Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
 
Closed TopicStart new topic
malware on my pc (Vundo, backdoor.bot, trojan.tdss, malware.trace etc.
crdavis221
post May 17 2009, 01:15 PM
Post #1


New Member
*
Posts: 6
OS: XP SP3



Hi,

I really need help in trying to find out what is wrong with my computer. Last week I noticed redirects and downloaded Malewarebytes and did a complete scan. It found quite a bit and asked me to restart to remove additional files, which I did. It also found more files on additional scans but these seemed to be "restore" files. I turned off sys resore and rebooted and have yet to turn it back on. I did another scan today as I still get redirects and it found Trojan.FakeAlert which I removed. Also in reading your Malware removal section, I have tried downloading the various tools but when doing so the download window pops ups on my screen and it never moves past 0%. I do have HijackThis so hopefully that will assist. Any assistance is greatly appreciated!!!

I have attached the logs from Malewarebytes and HiJackThis.

Malwarebytes

Malwarebytes' Anti-Malware 1.36
Database version: 2131
Windows 5.1.2600 Service Pack 3

5/14/2009 4:12:58 PM
mbam-log-2009-05-14 (16-12-58).txt

Scan type: Quick Scan
Objects scanned: 152255
Time elapsed: 19 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 36
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/piratepoppers.1.0.0.24.dll (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{49e67060-2c0d-415e-94c7-52a49f73b2f1} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{38d97cce-7243-4b6e-b6a8-dd872ad3eb33} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6868afe5-f258-47dc-bc37-0821f96dc1d2} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{49e67060-2c0d-415e-94c7-52a49f73b2f1} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{49e67060-2c0d-415e-94c7-52a49f73b2f1} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\downloader.downloaderctrl.1 (Adware.2020search) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\PiratePoppers.1.0.0.24.dll (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\twext.exe -> Delete on reboot.

Folders Infected:
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Delete on reboot.

Files Infected:
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\Downloaded Program Files\PiratePoppers.1.0.0.24.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TDSS115d.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twext.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\Downloaded Program Files\PiratePoppers.1.0.0.24.inf (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSqiyk.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSwghd.log (Trojan.TDSS) -> Quarantined and deleted successfully.

Malwarebytes' Anti-Malware 1.36
Database version: 2131
Windows 5.1.2600 Service Pack 3

5/15/2009 1:31:27 AM
mbam-log-2009-05-15 (01-31-27).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)
Objects scanned: 289880
Time elapsed: 1 hour(s), 39 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 27

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091399.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091417.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091386.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091393.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091397.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091401.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091406.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091407.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091408.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091409.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091410.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091411.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091413.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091414.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091415.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091416.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091418.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091419.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091420.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1054\A0091423.DLL (Adware.FunWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091571.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091572.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091574.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091575.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091576.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1061\A0091577.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1062\A0091681.dll (Adware.MyWeb) -> Quarantined and deleted successfully.

Malwarebytes' Anti-Malware 1.36
Database version: 2131
Windows 5.1.2600 Service Pack 3

5/15/2009 1:58:50 AM
mbam-log-2009-05-15 (01-58-50).txt

Scan type: Quick Scan
Objects scanned: 151651
Time elapsed: 21 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Malwarebytes' Anti-Malware 1.36
Database version: 2132
Windows 5.1.2600 Service Pack 3

5/16/2009 8:41:03 PM
mbam-log-2009-05-16 (20-41-03).txt

Scan type: Quick Scan
Objects scanned: 17
Time elapsed: 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Malwarebytes' Anti-Malware 1.36
Database version: 2145
Windows 5.1.2600 Service Pack 3

5/17/2009 2:53:43 PM
mbam-log-2009-05-17 (14-53-43).txt

Scan type: Quick Scan
Objects scanned: 159822
Time elapsed: 22 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bbd4551a-9b23-41cd-9bcd-818aa2da7b63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:13:40 PM, on 5/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL (file missing)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\WINDOWS\CouponBarIE.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FPCCSMiddleware] C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://theclonewars.cartoonnetwork.com/games/game_02_ext.html"
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1007\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Michele')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1009\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'Justin')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1009\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Justin')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1009\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Justin')
O4 - HKUS\S-1-5-21-2974765026-1988966726-3429167403-1009\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; FunWebProducts; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)" -"http://www.noggin.com/games/scribblevision/index.php?modid=9" (User 'Justin')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.gamehouse.com/realarcade-webgam...tgameloader.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) - http://real.gamehouse.com/games/adventureball/abx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} - http://coolsavings.coupons.smartsource.com...oad/cscmv5X.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.gamehouse.com/realarcade-webgam.../DinerDash2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1144036224453
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._2/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://real.gamehouse.com/games/chainz2/mjolauncher.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://real.gamehouse.com/games/tumblebugs/axhost.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://secure.acml.com/tsweb/msrdp.cab,Dan...tsweb.acml.com+
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVC Download Control) - http://real.gamehouse.com/games/thedavinci...loadControl.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.gamehouse.com/realarcade-webgam...zylomplayer.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://cablevision.oberon-media.com/Gamesh...ronGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock...ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/realarcade-webgam...outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_...inematycoon.cab
O16 - DPF: {E03EEB49-B0CB-46A3-A84B-BA758243A7B0} (Orbital Launcher) - http://www.gamehouse.com/realarcade-webgam...talLauncher.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://secure.acml.com/dana-cached/setup/J...perSetupSP1.cab
O16 - DPF: {E6BB2089-163F-466B-812A-748096614DFD} (CAScanner Control) - http://cainternetsecurity.net/scanner/cascanner.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

--
End of file - 18903 bytes
Go to the top of the page
 
+Quote Post
Rorschach112
post May 17 2009, 02:29 PM
Post #2


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



hi

Looking at your system now, one or more of the identified infections is a backdoor Trojan.

If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.




Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.




Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you don't know how to disable them then just continue on.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.





Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.



Go to the top of the page
 
+Quote Post
crdavis221
post May 18 2009, 02:12 AM
Post #3


New Member
*
Posts: 6
OS: XP SP3



Thank you for the quick response, I have already notified everyone and so far I have no fraudulent use.

I have aslo ran SDFix and ComboFix as instructed. I have posted the logs below.

One thing though is that I am still getting redirects, even when trying to link to this website. Please advise on how to rid my system of this and how my logs look.

Again thanks for your quick response ohmy.gif)

SDFix


SDFix: Version 1.240
Run by Craig on Mon 05/18/2009 at 03:20 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Documents and Settings\LocalService\Application Data\twain_32\user.ds - Deleted
C:\Documents and Settings\NetworkService\Application Data\twain_32\user.ds - Deleted
C:\DOCUME~1\Craig\LOCALS~1\Temp\tmp17.tmp - Deleted
C:\DOCUME~1\Craig\LOCALS~1\Temp\tmp1E.tmp - Deleted
C:\WINDOWS\SYSTEM32\TDSSMUPE.dat - Deleted



Folder C:\Documents and Settings\LocalService\Application Data\twain_32 - Removed
Folder C:\Documents and Settings\NetworkService\Application Data\twain_32 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 03:35:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Disabled:AOL"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Activision\\SHReK the THiRD Demo\\SHReK the THiRD.exe"="C:\\Program Files\\Activision\\SHReK the THiRD Demo\\SHReK the THiRD.exe:*:Enabled:SHReK the THiRD™ Demo"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 23 Jun 2007 31 A..H. --- "C:\WINDOWS\uccspecc.sys"
Thu 12 Feb 2009 848 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 9 Mar 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 11 Dec 2007 24,576 ...H. --- "C:\Documents and Settings\Michele\My Documents\~WRL1731.tmp"
Tue 11 Dec 2007 24,576 ...H. --- "C:\Documents and Settings\Michele\My Documents\~WRL2642.tmp"
Tue 11 Dec 2007 24,576 ...H. --- "C:\Documents and Settings\Michele\My Documents\~WRL2792.tmp"
Tue 11 Dec 2007 24,576 ...H. --- "C:\Documents and Settings\Michele\My Documents\~WRL3966.tmp"
Tue 11 Dec 2007 24,576 ...H. --- "C:\Documents and Settings\Michele\My Documents\~WRL3971.tmp"
Fri 17 Aug 2007 56 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_3691804567_2686976_65382.tmp"
Thu 4 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Tue 23 Oct 2007 3,350,528 A..H. --- "C:\Documents and Settings\Craig\Application Data\U3\temp\Launchpad Removal.exe"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\Michele\Application Data\U3\temp\Launchpad Removal.exe"
Thu 21 Oct 1999 806,400 A..H. --- "C:\Documents and Settings\All Users\Documents\eGames\Mini Golf Master\Game\WCDEMO.EXE"
Mon 18 May 2009 5,946 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE4.tmp"
Fri 8 Jun 2007 24,646 ..SHR --- "C:\Documents and Settings\Craig\Local Settings\Temp\Juniper Networks\setup\NeoterisSetupApp.exe"
Wed 15 Feb 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Sun 8 Apr 2007 8 A..H. --- "C:\Documents and Settings\Craig\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 8 Apr 2007 8 A..H. --- "C:\Documents and Settings\Craig\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 8 Apr 2007 8 A..H. --- "C:\Documents and Settings\Craig\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 15 Apr 2007 8 A..H. --- "C:\Documents and Settings\Craig\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Justin\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Justin\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 15 Apr 2007 8 A..H. --- "C:\Documents and Settings\Justin\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 15 Apr 2007 8 A..H. --- "C:\Documents and Settings\Justin\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Mon 9 Apr 2007 8 A..H. --- "C:\Documents and Settings\Nicholas\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 9 Apr 2007 8 A..H. --- "C:\Documents and Settings\Nicholas\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 9 Apr 2007 8 A..H. --- "C:\Documents and Settings\Nicholas\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 9 Apr 2007 8 A..H. --- "C:\Documents and Settings\Nicholas\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!


ComboFix

ComboFix 09-05-17.04 - Craig 05/18/2009 3:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1345 [GMT -4:00]
Running from: c:\documents and settings\Craig\Desktop\ComboFix.exe
AV: Trend Micro PC-cillin Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Craig\Application Data\Google\T-Scan
c:\documents and settings\Craig\Application Data\Google\T-Scan\n.gif
c:\documents and settings\Craig\Application Data\Google\T-Scan\t.gif
c:\documents and settings\Craig\Application Data\Google\T-Scan\y.gif
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc12.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc13.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc14.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc17.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc19.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc2.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc20.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc21.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc22.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc23.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc24.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc25.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc26.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc27.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc28.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc29.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc3.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc30.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc31.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc32.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc34.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc35.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc36.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc37.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc38.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc39.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc4.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc40.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc41.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc42.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc44.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc45.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc47.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc48.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc49.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc5.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc50.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc52.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc53.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc54.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc55.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc56.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc57.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc59.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc6.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc60.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc61.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc62.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc63.asd
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc64.doc
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc66.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc67.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc68.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc69.dll
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc7.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc70.url
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc71.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc8.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\Dc9.JPG
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1007\INFO2
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1008\Dc1.lnk
c:\recycler\S-1-5-21-2974765026-1988966726-3429167403-1008\INFO2
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\dirty_dishes.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\foodtray.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\heart1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\heart2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\heart3.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\menu_down.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\menu_up.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\mop_prop.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\accessories\ticket.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\music\cafe\cafe_music_a1.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\music\cafe\cafe_music_a2.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\music\cafe\cafe_music_a3.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\music\cafe\cafe_music_a4.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\music\mainmenumusic.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\baby_cry.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\chef_cook1.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\closing_time.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\customer_ditch.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\dialog_down.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\dialog_up.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\drink_table.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\expert.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\highchair_deliver.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\highchair_pickup.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\keystroke2.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\level_lose.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\level_win.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\menu_click.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\menu_rollover.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\mop_pickup.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\mop_spill.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_bring_check_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_deliver_food_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_dish_dropoff_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_dropoff_drinks_1.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_food_ready_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_gain_heart_1.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_get_drinks_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_menu_down.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_party_arrive_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_pencil_write_2.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_pickup_food_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\sfx_seat_people_snd.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\spill.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\table_drink.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\audio\sfx\tip_2.ogg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\flo_lose.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\flo_win.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\fullscreendialog.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\high_score_menu_bg.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\levelintro.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\levelintro.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\levelover.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\longdialog.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\longdialog.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\mainmenu.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\mainmenu_logo.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\popup.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\popup.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\textfield.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\backgrounds\upgrade_lines.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowdown_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowdown_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowdown_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowup_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowup_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\arrowup_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\checkbox_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\checkbox_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\checkbox_rotated_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\checkbox_rotated_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\decor_highlight.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\decor_normal.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\decor_selected.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_large_1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_large_2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_large_3.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_small_1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_small_2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a_small_3.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\dialog_button_a3.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\left_arrow_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\left_arrow_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\left_arrow_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button1_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button1_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button1_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button1_mask.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button2_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button2_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button2_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\main_menu_button2_mask.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\map_button_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\map_button_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\map_button_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\right_arrow_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\right_arrow_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\right_arrow_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\upgrade_down.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\upgrade_over.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\upgrade_up.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\buttons\welcome_player.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\actionpoints.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\career.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\customer.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\endless.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\global.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\config\powerups.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cook\stove.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cursor\arrow.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cursor\click.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cursor\click2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cursor\grab.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\cursor\open.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\anim.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\anim.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\blue.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\blue_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\legs.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\red.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\dad_male\red_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\anim.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\anim.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\blue.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\blue_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\legs.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\red.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\kid_male\red_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\anim.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\anim.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\baby.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\baby.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\blue.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\blue_baby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\blue_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\legs.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\red.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\red_baby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\mom_female\red_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\anim.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\anim.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\blue.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\blue_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\legs.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\red.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\customers\young_female\red_legs.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\idle.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\idle.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\lower.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\lower.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\upper.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\flo\upper.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\fonts\mercurius.mvec
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\bench.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\bench.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\blue_highchairbaby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\chair.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\chair.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\dirt2top.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\dirt4top.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\dishcart.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\dishcart.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\green_highchairbaby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\highchair_prop_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\highchair_prop_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\highchairbaby.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\highchairbaby.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\luxury_bench.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\luxury_bench.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\mop_station_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\mop_station_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\mop_station_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\podium.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\podium_heart.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\podium_heart.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\purple_highchairbaby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\radio.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\red_highchairbaby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\spill.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\spill.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\stereo.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\ticketstation.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\ticketstation.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\furniture\yellow_highchairbaby.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\family.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help_dividerline.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help1_colormatch1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help1_colormatch2.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help1_noise.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help1_score.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help2_cleardishes.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help2_givecheck.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help2_pickupfood.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help2_servefood.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\help\help2_takeorder.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\hiscore\local-hs-bb.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\hiscore\p1icon.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_1.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_2.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_3.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_4.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_5.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\career_1_6.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\endless_1_1.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\endless_1_1_a.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\endless_1_1_b.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\layouts\endless_1_1_c.bin
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\playfirstlogo.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\background.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\chairs\blue.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\chairs\green.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\chairs\green.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\chairs\grey.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\chairs\red.pal
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\food\cup1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\food\food.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\food\food.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\frames\2_0.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\frames\2_1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\furniture\drinkstation1_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\furniture\drinkstation1_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\furniture\drinkstation1_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\people\cook.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\people\cook.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\props\cup_prop1.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\tables\2top.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\tables\2top.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\tables\4top.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\tables\4top.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\upgrade_icons\cafe_icon_2_0.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\upgrade_icons\cafe_icon_2_1.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\cafe\upgrades.xml
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\restaurants\tableshadow.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\careerupgrade.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\choosedifficulty.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\closeconfirm.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\entername.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\game.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\getmoregames.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\help1.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\help2.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\hiscore.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\hiscoreinfo.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\hiscoresubmit.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\levelintro.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\levelover.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\loading.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\mainloop.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\mainmenu.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\ok.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\pause.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\style.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\upgrade.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\upsell.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\scripts\yesno.lua
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\splash\aol_logo.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\splash\playfirst_logo.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\strings.xml
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\angersmoke.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\angersmoke.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\bubbles\request_bubble.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\bubbles\request_mop.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\bubbles\request_rejectmeal.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\chairflags.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\chairflags.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\check.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\checkmark.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\closed.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\coinflip.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\coinflip.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\decor_lines.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\dollar.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\expert.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\foodpoof.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\foodpoof.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\heartgrow.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\heartgrow.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\jar.anm
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\jar.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\lives_icon.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\noisering.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_d.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_e.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\notes\music_boost_f.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\tablenumber_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\tablenumber_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\traynumber.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\tutorialarrow.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\tutorialbox.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\ui_base.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\ui_hand.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\ui_timer_off.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\ui_timer_on.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgradeanim.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_bench_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_bench_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_bench_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_drink_station1_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_drink_station1_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_drink_station1_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_luxury_bench_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_luxury_bench_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_luxury_bench_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_oven_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_oven_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_oven_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_podium_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_podium_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_podium_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_powerbars_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_powerbars_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_powerbars_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_radio_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_radio_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_radio_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_stereo_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_stereo_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_stereo_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_table_a.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_table_b.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\ui\upgrades\icon_table_c.png
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\upsell\dd1.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\upsell\dd2.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\upsell\dd3.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\assets\upsell\dd4.jpg
c:\windows\Downloaded Program Files\DinerDash2.1.0.0.53\dinerdash2.exe
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_boton_big.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_boton_big.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_boton_small.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_boton_small.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_explosion1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_explosion1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_highlight.alpha.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_highlight.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_hrzarrows.alpha.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_hrzarrows.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_magiclights.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_magiclights.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cat.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cat.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbb.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbb.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbg.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbk.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbr.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbv.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cbw.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_cby.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_chain.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_fireball.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_fireball.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_misc.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_misc.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_misc2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_misc2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_reverse.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_slow.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_speedshot.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_stop.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_pw_wild.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_questionmark.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_questionmark.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_rays.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_rays.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_smallballs.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\_smallballs.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\aol_logo.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_disabled.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_disabled.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_highlight.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_normal.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_pushed.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_down_pushed.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_left_highlight.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_left_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_left_normal.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_left_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_right_highlight.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_right_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_right_normal.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_right_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_disabled.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_disabled.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_highlight.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_normal.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_pushed.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\arrow_up_pushed.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_3.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_4.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_5.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_6.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_7.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_fireball.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_fireball.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_highlight.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_pusher.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_ray.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_ray.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_shadow.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_supercannonbal15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_wild.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ball_wild.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\barril_top.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\barril_top.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\barril_top_l.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\barril_top_l.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bigflare.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bigflare.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\blast.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\blast.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\blast.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bomb.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_big_disabled.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_big_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_big_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_big_pushed.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_small_disabled.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_small_highlight.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_small_normal.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\boton_small_pushed.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bright.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bright.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\bright.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\brillito01.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\brillito01.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cannonball.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cannonball.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0020.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0020.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0021.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0021.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0022.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0022.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0023.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0023.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0024.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0024.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0025.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0025.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0026.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0026.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0027.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0027.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0028.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0028.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0029.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0029.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0030.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0030.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0031.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cat0031.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\categories.ui
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_black31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_blue31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_green31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_red31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_violet31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_white31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cbomb_yellow31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0020.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0020.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0021.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0021.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0022.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0022.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0023.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0023.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0024.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0024.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0025.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0025.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0026.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0026.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0027.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0027.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0028.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0028.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0029.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0029.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0030.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0030.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0031.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\chain_break0031.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\checkbox_base.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\checkbox_base.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\checkbox_fill.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\checkbox_fill.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\commonfont.mvec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cursor_default.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cursor_default.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cursor_ingame.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\cursor_ingame.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\editbox_back.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\editbox_frame.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\expl_1_15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\explosion1.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\fireball31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\firetrail_smoke.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\firetrail2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\flare.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_back.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_back.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_bottom.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_left.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_ll.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_lr.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_right.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_top.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_ul.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\frame_int_ur.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\goldcoin.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\goldcoin.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_1.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_1.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_2.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_2.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_3.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_3.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_4.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_4.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_5.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_5.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_6.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_6.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_7.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_7.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_8.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_8.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_9.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highlight_9.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highscore_back.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highscore_entry.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highscore_entry.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highscore_entry_highlight.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\highscore_entry_highlight.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\hotfire.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\hotfire2.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\howtoplay_back.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\howtoplay_pathback.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\howtoplay_pathback.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\htp_ballfade.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\htp_ballfade.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\loadingscreen.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\login.ui
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclight.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclight.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclights1.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclights2.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclights3.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclights4.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\magiclights5.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\mainmenu.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_a.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_b.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_c.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_d.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_doble1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_doble2.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_doble3.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_doble4.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_doble5.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e_ovl1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e_ovl1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e_ovl2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_e_ovl2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_g.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_h.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_h.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_h_ovl1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_h_ovl1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_i.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_i.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_j.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl3.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_k_ovl3.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_l.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_m.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_m.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_n.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_n.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_o.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_o.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_p.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_p.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_q.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea2.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea2_ovl1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea2_ovl1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_sea3.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_skull1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_totem1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_volcan1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_volcan2.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1_ovl1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1_ovl1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1_ovl2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind1_ovl2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\map_whirlwind2.map
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\messages.xml
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\moreinfo.ui
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\mouse.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\mouse_left.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\mouse_move.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\mouse_right.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\p1icon.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pearls.theme
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\powerup.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\powerup_new.template
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pp_button_click.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\preload-anims.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\preload-emitter.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\preload-images.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\preload-music.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\preload-sounds.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\prescaled.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\progress_done.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\progress_full.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\progressbar_ball.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\progressbar_ball.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_back.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_chains.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_1.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_2.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_3.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_4.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_5.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_6.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_colorbomb_7.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_fireball.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_ray.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_sight.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_slow.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_stop.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\pu_wildball.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\puzzleballs.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\puzzleballs.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\question0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\questionmark.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rayos15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\resource-alias.txt
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0020.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0020.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0021.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0021.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0022.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0022.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0023.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0023.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0024.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0024.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0025.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0025.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0026.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0026.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0027.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0027.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0028.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0028.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0029.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0029.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0030.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0030.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0031.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\reverse0031.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ribbon.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\ribbon.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rieles.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\rieles.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\schwrzw.mvec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen3.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen4.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen5.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen6.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\screen7.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\separator.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_break_pusher.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_explosion.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_goalreached.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_insert.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_launch_ball.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_launch_bomb.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_launcher_reload.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_lose.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_match_1.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_match_2.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_merge.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_powerup.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_roll.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_spawn_chain.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_spawn_powerup.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_startlevel.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_swap_ball.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sfx_win_level.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\shooter.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\shooter.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\shooter_top.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\shooter_top.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sight.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\sight.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\silvercoin.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\silvercoin.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_empty.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_empty.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_fill.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_fill.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_thumb.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slider_thumb.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\slow31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_black.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_blue.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_cannon.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_empty.png
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_fireball.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_green.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_red.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_violet.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_white2.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_wildcard.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallball_yellow.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smallflare.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_3.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_3.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_1.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_1.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_2.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_2.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_3.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoke_w_3.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoketrail.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\smoketrail2.emitter
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0020.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0020.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0021.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0021.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0022.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0022.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0023.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0023.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0024.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0024.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0025.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0025.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0026.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0026.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0027.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0027.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0028.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0028.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0029.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0029.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0030.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0030.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0031.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\speed0031.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\splash_marino.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\splash_mystery.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\splash_playfirst.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\st_game_short.ogg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\statusbar_arcade.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\statusbar_arcade.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\statusbar_puzzle.alpha.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\statusbar_puzzle.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop00.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop00.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop01.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop01.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop02.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop02.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop03.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop03.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop04.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop04.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop05.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop05.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop06.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop06.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop07.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop07.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop08.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop08.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop09.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop09.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop10.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop10.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop11.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop11.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop12.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop12.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop13.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop13.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop14.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop14.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop15.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop15.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop16.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop16.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop17.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop17.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop18.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop18.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop19.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop19.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop20.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop20.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop21.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop21.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop22.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop22.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop23.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop23.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop24.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop24.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop25.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop25.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop26.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop26.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop27.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop27.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop28.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop28.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop29.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop29.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop30.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop30.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop31.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\stop31.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\submit.ui
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\upsell.jpg
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\webmessages.xml
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\whitesmoke.anim
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0000.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0000.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0001.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0001.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0002.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0002.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0003.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0003.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0004.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0004.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0005.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0005.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0006.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0006.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0007.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0007.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0008.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0008.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0009.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0009.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0010.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0010.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0011.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0011.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0012.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0012.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0013.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0013.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0014.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0014.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0015.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0015.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0016.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0016.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0017.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0017.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0018.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0018.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0019.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0019.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0020.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0020.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0021.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0021.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0022.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0022.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0023.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0023.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0024.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0024.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0025.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0025.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0026.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0026.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0027.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0027.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0028.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0028.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0029.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0029.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0030.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0030.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0031.spec
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\assets\wildcard0031.subimage
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\hiscore.dat
c:\windows\Downloaded Program Files\PiratePoppers.1.0.0.24\piratepoppers.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\bszip.dll
c:\windows\system32\mfc70.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 )))))))))))))))))))))))))))))))
.

2009-05-18 07:18 . 2009-05-18 07:18 552 ----a-w c:\windows\system32\d3d8caps.dat
2009-05-18 07:18 . 2009-05-18 07:18 578560 ----a-w c:\windows\system32\dllcache\user32.dll
2009-05-18 07:13 . 2009-05-18 07:13 -------- d-----w c:\windows\ERUNT
2009-05-18 05:49 . 2009-05-18 07:38 -------- d-----w C:\SDFix
2009-05-15 06:15 . 2009-05-15 06:15 -------- d-----w c:\documents and settings\Craig\SecurityScans
2009-05-15 06:14 . 2009-05-15 06:14 -------- d-----w c:\program files\Microsoft Baseline Security Analyzer 2
2009-05-14 17:56 . 2009-05-14 17:56 -------- d-----w c:\documents and settings\Craig\Application Data\Malwarebytes
2009-05-14 17:56 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-14 17:56 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-14 17:56 . 2009-05-14 17:56 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-14 17:56 . 2009-05-14 17:56 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-13 04:53 . 2009-05-13 04:53 -------- d-----w c:\documents and settings\Craig\Application Data\Uniblue
2009-05-13 04:53 . 2009-05-13 04:53 -------- d-----w c:\program files\Uniblue
2009-05-13 04:53 . 2009-05-13 04:53 -------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-05-13 04:51 . 2008-04-14 00:12 82432 ----a-w c:\windows\system32\dllcache\ws2_32.dll
2009-05-11 17:11 . 2009-05-11 17:11 -------- d-----w c:\documents and settings\All Users\Application Data\CA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 20:11 . 2006-01-04 02:24 -------- d-----w c:\program files\Trend Micro
2009-05-14 13:52 . 2006-11-30 00:00 -------- d-----w c:\program files\Dell Games
2009-05-14 13:46 . 2006-01-04 02:21 -------- d-----w c:\program files\WildTangent
2009-05-12 13:16 . 2007-06-14 16:08 32752 ----a-w c:\documents and settings\Nicholas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 22:21 . 2007-05-14 13:52 32752 ----a-w c:\documents and settings\Justin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-31 22:57 . 2007-05-17 23:55 32752 ----a-w c:\documents and settings\Cristian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-29 00:03 . 2006-07-20 17:43 32752 ----a-w c:\documents and settings\Michele\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-28 14:30 . 2006-02-10 19:43 32752 ----a-w c:\documents and settings\Craig\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-28 05:37 . 2009-03-28 05:37 -------- d-----w c:\program files\MSBuild
2009-03-28 05:37 . 2009-03-28 05:37 -------- d-----w c:\program files\Reference Assemblies
2009-03-20 17:55 . 2006-01-04 02:06 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 17:53 . 2009-03-20 17:53 -------- d-----w c:\program files\Activision
2009-03-06 14:22 . 2005-08-16 10:18 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-08-16 10:18 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2005-08-16 10:18 78336 ----a-w c:\windows\system32\ieencode.dll
2006-10-19 02:45 . 2006-10-21 02:43 774144 ----a-w c:\program files\RngInterstitial.dll
2009-02-12 21:19 . 2006-05-12 01:00 848 --sha-w c:\windows\system32\KGyGaAvL.sys
.

------- Sigcheck -------

[-] 2004-08-10 11:00 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\$NtServicePackUninstall$\ws2_32.dll
[-] 2008-04-14 00:12 82432 7D6C9783AB4344624B6922EDE675D518 c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 00:12 82432 7D6C9783AB4344624B6922EDE675D518 c:\windows\system32\ws2_32.dll
[-] 2008-04-14 00:12 82432 7D6C9783AB4344624B6922EDE675D518 c:\windows\system32\dllcache\ws2_32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-26 2019624]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-01-04 168448]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-12-13 58992]
"Norton Ghost 10.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2005-08-17 1531904]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-09 110592]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-11-17 106496]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-07 188416]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-01-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-19 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-19 217088]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-06 136600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"FPCCSMiddleware"="c:\program files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe" [2008-03-07 536184]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"MBMon"="CTMBHA.DLL" - c:\windows\system32\CTMBHA.DLL [2005-05-19 1345520]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-1-3 24576]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Activision\\SHReK the THiRD Demo\\SHReK the THiRD.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R1 NEOFLTR_540_11871;Juniper Networks TDI Filter Driver (NEOFLTR_540_11871);c:\windows\system32\drivers\NEOFLTR_540_11871.sys [6/8/2007 10:27 PM 57591]
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\tmxpflt.sys [8/30/2005 6:30 PM 205328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [8/30/2005 6:30 PM 290889]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [8/30/2005 6:30 PM 585792]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/30/2005 6:30 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [8/30/2005 6:30 PM 262215]
.
Contents of the 'Scheduled Tasks' folder

2009-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.optonline.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: RaptisoftGameLoader - hxxp://www.gamehouse.com/realarcade-webgames/hamsterball/raptisoftgameloader.cab
DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} - hxxp://www.ritzpix.com/net/Uploader/LPUploader45.cab
DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} - hxxp://real.gamehouse.com/games/adventureball/abx.cab
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://real.gamehouse.com/games/tumblebugs/axhost.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/realarcade-webgames/mahjongfortuna2/zylomplayer.cab
DPF: {E03EEB49-B0CB-46A3-A84B-BA758243A7B0} - hxxp://www.gamehouse.com/realarcade-webgames/thwartpoker/OrbitalLauncher.cab
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 03:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-18 3:53
ComboFix-quarantined-files.txt 2009-05-18 07:53

Pre-Run: 57,037,639,680 bytes free
Post-Run: 58,134,953,984 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

2016 --- E O F --- 2009-04-29 07:00
Go to the top of the page
 
+Quote Post
Rorschach112
post May 18 2009, 04:56 AM
Post #4


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



hi

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    CODE
    :Processes
    explorer.exe

    :Services

    :Reg

    :Files
    C:\WINDOWS\uccspecc.sys
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download ATF Cleaner by Atribune.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Go to the top of the page
 
+Quote Post
crdavis221
post May 19 2009, 10:56 PM
Post #5


New Member
*
Posts: 6
OS: XP SP3



Ok, so I have followed your instructions and posted the logs below. One other thing that did occur after running OTMoveIt3 and rebooting was that I got an error for Microsoft .NET Framework. I copied the details and included that here as well. Let me know what needs to be done next and thank you for the help you provided so far.

OTMoveIT3 log

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\uccspecc.sys moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\JET28A5.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\Perflib_Perfdata_9c.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\~DFB857.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\UQV619RW\malware-my-pc-Vundo-backdoor-bot-trojan-tdss-malware-trace-etc-t239324[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\QJXLVQ7B\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_110.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4a8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05192009_212812

Files moved on Reboot...
File C:\DOCUME~1\Craig\LOCALS~1\Temp\JET28A5.tmp not found!
File C:\DOCUME~1\Craig\LOCALS~1\Temp\Perflib_Perfdata_9c.dat not found!
File C:\DOCUME~1\Craig\LOCALS~1\Temp\~DFB857.tmp not found!
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\UQV619RW\malware-my-pc-Vundo-backdoor-bot-trojan-tdss-malware-trace-etc-t239324[1].htm moved successfully.
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\QJXLVQ7B\iframe[1].htm moved successfully.
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_110.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_4a8.dat not found!

Malwarebytes log

Malwarebytes' Anti-Malware 1.36
Database version: 2156
Windows 5.1.2600 Service Pack 3

5/19/2009 9:51:50 PM
mbam-log-2009-05-19 (21-51-50).txt

Scan type: Quick Scan
Objects scanned: 114567
Time elapsed: 4 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Kaspersky log

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, May 20, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, May 20, 2009 00:55:16
Records in database: 2200588
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan statistics:
Files scanned: 125313
Threat name: 6
Infected objects: 11
Suspicious objects: 0
Duration of the scan: 02:00:39


File name / Threat name / Threats count
C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\354.tmp Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.qd 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\356.tmp Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.qd 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\35C.tmp Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.qd 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\35E.tmp Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.qd 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36D.tmp Infected: Trojan-Dropper.MSPPoint.Agent.ay 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3B6.tmp Infected: Trojan-Dropper.MSPPoint.Agent.ay 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\400.tmp Infected: Backdoor.Win32.TDSS.blh 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\44A.tmp Infected: Backdoor.Win32.TDSS.atb 1
C:\WINDOWS\system32\wbem\proquota.exe Infected: Trojan.Win32.Agent.cgcn 1

The selected area was scanned.

Microsoft .NET Framework error

See the end of this message for details on invoking
just-in-time (JIT) debugging instead of this dialog box.

************** Exception Text **************
System.NullReferenceException: Object reference not set to an instance of an object.
at HP.CUE.Video.PlaybackControl.UpdateProgressBar()
at HP.CUE.Video.PlaybackControl._ProgressTimer_Tick(Object sender, EventArgs e)
at System.Windows.Forms.Timer.OnTick(EventArgs e)
at System.Windows.Forms.Timer.Callback(IntPtr hWnd, Int32 msg, IntPtr idEvent, IntPtr dwTime)


************** Loaded Assemblies **************
mscorlib
Assembly Version: 1.0.5000.0
Win32 Version: 1.1.4322.2407
CodeBase: file:///c:/windows/microsoft.net/framework/v1.1.4322/mscorlib.dll
----------------------------------------
hpqimzone
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///C:/Program%20Files/Hewlett-Packard/Digital%20Imaging/bin/hpqimzone.exe
----------------------------------------
hpqiface
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqiface/4.0.0.0__a53cf5803f4c3827/hpqiface.dll
----------------------------------------
System.Windows.Forms
Assembly Version: 1.0.5000.0
Win32 Version: 1.1.4322.2032
CodeBase: file:///c:/windows/assembly/gac/system.windows.forms/1.0.5000.0__b77a5c561934e089/system.windows.forms.dll
----------------------------------------
System.Drawing
Assembly Version: 1.0.5000.0
Win32 Version: 1.1.4322.2032
CodeBase: file:///c:/windows/assembly/gac/system.drawing/1.0.5000.0__b03f5f7f11d50a3a/system.drawing.dll
----------------------------------------
System
Assembly Version: 1.0.5000.0
Win32 Version: 1.1.4322.2407
CodeBase: file:///c:/windows/assembly/gac/system/1.0.5000.0__b77a5c561934e089/system.dll
----------------------------------------
hpqcc2
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqcc2/3.0.0.0__a53cf5803f4c3827/hpqcc2.dll
----------------------------------------
hpqutils
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqutils/4.0.0.0__a53cf5803f4c3827/hpqutils.dll
----------------------------------------
hpqfmrsc
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqfmrsc/4.0.0.0__a53cf5803f4c3827/hpqfmrsc.dll
----------------------------------------
hpqtray
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqtray/4.0.0.0__a53cf5803f4c3827/hpqtray.dll
----------------------------------------
hpqovskn
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqovskn/3.0.0.0__a53cf5803f4c3827/hpqovskn.dll
----------------------------------------
hpqthumb
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqthumb/3.0.0.0__a53cf5803f4c3827/hpqthumb.dll
----------------------------------------
hpqimvlt
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqimvlt/3.0.0.0__a53cf5803f4c3827/hpqimvlt.dll
----------------------------------------
hpqimgrc
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqimgrc/4.0.0.0__a53cf5803f4c3827/hpqimgrc.dll
----------------------------------------
hpqntrop
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqntrop/4.0.0.0__a53cf5803f4c3827/hpqntrop.dll
----------------------------------------
Interop.hpqcxm08
Assembly Version: 3.0.0.0
Win32 Version: 70.0.170.000
CodeBase: file:///c:/windows/assembly/gac/interop.hpqcxm08/3.0.0.0__a53cf5803f4c3827/interop.hpqcxm08.dll
----------------------------------------
System.Xml
Assembly Version: 1.0.5000.0
Win32 Version: 1.1.4322.2032
CodeBase: file:///c:/windows/assembly/gac/system.xml/1.0.5000.0__b77a5c561934e089/system.xml.dll
----------------------------------------
LEAD
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead/13.0.0.113__9cf889f53ea9b907/lead.dll
----------------------------------------
LEAD.Wrapper
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead.wrapper/13.0.0.113__9cf889f53ea9b907/lead.wrapper.dll
----------------------------------------
LEAD.Windows.Forms
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead.windows.forms/13.0.0.113__9cf889f53ea9b907/lead.windows.forms.dll
----------------------------------------
LEAD.Drawing
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead.drawing/13.0.0.113__9cf889f53ea9b907/lead.drawing.dll
----------------------------------------
interop.hpqimgr
Assembly Version: 4.0.0.0
Win32 Version: 4.0.0.0
CodeBase: file:///c:/windows/assembly/gac/interop.hpqimgr/4.0.0.0__a53cf5803f4c3827/interop.hpqimgr.dll
----------------------------------------
hpqasset
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqasset/4.0.0.0__a53cf5803f4c3827/hpqasset.dll
----------------------------------------
hpqmirsc
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///C:/Program%20Files/Hewlett-Packard/Digital%20Imaging/bin/hpqmirsc.DLL
----------------------------------------
hpqedit
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqedit/3.0.0.0__a53cf5803f4c3827/hpqedit.dll
----------------------------------------
hpqvideo
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqvideo/3.0.0.0__a53cf5803f4c3827/hpqvideo.dll
----------------------------------------
LEAD.Windows.Forms.DrawingContainer
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead.windows.forms.drawingcontainer/13.0.0.113__9cf889f53ea9b907/lead.windows.forms.drawingcontainer.dll
----------------------------------------
hpqmdmr
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqmdmr/4.0.0.0__a53cf5803f4c3827/hpqmdmr.dll
----------------------------------------
LEAD.Drawing.Imaging.ImageProcessing
Assembly Version: 13.0.0.113
Win32 Version: 13.0.0.113
CodeBase: file:///c:/windows/assembly/gac/lead.drawing.imaging.imageprocessing/13.0.0.113__9cf889f53ea9b907/lead.drawing.imaging.imageprocessing.dll
----------------------------------------
hpqimlib
Assembly Version: 3.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqimlib/3.0.0.0__a53cf5803f4c3827/hpqimlib.dll
----------------------------------------
hpqglutl
Assembly Version: 4.0.0.0
Win32 Version: 065.000.117.000
CodeBase: file:///c:/windows/assembly/gac/hpqglutl/4.0.0.0__a53cf5803f4c3827/hpqglutl.dll
----------------------------------------
interop.hpqvideo
Assembly Version: 4.0.0.0
Win32 Version: 4.0.0.0
CodeBase: file:///c:/windows/assembly/gac/interop.hpqvideo/4.0.0.0__a53cf5803f4c3827/interop.hpqvideo.dll
----------------------------------------

************** JIT Debugging **************
To enable just in time (JIT) debugging, the config file for this
application or machine (machine.config) must have the
jitDebugging value set in the system.windows.forms section.
The application must also be compiled with debugging
enabled.

For example:

<configuration>
<system.windows.forms jitDebugging="true" />
</configuration>

When JIT debugging is enabled, any unhandled exception
will be sent to the JIT debugger registered on the machine
rather than being handled by this dialog.

Thanks again


Go to the top of the page
 
+Quote Post
Rorschach112
post May 20 2009, 03:51 AM
Post #6


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



hi

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    CODE
    :Processes
    explorer.exe

    :Services

    :Reg

    :Files
    C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz
    C:\WINDOWS\system32\wbem\proquota.exe

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



also post a new HJT Log
Go to the top of the page
 
+Quote Post
crdavis221
post May 20 2009, 08:56 PM
Post #7


New Member
*
Posts: 6
OS: XP SP3



Hi,

Ok, so I ran OTMoveIt3 again using the new script and have pasted the log file below. I have also posted a new HiJackThis log as requested. But as mentioned before, I still have the Mircrosoft .NET Hardware error window. I posted the log of that prior as well. It prevented me from rebooting normally and I had to hold the power button to shutdown. Let me know what I need to do next.

OTMoveIT3 log

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz moved successfully.
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz moved successfully.
C:\WINDOWS\system32\wbem\proquota.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001.dir.0000\~df394b.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001.dir.0000\~efe2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\Perflib_Perfdata_950.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Craig\LOCALS~1\Temp\~DFA061.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\28WD0CDL\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\28WD0CDL\malware-my-pc-Vundo-backdoor-bot-trojan-tdss-malware-trace-etc-t239324[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_728.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_b8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_e70.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05202009_223802

Files moved on Reboot...
File C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001.dir.0000\~df394b.tmp not found!
File C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001.dir.0000\~efe2.tmp not found!
File C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001 not found!
File C:\DOCUME~1\Craig\LOCALS~1\Temp\Perflib_Perfdata_950.dat not found!
C:\DOCUME~1\Craig\LOCALS~1\Temp\~DFA061.tmp moved successfully.
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\28WD0CDL\iframe[1].htm moved successfully.
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\Content.IE5\28WD0CDL\malware-my-pc-Vundo-backdoor-bot-trojan-tdss-malware-trace-etc-t239324[1].htm moved successfully.
C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_728.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_b8.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_e70.dat not found!

HiJackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:43 PM, on 5/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\DOCUME~1\Craig\LOCALS~1\Temp\clclean.0001
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FPCCSMiddleware] C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.gamehouse.com/realarcade-webgam...tgameloader.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) - http://real.gamehouse.com/games/adventureball/abx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.gamehouse.com/realarcade-webgam.../DinerDash2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1144036224453
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._2/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://real.gamehouse.com/games/chainz2/mjolauncher.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://real.gamehouse.com/games/tumblebugs/axhost.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://secure.acml.com/tsweb/msrdp.cab,Dan...=tsweb.acml.com+
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVC Download Control) - http://real.gamehouse.com/games/thedavinci...loadControl.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.gamehouse.com/realarcade-webgam...zylomplayer.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://cablevision.oberon-media.com/Gamesh...ronGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock...ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/realarcade-webgam...outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_...inematycoon.cab
O16 - DPF: {E03EEB49-B0CB-46A3-A84B-BA758243A7B0} (Orbital Launcher) - http://www.gamehouse.com/realarcade-webgam...talLauncher.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://secure.acml.com/dana-cached/setup/J...perSetupSP1.cab
O16 - DPF: {E6BB2089-163F-466B-812A-748096614DFD} (CAScanner Control) - http://cainternetsecurity.net/scanner/cascanner.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

--
End of file - 16450 bytes



Go to the top of the page
 
+Quote Post
Rorschach112
post May 21 2009, 04:43 AM
Post #8


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



let me know if this fixes that

Please download Dial-A-Fix.
Unzip the folder found in the archive to a place you can remember. For example: C:\DialAFix
Then follow the steps below.
  • Browse to the folder where you saved Dial-A-Fix.
  • Open Dial-a-fix.exe
  • Tick the following boxes:
    CODE
    Empty temp folders
    Fix Windows Installer
    ActiveX controls/codecs
    Control Panel applets
    Programming cores/runtimes
    Explorer/IE/OE/shell/WMP
  • In the bottom left press the GO Button.

Note that ticking a box might tick others too. Leave them ticked!
Go to the top of the page
 
+Quote Post
crdavis221
post May 21 2009, 05:20 AM
Post #9


New Member
*
Posts: 6
OS: XP SP3



hi, I've ran the program and posted the log below. I haven't rebooted yet so I will let you know if the .NET error persists. Have you had a chance to review my other logs? When I looked at my computer today my Trend Micro antivirus detected and denied access to the following;

"Virus Log","2009/05/21","DJ10G091"
"Time","Event","Source Type","Virus Name","File Name","First Action","Second Action"
"00:43","Real-time Scan","File","ADW_COUPONS","C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000109.dll","Deny Access",""
"01:58","Real-time Scan","File","ADW_COUPONS","C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000109.dll","Deny Access",""
"04:22","Real-time Scan","File","ADW_COUPONS","C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000109.dll","Deny Access",""
"05:14","Real-time Scan","File","ADW_COUPONS","C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000109.dll","Deny Access",""
"06:16","Real-time Scan","File","ADW_COUPONS","C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000109.dll","Deny Access",""


Dial a fix log

Notes about this log:
1) "->" denotes an external command being executed, and "-> (number)" indicates
the return code from the previous command
2) Not all external command return codes are accurate, or useful
3) Sometimes commands return 0 (no error) even when they fail or crash
4) If an error occurs while registering an object, please send an email to:
dial-a-fix@DjLizard.net and include a copy of this log

DAF version: v0.60.0.24

--- System info ---
OS: Microsoft Windows XP Service Pack 3
IE version: 7.0.5730.11
MPC: 76487-OEM
CPU: Intel® Pentium® 4 CPU 3.00GHz (~3020MHz)
CPU: CPU is 64-bit or has 64-bit extensions
CPU: 2 CPU cores present
BIOS: 10/13/2005
Memory (approx): 2046MB
Uptime: 8 hour(s)
Current directory: C:\DOCUME~1\Craig\LOCALS~1\Temp\Temporary Directory 1 for Dial-a-fix-v0.60.0.24.zip\Dial-a-fix-v0.60.0.24
---

5/21/2009 7:10:20 AM -- Dial-a-fix : [v0.60.0.24] -- started
7:10:20 AM | Policy scan started
7:10:20 AM | Policy scan ended - no restrictive policies were found
--- Emptying temp folders ---
7:11:29 AM | Deleting C:\Documents and Settings\Craig\Local Settings\Temp...
7:11:29 AM | C:\Documents and Settings\Craig\Local Settings\Temp could not be completely emptied, please reboot and try again
7:11:29 AM | Deleting C:\WINDOWS\temp...
7:11:29 AM | C:\WINDOWS\temp could not be completely emptied, please reboot and try again
7:11:29 AM | Deleting C:\DOCUME~1\Craig\LOCALS~1\Temp...
7:11:29 AM | C:\DOCUME~1\Craig\LOCALS~1\Temp could not be completely emptied, please reboot and try again
--- MSI ---
7:11:31 AM | Registered: C:\WINDOWS\system32\msi.dll
--- Registration: ActiveX controls/codecs ---
7:11:34 AM | Registered: C:\WINDOWS\system32\acelpdec.ax
7:11:34 AM | Registered: C:\WINDOWS\system32\actxprxy.dll
7:11:34 AM | Registered: C:\WINDOWS\system32\asctrls.ocx
7:11:35 AM | Registered: C:\WINDOWS\system32\daxctle.ocx
7:11:35 AM | Registered: C:\WINDOWS\system32\hhctrl.ocx
7:11:35 AM | Registered: C:\WINDOWS\system32\l3codecx.ax
7:11:35 AM | Registered: C:\WINDOWS\system32\licmgr10.dll
7:11:35 AM | Registered: C:\WINDOWS\system32\mpg4ds32.ax
7:11:37 AM | Registered: C:\WINDOWS\system32\msdxm.ocx
7:11:37 AM | Registered: C:\WINDOWS\system32\proctexe.ocx
7:11:37 AM | Registered: C:\WINDOWS\system32\tdc.ocx
7:11:37 AM | Registered: C:\WINDOWS\system32\wshom.ocx
--- Registration: Control Panel applets ---
7:11:39 AM | DllInstalled: C:\WINDOWS\system32\inetcpl.cpl
7:11:39 AM | DllInstalled: C:\WINDOWS\system32\nusrmgr.cpl
7:11:39 AM | Registered: C:\WINDOWS\system32\nusrmgr.cpl
--- Registration: Programming cores/runtimes ---
7:11:39 AM | Registered: C:\WINDOWS\system32\atl.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\corpol.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\jscript.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\dispex.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\scrrun.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\scrobj.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\vbscript.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\wshext.dll
--- Registration: Explorer/IE/OE/shell/WMP ---
7:11:39 AM | Registered: C:\WINDOWS\system32\activeds.dll
7:11:39 AM | Registered: C:\WINDOWS\system32\audiodev.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\browsewm.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\cabview.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\cdfview.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\clbcatex.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\clbcatq.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\comcat.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\cscui.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\credui.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\datime.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\devmgr.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\dfsshlex.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\dmdlgs.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\dmdskmgr.dll
7:11:40 AM | Registered: C:\WINDOWS\system32\dmloader.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\dmocx.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\dmview.ocx
7:11:41 AM | DllInstalled: C:\WINDOWS\system32\dsuiext.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\dsuiext.dll
7:11:41 AM | DllInstalled: C:\WINDOWS\system32\dsquery.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\dsquery.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\dskquoui.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\els.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\es.dll
7:11:41 AM | Registered: C:\WINDOWS\system32\fontext.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\hlink.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\hnetcfg.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\iedkcs32.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\iepeers.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\ils.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\inetcfg.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\inetcomm.dll
7:11:42 AM | Registered: C:\WINDOWS\system32\laprxy.dll
7:11:43 AM | Registered: C:\WINDOWS\system32\lmrt.dll
7:11:43 AM | Registered: C:\WINDOWS\system32\mlang.dll
7:11:43 AM | Registered: C:\WINDOWS\system32\mmcndmgr.dll
7:11:43 AM | Registered: C:\WINDOWS\system32\mmcshext.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\mscoree.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\mshtmled.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\msoeacct.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\msr2c.dll
7:11:44 AM | DllInstalled: C:\WINDOWS\system32\mydocs.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\mydocs.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\mstime.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\netcfgx.dll
7:11:44 AM | DllInstalled: C:\WINDOWS\system32\netplwiz.dll
7:11:44 AM | Registered: C:\WINDOWS\system32\netplwiz.dll
7:11:45 AM | Registered: C:\WINDOWS\system32\netman.dll
7:11:45 AM | Registered: C:\WINDOWS\system32\netshell.dll
7:11:45 AM | Registered: C:\WINDOWS\system32\ntmsevt.dll
7:11:45 AM | Registered: C:\WINDOWS\system32\ntmsmgr.dll
7:11:45 AM | DllInstalled: C:\WINDOWS\system32\ntmssvc.dll
7:11:45 AM | Registered: C:\WINDOWS\system32\ntmssvc.dll
7:11:46 AM | DllInstalled: C:\WINDOWS\system32\occache.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\occache.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\ole32.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\oleaut32.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\oleacc.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\olepro32.dll
7:11:46 AM | DllInstalled: C:\WINDOWS\system32\photowiz.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\photowiz.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\remotepg.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\rpcrt4.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\rshx32.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\sendmail.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\slayerxp.dll
7:11:46 AM | Registered: C:\WINDOWS\system32\shell32.dll
7:11:51 AM | DllInstalled: C:\WINDOWS\system32\shell32.dll
7:11:51 AM | Registered: C:\WINDOWS\system32\shmedia.dll
7:11:51 AM | DllInstalled: C:\WINDOWS\system32\shimgvw.dll
7:11:51 AM | Registered: C:\WINDOWS\system32\shimgvw.dll
7:11:51 AM | DllInstalled: C:\WINDOWS\system32\shsvcs.dll
7:11:52 AM | Registered: C:\WINDOWS\system32\shsvcs.dll
7:11:52 AM | Registered: C:\WINDOWS\system32\srclient.dll
7:11:52 AM | Unregistered: C:\WINDOWS\system32\stobject.dll
7:11:52 AM | Registered: C:\WINDOWS\system32\stobject.dll
7:11:52 AM | Registered: C:\WINDOWS\system32\twext.dll
7:11:53 AM | DllInstalled: C:\WINDOWS\system32\urlmon.dll
7:11:53 AM | Registered: C:\WINDOWS\system32\urlmon.dll
7:11:53 AM | Registered: C:\WINDOWS\system32\userenv.dll
7:11:53 AM | Registered: C:\WINDOWS\system32\winhttp.dll
7:11:53 AM | DllInstalled: C:\WINDOWS\system32\wininet.dll
7:11:53 AM | Registered: C:\WINDOWS\system32\zipfldr.dll

again, thanks for your assistance thus far.

Go to the top of the page
 
+Quote Post
Rorschach112
post May 21 2009, 05:28 AM
Post #10


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



Your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.




  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.





Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html



Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here

Thank you for your patience, and performing all of the procedures requested.


Go to the top of the page
 
+Quote Post
crdavis221
post May 22 2009, 03:00 PM
Post #11


New Member
*
Posts: 6
OS: XP SP3



Hi,

good to hear. I really appreciate all of your assistance and prompt responses. So far everything seems to be working correctly. I am in the process of looking into all of the info you sent in your last post and will use what i can.

Again, thanks for all of your help. thumbsup.gif
Go to the top of the page
 
+Quote Post
Rorschach112
post May 22 2009, 06:07 PM
Post #12


GeekU Teacher
Group Icon
Posts: 34,385
From: Dublin
OS: XP



Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. smile.gif

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No new   16 / 1,217 16th July 2007 - 08:03 AM
Jorger2391 started - last by don77
No new   16 / 1,435 6th January 2008 - 04:06 PM
FSkip started - last by kahdah
No new   15 / 997 14th March 2008 - 10:23 AM
stokie.dan started - last by kahdah
No New Posts 1 / 1,897 12th November 2008 - 02:40 PM
mraskin started - last by mraskin

RSS Time is now: 8th November 2009 - 12:55 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising