All of the problems I was having before appear to be gone, and it feels like my computer is running faster on top of that, thanks for the help.
I really am amazed by the amount of help you all give.
ComboFix 09-03-14.02 - John 2009-03-16 21:02:05.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2046.1196 [GMT -4:00]
Running from: c:\users\John\Desktop\ComboFix.exe
Command switches used :: c:\users\John\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\Plupilerihehaf.dll
c:\windows\System32\3474.tmp
c:\windows\System32\464F.tmp
c:\windows\System32\8D2E.tmp
c:\windows\System32\CB47.tmp
c:\windows\System32\F42A.tmp
c:\windows\ukocobuhogehus.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\John\AppData\Roaming\LimeWire
c:\users\John\AppData\Roaming\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\alerts.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\caps.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\chardet.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\chrome.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\composer.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_html.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\cookie.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\directory.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\downloads.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\editor.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\extensions.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\feeds.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\find.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\gfx.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\inspector.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\intl.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\jar.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\locale.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\oji.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\places.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\plugin.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\pref.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\profile.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\rdf.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\satchel.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\shistory.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\storage.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\uconv.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\update.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\widget.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\windowds.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\xulutil.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.ini
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\dependentlibs.list
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.chk
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\all.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcom.jar
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\js3250.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\LICENSE
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\debug.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\Microformats.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\utils.js
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\mozctl.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\mozctlx.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\msvcr71.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\nspr4.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\nss3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\nssckbi.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\nssdbm3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\nssutil3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\platform.ini
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\plc4.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\plds4.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\README.txt
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\arrow.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\arrowd.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\broken-image.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetData.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\contenteditable.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\designmode.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\forms.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\grabber.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\html.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\html\folder.png
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\langGroups.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\language.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\loading-image.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\mathml.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\quirk.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\svg.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\ua.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\viewsource.css
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\res\wincharset.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\smime3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.chk
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\sqlite3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\ssl3.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\updater.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\version.properties
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpcom.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpcshell.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpicleanup.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpidl.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpt_dump.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xpt_link.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xul.dll
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\users\John\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner.exe
c:\users\John\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\John\AppData\Roaming\LimeWire\createtimes.cache
c:\users\John\AppData\Roaming\LimeWire\downloads.dat
c:\users\John\AppData\Roaming\LimeWire\fileurns.bak
c:\users\John\AppData\Roaming\LimeWire\fileurns.cache
c:\users\John\AppData\Roaming\LimeWire\filters.props
c:\users\John\AppData\Roaming\LimeWire\installation.props
c:\users\John\AppData\Roaming\LimeWire\library.dat
c:\users\John\AppData\Roaming\LimeWire\library5.dat
c:\users\John\AppData\Roaming\LimeWire\limewire.props
c:\users\John\AppData\Roaming\LimeWire\mojito.props
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\.autoreg
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\3816C1E5d01
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\AE98BDFFd01
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\Cache\BAFF9A9Fd01
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\cert8.db
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\compreg.dat
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\cookies.sqlite
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\downloads.sqlite
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\extensions.cache
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\extensions.ini
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\history.dat
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\key3.db
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\permissions.sqlite
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite-journal
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\pluginreg.dat
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\prefs.js
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\secmod.db
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\XPC.mfl
c:\users\John\AppData\Roaming\LimeWire\mozilla-profile\xpti.dat
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.lck
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.log
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\John\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\John\AppData\Roaming\LimeWire\questions.props
c:\users\John\AppData\Roaming\LimeWire\responses.cache
c:\users\John\AppData\Roaming\LimeWire\simpp.xml
c:\users\John\AppData\Roaming\LimeWire\spam.dat
c:\users\John\AppData\Roaming\LimeWire\tables.props
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme.lwtp
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\
01_star.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\
02_star.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\
03_star.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\
04_star.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\
05_star.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\chat.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\forward_dn.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\forward_up.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\kill.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\kill_on.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\pause_dn.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\pause_up.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\play_dn.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\play_up.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\question.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\rewind_dn.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\rewind_up.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\stop_dn.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\stop_up.gif
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\theme.txt
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\version.txt
c:\users\John\AppData\Roaming\LimeWire\themes\windows_theme\warning.gif
c:\users\John\AppData\Roaming\LimeWire\ttrees.cache
c:\users\John\AppData\Roaming\LimeWire\ttroot.cache
c:\users\John\AppData\Roaming\LimeWire\version.xml
c:\users\John\AppData\Roaming\LimeWire\versions.props
c:\users\John\AppData\Roaming\LimeWire\xml\data\audio.sxml2
c:\users\John\AppData\Roaming\LimeWire\xml\data\audio.sxml3
c:\users\John\AppData\Roaming\uTorrent
c:\users\John\AppData\Roaming\uTorrent\dht.dat
c:\users\John\AppData\Roaming\uTorrent\dht.dat.old
c:\users\John\AppData\Roaming\uTorrent\FEAR2_Project_Origin_Extracted-ready_to_play_NO_STEAM_NEEDED{RenaFUSED}.torrent
c:\users\John\AppData\Roaming\uTorrent\OOo_2.3.1_Win32Intel_install_en-US.exe.torrent
c:\users\John\AppData\Roaming\uTorrent\resume.dat
c:\users\John\AppData\Roaming\uTorrent\resume.dat.old
c:\users\John\AppData\Roaming\uTorrent\rss.dat
c:\users\John\AppData\Roaming\uTorrent\rss.dat.old
c:\users\John\AppData\Roaming\uTorrent\Savage2Install-01.00.00.exe.torrent
c:\users\John\AppData\Roaming\uTorrent\settings.dat
c:\users\John\AppData\Roaming\uTorrent\settings.dat.old
c:\users\John\AppData\Roaming\uTorrent\Sins_Of_A_Solar_Empire-PROCYON.torrent
c:\users\John\AppData\Roaming\uTorrent\The_Witcher_bik_files.torrent
c:\users\John\AppData\Roaming\uTorrent\utorrent.lng
c:\users\John\AppData\Roaming\uTorrent\Worms Armageddon - New Edition.torrent
c:\windows\Plupilerihehaf.dll
c:\windows\System32\3474.tmp
c:\windows\System32\464F.tmp
c:\windows\System32\8D2E.tmp
c:\windows\System32\CB47.tmp
c:\windows\System32\F42A.tmp
c:\windows\ukocobuhogehus.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.
2009-03-14 22:28 . 2009-03-14 22:28 <DIR> d-------- c:\program files\Trend Micro
2009-03-14 22:23 . 2009-03-14 22:23 <DIR> d-------- c:\program files\ERUNT
2009-03-14 21:12 . 2009-03-14 21:12 <DIR> d--h----- c:\windows\PIF
2009-03-14 18:59 . 2009-03-14 18:59 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-14 18:12 . 2009-03-14 18:12 <DIR> d--hs---- c:\windows\System32\NetworkService32
2009-03-14 12:22 . 2009-03-16 09:23 <DIR> d-------- c:\windows\System32\drivers\Avg
2009-03-14 12:22 . 2009-03-14 19:01 <DIR> d-------- c:\users\All Users\avg8
2009-03-14 12:22 . 2009-03-14 19:01 <DIR> d-------- c:\programdata\avg8
2009-03-14 12:22 . 2009-03-14 12:22 <DIR> d-------- c:\program files\AVG
2009-03-14 12:22 . 2009-03-14 12:22 325,640 --a------ c:\windows\System32\drivers\avgldx86.sys
2009-03-14 12:22 . 2009-03-14 12:22 107,912 --a------ c:\windows\System32\drivers\avgtdix.sys
2009-03-14 12:22 . 2009-03-14 12:22 10,520 --a------ c:\windows\System32\avgrsstx.dll
2009-03-14 10:59 . 2009-03-14 18:01 133 --a------ c:\windows\wininit.ini
2009-03-14 10:29 . 2009-03-14 10:45 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
2009-03-14 10:29 . 2009-03-14 10:45 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
2009-03-14 10:29 . 2009-03-14 17:40 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-03-13 21:51 . 2009-03-09 15:06 15,688 --a------ c:\windows\System32\lsdelete.exe
2009-03-13 21:34 . 2009-03-13 21:34 <DIR> d----c--- c:\windows\System32\DRVSTORE
2009-03-13 21:34 . 2009-03-09 15:06 64,160 --a------ c:\windows\System32\drivers\Lbd.sys
2009-03-13 21:33 . 2009-03-13 21:34 <DIR> d-------- c:\users\All Users\Lavasoft
2009-03-13 21:33 . 2009-03-13 21:33 <DIR> d--h-c--- c:\users\All Users\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-13 21:33 . 2009-03-13 21:34 <DIR> d-------- c:\programdata\Lavasoft
2009-03-13 21:33 . 2009-03-13 21:33 <DIR> d--h-c--- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-13 21:33 . 2009-03-13 21:33 <DIR> d-------- c:\program files\Lavasoft
2009-03-11 17:50 . 2009-03-11 17:50 <DIR> d-------- c:\program files\LucasArts
2009-03-11 01:48 . 2008-12-16 00:00 8,147,968 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 01:48 . 2008-12-16 01:53 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 01:48 . 2008-12-16 01:53 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 01:48 . 2008-12-16 01:53 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 01:47 . 2009-02-08 21:59 2,028,032 --a------ c:\windows\System32\win32k.sys
2009-03-11 01:47 . 2008-11-27 00:42 269,824 --a------ c:\windows\System32\schannel.dll
2009-03-06 23:59 . 2009-03-06 23:59 <DIR> d-------- C:\FEAR
2009-03-01 13:59 . 2009-03-01 13:59 <DIR> d-------- c:\users\John\AppData\Roaming\InstallShield
2009-02-18 22:40 . 2009-02-19 01:59 <DIR> d-------- c:\program files\Battle for Wesnoth 1.5.10-1_6beta2
2009-02-17 21:40 . 2008-10-10 05:52 4,379,984 --a------ c:\windows\System32\D3DX9_40.dll
2009-02-17 21:40 . 2008-10-10 05:52 2,036,576 --a------ c:\windows\System32\D3DCompiler_40.dll
2009-02-17 21:40 . 2008-10-27 11:04 514,384 --a------ c:\windows\System32\XAudio2_3.dll
2009-02-17 21:40 . 2008-10-10 05:52 452,440 --a------ c:\windows\System32\d3dx10_40.dll
2009-02-17 21:40 . 2008-10-27 11:04 235,856 --a------ c:\windows\System32\xactengine3_3.dll
2009-02-17 21:40 . 2008-10-27 11:04 70,992 --a------ c:\windows\System32\XAPOFX1_2.dll
2009-02-17 21:40 . 2008-10-27 11:04 23,376 --a------ c:\windows\System32\X3DAudio1_5.dll
2009-02-17 21:38 . 2009-02-17 21:39 <DIR> d--h----- c:\windows\msdownld.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 00:51 --------- d-----w c:\program files\UOAM
2009-03-17 00:50 --------- d-----w c:\program files\Viewpoint
2009-03-17 00:49 --------- d-----w c:\program files\Java
2009-03-17 00:47 --------- d-----w c:\program files\Steam
2009-03-17 00:38 --------- d-----w c:\program files\Dell
2009-03-17 00:36 --------- d-----w c:\program files\Logitech
2009-03-16 00:00 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-15 23:59 --------- d-----w c:\programdata\Symantec
2009-03-15 23:59 --------- d-----w c:\program files\Symantec
2009-03-15 02:21 --------- d-----w c:\users\John\AppData\Roaming\OpenOffice.org2
2009-03-15 01:12 --------- d-----w c:\programdata\Media Center Programs
2009-03-15 01:12 --------- d-----w c:\program files\Electronic Arts
2009-03-14 02:18 --------- d-----w c:\program files\Saga
2009-03-14 02:12 --------- d-----w c:\program files\GRETECH
2009-03-11 21:50 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-11 21:06 --------- d-----w c:\program files\NCsoft
2009-03-11 09:36 --------- d-----w c:\program files\Common Files\Steam
2009-03-11 07:12 --------- d-----w c:\program files\Windows Mail
2009-03-09 03:00 --------- d-----w c:\program files\Warcraft III
2009-03-01 18:01 --------- d-----w c:\program files\Garena
2009-02-19 03:25 --------- d-----w c:\program files\Diablo II
2009-02-14 01:12 --------- d-----w c:\program files\Google
2009-02-12 00:37 --------- d-----w c:\users\John\AppData\Roaming\UFOAI
2009-02-12 00:37 --------- d-----w c:\program files\UFOAI-2.2.1
2009-01-29 05:36 --------- d-----w c:\program files\Sword of The New World
2009-01-21 03:32 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2009-01-19 20:52 --------- d-----w c:\users\John\AppData\Roaming\Bioshock
2009-01-17 19:56 --------- d-----w c:\program files\Starcraft
2009-01-16 03:49 413,696 ----a-w c:\windows\System32\wrap_oal.dll
2009-01-16 03:49 110,592 ----a-w c:\windows\System32\OpenAL32.dll
2009-01-15 04:16 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-15 04:16 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-15 04:15 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2008-12-30 17:19 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-12-23 23:21 965,664 ----a-w c:\windows\System32\RtkPgExt.dll
2008-12-23 23:20 322,080 ----a-w c:\windows\System32\RtkApoApi.dll
2008-12-23 23:20 2,510,368 ----a-w c:\windows\System32\RtkAPO.dll
2008-12-18 19:32 37,376 ----a-w c:\windows\System32\RtkCoInst.dll
2008-12-10 08:15 174 --sha-w c:\program files\desktop.ini
2008-09-24 06:47 378 ----a-w c:\users\John\AppData\Roaming\wklnhst.dat
2008-01-16 23:23 22,328 ----a-w c:\users\John\AppData\Roaming\PnkBstrK.sys
2008-07-26 02:06 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-03-15_20.09.09.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-15 23:06:05 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-17 00:27:31 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-15 23:06:05 81,920 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 00:27:31 81,920 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-15 23:06:05 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-17 00:27:31 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:28 3,771,296 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32.dll
- 2008-10-05 03:24:04 235,936 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-02-03 02:15:30 240,544 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2009-01-03 09:55:08 84,661 ----a-w c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-03-17 00:47:26 84,661 ----a-w c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
- 2009-03-14 01:33:13 173,215,342 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-03-16 05:01:10 173,354,946 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Aim6"="c:\program files\AIM6\aim6.exe" [2007-09-29 50528]
"Steam"="c:\program files\steam\steam.exe" [2009-01-14 1410296]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 68856]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-25 29744]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13584928]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 92704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-12-23 6707744]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-14 1932568]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
c:\users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 393216]
PowerReg Scheduler V3.exe [2008-08-23 225280]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-02 50688]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-12 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\b2e5ccee553]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0053436]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00B861]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3A684CDF-90E0-411F-BB07-85E8EDE1253E}"= UDP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{706A8BE1-1528-4B08-94F8-B74E44B5F501}"= TCP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{9D319A95-97E0-42B3-BA24-2776D8C8AD10}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{8B7FAAA7-F543-4C27-8C7F-F46F8C9EB8CB}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{9E399F19-DC98-48B8-A322-73C945B1469F}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{EECA29B0-7DB5-469F-A39C-68E46A5A10E7}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{2ABD5C77-EFDF-4AE0-97CA-2C36E6765924}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{AC98F4E7-AE44-40F3-A7CB-CDD78AAB2D61}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{F1F0A753-C8E0-48BA-A59B-92D0DBD0E2B5}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{6FDF6478-5E11-4FE9-8D1F-F8EF1AD0FED5}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{17390B5C-C5B8-4B77-ADC7-610F8AB5A2E5}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{B4D0C5FD-87EB-4B63-8704-FAD14157D950}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{CAB5675C-391F-4CAF-917C-0AFA9AEFF2E1}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{3B07CD10-0119-4170-A617-568E5FFB5D99}"= UDP:c:\program files\Flagship Studios\Hellgate London Demo\Launcher.exe:Hellgate: London
"{6624886A-5E20-44ED-8672-A65FF6CF682F}"= TCP:c:\program files\Flagship Studios\Hellgate London Demo\Launcher.exe:Hellgate: London
"{24DEFE7E-44D2-4627-B437-A538D6B9ED11}"= UDP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{63F69C84-DB07-41DF-8D5D-111752B23133}"= TCP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{F47988EB-1806-4A4E-AC66-D9780E5CC41A}"= UDP:c:\program files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"{FCCD0D2B-54D9-4608-86FD-962709909873}"= TCP:c:\program files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"{C40784B5-B45F-40E3-A8DC-3332EFF2025B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{10F14B1A-5682-41A3-88FC-0798886B01A9}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{2D3408F3-2471-4537-9499-2B4BE4CAB1CD}"= UDP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{00D0E48C-D428-4D1A-AA79-C37183E2FE77}"= TCP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{521857CA-AD53-44BC-B2CA-917F10A8B96A}"= UDP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{2018BBF6-646F-4D6C-9AE7-5613228A0229}"= TCP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{2C74BEFE-762A-4F75-B51E-944968021D79}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{AD639613-62F9-4178-BD5B-9DF1CB0E6356}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{B21EF312-8A62-4782-ABE8-4ED227583F40}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{A8817154-4C3C-40D1-824F-748E6673C50D}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{BD3269AF-3059-44C5-B54B-2C32F6EBF3CE}c:\\program files\\starcraft\\starcraft.exe"= UDP:c:\program files\starcraft\starcraft.exe:StarCraft
"UDP Query User{F127E622-1BA4-4E5C-969D-7C14839487AE}c:\\program files\\starcraft\\starcraft.exe"= TCP:c:\program files\starcraft\starcraft.exe:StarCraft
"TCP Query User{A39CABEB-F8D1-4702-BA76-A204A7AA5AC6}c:\\program files\\steam\\steamapps\\jcjbolbro\\team fortress 2\\hl2.exe"= UDP:c:\program files\steam\steamapps\jcjbolbro\team fortress 2\hl2.exe:hl2
"UDP Query User{6587592B-C489-4D10-985D-F83EA4155613}c:\\program files\\steam\\steamapps\\jcjbolbro\\team fortress 2\\hl2.exe"= TCP:c:\program files\steam\steamapps\jcjbolbro\team fortress 2\hl2.exe:hl2
"{CD455C9B-9C88-411F-9707-3ADCB47437CA}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{A7F21424-52FE-41F1-8787-D40E1E87AEDA}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{0C1CFFD2-A987-4FA3-A10C-3B7D3E9928BE}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{59782AC3-12C1-420E-98BF-CA92D4177FD9}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{19CE2690-1F1B-416B-BCF3-74DCD4E7D338}"= UDP:c:\program files\Steam\steamapps\common\mass effect\runme.exe:Mass Effect
"{214085C3-986B-44C3-B681-61589256AC5F}"= TCP:c:\program files\Steam\steamapps\common\mass effect\runme.exe:Mass Effect
"{716B8984-81F8-4687-B373-AD235E60ACE8}"= UDP:c:\program files\Steam\steamapps\common\dawn of war gold\W40kWA.exe

awn of War Gold: Winter Assault
"{530364DD-5A4C-4316-9325-3E92043EC892}"= TCP:c:\program files\Steam\steamapps\common\dawn of war gold\W40kWA.exe

awn of War Gold: Winter Assault
"{EF1B7AD1-E78C-4DE2-84A5-D4B61CB4F23D}"= UDP:c:\program files\Steam\steamapps\common\dawn of war soulstorm\soulstorm.exe

awn of War: Soulstorm
"{D4CB4D40-FF4E-4E97-B11D-6E5D54E8B06B}"= TCP:c:\program files\Steam\steamapps\common\dawn of war soulstorm\soulstorm.exe

awn of War: Soulstorm
"{532C5271-7F2E-4622-8691-8551E8AB9311}"= UDP:c:\program files\Steam\steamapps\common\xcom apocalypse\dosbox.exe:X-COM: Apocalypse
"{63DCC686-52C8-4910-AF6C-CACE13250568}"= TCP:c:\program files\Steam\steamapps\common\xcom apocalypse\dosbox.exe:X-COM: Apocalypse
"{C0C3D64D-0998-46B4-8ABF-D12D9E733776}"= UDP:c:\program files\Steam\steamapps\common\bioshock\Builds\Release\Bioshock.exe:Bioshock
"{B0B13E06-00FE-46CA-88EE-D7DFF95ABAE7}"= TCP:c:\program files\Steam\steamapps\common\bioshock\Builds\Release\Bioshock.exe:Bioshock
"{E4691248-E805-440A-95E0-0073F091E420}"= UDP:c:\program files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe:Mass Effect
"{2C7191DB-352E-4B60-9D2B-200249D49556}"= TCP:c:\program files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe:Mass Effect
"{ECC0E85C-B25E-469B-98E6-12C93F3A3540}"= UDP:c:\program files\Steam\steamapps\common\world of goo\WorldOfGoo.exe:World of Goo
"{C8CE8448-F8E8-4864-B819-875E960F6B5C}"= TCP:c:\program files\Steam\steamapps\common\world of goo\WorldOfGoo.exe:World of Goo
"{EF86AAC7-0244-403E-B2E7-5455BC25942D}"= UDP:c:\program files\Steam\steamapps\common\fallout 3\FalloutLauncher.exe:Fallout 3
"{580B2C23-3001-4761-9A7B-6849A90ABA15}"= TCP:c:\program files\Steam\steamapps\common\fallout 3\FalloutLauncher.exe:Fallout 3
"{F47E0BAA-FEF9-49D4-BB43-2207DA7DF544}"= UDP:c:\program files\Steam\steamapps\common\dawn of war 2\DOW2.exe:Warhammer 40,000: Dawn of War II
"{246ACB8A-6A37-46FD-AF71-B61E0BE36A75}"= TCP:c:\program files\Steam\steamapps\common\dawn of war 2\DOW2.exe:Warhammer 40,000: Dawn of War II
"{6ECDE376-2F53-4C8A-95E2-97C4F02D10C9}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{920A9BE8-E427-47A4-8674-7D6CF9B782FA}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{98BD487D-3C31-4A34-A02B-924658A178F7}"= UDP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{95009411-CFAE-4668-B37E-AD0C430DCCC5}"= TCP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{ABA323B6-5198-43F4-8466-209AF58BE158}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{7B8168E1-02EB-4AA9-B578-1E4246906FB1}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{D8A6B6F0-B6FE-4904-914D-BE1110C9A5C2}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-03-13 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-03-14 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-03-14 107912]
R2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [2008-12-30 81920]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-14 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-14 298264]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-03-14 1153368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-10-05 24652]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-10-02 29744]
--- Other Services/Drivers In Memory ---
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - SPBBCDrv
*Deregistered* - SRTSPX
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMNDISV
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df86b74a-8408-11dc-8b71-001aa09804d5}]
\shell\AutoRun\command - G:\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:06]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKLM-Run-Qcinecabafojo - c:\windows\Plupilerihehaf.dll
HKLM-Run-Pmopayizajo - c:\windows\ukocobuhogehus.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1071002
FF - ProfilePath - c:\users\John\AppData\Roaming\Mozilla\Firefox\Profiles\bhnlhr78.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-16 21:06:18
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
Completion time: 2009-03-16 21:08:20
ComboFix-quarantined-files.txt 2009-03-17 01:08:18
ComboFix2.txt 2009-03-16 00:10:40
Pre-Run: 61,281,484,800 bytes free
Post-Run: 61,263,654,912 bytes free
767 --- E O F --- 2009-03-11 07:05:38