ComboFix 10-07-24.06 - Cory 07/26/2010 18:01:42.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.3117 [GMT -4:00]
Running from: c:\documents and settings\Cory\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cory\Desktop\CFScript.txt
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FILE ::
"c:\windows\system32\duyesedi.dll.vir"
"c:\windows\system32\gehazoze.exe"
"c:\windows\system32\pihuwali.dll.vir"
"c:\windows\system32\tizomovu.exe"
"c:\windows\system32\wahewozi.dll.vir"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Cory\Application Data\LimeWire
c:\documents and settings\Cory\Application Data\LimeWire\.AppSpecialShare\Batman Begins.wmv.torrent.bak
c:\documents and settings\Cory\Application Data\LimeWire\.AppSpecialShare\BB4E - BATMAN RETURNS.torrent.bak
c:\documents and settings\Cory\Application Data\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\branding.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\classic.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\comm.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\alerts.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\appshell.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\auth.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\caps.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\chardet.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\chrome.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\composer.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_html.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\cookie.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\directory.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\downloads.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\editor.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\extensions.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\feeds.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\find.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\gfx.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\inspector.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\intl.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\jar.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\locale.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\oji.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pippki.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\places.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\plugin.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\pref.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\profile.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\rdf.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\satchel.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\shistory.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\storage.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\transformiix.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\uconv.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\update.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\widget.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\windowds.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\xulutil.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\crashreporter.ini
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\dependentlibs.list
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\freebl3.chk
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\freebl3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\greprefs\all.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\javaxpcom.jar
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\js3250.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\LICENSE
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\debug.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\Microformats.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\utils.js
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\mozctl.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\mozctlx.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\nspr4.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\nss3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\nssckbi.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\nssutil3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\platform.ini
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\plc4.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\plds4.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\README.txt
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\arrow.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\arrowd.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\broken-image.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\charsetData.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\contenteditable.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\designmode.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\forms.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\grabber.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\html.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\html\folder.png
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\langGroups.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\language.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\loading-image.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\mathml.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\quirk.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\svg.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\ua.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\viewsource.css
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\res\wincharset.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\smime3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\softokn3.chk
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\softokn3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\sqlite3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\ssl3.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\updater.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\version.properties
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpcom.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpidl.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xul.dll
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\documents and settings\Cory\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
c:\documents and settings\Cory\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Cory\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Cory\Application Data\LimeWire\downloads.dat
c:\documents and settings\Cory\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Cory\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Cory\Application Data\LimeWire\filters.props
c:\documents and settings\Cory\Application Data\LimeWire\installation.props
c:\documents and settings\Cory\Application Data\LimeWire\library.dat
c:\documents and settings\Cory\Application Data\LimeWire\library5.dat
c:\documents and settings\Cory\Application Data\LimeWire\limewire.props
c:\documents and settings\Cory\Application Data\LimeWire\lock
c:\documents and settings\Cory\Application Data\LimeWire\mojito.props
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\.autoreg
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\280E3FA7d01
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\6E4DF74Ad01
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\AE98BDEDd01
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\Cache\BAFF9A9Bd01
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\cert8.db
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\compreg.dat
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\cookies.sqlite
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\downloads.sqlite
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\extensions.cache
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\extensions.ini
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\history.dat
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\key3.db
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\permissions.sqlite
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\places.sqlite-journal
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\places.sqlite
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\pluginreg.dat
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\prefs.js
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\secmod.db
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\XPC.mfl
c:\documents and settings\Cory\Application Data\LimeWire\mozilla-profile\xpti.dat
c:\documents and settings\Cory\Application Data\LimeWire\player.props
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Cory\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Cory\Application Data\LimeWire\questions.props
c:\documents and settings\Cory\Application Data\LimeWire\responses.cache
c:\documents and settings\Cory\Application Data\LimeWire\simpp.xml
c:\documents and settings\Cory\Application Data\LimeWire\spam.dat
c:\documents and settings\Cory\Application Data\LimeWire\tables.props
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Cory\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Cory\Application Data\LimeWire\ttdata.cache
c:\documents and settings\Cory\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Cory\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Cory\Application Data\LimeWire\version.xml
c:\documents and settings\Cory\Application Data\LimeWire\versions.props
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\audio.sxml3
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\image.sxml2
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\image.sxml3
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Cory\Application Data\LimeWire\xml\data\video.sxml3
c:\documents and settings\LocalService\Local Settings\Application Data\Windows Server
c:\documents and settings\NetworkService\Local Settings\Application Data\Windows Server
c:\program files\LimeWire
c:\program files\LimeWire\aopalliance.pack
c:\program files\LimeWire\clink.pack
c:\program files\LimeWire\commons-codec-1.3.pack
c:\program files\LimeWire\commons-logging.pack
c:\program files\LimeWire\commons-net.pack
c:\program files\LimeWire\daap.pack
c:\program files\LimeWire\dnsjava.pack
c:\program files\LimeWire\forms.pack
c:\program files\LimeWire\foxtrot.pack
c:\program files\LimeWire\gettext-commons.pack
c:\program files\LimeWire\guice-1.0.pack
c:\program files\LimeWire\hs_err_pid1100.log
c:\program files\LimeWire\hs_err_pid2008.log
c:\program files\LimeWire\hs_err_pid2276.log
c:\program files\LimeWire\hs_err_pid2464.log
c:\program files\LimeWire\hs_err_pid3004.log
c:\program files\LimeWire\hs_err_pid3324.log
c:\program files\LimeWire\hs_err_pid3604.log
c:\program files\LimeWire\hs_err_pid3632.log
c:\program files\LimeWire\hs_err_pid3980.log
c:\program files\LimeWire\hs_err_pid4952.log
c:\program files\LimeWire\hsqldb.pack
c:\program files\LimeWire\httpclient-4.0-alpha5-20080522.192134-5.pack
c:\program files\LimeWire\httpcore-4.0-beta2-20080510.140437-10.pack
c:\program files\LimeWire\httpcore-nio-4.0-beta2-20080510.140437-10.pack
c:\program files\LimeWire\icu4j.pack
c:\program files\LimeWire\jaudiotagger.pack
c:\program files\LimeWire\jcraft.pack
c:\program files\LimeWire\jdic.pack
c:\program files\LimeWire\jdic_stub.pack
c:\program files\LimeWire\jflac.pack
c:\program files\LimeWire\jl.pack
c:\program files\LimeWire\jmdns.pack
c:\program files\LimeWire\jogg.pack
c:\program files\LimeWire\jorbis.pack
c:\program files\LimeWire\lib\avg\ATL80.dll
c:\program files\LimeWire\lib\avg\avgcorex.dll
c:\program files\LimeWire\lib\avg\avgsdk.dll
c:\program files\LimeWire\lib\avg\avgsdkcom.dll
c:\program files\LimeWire\lib\avg\avgsdkupd.dll
c:\program files\LimeWire\lib\avg\Microsoft.VC80.ATL.manifest
c:\program files\LimeWire\lib\avg\Microsoft.VC80.CRT.manifest
c:\program files\LimeWire\lib\avg\msvcr80.dll
c:\program files\LimeWire\lib\jacob-1.15-M1-lw-x86.dll
c:\program files\LimeWire\lib\jdshow.dll
c:\program files\LimeWire\lib\JMediaFoundation.dll
c:\program files\LimeWire\lib\Microsoft.VC90.CRT.manifest
c:\program files\LimeWire\lib\msvcm90.dll
c:\program files\LimeWire\lib\msvcp90.dll
c:\program files\LimeWire\lib\msvcr90.dll
c:\program files\LimeWire\lib\torrent-wrapper.dll
c:\program files\LimeWire\lib\UnpackedJars.7z
c:\program files\LimeWire\LimeWire.jar.tmp
c:\program files\LimeWire\log4j.pack
c:\program files\LimeWire\looks.pack
c:\program files\LimeWire\messages.pack
c:\program files\LimeWire\mp3spi.pack
c:\program files\LimeWire\msvcr71.dll
c:\program files\LimeWire\onion-common.pack
c:\program files\LimeWire\onion-fec.pack
c:\program files\LimeWire\ProgressTabs.pack
c:\program files\LimeWire\swt.pack
c:\program files\LimeWire\themes.pack
c:\program files\LimeWire\tritonus.pack
c:\program files\LimeWire\unpack200.exe
c:\program files\LimeWire\vorbisspi.pack
c:\windows\system32\duyesedi.dll.vir
c:\windows\system32\gehazoze.exe
c:\windows\system32\pihuwali.dll.vir
c:\windows\system32\tizomovu.exe
c:\windows\system32\wahewozi.dll.vir
.
((((((((((((((((((((((((( Files Created from 2010-06-26 to 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-26 01:57 . 2010-07-26 01:57 -------- d-----w- c:\windows\Logs
2010-07-26 01:17 . 2010-07-26 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-07-25 20:50 . 2010-07-25 20:50 -------- d-----w- C:\rsit
2010-07-25 20:50 . 2010-07-25 20:50 -------- d-----w- c:\program files\trend micro
2010-07-18 19:39 . 2010-07-25 20:36 -------- d-----w- c:\documents and settings\Administrator
2010-07-18 19:24 . 2010-07-18 19:24 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-18 19:24 . 2010-07-18 19:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-18 19:03 . 2010-07-18 19:03 -------- d-----w- c:\program files\Alwil Software
2010-07-18 19:03 . 2010-07-18 19:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-02 03:32 . 2010-07-02 03:32 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 21:58 . 2009-10-26 21:06 720 ----a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2010-07-26 21:50 . 2008-04-10 01:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-26 21:48 . 2008-04-10 01:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-30 00:16 . 2009-09-17 20:36 -------- d-----w- c:\documents and settings\Cory\Application Data\Apple Computer
2010-05-30 00:13 . 2009-09-17 20:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-05-26 15:41 . 2010-07-26 01:58 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 15:41 . 2010-07-26 01:58 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 15:41 . 2010-07-26 01:58 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 15:41 . 2010-07-26 01:58 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 15:41 . 2010-07-26 01:58 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-05-06 10:41 . 2001-08-23 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2001-08-23 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2008-03-12 10:42 . 2008-04-10 01:36 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-03-12 10:42 . 2008-04-10 01:36 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-03-12 10:42 . 2008-04-10 01:36 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-03-12 10:42 . 2008-04-10 01:36 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-03-12 10:42 . 2008-04-10 01:36 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-07-26_00.24.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-26 21:58 . 2010-07-26 21:58 16384 c:\windows\Temp\Perflib_Perfdata_638.dat
+ 2010-07-26 01:58 . 2010-06-02 08:55 74072 c:\windows\system32\XAPOFX1_5.dll
+ 2010-07-26 01:58 . 2010-02-04 14:01 74072 c:\windows\system32\XAPOFX1_4.dll
+ 2010-07-26 01:58 . 2009-09-04 21:44 69464 c:\windows\system32\XAPOFX1_3.dll
+ 2010-07-26 01:58 . 2008-10-27 14:04 70992 c:\windows\system32\XAPOFX1_2.dll
+ 2010-07-26 01:58 . 2008-07-31 14:41 68616 c:\windows\system32\XAPOFX1_1.dll
+ 2010-07-26 01:58 . 2008-05-30 18:17 65032 c:\windows\system32\XAPOFX1_0.dll
+ 2010-07-26 01:58 . 2010-02-04 14:01 22360 c:\windows\system32\X3DAudio1_7.dll
+ 2010-07-26 01:58 . 2009-03-16 18:18 22360 c:\windows\system32\X3DAudio1_6.dll
+ 2010-07-26 01:58 . 2008-10-27 14:04 23376 c:\windows\system32\X3DAudio1_5.dll
+ 2010-07-26 01:58 . 2008-05-30 18:17 25608 c:\windows\system32\X3DAudio1_4.dll
+ 2010-07-26 01:58 . 2008-03-05 20:00 25608 c:\windows\system32\X3DAudio1_3.dll
+ 2010-07-26 01:58 . 2007-10-22 07:37 17928 c:\windows\system32\X3DAudio1_2.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-07-26 01:58 . 2010-06-02 08:55 527192 c:\windows\system32\XAudio2_7.dll
+ 2010-07-26 01:58 . 2010-02-04 14:01 528216 c:\windows\system32\XAudio2_6.dll
+ 2010-07-26 01:58 . 2009-09-04 21:44 515416 c:\windows\system32\XAudio2_5.dll
+ 2010-07-26 01:58 . 2009-03-16 18:18 517448 c:\windows\system32\XAudio2_4.dll
+ 2010-07-26 01:58 . 2008-10-27 14:04 514384 c:\windows\system32\XAudio2_3.dll
+ 2010-07-26 01:58 . 2008-07-31 14:40 509448 c:\windows\system32\XAudio2_2.dll
+ 2010-07-26 01:58 . 2008-05-30 18:19 507400 c:\windows\system32\XAudio2_1.dll
+ 2010-07-26 01:58 . 2008-03-05 20:03 479752 c:\windows\system32\XAudio2_0.dll
+ 2010-07-26 01:58 . 2010-06-02 08:55 239960 c:\windows\system32\xactengine3_7.dll
+ 2010-07-26 01:58 . 2010-02-04 14:01 238936 c:\windows\system32\xactengine3_6.dll
+ 2010-07-26 01:58 . 2009-09-04 21:44 238936 c:\windows\system32\xactengine3_5.dll
+ 2010-07-26 01:58 . 2009-03-16 18:18 235352 c:\windows\system32\xactengine3_4.dll
+ 2010-07-26 01:58 . 2008-10-27 14:04 235856 c:\windows\system32\xactengine3_3.dll
+ 2010-07-26 01:58 . 2008-07-31 14:41 238088 c:\windows\system32\xactengine3_2.dll
+ 2010-07-26 01:58 . 2008-05-30 18:18 238088 c:\windows\system32\xactengine3_1.dll
+ 2010-07-26 01:58 . 2008-03-05 20:03 238088 c:\windows\system32\xactengine3_0.dll
+ 2010-07-26 01:58 . 2007-07-20 04:57 267112 c:\windows\system32\xactengine2_9.dll
+ 2010-07-26 01:58 . 2007-06-21 00:46 266088 c:\windows\system32\xactengine2_8.dll
+ 2010-07-26 01:58 . 2007-10-22 07:39 267272 c:\windows\system32\xactengine2_10.dll
+ 2010-07-26 01:58 . 2009-09-04 21:29 235344 c:\windows\system32\d3dx11_42.dll
+ 2010-07-26 01:58 . 2009-09-04 21:29 453456 c:\windows\system32\d3dx10_42.dll
+ 2010-07-26 01:58 . 2009-03-09 19:27 453456 c:\windows\system32\d3dx10_41.dll
+ 2010-07-26 01:58 . 2008-10-15 10:22 452440 c:\windows\system32\d3dx10_40.dll
+ 2010-07-26 01:58 . 2008-07-10 15:01 467984 c:\windows\system32\d3dx10_39.dll
+ 2010-07-26 01:58 . 2008-05-30 18:11 467984 c:\windows\system32\d3dx10_38.dll
+ 2010-07-26 01:58 . 2008-02-06 03:07 462864 c:\windows\system32\d3dx10_37.dll
+ 2010-07-26 01:58 . 2007-10-02 13:56 444776 c:\windows\system32\d3dx10_36.dll
+ 2010-07-26 01:58 . 2006-03-31 15:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 21:31 . 2010-07-26 21:31 184320 c:\windows\ERDNT\AutoBackup\7-26-2010\Users\00000002\UsrClass.dat
+ 2010-07-26 21:31 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\7-26-2010\ERDNT.EXE
+ 2010-07-26 01:58 . 2010-07-26 01:58 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:57 . 2010-07-26 01:57 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:58 . 2010-07-26 01:58 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2010-03-12 17:58 . 2010-03-12 17:58 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-07-26 01:58 . 2009-09-04 21:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2010-07-26 01:58 . 2009-03-09 19:27 4178264 c:\windows\system32\D3DX9_41.dll
+ 2010-07-26 01:58 . 2008-10-15 10:22 4379984 c:\windows\system32\D3DX9_40.dll
+ 2010-07-26 01:58 . 2008-07-10 15:00 3851784 c:\windows\system32\D3DX9_39.dll
+ 2010-07-26 01:58 . 2008-05-30 18:11 3850760 c:\windows\system32\D3DX9_38.dll
+ 2010-07-26 01:58 . 2008-03-05 19:56 3786760 c:\windows\system32\D3DX9_37.dll
+ 2010-07-26 01:58 . 2007-10-12 19:14 3734536 c:\windows\system32\d3dx9_36.dll
+ 2010-07-26 01:58 . 2009-09-04 21:29 5501792 c:\windows\system32\d3dcsx_42.dll
+ 2010-07-26 01:58 . 2009-09-04 21:29 1974616 c:\windows\system32\D3DCompiler_42.dll
+ 2010-07-26 01:58 . 2009-03-09 19:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2010-07-26 01:58 . 2008-10-15 10:22 2036576 c:\windows\system32\D3DCompiler_40.dll
+ 2010-07-26 01:58 . 2008-07-10 15:00 1493528 c:\windows\system32\D3DCompiler_39.dll
+ 2010-07-26 01:58 . 2008-05-30 18:11 1491992 c:\windows\system32\D3DCompiler_38.dll
+ 2010-07-26 01:58 . 2008-03-05 19:56 1420824 c:\windows\system32\D3DCompiler_37.dll
+ 2010-07-26 01:58 . 2007-10-12 19:14 1374232 c:\windows\system32\D3DCompiler_36.dll
+ 2010-07-26 21:31 . 2010-07-26 21:31 6533120 c:\windows\ERDNT\AutoBackup\7-26-2010\Users\00000001\ntuser.dat
- 2009-02-23 04:46 . 2009-02-23 04:46 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:57 . 2010-07-26 01:57 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-02-23 04:46 . 2009-02-23 04:46 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-26 01:57 . 2010-07-26 01:57 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-04 00:07 . 2010-05-28 16:37 32472008 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-10 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 16844800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"nwiz"="nwiz.exe" [2008-09-18 1657376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-04 136600]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-05-04 1851128]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
c:\documents and settings\Cory\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2009-7-10 323584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\arma 2 operation arrowhead demo\\ArmA2OA_Demo.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [5/4/2009 12:19 AM 28544]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [3/19/2009 12:40 PM 110992]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3/19/2009 12:40 PM 24336]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/9/2008 11:02 PM 24652]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\43.tmp --> c:\windows\system32\43.tmp [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/5/2009 12:44 AM 721904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.27.0.cab
FF - ProfilePath - c:\documents and settings\Cory\Application Data\Mozilla\Firefox\Profiles\uh958jmt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-26 18:08
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\43.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-789336058-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b2,ef,31,0b,e3,ce,c7,f8,1d,14,4d,5e,e7,ae,a0,aa,e0,21,dd,92,62,6d,d7,
e2,f5,69,e5,0c,5b,9a,95,b5,8d,41,f7,95,80,2d,e1,c9,a2,41,c4,33,a2,1e,fb,aa,\
"??"=hex:47,88,b9,f6,c0,11,83,a9,b6,3f,09,2b,31,0b,2b,6f
[HKEY_USERS\S-1-5-21-1078081533-789336058-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:e1,3e,66,bb,b9,4d,85,db,bf,b4,86,60,c0,9d,55,b1,ce,96,75,69,b5,
d1,9e,ca,dc,31,82,20,d1,02,d2,ee,a5,0f,f1,d3,0e,f9,23,50,ed,fd,18,1a,43,d6,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------