Re:
hi katana... i did everything u asked me to do,,, from the logs of the Kasoersky... i see no malware.:laugh:
Here is the Combofix log:
ComboFix 09-05-22.05 - Ansar 23/05/2009 20:56.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1978.1145 [GMT -4:00]
Running from: c:\users\Ansar\Desktop\ComboFix.exe
Command switches used :: c:\users\Ansar\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
c:\users\ansar\desktop\programs\utorrent.exe
c:\windows\nod32fixtemdono.reg
c:\windows\nod32restoretemdono.reg
.
PEV Error: LocalSettingsFile
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\bittorrent
c:\program files\bittorrent\bittorrent.exe
c:\program files\bittorrent\BitTorrentIE.2.dll
c:\program files\bittorrent\uninst.exe
c:\program files\limewire
c:\program files\limewire\lib\aopalliance.jar
c:\program files\limewire\lib\clink.jar
c:\program files\limewire\lib\commons-codec-1.3.jar
c:\program files\limewire\lib\commons-logging.jar
c:\program files\limewire\lib\commons-net.jar
c:\program files\limewire\lib\daap.jar
c:\program files\limewire\lib\forms.jar
c:\program files\limewire\lib\foxtrot.jar
c:\program files\limewire\lib\gettext-commons.jar
c:\program files\limewire\lib\guice-1.0.jar
c:\program files\limewire\lib\httpclient-4.0-alpha3.jar
c:\program files\limewire\lib\httpcore-4.0-beta2.jar
c:\program files\limewire\lib\httpcore-nio-4.0-beta2.jar
c:\program files\limewire\lib\httpcore-niossl-4.0-alpha7.jar
c:\program files\limewire\lib\icu4j.jar
c:\program files\limewire\lib\jaudiotagger.jar
c:\program files\limewire\lib\jcraft.jar
c:\program files\limewire\lib\jdic.dll
c:\program files\limewire\lib\jdic.jar
c:\program files\limewire\lib\jdic_stub.jar
c:\program files\limewire\lib\jflac.jar
c:\program files\limewire\lib\jl.jar
c:\program files\limewire\lib\jmdns.jar
c:\program files\limewire\lib\jogg.jar
c:\program files\limewire\lib\jorbis.jar
c:\program files\limewire\lib\LimeWire.jar
c:\program files\limewire\lib\log4j.jar
c:\program files\limewire\lib\looks.jar
c:\program files\limewire\lib\messages.jar
c:\program files\limewire\lib\mp3spi.jar
c:\program files\limewire\lib\onion-common.jar
c:\program files\limewire\lib\onion-fec.jar
c:\program files\limewire\lib\ProgressTabs.jar
c:\program files\limewire\lib\swt.jar
c:\program files\limewire\lib\SystemUtilities.dll
c:\program files\limewire\lib\themes.jar
c:\program files\limewire\lib\tray.dll
c:\program files\limewire\lib\tritonus.jar
c:\program files\limewire\lib\vorbisspi.jar
c:\program files\limewire\LimeWire.exe
c:\users\Ansar\AppData\Roaming\LimeWire
c:\users\Ansar\AppData\Roaming\LimeWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\alerts.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\caps.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\chardet.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\chrome.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\composer.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_html.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\cookie.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\directory.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\downloads.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\editor.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\extensions.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\feeds.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\find.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\gfx.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\inspector.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\intl.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\jar.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\locale.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\oji.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\places.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\plugin.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\pref.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\profile.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\rdf.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\satchel.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\shistory.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\storage.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\uconv.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\update.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\widget.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\windowds.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\xulutil.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.ini
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\dependentlibs.list
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.chk
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\all.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcom.jar
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\js3250.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\LICENSE
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\debug.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\Microformats.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\utils.js
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\mozctl.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\mozctlx.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\msvcr71.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\nspr4.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\nss3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\nssckbi.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\nssdbm3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\nssutil3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\platform.ini
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\plc4.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\plds4.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\README.txt
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\arrow.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\arrowd.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\broken-image.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetData.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\contenteditable.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\designmode.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\forms.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\grabber.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\html.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\html\folder.png
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\langGroups.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\language.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\loading-image.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\mathml.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\quirk.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\svg.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\ua.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\viewsource.css
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\res\wincharset.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\smime3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.chk
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\sqlite3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\ssl3.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\updater.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\version.properties
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpcom.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpcshell.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpicleanup.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpidl.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpt_dump.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xpt_link.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xul.dll
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\users\Ansar\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner.exe
c:\users\Ansar\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\Ansar\AppData\Roaming\LimeWire\createtimes.cache
c:\users\Ansar\AppData\Roaming\LimeWire\downloads.dat
c:\users\Ansar\AppData\Roaming\LimeWire\fileurns.bak
c:\users\Ansar\AppData\Roaming\LimeWire\fileurns.cache
c:\users\Ansar\AppData\Roaming\LimeWire\filters.props
c:\users\Ansar\AppData\Roaming\LimeWire\gnutella.net
c:\users\Ansar\AppData\Roaming\LimeWire\installation.props
c:\users\Ansar\AppData\Roaming\LimeWire\library.dat
c:\users\Ansar\AppData\Roaming\LimeWire\library5.dat
c:\users\Ansar\AppData\Roaming\LimeWire\limewire.props
c:\users\Ansar\AppData\Roaming\LimeWire\mojito.props
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\.autoreg
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\98E79480d01
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\AE98BDF8d01
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\BAFF9A98d01
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\Cache\E746DCC7d01
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\cert8.db
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\compreg.dat
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\cookies.sqlite
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\downloads.sqlite
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\extensions.cache
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\extensions.ini
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\history.dat
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\key3.db
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\permissions.sqlite
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite-journal
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\pluginreg.dat
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\prefs.js
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\secmod.db
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\XPC.mfl
c:\users\Ansar\AppData\Roaming\LimeWire\mozilla-profile\xpti.dat
c:\users\Ansar\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\Ansar\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\Ansar\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\Ansar\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\Ansar\AppData\Roaming\LimeWire\questions.props
c:\users\Ansar\AppData\Roaming\LimeWire\responses.cache
c:\users\Ansar\AppData\Roaming\LimeWire\simpp.xml
c:\users\Ansar\AppData\Roaming\LimeWire\spam.dat
c:\users\Ansar\AppData\Roaming\LimeWire\tables.props
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme.lwtp
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\
01_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\
02_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\
03_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\
04_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\
05_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\chat.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\dir_closed.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\dir_open.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\forward_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\forward_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\kill.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\kill_on.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\lime.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\lw_logo.png
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\pause_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\pause_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\play_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\play_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\question.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\rewind_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\rewind_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\stop_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\stop_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\theme.txt
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\version.txt
c:\users\Ansar\AppData\Roaming\LimeWire\themes\limewirePro_theme\warning.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme.lwtp
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\
01_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\
02_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\
03_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\
04_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\
05_star.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\chat.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\forward_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\forward_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\kill.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\kill_on.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\logo.png
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\notsearching.png
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\pause_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\pause_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\play_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\play_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\question.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\rewind_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\rewind_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\searching.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\stop_dn.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\stop_up.gif
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\theme.txt
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\version.txt
c:\users\Ansar\AppData\Roaming\LimeWire\themes\windows_theme\warning.gif
c:\users\Ansar\AppData\Roaming\LimeWire\ttrees.cache
c:\users\Ansar\AppData\Roaming\LimeWire\ttroot.cache
c:\users\Ansar\AppData\Roaming\LimeWire\version.xml
c:\users\Ansar\AppData\Roaming\LimeWire\versions.props
c:\users\Ansar\AppData\Roaming\LimeWire\xml\data\audio.sxml2
c:\users\Ansar\AppData\Roaming\LimeWire\xml\data\audio.sxml3
c:\users\Ansar\AppData\Roaming\LimeWire\xml\data\image.sxml2
c:\users\Ansar\AppData\Roaming\LimeWire\xml\data\video.sxml2
c:\users\Ansar\AppData\Roaming\uTorrent
c:\users\Ansar\AppData\Roaming\uTorrent\Behemoth - At the Left Hand Ov God.avi.torrent
c:\users\Ansar\AppData\Roaming\uTorrent\dht.dat
c:\users\Ansar\AppData\Roaming\uTorrent\dht.dat.old
c:\users\Ansar\AppData\Roaming\uTorrent\Nickleback - dark horse(split tracks+covers).torrent
c:\users\Ansar\AppData\Roaming\uTorrent\resume.dat
c:\users\Ansar\AppData\Roaming\uTorrent\resume.dat.old
c:\users\Ansar\AppData\Roaming\uTorrent\rss.dat
c:\users\Ansar\AppData\Roaming\uTorrent\rss.dat.old
c:\users\Ansar\AppData\Roaming\uTorrent\settings.dat
c:\users\Ansar\AppData\Roaming\uTorrent\settings.dat.old
c:\windows\nod32fixtemdono.reg
c:\windows\nod32restoretemdono.reg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NOD32FiXTemDono
((((((((((((((((((((((((( Files Created from 2009-04-24 to 2009-05-24 )))))))))))))))))))))))))))))))
.
2009-05-23 01:08 . 2009-05-24 01:03 -------- d-----w c:\users\Ansar\AppData\Local\temp
2009-05-22 21:41 . 2009-05-22 21:41 -------- d-----w c:\users\Ansar\AppData\Roaming\Malwarebytes
2009-05-22 21:41 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-22 21:41 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-22 21:41 . 2009-05-22 21:41 -------- d-----w c:\programdata\Malwarebytes
2009-05-22 21:41 . 2009-05-22 21:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-22 21:35 . 2009-05-22 21:36 -------- d-----w C:\USBNoRisk
2009-05-21 23:21 . 2009-05-21 23:21 -------- d-----w C:\rsit
2009-05-21 17:22 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{14060FFD-C1F0-44A2-8F4A-7CF63395EAE2}\mpengine.dll
2009-05-21 04:04 . 2009-05-21 04:09 -------- d-----w C:\Lyrics
2009-05-21 02:51 . 2009-05-21 02:51 -------- d-----w c:\program files\Trend Micro
2009-05-20 01:44 . 2009-05-20 01:44 -------- d-----w c:\programdata\WindowsSearch
2009-05-20 01:21 . 2009-05-20 02:08 305184 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-19 23:58 . 2009-05-20 02:18 -------- d-----w c:\program files\Common Files\ParetoLogic
2009-05-19 23:57 . 2009-05-19 23:57 -------- d-----w c:\users\Ansar\AppData\Local\Downloaded Installations
2009-05-19 22:04 . 2009-05-19 22:04 -------- d-----w c:\programdata\SUPERAntiSpyware.com
2009-05-19 22:03 . 2009-05-19 23:55 -------- d-----w c:\users\Ansar\AppData\Roaming\SUPERAntiSpyware.com
2009-05-19 22:03 . 2009-05-19 23:55 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-19 01:49 . 2009-05-19 01:49 -------- d-----w c:\users\Ansar\{7b895694-a5cb-41d6-8eae-526bb9925d01}
2009-05-14 23:46 . 2009-05-14 23:46 -------- d-----w c:\users\Ansar\AppData\Local\BVRP Software
2009-05-14 23:46 . 2009-05-19 01:50 -------- d-----w c:\program files\Avanquest update
2009-05-14 23:44 . 2009-05-19 01:59 -------- d-----w c:\program files\Motorola Phone Tools
2009-05-14 23:42 . 2009-05-14 23:42 -------- d-----w c:\users\Ansar\AppData\Roaming\InstallShield
2009-05-09 01:21 . 2009-05-09 01:21 -------- d-----w c:\program files\Ubisoft
2009-05-09 00:26 . 2009-05-09 00:26 -------- d-----w c:\users\Ansar\AppData\Roaming\Leadertech
2009-05-09 00:04 . 2005-05-26 19:34 2297552 ----a-w c:\windows\system32\d3dx9_26.dll
2009-05-05 19:40 . 2009-05-05 19:40 -------- d-----w C:\divx
2009-05-04 19:31 . 2009-05-04 19:32 -------- d-----w c:\program files\PowerISO
2009-05-04 19:29 . 2009-05-04 19:29 -------- d-----w c:\programdata\DAEMON Tools Pro
2009-05-04 19:26 . 2009-05-04 19:26 721904 ----a-w c:\windows\system32\drivers\sptd.sys
2009-05-04 19:26 . 2009-05-04 19:26 -------- d-----w c:\users\Ansar\AppData\Roaming\DAEMON Tools Pro
2009-05-03 20:49 . 2009-05-03 20:49 -------- d-----w c:\users\Ansar\AppData\Local\ESET
2009-05-03 19:19 . 2009-05-03 19:19 -------- d-----w c:\program files\ESET
2009-05-03 12:09 . 2009-05-03 18:46 -------- d-----w c:\users\Ansar\AppData\Roaming\DivX
2009-05-03 00:03 . 2009-05-03 00:03 -------- d-----w c:\users\Ansar\AppData\Local\ABBYY
2009-05-02 22:48 . 2009-05-02 22:48 -------- d-----w c:\program files\Common Files\PX Storage Engine
2009-05-02 22:47 . 2009-05-02 22:51 -------- d-----w c:\program files\Common Files\DivX Shared
2009-05-02 22:47 . 2009-05-02 22:52 -------- d-----w c:\program files\DivX
2009-04-27 01:31 . 2009-04-27 01:31 2560 ----a-w c:\windows\_MSRSTRT.EXE
2009-04-26 05:19 . 2006-12-11 21:12 176235 ----a-w c:\windows\system32\Primomonnt.dll
2009-04-26 05:19 . 2009-04-26 05:19 -------- d-----w c:\windows\PrimoPDF4
2009-04-26 04:54 . 2009-05-03 14:46 -------- d-----w c:\users\Ansar\AppData\Local\CutePDF Writer
2009-04-26 04:51 . 2009-04-26 04:51 -------- d-----w c:\program files\GPLGS
2009-04-26 04:50 . 2007-07-13 02:33 87552 ----a-w c:\windows\system32\cpwmon2k.dll
2009-04-26 04:50 . 2009-04-26 04:50 -------- d-----w c:\program files\Acro Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 00:43 . 2009-03-06 11:16 -------- d-----w c:\programdata\Spybot - Search & Destroy
2009-05-23 22:19 . 2009-04-18 03:11 -------- d-----w c:\programdata\Google Updater
2009-05-23 04:28 . 2009-03-06 11:16 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-20 02:08 . 2009-05-20 01:21 5696 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-18 22:41 . 2008-12-07 23:52 -------- d-----w c:\program files\Google
2009-05-14 23:46 . 2009-01-05 02:54 -------- d-----w c:\programdata\BVRP Software
2009-05-14 23:46 . 2008-07-26 05:06 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-13 19:32 . 2008-07-26 06:12 -------- d-----w c:\programdata\Microsoft Help
2009-05-13 18:58 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-12 17:05 . 2008-12-07 03:34 106952 ----a-w c:\users\Ansar\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-10 18:08 . 2009-05-10 18:08 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-04-27 01:31 . 2009-03-27 07:01 -------- d-----w c:\programdata\SpeedBit
2009-04-18 01:24 . 2009-01-11 04:03 680 ----a-w c:\users\Ansar\AppData\Local\d3d9caps.dat
2009-04-17 06:11 . 2008-08-30 00:17 -------- d-----w c:\program files\Atheros
2009-04-17 05:56 . 2009-04-17 05:56 -------- d-----w c:\users\Ansar\AppData\Roaming\SuperAdBlocker.com
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w c:\windows\system32\DivX.dll
2009-04-12 02:58 . 2009-04-11 05:31 -------- d-----w c:\program files\AlcoDens
2009-04-10 02:17 . 2009-04-10 02:01 -------- d-----w c:\users\Ansar\AppData\Roaming\DMCache
2009-04-10 01:34 . 2008-07-26 06:36 -------- d-----w c:\program files\Java
2009-03-31 18:35 . 2009-05-10 02:23 17160 ----a-w c:\windows\Help\OEM\scripts\HC_TotalCareAdvisorUpdate.exe
2009-03-30 20:30 . 2009-05-10 02:23 17160 ----a-w c:\windows\Help\OEM\scripts\HC_DanzkaDubraBIOSUpdate.exe
2009-03-17 03:38 . 2009-04-15 04:20 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 04:20 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-15 10:25 . 2009-03-15 10:25 56268 ----a-w c:\windows\system32\drivers\scdemu.sys
2009-03-09 09:19 . 2009-03-14 16:09 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-09 03:02 . 2009-02-20 02:11 576 ----a-w c:\users\Ansar\AppData\Roaming\wklnhst.dat
2009-03-08 11:34 . 2009-03-20 00:54 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-03-20 00:54 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-03-20 00:54 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-03-20 00:54 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-03-20 00:54 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-03-20 00:54 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-03-20 00:54 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-03-20 00:54 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-03-20 00:54 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-03-20 00:54 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-03-20 00:54 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-03-20 00:54 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-03-20 00:54 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-03-20 00:54 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-03-20 00:54 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-03-20 00:54 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-03-20 00:54 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-03-20 00:54 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 21:12 . 2008-04-16 21:25 21256 ----a-w c:\windows\Help\OEM\scripts\HPScript.exe
2009-03-06 13:06 . 2009-03-06 13:06 140800 ----a-w c:\windows\system32\drivers\Rtlh86.sys
2009-03-05 16:29 . 2009-04-12 02:28 16648 ----a-w c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-03-05 10:54 . 2009-03-05 10:54 73728 ----a-w c:\windows\system32\RtNicProp32.dll
2009-03-03 04:46 . 2009-04-15 04:20 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 04:20 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 04:20 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 04:20 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 04:20 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 04:20 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 04:20 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 04:20 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 04:20 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 04:20 17408 ----a-w c:\windows\system32\iashost.exe
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-07-26 03:45 . 2008-07-26 03:45 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-05-23_01.04.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-05-24 00:47 61858 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-12-07 03:28 . 2009-05-24 01:05 16236 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1876926021-3462019510-1632751971-1000_UserData.bin
- 2008-12-07 03:23 . 2009-05-22 21:18 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-07 03:23 . 2009-05-23 22:19 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-07 03:23 . 2009-05-23 22:19 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-07 03:23 . 2009-05-22 21:18 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-07 03:23 . 2009-05-23 22:19 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-07 03:23 . 2009-05-22 21:18 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-23 03:53 . 2009-05-23 03:53 9560 c:\windows\System32\networklist\icons\{DC1A1E82-987F-49BE-9F5F-6C2E42E5400A}_48.bin
+ 2009-05-23 03:53 . 2009-05-23 03:53 4280 c:\windows\System32\networklist\icons\{DC1A1E82-987F-49BE-9F5F-6C2E42E5400A}_32.bin
+ 2009-05-23 03:53 . 2009-05-23 03:53 2456 c:\windows\System32\networklist\icons\{DC1A1E82-987F-49BE-9F5F-6C2E42E5400A}_24.bin
- 2009-05-23 00:41 . 2009-05-23 00:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-05-24 01:03 . 2009-05-24 01:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-23 00:41 . 2009-05-23 00:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-24 01:03 . 2009-05-24 01:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 13:02 . 2009-05-24 01:05 102218 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-17 145944]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-05-12 202032]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-18 185872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
c:\users\Ansar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-3-22 3450608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C8F554C7-B099-4399-813F-8A2B38A79F77}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{926F2246-DC26-4C54-B7A0-2536A5EFCC6F}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{8F12F9D3-7DCC-4A3E-A382-4908065B56FE}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3C8C8D18-6DF0-4C2D-9BCE-92F812D8F724}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{880AA6DE-1C3E-499E-BE84-F1158C0E778B}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{87694E78-9EB3-4CB9-8E88-7F074201024C}"= UDP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"{A0D24EB6-88FA-44A2-9070-2C5E8561C571}"= TCP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"TCP Query User{9F8F522E-F744-4DA0-82A7-357431FEFE2C}c:\\users\\ansar\\desktop\\warcraft iii\\warcraft iii\\war3.exe"= UDP:c:\users\ansar\desktop\warcraft iii\warcraft iii\war3.exe:war3.exe
"UDP Query User{C520C188-7412-4479-A39A-448045019040}c:\\users\\ansar\\desktop\\warcraft iii\\warcraft iii\\war3.exe"= TCP:c:\users\ansar\desktop\warcraft iii\warcraft iii\war3.exe:war3.exe
"{D4FA4BD8-A4E1-4958-B2BC-290E69633B95}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{89382D21-35EA-4F7D-8314-099FA7465973}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{6B55DE91-EF4B-4F37-8A20-EA69C44276B8}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"TCP Query User{C6B1AE5E-0F32-4E51-8195-86EC73C6736B}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe

2P service of Orbit Downloader
"UDP Query User{95AC2981-A5C0-46B3-960D-196819B918E1}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe

2P service of Orbit Downloader
"TCP Query User{E9E21F8E-605E-48F5-A0DA-8579CA2D297E}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{B6DB4579-5A6A-4FC2-956C-4AA6CE8137C9}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{6D0993DC-DD61-4890-9808-BEB550300D3C}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{54D0F3D7-27CA-4CEC-A1C5-B6A59E2F8916}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{E668AD22-749F-42CF-AA14-CC405485CEB0}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{DB70A845-A7E3-429C-B1D1-78C423E4AD0F}"= UDP:c:\program files\Windows Live\Messenger\msnmsgr.exe:Windows Live Messenger
"{A996D883-D014-45B1-930B-BFDD9BCD3943}"= TCP:c:\program files\Windows Live\Messenger\msnmsgr.exe:Windows Live Messenger
"{23E65CDD-0A74-41F4-8E1A-7DB0AE241D72}"= UDP:c:\program files\Ubisoft\Prince of Persia\Prince of Persia.exe

rince of Persia Dx
"{24BF3C7F-30C1-421C-911E-C46AAF704EF1}"= TCP:c:\program files\Ubisoft\Prince of Persia\Prince of Persia.exe

rince of Persia Dx
"{61F10E4D-E4A9-40C5-A3C0-3BA8FDBFD9E4}"= UDP:c:\program files\Ubisoft\Prince of Persia\PrinceOfPersia_Launcher.exe

rince of Persia Update
"{9C693193-662A-426C-8C09-96DCC6FA0FA8}"= TCP:c:\program files\Ubisoft\Prince of Persia\PrinceOfPersia_Launcher.exe

rince of Persia Update
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [20/02/2008 11:11 AM 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [20/02/2008 11:08 AM 472320]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [26/07/2008 02:31 AM 361808]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [06/03/2009 07:16 AM 1153368]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [26/07/2008 01:31 AM 193840]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [04/06/2008 01:54 PM 113664]
S2 gupdate1c9bfd3b32d50b1;Google Update Service (gupdate1c9bfd3b32d50b1);c:\program files\Google\Update\GoogleUpdate.exe [17/04/2009 11:13 PM 133104]
S3 mamotou;mamotou;c:\windows\System32\drivers\mamotou.sys [08/12/2008 09:01 PM 49377]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\w300mgmt.sys [11/12/2008 01:11 AM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\System32\drivers\w300obex.sys [11/12/2008 01:10 AM 85696]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2009-05-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-07 03:11]
2009-05-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 03:13]
2009-05-24 c:\windows\Tasks\User_Feed_Synchronization-{F8C11240-9989-415C-875C-C0D6EEC1AAD5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-20 11:31]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_tt&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyServer = 192.168.224.5:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ansar\AppData\Roaming\Mozilla\Firefox\Profiles\wk9qt557.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-23 21:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\users\Ansar\AppData\Roaming\Microsoft\Windows\Cookies\ansar@c.live[1].txt 63 bytes
c:\users\Ansar\AppData\Roaming\Microsoft\Windows\Cookies\ansar@live[2].txt
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5160)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\wlanext.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Internet Explorer\ielowutil.exe
.
**************************************************************************
.
Completion time: 2009-05-24 21:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-24 01:09
ComboFix2.txt 2009-05-23 01:07
Pre-Run: 32,579,125,248 bytes free
Post-Run: 32,319,270,912 bytes free
781 --- E O F --- 2009-05-21 17:22
And this is the Kaspersky log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, May 24, 2009
Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, May 24, 2009 02:52:28
Records in database: 2229912
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Files scanned: 187596
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 02:21:29
No malware has been detected. The scan area is clean.
The selected area was scanned.
thank you once again for your time. :thanks: