ComboFix Log:
ComboFix 09-02-21.01 - Justin 2009-02-22 14:02:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.522 [GMT -8:00]
Running from: c:\documents and settings\Justin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Justin\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\derudefe.dll
c:\windows\system32\drivers\qpohioms.sys
c:\windows\system32\gusilaji.dll
c:\windows\system32\heripihe.dll
c:\windows\system32\higawaka.dll
c:\windows\system32\hovivowe.dll
c:\windows\system32\jigefuwi.dll
c:\windows\system32\jobaruse.dll
c:\windows\system32\kofedasa.dll
c:\windows\system32\lavisuko.dll
c:\windows\system32\lebobofu.dll
c:\windows\system32\lofuwogi.dll
c:\windows\system32\lozisoke.dll
c:\windows\system32\luvokiya.dll
c:\windows\system32\masekaba.dll
c:\windows\system32\medesewo.dll
c:\windows\system32\misehula.dll
c:\windows\system32\mumawodu.dll
c:\windows\system32\nezapivu.dll
c:\windows\system32\nihigilo.dll
c:\windows\system32\sajekeye.dll
c:\windows\system32\satuzavo.dll
c:\windows\system32\tekunigo.dll
c:\windows\system32\tituzeki.dll
c:\windows\system32\wayapego.dll
c:\windows\system32\wuhahate.dll
c:\windows\system32\wuyedawa.dll
c:\windows\system32\yibisusi.dll
c:\windows\system32\yopuduku.dll
c:\windows\system32\yunevija.dll
c:\windows\system32\zumihade.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\~0
c:\documents and settings\All Users.WINDOWS\Application Data\~0\mia.lib
c:\documents and settings\All Users.WINDOWS\Application Data\~0\Uniblue RegistryBooster.exe
c:\documents and settings\Justin\Application Data\FrostWire
c:\documents and settings\Justin\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\documents and settings\Justin\Application Data\FrostWire\checkandupdate.txt
c:\documents and settings\Justin\Application Data\FrostWire\createtimes.cache
c:\documents and settings\Justin\Application Data\FrostWire\downloads.dat
c:\documents and settings\Justin\Application Data\FrostWire\fileurns.bak
c:\documents and settings\Justin\Application Data\FrostWire\fileurns.cache
c:\documents and settings\Justin\Application Data\FrostWire\filters.props
c:\documents and settings\Justin\Application Data\FrostWire\frostwire.props
c:\documents and settings\Justin\Application Data\FrostWire\gnutella.net
c:\documents and settings\Justin\Application Data\FrostWire\installation.props
c:\documents and settings\Justin\Application Data\FrostWire\intent.props
c:\documents and settings\Justin\Application Data\FrostWire\library.dat
c:\documents and settings\Justin\Application Data\FrostWire\mojito.props
c:\documents and settings\Justin\Application Data\FrostWire\questions.props
c:\documents and settings\Justin\Application Data\FrostWire\responses.cache
c:\documents and settings\Justin\Application Data\FrostWire\simpp.xml
c:\documents and settings\Justin\Application Data\FrostWire\spam.dat
c:\documents and settings\Justin\Application Data\FrostWire\tables.props
c:\documents and settings\Justin\Application Data\FrostWire\themes\frostwirePro_theme.fwtp
c:\documents and settings\Justin\Application Data\FrostWire\themes\frostwirePro_theme\theme.txt
c:\documents and settings\Justin\Application Data\FrostWire\themes\frostwirePro_theme\version.txt
c:\documents and settings\Justin\Application Data\FrostWire\ttrees.cache
c:\documents and settings\Justin\Application Data\FrostWire\ttroot.cache
c:\documents and settings\Justin\Application Data\FrostWire\version.xml
c:\documents and settings\Justin\Application Data\FrostWire\xml\data\audio.sxml2
c:\documents and settings\Justin\Application Data\LimeWire
c:\documents and settings\Justin\Application Data\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\branding.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\classic.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\comm.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\alerts.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\appshell.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\auth.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\caps.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\chardet.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\chrome.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\composer.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_html.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\cookie.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\directory.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\downloads.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\editor.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\extensions.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\feeds.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\find.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\gfx.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\inspector.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\intl.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\jar.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\locale.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\oji.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pippki.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\places.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\plugin.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\pref.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\profile.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\rdf.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\satchel.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\shistory.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\storage.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\transformiix.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\uconv.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\update.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\widget.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\windowds.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\xulutil.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\crashreporter.ini
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\dependentlibs.list
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\freebl3.chk
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\freebl3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\greprefs\all.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\javaxpcom.jar
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\js3250.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\LICENSE
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\debug.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\Microformats.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\utils.js
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\mozctl.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\mozctlx.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\nspr4.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\nss3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\nssckbi.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\nssutil3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\platform.ini
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\plc4.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\plds4.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\README.txt
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\arrow.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\arrowd.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\broken-image.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\charsetData.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\contenteditable.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\designmode.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\forms.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\grabber.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\html.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\html\folder.png
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\langGroups.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\language.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\loading-image.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\mathml.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\quirk.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\svg.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\ua.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\viewsource.css
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\res\wincharset.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\smime3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\softokn3.chk
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\softokn3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\sqlite3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\ssl3.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\updater.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\version.properties
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpcom.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpidl.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xul.dll
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
c:\documents and settings\Justin\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Justin\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Justin\Application Data\LimeWire\downloads.dat
c:\documents and settings\Justin\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Justin\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Justin\Application Data\LimeWire\filters.props
c:\documents and settings\Justin\Application Data\LimeWire\gnutella.net
c:\documents and settings\Justin\Application Data\LimeWire\installation.props
c:\documents and settings\Justin\Application Data\LimeWire\library.dat
c:\documents and settings\Justin\Application Data\LimeWire\library5.dat
c:\documents and settings\Justin\Application Data\LimeWire\limewire.props
c:\documents and settings\Justin\Application Data\LimeWire\mojito.props
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\.autoreg
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\489D2361d01
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\51CFDFBBd01
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\6A326B34d01
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\Cache\98E79480d01
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\cert8.db
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\compreg.dat
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\cookies.sqlite
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\downloads.sqlite
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\extensions.cache
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\extensions.ini
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\history.dat
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\key3.db
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\permissions.sqlite
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\places.sqlite
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\pluginreg.dat
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\prefs.js
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\secmod.db
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\XPC.mfl
c:\documents and settings\Justin\Application Data\LimeWire\mozilla-profile\xpti.dat
c:\documents and settings\Justin\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Justin\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Justin\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Justin\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Justin\Application Data\LimeWire\questions.props
c:\documents and settings\Justin\Application Data\LimeWire\responses.cache
c:\documents and settings\Justin\Application Data\LimeWire\simpp.xml
c:\documents and settings\Justin\Application Data\LimeWire\spam.dat
c:\documents and settings\Justin\Application Data\LimeWire\tables.props
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Justin\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Justin\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Justin\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Justin\Application Data\LimeWire\version.xml
c:\documents and settings\Justin\Application Data\LimeWire\versions.props
c:\documents and settings\Justin\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Justin\Application Data\LimeWire\xml\data\audio.sxml3
c:\documents and settings\Justin\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Justin\Application Data\LimeWire\xml\data\video.sxml3
c:\program files\Enigma Software Group
C:\VundoFix Backups
c:\windows\system32\derudefe.dll
c:\windows\system32\gusilaji.dll
c:\windows\system32\heripihe.dll
c:\windows\system32\higawaka.dll
c:\windows\system32\hovivowe.dll
c:\windows\system32\jigefuwi.dll
c:\windows\system32\jobaruse.dll
c:\windows\system32\kofedasa.dll
c:\windows\system32\lavisuko.dll
c:\windows\system32\lebobofu.dll
c:\windows\system32\lofuwogi.dll
c:\windows\system32\lozisoke.dll
c:\windows\system32\luvokiya.dll
c:\windows\system32\masekaba.dll
c:\windows\system32\medesewo.dll
c:\windows\system32\misehula.dll
c:\windows\system32\mumawodu.dll
c:\windows\system32\nezapivu.dll
c:\windows\system32\nihigilo.dll
c:\windows\system32\sajekeye.dll
c:\windows\system32\satuzavo.dll
c:\windows\system32\tekunigo.dll
c:\windows\system32\tituzeki.dll
c:\windows\system32\wayapego.dll
c:\windows\system32\wuhahate.dll
c:\windows\system32\wuyedawa.dll
c:\windows\system32\yibisusi.dll
c:\windows\system32\yopuduku.dll
c:\windows\system32\yunevija.dll
c:\windows\system32\zumihade.dll
c:\windows\vxoqgiqn\
c:\windows\xapvsxni\
.
((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-22 14:00 . 2009-02-22 14:00 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-22 13:55 . 2009-02-22 13:55 196 --a------ c:\windows\system32\msexcr.ini
2009-02-20 23:39 . 2009-02-21 14:52 20 --a------ c:\windows\Settings.ini
2009-02-17 16:31 . 2009-02-17 16:31 <DIR> d-------- c:\documents and settings\Justin\Application Data\Auslogics
2009-02-17 16:30 . 2009-02-17 16:30 <DIR> d-------- c:\program files\Auslogics
2009-02-17 06:34 . 2009-02-17 06:34 <DIR> d--hs---- C:\found.006
2009-02-05 23:29 . 2009-02-05 23:29 <DIR> d--hs---- C:\found.005
2009-02-04 17:34 . 2009-02-04 17:34 <DIR> d-------- c:\documents and settings\Justin\Application Data\Uniblue
2009-02-03 19:22 . 2009-02-03 19:22 <DIR> d-------- c:\program files\Trend Micro
2009-02-03 15:36 . 2009-02-22 14:00 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-03 15:07 . 2009-02-03 15:07 0 --a------ c:\windows\system32\AAWService_2009_02_03_15_07_21.dmp
2009-02-02 18:22 . 2009-02-02 18:22 22,970 --a------ c:\windows\system32\AAWService_2009_02_02_18_22_29.dmp
2009-02-02 18:20 . 2009-02-02 18:08 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-02 18:08 . 2009-02-02 18:08 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-02 18:05 . 2009-02-02 18:08 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-02-02 18:05 . 2009-02-02 18:06 <DIR> d--h-c--- c:\documents and settings\All Users.WINDOWS\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-02 17:25 . 2009-02-02 17:25 <DIR> d-------- c:\program files\Kaspersky Lab
2009-02-02 17:25 . 2009-02-08 10:01 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2009-01-29 20:03 . 2009-02-03 15:07 4 --a------ c:\windows\xapvsxni
2009-01-24 15:10 . 2009-02-22 14:08 2,816 --a------ c:\windows\vxoqgiqn
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 22:00 --------- d-----w c:\program files\Java
2009-02-22 21:56 --------- d-----w c:\program files\Viewpoint
2009-02-22 21:56 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Viewpoint
2009-02-21 07:39 --------- d-----w c:\program files\BizarroTrainer
2009-02-16 19:16 --------- d-----w c:\documents and settings\Justin\Application Data\mIRC
2009-02-16 19:15 --------- d-----w c:\program files\mIRC
2009-02-07 15:56 --------- d-----w c:\program files\CCleaner
2009-02-03 02:05 --------- d-----w c:\program files\Lavasoft
2009-01-30 03:42 --------- d--h--w c:\documents and settings\Justin\Application Data\ijjigame
2009-01-10 04:08 --------- d-----w c:\program files\Pando Networks
2009-01-10 02:03 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\VMware
2009-01-09 14:41 --------- d-----w c:\documents and settings\LocalService.NT AUTHORITY\Application Data\VMware
2009-01-09 05:36 --------- d-----w c:\documents and settings\Justin\Application Data\VMware
2008-12-31 17:28 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-12-31 12:10 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-31 12:08 --------- d-----w c:\program files\7-Zip
2008-12-31 12:06 --------- d-----w c:\documents and settings\Justin\Application Data\Orbit
2008-12-25 03:51 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2008-12-24 22:00 --------- d-----w c:\documents and settings\Justin\Application Data\vlc
2008-12-24 16:51 --------- d-----w c:\program files\VideoLAN
2008-12-15 07:45 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-12-15 07:45 290,816 ------w c:\windows\Setup1.exe
2006-12-16 19:39 784 ----a-w c:\documents and settings\USER01\Application Data\mpauth.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-02-22_11.41.41.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 23:35:52 144,792 ----a-w c:\windows\system32\java.exe
+ 2009-02-22 22:00:19 144,792 ----a-w c:\windows\system32\java.exe
- 2009-02-03 23:35:52 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-02-22 22:00:19 144,792 ----a-w c:\windows\system32\javaw.exe
- 2009-02-03 23:35:52 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-02-22 22:00:19 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-02-22 22:09:20 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_7a8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-22 148888]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-02 64160]
R3 vkeyfdo;Virtual Keybord Function Driver;c:\windows\system32\drivers\vkeyfdo.sys [2008-10-02 11336]
S0 vxoqgiqn;vxoqgiqn;c:\windows\system32\drivers\qpohioms.sys []
S3 ROCKSTAR;ROCKSTAR;\??\c:\documents and settings\Justin\Desktop\Nooblegend\ksysdrv.sys --> c:\documents and settings\Justin\Desktop\Nooblegend\ksysdrv.sys [?]
S3 XDva202;XDva202;\??\c:\windows\system32\XDva202.sys --> c:\windows\system32\XDva202.sys [?]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
.
Contents of the 'Scheduled Tasks' folder
2008-12-23 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1222209292.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 16:56]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Justin\Application Data\Mozilla\Firefox\Profiles\jrvqk3jx.default\
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPJPI150_16.dll
FF - plugin: c:\program files\Java\jre1.5.0_16\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-22 14:09:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\qpohioms.sys 25088 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-527237240-839522115-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0C691A44-A542-3509-7EE2-B4B98962278A}*]
"hanlekgopnjhmedb"=hex:6a,61,68,61,6a,68,69,68,66,67,63,6f,6e,66,6b,69,63,6f,
6c,6d,00,00
"abhkkipmlpihnfihheoheoadalppbednin"=hex:61,61,00,00
"mamkhinfpmifnacijkflgikdho"=hex:61,61,00,00
"iadjkklgifdfhnpnbl"=hex:6a,61,68,61,6b,68,6c,69,6e,64,6e,69,6f,64,64,6d,66,6a,
64,6c,00,00
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-22 14:12:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-22 22:12:41
ComboFix2.txt 2009-02-22 19:42:31
Pre-Run: 5,831,442,432 bytes free
Post-Run: 5,811,089,408 bytes free
621
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:01:17 PM, on 2/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 1684 bytes