run by Parratjie on 2008-04-17 09:29:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
59: 2008-04-17 07:29:41 UTC - RP519 - Deckard's System Scanner Restore Point
58: 2008-04-17 07:17:28 UTC - RP518 - Removed Adobe Photoshop Album 2.0 Starter Edition
57: 2008-04-17 05:54:01 UTC - RP517 - RegCure Backup
56: 2008-04-17 05:53:27 UTC - RP516 - RegCure Backup
55: 2008-04-16 17:18:11 UTC - RP515 - System Checkpoint


-- First Restore Point --
1: 2008-04-12 05:45:23 UTC - RP461 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 2.5 GiB (less than 15%) free.


-- HijackThis (run as Parratjie.exe) -------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:33:29 AM, on 2008/04/17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\ZSSnp211.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Parratjie\Desktop\dss.exe
F:\HIJACK~1\Parratjie.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www4.king.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = dsl-cache.saix.net:8080
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [e43075dd] rundll32.exe "C:\WINDOWS\system32\qpfrsnow.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.antispywarebot.com
O15 - Trusted Zone: http://forum.astalavista.ms
O15 - Trusted Zone: http://www4.king.com
O15 - Trusted Zone: http://forums.techguy.org
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFramework/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://cdn2.zone.msn.com/binFramework/v10/...dy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://cdn2.zone.msn.com/binFramework/v10/...at.cab55579.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1198741601859
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1198741744515
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://cdn3.zone.msn.com/binFramework/v10/...xy.cab55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3511FFFE-ECE2-477E-A99B-6CBF41CECE5B}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9918 bytes

-- HijackThis Fixed Entries (F:\HIJACK~1\backups\) -----------------------------

backup-20080131-054942-486 O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
backup-20080131-054942-937 O21 - SSODL: aswmklt - {A0B8F6B5-85EC-48EA-9221-E2AC7094B645} - C:\WINDOWS\aswmklt.dll (file missing)

-- File Associations -----------------------------------------------------------

.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys <Not Verified; IVT Corporation; BlueSoleil©>
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 prosync1 (StarForce Protection Synchronization Driver v1) - c:\windows\system32\drivers\prosync1.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys <Not Verified; IVT Corporation; Windows ® 2000 DDK driver>
R3 BlueletSCOAudio (Bluetooth SCO Audio Service) - c:\windows\system32\drivers\blueletscoaudio.sys <Not Verified; IVT Corporation; Windows ® 2000 DDK driver>
R3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
R3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys <Not Verified; IVT Corporation; BlueSoleil>
R3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys <Not Verified; IVT Corporation; BlueSoleil>

S3 Ad-Watch Connect Filter (Ad-Watch Connect Kernel Filter) - c:\windows\system32\drivers\nsdriver.sys <Not Verified; Lavasoft AB; Ad-Watch Connections>
S3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys <Not Verified; IVT Corporation; BlueSoleil>
S3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys <Not Verified; IVT Corporation; Bluetooth USB Device Driver>
S3 GMSIPCI - d:\install\gmsipci.sys (file missing)
S3 NPF (NetGroup Packet Filter Driver) - c:\windows\system32\drivers\npf.sys <Not Verified; NetGroup - Politecnico di Torino; WinPcap Netgroup Packet Filter Driver>
S3 NTACCESS - d:\ntaccess.sys (file missing)
S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S3 SetupNTGLM7X - d:\ntglm7x.sys (file missing)
S3 Vsp - c:\windows\system32\drivers\vsp.sys
S3 ZSMC211 (USB PC Camera (ZS211)) - c:\windows\system32\drivers\zs211.sys <Not Verified; ZSMC Corporation; >


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 BlueSoleil Hid Service - c:\program files\ivt corporation\bluesoleil\btntservice.exe

S3 rpcapd (Remote Packet Capture Protocol v.0 (experimental)) - "c:\program files\winpcap\rpcapd.exe" -d -f "c:\program files\winpcap\rpcapd.ini" <Not Verified; NetGroup - Politecnico di Torino; Remote Packet Capture Daemon>
S4 Boonty Games - "c:\program files\common files\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318}
Description: LogMeIn Mirror Driver
Device ID: ROOT\DISPLAY\0000
Manufacturer: LogMeIn, Inc.
Name: LogMeIn Mirror Driver
PNP Device ID: ROOT\DISPLAY\0000
Service: lmimirr

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Bluetooth PAN Network Adapter
Device ID: ROOT\NET\0000
Manufacturer: IVT Corporation
Name: Bluetooth PAN Network Adapter
PNP Device ID: ROOT\NET\0000
Service: BT


-- Scheduled Tasks -------------------------------------------------------------

2008-04-17 08:58:01 262 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-04-17 06:35:54 390 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2008-02-29 13:37:19 324 --a------ C:\WINDOWS\Tasks\RegCure.job


-- Files created between 2008-03-17 and 2008-04-17 -----------------------------

2008-04-17 09:05:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-17 09:05:38 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-17 09:05:36 0 d-------- C:\WINDOWS\LastGood
2008-04-16 09:41:31 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Runes of Avalon 2
2008-04-16 06:41:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Malwarebytes
2008-04-16 06:41:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 06:41:35 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-15 10:41:51 0 d-------- C:\Documents and Settings\Parratjie\Application Data\BitTorrent
2008-04-15 10:41:34 0 d-------- C:\Program Files\DNA
2008-04-15 10:41:34 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DNA
2008-04-15 08:57:02 85056 -----n--- C:\WINDOWS\system32\qpfrsnow.dll
2008-04-12 07:45:11 103640 --ahs---- C:\WINDOWS\system32\kjSYIkkj.ini2
2008-04-12 07:44:59 273408 -----n--- C:\WINDOWS\system32\jkkIYSjk.dll
2008-04-12 07:40:35 4096 --a------ C:\WINDOWS\system32taack.dat
2008-04-12 07:40:35 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-04-12 07:40:32 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-04-12 07:40:31 4096 --a------ C:\WINDOWS\system32bdn.com
2008-04-12 07:40:10 0 d-------- C:\Documents and Settings\All Users\Application Data\kjcpwlsr
2008-04-12 07:39:53 39936 -----n--- C:\WINDOWS\system32\ljJcDWpM.dll
2008-04-07 21:12:01 0 d-------- C:\Documents and Settings\Parratjie\Application Data\SprillBermudeEng
2008-04-04 06:48:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Meridian93
2008-04-03 05:38:00 0 d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-01 06:47:36 0 d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-28 06:41:17 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Jane s Hotel Family Hero
2008-03-25 05:37:45 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Yatec Games
2008-03-20 22:29:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2


-- Find3M Report ---------------------------------------------------------------

2008-04-17 09:24:20 0 d-------- C:\Program Files\VeZA Route planner
2008-04-13 04:57:38 0 d-------- C:\Program Files\Java
2008-04-09 07:00:13 0 d-------- C:\Program Files\OFFICE11
2008-04-08 10:26:35 0 d-------- C:\Program Files\IncrediMail
2008-04-08 09:22:08 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-07 20:51:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\PlayFirst
2008-04-05 07:13:34 0 d-------- C:\Program Files\GamesBar
2008-04-05 07:13:29 0 d-------- C:\Program Files\Oberon Media
2008-04-01 06:40:58 0 d-------- C:\Program Files\Lavasoft
2008-04-01 06:39:57 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 06:37:24 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Wildfire
2008-03-27 19:35:51 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-21 07:23:28 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-14 20:28:40 218929 --a------ C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2008-03-07 19:09:20 0 d-------- C:\Program Files\PartyGaming
2008-03-06 16:52:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\eGames
2008-03-02 21:51:06 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DivX
2008-03-01 08:30:26 0 d-------- C:\Program Files\The Weather Channel FW
2008-02-29 19:21:11 0 d-------- C:\Documents and Settings\Parratjie\Application Data\iWin
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-02-21 20:13:43 0 d-------- C:\Documents and Settings\Parratjie\Application Data\MysteryStudio
2008-02-21 14:00:33 0 d-------- C:\Program Files\WinPcap
2008-02-21 14:00:21 0 d-------- C:\Program Files\IMMonitor
2008-02-17 09:49:22 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Bloom


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003/09/01 03:32 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004/04/23 06:24 AM]
"nwiz"="nwiz.exe" [2004/04/23 06:24 AM C:\WINDOWS\system32\nwiz.exe]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006/07/14 04:24 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008/03/29 08:37 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004/08/04 01:56 AM C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007/04/08 08:07 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008/01/11 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008/02/22 04:25 AM]
"e43075dd"="C:\WINDOWS\system32\qpfrsnow.dll" [2008/04/16 07:59 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006/11/30 09:49 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008/03/21 07:23 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004/08/04 01:56 AM]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008/04/15 10:41 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007/04/19 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007/05/25 03:22 PM 63040 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
C:\WINDOWS\Domino.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
"C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ




-- End of Deckard's System Scanner: finished at 2008-04-17 09:35:33 ------------



DSS EXTRA.TXT


Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® CPU 2.40GHz
Percentage of Memory in Use: 59%
Physical Memory (total/avail): 511.49 MiB / 207.4 MiB
Pagefile Memory (total/avail): 2015.87 MiB / 1654.38 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1916.86 MiB

A: is Removable (Unformatted)
C: is Fixed (NTFS) - 29.29 GiB total, 2.51 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is Fixed (NTFS) - 45.23 GiB total, 16.31 GiB free.

\\.\PHYSICALDRIVE0 - SAMSUNG SP0842N - 74.53 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 29.29 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 45.23 GiB - F:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AV: avast! antivirus 4.8.1169 [VPS 080416-1] v4.8.1169 (ALWIL Software)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Disabled:Yahoo! Messenger"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"F:\\MALWARE DESTROYER\\EMCO Malware Destroyer\\MalwareDestroyer.exe"="F:\\MALWARE DESTROYER\\EMCO Malware Destroyer\\MalwareDestroyer.exe:*:Enabled:Malware Scanner for Home User's"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"F:\\Ons Eie Internet File\\BitTorrent 6.3\\BitTorrent\\bittorrent.exe"="F:\\Ons Eie Internet File\\BitTorrent 6.3\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Parratjie\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=ANNA
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Parratjie
LOGONSERVER=\\ANNA
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\Program Files\IncrediMail\bin;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Common Files\Ulead Systems\DVD;F:\Image Converter Plus\ImageConverter Plus;
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\PARRAT~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\PARRAT~1\LOCALS~1\Temp
USERDOMAIN=ANNA
USERNAME=Parratjie
USERPROFILE=C:\Documents and Settings\Parratjie
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Parratjie (admin)
Administrator (new local, admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
33 Corners --> "C:\Program Files\Oberon Media\33 Corners\Uninstall.exe" "C:\Program Files\Oberon Media\33 Corners\install.log"
3D Ultra Minigolf Adventures --> "C:\Program Files\Oberon Media\3D Ultra Minigolf Adventures\Uninstall.exe" "C:\Program Files\Oberon Media\3D Ultra Minigolf Adventures\install.log"
7 Lands --> "F:\Ons Eie Internet File\Reflexive Games\7 Lands\ReflexiveArcade\unins000.exe"
7 Wonders --> "F:\Ons Eie Internet File\Reflexive Games\7 Wonders\ReflexiveArcade\unins000.exe"
80 Days --> "F:\Ons Eie Internet File\Reflexive Games\80 Days\ReflexiveArcade\unins000.exe"
ABC Island --> "F:\Ons Eie Internet File\Reflexive Games\ABC Island\ReflexiveArcade\unins000.exe"
Abra Academy --> "C:\Program Files\Oberon Media\Abra Academy\Uninstall.exe" "C:\Program Files\Oberon Media\Abra Academy\install.log"
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adventure Inlay --> "F:\Ons Eie Internet File\Reflexive Games\Adventure Inlay\ReflexiveArcade\unins000.exe"
Agatha Christie Death On The Nile --> "F:\Ons Eie Internet File\Reflexive Games\Death On The Nile\ReflexiveArcade\unins000.exe"
Agatha Christie Peril At End House --> "F:\Ons Eie Internet File\Reflexive Games\Agatha Christie Peril At End House\ReflexiveArcade\unins000.exe"
Age of Castles --> "F:\Ons Eie Internet File\Reflexive Games\Age of Castles\ReflexiveArcade\unins000.exe"
Age of Emerald --> "C:\Program Files\Oberon Media\Age of Emerald\Uninstall.exe" "C:\Program Files\Oberon Media\Age of Emerald\install.log"
Ahead InCD --> C:\WINDOWS\NuNInst.exe /UNINSTALL
Airport Mania --> "F:\Ons Eie Internet File\Reflexive Games\Airport Mania\ReflexiveArcade\unins000.exe"
Alice Greenfingers --> "F:\Ons Eie Internet File\Reflexive Games\Alice Greenfingers\ReflexiveArcade\unins000.exe"
All-Time Sudoku --> "C:\Program Files\Oberon Media\All-Time Sudoku\Uninstall.exe" "C:\Program Files\Oberon Media\All-Time Sudoku\install.log"
Amazing Adventures The Lost Tomb --> "F:\Ons Eie Internet File\Reflexive Games\Amazing Adventures The Lost Tomb\ReflexiveArcade\unins000.exe"
Amazonia --> "F:\Ons Eie Internet File\Reflexive Games\Amazonia\ReflexiveArcade\unins000.exe"
Ancient Spider Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Ancient Spider Solitaire\ReflexiveArcade\unins000.exe"
Ancient Sudoku --> "F:\Ons Eie Internet File\Reflexive Games\Ancient Sudoku\ReflexiveArcade\unins000.exe"
Ancient Wonderland --> "C:\Program Files\Oberon Media\Ancient Wonderland\Uninstall.exe" "C:\Program Files\Oberon Media\Ancient Wonderland\install.log"
Animal Empire --> "F:\Ons Eie Internet File\Reflexive Games\Animal Empire\ReflexiveArcade\unins000.exe"
Ant War --> "F:\Ons Eie Internet File\Reflexive Games\Ant War\ReflexiveArcade\unins000.exe"
Aqua Pearls --> "F:\Ons Eie Internet File\Reflexive Games\Aqua Pearls\ReflexiveArcade\unins000.exe"
Aquabble Avalanche --> "F:\Ons Eie Internet File\Reflexive Games\Aquabble Avalanche\ReflexiveArcade\unins000.exe"
Aquacade --> "F:\Ons Eie Internet File\Reflexive Games\Aquacade\ReflexiveArcade\unins000.exe"
AquaPark --> "C:\Program Files\MSN Games\AquaPark\Uninstall.exe" "C:\Program Files\MSN Games\AquaPark\install.log"
AquaPark --> "F:\Ons Eie Internet File\Reflexive Games\AquaPark\ReflexiveArcade\unins000.exe"
AquaPOP --> "F:\Ons Eie Internet File\Reflexive Games\AquaPOP\ReflexiveArcade\unins000.exe"
Arabella the Fairy --> "C:\Program Files\Oberon Media\Arabella the Fairy\Uninstall.exe" "C:\Program Files\Oberon Media\Arabella the Fairy\install.log"
Arcadia REMIX --> "C:\Program Files\Oberon Media\Arcadia REMIX\Uninstall.exe" "C:\Program Files\Oberon Media\Arcadia REMIX\install.log"
Archipelago --> "F:\Ons Eie Internet File\Reflexive Games\Archipelago\ReflexiveArcade\unins000.exe"
ArchMage --> "C:\Program Files\Oberon Media\ArchMage\Uninstall.exe" "C:\Program Files\Oberon Media\ArchMage\install.log"
Arctic Quest --> "F:\Ons Eie Internet File\Reflexive Games\Arctic Quest\ReflexiveArcade\unins000.exe"
Arctic Quest 2 --> "F:\Ons Eie Internet File\Reflexive Games\Arctic Quest 2\ReflexiveArcade\unins000.exe"
Arxon --> "F:\Ons Eie Internet File\Reflexive Games\Arxon\ReflexiveArcade\unins000.exe"
Atlantis (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Atlantis\Uninstall.exe
Atlantis Adventure --> "F:\Ons Eie Internet File\Reflexive Games\Atlantis Adventure\ReflexiveArcade\unins000.exe"
Atlantis Sky Patrol --> "F:\Ons Eie Internet File\Reflexive Games\Atlantis Sky Patrol\ReflexiveArcade\unins000.exe"
Autodesk Design Review 2008 --> MsiExec.exe /I{FACF203E-0F4D-489A-B80C-D185253C8FCB}
AutoImager --> "C:\Documents and Settings\All Users\Application Data\{C0E25C17-3952-4684-8CE2-B00A1270A074}\setup_ai.exe" REMOVE=TRUE MODIFY=FALSE
AutoImager --> C:\Documents and Settings\All Users\Application Data\{C0E25C17-3952-4684-8CE2-B00A1270A074}\setup_ai.exe
Avalanche --> "F:\Ons Eie Internet File\Reflexive Games\Avalanche\ReflexiveArcade\unins000.exe"
avast! Antivirus --> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Aveyond 2 --> "F:\Ons Eie Internet File\Reflexive Games\Aveyond 2\ReflexiveArcade\unins000.exe"
Azada --> "F:\Ons Eie Internet File\Reflexive Games\Azada\ReflexiveArcade\unins000.exe"
Babel Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Babel Deluxe\ReflexiveArcade\unins000.exe"
Baby Luv --> "F:\Ons Eie Internet File\Reflexive Games\Baby Luv\ReflexiveArcade\unins000.exe"
Babysitting Mania --> "F:\Ons Eie Internet File\Reflexive Games\Babysitting Mania\ReflexiveArcade\unins000.exe"
Ballhalla --> "F:\Ons Eie Internet File\Reflexive Games\Ballhalla\ReflexiveArcade\unins000.exe"
Balloon Blast --> "F:\Ons Eie Internet File\Reflexive Games\Balloon Blast\ReflexiveArcade\unins000.exe"
Band Of Bugs --> "F:\Ons Eie Internet File\Reflexive Games\Band Of Bugs\ReflexiveArcade\unins000.exe"
Barrel Mania --> "F:\Ons Eie Internet File\Reflexive Games\Barrel Mania\ReflexiveArcade\unins000.exe"
Beads --> "F:\Ons Eie Internet File\Reflexive Games\Beads\ReflexiveArcade\unins000.exe"
Beesly's Buzzwords --> "F:\Ons Eie Internet File\Reflexive Games\Beesly's Buzzwords\ReflexiveArcade\unins000.exe"
Beetle Bomp --> "F:\Ons Eie Internet File\Reflexive Games\Beetle Bomp\ReflexiveArcade\unins000.exe"
Bejeweled 2 Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Bejeweled 2 Deluxe\ReflexiveArcade\unins000.exe"
Believe In Santa --> "F:\Ons Eie Internet File\Reflexive Games\Believe In Santa\ReflexiveArcade\unins000.exe"
BeTrapped! --> "C:\Program Files\Oberon Media\BeTrapped!\Uninstall.exe" "C:\Program Files\Oberon Media\BeTrapped!\install.log"
Betty's Beer Bar --> "F:\Ons Eie Internet File\Reflexive Games\Betty's Beer Bar\ReflexiveArcade\unins000.exe"
Big City Adventure San Francisco --> "F:\Ons Eie Internet File\Reflexive Games\Big City Adventure San Francisco\ReflexiveArcade\unins000.exe"
Big City Adventure Sydney Australia --> "F:\Ons Eie Internet File\Reflexive Games\Big City Adventure Sydney Australia\ReflexiveArcade\unins000.exe"
Big Fish Games Client --> C:\Program Files\bfgclient\Uninstall.exe
Big Island Blends --> "F:\Ons Eie Internet File\Reflexive Games\Big Island Blends\ReflexiveArcade\unins000.exe"
Big Kahuna Reef 2 - Chain Reaction --> "F:\Ons Eie Internet File\Reflexive Games\Big Kahuna Reef 2\ReflexiveArcade\unins000.exe"
Bird Pirates --> "C:\Program Files\Oberon Media\Bird Pirates\Uninstall.exe" "C:\Program Files\Oberon Media\Bird Pirates\install.log"
Birdies --> "F:\Ons Eie Internet File\Reflexive Games\Birdies\ReflexiveArcade\unins000.exe"
Birds On A Wire --> "F:\Ons Eie Internet File\Reflexive Games\Birds On A Wire\ReflexiveArcade\unins000.exe"
BitTorrent --> F:\Ons Eie Internet File\BitTorrent 6.3\BitTorrent\uninst.exe
Blobbeez --> "C:\Program Files\Oberon Media\Blobbeez\Uninstall.exe" "C:\Program Files\Oberon Media\Blobbeez\install.log"
Blokus World Tour --> "F:\Ons Eie Internet File\Reflexive Games\Blokus World Tour\ReflexiveArcade\unins000.exe"
Blood Ties --> "F:\Ons Eie Internet File\Reflexive Games\Blood Ties\ReflexiveArcade\unins000.exe"
Bloom --> "F:\Ons Eie Internet File\Reflexive Games\Bloom\ReflexiveArcade\unins000.exe"
BlueSoleil --> MsiExec.exe /X{38F0F8B4-3786-42D6-A82C-DF1FEB010C46}
Boggle --> "F:\Ons Eie Internet File\Reflexive Games\Boggle\ReflexiveArcade\unins000.exe"
Book Stories --> "C:\Program Files\Oberon Media\Book Stories\Uninstall.exe" "C:\Program Files\Oberon Media\Book Stories\install.log"
Bookworm Adventures Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Bookworm Adventures Deluxe\ReflexiveArcade\unins000.exe"
Boorps Balls --> "F:\Ons Eie Internet File\Reflexive Games\Boorps Balls\ReflexiveArcade\unins000.exe"
Brain Booster --> "C:\Program Files\Oberon Media\Brain Booster\Uninstall.exe" "C:\Program Files\Oberon Media\Brain Booster\install.log"
Brainiversity --> "C:\Program Files\Oberon Media\Brainiversity\Uninstall.exe" "C:\Program Files\Oberon Media\Brainiversity\install.log"
Brave Dwarves Back For Treasures --> "F:\Ons Eie Internet File\Reflexive Games\Brave Dwarves Back For Treasures\ReflexiveArcade\unins000.exe"
Brave Piglet --> "F:\Ons Eie Internet File\Reflexive Games\Brave Piglet\ReflexiveArcade\unins000.exe"
Breaking News --> "F:\Ons Eie Internet File\Reflexive Games\Breaking News\ReflexiveArcade\unins000.exe"
Brian Lara Cricket Demo --> C:\WINDOWS\IsUninst.exe -f"C:\Codemasters\Brian Lara Cricket Demo\Uninst.isu"
Brick Journey --> "F:\Ons Eie Internet File\Reflexive Games\Brick Journey\ReflexiveArcade\unins000.exe"
Bricktopia --> "F:\Ons Eie Internet File\Reflexive Games\Bricktopia\ReflexiveArcade\unins000.exe"
Bubble Bay --> "F:\Ons Eie Internet File\Reflexive Games\Bubble Bay\ReflexiveArcade\unins000.exe"
Bubble Shooter Premium Edition --> "C:\Program Files\Oberon Media\Bubble Shooter Premium Edition\Uninstall.exe" "C:\Program Files\Oberon Media\Bubble Shooter Premium Edition\install.log"
Bubble Shooter Premium Edition --> "F:\Ons Eie Internet File\Reflexive Games\Bubble Shooter Premium Edition\ReflexiveArcade\unins000.exe"
Buildalot --> "F:\Ons Eie Internet File\Reflexive Games\Buildalot\ReflexiveArcade\unins000.exe"
Bullet Candy --> "F:\Ons Eie Internet File\Reflexive Games\Bullet Candy\ReflexiveArcade\unins000.exe"
Burger Island --> "F:\Ons Eie Internet File\Reflexive Games\Burger Island\ReflexiveArcade\unins000.exe"
Burger Shop --> "C:\Program Files\Oberon Media\Burger Shop\Uninstall.exe" "C:\Program Files\Oberon Media\Burger Shop\install.log"
Butterfly Escape --> "F:\Ons Eie Internet File\Reflexive Games\Butterfly Escape\ReflexiveArcade\unins000.exe"
Cake Mania --> "C:\Program Files\Oberon Media\Cake Mania\Uninstall.exe" "C:\Program Files\Oberon Media\Cake Mania\install.log"
Cake Mania 2 --> "C:\Program Files\MSN Games\Cake Mania 2\Uninstall.exe" "C:\Program Files\MSN Games\Cake Mania 2\install.log"
Candace Kanes Candy Factory --> "C:\Program Files\Oberon Media\Candace Kanes Candy Factory\Uninstall.exe" "C:\Program Files\Oberon Media\Candace Kanes Candy Factory\install.log"
Candy Crisis --> "C:\Program Files\Oberon Media\Candy Crisis\Uninstall.exe" "C:\Program Files\Oberon Media\Candy Crisis\install.log"
Capitalism II --> "F:\Ons Eie Internet File\Reflexive Games\Capitalism II\ReflexiveArcade\unins000.exe"
Card Tricks --> "C:\Program Files\Oberon Media\Card Tricks\Uninstall.exe" "C:\Program Files\Oberon Media\Card Tricks\install.log"
Carrie the Caregiver --> "C:\Program Files\Oberon Media\Carrie the Caregiver\Uninstall.exe" "C:\Program Files\Oberon Media\Carrie the Caregiver\install.log"
Casino Island To Go (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Casino Island To Go\Uninstall.exe
Casper's Spooky Swap --> "C:\Program Files\Oberon Media\Caspers Spooky Swap\Uninstall.exe" "C:\Program Files\Oberon Media\Caspers Spooky Swap\install.log"
Catan - The Computer Game --> "C:\Program Files\Oberon Media\Catan - The Computer Game\Uninstall.exe" "C:\Program Files\Oberon Media\Catan - The Computer Game\install.log"
Cathys Caribbean Club --> "F:\Ons Eie Internet File\Reflexive Games\Cathys Caribbean Club\ReflexiveArcade\unins000.exe"
Chaks Temple --> "F:\Ons Eie Internet File\Reflexive Games\Chaks Temple\ReflexiveArcade\unins000.exe"
Charm Tale --> "F:\Ons Eie Internet File\Reflexive Games\Charm Tale\ReflexiveArcade\unins000.exe"
Chicken Chase --> "F:\Ons Eie Internet File\Reflexive Games\Chicken Chase\ReflexiveArcade\unins000.exe"
Chicken Invaders 3 --> "F:\Ons Eie Internet File\Reflexive Games\Chicken Invaders 3\ReflexiveArcade\unins000.exe"
Chicken Rush Deluxe --> "C:\Program Files\Oberon Media\Chicken Rush Deluxe\Uninstall.exe" "C:\Program Files\Oberon Media\Chicken Rush Deluxe\install.log"
Chicken Village --> "F:\Ons Eie Internet File\Reflexive Games\Chicken Village\ReflexiveArcade\unins000.exe"
Chocolate Castle --> "F:\Ons Eie Internet File\Reflexive Games\Chocolate Castle\ReflexiveArcade\unins000.exe"
Chocolatier --> "F:\Ons Eie Internet File\Reflexive Games\Chocolatier\ReflexiveArcade\unins000.exe"
Chocolatier 2 --> "F:\Ons Eie Internet File\Reflexive Games\Chocolatier 2\ReflexiveArcade\unins000.exe"
Choo Choo Challenge --> "C:\Program Files\Oberon Media\Choo Choo Challenge\Uninstall.exe" "C:\Program Files\Oberon Media\Choo Choo Challenge\install.log"
Christmasville --> "F:\Ons Eie Internet File\Reflexive Games\Christmasville\ReflexiveArcade\unins000.exe"
Chroma Crash --> "C:\Program Files\Oberon Media\Chroma Crash\Uninstall.exe" "C:\Program Files\Oberon Media\Chroma Crash\install.log"
Chuzzle Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Chuzzle Deluxe\ReflexiveArcade\unins000.exe"
Cindys Sundaes --> "F:\Ons Eie Internet File\Reflexive Games\Cindys Sundaes\ReflexiveArcade\unins000.exe"
Click O Pack --> "F:\Ons Eie Internet File\Reflexive Games\Click O Pack\ReflexiveArcade\unins000.exe"
Coffee Rush --> "F:\Ons Eie Internet File\Reflexive Games\Coffee Rush\ReflexiveArcade\unins000.exe"
Colony --> "F:\Ons Eie Internet File\Reflexive Games\Colony\ReflexiveArcade\unins000.exe"
Concentration --> "F:\Ons Eie Internet File\Reflexive Games\Concentration\ReflexiveArcade\unins000.exe"
Conexant 56K PCI Soft Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F00&SUBSYS_8D8A122D\HXFSETUP.EXE -U -Iazt3885k.inf
Cookie Chef --> "F:\Ons Eie Internet File\Reflexive Games\Cookie Chef\ReflexiveArcade\unins000.exe"
Cosmic Stacker --> "F:\Ons Eie Internet File\Reflexive Games\Cosmic Stacker\ReflexiveArcade\unins000.exe"
Cradle Of Rome --> "F:\Ons Eie Internet File\Reflexive Games\Cradle Of Rome\ReflexiveArcade\unins000.exe"
Crazy Eggs --> "C:\Program Files\Oberon Media\Crazy Eggs\Uninstall.exe" "C:\Program Files\Oberon Media\Crazy Eggs\install.log"
Cribbage Quest --> "C:\Program Files\Oberon Media\Cribbage Quest\Uninstall.exe" "C:\Program Files\Oberon Media\Cribbage Quest\install.log"
Cricket World Cup 1999 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\EA Sports\Cricket World Cup 1999\Uninst.isu"
Cubozoid --> "F:\Ons Eie Internet File\Reflexive Games\Cubozoid\ReflexiveArcade\unins000.exe"
Cute Knight --> "F:\Ons Eie Internet File\Reflexive Games\Cute Knight\ReflexiveArcade\unins000.exe"
Daycare Nightmare --> "F:\Ons Eie Internet File\Reflexive Games\Daycare Nightmare\ReflexiveArcade\unins000.exe"
Deep Blue Sea --> "F:\Ons Eie Internet File\Reflexive Games\Deep Blue Sea\ReflexiveArcade\unins000.exe"
Deep Sea Adventures --> "F:\Ons Eie Internet File\Reflexive Games\Deep Sea Adventures\ReflexiveArcade\unins000.exe"
Deep Sea Tycoon 2 --> "F:\Ons Eie Internet File\Reflexive Games\Deep Sea Tycoon 2\ReflexiveArcade\unins000.exe"
Delivery King --> "F:\Ons Eie Internet File\Reflexive Games\Delivery King\ReflexiveArcade\unins000.exe"
Diamond Detective --> "F:\Ons Eie Internet File\Reflexive Games\Diamond Detective\ReflexiveArcade\unins000.exe"
Digby's Donuts --> "F:\Ons Eie Internet File\Reflexive Games\Digby's Donuts\ReflexiveArcade\unins000.exe"
Digi Pool --> "F:\Ons Eie Internet File\Reflexive Games\Digi Pool\ReflexiveArcade\unins000.exe"
Diner Dash 2 --> "F:\Ons Eie Internet File\Reflexive Games\Diner Dash 2\ReflexiveArcade\unins000.exe"
Diner Dash Flo On The Go --> "F:\Ons Eie Internet File\Reflexive Games\Diner Dash Flo On The Go\ReflexiveArcade\unins000.exe"
Diner Dash Hometown Hero --> "F:\Ons Eie Internet File\Reflexive Games\Diner Dash Hometown Hero\ReflexiveArcade\unins000.exe"
Discord Times --> "F:\Ons Eie Internet File\Reflexive Games\Discord Times\ReflexiveArcade\unins000.exe"
Discovering Nature --> "F:\Ons Eie Internet File\Reflexive Games\Discovering Nature\ReflexiveArcade\unins000.exe"
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
DNA --> "F:\Ons Eie Internet File\Reflexive Games\DNA\ReflexiveArcade\unins000.exe"
Doggie Dash --> "F:\Ons Eie Internet File\Reflexive Games\Doggie Dash\ReflexiveArcade\unins000.exe"
Downbeat --> "C:\Program Files\Oberon Media\Downbeat\Uninstall.exe" "C:\Program Files\Oberon Media\Downbeat\install.log"
Dr Daisy Pet Vet --> "C:\Program Files\Oberon Media\Dr Daisy Pet Vet\Uninstall.exe" "C:\Program Files\Oberon Media\Dr Daisy Pet Vet\install.log"
Dr Germ --> "F:\Ons Eie Internet File\Reflexive Games\Dr Germ\ReflexiveArcade\unins000.exe"
Dragon --> "C:\Program Files\Oberon Media\Dragon\Uninstall.exe" "C:\Program Files\Oberon Media\Dragon\install.log"
Dream Chronicles --> "F:\Ons Eie Internet File\Reflexive Games\Dream Chronicles\ReflexiveArcade\unins000.exe"
Dream Chronicles 2 --> "F:\Ons Eie Internet File\Reflexive Games\Dream Chronicles 2\ReflexiveArcade\unins000.exe"
Dream Day First Home --> "C:\Program Files\Oberon Media\Dream Day First Home\Uninstall.exe" "C:\Program Files\Oberon Media\Dream Day First Home\install.log"
Dream Day Honeymoon --> "F:\Ons Eie Internet File\Reflexive Games\Dream Day Honeymoon\ReflexiveArcade\unins000.exe"
Dream Day Wedding --> "F:\Ons Eie Internet File\Reflexive Games\Dream Day Wedding\ReflexiveArcade\unins000.exe"
Dream Vacation Solitaire --> "C:\Program Files\Oberon Media\Dream Vacation Solitaire\Uninstall.exe" "C:\Program Files\Oberon Media\Dream Vacation Solitaire\install.log"
Dress Shop Hop --> "C:\Program Files\Oberon Media\Dress Shop Hop\Uninstall.exe" "C:\Program Files\Oberon Media\Dress Shop Hop\install.log"
Dress Shop Hop --> "F:\Ons Eie Internet File\Reflexive Games\Dress Shop Hop\ReflexiveArcade\unins000.exe"
Dungeon Scroll Gold Edition --> "F:\Ons Eie Internet File\Reflexive Games\Dungeon Scroll Gold Edition\ReflexiveArcade\unins000.exe"
ebgcInfra --> MsiExec.exe /X{39B1BD87-561E-4762-AED9-7C5213B06C24}
ebgcRes --> MsiExec.exe /X{B99C4D88-A353-4DE5-A0F4-D4D52D35966F}
ebgcSDK --> MsiExec.exe /X{53B2D537-21CF-44D5-A03A-0DAF993B5728}
El Dorado Quest --> "F:\Ons Eie Internet File\Reflexive Games\El Dorado Quest\ReflexiveArcade\unins000.exe"
Elemental --> "F:\Ons Eie Internet File\Reflexive Games\Elemental\ReflexiveArcade\unins000.exe"
Elven Mists --> "C:\Program Files\Oberon Media\Elven Mists\Uninstall.exe" "C:\Program Files\Oberon Media\Elven Mists\install.log"
EMCO Malware Destroyer --> "F:\MALWARE DESTROYER\EMCO Malware Destroyer\unins000.exe"
Emerald Tale --> "F:\Ons Eie Internet File\Reflexive Games\Emerald Tale\ReflexiveArcade\unins000.exe"
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
Escape From Paradise --> "F:\Ons Eie Internet File\Reflexive Games\Escape From Paradise\ReflexiveArcade\unins000.exe"
Escape The Museum --> "F:\Ons Eie Internet File\Reflexive Games\Escape The Museum\ReflexiveArcade\unins000.exe"
Exocubes --> "F:\Ons Eie Internet File\Reflexive Games\Exocubes\ReflexiveArcade\unins000.exe"
Fairies (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Fairies\Uninstall.exe
Fairway Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Fairway Solitaire\ReflexiveArcade\unins000.exe"
Fairy Godmother Tycoon --> "F:\Ons Eie Internet File\Reflexive Games\Fairy Godmother Tycoon\ReflexiveArcade\unins000.exe"
Family Restaurant --> "C:\Program Files\Oberon Media\Family Restaurant\Uninstall.exe" "C:\Program Files\Oberon Media\Family Restaurant\install.log"
Farm Frenzy --> "F:\Ons Eie Internet File\Reflexive Games\Farm Frenzy\ReflexiveArcade\unins000.exe"
Fashion Craze --> "C:\Program Files\Oberon Media\Fashion Craze\Uninstall.exe" "C:\Program Files\Oberon Media\Fashion Craze\install.log"
Fashion Craze --> "F:\Ons Eie Internet File\Reflexive Games\Fashion Craze\ReflexiveArcade\unins000.exe"
Fashion Fits --> "F:\Ons Eie Internet File\Reflexive Games\Fashion Fits\ReflexiveArcade\unins000.exe"
Fashion Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Fashion Solitaire\ReflexiveArcade\unins000.exe"
Fatal Hearts --> "F:\Ons Eie Internet File\Reflexive Games\Fatal Hearts\ReflexiveArcade\unins000.exe"
Fate --> "C:\Program Files\Oberon Media\Fate\Uninstall.exe" "C:\Program Files\Oberon Media\Fate\install.log"
Fatman Adventures --> "F:\Ons Eie Internet File\Reflexive Games\Fatman Adventures\ReflexiveArcade\unins000.exe"
Feelers --> "F:\Ons Eie Internet File\Reflexive Games\Feelers\ReflexiveArcade\unins000.exe"
Fever Frenzy --> "F:\Ons Eie Internet File\Reflexive Games\Fever Frenzy\ReflexiveArcade\unins000.exe"
Finders Keepers --> "F:\Ons Eie Internet File\Reflexive Games\Finders Keepers\ReflexiveArcade\unins000.exe"
Fire Flower --> "C:\Program Files\Oberon Media\Fire Flower\Uninstall.exe" "C:\Program Files\Oberon Media\Fire Flower\install.log"
Fireworks Extravaganza --> "F:\Ons Eie Internet File\Reflexive Games\Fireworks Extravaganza\ReflexiveArcade\unins000.exe"
Fishing Trip --> "F:\Ons Eie Internet File\Reflexive Games\Fishing Trip\ReflexiveArcade\unins000.exe"
Flower Quest --> "F:\Ons Eie Internet File\Reflexive Games\Flower Quest\ReflexiveArcade\unins000.exe"
Flower Shop - Big City Break (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Flower Shop - Big City Break\Uninstall.exe
Flower Stand Tycoon (remove only) --> "F:\Ons Eie Internet File\Flowerstand Tycoon\Flower Stand Tycoon\Uninst.exe"
Flowery Vale --> "F:\Ons Eie Internet File\Reflexive Games\Flowery Vale\ReflexiveArcade\unins000.exe"
Forgotten Riddles The Mayan Princess --> "F:\Ons Eie Internet File\Reflexive Games\Forgotten Riddles The Mayan Princess\ReflexiveArcade\unins000.exe"
Freaky Freezeday --> "C:\Program Files\Oberon Media\Freaky Freezeday\Uninstall.exe" "C:\Program Files\Oberon Media\Freaky Freezeday\install.log"
Full Circle --> "F:\Ons Eie Internet File\Reflexive Games\Full Circle\ReflexiveArcade\unins000.exe"
Funky Farm --> "F:\Ons Eie Internet File\Reflexive Games\Funky Farm\ReflexiveArcade\unins000.exe"
Galapago --> "C:\Program Files\Oberon Media\Galapago\Uninstall.exe" "C:\Program Files\Oberon Media\Galapago\install.log"
Galapago (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Galapago\Uninstall.exe
Gallop for Gold --> "C:\Program Files\Oberon Media\Gallop for Gold\Uninstall.exe" "C:\Program Files\Oberon Media\Gallop for Gold\install.log"
Garfield Goes to Pieces --> "F:\Ons Eie Internet File\Reflexive Games\Garfield Goes to Pieces\ReflexiveArcade\unins000.exe"
Gazillionaire III --> "F:\Ons Eie Internet File\Reflexive Games\Gazillionaire III\ReflexiveArcade\unins000.exe"
Geeks Unleashed --> "C:\Program Files\Oberon Media\Geeks Unleashed\Uninstall.exe" "C:\Program Files\Oberon Media\Geeks Unleashed\install.log"
Gem Mine --> "F:\Ons Eie Internet File\Reflexive Games\Gem Mine\ReflexiveArcade\unins000.exe"
Geom --> "F:\Ons Eie Internet File\Reflexive Games\Geom\ReflexiveArcade\unins000.exe"
Glow Worm --> "F:\Ons Eie Internet File\Reflexive Games\Glow Worm\ReflexiveArcade\unins000.exe"
Glyph --> "C:\Program Files\Oberon Media\Glyph\Uninstall.exe" "C:\Program Files\Oberon Media\Glyph\install.log"
Go-Go Gourmet --> "C:\Program Files\Oberon Media\Go-Go Gourmet\Uninstall.exe" "C:\Program Files\Oberon Media\Go-Go Gourmet\install.log"
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
Great Escapes Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Great Escapes Solitaire\ReflexiveArcade\unins000.exe"
Great Secrets Da Vinci --> "F:\Ons Eie Internet File\Reflexive Games\Great Secrets Da Vinci\ReflexiveArcade\unins000.exe"
Grimms Hatchery --> "F:\Ons Eie Internet File\Reflexive Games\Grimms Hatchery\ReflexiveArcade\unins000.exe"
Hangman Wild West 2 --> "F:\Ons Eie Internet File\Reflexive Games\Hangman Wild West 2\ReflexiveArcade\unins000.exe"
Happy Hour --> "F:\Ons Eie Internet File\Reflexive Games\Happy Hour\ReflexiveArcade\unins000.exe"
Harvest Mania To Go --> "F:\Ons Eie Internet File\Reflexive Games\Harvest Mania To Go\ReflexiveArcade\unins000.exe"
Hawaiian Explorer Pearl Harbor --> "F:\Ons Eie Internet File\Reflexive Games\Hawaiian Explorer Pearl Harbor\ReflexiveArcade\unins000.exe"
Hidden Expedition Everest --> "F:\Ons Eie Internet File\Reflexive Games\Hidden Expedition Everest\ReflexiveArcade\unins000.exe"
Hidden Expedition Titanic --> "F:\Ons Eie Internet File\Reflexive Games\Hidden Expedition Titanic\ReflexiveArcade\unins000.exe"
Hidden Relics --> "F:\Ons Eie Internet File\Reflexive Games\Hidden Relics\ReflexiveArcade\unins000.exe"
Hidden Secrets The Nightmare --> "F:\Ons Eie Internet File\Reflexive Games\Hidden Secrets The Nightmare\ReflexiveArcade\unins000.exe"
Hide And Secret --> "F:\Ons Eie Internet File\Reflexive Games\Hide And Secret\ReflexiveArcade\unins000.exe"
High Seas The Family Fortune --> "F:\Ons Eie Internet File\Reflexive Games\High Seas The Family Fortune\ReflexiveArcade\unins000.exe"
HijackThis 2.0.2 --> "F:\HIJACK THIS\HijackThis.exe" /uninstall
Holiday Gift --> "F:\Ons Eie Internet File\Reflexive Games\Holiday Gift\ReflexiveArcade\unins000.exe"
Holly A Christmas Tale --> "F:\Ons Eie Internet File\Reflexive Games\Holly A Christmas Tale\ReflexiveArcade\unins000.exe"
Home Sweet Home --> "F:\Ons Eie Internet File\Reflexive Games\Home Sweet Home\ReflexiveArcade\unins000.exe"
Hoteis Jewels --> "F:\Ons Eie Internet File\Reflexive Games\Hoteis Jewels\ReflexiveArcade\unins000.exe"
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hyperballoid Golden Pack --> "F:\Ons Eie Internet File\Reflexive Games\Hyperballoid Golden Pack\ReflexiveArcade\unins000.exe"
Ice Age --> "F:\Ons Eie Internet File\Reflexive Games\Ice Age\ReflexiveArcade\unins000.exe"
Ice Cream Tycoon (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Ice Cream Tycoon\Uninstall.exe
Icy Spell --> "F:\Ons Eie Internet File\Reflexive Games\Icy Spell\ReflexiveArcade\unins000.exe"
Inca Ball (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Inca Ball\Uninstall.exe
IncrediMail Xe --> C:\Program Files\IncrediMail\bin\ImSetup.exe /remove /addon:IncrediMail /log:IncMail.log
Ingenious --> "F:\Ons Eie Internet File\Reflexive Games\Ingenious\ReflexiveArcade\unins000.exe"
Inspector-Parker --> "C:\Program Files\Oberon Media\Inspector-Parker\Uninstall.exe" "C:\Program Files\Oberon Media\Inspector-Parker\install.log"
Inspector Parker --> "F:\Ons Eie Internet File\Reflexive Games\Inspector Parker\ReflexiveArcade\unins000.exe"
Interpol The Trail Of Dr Chaos --> "F:\Ons Eie Internet File\Reflexive Games\Interpol The Trail Of Dr Chaos\ReflexiveArcade\unins000.exe"
IQ Identity Quest --> "F:\Ons Eie Internet File\Reflexive Games\IQ Identity Quest\ReflexiveArcade\unins000.exe"
Island Wars 2 --> "F:\Ons Eie Internet File\Reflexive Games\Island Wars 2\ReflexiveArcade\unins000.exe"
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Jackpot Matchup --> "F:\Ons Eie Internet File\Reflexive Games\Jackpot Matchup\ReflexiveArcade\unins000.exe"
Janes Hotel --> "F:\Ons Eie Internet File\Reflexive Games\Janes Hotel\ReflexiveArcade\unins000.exe"
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Jericho Mirage --> "C:\Program Files\Oberon Media\Jericho Mirage\Uninstall.exe" "C:\Program Files\Oberon Media\Jericho Mirage\install.log"
Jewel Craft --> "F:\Ons Eie Internet File\Reflexive Games\Jewel Craft\ReflexiveArcade\unins000.exe"
Jewel Quest --> "F:\Ons Eie Internet File\Reflexive Games\Jewel Quest\ReflexiveArcade\unins000.exe"
Jewel Quest 2 --> "F:\Ons Eie Internet File\Reflexive Games\Jewel Quest 2\ReflexiveArcade\unins000.exe"
Jezzonix --> "F:\Ons Eie Internet File\Reflexive Games\Jezzonix\ReflexiveArcade\unins000.exe"
Jig Jag! --> "C:\Program Files\Oberon Media\Jig Jag!\Uninstall.exe" "C:\Program Files\Oberon Media\Jig Jag!\install.log"
Jigsaw Puzzle 2 Mix --> "C:\Program Files\Oberon Media\Jigsaw Puzzle 2 Mix\Uninstall.exe" "C:\Program Files\Oberon Media\Jigsaw Puzzle 2 Mix\install.log"
Jigsaw365 --> "F:\Ons Eie Internet File\Reflexive Games\Jigsaw365\ReflexiveArcade\unins000.exe"
Jojos Fashion Show --> "F:\Ons Eie Internet File\Reflexive Games\Jojos Fashion Show\ReflexiveArcade\unins000.exe"
Jungo --> "C:\Program Files\Oberon Media\Jungo\Uninstall.exe" "C:\Program Files\Oberon Media\Jungo\install.log"
Jungular --> "C:\Program Files\Oberon Media\Jungular\Uninstall.exe" "C:\Program Files\Oberon Media\Jungular\install.log"
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
King Kong Skull Island Adventure --> "F:\Ons Eie Internet File\Reflexive Games\King Kong Skull Island Adventure\ReflexiveArcade\unins000.exe"
KingMania --> "F:\Ons Eie Internet File\Reflexive Games\KingMania\ReflexiveArcade\unins000.exe"
Koi Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Koi Solitaire\ReflexiveArcade\unins000.exe"
Kudos --> "C:\Program Files\Oberon Media\Kudos\Uninstall.exe" "C:\Program Files\Oberon Media\Kudos\install.log"
Kudos Rock Legend --> "F:\Ons Eie Internet File\Reflexive Games\Kudos Rock Legend\ReflexiveArcade\unins000.exe"
LEGO Builder Bots --> "C:\Program Files\Oberon Media\LEGO Builder Bots\Uninstall.exe" "C:\Program Files\Oberon Media\LEGO Builder Bots\install.log"
LEGO Chic Boutique --> "C:\Program Files\Oberon Media\LEGO Chic Boutique\Uninstall.exe" "C:\Program Files\Oberon Media\LEGO Chic Boutique\install.log"
Letter Lab --> "F:\Ons Eie Internet File\Reflexive Games\Letter Lab\ReflexiveArcade\unins000.exe"
LexiCastle --> "F:\Ons Eie Internet File\Reflexive Games\LexiCastle\ReflexiveArcade\unins000.exe"
Little Shop Of Treasures --> "F:\Ons Eie Internet File\Reflexive Games\Little Shop Of Treasures\Little Shop Of Treasures\ReflexiveArcade\unins000.exe"
Loco --> "F:\Ons Eie Internet File\Reflexive Games\Loco\ReflexiveArcade\unins000.exe"
Lottso --> "C:\Program Files\Oberon Media\Lottso\Uninstall.exe" "C:\Program Files\Oberon Media\Lottso\install.log"
Lotus Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Lotus Deluxe\ReflexiveArcade\unins000.exe"
Luck Charm Deluxe --> "C:\Program Files\Oberon Media\Luck Charm Deluxe\Uninstall.exe" "C:\Program Files\Oberon Media\Luck Charm Deluxe\install.log"
Lucky Clover --> "F:\Ons Eie Internet File\Reflexive Games\Lucky Clover\ReflexiveArcade\unins000.exe"
Lumen --> "C:\Program Files\Oberon Media\Lumen\Uninstall.exe" "C:\Program Files\Oberon Media\Lumen\install.log"
Luxor 3 --> "F:\Ons Eie Internet File\Reflexive Games\Luxor 3\ReflexiveArcade\unins000.exe"
Magentic --> C:\PROGRA~1\Magentic\bin\mgsetup.exe /remove /addon:Magentic
Magic Academy --> "F:\Ons Eie Internet File\Reflexive Games\Magic Academy\ReflexiveArcade\unins000.exe"
Magic Blast --> "F:\Ons Eie Internet File\Reflexive Games\Magic Blast\ReflexiveArcade\unins000.exe"
Magic Farm --> "F:\Ons Eie Internet File\Reflexive Games\Magic Farm\ReflexiveArcade\unins000.exe"
Magic Shop --> "F:\Ons Eie Internet File\Reflexive Games\Magic Shop\ReflexiveArcade\unins000.exe"
Magic Tale --> "C:\Program Files\Oberon Media\Magic Tale\Uninstall.exe" "C:\Program Files\Oberon Media\Magic Tale\install.log"
Magic Tale --> "F:\Ons Eie Internet File\Reflexive Games\Magic Tale\ReflexiveArcade\unins000.exe"
Magic Tea --> "C:\Program Files\Oberon Media\Magic Tea\Uninstall.exe" "C:\Program Files\Oberon Media\Magic Tea\install.log"
Magic Vines (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Magic Vines\Uninstall.exe
Mahjongg Investigations Under Suspicion --> "C:\Program Files\Oberon Media\Mahjongg Investigations Under Suspicion\Uninstall.exe" "C:\Program Files\Oberon Media\Mahjongg Investigations Under Suspicion\install.log"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marblez --> "F:\Ons Eie Internet File\Reflexive Games\Marblez\ReflexiveArcade\unins000.exe"
Mariposa --> "F:\Ons Eie Internet File\Reflexive Games\Mariposa\ReflexiveArcade\unins000.exe"
Maui And The Big Fish --> "F:\Ons Eie Internet File\Reflexive Games\Maui And The Big Fish\ReflexiveArcade\unins000.exe"
Mega Flexicon --> "C:\Program Files\Oberon Media\Mega Flexicon\Uninstall.exe" "C:\Program Files\Oberon Media\Mega Flexicon\install.log"
MeggieSoft Games Compendium --> "C:\Program Files\MeggieSoft Games\unins000.exe"
Merriam Websters Spell Jam --> "C:\Program Files\Oberon Media\Merriam Websters Spell Jam\Uninstall.exe" "C:\Program Files\Oberon Media\Merriam Websters Spell Jam\install.log"
Mezzo Winter --> "C:\Program Files\Oberon Media\Mezzo Winter\Uninstall.exe" "C:\Program Files\Oberon Media\Mezzo Winter\install.log"
Microblots --> "F:\Ons Eie Internet File\Reflexive Games\Microblots\ReflexiveArcade\unins000.exe"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Excel Viewer 97 --> C:\Program Files\XLView\setup\setup.exe
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft PowerPoint Viewer 97 --> C:\Program Files\PowerPoint Viewer\setup\setup.exe
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Word Viewer 97 --> C:\Program Files\WordView\setup\setup.exe
MikeMary --> MsiExec.exe /I{1631F462-456E-11D6-B530-0000C0CE5D01}
Mind Machine --> "F:\Ons Eie Internet File\Reflexive Games\Mind Machine\ReflexiveArcade\unins000.exe"
Mind Your Marbles --> "F:\Ons Eie Internet File\Reflexive Games\Mind Your Marbles\ReflexiveArcade\unins000.exe"
Mirror Magic --> "F:\Ons Eie Internet File\Reflexive Games\Mirror Magic\ReflexiveArcade\unins000.exe"
Mirror Mixup --> "F:\Ons Eie Internet File\Reflexive Games\Mirror Mixup\ReflexiveArcade\unins000.exe"
Miss Teri Tale --> "F:\Ons Eie Internet File\Reflexive Games\Miss Teri Tale\ReflexiveArcade\unins000.exe"
Moleculous --> "F:\Ons Eie Internet File\Reflexive Games\Moleculous\ReflexiveArcade\unins000.exe"
Monkey Madness --> "C:\Program Files\Oberon Media\Monkey Madness\Uninstall.exe" "C:\Program Files\Oberon Media\Monkey Madness\install.log"
Mosaic Tomb of Mystery --> "F:\Ons Eie Internet File\Reflexive Games\Mosaic Tomb of Mystery\ReflexiveArcade\unins000.exe"
Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
mpowerplayer --> C:\WINDOWS\system32\javaws.exe -uninstall -prompt "http://content.mplayit.com/client/player.jarjnlp"
MSN Messenger Monitor Sniffer --> "C:\Program Files\IMMonitor\MSN Messenger Monitor Sniffer\unins000.exe"
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
My Farm --> "F:\Ons Eie Internet File\Reflexive Games\My Farm\ReflexiveArcade\unins000.exe"
Mystery Case Files - Prime Suspects (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Mystery Case Files - Prime Suspects\Uninstall.exe
Mystery Case Files Madame Fate --> "F:\Ons Eie Internet File\Reflexive Games\Mystery Case Files Madame Fate\ReflexiveArcade\unins000.exe"
Mystery Case Files Ravenhearst --> "F:\Ons Eie Internet File\Reflexive Games\Mystery Case Files Ravenhearst\Mystery Case Files Ravenhearst\ReflexiveArcade\unins000.exe"
Mystery In London --> "F:\Ons Eie Internet File\Reflexive Games\Mystery In London\ReflexiveArcade\unins000.exe"
Mystery Of Shark Island --> "F:\Ons Eie Internet File\Reflexive Games\Mystery Of Shark Island\ReflexiveArcade\unins000.exe"
Mystery PI The Lottery Ticket --> "F:\Ons Eie Internet File\Reflexive Games\Mystery PI The Lottery Ticket\ReflexiveArcade\unins000.exe"
Mysteryville 2 --> "F:\Ons Eie Internet File\Reflexive Games\Mysteryville 2\ReflexiveArcade\unins000.exe"
Mystic Inn --> "F:\Ons Eie Internet File\Reflexive Games\Mystic Inn\ReflexiveArcade\unins000.exe"
Mythic Marbles --> "F:\Ons Eie Internet File\Reflexive Games\Mythic Marbles\ReflexiveArcade\unins000.exe"
Mythic Pearls --> "F:\Ons Eie Internet File\Reflexive Games\Mythic Pearls\ReflexiveArcade\unins000.exe"
Nanny Mania --> "F:\Ons Eie Internet File\Reflexive Games\Nanny Mania\ReflexiveArcade\unins000.exe"
Navigatris --> "F:\Ons Eie Internet File\Reflexive Games\Navigatris\ReflexiveArcade\unins000.exe"
Nero - Burning Rom --> MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
Nertz Solitaire --> "C:\Program Files\Oberon Media\Nertz Solitaire\Uninstall.exe" "C:\Program Files\Oberon Media\Nertz Solitaire\install.log"
Nertz Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Nertz Solitaire\ReflexiveArcade\unins000.exe"
Newspaper Puzzle Challenge - Sudoku Edition (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Newspaper Puzzle Challenge - Sudoku Edition\Uninstall.exe
Nokia Connectivity Cable Driver --> RUNDLL32.EXE nsesetup.dll,DoNTUninst
Numericon --> "C:\Program Files\Oberon Media\Numericon\Uninstall.exe" "C:\Program Files\Oberon Media\Numericon\install.log"
NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Ocean Diver --> "F:\Ons Eie Internet File\Reflexive Games\Ocean Diver\ReflexiveArcade\unins000.exe"
Ocean Express --> "C:\Program Files\Oberon Media\Ocean Express\Uninstall.exe" "C:\Program Files\Oberon Media\Ocean Express\install.log"
Orchidia --> "C:\Program Files\Oberon Media\Orchidia\Uninstall.exe" "C:\Program Files\Oberon Media\Orchidia\install.log"
Paparazzi --> "F:\Ons Eie Internet File\Reflexive Games\Paparazzi\ReflexiveArcade\unins000.exe"
Paradise Pet Salon --> "F:\Ons Eie Internet File\Reflexive Games\Paradise Pet Salon\ReflexiveArcade\unins000.exe"
PartyCasino --> "C:\Program Files\PartyGaming\PartyCasino\Uninstall.exe" "C:\Program Files\PartyGaming\PartyCasino\install.log"
Pathstorm (remove only) --> "C:\Program Files\Pathstorm\Uninstall.exe"
Pearls --> "C:\Program Files\Oberon Media\Pearls\Uninstall.exe" "C:\Program Files\Oberon Media\Pearls\install.log"
Peggle Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Peggle Deluxe\ReflexiveArcade\unins000.exe"
Penguins Journey --> "F:\Ons Eie Internet File\Reflexive Games\Penguins Journey\ReflexiveArcade\unins000.exe"
Phantasia 2 --> "F:\Ons Eie Internet File\Reflexive Games\Phantasia 2\ReflexiveArcade\unins000.exe"
Pirates of the Atlantic --> "C:\Program Files\Oberon Media\Pirates of the Atlantic\Uninstall.exe" "C:\Program Files\Oberon Media\Pirates of the Atlantic\install.log"
Pirates Plunder --> "C:\Program Files\Oberon Media\Pirates Plunder\Uninstall.exe" "C:\Program Files\Oberon Media\Pirates Plunder\install.log"
Pirateville --> "F:\Ons Eie Internet File\Reflexive Games\Pirateville\ReflexiveArcade\unins000.exe"
Pizza Panic --> "F:\Ons Eie Internet File\Reflexive Games\Pizza Panic\ReflexiveArcade\unins000.exe"
Plant Tycoon --> "F:\Ons Eie Internet File\Reflexive Games\Plant Tycoon\ReflexiveArcade\unins000.exe"
Plantasia --> "F:\Ons Eie Internet File\Reflexive Games\Plantasia\ReflexiveArcade\unins000.exe"
Plumeboom The First Chapter --> "F:\Ons Eie Internet File\Reflexive Games\Plumeboom The First Chapter\ReflexiveArcade\unins000.exe"
Polly Pride Pet Detective --> "F:\Ons Eie Internet File\Reflexive Games\Polly Pride Pet Detective\ReflexiveArcade\unins000.exe"
PrimoPDF --> "C:\WINDOWS\PrimoPDF\uninstall.exe" "/U:C:\Program Files\activePDF\PrimoPDF\Uninstall\uninstall.xml"
PrimoPDF Redistribution Package --> MsiExec.exe /I{885744A4-1A01-44B0-858A-0AE6738CBCF7}
Prison Tycoon 2 (remove only) --> "F:\Ons Eie Internet File\Games 2 Download Games\Prison Tycoon 2\Uninstall.exe"
Private Eye Greatest Unsolved Mysteries --> "F:\Ons Eie Internet File\Reflexive Games\Private Eye Greatest Unsolved Mysteries\ReflexiveArcade\unins000.exe"
Professor Fizzwizzle And The Molten Mystery --> "F:\Ons Eie Internet File\Reflexive Games\Professor Fizzwizzle And The Molten Mystery\ReflexiveArcade\unins000.exe"
Purrfect Pet Shop --> "F:\Ons Eie Internet File\Reflexive Games\Purrfect Pet Shop\ReflexiveArcade\unins000.exe"
Puzzle Blast --> "F:\Ons Eie Internet File\Reflexive Games\Puzzle Blast\ReflexiveArcade\unins000.exe"
Puzzle City --> "F:\Ons Eie Internet File\Reflexive Games\Puzzle City\ReflexiveArcade\unins000.exe"
Puzzle Detective --> "F:\Ons Eie Internet File\Reflexive Games\Puzzle Detective\ReflexiveArcade\unins000.exe"
Puzzle Mania --> "F:\Ons Eie Internet File\Reflexive Games\Puzzle Mania\ReflexiveArcade\unins000.exe"
Puzzle Word --> "F:\Ons Eie Internet File\Reflexive Games\Puzzle Word\ReflexiveArcade\unins000.exe"
PyraCubes --> "F:\Ons Eie Internet File\Reflexive Games\PyraCubes\ReflexiveArcade\unins000.exe"
QBicles --> "F:\Ons Eie Internet File\Reflexive Games\QBicles\ReflexiveArcade\unins000.exe"
Qphoto --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{947FA832-4467-4F4C-AE33-25E3ABF2D4D0}\Setup.exe"
Race Cars en --> "C:\Program Files\BoontyGames\Race Cars\unins000.exe"
Rage Of Magic 2 --> "F:\Ons Eie Internet File\Great Day Games\Rage Of Magic 2\ReflexiveArcade\unins000.exe"
Rain Talisman --> "C:\Program Files\Oberon Media\Rain Talisman\Uninstall.exe" "C:\Program Files\Oberon Media\Rain Talisman\install.log"
Rainbow Drops Buster --> "F:\Ons Eie Internet File\Reflexive Games\Rainbow Drops Buster\ReflexiveArcade\unins000.exe"
Rainbow Mystery --> "F:\Ons Eie Internet File\Reflexive Games\Rainbow Mystery\ReflexiveArcade\unins000.exe"
Rainbow Web --> "C:\Program Files\Oberon Media\Rainbow Web\Uninstall.exe" "C:\Program Files\Oberon Media\Rainbow Web\install.log"
Rally Racers --> "F:\Ons Eie Internet File\Reflexive Games\Rally Racers\ReflexiveArcade\unins000.exe"
Reader's Digest Super Word Power --> "F:\Ons Eie Internet File\Reflexive Games\Reader's Digest Super Word Power\ReflexiveArcade\unins000.exe"
RealArcade --> C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RegCure 1.3.0.2 --> F:\RegCure\uninst.exe
Registry Cleaner 1.0 --> "C:\Program Files\Registry Cleaner Retail\unins000.exe"
Rhombis --> "F:\Ons Eie Internet File\Reflexive Games\Rhombis\ReflexiveArcade\unins000.exe"
Ricochet Infinity --> "F:\Ons Eie Internet File\Reflexive Games\Ricochet Infinity\ReflexiveArcade\unins000.exe"
Roller Rush --> "F:\Ons Eie Internet File\Reflexive Games\Roller Rush\ReflexiveArcade\unins000.exe"
RSVP --> "F:\Ons Eie Internet File\Reflexive Games\RSVP\ReflexiveArcade\unins000.exe"
Runes Of Avalon 2 --> "F:\Ons Eie Internet File\Reflexive Games\Runes Of Avalon 2\ReflexiveArcade\unins000.exe"
Saints And Sinners Bingo --> "F:\Ons Eie Internet File\Reflexive Games\Saints And Sinners Bingo\ReflexiveArcade\unins000.exe"
SAMSUNG CDMA Modem Driver Set --> C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
Samsung Mobile phone USB driver Software --> C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software --> C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software --> C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x9 -removeonly
Samsung Samples Installer --> "C:\Program Files\InstallShield Installation Information\{7AC15160-A49B-4A89-B181-D4619C025FFF}\setup.exe" -runfromtemp -l0x0009 -removeonly
Sandlot Games Client Services 1.2.2 --> "C:\Program Files\Common Files\Sandlot Shared\unins000.exe"
SandScript --> "F:\Ons Eie Internet File\Reflexive Games\SandScript\ReflexiveArcade\unins000.exe"
Santas Super Friends --> "F:\Ons Eie Internet File\Reflexive Games\Santas Super Friends\ReflexiveArcade\unins000.exe"
Scarab Shooter 1.2 --> "F:\Ons Eie Internet File\Ander Games\ScarabShooter DEMO\unins000.exe"
Scavenger --> "F:\Ons Eie Internet File\Reflexive Games\Scavenger\ReflexiveArcade\unins000.exe"
Scepter of Ra --> "C:\Program Files\Oberon Media\Scepter of Ra\Uninstall.exe" "C:\Program Files\Oberon Media\Scepter of Ra\install.log"
Scrubbles --> "F:\Ons Eie Internet File\Great Day Games\Scrubbles\ReflexiveArcade\unins000.exe"
Secrets Of Great Art --> "F:\Ons Eie Internet File\Reflexive Games\Secrets Of Great Art\ReflexiveArcade\unins000.exe"
Secrets Of Olympus --> "F:\Ons Eie Internet File\Reflexive Games\Secrets Of Olympus\ReflexiveArcade\unins000.exe"
Secrets Of The Seas --> "F:\Ons Eie Internet File\Reflexive Games\Secrets Of The Seas\ReflexiveArcade\unins000.exe"
Sheeplings --> "F:\Ons Eie Internet File\Reflexive Games\Sheeplings\ReflexiveArcade\unins000.exe"
SiL --> "C:\Program Files\Oberon Media\SiL\Uninstall.exe" "C:\Program Files\Oberon Media\SiL\install.log"
Slingo Casino Pak --> "F:\Ons Eie Internet File\Reflexive Games\Slingo Casino Pak\ReflexiveArcade\unins000.exe"
Slingo Quest --> "C:\Program Files\Oberon Media\Slingo Quest\Uninstall.exe" "C:\Program Files\Oberon Media\Slingo Quest\install.log"
Slot Words --> "F:\Ons Eie Internet File\Reflexive Games\Slot Words\ReflexiveArcade\unins000.exe"
Snaky Jake --> "F:\Ons Eie Internet File\Reflexive Games\Snaky Jake\ReflexiveArcade\unins000.exe"
Souptoys Toybox --> "C:\Program Files\Oberon Media\Souptoys Toybox\Uninstall.exe" "C:\Program Files\Oberon Media\Souptoys Toybox\install.log"
Space Taxi 2 --> "F:\Ons Eie Internet File\Reflexive Games\Space Taxi 2\ReflexiveArcade\unins000.exe"
Spellagories --> "F:\Ons Eie Internet File\Reflexive Games\Spellagories\ReflexiveArcade\unins000.exe"
Spelling Dictionaries Support For Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Spellunker --> "F:\Ons Eie Internet File\Reflexive Games\Spellunker\ReflexiveArcade\unins000.exe"
Sprill --> "F:\Ons Eie Internet File\Reflexive Games\Sprill\ReflexiveArcade\unins000.exe"
Sprill The Mystery Of The Bermuda Triangle --> "F:\Ons Eie Internet File\Reflexive Games\Sprill The Mystery Of The Bermuda Triangle\ReflexiveArcade\unins000.exe"
Sproink --> "F:\Ons Eie Internet File\Reflexive Games\Sproink\ReflexiveArcade\unins000.exe"
Spybot - Search & Destroy 1.4 --> "F:\Ons Eie Internet File\SPYBOT SEARCH & DESTROY\Spybot - Search & Destroy\unins000.exe"
Spyde Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\Spyde Solitaire\ReflexiveArcade\unins000.exe"
Starcrossed --> "F:\Ons Eie Internet File\Reflexive Games\Starcrossed\ReflexiveArcade\unins000.exe"
Stone Of Destiny --> "F:\Ons Eie Internet File\Reflexive Games\Stone Of Destiny\ReflexiveArcade\unins000.exe"
Story Of Fairy Place --> "F:\Ons Eie Internet File\Reflexive Games\Story Of Fairy Place\ReflexiveArcade\unins000.exe"
Su-Doku Quest --> "C:\Program Files\Oberon Media\Su-Doku Quest\Uninstall.exe" "C:\Program Files\Oberon Media\Su-Doku Quest\install.log"
Sudoku Maya Gold --> "F:\Ons Eie Internet File\Reflexive Games\Sudoku Maya Gold\ReflexiveArcade\unins000.exe"
Sudoku Pagoda --> "F:\Ons Eie Internet File\Reflexive Games\Sudoku Pagoda\ReflexiveArcade\unins000.exe"
Super Granny 3 --> "F:\Ons Eie Internet File\Reflexive Games\Super Granny 3\ReflexiveArcade\unins000.exe"
Super Mahjong --> "F:\Ons Eie Internet File\Reflexive Games\Super Mahjong\ReflexiveArcade\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Supercow --> "C:\Program Files\Oberon Media\Supercow\Uninstall.exe" "C:\Program Files\Oberon Media\Supercow\install.log"
Supple --> "C:\Program Files\Oberon Media\Supple\Uninstall.exe" "C:\Program Files\Oberon Media\Supple\install.log"
Sushi Frenzy --> "F:\Ons Eie Internet File\Reflexive Games\Sushi Frenzy\ReflexiveArcade\unins000.exe"
Svetlograd --> "F:\Ons Eie Internet File\Reflexive Games\Svetlograd\ReflexiveArcade\unins000.exe"
Swashbucks To Go --> "C:\Program Files\Oberon Media\Swashbucks To Go\Uninstall.exe" "C:\Program Files\Oberon Media\Swashbucks To Go\install.log"
The Count Of Monte Cristo --> "F:\Ons Eie Internet File\Reflexive Games\The Count Of Monte Cristo\ReflexiveArcade\unins000.exe"
The Exchange Student Episode 1 --> "C:\Program Files\Oberon Media\The Exchange Student Episode 1\Uninstall.exe" "C:\Program Files\Oberon Media\The Exchange Student Episode 1\install.log"
The Great Tree --> "F:\Ons Eie Internet File\Reflexive Games\The Great Tree\ReflexiveArcade\unins000.exe"
The Great Wall Of Words --> "F:\Ons Eie Internet File\Reflexive Games\The Great Wall Of Words\ReflexiveArcade\unins000.exe"
The Magicians Handbook Cursed Valley --> "F:\Ons Eie Internet File\Reflexive Games\The Magicians Handbook Cursed Valley\ReflexiveArcade\unins000.exe"
The Nightshift Code --> "F:\Ons Eie Internet File\Reflexive Games\The Nightshift Code\ReflexiveArcade\unins000.exe"
The Office --> "C:\Program Files\Oberon Media\The Office\Uninstall.exe" "C:\Program Files\Oberon Media\The Office\install.log"
The Rise Of Atlantis --> "F:\Ons Eie Internet File\Reflexive Games\The Rise Of Atlantis\ReflexiveArcade\unins000.exe"
The Scruffs --> "F:\Ons Eie Internet File\Reflexive Games\The Scruffs\ReflexiveArcade\unins000.exe"
The Treasures Of Montezuma --> "F:\Ons Eie Internet File\Reflexive Games\The Treasures Of Montezuma\ReflexiveArcade\unins000.exe"
The Tuttles --> "F:\Ons Eie Internet File\Reflexive Games\The Tuttles\ReflexiveArcade\unins000.exe"
The Walls of Jericho --> "F:\Ons Eie Internet File\Reflexive Games\The Walls of Jericho\ReflexiveArcade\unins000.exe"
The Weather Channel Desktop --> C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
The Witch’s Yarn --> "C:\Program Files\Oberon Media\The Witchs Yarn\Uninstall.exe" "C:\Program Files\Oberon Media\The Witchs Yarn\install.log"
The Wonderful Wizard Of Oz --> "F:\Ons Eie Internet File\Reflexive Games\The Wonderful Wizard Of Oz\ReflexiveArcade\unins000.exe"
Tiny Cars 2 --> "C:\Program Files\Oberon Media\Tiny Cars 2\Uninstall.exe" "C:\Program Files\Oberon Media\Tiny Cars 2\install.log"
Top Ten Solitaire (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Top Ten Solitaire\Uninstall.exe
Travelogue 360 Paris --> "F:\Ons Eie Internet File\Reflexive Games\Travelogue 360 Paris\ReflexiveArcade\unins000.exe"
Travelogue 360 Rome --> "F:\Ons Eie Internet File\Reflexive Games\Travelogue 360 Rome\ReflexiveArcade\unins000.exe"
Treasure Machine --> "F:\Ons Eie Internet File\Reflexive Games\Treasure Machine\ReflexiveArcade\unins000.exe"
Treasure Of Persia --> "F:\Ons Eie Internet File\Reflexive Games\Treasure Of Persia\ReflexiveArcade\unins000.exe"
Treasure Pyramid --> "F:\Ons Eie Internet File\Reflexive Games\Treasure Pyramid\ReflexiveArcade\unins000.exe"
Treasures Of The Deep --> "F:\Ons Eie Internet File\Reflexive Games\Treasures Of The Deep\ReflexiveArcade\unins000.exe"
Trivial Pursuit Bring On The 90s --> "F:\Ons Eie Internet File\Reflexive Games\Trivial Pursuit Bring On The 90s\ReflexiveArcade\unins000.exe"
Trivial Pursuit Silver Screen Edition --> "C:\Program Files\Oberon Media\Trivial Pursuit Silver Screen Edition\Uninstall.exe" "C:\Program Files\Oberon Media\Trivial Pursuit Silver Screen Edition\install.log"
Truffle Tray --> "F:\Ons Eie Internet File\Reflexive Games\Truffle Tray\ReflexiveArcade\unins000.exe"
Tube Twist --> "F:\Ons Eie Internet File\Reflexive Games\Tube Twist\ReflexiveArcade\unins000.exe"
Turbo Gems --> "F:\Ons Eie Internet File\Reflexive Games\Turbo Gems\ReflexiveArcade\unins000.exe"
Turbo Pizza --> "F:\Ons Eie Internet File\Reflexive Games\Turbo Pizza\ReflexiveArcade\unins000.exe"
Turbo Subs --> "F:\Ons Eie Internet File\Reflexive Games\Turbo Subs\ReflexiveArcade\unins000.exe"
Turtle Bay --> "F:\Ons Eie Internet File\Reflexive Games\Turtle Bay\ReflexiveArcade\unins000.exe"
Twistingo --> "F:\Ons Eie Internet File\Reflexive Games\Twistingo\ReflexiveArcade\unins000.exe"
Twisty Tracks --> "F:\Ons Eie Internet File\Reflexive Games\Twisty Tracks\ReflexiveArcade\unins000.exe"
Ulead Photo Explorer 8.0 SE Basic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D271DAE0-8D68-4C97-8356-A126D48A1D8C}\Setup.exe" -l0x9
Ulead Photo Express 5 SE --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31383A1D-FAE6-435A-9DBD-FDB61C7C8EC9}\Setup.exe" -l0x9
USB PC Camera (ZS211) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44D02D8B-FFB3-4245-8D26-68D10B4C4023}\Setup.exe" -l0x9
Valentines Gift --> "F:\Ons Eie Internet File\Reflexive Games\Valentines Gift\ReflexiveArcade\unins000.exe"
Venice --> "F:\Ons Eie Internet File\Reflexive Games\Venice\ReflexiveArcade\unins000.exe"
Venture Arctic --> "F:\Ons Eie Internet File\Reflexive Games\Venture Arctic\ReflexiveArcade\unins000.exe"
VIA Audio Driver Setup Program --> RunDll32.exe UnAudioNT.dll,UninstallAudio C:\WINDOWS\IsUninst.exe -f"C:\PROGRA~1\VIATEC~1\VIAAUD~1/Uninst.isu"
VIA Rhine-Family Fast-Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Virtual Marbles --> "C:\Program Files\Oberon Media\Virtual Marbles\Uninstall.exe" "C:\Program Files\Oberon Media\Virtual Marbles\install.log"
Virtual Villagers --> "F:\Ons Eie Internet File\Reflexive Games\Virtual Villagers\Virtual Villagers\ReflexiveArcade\unins000.exe"
Virtual Villagers - The Lost Children (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Virtual Villagers - The Lost Children\Uninstall.exe
Waterscape Solitaire American Falls --> "F:\Ons Eie Internet File\Reflexive Games\Waterscape Solitaire American Falls\ReflexiveArcade\unins000.exe"
Wedding Dash --> "F:\Ons Eie Internet File\Reflexive Games\Wedding Dash\ReflexiveArcade\unins000.exe"
Westward --> "C:\Program Files\Oberon Media\Westward\Uninstall.exe" "C:\Program Files\Oberon Media\Westward\install.log"
Westward II Heroes Of The Frontier --> "F:\Ons Eie Internet File\Reflexive Games\Westward II Heroes Of The Frontier\ReflexiveArcade\unins000.exe"
Wild West Wendy --> "F:\Ons Eie Internet File\Reflexive Games\Wild West Wendy\ReflexiveArcade\unins000.exe"
Wildlife Tycoon Venture Africa --> "F:\Ons Eie Internet File\Reflexive Games\Wildlife Tycoon Venture Africa\ReflexiveArcade\unins000.exe"
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live installer --> MsiExec.exe /X{7BC43F11-02C8-45FA-ABDC-E2F9FF31F825}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Outlook Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE}
Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar Extension (Windows Live Toolbar) --> MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
WinPcap 3.1 beta3 --> "C:\Program Files\WinPcap\Uninstall.exe" "C:\Program Files\WinPcap\install.log"
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
WinZip Self-Extractor --> "C:\Program Files\WinZip Self-Extractor\wzipse32.exe" -uninstall
Wonderland Secret Worlds (remove only) --> "F:\Ons Eie Internet File\Big Fish Games\Wonderland Secret Worlds\Uninstall.exe"
Word Blitz Deluxe --> "F:\Ons Eie Internet File\Reflexive Games\Word Blitz Deluxe\ReflexiveArcade\unins000.exe"
Word Search Deluxe (remove only) --> F:\Ons Eie Internet File\Big Fish Games\Word Search Deluxe\Uninstall.exe
Word Whomp To Go --> "F:\Ons Eie Internet File\Reflexive Games\Word Whomp To Go\ReflexiveArcade\unins000.exe"
WordPerfect Office 12 --> MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}
World Class Solitaire --> "F:\Ons Eie Internet File\Reflexive Games\World Class Solitaire\ReflexiveArcade\unins000.exe"
World Jongg --> "C:\Program Files\Oberon Media\World Jongg\Uninstall.exe" "C:\Program Files\Oberon Media\World Jongg\install.log"
XML Paper Specification Shared Components Pack 1.0 -->
Yahoo Messenger Monitor Sniffer --> "C:\Program Files\IMMonitor\Yahoo Messenger Monitor Sniffer\unins000.exe"
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
Yahtzee --> "F:\Ons Eie Internet File\Reflexive Games\Yahtzee\ReflexiveArcade\unins000.exe"
Yumsters --> "F:\Ons Eie Internet File\Reflexive Games\Yumsters\ReflexiveArcade\unins000.exe"
Zak and Jack in Showdown at Monstertown --> "C:\Program Files\Oberon Media\Zak and Jack in Showdown at Monstertown\Uninstall.exe" "C:\Program Files\Oberon Media\Zak and Jack in Showdown at Monstertown\install.log"
Zam Beezee --> "C:\Program Files\Oberon Media\Zam Beezee\Uninstall.exe" "C:\Program Files\Oberon Media\Zam Beezee\install.log"
Zen Games --> "C:\Program Files\Oberon Media\Zen Games\Uninstall.exe" "C:\Program Files\Oberon Media\Zen Games\install.log"
ZoomBook The Temple Of The Sun --> "F:\Ons Eie Internet File\Reflexive Games\ZoomBook The Temple Of The Sun\ReflexiveArcade\unins000.exe"
Zulu Gems --> "F:\Ons Eie Internet File\Reflexive Games\Zulu Gems\ReflexiveArcade\unins000.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type7149 / Error
Event Submitted/Written: 04/17/2008 09:33:47 AM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The specified server cannot perform the requested operation.

Event Record #/Type7148 / Error
Event Submitted/Written: 04/17/2008 09:33:47 AM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

Event Record #/Type7142 / Error
Event Submitted/Written: 04/15/2008 09:15:28 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type7141 / Error
Event Submitted/Written: 04/15/2008 09:06:01 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application airportmania.rwg, version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x109703e1.
Processing media-specific event for [airportmania.rwg!ws!]

Event Record #/Type7139 / Error
Event Submitted/Written: 04/15/2008 10:12:37 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application IncMail.exe, version 5.7.0.3505, hang module hungapp, version 0.0.0.0, hang address 0x00000000.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type45145 / Error
Event Submitted/Written: 04/17/2008 09:21:25 AM
Event ID/Source: 59 / SideBySide
Event Description:
Generate Activation Context failed for C:\Program Files\IncrediMail\bin\MFC80U.DLL.
Reference error message: The operation completed successfully.
.

Event Record #/Type45144 / Error
Event Submitted/Written: 04/17/2008 09:21:25 AM
Event ID/Source: 59 / SideBySide
Event Description:
Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.

Event Record #/Type45143 / Error
Event Submitted/Written: 04/17/2008 09:21:25 AM
Event ID/Source: 32 / SideBySide
Event Description:
Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

Event Record #/Type45142 / Error
Event Submitted/Written: 04/17/2008 09:21:25 AM
Event ID/Source: 59 / SideBySide
Event Description:
Generate Activation Context failed for C:\Program Files\IncrediMail\bin\MFC80U.DLL.
Reference error message: The operation completed successfully.
.

Event Record #/Type45141 / Error
Event Submitted/Written: 04/17/2008 09:21:25 AM
Event ID/Source: 59 / SideBySide
Event Description:
Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.



-- End of Deckard's System Scanner: finished at 2008-04-17 09:35:33 ------------



KASPERSKY REPORT

KASPERSKY ONLINE SCANNER REPORT
Thursday, April 17, 2008 4:38:40 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/04/2008
Kaspersky Anti-Virus database records: 711959
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 282829
Number of viruses found: 12
Number of infected objects: 61
Number of suspicious objects: 0
Duration of the scan process: 05:34:22

Infected Object Name / Virus Name / Last Action
C:\avenger\backup.zip/avenger/fvqkfsp.exe Infected: not-a-virus:AdWare.Win32.Vapsup.ano skipped
C:\avenger\backup.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Parratjie\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-7db78a7c/OwnClassLoader.class Infected: Trojan.Java.ClassLoader.au skipped
C:\Documents and Settings\Parratjie\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-7db78a7c ZIP: infected - 1 skipped
C:\Documents and Settings\Parratjie\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Parratjie\Desktop\RAINER\msnmonitor.exe/file1 Infected: not-a-virus:Monitor.Win32.MonitorSniffer.b skipped
C:\Documents and Settings\Parratjie\Desktop\RAINER\msnmonitor.exe Inno: infected - 1 skipped
C:\Documents and Settings\Parratjie\Desktop\VIRUS,AD,SPY,REG\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Parratjie\Desktop\VIRUS,AD,SPY,REG\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Parratjie\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Temp\IMG57.tmp Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Temp\~DF759F.tmp Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Temp\~DF75B3.tmp Object is locked skipped
C:\Documents and Settings\Parratjie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Parratjie\My Documents\Downloads\Programs\site-tickets2006.exe/stream Infected: Trojan.Win32.DNSChanger.ik skipped
C:\Documents and Settings\Parratjie\My Documents\Downloads\Programs\site-tickets2006.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Parratjie\My Documents\IncrediMail\magentic_install.exe Infected: not-a-virus:Downloader.Win32.ImLoader.f skipped
C:\Documents and Settings\Parratjie\My Documents\Registry Cleaner\Wsk\Christina Aguilera Topless Photoshoot_encrypted.wmv Infected: Trojan-Downloader.WMA.Wimad.h skipped
C:\Documents and Settings\Parratjie\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Parratjie\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\IMMonitor\MSN Messenger Monitor Sniffer\MsnMonitor.exe Infected: not-a-virus:Monitor.Win32.MonitorSniffer.b skipped
C:\SDFix\backups_old1\backups.zip/backups/jetctrl.dll Infected: not-a-virus:AdWare.Win32.Vapsup.qi skipped
C:\SDFix\backups_old1\backups.zip/backups/kopmet.dll Infected: not-a-virus:AdWare.Win32.Vapsup.qi skipped
C:\SDFix\backups_old1\backups.zip/backups/mssql.dll Infected: not-a-virus:AdWare.Win32.Agent.lb skipped
C:\SDFix\backups_old1\backups.zip ZIP: infected - 3 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_618.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\McAfee_VirusScan_v7.0_AllVersions_LicenseGenerator.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_AllVersions_LicenseGenerator.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_AllVersions_LicenseGenerator.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_AllVersions_LicenseGenerator.zip ZIP: infected - 3 skipped
F:\McAfee_VirusScan_v7.0_All_Versions.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_All_Versions.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_All_Versions.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_All_Versions.zip ZIP: infected - 3 skipped
F:\McAfee_VirusScan_v7.0_Trial_Reset.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_Trial_Reset.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_Trial_Reset.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v7.0_Trial_Reset.zip ZIP: infected - 3 skipped
F:\McAfee_VirusScan_v8.0_Professinal.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v8.0_Professinal.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v8.0_Professinal.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\McAfee_VirusScan_v8.0_Professinal.zip ZIP: infected - 3 skipped
F:\Ons Eie Internet File\Gamehouse Games\All_games_from_gamehouse_com_read_nfo_keygen_keygen-tsrh.exe/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Gamehouse Games\All_games_from_gamehouse_com_read_nfo_keygen_keygen-tsrh.exe/run.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Gamehouse Games\All_games_from_gamehouse_com_read_nfo_keygen_keygen-tsrh.exe/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Gamehouse Games\All_games_from_gamehouse_com_read_nfo_keygen_keygen-tsrh.exe/run.exe Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Gamehouse Games\All_games_from_gamehouse_com_read_nfo_keygen_keygen-tsrh.exe ZIP: infected - 4 skipped
F:\Ons Eie Internet File\Gamehouse Games\Patch_Maker_v1.2.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Gamehouse Games\Patch_Maker_v1.2.zip/run.exe/stream/data0003 Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\Patch_Maker_v1.2.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\Patch_Maker_v1.2.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\Patch_Maker_v1.2.zip ZIP: infected - 4 skipped
F:\Ons Eie Internet File\Gamehouse Games\run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Gamehouse Games\run.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Gamehouse Games\run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Gamehouse Games\run.exe NSIS: infected - 3 skipped
F:\Ons Eie Internet File\Gamehouse Games\SoftICE_v4.05_by_CrackLabs.zip/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Gamehouse Games\SoftICE_v4.05_by_CrackLabs.zip/run.exe/stream/data0003 Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\SoftICE_v4.05_by_CrackLabs.zip/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\SoftICE_v4.05_by_CrackLabs.zip/run.exe Infected: Trojan-Downloader.Win32.Zlob.eyq skipped
F:\Ons Eie Internet File\Gamehouse Games\SoftICE_v4.05_by_CrackLabs.zip ZIP: infected - 4 skipped
F:\Ons Eie Internet File\Reflexive Games\All Reflexive Arcade Torrent\run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Reflexive Games\All Reflexive Arcade Torrent\run.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Reflexive Games\All Reflexive Arcade Torrent\run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Reflexive Games\All Reflexive Arcade Torrent\run.exe NSIS: infected - 3 skipped
F:\Ons Eie Internet File\Reflexive Games\All_Reflexive_Arcade_Games_2.0.exe/run.exe/stream/Script Infected: Trojan-Downloader.Win32.Zlob.fjh skipped
F:\Ons Eie Internet File\Reflexive Games\All_Reflexive_Arcade_Games_2.0.exe/run.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Reflexive Games\All_Reflexive_Arcade_Games_2.0.exe/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Reflexive Games\All_Reflexive_Arcade_Games_2.0.exe/run.exe Infected: Trojan-Downloader.Win32.Zlob.epi skipped
F:\Ons Eie Internet File\Reflexive Games\All_Reflexive_Arcade_Games_2.0.exe ZIP: infected - 4 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.



DSS MAIN.TXT after the Kaspersky report

Deckard's System Scanner v20071014.68
Run by Parratjie on 2008-04-17 16:41:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

System Drive C: has 3.17 GiB (less than 15%) free.


-- HijackThis (run as Parratjie.exe) -------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:41:59 PM, on 2008/04/17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\ZSSnp211.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Parratjie\Desktop\dss.exe
F:\HIJACK~1\PARRAT~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www4.king.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = dsl-cache.saix.net:8080
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [e43075dd] rundll32.exe "C:\WINDOWS\system32\qpfrsnow.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.antispywarebot.com
O15 - Trusted Zone: http://forum.astalavista.ms
O15 - Trusted Zone: http://www4.king.com
O15 - Trusted Zone: http://forums.techguy.org
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFramework/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://cdn2.zone.msn.com/binFramework/v10/...dy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://cdn2.zone.msn.com/binFramework/v10/...at.cab55579.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1198741601859
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1198741744515
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://cdn3.zone.msn.com/binFramework/v10/...xy.cab55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3511FFFE-ECE2-477E-A99B-6CBF41CECE5B}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9630 bytes

-- Files created between 2008-03-17 and 2008-04-17 -----------------------------

2008-04-17 09:05:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-17 09:05:38 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-17 09:05:36 0 d-------- C:\WINDOWS\LastGood
2008-04-16 09:41:31 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Runes of Avalon 2
2008-04-16 06:41:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Malwarebytes
2008-04-16 06:41:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 06:41:35 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-15 10:41:51 0 d-------- C:\Documents and Settings\Parratjie\Application Data\BitTorrent
2008-04-15 10:41:34 0 d-------- C:\Program Files\DNA
2008-04-15 10:41:34 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DNA
2008-04-15 08:57:02 85056 -----n--- C:\WINDOWS\system32\qpfrsnow.dll
2008-04-12 07:45:11 103640 --ahs---- C:\WINDOWS\system32\kjSYIkkj.ini2
2008-04-12 07:44:59 273408 -----n--- C:\WINDOWS\system32\jkkIYSjk.dll
2008-04-12 07:40:35 4096 --a------ C:\WINDOWS\system32taack.dat
2008-04-12 07:40:35 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-04-12 07:40:32 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-04-12 07:40:31 4096 --a------ C:\WINDOWS\system32bdn.com
2008-04-12 07:40:10 0 d-------- C:\Documents and Settings\All Users\Application Data\kjcpwlsr
2008-04-12 07:39:53 39936 -----n--- C:\WINDOWS\system32\ljJcDWpM.dll
2008-04-07 21:12:01 0 d-------- C:\Documents and Settings\Parratjie\Application Data\SprillBermudeEng
2008-04-04 06:48:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Meridian93
2008-04-03 05:38:00 0 d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-01 06:47:36 0 d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-28 06:41:17 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Jane s Hotel Family Hero
2008-03-25 05:37:45 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Yatec Games
2008-03-20 22:29:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2


-- Find3M Report ---------------------------------------------------------------

2008-04-17 09:24:20 0 d-------- C:\Program Files\VeZA Route planner
2008-04-17 09:24:20 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-13 04:57:38 0 d-------- C:\Program Files\Java
2008-04-09 07:00:13 0 d-------- C:\Program Files\OFFICE11
2008-04-08 10:26:35 0 d-------- C:\Program Files\IncrediMail
2008-04-08 09:22:08 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-07 20:51:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\PlayFirst
2008-04-05 07:13:34 0 d-------- C:\Program Files\GamesBar
2008-04-05 07:13:29 0 d-------- C:\Program Files\Oberon Media
2008-04-01 06:40:58 0 d-------- C:\Program Files\Lavasoft
2008-04-01 06:39:57 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 06:37:24 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Wildfire
2008-03-21 07:23:28 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-14 20:28:40 218929 --a------ C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2008-03-07 19:09:20 0 d-------- C:\Program Files\PartyGaming
2008-03-06 16:52:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\eGames
2008-03-02 21:51:06 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DivX
2008-03-01 08:30:26 0 d-------- C:\Program Files\The Weather Channel FW
2008-02-29 19:21:11 0 d-------- C:\Documents and Settings\Parratjie\Application Data\iWin
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-02-21 20:13:43 0 d-------- C:\Documents and Settings\Parratjie\Application Data\MysteryStudio
2008-02-21 14:00:33 0 d-------- C:\Program Files\WinPcap
2008-02-21 14:00:21 0 d-------- C:\Program Files\IMMonitor
2008-02-17 09:49:22 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Bloom


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003/09/01 03:32 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004/04/23 06:24 AM]
"nwiz"="nwiz.exe" [2004/04/23 06:24 AM C:\WINDOWS\system32\nwiz.exe]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006/07/14 04:24 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008/03/29 08:37 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004/08/04 01:56 AM C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007/04/08 08:07 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008/01/11 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008/02/22 04:25 AM]
"e43075dd"="C:\WINDOWS\system32\qpfrsnow.dll" [2008/04/16 07:59 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006/11/30 09:49 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008/03/21 07:23 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004/08/04 01:56 AM]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008/04/15 10:41 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007/04/19 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007/05/25 03:22 PM 63040 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
C:\WINDOWS\Domino.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
"C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ




-- End of Deckard's System Scanner: finished at 2008-04-17 16:42:41 ------------

BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 18 April 2008 - 07:19 AM

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. :thumbsup:

Run Hijackthis again, click scan, and Put a checkmark next to each of the lines listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [e43075dd] rundll32.exe "C:\WINDOWS\system32\qpfrsnow.dll",b



================


Click Start -> Control Panel -> Add Remove Programs and uninstall these programs:

J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1




Reboot and post a new hijackthis log.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 18 April 2008 - 10:39 AM

Hi Sam. :blink:

Thanx for taking the time to look into my problem. You realy didn't waste any time. :thumbsup:

I've done everything you said, but I just want to ask you this please - all the thing on my pc like Malwarebytes Anti-Malware, EMCO Malware Destroyer, SDFix, SmitfraudFix, ComboFix and Deckard's System Scanner - can or must I take it of or can or must I leave it on my pc?

Thanx again for your time
Anna Dercksen

Here is the new hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:16:53 PM, on 2008/04/18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\ZSSnp211.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
F:\HIJACK THIS\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www4.king.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = dsl-cache.saix.net:8080
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.antispywarebot.com
O15 - Trusted Zone: http://forum.astalavista.ms
O15 - Trusted Zone: http://www4.king.com
O15 - Trusted Zone: http://forums.techguy.org
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFramework/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://cdn2.zone.msn.com/binFramework/v10/...dy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://cdn2.zone.msn.com/binFramework/v10/...at.cab55579.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1198741601859
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1198741744515
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://cdn3.zone.msn.com/binFramework/v10/...xy.cab55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3511FFFE-ECE2-477E-A99B-6CBF41CECE5B}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 9429 bytes

#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 19 April 2008 - 07:41 AM

I'd keep all those tools on your computer for now. But once we have everything cleaned up it's best just to remove the specialized tools like combofix, sdfix, and smitfraudfix since new version are being released very regularly. The other programs you can keep if you wish and just update them as needed.

If you have combofix on your computer now, please delete it so we can get the current version.



Please download ComboFix and save it to your desktop.
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Double click combofix.exe and follow the prompts.
When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 19 April 2008 - 01:13 PM

Hi Sam.
I did everything u said I must do.
After ComboFix had run, it restarted my pc by itself.
When I look for the log, all I could find in C:\ComboFix was this:

ComboFix 08-04-18.3 - Parratjie 2008-04-19 19:48:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.206 [GMT 2:00]
Running from: C:\Documents and Settings\Parratjie\Desktop\ComboFix.exe
.

BUT NOW MY DESKTOP IS A WHITE COLOUR THAT SAYS RESTORE MY ACTIVE DESKTOP AND WHEN I CLICKED ON THAT IT SAYS SOMETHING ABOUT A SKRIP ERROR.

WHAT DID I DO WRONG? PLEASE HELP

#6 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 19 April 2008 - 03:53 PM

Try this.
  • Click Start -> Control Panel -> Display
  • Go to the Desktop tab and click on the Customize Desktop button.
  • Go to the Web tab
  • Select everything except "My Current Homepage" and then click the Delete button.

Check here for your combofix log.

C:\combofix.txt
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#7 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 20 April 2008 - 09:44 AM

Hi again Sam.

Ok my desktop is fine now, but there is nothing else under C:\combofix.txt but this:

ComboFix 08-04-18.3 - Parratjie 2008-04-19 19:48:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.206 [GMT 2:00]
Running from: C:\Documents and Settings\Parratjie\Desktop\ComboFix.exe.

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 20 April 2008 - 09:50 AM

Ok, let's try this. Rename combofix.exe to cf.exe and run it again.
Let me know how it goes this time.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#9 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 20 April 2008 - 10:59 AM

Hi Sam.

I've change the name and run it again. Here is the log:

ComboFix 08-04-18.3 - Parratjie 2008-04-20 17:34:07.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.197 [GMT 2:00]
Running from: C:\Documents and Settings\Parratjie\Desktop\cf.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\jkkIYSjk.dll
C:\WINDOWS\system32\kjSYIkkj.ini
C:\WINDOWS\system32\kjSYIkkj.ini2
C:\WINDOWS\system32\ljJcDWpM.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\obvvtmyy.ini
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\qpfrsnow.dll
C:\WINDOWS\system32\sidjqsot.ini
C:\WINDOWS\system32\ujxlkvpd.ini
C:\WINDOWS\system32\vgfvntet.ini
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wonsrfpq.ini
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32VBIEWER.OCX

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.

2008-04-20 08:47 . 2008-04-20 08:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intenium
2008-04-19 19:48 . 2008-04-19 19:48 <DIR> d-------- C:\ComboFix
2008-04-17 09:29 . 2008-04-17 09:29 <DIR> d-------- C:\Deckard
2008-04-17 09:05 . 2008-04-17 09:05 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-17 09:05 . 2008-04-17 09:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-16 09:41 . 2008-04-16 09:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Runes of Avalon 2
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Malwarebytes
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-15 10:41 . 2008-04-15 10:41 <DIR> d-------- C:\Program Files\DNA
2008-04-15 10:41 . 2008-04-20 17:38 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\DNA
2008-04-15 10:41 . 2008-04-19 19:15 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\BitTorrent
2008-04-12 07:40 . 2008-04-16 07:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\kjcpwlsr
2008-04-07 21:12 . 2008-04-07 21:12 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\SprillBermudeEng
2008-04-04 06:48 . 2008-04-04 06:48 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Meridian93
2008-04-03 05:38 . 2008-04-03 05:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-01 06:47 . 2008-04-01 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-28 06:41 . 2008-03-28 06:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Jane s Hotel Family Hero
2008-03-25 05:37 . 2008-03-25 05:37 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Yatec Games
2008-03-20 22:29 . 2008-03-21 22:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 06:44 --------- d-----w C:\Program Files\Oberon Media
2008-04-18 14:56 --------- d-----w C:\Program Files\Java
2008-04-17 07:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 07:24 --------- d-----w C:\Program Files\VeZA Route planner
2008-04-16 17:01 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-14 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-04-09 05:00 --------- d-----w C:\Program Files\OFFICE11
2008-04-08 08:26 --------- d-----w C:\Program Files\IncrediMail
2008-04-08 07:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-07 18:51 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\PlayFirst
2008-04-07 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-04-05 05:13 --------- d-----w C:\Program Files\GamesBar
2008-04-01 04:40 --------- d-----w C:\Program Files\Lavasoft
2008-04-01 04:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 04:37 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\Wildfire
2008-03-21 05:23 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 18:28 218,929 ----a-w C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2008-03-07 17:09 --------- d-----w C:\Program Files\PartyGaming
2008-03-06 14:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\eGames
2008-03-06 14:52 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\eGames
2008-03-05 17:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-03-05 17:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-03-02 19:51 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\DivX
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-01 06:30 --------- d-----w C:\Program Files\The Weather Channel FW
2008-02-29 17:21 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\iWin
2008-02-28 12:46 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-02-21 18:13 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\MysteryStudio
2008-02-21 12:00 --------- d-----w C:\Program Files\WinPcap
2008-02-21 12:00 --------- d-----w C:\Program Files\IMMonitor
2008-02-21 02:05 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-07-22 08:23 81,920 ----a-w C:\Documents and Settings\Parratjie\Application Data\ezpinst.exe
2007-07-22 08:23 47,360 ----a-w C:\Documents and Settings\Parratjie\Application Data\pcouffin.sys
2007-04-07 18:43 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49 4662776]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-03-21 07:23 1481968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-04-15 10:41 288576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003-09-01 15:32 1200178]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-04-23 06:24 3756032]
"nwiz"="nwiz.exe" [2004-04-23 06:24 831488 C:\WINDOWS\system32\nwiz.exe]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-07-14 16:24 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-08 20:07 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
--a------ 2006-07-04 14:16 49152 C:\WINDOWS\Domino.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
--a------ 2007-12-20 08:10 715888 C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-04-03 09:56 243072 C:\Program Files\IncrediMail\bin\IncMail.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-02-21 13:53 5728112 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
-ra------ 2004-04-23 06:24 46080 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-07-07 22:49 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-04-08 20:07 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
--------- 2003-11-18 18:20 45056 C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
--a------ 2004-01-12 21:40 69632 C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"F:\\MALWARE DESTROYER\\EMCO Malware Destroyer\\MalwareDestroyer.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"F:\\Ons Eie Internet File\\BitTorrent 6.3\\BitTorrent\\bittorrent.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 20:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 20:35]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-09-21 11:24]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 Vsp;Vsp;C:\WINDOWS\System32\drivers\Vsp.sys [2003-05-27 17:45]
S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-04-13 11:52]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-20 14:58:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-20 15:13:15 C:\WINDOWS\Tasks\RegCure Program Check.job"
- F:\RegCure\RegCure.exe
"2008-02-29 11:37:19 C:\WINDOWS\Tasks\RegCure.job"
- F:\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 17:38:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-20 17:45:21
ComboFix-quarantined-files.txt 2008-04-20 15:44:28
ComboFix2.txt 2008-01-30 04:07:37

Pre-Run: 3,322,654,720 bytes free
Post-Run: 3,311,587,328 bytes free

198 --- E O F --- 2008-04-09 05:01:11

#10 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 20 April 2008 - 11:27 AM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

Dirlook::
C:\Documents and Settings\All Users\Application Data\kjcpwlsr
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#11 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 20 April 2008 - 02:27 PM

Hi Sam.

I've copied the word CODE as part of that text. I did what you told me to do. I don't know if Avast was disabled because my pc keep saying that I am protected by Avast, and I don't know where to disable it.

Here is the new log file:

ComboFix 08-04-18.3 - Parratjie 2008-04-20 21:01:53.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.203 [GMT 2:00]
Running from: C:\Documents and Settings\Parratjie\Desktop\cf.exe
Command switches used :: C:\Documents and Settings\Parratjie\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.

2008-04-20 08:47 . 2008-04-20 08:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intenium
2008-04-19 19:48 . 2008-04-19 19:48 <DIR> d-------- C:\ComboFix
2008-04-17 09:29 . 2008-04-17 09:29 <DIR> d-------- C:\Deckard
2008-04-17 09:05 . 2008-04-17 09:05 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-17 09:05 . 2008-04-17 09:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-16 09:41 . 2008-04-16 09:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Runes of Avalon 2
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Malwarebytes
2008-04-16 06:41 . 2008-04-16 06:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-15 10:41 . 2008-04-15 10:41 <DIR> d-------- C:\Program Files\DNA
2008-04-15 10:41 . 2008-04-20 20:58 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\DNA
2008-04-15 10:41 . 2008-04-19 19:15 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\BitTorrent
2008-04-12 07:40 . 2008-04-16 07:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\kjcpwlsr
2008-04-07 21:12 . 2008-04-07 21:12 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\SprillBermudeEng
2008-04-04 06:48 . 2008-04-04 06:48 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Meridian93
2008-04-03 05:38 . 2008-04-03 05:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-01 06:47 . 2008-04-01 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-28 06:41 . 2008-03-28 06:41 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Jane s Hotel Family Hero
2008-03-25 05:37 . 2008-03-25 05:37 <DIR> d-------- C:\Documents and Settings\Parratjie\Application Data\Yatec Games
2008-03-20 22:29 . 2008-03-21 22:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 18:15 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 06:44 --------- d-----w C:\Program Files\Oberon Media
2008-04-18 14:56 --------- d-----w C:\Program Files\Java
2008-04-17 07:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 07:24 --------- d-----w C:\Program Files\VeZA Route planner
2008-04-14 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-04-09 05:00 --------- d-----w C:\Program Files\OFFICE11
2008-04-08 08:26 --------- d-----w C:\Program Files\IncrediMail
2008-04-08 07:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-07 18:51 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\PlayFirst
2008-04-07 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-04-05 05:13 --------- d-----w C:\Program Files\GamesBar
2008-04-01 04:40 --------- d-----w C:\Program Files\Lavasoft
2008-04-01 04:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 04:37 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\Wildfire
2008-03-21 05:23 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 18:28 218,929 ----a-w C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2008-03-07 17:09 --------- d-----w C:\Program Files\PartyGaming
2008-03-06 14:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\eGames
2008-03-06 14:52 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\eGames
2008-03-05 17:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\IM
2008-03-05 17:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-03-02 19:51 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\DivX
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-01 06:30 --------- d-----w C:\Program Files\The Weather Channel FW
2008-02-29 17:21 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\iWin
2008-02-28 12:46 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-02-21 18:13 --------- d-----w C:\Documents and Settings\Parratjie\Application Data\MysteryStudio
2008-02-21 12:00 --------- d-----w C:\Program Files\WinPcap
2008-02-21 12:00 --------- d-----w C:\Program Files\IMMonitor
2008-02-21 02:05 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-07-22 08:23 81,920 ----a-w C:\Documents and Settings\Parratjie\Application Data\ezpinst.exe
2007-07-22 08:23 47,360 ----a-w C:\Documents and Settings\Parratjie\Application Data\pcouffin.sys
2007-04-07 18:43 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Documents and Settings\All Users\Application Data\kjcpwlsr ----



((((((((((((((((((((((((((((( snapshot@2008-04-20_17.32.27.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-20 15:07:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-20 18:47:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-20 18:48:08 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_560.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49 4662776]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-03-21 07:23 1481968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-04-15 10:41 288576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003-09-01 15:32 1200178]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-04-23 06:24 3756032]
"nwiz"="nwiz.exe" [2004-04-23 06:24 831488 C:\WINDOWS\system32\nwiz.exe]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-07-14 16:24 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-08 20:07 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
--a------ 2006-07-04 14:16 49152 C:\WINDOWS\Domino.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
--a------ 2007-12-20 08:10 715888 C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-04-03 09:56 243072 C:\Program Files\IncrediMail\bin\IncMail.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-02-21 13:53 5728112 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
-ra------ 2004-04-23 06:24 46080 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-07-07 22:49 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-04-08 20:07 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
--------- 2003-11-18 18:20 45056 C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
--a------ 2004-01-12 21:40 69632 C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"F:\\MALWARE DESTROYER\\EMCO Malware Destroyer\\MalwareDestroyer.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"F:\\Ons Eie Internet File\\BitTorrent 6.3\\BitTorrent\\bittorrent.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 20:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 20:35]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-09-21 11:24]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 Vsp;Vsp;C:\WINDOWS\System32\drivers\Vsp.sys [2003-05-27 17:45]
S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-04-13 11:52]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-20 18:58:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-20 18:48:22 C:\WINDOWS\Tasks\RegCure Program Check.job"
- F:\RegCure\RegCure.exe
"2008-02-29 11:37:19 C:\WINDOWS\Tasks\RegCure.job"
- F:\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 21:06:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-20 21:15:45
ComboFix-quarantined-files.txt 2008-04-20 19:15:03
ComboFix2.txt 2008-04-20 15:45:22
ComboFix3.txt 2008-01-30 04:07:37

Pre-Run: 3,321,720,832 bytes free
Post-Run: 3,307,630,592 bytes free

176 --- E O F --- 2008-04-09 05:01:11

#12 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 21 April 2008 - 06:52 AM

You can go ahead and delete this folder:

C:\Documents and Settings\All Users\Application Data\kjcpwlsr

Otherwise it's looking pretty good.
How are things on your end? Any problems?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#13 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 21 April 2008 - 11:04 AM

Hi Sam, its me again.

I've deleted that file, and everything else seems to be in place now.

It was very nice having someone like you helping me. Thank you VERY VERY much again. Your response was always so quick. Out of 10 I would rate you a 12.

Anna Dercksen

#14 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:05 AM

Posted 22 April 2008 - 06:02 AM

Excellent! I like that score! :thumbsup:
Let's just finish up a few things.

First go ahead and rename cf.exe back to combofix.exe like it was before.
Then run through this process to clean it all up.


And finally, let's get rid of Combofix now that we're done with it.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK

    • Posted Image
  • When shown the disclaimer, Select "2"
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


=====================



Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:blink: :wacko:
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#15 ghoempie

ghoempie
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 24 April 2008 - 10:39 AM

Hi Sam.

I've done what you said and when I put my pc on this afternoon it seems as if my original problem is back.

I'm getting those pop-up and warnings again. I've run Deckard and here is the report.

Please see if you can help me!!!!!!!!!!!!

Deckard's System Scanner v20071014.68
Run by Parratjie on 2008-04-24 17:29:25
Computer is in Normal Mode.
--------------------------------------------------------------------------------

System Drive C: has 3.36 GiB (less than 15%) free.


-- HijackThis (run as Parratjie.exe) -------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:29:52 PM, on 2008/04/24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\epmfytkn\ghixsdyj.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\DNA\btdna.exe
F:\Ons Eie Internet File\SPYBOT SEARCH & DESTROY\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\edsnmhev.exe
C:\Program Files\YesMessenger\YesMessenger.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Parratjie\Desktop\dss.exe
F:\HIJACK~1\PARRAT~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www4.king.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = dsl-cache.saix.net:8080
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {10BDDEFB-C944-4BE5-A90C-BB931273E0BD} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\ONSEIE~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {53FE12C2-4429-488F-847B-7B285F8F6778} - C:\WINDOWS\system32\fccYPgFw.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {942108D4-F757-4477-8587-4360F6B47A2A} - C:\WINDOWS\system32\awtuuSMe.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [e43075dd] rundll32.exe "C:\WINDOWS\system32\ocexaxga.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Ons Eie Internet File\SPYBOT SEARCH & DESTROY\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [hlkxsscz] C:\WINDOWS\system32\edsnmhev.exe
O4 - HKLM\..\Policies\Explorer\Run: [C72MO0I5Qy] C:\Documents and Settings\All Users\Application Data\epmfytkn\ghixsdyj.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: YesMessenger.lnk = C:\Program Files\YesMessenger\YesMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\ONSEIE~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\ONSEIE~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.antispywarebot.com
O15 - Trusted Zone: http://forum.astalavista.ms
O15 - Trusted Zone: http://www4.king.com
O15 - Trusted Zone: http://forums.techguy.org
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFramework/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://cdn2.zone.msn.com/binFramework/v10/...dy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://cdn2.zone.msn.com/binFramework/v10/...at.cab55579.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1198741601859
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1198741744515
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://cdn3.zone.msn.com/binFramework/v10/...xy.cab55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3511FFFE-ECE2-477E-A99B-6CBF41CECE5B}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: fccYPgFw - C:\WINDOWS\SYSTEM32\fccYPgFw.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 11029 bytes

-- Files created between 2008-03-24 and 2008-04-24 -----------------------------

2008-04-24 16:28:45 89152 --a------ C:\WINDOWS\system32\qxpvrobm.dll
2008-04-24 11:25:40 89664 -----n--- C:\WINDOWS\system32\ocexaxga.dll
2008-04-24 11:15:01 98417 --ahs---- C:\WINDOWS\system32\eMSuutwa.ini2
2008-04-24 11:14:55 0 d-------- C:\Program Files\YesMessenger
2008-04-24 11:14:51 272384 --a------ C:\WINDOWS\system32\awtuuSMe.dll
2008-04-24 11:11:42 38912 --a------ C:\WINDOWS\system32\urqOFXno.dll
2008-04-24 11:09:45 38912 --a------ C:\WINDOWS\system32\fccYPgFw.dll
2008-04-24 11:09:38 200704 --a------ C:\WINDOWS\qtvglped.dll
2008-04-24 11:09:38 290816 --a------ C:\WINDOWS\pmsoarbf.dll
2008-04-24 11:09:38 335872 --a------ C:\WINDOWS\omlbpkaw.dll
2008-04-24 11:09:38 98304 --a------ C:\WINDOWS\npqtsrak.exe
2008-04-24 11:09:38 286720 --a------ C:\WINDOWS\lgmxvpatfbo.dll
2008-04-24 11:09:37 98304 --a------ C:\WINDOWS\rtqmekwg.exe
2008-04-24 11:09:19 0 d-------- C:\Documents and Settings\All Users\Application Data\epmfytkn
2008-04-24 11:09:18 98304 --a------ C:\WINDOWS\system32\edsnmhev.exe
2008-04-22 06:54:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Astar Games
2008-04-20 08:47:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Intenium
2008-04-17 09:05:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-17 09:05:38 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-16 09:41:31 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Runes of Avalon 2
2008-04-16 06:41:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Malwarebytes
2008-04-16 06:41:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 06:41:35 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-15 10:41:51 0 d-------- C:\Documents and Settings\Parratjie\Application Data\BitTorrent
2008-04-15 10:41:34 0 d-------- C:\Program Files\DNA
2008-04-15 10:41:34 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DNA
2008-04-07 21:12:01 0 d-------- C:\Documents and Settings\Parratjie\Application Data\SprillBermudeEng
2008-04-04 06:48:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Meridian93
2008-04-03 05:38:00 0 d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-01 06:47:36 0 d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-28 06:41:17 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Jane s Hotel Family Hero
2008-03-25 05:37:45 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Yatec Games


-- Find3M Report ---------------------------------------------------------------

2008-04-21 18:01:26 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Real
2008-04-20 08:44:55 0 d-------- C:\Program Files\Oberon Media
2008-04-18 16:56:05 0 d-------- C:\Program Files\Java
2008-04-17 09:24:20 0 d-------- C:\Program Files\VeZA Route planner
2008-04-17 09:24:20 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-09 07:00:13 0 d-------- C:\Program Files\OFFICE11
2008-04-08 10:26:35 0 d-------- C:\Program Files\IncrediMail
2008-04-08 09:22:08 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-07 20:51:57 0 d-------- C:\Documents and Settings\Parratjie\Application Data\PlayFirst
2008-04-05 07:13:34 0 d-------- C:\Program Files\GamesBar
2008-04-01 06:40:58 0 d-------- C:\Program Files\Lavasoft
2008-04-01 06:39:57 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 06:37:24 0 d-------- C:\Documents and Settings\Parratjie\Application Data\Wildfire
2008-03-21 07:23:28 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-14 20:28:40 218929 --a------ C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2008-03-07 19:09:20 0 d-------- C:\Program Files\PartyGaming
2008-03-06 16:52:48 0 d-------- C:\Documents and Settings\Parratjie\Application Data\eGames
2008-03-02 21:51:06 0 d-------- C:\Documents and Settings\Parratjie\Application Data\DivX
2008-03-01 08:30:26 0 d-------- C:\Program Files\The Weather Channel FW
2008-02-29 19:21:11 0 d-------- C:\Documents and Settings\Parratjie\Application Data\iWin
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files
2008-02-28 14:46:25 0 d-------- C:\Program Files\Common Files\SWF Studio


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10BDDEFB-C944-4BE5-A90C-BB931273E0BD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53FE12C2-4429-488F-847B-7B285F8F6778}]
2008/04/24 11:09 AM 38912 --a------ C:\WINDOWS\system32\fccYPgFw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{942108D4-F757-4477-8587-4360F6B47A2A}]
2008/04/24 11:14 AM 272384 --a------ C:\WINDOWS\system32\awtuuSMe.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003/09/01 03:32 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004/04/23 06:24 AM]
"nwiz"="nwiz.exe" [2004/04/23 06:24 AM C:\WINDOWS\system32\nwiz.exe]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006/07/14 04:24 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004/08/04 01:56 AM C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007/04/08 08:07 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008/01/11 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008/02/22 04:25 AM]
"e43075dd"="C:\WINDOWS\system32\ocexaxga.dll" [2008/04/24 11:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006/11/30 09:49 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008/03/21 07:23 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004/08/04 01:56 AM]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008/04/15 10:41 AM]
"SpybotSD TeaTimer"="F:\Ons Eie Internet File\SPYBOT SEARCH & DESTROY\Spybot - Search & Destroy\TeaTimer.exe" [2008/01/28 11:43 AM]
"hlkxsscz"="C:\WINDOWS\system32\edsnmhev.exe" [2008/04/24 11:09 AM]

C:\Documents and Settings\Parratjie\Start Menu\Programs\Startup\
YesMessenger.lnk - C:\Program Files\YesMessenger\YesMessenger.exe [2008/04/24 11:14:56 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"disableregistrytools"=0 (0x0)
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"C72MO0I5Qy"=C:\Documents and Settings\All Users\Application Data\epmfytkn\ghixsdyj.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{53FE12C2-4429-488F-847B-7B285F8F6778}"= C:\WINDOWS\system32\fccYPgFw.dll [2008/04/24 11:09 AM 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007/04/19 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccYPgFw]
fccYPgFw.dll 2008/04/24 11:09 AM 38912 C:\WINDOWS\system32\fccYPgFw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007/05/25 03:22 PM 63040 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtuuSMe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
C:\WINDOWS\Domino.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
"C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ




-- End of Deckard's System Scanner: finished at 2008-04-24 17:31:01 ------------




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users