I was using the SanDisk with USB although it had no cards in it
Here's the combofix.txt:
ComboFix 09-01-21.01 - Melody Strange 01/21/2009 14:09:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.138 [GMT -6:00]
Running from: c:\documents and settings\Melody Strange\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Melody Strange\Application Data\FunWebProducts
c:\documents and settings\Melody Strange\Application Data\FunWebProducts\kernell32.dll
c:\program files\Altnet
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\adsntfs.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.rvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\dbx.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\dbx.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\iso.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\java.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\java.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mbox.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_w95.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_x95.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mime.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\nelf.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\nelf.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\pdf.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\rar.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\rup.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\sdx.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\sdx.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\update.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\update.txt.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\zip.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\zip.xmd.cab
c:\program files\Need2Find
c:\program files\Need2Find\bar\History\search
c:\windows\IE4 Error Log.txt
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\Cache
c:\windows\system32\Cache\buts.bin
c:\windows\system32\Cache\comp40.bmp
c:\windows\system32\Cache\football.bmp
c:\windows\system32\Cache\msg.bin
c:\windows\system32\Cache\search find 2.bmp
c:\windows\system32\Cache\showbtn12.bmp
c:\windows\system32\Cache\showbtn123.bmp
c:\windows\system32\Cache\showbtn1234.bmp
c:\windows\system32\Cache\showbtn12345.bmp
c:\windows\system32\Cache\showbtn123456.bmp
c:\windows\system32\Cache\slotmachine.bmp
c:\windows\system32\Cache\untitled.bmp
c:\windows\system32\Cache\valentines copy.bmp
c:\windows\system32\Cache\web app.bmp
c:\documents and settings\Tanner and Tori\Application Data\FunWebProducts . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 )))))))))))))))))))))))))))))))
.
2009-01-21 14:00 . 2009-01-21 14:01 d-------- C:\32788R22FWJFW
2009-01-21 13:06 . 2009-01-21 13:11 d-------- c:\program files\Mozilla Firefox 3.1 Beta 2
2009-01-21 10:49 . 2006-06-16 09:38 102,368 --a------ c:\windows\TrueInstall.exe
2009-01-20 20:07 . 2009-01-20 20:07 d-------- c:\documents and settings\Melody Strange\Application Data\Malwarebytes
2009-01-20 13:02 . 2009-01-20 18:41 d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-20 13:02 . 2009-01-20 13:02 d-------- c:\documents and settings\Tanner and Tori\Application Data\Malwarebytes
2009-01-20 13:02 . 2009-01-20 13:02 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-20 13:02 . 2009-01-14 16:11 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-20 13:02 . 2009-01-14 16:11 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-20 09:32 . 2009-01-20 09:32 d-------- c:\program files\Common Files\Adobe AIR
2009-01-20 09:23 . 2009-01-20 09:23 52,389 --a------ c:\windows\Sysvxd.exe
2009-01-20 09:12 . 2009-01-20 09:12 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-01-20 09:12 . 2009-01-20 09:12 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-01-20 09:09 . 2009-01-21 14:45 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-20 09:09 . 2009-01-20 09:09 1,409 --a------ c:\windows\QTFont.for
2009-01-19 21:15 . 2009-01-19 21:15 d-------- c:\documents and settings\Melody Strange\Application Data\Yahoo
2009-01-05 08:23 . 2009-01-05 08:34 d-------- c:\documents and settings\All Users\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 20:23 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-21 18:47 --------- d-----w c:\documents and settings\Melody Strange\Application Data\MSN6
2009-01-21 16:47 --------- d-----w c:\program files\Common Files\HP
2009-01-21 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\Napster
2009-01-21 16:24 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-21 16:24 --------- d-----w c:\program files\Design Science
2009-01-21 16:23 --------- d-----w c:\program files\Logitech
2009-01-21 16:22 --------- d-----w c:\program files\Jasc Software Inc
2009-01-21 16:19 --------- d-----w c:\program files\InterActual
2009-01-21 16:16 --------- d-----w c:\program files\Hewlett-Packard
2009-01-21 16:12 --------- d-----w c:\program files\Google
2009-01-21 16:08 --------- d-----w c:\program files\Common Files\AOL
2009-01-21 16:08 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-21 16:07 --------- d-----w c:\program files\Abacast
2009-01-21 01:06 --------- d-----w c:\program files\LimeWire
2009-01-20 15:30 --------- d-----w c:\program files\Common Files\Adobe
2009-01-20 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-01-20 15:18 --------- d-----w c:\program files\Java
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\Digital Album Organizer
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\CyberLink
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\ArcSoft
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\Apple Computer
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\AdobeUM
2009-01-20 00:05 42,666 ----a-w c:\documents and settings\Melody Strange\Application Data\wklnhst.dat
2009-01-09 03:09 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 03:09 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 03:09 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 03:09 --------- d-----w c:\program files\Symantec
2009-01-05 17:18 --------- d-----w c:\program files\MSN Messenger
2009-01-05 14:23 --------- d-----w c:\program files\Lavasoft
2009-01-05 14:22 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-04 14:30 --------- d-----w c:\program files\MSECache
2008-10-07 03:27 35,630 ----a-w c:\documents and settings\Tanner and Tori\Application Data\wklnhst.dat
2008-06-16 17:47 118,112 ----a-w c:\documents and settings\Melody Strange\Application Data\GDIPFONTCACHEV1.DAT
2007-01-09 04:09 118,112 ----a-w c:\documents and settings\Tanner and Tori\Application Data\GDIPFONTCACHEV1.DAT
2004-10-08 23:30 164 ---ha-w c:\documents and settings\All Users\hpothb07.dat
2008-06-30 18:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-23 00:51 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008082220080823\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 57,344 2005-06-07 05:46:24 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 1,597,440 2004-09-09 23:35:38 c:\program files\AWS\WeatherBug\bak\Weather.exe
----a-w 50,688 2003-12-06 04:08:04 c:\program files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe
----a-w 180,269 2006-03-24 18:27:30 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 110,592 2003-08-19 07:01:00 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
----a-w 204,800 2003-08-27 01:47:34 c:\program files\Dell\Media Experience\bak\PCMService.exe
----a-w 69,632 2002-04-17 16:42:56 c:\program files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe
----a-w 49,152 2004-09-13 21:49:00 c:\program files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe
----a-w 278,528 2005-12-21 02:54:48 c:\program files\iTunes\bak\iTunesHelper.exe
----a-w 267,048 2008-03-30 15:36:40 c:\program files\iTunes\iTunesHelper.exe
----a-w 11,776 2006-01-19 17:06:16 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\bak\mimboot.exe
----a-w 110,592 2006-01-19 17:06:18 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\bak\mm_tray.exe
----a-w 5,562,368 2007-08-14 00:04:18 c:\program files\MySpace\IM\bak\MySpaceIM.exe
----a-w 8,720,384 2007-12-19 01:47:24 c:\program files\MySpace\IM\MySpaceIM.exe
----a-w 282,624 2006-10-26 00:58:18 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-03-29 04:37:20 c:\program files\QuickTime\QTTask.exe
----a-w 385,024 2005-02-12 13:39:54 c:\program files\Verizon Online\SupportCenter\SmartBridge\bak\MotiveSB.exe
----a-w 15,360 2004-08-04 07:56:48 c:\windows\SYSTEM32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 00:12:16 c:\windows\SYSTEM32\ctfmon.exe
----a-w 28,672 2003-08-13 16:27:40 c:\windows\SYSTEM32\bak\DSentry.exe
----a-w 348,160 2002-11-22 19:48:32 c:\windows\SYSTEM32\bak\hphmon04.exe
----a-w 114,741 2003-08-06 07:04:00 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe
----a-w 176,128 2004-12-14 16:07:44 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb12.exe
Here's the combofix.txt:
ComboFix 09-01-21.01 - Melody Strange 01/21/2009 14:09:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.138 [GMT -6:00]
Running from: c:\documents and settings\Melody Strange\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Melody Strange\Application Data\FunWebProducts
c:\documents and settings\Melody Strange\Application Data\FunWebProducts\kernell32.dll
c:\program files\Altnet
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\adsntfs.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.rvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\cran.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\dbx.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\dbx.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\emalware.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\iso.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\java.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\java.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mbox.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_w95.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mdx_x95.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\mime.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\na.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\nelf.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\nelf.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\pdf.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\rar.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\rup.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\sdx.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\sdx.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\unpack.ivd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\update.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\update.txt.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.cvd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\ve.xmd.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\zip.cab
c:\program files\Altnet\My Altnet Shares\Bullguard Protection\zip.xmd.cab
c:\program files\Need2Find
c:\program files\Need2Find\bar\History\search
c:\windows\IE4 Error Log.txt
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\Cache
c:\windows\system32\Cache\buts.bin
c:\windows\system32\Cache\comp40.bmp
c:\windows\system32\Cache\football.bmp
c:\windows\system32\Cache\msg.bin
c:\windows\system32\Cache\search find 2.bmp
c:\windows\system32\Cache\showbtn12.bmp
c:\windows\system32\Cache\showbtn123.bmp
c:\windows\system32\Cache\showbtn1234.bmp
c:\windows\system32\Cache\showbtn12345.bmp
c:\windows\system32\Cache\showbtn123456.bmp
c:\windows\system32\Cache\slotmachine.bmp
c:\windows\system32\Cache\untitled.bmp
c:\windows\system32\Cache\valentines copy.bmp
c:\windows\system32\Cache\web app.bmp
c:\documents and settings\Tanner and Tori\Application Data\FunWebProducts . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 )))))))))))))))))))))))))))))))
.
2009-01-21 14:00 . 2009-01-21 14:01
2009-01-21 13:06 . 2009-01-21 13:11
2009-01-21 10:49 . 2006-06-16 09:38 102,368 --a------ c:\windows\TrueInstall.exe
2009-01-20 20:07 . 2009-01-20 20:07
2009-01-20 13:02 . 2009-01-20 18:41
2009-01-20 13:02 . 2009-01-20 13:02
2009-01-20 13:02 . 2009-01-20 13:02
2009-01-20 13:02 . 2009-01-14 16:11 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-20 13:02 . 2009-01-14 16:11 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-20 09:32 . 2009-01-20 09:32
2009-01-20 09:23 . 2009-01-20 09:23 52,389 --a------ c:\windows\Sysvxd.exe
2009-01-20 09:12 . 2009-01-20 09:12 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-01-20 09:12 . 2009-01-20 09:12 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-01-20 09:09 . 2009-01-21 14:45 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-20 09:09 . 2009-01-20 09:09 1,409 --a------ c:\windows\QTFont.for
2009-01-19 21:15 . 2009-01-19 21:15
2009-01-05 08:23 . 2009-01-05 08:34
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 20:23 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-21 18:47 --------- d-----w c:\documents and settings\Melody Strange\Application Data\MSN6
2009-01-21 16:47 --------- d-----w c:\program files\Common Files\HP
2009-01-21 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\Napster
2009-01-21 16:24 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-21 16:24 --------- d-----w c:\program files\Design Science
2009-01-21 16:23 --------- d-----w c:\program files\Logitech
2009-01-21 16:22 --------- d-----w c:\program files\Jasc Software Inc
2009-01-21 16:19 --------- d-----w c:\program files\InterActual
2009-01-21 16:16 --------- d-----w c:\program files\Hewlett-Packard
2009-01-21 16:12 --------- d-----w c:\program files\Google
2009-01-21 16:08 --------- d-----w c:\program files\Common Files\AOL
2009-01-21 16:08 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-21 16:07 --------- d-----w c:\program files\Abacast
2009-01-21 01:06 --------- d-----w c:\program files\LimeWire
2009-01-20 15:30 --------- d-----w c:\program files\Common Files\Adobe
2009-01-20 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-01-20 15:18 --------- d-----w c:\program files\Java
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\Digital Album Organizer
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\CyberLink
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\ArcSoft
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\Apple Computer
2009-01-20 02:55 --------- d-----w c:\documents and settings\Melody Strange\Application Data\AdobeUM
2009-01-20 00:05 42,666 ----a-w c:\documents and settings\Melody Strange\Application Data\wklnhst.dat
2009-01-09 03:09 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 03:09 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 03:09 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 03:09 --------- d-----w c:\program files\Symantec
2009-01-05 17:18 --------- d-----w c:\program files\MSN Messenger
2009-01-05 14:23 --------- d-----w c:\program files\Lavasoft
2009-01-05 14:22 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-04 14:30 --------- d-----w c:\program files\MSECache
2008-10-07 03:27 35,630 ----a-w c:\documents and settings\Tanner and Tori\Application Data\wklnhst.dat
2008-06-16 17:47 118,112 ----a-w c:\documents and settings\Melody Strange\Application Data\GDIPFONTCACHEV1.DAT
2007-01-09 04:09 118,112 ----a-w c:\documents and settings\Tanner and Tori\Application Data\GDIPFONTCACHEV1.DAT
2004-10-08 23:30 164 ---ha-w c:\documents and settings\All Users\hpothb07.dat
2008-06-30 18:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-23 00:51 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008082220080823\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 57,344 2005-06-07 05:46:24 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 1,597,440 2004-09-09 23:35:38 c:\program files\AWS\WeatherBug\bak\Weather.exe
----a-w 50,688 2003-12-06 04:08:04 c:\program files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe
----a-w 180,269 2006-03-24 18:27:30 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 110,592 2003-08-19 07:01:00 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
----a-w 204,800 2003-08-27 01:47:34 c:\program files\Dell\Media Experience\bak\PCMService.exe
----a-w 69,632 2002-04-17 16:42:56 c:\program files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe
----a-w 49,152 2004-09-13 21:49:00 c:\program files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe
----a-w 278,528 2005-12-21 02:54:48 c:\program files\iTunes\bak\iTunesHelper.exe
----a-w 267,048 2008-03-30 15:36:40 c:\program files\iTunes\iTunesHelper.exe
----a-w 11,776 2006-01-19 17:06:16 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\bak\mimboot.exe
----a-w 110,592 2006-01-19 17:06:18 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\bak\mm_tray.exe
----a-w 5,562,368 2007-08-14 00:04:18 c:\program files\MySpace\IM\bak\MySpaceIM.exe
----a-w 8,720,384 2007-12-19 01:47:24 c:\program files\MySpace\IM\MySpaceIM.exe
----a-w 282,624 2006-10-26 00:58:18 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-03-29 04:37:20 c:\program files\QuickTime\QTTask.exe
----a-w 385,024 2005-02-12 13:39:54 c:\program files\Verizon Online\SupportCenter\SmartBridge\bak\MotiveSB.exe
----a-w 15,360 2004-08-04 07:56:48 c:\windows\SYSTEM32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 00:12:16 c:\windows\SYSTEM32\ctfmon.exe
----a-w 28,672 2003-08-13 16:27:40 c:\windows\SYSTEM32\bak\DSentry.exe
----a-w 348,160 2002-11-22 19:48:32 c:\windows\SYSTEM32\bak\hphmon04.exe
----a-w 114,741 2003-08-06 07:04:00 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe
----a-w 176,128 2004-12-14 16:07:44 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb12.exe