C:\Documents and Settings\Despe\Application Data\Mozilla\Firefox\Profiles\76dxz8hu.eugénie\prefs.js (.not file.)
M0 - MFSP: prefs.js [Despe - 76dxz8hu.eugénie]
http://allssearch.comM0 - MFSP: user.js [Despe - 76dxz8hu.eugénie]
http://allssearch.com/M0 - MFSP: user.js [Despe - 76dxz8hu.eugénie]
http://allssearch.com/ P2 - FPN:Firefox Plugin Navigator . (.PopCap Games - PopCap Games Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nppopcaploader.dll
R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.rpidity.com O4 - HKLM\..\Run: [ReadingFanatic Search Scope Monitor] C:\Program Files\READIN~2\bar\1.bin\6xsrchmn.exe (.not file.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - (SpinTop DRM Control) - (.not file.) - C:\Program Files\Artist Colony\Images\stg_drm.ocx
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) -
http://m.boonty.com/webgames/TriJinx/Tr ... 0.0.55.cab O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) -
http://m.boonty.com/webgames/PiratesPop ... 0.0.24.cab O16 - DPF: {5392B545-31A5-4724-BEF3-4FED1D56FDAC} - (CPlayFirstDinerDash2_frControl Object) - (.not file.) - C:\Documents and Settings\Eugénie\Local Settings\Application Data\Oberon Media\Oberon Games Host\DinerDash2_fr.1.0.0.70.cab
O16 - DPF: {AA59202C-5E41-48FC-AF7D-324F5FD6A9F1} () -
http://scripts.dlv4.com/binaries/egacce ... _em_XP.cab O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} - (CPlayFirstddfotgControl Object) - (.not file.) - C:\Documents and Settings\Eugénie\Local Settings\Application Data\Oberon Media\Oberon Games Host\ddfotg.1.0.0.37.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game12.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - (ArmHelper Control) - (.not file.) - C:\Program Files\Monster Mash\Images\armhelper.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - (PopCapLoader Object) - (.not file.) - C:\Documents and Settings\Eugénie\Local Settings\Application Data\Oberon Media\Oberon Games Host\popcaploader_v6.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) -
http://m.boonty.com/webgames/Sweetopia/ ... 0.0.20.cab O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Express DownloaderUpdate.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Go for FilesUpdate.job
[MD5.00000000000000000000000000000000] [APT] [Express DownloaderUpdate] (...) -- C:\Program Files\ExpressDownloader\EDUpdater.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [Go for FilesUpdate] (...) -- C:\Program Files\GoforFiles\GFFUpdater.exe (.not file.)
[HKCU\Software\SweetIM]
[HKCU\Software\Trymedia Systems]
[HKCU\Software\fcn]
[HKCU\Software\iWinArcade]
[HKLM\Software\Companion Wizard]
[HKLM\Software\SweetIM]
[HKLM\Software\Trymedia Systems]
[HKLM\Software\iWinArcade]
[HKLM\Software\iWin]
O43 - CFD: 26/10/2012 - 11:33:06 - [0] ----D C:\Program Files\rpidity
O43 - CFD: 11/07/2009 - 16:32:20 - [0,032] ----D C:\Documents and Settings\Despe\Application Data\PopCapv1002
O59 - HSMI:Heuristic Search MagicControl Infection - C:\WINDOWS\system32\nvs2.inf
O69 - SBI: SearchScopes [HKCU] {fe8a5a30-7831-4eb2-a9e7-8402c384c841} - (My Web Search) -
http://search.mywebsearch.com FirewallRaz
EmptyFlash
Emptytemp