rundll32
Ok that worked fine, Control Panel add/remove functions restored. I did not see any listing for Big Fish Games, but there was another game that looks like it was associated with Big Fish, so I removed it. Next I still found this on my drive:
c:\Program Files\bfgtoolbar\bfgtoolbar.dll
So I renamed the folder and renamed the dll, let me know if I should just delete them.
Here's the new Kaspersy:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, November 30, 2007 12:47:57 PM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/11/2007
Kaspersky Anti-Virus database records: 469309
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 88365
Number of viruses found: 11
Number of infected objects: 28
Number of suspicious objects: 8
Duration of the scan process: 03:24:12
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip/winCBC.tmp.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/win6C9.tmp.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde9.zip/winC49.tmp.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.5/wbuninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tracy C\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Tracy C\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Tracy C\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Tracy C\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Tracy C\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dfd Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.did Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dsd Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdb Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdl Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kib Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kpf Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.ksb Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\History\History.IE5\MSHist012007113020071201\index.dat Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Temp\D.tmp Object is locked skipped
C:\Documents and Settings\Tracy C\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tracy C\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tracy C\ntuser.dat.LOG Object is locked skipped
C:\Program Files\ComPlus Applications\holesufup4444.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\Program Files\ComPlus Applications\holesufup555077.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\Program Files\ComPlus Applications\holesufup83122.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\WINDOWS\df87173.exe.vir Infected: Trojan-Clicker.Win32.VB.vx skipped
C:\qoobox\Quarantine\C\WINDOWS\hg173.exe.vir Infected: Trojan-Clicker.Win32.VB.vx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\hgggdda.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\jkkhghi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.app skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nnnkljg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.arf skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nnnnmmn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.arf skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\opnomjk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.app skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ssqqqno.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\urqoolj.dll.vir Infected: Trojan.Win32.Inject.kq skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP19\change.log Object is locked skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002356.exe Infected: Trojan-Clicker.Win32.VB.vx skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002357.exe Infected: Trojan-Clicker.Win32.VB.vx skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002359.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002360.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.app skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002361.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arf skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002362.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arf skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002363.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.app skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002364.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002365.dll Infected: Trojan.Win32.Inject.kq skipped
C:\System Volume Information\_restore{A0F9910A-8AC8-4420-AE91-F1DE8E78E34A}\RP6\A0002458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.atj skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus

ownloader.Win32.PopCap.b skipped
C:\WINDOWS\Downloaded Program Files\ZwinkyInitialSetup1.0.0.15-3.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.aw skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7B3761B3-5C34-4804-BF9B-570FC5DC9C60}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.