ComboFix 09-04-14.08 - End user 15/04/2009 13:14.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.609 [GMT 1:00]
Running from: d:\documents and settings\End user\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\End user\Desktop\CFscript.txt
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\nlqqxjywvg.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\nlqqxjywvg.exe
d:\documents and settings\End user\Application Data\LimeWire
d:\documents and settings\End user\Application Data\LimeWire\browser\xul-v2.0b2.4-do-not-remove
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\branding.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\branding.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\classic.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\classic.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\comm.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\comm.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\en-US.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\en-US.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\limewire.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\limewire.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\pippki.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\pippki.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\chrome\toolkit.manifest
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\accessibility.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\alerts.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\appshell.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\appstartup.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\auth.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\autocomplete.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\autoconfig.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\caps.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\chardet.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\chrome.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\commandhandler.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\commandlines.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\composer.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_html.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_xslt.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\content_xtf.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\contentprefs.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\cookie.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\directory.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\docshell_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_canvas.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_core.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_css.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_events.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_html.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_json.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_offline.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_range.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_storage.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_svg.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_traversal.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_views.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_xbl.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_xpath.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\dom_xul.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\downloads.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\editor.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\embed_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\extensions.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\exthandler.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\exthelper.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\fastfind.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\FeedProcessor.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\feeds.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\find.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\gfx.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\htmlparser.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\imgicon.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\imglib2.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\inspector.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\intl.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\jar.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\jsdservice.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\layout_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\layout_printing.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\layout_xul.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\locale.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\loginmgr.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\lwbrk.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\mimetype.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\mozfind.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_about.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_cache.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_cookie.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_dns.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_file.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_ftp.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_http.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_res.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_socket.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_strconv.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsAddonRepository.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsBlocklistService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsContentPrefService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsDictionary.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsExtensionManager.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsHandlerService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsLivemarkService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsLoginInfo.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsLoginManager.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsProgressDialog.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsResetPref.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsTaggingService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsTryToClose.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsUpdateService.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsURLFormatter.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\oji.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pipboot.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pipnss.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pippki.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\places.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\plugin.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pluginGlue.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\pref.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\prefetch.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\profile.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\proxyObject.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\rdf.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\satchel.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\saxparser.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\shistory.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\spellchecker.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\storage-Legacy.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\storage.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\transformiix.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\txmgr.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\txtsvc.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\uconv.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\unicharutil.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\universalchardet.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\update.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\urlformatter.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\webshell_idls.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\websrvcs.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\widget.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\windowds.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\windowwatcher.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xml-rpc.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xmlextras.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_base.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_components.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_io.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_system.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpconnect.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xpinstall.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xulapp.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xuldoc.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xultmpl.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\xulutil.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\components\zipwriter.xpt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\crashreporter.ini
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\dependentlibs.list
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.aff
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\dictionaries\en-US.dic
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\freebl3.chk
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\freebl3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\greprefs\all.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\greprefs\security-prefs.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\greprefs\xpinstall.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\javaxpcom.jar
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\javaxpcomglue.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\js3250.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\LICENSE
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\debug.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\JSON.jsm
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\Microformats.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\PluralForm.jsm
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\utils.js
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\mozctl.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\mozctlx.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\nspr4.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\nss3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\nssckbi.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\nssutil3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\platform.ini
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\plc4.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\plds4.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\plugins\npnul32.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\README.txt
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\arrow.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\arrowd.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\broken-image.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\charsetalias.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\charsetData.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\contenteditable.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\designmode.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\EditorOverride.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\forms.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\grabber.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\hiddenWindow.html
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\html.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\html\folder.png
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\langGroups.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\language.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\loading-image.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\mathml.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\quirk.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\svg.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-after.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-column-before.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-after.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-add-row-before.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-column.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\table-remove-row.gif
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\ua.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\viewsource.css
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\res\wincharset.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\smime3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\softokn3.chk
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\softokn3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\sqlite3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\ssl3.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\updater.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\version.properties
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpcom.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpidl.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xul.dll
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
d:\documents and settings\End user\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
d:\documents and settings\End user\Application Data\LimeWire\certificate\limewire.keystore
d:\documents and settings\End user\Application Data\LimeWire\createtimes.cache
d:\documents and settings\End user\Application Data\LimeWire\downloads.dat
d:\documents and settings\End user\Application Data\LimeWire\gnutella.net
d:\documents and settings\End user\Application Data\LimeWire\installation.props
d:\documents and settings\End user\Application Data\LimeWire\library.dat
d:\documents and settings\End user\Application Data\LimeWire\library5.dat
d:\documents and settings\End user\Application Data\LimeWire\limewire.props
d:\documents and settings\End user\Application Data\LimeWire\mojito.props
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\.autoreg
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_001_
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_002_
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_003_
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\3816C1E5d01
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\6B5B8EF7d01
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\7BD6A121d01
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\AE98BDFFd01
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\Cache\BAFF9A9Cd01
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\cert8.db
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\compreg.dat
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\cookies.sqlite
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\downloads.sqlite
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\extensions.cache
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\extensions.ini
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\history.dat
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\key3.db
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\permissions.sqlite
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\places.sqlite-journal
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\places.sqlite
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\pluginreg.dat
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\prefs.js
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\secmod.db
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\XPC.mfl
d:\documents and settings\End user\Application Data\LimeWire\mozilla-profile\xpti.dat
d:\documents and settings\End user\Application Data\LimeWire\promotion\promodb.backup
d:\documents and settings\End user\Application Data\LimeWire\promotion\promodb.data
d:\documents and settings\End user\Application Data\LimeWire\promotion\promodb.properties
d:\documents and settings\End user\Application Data\LimeWire\promotion\promodb.script
d:\documents and settings\End user\Application Data\LimeWire\questions.props
d:\documents and settings\End user\Application Data\LimeWire\responses.cache
d:\documents and settings\End user\Application Data\LimeWire\simpp.xml
d:\documents and settings\End user\Application Data\LimeWire\spam.dat
d:\documents and settings\End user\Application Data\LimeWire\tables.props
d:\documents and settings\End user\Application Data\LimeWire\version.xml
d:\documents and settings\End user\Application Data\LimeWire\versions.props
d:\documents and settings\End user\My Documents\FrostWire
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\Preview-T-31551043-Paint Shop Pro 7.04 + Animation Shop 3.04.zip
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\T-115969-Jasc Paint Shop Pro 7.zip
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\T-1287301-Jasc Paint Shop Pro 7.04 And Animation Shop 3.04 (portable).zip
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\T-31354419-Paint Shop Pro 7 full.zip
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\T-38518-Jasc Paint Shop Pro 7.0 (Serial).zip
d:\documents and settings\End user\My Documents\FrostWire\Incomplete\T-4153504-Paint Shop Pro 7 full(1).zip
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc Paint Shop Pro 7.00--.zip
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc Paint Shop Pro 7.04 (Portable).zip
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full.zip
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\
0x0409.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\Data1.cab
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\instmsia.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\instmsiw.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\Jasc Animation Shop 3.msi
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\setup.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Animation Shop\Setup.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\autorun.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\autorun.ico
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\AUTORUN.INF
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\
0x0409.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\Data1.cab
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\instmsia.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\instmsiw.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\Jasc Paint Shop Photo Album 5.msi
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\setup.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Photo Album 5\Setup.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\
0x0409.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\Data1.cab
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\instmsia.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\instmsiw.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\Jasc Paint Shop Pro 9.msi
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\setup.exe
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\Paint Shop Pro 9\Setup.ini
d:\documents and settings\End user\My Documents\FrostWire\Saved\Jasc PaintShop Pro 9 and Paint Shop Photo Album 5 Full\SerialInfo.txt
.
((((((((((((((((((((((((( Files Created from 2009-03-15 to 2009-04-15 )))))))))))))))))))))))))))))))
.
2009-04-15 12:13 . 2006-03-02 23:42 73728 ----a-w C:\pv.exe
2009-04-15 08:57 . 2009-04-15 08:57 -------- d-----w c:\windows\LastGood
2009-04-13 10:26 . 2009-04-13 10:26 -------- dc----w d:\documents and settings\End user\Local Settings\Application Data\Google
2009-04-13 10:16 . 2009-04-13 10:16 -------- dc----w d:\documents and settings\End user\Application Data\IObit
2009-04-13 10:07 . 2009-04-10 10:23 713216 ----a-w c:\windows\system32\nsk56.tmp
2009-04-04 15:46 . 2009-04-04 15:46 -------- d-sh--w c:\windows\ftpcache
2009-03-21 17:58 . 2009-04-13 17:12 54 ----a-w c:\windows\JascCmdFile.INI
2009-03-21 15:28 . 2009-03-21 15:28 -------- dc----w d:\documents and settings\End user\Application Data\SmartFTP
2009-03-20 18:04 . 2009-03-20 18:04 -------- d-----w c:\windows\Sun
2009-03-18 21:44 . 2005-05-01 14:41 49152 ------w c:\windows\system32\setupsvc.dll
2009-03-18 21:44 . 2005-04-30 17:09 57344 ------w c:\windows\system32\GenSvcInst.exe
2009-03-18 21:44 . 2005-04-30 17:02 86016 ------w c:\windows\system32\bgsvcgen.exe
2009-03-18 21:44 . 2005-05-11 00:33 32256 ------w c:\windows\system32\drivers\cdrbsdrv.sys
2009-03-18 21:34 . 2009-03-20 17:48 -------- dc----w d:\documents and settings\End user\Application Data\FUJIFILM
2009-03-18 21:33 . 2006-07-12 14:39 208896 ----a-w c:\windows\system32\FFRafShellEx.dll
2009-03-18 21:33 . 2004-07-24 21:28 155648 ----a-w c:\windows\system32\FFRAFLIB.DLL
2009-03-18 21:33 . 2003-09-03 16:45 274432 ----a-w c:\windows\system32\FFTIFF16.dll
2009-03-18 21:32 . 2009-03-18 21:32 -------- dc----w d:\documents and settings\End user\Application Data\InstallShield
2009-03-18 21:31 . 2001-11-25 11:11 81924 ------w c:\windows\system32\drivers\VC4CB104.SYS
2009-03-18 21:31 . 2002-06-25 10:06 45056 ------w c:\windows\system32\FINFCOPY.dll
2009-03-18 21:31 . 2002-02-27 11:27 65536 ------w c:\windows\system32\FINFCHECK.dll
2009-03-18 21:31 . 2002-02-05 16:33 69632 ------w c:\windows\system32\FREGSHEX.DLL
2009-03-18 21:31 . 2002-02-13 10:00 45056 ------w c:\windows\system32\FCLKBTN.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 10:21 . 2009-03-09 20:05 -------- d-----w c:\program files\Jasc Software Inc
2009-04-14 15:54 . 2008-07-24 20:13 -------- dc----w d:\documents and settings\All Users\Application Data\SecTaskMan
2009-04-14 11:39 . 2009-03-08 12:45 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-13 10:19 . 2008-07-24 20:41 -------- dc----w d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-13 10:16 . 2009-04-13 10:16 -------- d-----w c:\program files\IObit
2009-04-13 10:13 . 2009-04-13 10:13 -------- d-----w c:\program files\CCleaner
2009-04-13 10:06 . 2009-03-08 16:58 -------- d-----w c:\program files\Bonjour
2009-04-13 08:52 . 2009-03-08 12:47 -------- d-----w c:\program files\Norton 360
2009-04-12 18:27 . 2009-03-08 17:15 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-11 13:49 . 2009-03-18 21:33 -------- d-----w c:\program files\FinePixViewer
2009-04-04 15:56 . 2009-03-05 18:50 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-02 16:06 . 2009-03-08 18:48 -------- dc----w d:\documents and settings\End user\Application Data\FrostWire
2009-03-21 15:27 . 2009-03-21 15:27 -------- d-----w c:\program files\SmartFTP Client
2009-03-21 15:26 . 2009-03-21 15:26 -------- d-----w c:\program files\SmartFTP Client 3.0 Setup Files
2009-03-20 16:48 . 2009-03-05 11:07 75520 -c--a-w d:\documents and settings\End user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-18 21:44 . 2009-03-18 21:44 -------- d-----w c:\program files\PIXELA
2009-03-18 21:44 . 2009-03-05 18:50 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-18 21:31 . 2009-03-18 21:31 -------- d-----w c:\program files\REGSHAVE
2009-03-15 11:15 . 2009-03-15 11:15 -------- dc----w d:\documents and settings\End user\Application Data\AdobeUM
2009-03-13 21:18 . 2009-03-13 21:18 -------- dc----w d:\documents and settings\End user\Application Data\OD2
2009-03-11 21:24 . 2009-03-11 21:24 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-10 19:14 . 2009-03-10 19:14 -------- dc----w d:\documents and settings\End user\Application Data\Jasc Software Inc
2009-03-08 22:26 . 2009-03-08 17:00 -------- dc----w d:\documents and settings\End user\Application Data\Apple Computer
2009-03-08 17:38 . 2009-03-05 18:50 -------- d-----w c:\program files\Java
2009-03-08 17:03 . 2009-03-08 17:01 -------- d-----w c:\program files\Windows Live
2009-03-08 17:02 . 2009-03-08 17:02 -------- d-----w c:\program files\Microsoft
2009-03-08 17:02 . 2009-03-08 17:02 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-08 16:59 . 2009-03-08 16:59 -------- d-----w c:\program files\iTunes
2009-03-08 16:59 . 2009-03-08 16:59 -------- d-----w c:\program files\iPod
2009-03-08 16:59 . 2009-03-08 16:56 -------- d-----w c:\program files\Common Files\Apple
2009-03-08 16:58 . 2009-03-08 16:58 -------- d-----w c:\program files\QuickTime
2009-03-08 16:57 . 2009-03-08 16:57 -------- d-----w c:\program files\Apple Software Update
2009-03-08 16:35 . 2009-03-08 16:35 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-08 15:53 . 2005-10-28 20:11 -------- dc----w d:\documents and settings\All Users\Application Data\Symantec
2009-03-08 15:52 . 2009-03-08 12:46 -------- d-----w c:\program files\Symantec
2009-03-08 15:52 . 2009-03-08 12:46 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-08 15:52 . 2009-03-08 12:46 60808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-03-08 15:52 . 2009-03-08 12:46 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-08 15:52 . 2009-03-08 12:46 10635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-08 15:45 . 2008-12-14 19:10 -------- dc----w d:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-08 15:35 . 2009-03-08 15:35 -------- d-----w c:\program files\Common Files\L&H
2009-03-08 15:35 . 2009-03-08 15:35 -------- d-----w c:\program files\Microsoft ActiveSync
2009-03-08 15:33 . 2009-03-08 15:33 -------- d-----w c:\program files\Microsoft.NET
2009-03-08 15:20 . 2009-03-08 15:20 15939 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-03-08 15:20 . 2009-03-08 15:20 -------- d-----w c:\program files\Belkin
2009-03-08 15:09 . 2009-03-08 15:09 -------- dc----w d:\documents and settings\End user\Application Data\Ulead Systems
2009-03-08 13:02 . 2009-03-05 11:07 -------- dc----w d:\documents and settings\End user\Application Data\Symantec
2009-03-08 12:48 . 2009-03-08 12:48 -------- d-----w c:\program files\Windows Sidebar
2009-03-05 18:57 . 2009-03-05 18:50 -------- d-----w c:\program files\AOL 9.0
2009-03-05 18:56 . 2005-10-28 20:09 -------- dc----w d:\documents and settings\All Users\Application Data\AOL
2009-03-05 18:53 . 2009-03-05 18:50 -------- d-----w c:\program files\Microsoft Works
2009-03-05 13:10 . 2009-03-05 13:10 -------- d-----w c:\program files\MSXML 4.0
2009-03-05 11:30 . 2004-08-10 15:57 76487 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-05 11:24 . 2004-08-04 13:00 250048 ----a-w C:\NTLDR
2009-02-21 18:16 . 2008-06-08 20:57 -------- dc----w d:\documents and settings\All Users\Application Data\Kontiki
2009-02-19 13:38 . 2009-02-19 12:32 -------- dc----w d:\documents and settings\Administrator\Application Data\AVG7
2009-02-19 12:03 . 2009-02-19 12:03 579464 ----a-w c:\windows\system32\SymNeti.dll
2009-02-19 12:03 . 2009-02-19 12:03 207240 ----a-w c:\windows\system32\SymRedir.dll
2009-02-19 11:31 . 2009-02-19 11:31 9844 ----a-w c:\windows\system32\drivers\SymRedir.cat
2009-02-19 11:31 . 2009-02-19 11:31 31280 ----a-w c:\windows\system32\drivers\SymIM.sys
2009-02-19 11:31 . 2009-02-19 11:31 1611 ----a-w c:\windows\system32\drivers\SymRedir.inf
2009-02-19 11:31 . 2009-02-19 11:31 41008 ----a-w c:\windows\system32\drivers\symndisv.sys
2009-02-19 11:31 . 2009-02-19 11:31 96560 ----a-w c:\windows\system32\drivers\symfw.sys
2009-02-19 11:31 . 2009-02-19 11:31 38576 ----a-w c:\windows\system32\drivers\symids.sys
2009-02-19 11:31 . 2009-02-19 11:31 37424 ----a-w c:\windows\system32\drivers\symndis.sys
2009-02-19 11:31 . 2009-02-19 11:31 22320 ----a-w c:\windows\system32\drivers\symredrv.sys
2009-02-19 11:31 . 2009-02-19 11:31 184496 ----a-w c:\windows\system32\drivers\symtdi.sys
2009-02-19 11:31 . 2009-02-19 11:31 13616 ----a-w c:\windows\system32\drivers\symdns.sys
2009-02-18 17:25 . 2009-02-18 17:25 -------- dc----w d:\documents and settings\All Users\Application Data\Macrovision
2009-02-09 11:13 . 2009-03-05 12:53 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-10 15:38 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 18:52 . 2009-02-06 18:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-01-16 21:35 . 2007-08-13 18:54 3594752 ------w c:\windows\system32\dllcache\mshtml.dll
2007-02-05 19:30 . 2007-02-05 16:33 90760 -c--a-w d:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2005-10-28 20:11 . 2009-02-19 12:28 34232 -c--a-w d:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-31 21:2009-03-08 16:39 47:26 . c:\program files\mozilla firefox\components\coFFPlgn.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-14_11.09.47 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-10-28 180269]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-17 61952]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2004-09-10 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-09-15 2557952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2009-3-18 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
2003-07-02 10:13 40960 -c--a-w c:\apps\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 05:42 1695232 ----a-w c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2005-05-11 12:48 127118 ----a-w c:\apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2005-04-01 15:16 1495040 ----a-w c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 49152]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\system32\DRIVERS\rt2500usb.sys [2004-07-16 140416]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-08 101936]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7aed521a-0bef-11de-b652-001485b12e7a}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-05 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 05:42]
2009-04-13 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-04-13 17:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/?o=101677&l=dis
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\End user\Application Data\Mozilla\Firefox\Profiles\1cg225ju.default\
FF - prefs.js: browser.startup.homepage - hxxp://home.myspace.com/index.cfm?fuseaction=user|
http://www.facebook.com/home.php?re...tp://twitter.com/home|http://oh-revoir.co.uk/
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: keyword.enabled - true
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-15 13:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: ~,10time:~,-3
ComboFix-quarantined-files.txt 2009-04-15 12:20
ComboFix2.txt 2009-04-14 11:10
Pre-Run: 19,855,781,888 bytes free
Post-Run: 19,100,135,424 bytes free
712 --- E O F --- 2009-03-14 11:34
post it too long to fit both logs in, so i'll post them separately.