Tried to post this yesterday but it wouldn't go through.
"Karen" - 07-04-21 19:53:11 Service Pack 1
ComboFix 07-04-21.2V - Running from: C:\Documents and Settings\Karen\Desktop\
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\newname.dat
C:\WINDOWS\system32\dlh9jkdq2.exe
C:\WINDOWS\system32\dlh9jkdq8.exe
C:\Program Files\Common Files\simtest\svchostsys.bat
C:\Program Files\Common Files\svchostsys\ICSharpCode.SharpZipLib.dll
C:\Program Files\Common Files\svchostsys\svchostsys.exe.config
C:\Program Files\Common Files\svchostsys\svchostupdate.exe.config
C:\Program Files\Common Files\svchostsys\Version.txt
C:\Program Files\inetget2\direct3.exe
C:\Program Files\windows\WinUpdate.fld
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\dinerdash.exe
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\playfirst_logo.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\strings.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\cup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\customer_cup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\heart.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\menu_down.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\menu_up.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\plates.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\ticket.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\accessories\tray.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\music\mainmenumusic.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_bring_check_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_deliver_food_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_deliver_order_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_diner.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_dish_dropoff_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_food_ready_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_gain_heart_1.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_get_drinks_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_party_arrive_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_pencil_write_2.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_pickup_food_1_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_rollover_1.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\audio\sfx\sfx_seat_people_snd.ogg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\choosedifficulty.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\credits.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\flo_lose.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\flo_win.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\help1.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\help2.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\highscores.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\levelintro.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\levelintro_mask.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\levelover.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\levelover_mask.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\mainmenu.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\popup.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\popup_mask.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\upgradegrid.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\upgradetitle.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\backgrounds\upsell.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\arrowleft_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\arrowleft_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\arrowright_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\arrowright_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\backchalk.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\backchalkup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\backtomenu_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\backtomenu_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\back_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\back_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\cancel.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\cancelup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\career.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\career_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\close.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\closeup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\continue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\continueover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\credits_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\credits_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\download_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\download_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\easy.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\easy_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\endlessshift.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\endlessshift_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\hard.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\hard_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\help.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\help_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\highscores.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\highscores_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\instructions_blue.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\instructions_yellow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\letsplay.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\letsplayover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\medium.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\medium_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\moreinfo.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\moreinfoup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\off.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\off_on.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\on.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\on_on.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\pause.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\pauseover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\quit.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\quitgame.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\quitgameover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\quitover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\resumegame.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\resumegameover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\submit.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\submitup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\tryagain.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\tryagainover.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\upgrade_over.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\upgrade_up.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewglobal.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewglobalup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewhighscore.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewhighscoreon.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewlocal.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\buttons\viewlocalup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\comics\webcomic.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\config\career.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\config\customer.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\config\endless.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\config\global.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\config\powerups.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cook\cook.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cook\cook.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cook\stove.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cursor\arrow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cursor\click.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cursor\click2.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cursor\grab.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\cursor\open.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\blue\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\blue\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\blue\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\green\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\green\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\green\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\purple\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\purple\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\purple\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\red\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\red\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\red\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\yellow\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\yellow\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\old_male\yellow\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\blue\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\blue\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\blue\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\green\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\green\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\green\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\purple\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\purple\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\purple\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\red\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\red\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\red\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\yellow\anim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\yellow\anim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\customers\young_female\yellow\sit_legs.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\idle.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\idle.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\lower.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\lower.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\upper.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\flo\upper.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\fonts\arial.mvec
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\fonts\komikaaxis.mvec
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\chair.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\chair.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\dirt2top.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\dirt4top.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\dishcart.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\dishcart.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\drinkstation_off.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\drinkstation_on1.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\drinkstation_on2.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\ticketstation.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\furniture\ticketstation.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowdown.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowdownon.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowleft.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowlefton.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowright.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowrighton.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\arrowupon.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\p1icon.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\textedit.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\hiscore\title.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_1.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_1_a.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_1_b.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_1_c.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_2.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_2_a.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_2_b.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_2_c.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_2_d.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_3.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_3_a.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_3_b.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_3_c.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\endless_1_3_d.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\fifth_level_diner.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\first_level_diner.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\fourth_level_diner.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\layouts\second_level_diner.txt
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\tableshadow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\background.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\upgrades.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food1.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food1.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food2.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food2.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food3.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\food\food3.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\frames\upgrade_0001.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\tables\2top.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\tables\2top.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\tables\4top.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\restaurants\diner\tables\4top.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\choosedifficulty.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\chooseplayer.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\chooserestaurant.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\credits.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\game.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\gothighscore.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\help.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\help2.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\hiscore.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\hiscoreinfo.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\hiscoresubmit.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\levelintro.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\levelover.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\loading.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\mainloop.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\mainmenu.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\ok.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\pause.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\style.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\tutorialintro.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\upgrade.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\upsell.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\webcomic.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\scripts\yesno.lua
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\splash\aol_logo.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\splash\gamelabsplash.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\splash\playfirst_logo.jpg
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\angersmoke.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\angersmoke.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\chairflags.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\chairflags.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\check.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\checkmark.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\clock.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\closed.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\closingtime.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\coinflip.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\coinflip.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\dollar.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\expert.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\expertscore.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\foodpoof.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\foodpoof.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\fork_timer.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\goalcompleted.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\heartgrow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\heartgrow.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\jar.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\jar.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\level.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\level_career.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\score.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\sound.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\staroff.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\staron.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\tablenumber.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\tablenumberup.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\traynumber.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\tutorialarrow.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\tutorialbox.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\tutorial_character.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgradeanim.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgradeanim.xml
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\doodles\coffee.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\doodles\tables.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\doodles\wallpaper.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\drinks.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\maitred.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\oven.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\select.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\shoes.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\stereo.png
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92\assets\ui\upgrades\table.png
C:\DOCUME~1\Karen\Desktop.\internet explorer.lnk
C:\DOCUME~1\Karen\Desktop\internet.lnk
C:\install.log
C:\Program Files\Common Files\inetget
C:\Program Files\Common Files\misc001
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\svchostsys
C:\Program Files\dialers
C:\Program Files\inetget2
C:\Program Files\windows
C:\WINDOWS\DOWNLO~1.\DDSonic.1.0.0.92
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\Program Files\ASEMBL~1
C:\qoobox\purity\C\Program Files\FNTS~1
C:\qoobox\purity\C\Program Files\PPATCH~1
C:\qoobox\purity\C\Program Files\RACLE~1
C:\qoobox\purity\C\Program Files\SCURIT~1
C:\qoobox\purity\C\Program Files\SEMBLY~1
C:\qoobox\purity\C\Program Files\WNSXS~1
C:\qoobox\purity\C\Program Files\YSTEM3~1
C:\qoobox\purity\C\Program Files\Common Files\ASEMBL~1
C:\qoobox\purity\C\Program Files\Common Files\CROSOF~1
C:\qoobox\purity\C\Program Files\Common Files\FNTS~1
C:\qoobox\purity\C\Program Files\Common Files\MCROSO~1.NET
C:\qoobox\purity\C\Program Files\Common Files\YMANTE~1
C:\qoobox\purity\C\WINDOWS\ASKS~1
C:\qoobox\purity\C\WINDOWS\ICROSO~1
C:\qoobox\purity\C\WINDOWS\system32\DOBE~1
C:\qoobox\purity\C\WINDOWS\system32\MCROSO~1
C:\qoobox\purity\C\WINDOWS\system32\MCROSO~1.NET
C:\qoobox\purity\C\WINDOWS\system32\PPATCH~1
C:\qoobox\purity\C\WINDOWS\system32\RACLE~1
C:\qoobox\purity\C\WINDOWS\system32\SCURIT~1
C:\qoobox\purity\C\WINDOWS\system32\YMBOLS~1
C:\qoobox\purity\C\WINDOWS\system32\RACLE~1\RACLE~1
((((((((((((((((((((((((((((((( Files Created from 2007-03-21 to 2007-04-21 ))))))))))))))))))))))))))))))))))
2007-04-21 17:23 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-04-21 16:48 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-21 16:08 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-04-19 12:50 <DIR> d-------- C:\DOCUME~1\Karen\APPLIC~1\acccore
2007-04-19 12:40 <DIR> d-------- C:\Program Files\AIM6
2007-04-18 15:46 <DIR> d-------- C:\HJT
2007-04-18 14:09 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-04-18 01:13 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-04-17 23:12 <DIR> d-------- C:\DOCUME~1\Ed\APPLIC~1\SpamBlockerUtility_Icons
2007-04-17 23:04 <DIR> d-------- C:\DOCUME~1\Ed\APPLIC~1\MySpace
2007-04-17 23:04 <DIR> d-------- C:\DOCUME~1\Ed\APPLIC~1\AIMPro
2007-04-17 23:03 <DIR> d-------- C:\DOCUME~1\Ed\APPLIC~1\SpamBlockerUtility
2007-04-17 17:52 <DIR> d-------- C:\Program Files\SpamBlockerUtility
2007-04-17 17:52 <DIR> d-------- C:\Program Files\IE Protector And Tracks Eraser
2007-04-17 17:52 <DIR> d-------- C:\DOCUME~1\Karen\APPLIC~1\SpamBlockerUtility_Icons
2007-04-17 17:52 <DIR> d-------- C:\DOCUME~1\Karen\APPLIC~1\SpamBlockerUtility
2007-04-17 17:52 <DIR> d-------- C:\DOCUME~1\Karen\APPLIC~1\SpamBlocker
2007-04-16 09:27 4,636,672 --a------ C:\DOCUME~1\Karen\ntuser.dat
2007-04-03 13:00 <DIR> d-------- C:\Temp\HP_WebRelease
2007-04-02 20:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Incomplete
2007-03-31 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-03-31 17:42 <DIR> d-------- C:\DOCUME~1\Karen\AIMPro
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-21 16:08 2560 --a------ C:\WINDOWS\_msrstrt.exe
2007-04-21 16:08 -------- d-------- C:\Program Files\viewpoint
2007-04-20 11:36 -------- d-------- C:\Program Files\navnt
2007-04-20 11:35 -------- d-------- C:\Program Files\symantec
2007-04-18 18:49 1082 --a------ C:\WINDOWS\system32\winpfz32.sys
2007-04-18 14:09 -------- d--h----- C:\Program Files\windowsupdate
2007-04-02 20:05 -------- d-------- C:\DOCUME~1\Karen\APPLIC~1\yahoo!
2007-04-01 16:31 -------- d-------- C:\DOCUME~1\Karen\APPLIC~1\viewpoint
2007-03-19 18:07 -------- d-------- C:\DOCUME~1\Karen\APPLIC~1\hp
2007-03-19 17:59 112886 --a------ C:\WINDOWS\hpoins07.dat
2007-02-27 09:57 184435 --a------ C:\WINDOWS\system32\swintodx.exe
2007-02-12 07:55 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"nwiz"="nwiz.exe /install"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1140711823\\ee\\AOLSoftware.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"vptray"="C:\\Program Files\\NavNT\\vptray.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"TivoServer"="\"C:\\Program Files\\TiVo\\Desktop\\TiVoServer.exe\" /service /auto:TivoServer"
"MySpaceIM"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=""
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ookk"="C:\\Program Files\\Common Files\\ookk\\ookkm.exe"
"MySpaceIM"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"WinUpdate.exe"="C:\\Program Files\\Windows\\WinUpdate.exe"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source REG_SZ C:\WINDOWS\warnhp.html
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5}"="st3"
"{C7CF1142-0785-4B12-A280-B64681E4D45E}"="z"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest
Notification Packages REG_MULTI_SZ scecli
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV
NetworkService REG_MULTI_SZ DnsCache
rpcss REG_MULTI_SZ RpcSs
imgsvc REG_MULTI_SZ StiSvc
termsvcs REG_MULTI_SZ TermService
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070421-163055-787
O23 - Service: Windows Alerter (ALT) - Unknown owner - C:\WINDOWS\services.exe (file missing)
backup-20070421-163054-495
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\winmp32.dll (file missing)
backup-20070421-163054-260
O17 - HKLM\System\CS1\Services\Tcpip\..\{0025578F-2414-49C8-84A8-C5144345F71B}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-676
O17 - HKLM\System\CCS\Services\Tcpip\..\{B73DDBC4-CB7E-4E71-ACD3-58BDCFF97738}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-509
O17 - HKLM\System\CS2\Services\Tcpip\..\{0025578F-2414-49C8-84A8-C5144345F71B}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-537
O17 - HKLM\System\CCS\Services\Tcpip\..\{A92CA0B8-00FE-46AD-B21E-D69487D4EC51}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-287
O17 - HKLM\System\CCS\Services\Tcpip\..\{66BB3FF3-E4E6-41B7-8195-F84A95ECA6B9}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-164
O17 - HKLM\System\CCS\Services\Tcpip\..\{788CC061-E4B5-4C76-B7B0-67AF4E439B8D}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-876
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BBF9A52-DD77-45B9-B2C2-180657B67B9D}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-309
O17 - HKLM\System\CCS\Services\Tcpip\..\{35045A3F-19BD-4E4C-939A-582147EBEDB8}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-319
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FB1C57D-5C46-4C09-9700-B7CF2241D8E3}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-339
O17 - HKLM\System\CCS\Services\Tcpip\..\{0025578F-2414-49C8-84A8-C5144345F71B}: NameServer = 85.255.116.89,85.255.112.204
backup-20070421-163054-304
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} -
http://locator1.cdn.imagesrvr.com/sites/wi...nnerInstall.cabbackup-20070421-163054-470
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} -
http://awbeta.net-nucleus.com/FIX/WinATS.cabbackup-20070421-163054-793
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX27.cabbackup-20070421-163053-988
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} -
http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1112backup-20070421-163053-487
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) -
https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CABbackup-20070421-163053-431
O16 - DPF: {2A510DC8-C9B5-4269-B9BA-E5B04D47D981} (CPlayFirstDDSonicControl Object) -
http://www.shockwave.com/content/dinerdash...ic.1.0.0.92.cabbackup-20070421-163052-505
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cabbackup-20070421-163052-765
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windupdates.com/cab/6247971C...e/bridge-c8.cabbackup-20070421-163052-215
O16 - DPF: {03A0F84E-3E69-4B3E-B4D3-019CB73B57B3} -
http://www3.authentium.com/cssrelease/bin/WizMain.exebackup-20070421-163052-884
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
backup-20070421-163051-485
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
backup-20070421-163051-660
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swintodv.exe
backup-20070421-163051-169
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Karen\Local Settings\Temp\{A7FD5ADB-FEDF-4BF8-8AE9-C19C9C06BE71}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
backup-20070421-163051-977
O4 - Startup: PowerReg Scheduler V3.exe
backup-20070421-163051-409
O4 - HKCU\..\Run: [killall] control64.exe
backup-20070421-163051-915
O4 - HKCU\..\Run: [RtlFindVal] teqq32.exe
backup-20070421-163051-370
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
backup-20070421-163051-484
O4 - HKCU\..\Run: [nmdllw] trycrt.exe
backup-20070421-163051-101
O4 - HKCU\..\Run: [ookk] C:\PROGRA~1\COMMON~1\ookk\ookkm.exe
backup-20070421-163051-884
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\484~1.0\SBInst.exe
backup-20070421-163051-665
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
backup-20070421-163051-926
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
backup-20070421-163051-944
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20070421-163051-691
O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
backup-20070421-163051-574
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\swintodv.exe GID003
backup-20070421-163051-172
O4 - HKLM\..\Run: [dmgqq.exe] C:\WINDOWS\System32\dmgqq.exe
backup-20070421-163051-313
O4 - HKLM\..\Run: [JAguAr] srbho.exe
backup-20070421-163051-674
O4 - HKLM\..\Run: [DTOURS] xwiz.exe
backup-20070421-163051-453
O4 - HKLM\..\Run: [AppMasterCenter] TemplateDongle.exe
backup-20070421-163051-584
O4 - HKLM\..\Run: [newname] C:\\newname25.exe
backup-20070421-163051-534
O4 - HKLM\..\Run: [fkh] C:\WINDOWS\fkh.exe
backup-20070421-163051-862
O3 - Toolbar: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbHostIE.dll
backup-20070421-163051-808
O3 - Toolbar: (no name) - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - (no file)
backup-20070421-163051-809
O4 - HKLM\..\Run: [SetupExeDll] _ctcp.exe
backup-20070421-163051-292
O4 - HKLM\..\Run: [links] links.exe
backup-20070421-163051-861
O2 - BHO: (no name) - {B4FABB59-2FEF-0C36-9584-7622518F7BC0} - C:\WINDOWS\System32\zoklp.dll
backup-20070421-163051-418
O2 - BHO: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbHostIE.dll
backup-20070421-163051-868
O2 - BHO: (no name) - {B0279FA8-5A4E-20E7-4493-21C0DC57019E} - C:\WINDOWS\System32\tonme.dll (file missing)
backup-20070421-163051-421
R3 - URLSearchHook: (no name) - {158F1EF3-E49C-F12E-505B-20F4F84588B7} - ___.dll (file missing)
backup-20070421-163051-220
O2 - BHO: (no name) - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - (no file)
backup-20070421-163051-785
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://resultsmaster.com/SmartOffers/Servi...omeLeftPane.htmbackup-20070421-163051-389
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.bearshare.com/sidebar.html?src=ssbbackup-20070421-163051-644
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://search.bearshare.com/sidebar.html?src=ssbbackup-20070421-163051-610
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.bearshare.com/sidebar.html?src=ssbbackup-20070421-163051-599
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=20065&k=
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\SDMsgUpdate (SmartDrawTrial).job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-04-21 20:03:44
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-21 20:05:00
C:\ComboFix-quarantined-files.txt ... 07-04-21 20:05