PDA

View Full Version : Unable to remove what was detected by my antivirus



IrishEyes
2009-11-12, 20:10
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:34 PM, on 11/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Button Manager\BM.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: HP Button Manager.lnk = ?
O4 - Global Startup: Magic-i.lnk = C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MgiSvr - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 6822 bytes

Blade81
2009-11-16, 15:15
Hi,

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.


LimeWire


I'd like you to read this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).


What did your antivirus program detect and in what item?

IrishEyes
2009-11-17, 03:43
The program has been removed as per your instructions.

The only thing that keeps showing up is:

C:\Documents and Settings\Amanda\Local Settings\Temp\ehEa0cAb.pdf.part=](JAVASCRIPT) Exploit.PDF-JS.Gen Disinfect Failed

My computer has been running slower than normal, but I tried to quarantine it as per the instructions but it comes up with no options available.

Blade81
2009-11-17, 09:19
Hi again,

Let's create a few more logs.

Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.


Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log in your reply.

IrishEyes
2009-11-17, 23:25
DDS log:

DDS (Ver_09-09-29.01) - NTFSx86
Run by Amanda at 15:33:24.79 on Tue 11/17/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.480 [GMT -6:00]

AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Button Manager\BM.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe -kbdx
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Amanda\Desktop\dds.com

============== Pseudo HJT Report ===============

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2008\IEToolbar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2008\IEShow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2008\bdagent.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\amanda\applic~1\mozilla\firefox\profiles\5943iofy.default\
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-1-25 86792]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-7-20 84992]

=============== Created Last 30 ================

2009-11-12 13:09 <DIR> --d----- c:\program files\Trend Micro
2009-11-07 13:47 <DIR> --d----- c:\docume~1\amanda\applic~1\LimeWire
2009-11-07 13:46 <DIR> --d----- c:\program files\LimeWire
2009-10-24 16:13 1 ----h--- c:\windows\mmsmark2.dat
2009-10-24 16:13 2 a------- c:\windows\0101120101465050.xxe
2009-10-24 16:13 1 ----h--- c:\windows\bk23567.dat
2009-10-24 16:13 2 a------- c:\windows\0101120101464955.xxe
2009-10-24 16:13 2 a------- c:\windows\010112010146116101.xxe
2009-10-24 16:12 2 a------- c:\windows\010112010146101105.rx

==================== Find3M ====================

2009-11-16 20:41 81,984 a------- c:\windows\system32\bdod.bin
2009-09-11 08:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-04 15:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-30 08:44 507,904 a----r-- c:\windows\system32\btwapi.dll
2009-08-29 02:08 916,480 a------- c:\windows\system32\wininet.dll
2009-08-26 02:00 247,326 a------- c:\windows\system32\strmdll.dll

============= FINISH: 15:34:22.27 ===============

Attach log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/16/2009 8:50:45 PM
System Uptime: 11/16/2009 7:39:18 PM (20 hours ago)

Motherboard: Dell Computer Corp. | | 0F4491
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 59.82 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: ATI Function Driver for High Definition Audio - ATI AA01
Device ID: HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1000\5&BDC24A&0&0001
Manufacturer: ATI
Name: ATI Function Driver for High Definition Audio - ATI AA01
PNP Device ID: HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1000\5&BDC24A&0&0001
Service: AtiHdmiService

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2702&SUBSYS_8D881028&REV_01\4&1C660DD6&0&10F0
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2702&SUBSYS_8D881028&REV_01\4&1C660DD6&0&10F0
Service:

==== System Restore Points ===================

RP176: 8/20/2009 9:37:03 AM - System Checkpoint
RP177: 8/20/2009 4:42:10 PM - Installed Java(TM) 6 Update 15
RP178: 8/21/2009 5:40:19 PM - System Checkpoint
RP179: 8/22/2009 6:51:35 PM - System Checkpoint
RP180: 8/22/2009 8:50:29 PM - Installed DirectX
RP181: 8/23/2009 8:56:32 PM - System Checkpoint
RP182: 8/24/2009 9:42:59 PM - System Checkpoint
RP183: 8/25/2009 10:42:58 PM - System Checkpoint
RP184: 8/26/2009 3:00:14 AM - Software Distribution Service 3.0
RP185: 8/27/2009 3:42:58 AM - System Checkpoint
RP186: 8/28/2009 4:42:58 AM - System Checkpoint
RP187: 8/29/2009 5:42:59 AM - System Checkpoint
RP188: 8/30/2009 6:43:01 AM - System Checkpoint
RP189: 8/31/2009 7:43:01 AM - System Checkpoint
RP190: 9/1/2009 5:37:26 PM - System Checkpoint
RP191: 9/2/2009 3:00:14 AM - Software Distribution Service 3.0
RP192: 9/3/2009 3:43:01 AM - System Checkpoint
RP193: 9/4/2009 4:43:01 AM - System Checkpoint
RP194: 9/6/2009 7:40:08 PM - System Checkpoint
RP195: 9/7/2009 7:56:47 PM - System Checkpoint
RP196: 9/8/2009 8:30:40 PM - System Checkpoint
RP197: 9/9/2009 9:18:37 PM - System Checkpoint
RP198: 9/10/2009 3:00:15 AM - Software Distribution Service 3.0
RP199: 9/11/2009 10:46:28 AM - System Checkpoint
RP200: 9/12/2009 10:49:35 AM - System Checkpoint
RP201: 9/13/2009 1:00:10 PM - System Checkpoint
RP202: 9/14/2009 1:03:33 PM - System Checkpoint
RP203: 9/15/2009 2:03:33 PM - System Checkpoint
RP204: 9/16/2009 3:03:33 PM - System Checkpoint
RP205: 9/18/2009 5:49:58 PM - System Checkpoint
RP206: 9/21/2009 3:44:11 PM - System Checkpoint
RP207: 9/22/2009 3:48:29 PM - System Checkpoint
RP208: 9/23/2009 6:51:38 PM - System Checkpoint
RP209: 9/24/2009 6:57:25 PM - System Checkpoint
RP210: 9/25/2009 7:49:41 PM - System Checkpoint
RP211: 9/26/2009 8:48:36 PM - System Checkpoint
RP212: 9/28/2009 3:44:13 PM - System Checkpoint
RP213: 9/29/2009 3:47:13 PM - System Checkpoint
RP214: 9/30/2009 4:15:41 PM - System Checkpoint
RP215: 10/1/2009 4:50:26 PM - System Checkpoint
RP216: 10/2/2009 5:47:12 PM - System Checkpoint
RP217: 10/3/2009 6:47:14 PM - System Checkpoint
RP218: 10/3/2009 10:05:11 PM - Installed Windows Media Player 11
RP219: 10/3/2009 10:05:54 PM - Software Distribution Service 3.0
RP220: 10/4/2009 3:00:16 AM - Software Distribution Service 3.0
RP221: 10/5/2009 3:00:16 AM - Software Distribution Service 3.0
RP222: 10/6/2009 3:09:55 AM - System Checkpoint
RP223: 10/7/2009 3:57:53 AM - System Checkpoint
RP224: 10/8/2009 4:57:54 AM - System Checkpoint
RP225: 10/9/2009 4:59:00 AM - System Checkpoint
RP226: 10/10/2009 5:56:53 AM - System Checkpoint
RP227: 10/11/2009 5:57:11 AM - System Checkpoint
RP228: 10/12/2009 6:57:10 AM - System Checkpoint
RP229: 10/13/2009 5:42:13 PM - System Checkpoint
RP230: 10/14/2009 3:00:17 AM - Software Distribution Service 3.0
RP231: 10/15/2009 3:36:42 AM - System Checkpoint
RP232: 10/16/2009 4:36:42 AM - System Checkpoint
RP233: 10/17/2009 5:36:42 AM - System Checkpoint
RP234: 10/18/2009 10:08:49 AM - System Checkpoint
RP235: 10/19/2009 10:36:42 AM - System Checkpoint
RP236: 10/20/2009 11:36:43 AM - System Checkpoint
RP237: 10/21/2009 12:36:47 PM - System Checkpoint
RP238: 10/22/2009 1:36:48 PM - System Checkpoint
RP239: 10/23/2009 2:36:48 PM - System Checkpoint
RP240: 10/24/2009 3:36:49 PM - System Checkpoint
RP241: 10/25/2009 4:37:55 PM - System Checkpoint
RP242: 10/25/2009 6:59:01 PM - Removed Acrobat.com
RP243: 10/25/2009 6:59:50 PM - Removed Adobe Reader 9.1.3.
RP244: 10/25/2009 7:01:51 PM - Removed Google Earth.
RP245: 10/25/2009 7:05:13 PM - Removed Ventrilo Client
RP246: 10/26/2009 9:09:34 PM - System Checkpoint
RP247: 10/27/2009 9:10:47 PM - System Checkpoint
RP248: 10/28/2009 10:06:23 PM - System Checkpoint
RP249: 10/29/2009 11:06:21 PM - System Checkpoint
RP250: 10/31/2009 2:34:19 PM - System Checkpoint
RP251: 11/1/2009 3:11:45 PM - System Checkpoint
RP252: 11/2/2009 7:06:01 PM - System Checkpoint
RP253: 11/3/2009 7:12:54 PM - System Checkpoint
RP254: 11/4/2009 4:00:18 AM - Software Distribution Service 3.0
RP255: 11/5/2009 4:33:04 AM - System Checkpoint
RP256: 11/6/2009 6:55:09 AM - System Checkpoint
RP257: 11/7/2009 7:29:40 AM - System Checkpoint
RP258: 11/8/2009 6:45:27 AM - System Checkpoint
RP259: 11/9/2009 9:23:29 AM - System Checkpoint
RP260: 11/10/2009 10:21:56 AM - System Checkpoint
RP261: 11/11/2009 12:39:33 PM - System Checkpoint
RP262: 11/12/2009 3:00:19 AM - Software Distribution Service 3.0
RP263: 11/12/2009 12:51:11 PM - Installed BlackBerry Device Software Updater.
RP264: 11/13/2009 1:27:55 PM - System Checkpoint
RP265: 11/14/2009 1:40:26 PM - System Checkpoint
RP266: 11/15/2009 2:01:22 PM - System Checkpoint
RP267: 11/16/2009 3:01:26 PM - System Checkpoint

==== Installed Programs ======================

Adobe Flash Player 10 Plugin
ArcSoft Magic-i 3
ArcSoft VideoImpression 2
ArcSoft WebCam Companion 2
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Parental Control & Encoder
BitDefender GameSafe
BlackBerry Desktop Software 4.5
BlackBerry Device Software Updater
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Dell ResourceCD
Driver Robot
ERUNT 1.1j
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Button Manager
HP Webcam User's Guide
Intel(R) Network Connections 13.1.33.0
Java(TM) 6 Update 15
K-Lite Codec Pack 4.7.5 (Full)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.0.15)
MSXML 4.0 SP2 (KB954430)
QuickTime
Roxio Media Manager
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Skins
SoundMAX
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Yahoo! Messenger

==== Event Viewer Messages From Past Week ========

11/12/2009 3:20:28 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect.

==== End Of File ===========================

GMER log:

GMER 1.0.15.15227 - http://www.gmer.net
Rootkit scan 2009-11-17 16:25:04
Windows 5.1.2600 Service Pack 3
Running: jozdz8vs.exe; Driver: C:\DOCUME~1\Amanda\LOCALS~1\Temp\ufloipow.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender S.R.L.) ZwOpenProcess [0xABCC1B4C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender S.R.L.) ZwOpenThread [0xABCC1C3A]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender S.R.L.) ZwTerminateProcess [0xABCC1AB0]

INT 0x01 \SystemRoot\System32\DRIVERS\ati2mtag.sys (ATI Radeon WindowsNT Miniport Driver/ATI Technologies Inc.) F7264541
INT 0x03 \SystemRoot\System32\DRIVERS\ati2mtag.sys (ATI Radeon WindowsNT Miniport Driver/ATI Technologies Inc.) F72645E7

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!_abnormal_termination + 451 804E2AAD 3 Bytes [1A, CC, AB] {SBB CL, AH; STOSD }

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender SRL)
AttachedDevice \Driver\Tcpip \Device\Tcp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender SRL)
AttachedDevice \Driver\Tcpip \Device\Udp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender SRL)
AttachedDevice \Driver\Tcpip \Device\RawIp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender SRL)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Blade81
2009-11-18, 07:32
Hi,

Limewire is still installed there. Kindly remove it if you want me to assist on this.


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log (dds.txt part only).

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

IrishEyes
2009-11-19, 03:29
I did remove Limewire from the Add/Remove programs when I was originally told. I looked again and I didn't see it in the list. I found some folders and deleted them. I hope that was the right thing to do. I don't know how else to get it off other than the Add/Remove programs option. I hope it worked; if not, could you please tell me how to remove it if I didn't get it all.

ComboFix log:

ComboFix 09-11-18.06 - Amanda 11/18/2009 20:09.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.379 [GMT -6:00]
Running from: c:\documents and settings\Amanda\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\010112010146101105.rx
c:\windows\010112010146116101.xxe
c:\windows\0101120101464955.xxe
c:\windows\0101120101465050.xxe
c:\windows\bk23567.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_FIOO32


((((((((((((((((((((((((( Files Created from 2009-10-19 to 2009-11-19 )))))))))))))))))))))))))))))))
.

2009-11-12 19:09 . 2009-11-12 19:09 -------- d-----w- c:\program files\Trend Micro
2009-11-12 19:06 . 2009-11-12 19:06 -------- d-----w- c:\program files\ERUNT
2009-11-12 18:53 . 2009-11-12 18:53 53248 ----a-r- c:\documents and settings\Amanda\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe
2009-10-24 22:13 . 2009-10-24 22:13 1 ---h--w- c:\windows\mmsmark2.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-19 02:16 . 2009-04-18 21:57 81984 ----a-w- c:\windows\system32\bdod.bin
2009-11-17 20:07 . 2009-11-07 19:47 -------- d-----w- c:\documents and settings\Amanda\Application Data\LimeWire
2009-11-12 21:59 . 2009-07-07 22:46 256 ----a-w- c:\windows\system32\pool.bin
2009-11-12 18:53 . 2009-07-07 22:28 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-11-08 19:35 . 2009-04-18 16:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 19:35 . 2009-06-14 20:33 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-26 01:56 . 2009-05-12 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-26 01:56 . 2009-09-07 12:03 -------- d-----w- c:\program files\Google
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\program files\Yahoo!
2009-10-26 00:01 . 2009-08-22 23:29 -------- d-----w- c:\documents and settings\Amanda\Application Data\IGN_DLM
2009-10-26 00:00 . 2009-08-23 01:50 -------- d-----w- c:\program files\Cryptic Studios
2009-10-04 03:08 . 2009-10-04 03:08 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-30 22:37 . 2009-09-30 22:37 1417353 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_HiddenSecretNightmar\IAF.dll
2009-09-30 22:37 . 2009-09-30 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-09-24 21:49 . 2009-04-17 02:25 29520 ----a-w- c:\documents and settings\Amanda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2003-07-16 16:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 20:53 . 2009-04-18 16:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2003-07-16 16:29 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 14:44 . 2009-08-30 14:44 507904 ----a-r- c:\windows\system32\btwapi.dll
2009-08-29 08:08 . 2003-07-16 16:45 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2003-07-16 16:41 247326 ----a-w- c:\windows\system32\strmdll.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-04-18 368640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-7-29 266240]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-7-29 530944]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:fio32

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [1/25/2008 2:40 PM 86792]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
fioo32 REG_MULTI_SZ fioo32
.
Contents of the 'Scheduled Tasks' folder

2009-11-16 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2009-04-18 21:51]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-18 20:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(964)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2316)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ArcSoft\Magic-i 3\uMgiSvr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-11-18 20:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-19 02:22

Pre-Run: 65,199,435,776 bytes free
Post-Run: 65,601,794,048 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - D6C12F915FB8F260847064C4A19F18B5

Blade81
2009-11-19, 07:13
Ok. Of some reason folders were not deleted by Limewire uninstall routine.

Could you post fresh dds.txt log, please?

IrishEyes
2009-11-20, 02:48
DDS log:


DDS (Ver_09-09-29.01) - NTFSx86
Run by Amanda at 19:47:09.34 on Thu 11/19/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.386 [GMT -6:00]

AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe -kbdx
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Amanda\Desktop\dds.com

============== Pseudo HJT Report ===============

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2008\IEToolbar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2008\IEShow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2008\bdagent.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\amanda\applic~1\mozilla\firefox\profiles\5943iofy.default\
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-1-25 86792]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-7-20 84992]

=============== Created Last 30 ================

2009-11-18 20:08 <DIR> a-dshr-- C:\cmdcons
2009-11-18 20:07 260,608 a------- c:\windows\PEV.exe
2009-11-18 20:07 161,792 a------- c:\windows\SWREG.exe
2009-11-18 20:07 98,816 a------- c:\windows\sed.exe
2009-11-18 20:07 77,312 a------- c:\windows\MBR.exe
2009-11-12 13:09 <DIR> --d----- c:\program files\Trend Micro
2009-11-07 13:47 <DIR> --d----- c:\docume~1\amanda\applic~1\LimeWire
2009-10-24 16:13 1 ----h--- c:\windows\mmsmark2.dat

==================== Find3M ====================

2009-11-19 19:45 81,984 a------- c:\windows\system32\bdod.bin
2009-09-11 08:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-04 15:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-30 08:44 507,904 a----r-- c:\windows\system32\btwapi.dll
2009-08-29 02:08 916,480 -------- c:\windows\system32\wininet.dll
2009-08-26 02:00 247,326 a------- c:\windows\system32\strmdll.dll

============= FINISH: 19:47:47.02 ===============

Blade81
2009-11-20, 08:20
Hi again,


Open notepad and copy/paste the text in the quotebox below into it:



http://forums.spybot.info/showthread.php?p=347686#post347686
Collect::
c:\windows\mmsmark2.dat
DDS::
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
Folder::
c:\documents and settings\Amanda\Application Data\LimeWire
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
"fioo32"=-



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 17 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

IrishEyes
2009-11-21, 21:22
ComboFix log:

09-11-20.05 - Amanda 11/21/2009 12:21.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.451 [GMT -6:00]
Running from: c:\documents and settings\Amanda\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Amanda\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.

2009-11-21 18:15 . 2009-11-21 18:15 -------- d-----w- c:\program files\Java
2009-11-20 01:52 . 2009-11-06 15:20 34112 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-20 01:52 . 2009-11-06 15:20 32448 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-20 01:52 . 2009-11-06 15:20 22352 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-12 19:09 . 2009-11-12 19:09 -------- d-----w- c:\program files\Trend Micro
2009-11-12 19:06 . 2009-11-12 19:06 -------- d-----w- c:\program files\ERUNT
2009-11-12 18:53 . 2009-11-12 18:53 53248 ----a-r- c:\documents and settings\Amanda\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 18:25 . 2009-04-18 21:57 81984 ----a-w- c:\windows\system32\bdod.bin
2009-11-21 18:15 . 2009-05-20 20:42 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-20 23:18 . 2009-05-12 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-12 21:59 . 2009-07-07 22:46 256 ----a-w- c:\windows\system32\pool.bin
2009-11-12 18:53 . 2009-07-07 22:28 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-11-08 19:35 . 2009-04-18 16:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 19:35 . 2009-06-14 20:33 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-26 01:56 . 2009-09-07 12:03 -------- d-----w- c:\program files\Google
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\program files\Yahoo!
2009-10-26 00:01 . 2009-08-22 23:29 -------- d-----w- c:\documents and settings\Amanda\Application Data\IGN_DLM
2009-10-26 00:00 . 2009-08-23 01:50 -------- d-----w- c:\program files\Cryptic Studios
2009-10-04 03:08 . 2009-10-04 03:08 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-30 22:37 . 2009-09-30 22:37 1417353 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_HiddenSecretNightmar\IAF.dll
2009-09-30 22:37 . 2009-09-30 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-09-24 21:49 . 2009-04-17 02:25 29520 ----a-w- c:\documents and settings\Amanda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2003-07-16 16:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 20:53 . 2009-04-18 16:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2003-07-16 16:29 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 14:44 . 2009-08-30 14:44 507904 ----a-r- c:\windows\system32\btwapi.dll
2009-08-29 08:08 . 2003-07-16 16:45 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2003-07-16 16:41 247326 ----a-w- c:\windows\system32\strmdll.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-11-19_02.17.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-21 18:15 . 2009-11-21 18:15 16384 c:\windows\Temp\Perflib_Perfdata_6f4.dat
- 2009-10-26 00:22 . 2009-10-26 00:22 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-10-26 00:22 . 2009-11-20 01:53 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2009-08-20 21:42 . 2009-07-25 10:23 149280 c:\windows\system32\javaws.exe
+ 2009-11-21 18:15 . 2009-11-21 18:15 149280 c:\windows\system32\javaws.exe
- 2009-08-20 21:42 . 2009-07-25 10:23 145184 c:\windows\system32\javaw.exe
+ 2009-11-21 18:15 . 2009-11-21 18:15 145184 c:\windows\system32\javaw.exe
- 2009-08-20 21:42 . 2009-07-25 10:23 145184 c:\windows\system32\java.exe
+ 2009-11-21 18:15 . 2009-11-21 18:15 145184 c:\windows\system32\java.exe
+ 2009-11-21 18:15 . 2009-11-21 18:15 1757696 c:\windows\Installer\2b87b.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-04-18 368640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-21 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-7-29 266240]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-7-29 530944]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [1/25/2008 2:40 PM 86792]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - JAVAQUICKSTARTERSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder

2009-11-16 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2009-04-18 21:51]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\
FF - plugin: c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-21 12:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(960)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2600)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-11-21 12:28
ComboFix-quarantined-files.txt 2009-11-21 18:28
ComboFix2.txt 2009-11-21 18:09
ComboFix3.txt 2009-11-19 02:23

Pre-Run: 65,483,075,584 bytes free
Post-Run: 65,439,219,712 bytes free

- - End Of File - - CC70A645F7971DDFE3CA9F9852E74F18

DDS log:


DDS (Ver_09-09-29.01) - NTFSx86
Run by Amanda at 12:32:56.71 on Sat 11/21/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.496 [GMT -6:00]

AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe -kbdx
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Amanda\Desktop\dds.com

============== Pseudo HJT Report ===============

BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2008\IEToolbar.dll
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2008\IEShow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2008\bdagent.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\amanda\applic~1\mozilla\firefox\profiles\5943iofy.default\
FF - plugin: c:\documents and settings\amanda\application data\mozilla\firefox\profiles\5943iofy.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-1-25 86792]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-7-20 84992]

=============== Created Last 30 ================

2009-11-21 12:15 73,728 a------- c:\windows\system32\javacpl.cpl
2009-11-21 12:00 1,225 a------- C:\CF-Submit.htm
2009-11-18 20:08 <DIR> a-dshr-- C:\cmdcons
2009-11-18 20:07 260,608 a------- c:\windows\PEV.exe
2009-11-18 20:07 161,792 a------- c:\windows\SWREG.exe
2009-11-18 20:07 98,816 a------- c:\windows\sed.exe
2009-11-18 20:07 77,312 a------- c:\windows\MBR.exe
2009-11-12 13:09 <DIR> --d----- c:\program files\Trend Micro

==================== Find3M ====================

2009-11-21 12:32 81,984 a------- c:\windows\system32\bdod.bin
2009-11-21 12:15 411,368 a------- c:\windows\system32\deploytk.dll
2009-09-11 08:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-04 15:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-30 08:44 507,904 a----r-- c:\windows\system32\btwapi.dll
2009-08-29 02:08 916,480 -------- c:\windows\system32\wininet.dll
2009-08-26 02:00 247,326 a------- c:\windows\system32\strmdll.dll

============= FINISH: 12:33:07.71 ===============

Kapersky Online Scanner report:

KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, November 21, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, November 21, 2009 18:02:11
Records in database: 3261619
Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes
Scan area My Computer
A:\
C:\
D:\
E:\
F:\
Scan statistics
Objects scanned 51219
Threats found 1
Infected objects found 1
Suspicious objects found 0
Scan duration 01:11:36

File name Threat Threats count
C:\Documents and Settings\Amanda\Application Data\Sun\Java\Deployment\cache\6.0\57\36d3f0f9-75c9d641 Infected: Trojan-Downloader.Java.Agent.ab 1
Selected area has been scanned.

Blade81
2009-11-21, 23:30
Hi,

Seems that you ran ComboFix twice. Could you post contents of c:\ComboFix\ComboFix2.txt file, please? :)

Delete C:\Documents and Settings\Amanda\Application Data\Sun\Java\Deployment\cache\6.0\57\36d3f0f9-75c9d641 file if found.

IrishEyes
2009-11-22, 04:02
My apologies, my computer had locked up. I think this is the right one.

ComboFix 09-11-20.05 - Amanda 11/21/2009 12:00.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.446 [GMT -6:00]
Running from: c:\documents and settings\Amanda\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Amanda\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

file zipped: c:\windows\mmsmark2.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Amanda\Application Data\LimeWire
c:\documents and settings\Amanda\Application Data\LimeWire\active.mojito
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\branding.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\classic.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\comm.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\alerts.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\appshell.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\auth.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\caps.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\chardet.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\chrome.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\composer.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_html.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\cookie.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\directory.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\downloads.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\editor.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\extensions.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\feeds.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\find.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\gfx.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\inspector.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\intl.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\jar.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\locale.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\oji.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pippki.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\places.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\plugin.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\pref.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\profile.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\rdf.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\satchel.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\shistory.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\storage.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\transformiix.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\uconv.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\update.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\widget.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\windowds.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\xulutil.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\crashreporter.ini
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\dependentlibs.list
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\freebl3.chk
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\freebl3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\greprefs\all.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\javaxpcom.jar
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\js3250.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\LICENSE
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\debug.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\Microformats.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\utils.js
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\mozctl.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\mozctlx.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\nspr4.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\nss3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\nssckbi.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\nssutil3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\platform.ini
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\plc4.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\plds4.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\README.txt
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\arrow.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\arrowd.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\broken-image.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\charsetData.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\contenteditable.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\designmode.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\forms.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\grabber.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\html.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\html\folder.png
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\langGroups.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\language.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\loading-image.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\mathml.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\quirk.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\svg.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\ua.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\viewsource.css
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\res\wincharset.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\smime3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\softokn3.chk
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\softokn3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\sqlite3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\ssl3.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\updater.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\version.properties
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpcom.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpidl.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xul.dll
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\documents and settings\Amanda\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
c:\documents and settings\Amanda\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Amanda\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Amanda\Application Data\LimeWire\downloads.dat
c:\documents and settings\Amanda\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Amanda\Application Data\LimeWire\installation.props
c:\documents and settings\Amanda\Application Data\LimeWire\library.dat
c:\documents and settings\Amanda\Application Data\LimeWire\library5.dat
c:\documents and settings\Amanda\Application Data\LimeWire\limewire.props
c:\documents and settings\Amanda\Application Data\LimeWire\lock
c:\documents and settings\Amanda\Application Data\LimeWire\mojito.props
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\.autoreg
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\310B24C2d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\60393689d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\60D7D5A5d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\98E79480d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\AE98BDF4d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\BAFF9A85d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\C9DF1160d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\Cache\D5267890d01
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\cert8.db
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\compreg.dat
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\cookies.sqlite
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\downloads.sqlite
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\extensions.cache
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\extensions.ini
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\history.dat
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\key3.db
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\permissions.sqlite
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\places.sqlite-journal
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\places.sqlite-stmtjrnl
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\places.sqlite
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\pluginreg.dat
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\prefs.js
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\secmod.db
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\XPC.mfl
c:\documents and settings\Amanda\Application Data\LimeWire\mozilla-profile\xpti.dat
c:\documents and settings\Amanda\Application Data\LimeWire\passive.mojito
c:\documents and settings\Amanda\Application Data\LimeWire\player.props
c:\documents and settings\Amanda\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Amanda\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Amanda\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Amanda\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Amanda\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Amanda\Application Data\LimeWire\questions.props
c:\documents and settings\Amanda\Application Data\LimeWire\simpp.xml
c:\documents and settings\Amanda\Application Data\LimeWire\tables.props
c:\documents and settings\Amanda\Application Data\LimeWire\version.xml
c:\documents and settings\Amanda\Application Data\LimeWire\versions.props
c:\documents and settings\Amanda\Application Data\LimeWire\xml\data\audio.sxml3
c:\windows\mmsmark2.dat

.
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.

2009-11-20 01:52 . 2009-11-06 15:20 34112 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-20 01:52 . 2009-11-06 15:20 32448 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-20 01:52 . 2009-11-06 15:20 22352 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-12 19:09 . 2009-11-12 19:09 -------- d-----w- c:\program files\Trend Micro
2009-11-12 19:06 . 2009-11-12 19:06 -------- d-----w- c:\program files\ERUNT
2009-11-12 18:53 . 2009-11-12 18:53 53248 ----a-r- c:\documents and settings\Amanda\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 18:00 . 2009-04-18 21:57 81984 ----a-w- c:\windows\system32\bdod.bin
2009-11-20 23:18 . 2009-05-12 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-12 21:59 . 2009-07-07 22:46 256 ----a-w- c:\windows\system32\pool.bin
2009-11-12 18:53 . 2009-07-07 22:28 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-11-08 19:35 . 2009-04-18 16:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 19:35 . 2009-06-14 20:33 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-26 01:56 . 2009-09-07 12:03 -------- d-----w- c:\program files\Google
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\program files\Yahoo!
2009-10-26 00:01 . 2009-08-22 23:29 -------- d-----w- c:\documents and settings\Amanda\Application Data\IGN_DLM
2009-10-26 00:00 . 2009-08-23 01:50 -------- d-----w- c:\program files\Cryptic Studios
2009-10-04 03:08 . 2009-10-04 03:08 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-30 22:37 . 2009-09-30 22:37 1417353 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_HiddenSecretNightmar\IAF.dll
2009-09-30 22:37 . 2009-09-30 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-09-24 21:49 . 2009-04-17 02:25 29520 ----a-w- c:\documents and settings\Amanda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2003-07-16 16:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 20:53 . 2009-04-18 16:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2003-07-16 16:29 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 14:44 . 2009-08-30 14:44 507904 ----a-r- c:\windows\system32\btwapi.dll
2009-08-29 08:08 . 2003-07-16 16:45 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2003-07-16 16:41 247326 ----a-w- c:\windows\system32\strmdll.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-11-19_02.17.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-26 00:22 . 2009-11-20 01:53 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2009-10-26 00:22 . 2009-10-26 00:22 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-04-18 368640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-7-29 266240]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-7-29 530944]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [1/25/2008 2:40 PM 86792]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - 6D4E08F6
*NewlyCreated* - B4475D7D
*Deregistered* - 6d4e08f6
*Deregistered* - b4475d7d

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder

2009-11-16 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2009-04-18 21:51]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\
FF - plugin: c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-21 12:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(960)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-11-21 12:09
ComboFix-quarantined-files.txt 2009-11-21 18:09
ComboFix2.txt 2009-11-19 02:23

Pre-Run: 65,682,083,840 bytes free
Post-Run: 65,624,436,736 bytes free

- - End Of File - - EDC73FDFBD043AF815EAFF78E11DCD74

Blade81
2009-11-22, 11:58
Hi,

Double-click C:\CF-Submit.htm file and follow instructions given.

IrishEyes
2009-11-22, 15:33
Where do I click on it from? I looked for it on my computer, but couldn't find it.

Blade81
2009-11-22, 16:31
Hi,

If you can't find the file then go to c:\qoobox\quarantine folder and look for a zip file that name begins as [4]-Submit. If you find one, upload it here (http://www.bleepingcomputer.com/submit-malware.php?channel=4). Kindly include a link to this topic.

IrishEyes
2009-11-22, 21:41
I submitted it as you stated in your previous reply.

http://www.bleepingcomputer.com/submit-malware.php?channel=4

Blade81
2009-11-22, 22:52
Hi,

Looks like you uploaded ComboFix.txt file instead of [4]-Submit zip file in c:\qoobox\quarantine folder. Was there [4]-Submit file present?

IrishEyes
2009-11-23, 02:35
I just submitted what was there in that folder. I'm sorry if I did it wrong. Just a little confused.

Blade81
2009-11-23, 07:02
Ok. I believe there's no need to try looking for the file longer :)

How's your system running now? Any original symptoms left?

IrishEyes
2009-11-24, 00:08
It seems to still be running a little sluggish. Out of nowhere my browser will redirect me to another site telling me I have a virus.

Blade81
2009-11-24, 06:20
Hi,

Does redirecting occur with both Internet Explorer and Firefox?

Start Malwarebytes' Anti-Malware, update definitions on update tab and run a quick scan letting found items to be removed. Post back the report.

Run ComboFix and let it update itself. Post back the report.

IrishEyes
2009-11-25, 23:41
The malwarebytes didn't find anything.

ComboFix 09-11-25.01 - Amanda 11/25/2009 16:32.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.589 [GMT -6:00]
Running from: c:\documents and settings\Amanda\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.

2009-11-20 01:52 . 2009-11-06 15:20 34112 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-20 01:52 . 2009-11-06 15:20 32448 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-20 01:52 . 2009-11-06 15:20 22352 ----a-w- c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-12 19:09 . 2009-11-12 19:09 -------- d-----w- c:\program files\Trend Micro
2009-11-12 19:06 . 2009-11-12 19:06 -------- d-----w- c:\program files\ERUNT
2009-11-12 18:53 . 2009-11-12 18:53 53248 ----a-r- c:\documents and settings\Amanda\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 22:32 . 2009-04-18 21:57 81984 ----a-w- c:\windows\system32\bdod.bin
2009-11-25 22:19 . 2009-04-18 16:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-25 22:19 . 2009-06-14 20:33 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-21 18:15 . 2009-05-20 20:42 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-20 23:18 . 2009-05-12 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-12 21:59 . 2009-07-07 22:46 256 ----a-w- c:\windows\system32\pool.bin
2009-11-12 18:53 . 2009-07-07 22:28 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-10-26 01:56 . 2009-09-07 12:03 -------- d-----w- c:\program files\Google
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-26 00:06 . 2009-07-30 20:53 -------- d-----w- c:\program files\Yahoo!
2009-10-26 00:01 . 2009-08-22 23:29 -------- d-----w- c:\documents and settings\Amanda\Application Data\IGN_DLM
2009-10-26 00:00 . 2009-08-23 01:50 -------- d-----w- c:\program files\Cryptic Studios
2009-10-04 03:08 . 2009-10-04 03:08 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-30 22:37 . 2009-09-30 22:37 1417353 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_HiddenSecretNightmar\IAF.dll
2009-09-30 22:37 . 2009-09-30 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-09-24 21:49 . 2009-04-17 02:25 29520 ----a-w- c:\documents and settings\Amanda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2003-07-16 16:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 20:54 . 2009-04-18 16:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 20:53 . 2009-04-18 16:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2003-07-16 16:29 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 14:44 . 2009-08-30 14:44 507904 ----a-r- c:\windows\system32\btwapi.dll
2009-08-29 08:08 . 2003-07-16 16:45 916480 ------w- c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-11-19_02.17.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-22 09:47 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
- 2008-10-22 09:47 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2009-10-04 03:08 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
- 2009-10-04 03:08 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2009-10-26 00:22 . 2009-11-20 01:53 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2009-10-26 00:22 . 2009-10-26 00:22 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-11-25 09:00 . 2009-11-25 09:00 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
+ 2009-11-25 09:00 . 2009-11-25 09:00 429568 c:\windows\Installer\14ed436.msi
+ 2009-07-21 06:03 . 2009-07-21 06:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
+ 2009-04-18 16:54 . 2009-07-31 16:05 1372672 c:\windows\system32\msxml6.dll
+ 2009-07-21 06:05 . 2009-07-21 06:05 1348432 c:\windows\system32\msxml4.dll
+ 2003-07-16 16:31 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2009-04-18 16:54 . 2009-07-31 16:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2006-09-13 05:01 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-04-18 368640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-7-29 266240]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-7-29 530944]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [1/25/2008 2:40 PM 86792]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder

2009-11-22 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2009-04-18 21:51]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\
FF - plugin: c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\5943iofy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-25 16:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(968)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(5032)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-11-25 16:39
ComboFix-quarantined-files.txt 2009-11-25 22:39
ComboFix2.txt 2009-11-21 18:28
ComboFix3.txt 2009-11-21 18:09
ComboFix4.txt 2009-11-19 02:23

Pre-Run: 65,495,568,384 bytes free
Post-Run: 65,553,620,992 bytes free

- - End Of File - - CE1908011A0672C8A5827F0A5A33607C

Blade81
2009-11-26, 06:31
Hi,

How about this:

Does redirecting occur with both Internet Explorer and Firefox?

tashi
2009-12-03, 19:07
IrishEyes this thread has been closed due to inactivity.

As it has been four days or more since your last post, it will not be re-opened.

If you still require help, please start a new topic and include a new HijackThis log with a link to your previous thread.

Please do not add any logs that might have been requested previously, you would be starting fresh.

Applies only to the original poster, anyone else with similar problems please start your own topic.

Thank you Blade81.