ComboFix 10-09-02.04 - Coach 09/03/2010 10:34:53.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2457 [GMT -7:00]
Running from: c:\documents and settings\Coach\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Coach\Desktop\CFScript.txt
file zipped: c:\windows\system32\ctuuef.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\JD\Application Data\LimeWire
c:\documents and settings\JD\Application Data\LimeWire\browser\xul-v2.0b2.5-do-not-remove
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\branding.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\classic.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\comm.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\alerts.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\appshell.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\auth.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\caps.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\chardet.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\chrome.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\composer.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_html.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\cookie.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\directory.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\downloads.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\editor.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\extensions.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\feeds.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\find.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\gfx.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\inspector.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\intl.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\jar.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\locale.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\oji.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pippki.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\places.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\plugin.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\pref.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\profile.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\rdf.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\satchel.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\shistory.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\storage.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\transformiix.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\uconv.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\update.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\widget.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\windowds.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\xulutil.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\crashreporter.ini
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\dependentlibs.list
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\freebl3.chk
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\freebl3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\greprefs\all.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\javaxpcom.jar
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\js3250.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\LICENSE
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\debug.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\Microformats.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\utils.js
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\mozctl.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\mozctlx.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\nspr4.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\nss3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\nssckbi.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\nssutil3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\platform.ini
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\plc4.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\plds4.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\README.txt
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\arrow.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\arrowd.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\broken-image.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\charsetData.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\contenteditable.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\designmode.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\forms.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\grabber.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\html.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\html\folder.png
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\langGroups.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\language.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\loading-image.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\mathml.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\quirk.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\svg.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\ua.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\viewsource.css
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\res\wincharset.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\smime3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\softokn3.chk
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\softokn3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\sqlite3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\ssl3.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\updater.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\version.properties
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpcom.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpidl.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xul.dll
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\documents and settings\JD\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
c:\documents and settings\JD\Application Data\LimeWire\bugs.data
c:\documents and settings\JD\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\JD\Application Data\LimeWire\createtimes.cache
c:\documents and settings\JD\Application Data\LimeWire\downloads.dat
c:\documents and settings\JD\Application Data\LimeWire\fileurns.cache
c:\documents and settings\JD\Application Data\LimeWire\filters.props
c:\documents and settings\JD\Application Data\LimeWire\gnutella.net
c:\documents and settings\JD\Application Data\LimeWire\installation.props
c:\documents and settings\JD\Application Data\LimeWire\library.dat
c:\documents and settings\JD\Application Data\LimeWire\library5.dat
c:\documents and settings\JD\Application Data\LimeWire\limewire.props
c:\documents and settings\JD\Application Data\LimeWire\lock
c:\documents and settings\JD\Application Data\LimeWire\mojito.props
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\.autoreg
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\1FEE1D11d01
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\Cache\D3A366EBd01
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\cert8.db
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\compreg.dat
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\cookies.sqlite
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\downloads.sqlite
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\extensions.cache
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\extensions.ini
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\history.dat
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\key3.db
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\permissions.sqlite
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\places.sqlite-journal
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\places.sqlite
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\pluginreg.dat
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\prefs.js
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\secmod.db
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\XPC.mfl
c:\documents and settings\JD\Application Data\LimeWire\mozilla-profile\xpti.dat
c:\documents and settings\JD\Application Data\LimeWire\player.props
c:\documents and settings\JD\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\JD\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\JD\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\JD\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\JD\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\JD\Application Data\LimeWire\questions.props
c:\documents and settings\JD\Application Data\LimeWire\responses.cache
c:\documents and settings\JD\Application Data\LimeWire\simpp.cert
c:\documents and settings\JD\Application Data\LimeWire\simpp.xml
c:\documents and settings\JD\Application Data\LimeWire\spam.dat
c:\documents and settings\JD\Application Data\LimeWire\tables.props
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\JD\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\JD\Application Data\LimeWire\ttdata.cache
c:\documents and settings\JD\Application Data\LimeWire\ttrees.cache
c:\documents and settings\JD\Application Data\LimeWire\ttroot.cache
c:\documents and settings\JD\Application Data\LimeWire\update.cert
c:\documents and settings\JD\Application Data\LimeWire\urns.dat
c:\documents and settings\JD\Application Data\LimeWire\version.xml
c:\documents and settings\JD\Application Data\LimeWire\versions.props
c:\documents and settings\JD\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\JD\Application Data\LimeWire\xml\data\audio.sxml3
c:\documents and settings\JD\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\JD\Application Data\LimeWire\xml\data\video.sxml3
c:\program files\LimeWire
c:\program files\LimeWire\hs_err_pid1680.log
c:\program files\LimeWire\hs_err_pid2096.log
c:\program files\LimeWire\hs_err_pid2568.log
c:\program files\LimeWire\hs_err_pid624.log
c:\windows\system32\ctuuef.dll
H:\Autorun.inf
I:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_HODTUVKN
-------\Legacy_IMHJBMDID
-------\Legacy_UHLDXPP
-------\Service_hodtuvkn
-------\Service_igchwpk
-------\Service_imhjbmdid
-------\Service_negxqf
-------\Service_uhldxpp
-------\Service_woagvvueo
-------\Service_xpqugsxx
((((((((((((((((((((((((( Files Created from 2010-08-03 to 2010-09-03 )))))))))))))))))))))))))))))))
.
2010-09-03 17:42 . 2010-09-03 17:42 -------- d-----w- c:\windows\LastGood
2010-08-25 17:25 . 2010-08-25 17:29 -------- d-----w- c:\program files\SpywareBlaster
2010-08-25 00:57 . 2010-08-25 01:26 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-24 19:58 . 2010-08-24 19:58 -------- d-----w- c:\program files\ERUNT
2010-08-19 18:32 . 2010-08-19 18:32 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-08-19 18:32 . 2010-08-19 18:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2010-08-19 18:32 . 2010-08-19 18:32 -------- d-----w- c:\program files\Common Files\XoftSpySE
2010-08-19 18:32 . 2010-08-19 18:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\XoftSpySE
2010-08-19 18:32 . 2010-08-19 18:32 -------- d-----w- c:\program files\XoftSpySE6
2010-08-16 21:23 . 2010-08-16 21:23 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 00:11 . 2008-12-11 22:40 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Temp
2010-08-25 20:31 . 2010-08-25 20:31 61440 ----a-w- c:\documents and settings\JD\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-32b7d32e-n\decora-sse.dll
2010-08-25 20:31 . 2010-08-25 20:31 503808 ----a-w- c:\documents and settings\JD\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-628ce583-n\msvcp71.dll
2010-08-25 20:31 . 2010-08-25 20:31 499712 ----a-w- c:\documents and settings\JD\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-628ce583-n\jmc.dll
2010-08-25 20:31 . 2010-08-25 20:31 348160 ----a-w- c:\documents and settings\JD\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-628ce583-n\msvcr71.dll
2010-08-25 20:31 . 2010-08-25 20:31 12800 ----a-w- c:\documents and settings\JD\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-32b7d32e-n\decora-d3d.dll
2010-08-25 16:44 . 2008-12-11 08:12 -------- d-----w- c:\program files\Google
2010-08-25 01:26 . 2010-08-25 01:26 61440 ----a-w- c:\documents and settings\Coach\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4c6f6996-n\decora-sse.dll
2010-08-25 01:26 . 2010-08-25 01:26 503808 ----a-w- c:\documents and settings\Coach\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-338cc03d-n\msvcp71.dll
2010-08-25 01:26 . 2010-08-25 01:26 499712 ----a-w- c:\documents and settings\Coach\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-338cc03d-n\jmc.dll
2010-08-25 01:26 . 2010-08-25 01:26 348160 ----a-w- c:\documents and settings\Coach\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-338cc03d-n\msvcr71.dll
2010-08-25 01:26 . 2010-08-25 01:26 12800 ----a-w- c:\documents and settings\Coach\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4c6f6996-n\decora-d3d.dll
2010-08-25 00:57 . 2008-12-09 10:18 -------- d-----w- c:\program files\Common Files\Java
2010-08-25 00:57 . 2010-08-25 00:57 0 ----a-w- c:\windows\system32\REN57.tmp
2010-08-25 00:57 . 2008-12-09 10:18 -------- d-----w- c:\program files\Java
2010-08-24 23:59 . 2009-03-10 20:52 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-08-22 20:19 . 2009-01-28 04:23 130712 ----a-w- c:\documents and settings\JD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-18 18:56 . 2008-12-12 02:07 130712 ----a-w- c:\documents and settings\Coach\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-16 17:36 . 2008-01-13 09:13 -------- d-----w- c:\program files\Common Files\supportsoft
2010-08-16 17:28 . 2009-02-27 20:44 -------- d-----w- c:\program files\Alternate Chord
2010-08-16 17:28 . 2009-02-27 20:44 -------- d-----w- c:\documents and settings\Coach\Application Data\Alternate
2010-08-16 17:28 . 2009-02-27 20:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Alternate
2010-08-16 16:47 . 2010-07-14 23:16 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-08-16 16:47 . 2008-12-09 09:42 -------- d-----w- c:\program files\Logitech
2010-08-16 16:47 . 2010-07-14 23:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogiShrd
2010-07-31 04:57 . 2010-07-31 04:57 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ArcSoft
2010-07-31 04:56 . 2010-07-31 04:56 -------- d-----w- c:\documents and settings\JD\Application Data\ArcSoft
2010-07-31 04:56 . 2010-07-31 04:56 -------- d-----w- c:\documents and settings\JD\Application Data\HP SimpleSave Application
2010-07-30 06:37 . 2010-07-15 16:55 -------- d-----w- c:\documents and settings\Mom\Application Data\Yahoo!
2010-07-25 20:30 . 2008-12-11 22:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2010-07-17 16:58 . 2010-07-17 16:58 94776 ---ha-w- c:\windows\system32\mlfcache.dat
2010-07-17 16:31 . 2009-08-29 14:40 -------- d-----w- c:\documents and settings\Mom\Application Data\Apple Computer
2010-07-17 06:46 . 2009-12-29 18:07 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-15 22:39 . 2008-12-13 00:45 -------- d-----w- c:\documents and settings\JD\Application Data\Apple Computer
2010-07-15 21:51 . 2010-07-15 21:51 4096 ----a-w- c:\windows\system32\03.tmp
2010-07-15 21:44 . 2008-04-02 00:01 -------- d-----w- c:\program files\iTunes
2010-07-15 21:43 . 2007-01-02 03:49 -------- d-----w- c:\program files\iPod
2010-07-15 21:43 . 2007-10-29 17:44 -------- d-----w- c:\program files\Common Files\Apple
2010-07-15 21:42 . 2010-07-15 21:42 -------- d-----w- c:\program files\Bonjour
2010-07-15 21:23 . 2010-04-13 19:51 -------- d-----w- c:\program files\Yahoo!
2010-07-15 21:21 . 2010-07-15 20:40 -------- d-----w- c:\documents and settings\Coach\Application Data\Skype
2010-07-15 21:10 . 2010-07-15 21:10 -------- d-----w- c:\documents and settings\JD\Application Data\DassaultSystemes
2010-07-15 21:10 . 2009-02-12 05:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DassaultSystemes
2010-07-15 21:08 . 2003-10-20 19:45 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-15 21:02 . 2010-07-15 20:41 -------- d-----w- c:\documents and settings\Coach\Application Data\skypePM
2010-07-15 20:40 . 2010-01-13 01:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2010-07-15 20:37 . 2010-07-15 20:37 -------- d-----w- c:\documents and settings\Coach\Application Data\MSNInstaller
2010-07-15 20:32 . 2010-04-13 19:53 -------- d-----w- c:\documents and settings\Coach\Application Data\Yahoo!
2010-07-15 08:13 . 2010-07-15 08:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-15 08:11 . 2009-02-24 20:36 -------- d-----w- c:\program files\QuickTime
2010-07-15 08:09 . 2010-07-15 08:09 -------- d-----w- c:\program files\Apple Software Update
2010-07-15 07:41 . 2010-07-15 07:40 -------- d-----w- c:\documents and settings\JD\Application Data\Yahoo!
2010-07-15 07:40 . 2009-01-09 21:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2010-07-14 23:18 . 2010-07-14 23:18 10134 ----a-r- c:\documents and settings\Mom\Application Data\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
2010-07-14 23:16 . 2010-07-14 23:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech
2010-07-12 20:29 . 2010-07-12 20:29 45056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-07-12 20:29 . 2010-07-12 20:29 45056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-07-12 20:29 . 2010-07-12 20:29 49152 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-07-12 20:29 . 2010-07-12 20:29 45056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-07-12 20:29 . 2010-07-12 20:29 45056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-07-12 20:29 . 2010-07-12 20:29 40960 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-07-12 20:29 . 2010-07-12 20:29 308808 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-07-12 20:29 . 2010-07-12 20:29 14848 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-07-12 20:29 . 2010-07-12 20:29 341600 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-07-12 20:29 . 2008-12-09 09:29 -------- d-----w- c:\program files\Common Files\Real
2010-07-12 20:29 . 2008-12-09 09:29 -------- d-----w- c:\program files\Real
2010-07-12 20:29 . 2010-07-12 20:29 -------- d-----w- c:\program files\Common Files\xing shared
2010-07-12 20:28 . 2006-07-12 01:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-12 20:28 . 2003-03-19 04:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-07-12 20:27 . 2010-07-12 20:27 493064 ----a-w- c:\documents and settings\Coach\Application Data\Real\RealOne Player\setup\AU_setup16.exe
2010-07-06 18:43 . 2008-12-11 00:10 131104 ----a-w- c:\documents and settings\Mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-06 18:43 . 2010-07-06 18:43 126 ----a-w- c:\documents and settings\Mom\Local Settings\Application Data\fusioncache.dat
2010-06-16 01:01 . 2010-06-16 01:01 72504 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-12 05:16 . 2010-06-26 16:13 9830400 ----a-w- c:\windows\VerizonDM.msi
2010-06-11 21:51 . 2010-06-11 21:51 3055600 ----a-w- c:\documents and settings\Mom\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 21:51 . 2010-06-11 21:51 3055600 ----a-w- c:\documents and settings\Coach\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 21:36 . 2010-06-11 21:36 275952 ----a-w- c:\documents and settings\Mom\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-06-11 21:36 . 2010-06-11 21:36 275952 ----a-w- c:\documents and settings\Coach\Application Data\Mozilla\plugins\npgoogletalk.dll
2008-04-25 17:33 . 2008-04-25 17:33 8548984 ----a-w- c:\program files\WindowsMaliciousSoftwareRemoval-KB890830-V1.40.exe
2010-03-08 02:24 . 2010-03-08 02:24 2161527 ----a-w- c:\program files\mozilla firefox\components\1399571.dll
2008-09-10 21:49 . 2008-09-10 21:49 5817064 ----a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\windows\system32\03.tmp ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 4096
Created time: 2010-07-15 21:51
Modified time: 2010-07-15 21:51
MD5: !HASH: COULD NOT OPEN FILE !!!!!
SHA1: !HASH: COULD NOT OPEN FILE !!!!!
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-12 202256]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Logitech Mouse"="c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Documents and Settings\\Coach\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Documents and Settings\\Coach\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R3 wsvad_driver;WS Audio Device;c:\windows\system32\drivers\VirtualAudio.sys [5/13/2009 1:14 PM 16896]
S3 gupdate1c992b44a9e1d9c;Google Update Service (gupdate1c992b44a9e1d9c);c:\program files\Google\Update\GoogleUpdate.exe [2/19/2009 10:05 AM 133104]
S3 XoftSpyService;XoftSpyService;c:\program files\Common Files\XoftSpySE\6\xoftspyservice.exe [10/23/2009 2:58 PM 582424]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
svcboot_fbgekqqsy REG_MULTI_SZ svcboot_fbgekqqsy
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-07-30 c:\windows\Tasks\1-EraseUnused.job
- c:\progra~1\Eraser\Eraser.exe [2007-12-22 23:03]
2010-07-30 c:\windows\Tasks\2-MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2010-07-17 c:\windows\Tasks\4-C-drive - ChkDsk.job
- c:\windows\system32\chkdsk.exe [2002-09-03 19:34]
2010-07-16 c:\windows\Tasks\5-G-drive - Chkdsk.job
- c:\windows\system32\chkdsk.exe [2002-09-03 19:34]
2010-07-16 c:\windows\Tasks\6-I-drive - Chkdsk.job
- c:\windows\system32\chkdsk.exe [2002-09-03 19:34]
2010-07-16 c:\windows\Tasks\7-Defrag C drive.job
- c:\windows\system32\defrag.exe [2002-09-03 00:12]
2010-07-16 c:\windows\Tasks\8-Defrag G drive.job
- c:\windows\system32\defrag.exe [2002-09-03 00:12]
2010-07-16 c:\windows\Tasks\9-Defrag I drive.job
- c:\windows\system32\defrag.exe [2002-09-03 00:12]
2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
2010-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-19 17:05]
2010-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-19 17:05]
2010-08-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-790525478-725345543-1004Core.job
- c:\documents and settings\Coach\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 14:32]
2010-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-790525478-725345543-1004UA.job
- c:\documents and settings\Coach\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 14:32]
2010-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-790525478-725345543-1005Core.job
- c:\documents and settings\Mom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-22 20:43]
2010-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-790525478-725345543-1005UA.job
- c:\documents and settings\Mom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-22 20:43]
2010-09-01 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-10-23 21:58]
2010-08-24 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-23 21:58]
2010-09-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-682003330-790525478-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
2010-08-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-682003330-790525478-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
2010-09-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-682003330-790525478-725345543-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
2010-09-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-682003330-790525478-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
2010-09-02 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-682003330-790525478-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
2010-09-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-682003330-790525478-725345543-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\Coach\Application Data\Mozilla\Firefox\Profiles\6av5imng.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.type - 4
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-03 10:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
@DACL=(02 0010)
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@DACL=(02 0010)
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(788)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1980)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\SoftwareDistribution\Download\ff678be2eb092eccce792bf844fea6ab\update\update.exe
.
**************************************************************************
.
Completion time: 2010-09-03 10:59:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-03 17:58
ComboFix2.txt 2010-08-24 19:15
Pre-Run: 37,879,640,064 bytes free
Post-Run: 37,597,052,928 bytes free
- - End Of File - - 5648EB844B6688E089F05D26F43C8FD6