Ok I'm back after fiddling for some time. Have editted and re-editted this so apologise if you have been on trying to access.
Anyway here's an update from your last message to now:
Couldn't get Safe Mode to work (no beep and when I did get screen up by switching off during boot, it wouldn't toggle to safe mode??
Ran SDFix Runthis.bat anyway and it had no 'Y' option (tried Y anyway but nothing happened on reboot)
Options that are available are 1,2,3,4 A,B,C,D,H,R,U or E (exit)
A is create system report
B is create service /driver list
C is Create catchMe log
D is Export Safeboot Key
H is Add Window Default Host File
R is Repair Safeboot Key
U is Download Latest SDFix
1 is download ASquared
2 is DoWnload Norman Malware Cleaner
3 is Sav32cu
4 is AVPTOOL
So….
Downloaded and ran COMBOFIX
I tried this because I read through other posts on this and other sites. I havent DEEWOO, it is no longer in Start up and looks to be gone. Still didnt get a beep when loading up however never tried F8 to see if safe mode works (will do next time I log in). I have pasted the Combofix log below. What do you think? Below this is an updated HJT log? Below this I have pasted a scan report from ASquared which I run to see if i had any adware. I quarantined Trojan-Downloader.W32.Small.buy which came out as a high risk and a trace registry for Kazaa which I havent got downloaded on this PC.
I AM STILL GETTING POP UPS - while on line - not intense 3 pagescame on and after 30 mins+ another page popped up. Havent done reboot yet but doubt this affects it.
What do you recommend now. Also what should I download as protection for my system against adware,spyware,malware,virus etc. I have ASquared (which has worked with some things) and also this Norton Check Up thing(Which doesnt do anything really, so will delete shortly I think)
Once again thanks for your assistance. Now for the reboot!! Speak soon, thanks
================================================================================
==================================
ComboFix 08-11-19.08 - Carl 2008-11-20 10:22:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.543 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\docume~1\Carl\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\Carl\Application Data\gadcom
c:\documents and settings\Carl\Application Data\gadcom\gadcom.exe
c:\documents and settings\Carl\Application Data\ShoppingReport
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\Carl\Favorites\Online Security Test.url
c:\documents and settings\Carl\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Carl\Start Menu\Programs\Startup\Deewoo.lnk
c:\documents and settings\Carl\Start Menu\Programs\Startup\DW_Start.lnk
c:\documents and settings\LocalService\Application Data\NetMon
c:\documents and settings\LocalService\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService\Application Data\NetMon\log.txt
c:\program files\GetPack
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\GetPack24.exe
c:\program files\GetPack\trgtame.gz
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\network monitor
c:\program files\network monitor\netmon.exe
c:\program files\OneStepSearch
c:\program files\OneStepSearch\home.js
c:\program files\OneStepSearch\readme.html
c:\program files\pcast
c:\recycler\ADAPT_Installer.exe
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\Downloaded Program Files\setup.inf
c:\windows\Q2FybCBRdWFydGVybWFpbg\
c:\windows\Q2FybCBRdWFydGVybWFpbg\\asappsrv.dll
c:\windows\Q2FybCBRdWFydGVybWFpbg\\command.exe
c:\windows\Q2FybCBRdWFydGVybWFpbg\\kZIVvF1lxqIVx3pVvqIDv0.vbs
c:\windows\Q2FybCBRdWFydGVybWFpbg\command.exe
c:\windows\system32\aqmmyf.dll
c:\windows\system32\atmtd.dll
c:\windows\system32\cgaiho(2).dll
c:\windows\system32\cwulmy.dll
c:\windows\system32\ddcBQkHY.dll
c:\windows\system32\dwwnw64r.exe
c:\windows\system32\fwpsuvnh.ini
c:\windows\system32\gside.exe
c:\windows\system32\hnvuspwf.dll
c:\windows\system32\kltgacrf.dll
c:\windows\system32\kprqfdio.dll
c:\windows\system32\mlqlma.dll
c:\windows\system32\MSINET.oca
c:\windows\system32\msnav32.ax
c:\windows\system32\pac.txt
c:\windows\system32\ppjfuq.dll
c:\windows\system32\rkpvvptx.dll
c:\windows\system32\rqRLdETM.dll
c:\windows\system32\rswnw64l.exe
c:\windows\system32\ssqPICRI.dll
c:\windows\system32\sxvgbvab.dll
c:\windows\system32\ujnsswrf.ini
c:\windows\system32\winpfz33.sys
c:\windows\system32\YHkQBcdd.ini
c:\windows\system32\YHkQBcdd.ini2
c:\windows\system32\ykogmycl.ini
c:\windows\system32\zxdnt3d.cfg
c:\windows\ufdata2000.log
c:\windows\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_CMDSERVICE
——-\Legacy_NETWORK_MONITOR
——-\Service_cmdService
——-\Service_Network Monitor
((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.
2008-11-20 09:11 . 2008-11-20 09:11 1,529,241 –a—— C:\SDFix.exe
2008-11-20 08:52 . 2008-11-20 08:52 41,472 –a—— c:\windows\system32\vxnpwxlw.dll
2008-11-20 00:13 . 2008-11-20 09:59 d——– C:\SDFix
2008-11-20 00:07 . 2008-11-20 00:07 465,920 –a—— c:\windows\system32\iesvcmon.exe
2008-11-20 00:07 . 2008-11-20 00:07 53,938 –a—— c:\windows\system32\cont_adsoftinc-remove.exe
2008-11-19 10:15 . 2008-11-19 10:15 600,576 –a—— c:\windows\system32\jpvycakhwzdspam.dll
2008-11-19 07:24 . 2008-11-19 07:24 41,472 –a—— c:\windows\system32\gklxpket.dll
2008-11-18 23:49 . 2008-11-18 23:49 41,472 –a—— c:\windows\system32\dwtqibih.dll
2008-11-18 23:29 . 2008-11-18 23:29 d——– c:\program files\Trend Micro
2008-11-18 22:57 . 2008-11-18 22:57 d——– c:\program files\ERUNT
2008-11-18 22:29 . 2008-11-20 08:52 88,372 –a—— c:\windows\system32\jpvycakhwzdspam.dll-uninst.exe
2008-11-17 23:48 . 2008-11-17 23:48 41,472 –a—— c:\windows\system32\upryaxhx.dll
2008-11-17 23:43 . 2008-11-17 23:43 d——– c:\program files\PartyGaming
2008-11-17 16:59 . 2008-11-17 16:59 d——– c:\documents and settings\Carl\Application Data\IUpd721
2008-11-17 16:46 . 2008-11-17 16:46 548,928 –a—— c:\windows\system32\pcnttsdl.exe
2008-11-17 16:46 . 2008-11-17 16:46 153,483 –a—— c:\windows\system32\g76.exe
2008-11-17 16:46 . 2008-11-18 12:30 77,895 –a—— c:\windows\system32\cirjrsdilspfpvb.exe
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\sX3i19
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\nas
2008-11-17 16:45 . 2008-11-17 16:46 d——– c:\windows\system32\mex
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\ITX
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\dcs2
2008-11-17 16:45 . 2008-11-17 16:46 d——– c:\temp\PRE45
2008-11-17 16:45 . 2008-11-20 10:23 d——– C:\Temp
2008-11-17 16:45 . 2008-11-17 16:45 35,840 –a—— c:\windows\system32\prun.exe
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\program files\TVUPlayer
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\Carl\LocalLow
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-01 09:37 . 2008-11-01 09:37 178,176 –a—— c:\windows\system32\pyinryaknafj.dll
2008-10-28 15:20 . 2008-10-28 15:20 555,008 –a—— c:\windows\system32\nsn59D.dll
2008-10-26 14:35 . 2008-10-26 14:35 d——– c:\program files\iLike
2008-10-21 22:53 . 2008-10-21 22:53 d——– c:\program files\Freeze.com
2008-10-21 22:53 . 2008-10-21 23:07 243 –a—— C:\log.html
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 23:43 ——— d—–w c:\program files\Winferno
2008-11-11 10:18 ——— d—–w c:\documents and settings\Carl\Application Data\Image Zone Express
2008-11-03 19:46 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-03 08:33 ——— d—–w c:\program files\Common Files\Adobe
2008-11-02 20:43 ——— d—–w c:\program files\Windows Live
2008-11-02 15:15 ——— d—–w c:\program files\PKR
2008-11-01 12:05 ——— d—–w c:\program files\Zylom Games
2008-10-30 17:03 ——— d—–w c:\program files\iTunes
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 13:23 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Zylom
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Jane s Hotel Family Hero
2008-10-07 20:00 ——— d—–w c:\documents and settings\Carl\Application Data\Total Eclipse
2008-10-06 16:29 ——— d—–w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-10-02 20:46 ——— d—–w c:\documents and settings\Carl\Application Data\PlayFirst
2008-10-02 20:46 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2008-09-28 21:07 ——— d—–w c:\program files\UUTV
2008-09-28 10:49 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-28 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\SpinTopV1005
2008-09-28 09:42 ——— d—–w c:\program files\FinePixViewerS
2008-09-27 20:54 ——— d—–w c:\documents and settings\All Users\Application Data\Zylom
2008-09-26 10:19 ——— d—–w c:\documents and settings\All Users\Application Data\GameHouse
2008-09-21 12:48 ——— d—–w c:\documents and settings\Carl\Application Data\SpinTop
2007-06-04 21:44 20,632 —-a-w c:\documents and settings\Carl\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CF9E491-A3D7-4C5A-CA99-A8DE8FA87955}]
2008-11-20 09:44 325120 –a—— c:\windows\system32\pyinryaknafj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74fe2921-9c19-35aa-8e46-c45c444e809c}]
2008-10-28 15:20 555008 –a—— c:\windows\system32\nsn59D.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0E80497-094E-6810-BB98-70792C1068C4}]
2008-11-19 10:15 600576 –a—— c:\windows\system32\jpvycakhwzdspam.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"prunnet"="c:\windows\system32\prun.exe" [2008-11-17 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-23 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"prunnet"="c:\windows\system32\prun.exe" [2008-11-17 35840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-20 465920]
"vdfhaeheeuhnyxqtq"="c:\windows\system32\pyinryaknafj.dll" [2008-11-20 325120]
"nwiz"="nwiz.exe" [2006-07-12 c:\windows\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-01 c:\windows\RTHDCPL.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
"iLike"="c:\program files\iLike\1.1.51\ilikesidebar.exe" [2008-09-10 63024]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-01-18 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-01-20 671744]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ppjfuq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Documents and Settings\\Carl\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
R2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2007-01-20 3712]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2007-01-21 167424]
.
Contents of the 'Scheduled Tasks' folder
2008-11-12 c:\windows\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 21:50]
2008-11-15 c:\windows\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 21:50]
2008-10-22 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{c9f821c6-221f-4c6e-8f47-359adc5f2b01} - c:\windows\system32\ppjfuq.dll
BHO-{E4EDCFE7-5488-4A47-B175-4F45FBA15683} - c:\windows\system32\ddcBQkHY.dll
HKCU-Run-GetPack24 - c:\program files\GetPack\GetPack24.exe
HKLM-Run-trioService - c:\progra~1\Freeze.com\Halloween\\trioService.exe
HKLM-Run-{D6-6C-C3-3D-DW} - c:\windows\system32\rswnw64l.exe
HKLM-Run-IMJPMIG8.2 - msime82.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Carl\Application Data\Mozilla\Firefox\Profiles\3eyqhdeo.default\
FF -: plugin - c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - c:\documents and settings\Carl\Application Data\Mozilla\Firefox\Profiles\3eyqhdeo.default\extensions\[removed]\plugins\npTVUAx.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - c:\program files\Virtools\3D Life Player\npvirtools.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-20 10:34:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Logitech\khalshared\KHALMNPR.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\windows\system32\regsvr32.exe
.
**************************************************************************
.
Completion time: 2008-11-20 10:45:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-20 10:45:21
Pre-Run: 24,163,655,680 bytes free
Post-Run: 25,139,478,528 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
275 — E O F — 2008-11-12 22:18:40
================================================================================
====================
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:50, on 20/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\iesvcmon.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: agadoo browser enhancer - {5CF9E491-A3D7-4C5A-CA99-A8DE8FA87955} - C:\WINDOWS\system32\pyinryaknafj.dll
O2 - BHO: adsoftinc - {74fe2921-9c19-35aa-8e46-c45c444e809c} - C:\WINDOWS\system32\nsn59D.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: mysidesearch search enhancer - {E0E80497-094E-6810-BB98-70792C1068C4} - C:\WINDOWS\system32\jpvycakhwzdspam.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iesvcmon] "C:\WINDOWS\system32\iesvcmon.exe"
O4 - HKLM\..\Run: [vdfhaeheeuhnyxqtq] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\pyinryaknafj.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.1.51\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm443YYGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) -
http://www.euchannels.net/KooPlayer.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://signin3.valueactive.com/Register/Br…018/flashax.cab
O20 - AppInit_DLLs: ppjfuq.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
–
End of file - 9839 bytes
================================================================================
==================================
a-squared Free - Version 3.1
Last update: 13/02/2008 23:19:01
Scan settings:
Objects: Memory, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 20/11/2008 11:32:47
c:\documents and settings\carl\application data\microsoft\internet explorer\quick launch\titan poker.lnk detected: Trace.File.Titan Poker
c:\documents and settings\all users\start menu\programs\titan poker\titan poker.lnk detected: Trace.File.Titan Poker
c:\documents and settings\all users\start menu\programs\titan poker\uninstall titan poker.lnk detected: Trace.File.Titan Poker
Key: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\software\kazaa detected: Trace.Registry.KaZaA
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Titan Poker –> Order detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_music detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_avatar_num detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_sounds detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options-fullscreen detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options-volume detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> ButtonText detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Default Visible detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Exec detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> HotIcon detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Icon detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> MenuText detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> ToolTip detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker –> DisplayName detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker –> UninstallString detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> account detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> advertisercode detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> banner detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> creferer detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> profile detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> referer detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> safemode detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> uninstall detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> uninstall_lang detected: Trace.Registry.Titan Poker
c:\program files\winferno\registrypowercleaner detected: Trace.Directory.RegistryPowerCleaner
c:\program files\partygaming detected: Trace.Directory.PartyPoker
c:\program files\partygaming\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\de_de detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\de_de\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\blackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\blackjack\blackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\multiplayerbj detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\multiplayerbj\multiplayerblackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\es_es detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\es_es\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\images detected: Trace.Directory.PartyPoker
c:\documents and settings\carl\start menu\programs\partypoker detected: Trace.Directory.PartyPoker
c:\documents and settings\all users\start menu\programs\titan poker detected: Trace.Directory.Titan Poker
c:\documents and settings\carl\application data\microsoft\internet explorer\quick launch\partypoker.lnk detected: Trace.File.PartyPoker
c:\program files\partygaming\ara.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\dm.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\libeay32.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\llh.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\gra.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\partycasino.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\sys.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partygaming.exe detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\gra.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\54866.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\54870.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\62958.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\partypoker.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\ppunistall.bat detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\runapp.exe detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\sys.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\ssleay32.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\zlib1.dll detected: Trace.File.PartyPoker
c:\documents and settings\carl\start menu\programs\partypoker\partypoker.lnk detected: Trace.File.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 1 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 10 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 2 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 4 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 5 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 6 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 7 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 9 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> AdsLastKnownState detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> AppPath detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> BlackjackSounds detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> BlackjackVoice detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCallOuts detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCardAnimations detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCongratulations detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableSounds detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> FourColourDeck detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHEnableLog detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHLogDays detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHLogSize detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> id detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> InitialPort detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> InstallState detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> MuckLosingHand detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> SL detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> TableType detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> useCount detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> AutoLoginToOtherGames detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> CFDialogShown detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> FreshInstall detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> OldCFformat detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> ButtonText detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> CLSID detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Default Visible detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Exec detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> HotIcon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Icon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> MenuStatusBar detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> MenuText detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Path detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayIcon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayName detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayVersion detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallDate detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallLocation detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallSource detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallSourceFile detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> Publisher detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> SilentSettings detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> UninstallString detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funaccount detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funnickname detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funusername detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> global_login_hint detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> lobby_favouritegames detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_autologinfun detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_dealervoices detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_empty detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_finished detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_full detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_inprogress detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_showsidegames detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_smallview detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_xlslots detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> poker_login_type detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> poker_nickname detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> ptdevm detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> tribeca_playernotes detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> username detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> CLSID detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> homedir detected: Trace.Registry.Titan Poker
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@adtech[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@advertising[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@atdmt[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@computerhope[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@doubleclick[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@hitbox[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@hotbar[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@media6degrees[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@mediaplex[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@mediatraffic[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@pro-market[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@realmedia[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@revenuehit[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][3].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@tradedoubler[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@tribalfusion[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@zedo[1].txt detected: Trace.TrackingCookie
C:\WINDOWS\system32\ITX\CMAE3av.exe detected: Trojan-Downloader.Win32.Small.buy
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\Base\TSBin\Sims2.exe detected: Heuristic.Dialer.RAS
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\EP2\TSBin\Sims2EP2.exe detected: Heuristic.Dialer.RAS
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\SP4\TSBin\Sims2SP4.exe detected: Heuristic.Dialer.RAS
Scanned
Files: 96776
Traces: 369019
Cookies: 214
Processes: 42
Found
Files: 4
Traces: 146
Cookies: 21
Processes: 0
Registry keys: 0
Scan end: 20/11/2008 12:02:15
Scan time: 0:29:28
C:\WINDOWS\system32\ITX\CMAE3av.exe quarantined: Trojan-Downloader.Win32.Small.buy
Key: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\software\kazaa quarantined: Trace.Registry.KaZaA
quarantined:
Files: 1
Traces: 1
Cookies: 0