DDS logs attached
ComboFix Run #2
ComboFix 09-09-07.05 - Amy 09/08/2009 10:19.2.2 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.1918.1040 [GMT -4:00]
Running from: c:\users\Amy\Desktop\ComboFix.exe
Command switches used :: c:\users\Amy\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
FILE ::
"c:\windows\ge5ygeyu.rep"
"c:\windows\system32\rrrrrrrrrr"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Amy\AppData\Roaming\LimeWire
c:\users\Amy\AppData\Roaming\LimeWire\active.mojito
c:\users\Amy\AppData\Roaming\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\alerts.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\caps.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\chardet.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\chrome.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\composer.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_html.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\cookie.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\directory.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\downloads.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\editor.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\extensions.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\feeds.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\find.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\gfx.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\inspector.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\intl.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\jar.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\locale.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\oji.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\places.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\plugin.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\pref.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\profile.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\rdf.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\satchel.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\shistory.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\storage.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\uconv.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\update.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\widget.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\windowds.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\xulutil.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.ini
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\dependentlibs.list
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.chk
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\all.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcom.jar
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\js3250.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\LICENSE
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\debug.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\Microformats.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\utils.js
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\mozctl.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\mozctlx.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\msvcr71.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\nspr4.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\nss3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\nssckbi.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\nssdbm3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\nssutil3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\platform.ini
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\plc4.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\plds4.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\README.txt
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\arrow.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\arrowd.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\broken-image.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetData.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\contenteditable.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\designmode.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\forms.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\grabber.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\html.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\html\folder.png
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\langGroups.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\language.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\loading-image.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\mathml.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\quirk.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\svg.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\ua.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\viewsource.css
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\res\wincharset.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\smime3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.chk
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\sqlite3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\ssl3.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\updater.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\version.properties
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpcom.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpcshell.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpicleanup.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpidl.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpt_dump.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xpt_link.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xul.dll
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\users\Amy\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner.exe
c:\users\Amy\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\Amy\AppData\Roaming\LimeWire\createtimes.cache
c:\users\Amy\AppData\Roaming\LimeWire\downloads.dat
c:\users\Amy\AppData\Roaming\LimeWire\fileurns.cache
c:\users\Amy\AppData\Roaming\LimeWire\gnutella.net
c:\users\Amy\AppData\Roaming\LimeWire\installation.props
c:\users\Amy\AppData\Roaming\LimeWire\library.dat
c:\users\Amy\AppData\Roaming\LimeWire\library5.dat
c:\users\Amy\AppData\Roaming\LimeWire\limewire.props
c:\users\Amy\AppData\Roaming\LimeWire\lock
c:\users\Amy\AppData\Roaming\LimeWire\mojito.props
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\.autoreg
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\04DF0396d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\30B5DE57d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\4C4B6535d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\98E79480d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\AE98BDF5d01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\AE98BDFBd01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\BAFF9A8Ed01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\Cache\BAFF9A9Bd01
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\cert8.db
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\compreg.dat
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\cookies.sqlite
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\downloads.sqlite
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\extensions.cache
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\extensions.ini
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\history.dat
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\key3.db
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\permissions.sqlite
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite-journal
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\pluginreg.dat
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\prefs.js
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\secmod.db
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\XPC.mfl
c:\users\Amy\AppData\Roaming\LimeWire\mozilla-profile\xpti.dat
c:\users\Amy\AppData\Roaming\LimeWire\passive.mojito
c:\users\Amy\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\Amy\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\Amy\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\Amy\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\Amy\AppData\Roaming\LimeWire\questions.props
c:\users\Amy\AppData\Roaming\LimeWire\responses.cache
c:\users\Amy\AppData\Roaming\LimeWire\simpp.xml
c:\users\Amy\AppData\Roaming\LimeWire\spam.dat
c:\users\Amy\AppData\Roaming\LimeWire\tables.props
c:\users\Amy\AppData\Roaming\LimeWire\ttdata.cache
c:\users\Amy\AppData\Roaming\LimeWire\ttroot.cache
c:\users\Amy\AppData\Roaming\LimeWire\version.xml
c:\users\Amy\AppData\Roaming\LimeWire\versions.props
c:\users\Amy\AppData\Roaming\LimeWire\xml\data\audio.sxml3
c:\windows\ge5ygeyu.rep
c:\windows\system32\coredb
c:\windows\system32\coredb\storage
c:\windows\system32\rrrrrrrrrr
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-08-08 to 2009-09-08 )))))))))))))))))))))))))))))))
.
2009-09-03 11:55 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-03 11:55 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-01 19:11 . 2009-09-01 19:11 -------- d-----w- c:\program files\Trend Micro
2009-09-01 19:09 . 2009-09-08 12:40 -------- d-----w- c:\users\Guest
2009-09-01 19:09 . 2009-09-01 19:10 -------- d-----w- c:\program files\ERUNT
2009-08-31 13:45 . 2009-08-31 13:45 -------- d-----w- c:\program files\Microsoft Games
2009-08-31 13:22 . 2009-08-31 13:29 -------- d-----w- c:\windows\BDOSCAN8
2009-08-28 18:50 . 2009-08-28 18:50 -------- d-----w- c:\programdata\Applications
2009-08-28 12:57 . 2009-08-28 13:01 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-27 12:27 . 2009-08-28 14:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-27 12:27 . 2009-08-27 13:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-26 19:43 . 2009-08-26 19:43 -------- d-----w- c:\users\Amy\AppData\Roaming\Malwarebytes
2009-08-26 19:43 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-26 19:43 . 2009-08-26 19:43 -------- d-----w- c:\programdata\Malwarebytes
2009-08-26 19:43 . 2009-08-26 19:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 19:43 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-26 19:43 . 2009-08-26 19:43 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-08-26 19:41 . 2009-09-08 12:05 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-26 19:41 . 2009-08-26 19:41 -------- d-----w- c:\users\Amy\AppData\Roaming\SUPERAntiSpyware.com
2009-08-26 19:40 . 2009-08-26 19:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-26 18:58 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-26 18:58 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-26 18:58 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-26 18:58 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-26 18:58 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-26 18:58 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-26 18:58 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-26 18:57 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-26 16:01 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-24 12:11 . 2009-08-24 12:11 -------- d-----w- c:\program files\Common Files\Memeo
2009-08-24 12:11 . 2009-08-24 12:11 -------- d-----w- c:\program files\WD
2009-08-21 15:12 . 2009-08-21 15:12 -------- d-----w- c:\programdata\MemeoCommon
2009-08-21 15:11 . 2009-08-21 15:11 -------- d-----w- c:\users\Amy\AppData\Roaming\WD
2009-08-21 15:11 . 2009-08-21 15:11 -------- d-----w- c:\program files\Common Files\eSellerate
2009-08-21 14:56 . 2009-08-21 15:17 -------- d-----w- c:\users\Amy\AppData\Roaming\MioNet
2009-08-13 11:57 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-13 11:57 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-13 11:56 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-13 11:56 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-13 11:56 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-13 11:56 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-13 11:56 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-13 11:56 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 16:02 . 2008-06-23 19:10 -------- d-----w- c:\programdata\Microsoft Help
2009-09-01 14:27 . 2008-07-07 15:58 122152 ----a-w- c:\users\Amy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-31 12:10 . 2009-04-28 11:59 -------- d-----w- c:\programdata\Sonic
2009-08-28 17:29 . 2008-07-17 15:07 -------- d-----w- c:\program files\Windows Live
2009-08-13 16:01 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-22 14:28 . 2009-04-28 15:06 -------- d-----w- c:\users\Amy\AppData\Roaming\Roxio
2009-07-20 18:04 . 2008-08-05 17:20 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2009-07-20 18:04 . 2008-08-05 17:20 249856 ----a-w- c:\windows\system32\pdfmona.dll
2009-07-18 16:06 . 2009-07-29 12:07 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-29 12:07 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-29 12:07 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-08 12:02 . 2009-07-08 12:02 0 ----a-w- c:\windows\system32\cd.dat
2009-06-15 15:24 . 2009-07-15 12:06 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 12:06 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 12:06 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 12:06 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-08_12.36.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-09-08 12:38 47906 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:05 . 2009-09-08 12:02 73028 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-08 12:38 73028 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-23 18:39 . 2009-09-08 12:21 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-23 18:39 . 2009-09-08 14:17 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-23 18:39 . 2009-09-08 14:17 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-23 18:39 . 2009-09-08 12:21 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-23 18:39 . 2009-09-08 14:17 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-23 18:39 . 2009-09-08 12:21 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-07-09 14:56 . 2009-09-08 12:38 9686 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1467385788-3812229184-58112958-1001_UserData.bin
+ 2009-09-08 12:36 . 2009-09-08 12:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-08 12:36 . 2009-09-08 12:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-08 14:09 . 2009-09-08 14:09 802304 c:\windows\Installer\5464da.msi
+ 2009-09-08 14:09 . 2009-09-08 14:09 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-01-18 20:05 . 2009-01-18 20:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-09-08 14:07 . 2009-09-08 14:07 6653952 c:\windows\Installer\5464d3.msp
+ 2009-09-08 14:07 . 2009-09-08 14:07 1697792 c:\windows\Installer\5464d2.msp
+ 2008-12-18 20:48 . 2008-12-18 20:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2009-02-27 20:37 . 2009-02-27 20:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-08 1994480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-06-23 949376]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"WD Anywhere Backup"="c:\program files\WD\WD Anywhere Backup\MemeoLauncher2.exe" [2009-04-17 197856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-04-23 4435968]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-6-23 805392]
QuickBooks Pro 2009.lnk - c:\program files\Intuit\QuickBooks 2009\QBW32Pro.exe [2006-8-31 902672]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-5-20 967960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-08 12:05 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 03:34 24576 ----a-w- c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\beep.sys]
@="beep"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1467385788-3812229184-58112958-1000]
"EnableNotificationsRef"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1467385788-3812229184-58112958-1001]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{F5615212-4CE2-4081-9E72-7C7B86AC92E1}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{56D48439-7264-4005-86B6-5FCAC0BEDD39}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{4C636389-FEF5-498C-B676-0A5D7A4990E1}c:\\users\\amy\\desktop\\wowclient-downloader.exe"= UDP:c:\users\amy\desktop\wowclient-downloader.exe:wowclient-downloader.exe
"UDP Query User{AB23A2F7-AE84-4D96-B8F0-B3317739BF58}c:\\users\\amy\\desktop\\wowclient-downloader.exe"= TCP:c:\users\amy\desktop\wowclient-downloader.exe:wowclient-downloader.exe
"TCP Query User{E0A74B28-3C23-4426-8CB0-C1C53F8C2D5A}c:\\users\\amy\\appdata\\roaming\\macromedia\\flash player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"= UDP:c:\users\amy\appdata\roaming\macromedia\flash player\
www.macromedia.com\bin\octoshape\octoshape.exe:octoshape.exe
"UDP Query User{E3FDBBFA-AE06-4CE2-B6E0-C63639FAAFF6}c:\\users\\amy\\appdata\\roaming\\macromedia\\flash player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"= TCP:c:\users\amy\appdata\roaming\macromedia\flash player\
www.macromedia.com\bin\octoshape\octoshape.exe:octoshape.exe
"TCP Query User{B1396F88-8C71-4D60-8242-BECED4BA02D0}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{0673F0C2-B736-4525-A06A-EAD3E977E924}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{8AA96FEC-1016-4EE1-A3C2-79089752E6AF}c:\\program files\\crossloop\\crossloopconnect.exe"= UDP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"UDP Query User{32BC4947-DE91-44B0-B8E4-F22086698527}c:\\program files\\crossloop\\crossloopconnect.exe"= TCP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"{20FF1244-B175-44DA-9CCD-068C4EF28F38}"= UDP:c:\program files\Google\Google Talk\googletalk.exe:Google Talk
"{2E884277-F735-42D4-9732-0F7F21990936}"= TCP:c:\program files\Google\Google Talk\googletalk.exe:Google Talk
"TCP Query User{D95466C5-953B-46EC-B711-2FA828590B4B}c:\\program files\\mionet\\jvm\\bin\\mionet.exe"= UDP:c:\program files\mionet\jvm\bin\mionet.exe:Java(TM) Platform SE binary
"UDP Query User{FAFE4C21-F0D6-4C51-9B49-7A6A67E2F89C}c:\\program files\\mionet\\jvm\\bin\\mionet.exe"= TCP:c:\program files\mionet\jvm\bin\mionet.exe:Java(TM) Platform SE binary
"{8989836C-AB36-424B-9CBF-7DC826BF5C1F}"= UDP:1700:MioNet Remote Drive Access 0
"{0A1783EF-51D7-4AFF-A784-50CF4F62FB88}"= UDP:1701:MioNet Remote Drive Access 1
"{528B6578-37AF-44FB-B557-65810BAA2317}"= UDP:1702:MioNet Remote Drive Access 2
"{AE4C7CD4-C073-4CA1-8F4B-EEDFBEC4700A}"= UDP:1703:MioNet Remote Drive Access 3
"{86865F70-194A-4E69-BDE5-DAA6DED3B5FD}"= UDP:1704:MioNet Remote Drive Access 4
"{147741C0-4975-402A-B796-B9175FCC48AB}"= UDP:1705:MioNet Remote Drive Access 5
"{067586C0-CF40-4B66-9148-5E06963DFEAF}"= UDP:1706:MioNet Remote Drive Access 6
"{1FB36630-120A-49A7-A430-C5E0C977CD3A}"= UDP:1707:MioNet Remote Drive Access 7
"{E3185AE3-75AF-472C-AE03-79F910DA2119}"= UDP:1708:MioNet Remote Drive Access 8
"{1F3837CA-B821-4C09-9F79-F195632E1435}"= UDP:1709:MioNet Remote Drive Access 9
"{D2ECDCB5-EC93-4F19-AF02-878B6A37DFFC}"= UDP:1641:MioNet Remote Drive Verification
"{A02A9A4C-4CF1-414B-854B-54FBF6F992AF}"= UDP:1647:MioNet Storage Device Configuration
"{953382DE-7463-4F74-9B04-36554CA8F27D}"= TCP:5432:MioNet Storage Device Discovery
"{89CC239C-9E23-48FA-B30E-33C38016CD72}"= UDP:c:\program files\MioNet\MioNetManager.exe:MioNetManager
"{A71FE302-79AE-43F5-995F-49B4A14C0D1F}"= TCP:c:\program files\MioNet\MioNetManager.exe:MioNetManager
"{6183CD38-1205-4133-BB3D-336F5259EF40}"= UDP:c:\program files\MioNet\jvm\bin\MioNet.exe:MioNet
"{60AAE654-F889-459C-B191-E99F228B4330}"= TCP:c:\program files\MioNet\jvm\bin\MioNet.exe:MioNet
"{ECC292D9-53C3-45BB-9A36-39EDA483A3AC}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\River Past\\Video Cleaner Pro\\VideoCleanerPro.exe"= c:\program files\River Past\Video Cleaner Pro\VideoCleanerPro.exe:*:Enabled:River Past Video Cleaner Pro
R1 nod32drv;nod32drv;c:\windows\System32\drivers\nod32drv.sys [6/23/2008 3:16 PM 15424]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [4/17/2009 1:51 PM 25824]
R2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [8/27/2009 8:27 AM 1153368]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [8/14/2008 12:25 AM 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [8/14/2008 12:24 AM 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [8/14/2008 12:24 AM 170480]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.EXE --> c:\program files\Hotspot Shield\bin\HssTrayService.EXE [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [8/26/2009 3:43 PM 38160]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [8/14/2008 12:25 AM 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [3/3/2009 10:58 PM 1124848]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SASDIFSV
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {3A4E5ABE-E56F-CF60-9F13-8AB5B29C8960} /qb
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aqualibrium.ca/
IE: Append Link Target to Existing PDF
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\hzmzerj0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aqualibrium.ca/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-08 10:25
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\TMP000001091A43CFB3B19D32B4 524288 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2009-09-08 10:27
ComboFix-quarantined-files.txt 2009-09-08 14:27
ComboFix2.txt 2009-09-08 12:40
Pre-Run: 6,134,575,104 bytes free
Post-Run: 6,950,342,656 bytes free
598 --- E O F --- 2009-09-08 12:03
Kaspersky
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, September 8, 2009
Operating system: Microsoft Windows Vista Business Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, September 08, 2009 16:42:45
Records in database: 2760708
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Objects scanned: 119061
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 01:44:19
File name / Threat / Threats count
C:\Program Files\ESET\cache\FND3.NFI Infected: Trojan-PSW.Win32.Agent.nnh 1
Selected area has been scanned.