ComboFix 09-03-29.02 - Jim & Amy 2009-03-30 17:23:18.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1015.304 [GMT -5:00]
Running from: E:\Combo-Fix.exe
Command switches used :: c:\users\Jim & Amy\Desktop\CFScript.txt
* Created a new restore point
.
Error: Cfolders.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AVG
c:\program files\AVG\AVG8\aAvgApi.exe
c:\program files\AVG\AVG8\avg.snu
c:\program files\AVG\AVG8\avg404.txt
c:\program files\AVG\AVG8\avg7api.dll
c:\program files\AVG\AVG8\avg8us.chm
c:\program files\AVG\AVG8\avg8us.lng
c:\program files\AVG\AVG8\avgabout.dll
c:\program files\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgameh.dll
c:\program files\AVG\AVG8\avgamnot.dll
c:\program files\AVG\AVG8\avgapix.dll
c:\program files\AVG\AVG8\avgar8us.chm
c:\program files\AVG\AVG8\avgas8us.chm
c:\program files\AVG\AVG8\avgaspmx.dll
c:\program files\AVG\AVG8\avgatend.stp
c:\program files\AVG\AVG8\avgatupd.stp
c:\program files\AVG\AVG8\avgbat.bav
c:\program files\AVG\AVG8\avgcclix.dll
c:\program files\AVG\AVG8\avgcfgex.exe
c:\program files\AVG\AVG8\avgclitx.dll
c:\program files\AVG\AVG8\avgcmgr.exe
c:\program files\AVG\AVG8\avgcrlpx.dll
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\AVG\AVG8\avgdg8us.chm
c:\program files\AVG\AVG8\avgdiag.dll
c:\program files\AVG\AVG8\avgdiag.exe
c:\program files\AVG\AVG8\avgdiagex.exe
c:\program files\AVG\AVG8\avgdumpx.exe
c:\program files\AVG\AVG8\avgemc.exe
c:\program files\AVG\AVG8\avgfrw.exe
c:\program files\AVG\AVG8\avgfw8fd.ini
c:\program files\AVG\AVG8\avgfw8us.chm
c:\program files\AVG\AVG8\avgfwui.dll
c:\program files\AVG\AVG8\avgfwwiz.dll
c:\program files\AVG\AVG8\avgfwwiz.exe
c:\program files\AVG\AVG8\avginet.dll
c:\program files\AVG\AVG8\avgiproxy.exe
c:\program files\AVG\AVG8\avglngx.dll
c:\program files\AVG\AVG8\avgmail.dll
c:\program files\AVG\AVG8\avgmvflx.dll
c:\program files\AVG\AVG8\avgmwdef_us.mht
c:\program files\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgoff2k.dll
c:\program files\AVG\AVG8\avgpp.dll
c:\program files\AVG\AVG8\avgresf.dll
c:\program files\AVG\AVG8\avgrktx.dll
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgscanx.dll
c:\program files\AVG\AVG8\avgscanx.exe
c:\program files\AVG\AVG8\avgsched.dll
c:\program files\AVG\AVG8\avgse.dll
c:\program files\AVG\AVG8\avgspmui.dll
c:\program files\AVG\AVG8\avgsrmax.exe
c:\program files\AVG\AVG8\avgsrmx.dll
c:\program files\AVG\AVG8\avgssie.dll
c:\program files\AVG\AVG8\avgst8us.chm
c:\program files\AVG\AVG8\avgstrmx.exe
c:\program files\AVG\AVG8\avgsystx.exe
c:\program files\AVG\AVG8\avgtbapi.dll
c:\program files\AVG\AVG8\avgtbas.tbp
c:\program files\AVG\AVG8\avgtoolbar.dll
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\AVG\AVG8\avgui.exe
c:\program files\AVG\AVG8\avguiadv.dll
c:\program files\AVG\AVG8\avguires.dll
c:\program files\AVG\AVG8\avgupd.dll
c:\program files\AVG\AVG8\avgupd.exe
c:\program files\AVG\AVG8\avgvvx.dll
c:\program files\AVG\AVG8\avgwdsvc.exe
c:\program files\AVG\AVG8\avgwdwsc.dll
c:\program files\AVG\AVG8\avgwebui.dll
c:\program files\AVG\AVG8\avgwsc.exe
c:\program files\AVG\AVG8\avgxpl.dll
c:\program files\AVG\AVG8\cf.dat
c:\program files\AVG\AVG8\contacts_us.html
c:\program files\AVG\AVG8\dbghelp.dll
c:\program files\AVG\AVG8\dfncfg.dat
c:\program files\AVG\AVG8\Drivers\avgfwd6\avgfwd6a.sys
c:\program files\AVG\AVG8\Drivers\avgfwd6\avgfwd6x.sys
c:\program files\AVG\AVG8\Drivers\avgfwd6\avgfwfd6.cat
c:\program files\AVG\AVG8\Drivers\avgfwd6\avgfwfd6.inf
c:\program files\AVG\AVG8\fixcfg.exe
c:\program files\AVG\AVG8\Icons\background_middle_gray.gif
c:\program files\AVG\AVG8\Icons\background_middle_green.gif
c:\program files\AVG\AVG8\Icons\background_middle_orange.gif
c:\program files\AVG\AVG8\Icons\background_middle_red.gif
c:\program files\AVG\AVG8\Icons\background_middle_yellow.gif
c:\program files\AVG\AVG8\Icons\background_top_gray.gif
c:\program files\AVG\AVG8\Icons\background_top_green.gif
c:\program files\AVG\AVG8\Icons\background_top_orange.gif
c:\program files\AVG\AVG8\Icons\background_top_red.gif
c:\program files\AVG\AVG8\Icons\background_top_yellow.gif
c:\program files\AVG\AVG8\Icons\block-doc.gif
c:\program files\AVG\AVG8\Icons\blocked.gif
c:\program files\AVG\AVG8\Icons\border_bottom_gray.gif
c:\program files\AVG\AVG8\Icons\border_bottom_green.gif
c:\program files\AVG\AVG8\Icons\border_bottom_orange.gif
c:\program files\AVG\AVG8\Icons\border_bottom_red.gif
c:\program files\AVG\AVG8\Icons\border_bottom_yellow.gif
c:\program files\AVG\AVG8\Icons\border_top_gray.gif
c:\program files\AVG\AVG8\Icons\border_top_green.gif
c:\program files\AVG\AVG8\Icons\border_top_orange.gif
c:\program files\AVG\AVG8\Icons\border_top_red.gif
c:\program files\AVG\AVG8\Icons\border_top_yellow.gif
c:\program files\AVG\AVG8\Icons\box_bottom_red.gif
c:\program files\AVG\AVG8\Icons\box_top_red.gif
c:\program files\AVG\AVG8\Icons\caution.gif
c:\program files\AVG\AVG8\Icons\click_here_gray.gif
c:\program files\AVG\AVG8\Icons\click_here_green.gif
c:\program files\AVG\AVG8\Icons\click_here_orange.gif
c:\program files\AVG\AVG8\Icons\click_here_red.gif
c:\program files\AVG\AVG8\Icons\click_here_yellow.gif
c:\program files\AVG\AVG8\Icons\clock.gif
c:\program files\AVG\AVG8\Icons\close.gif
c:\program files\AVG\AVG8\Icons\icons_blocked.gif
c:\program files\AVG\AVG8\Icons\icons_caution.gif
c:\program files\AVG\AVG8\Icons\icons_close.gif
c:\program files\AVG\AVG8\Icons\icons_safe.gif
c:\program files\AVG\AVG8\Icons\icons_unknown.gif
c:\program files\AVG\AVG8\Icons\icons_warning.gif
c:\program files\AVG\AVG8\Icons\LS_Logo_Results.gif
c:\program files\AVG\AVG8\Icons\safe.gif
c:\program files\AVG\AVG8\Icons\unknown.gif
c:\program files\AVG\AVG8\Icons\warning.gif
c:\program files\AVG\AVG8\imsdk32.dll
c:\program files\AVG\AVG8\libsasl.dll
c:\program files\AVG\AVG8\license_us.txt
c:\program files\AVG\AVG8\ph.dat
c:\program files\AVG\AVG8\saslcrammd5.dll
c:\program files\AVG\AVG8\sasldigestmd5.dll
c:\program files\AVG\AVG8\sasllogin.dll
c:\program files\AVG\AVG8\saslplain.dll
c:\program files\AVG\AVG8\sb.dat
c:\program files\AVG\AVG8\sb.dat.xcd
c:\program files\AVG\AVG8\sb2.dat
c:\program files\AVG\AVG8\sc.dat
c:\program files\AVG\AVG8\sc.dat.xcd
c:\program files\AVG\AVG8\setupus.lns
c:\program files\AVG\AVG8\ToolbarIEcache\avglinks.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\avglogo.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\avgstatus.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\avgstatus_error.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\avgtoolbartb0502.cfg
c:\program files\AVG\AVG8\ToolbarIEcache\brandlogo.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\p_yahoo.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesearch.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesearch_off.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesearch_on.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesurf.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesurf_off.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\safesurf_on.bmp
c:\program files\AVG\AVG8\ToolbarIEcache\slider.bmp
c:\program files\AVG\AVG8\winspamcatcher.dll
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\FunWebProducts
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\programdata\avg8
c:\programdata\avg8\Antispam\productid
c:\programdata\avg8\Antispam\rkd
c:\programdata\avg8\Antispam\sc1.bin
c:\programdata\avg8\Antispam\sc1.bin.full.2009.03.26.05.22.59
c:\programdata\avg8\Antispam\sc1.bin.full.2009.03.26.05.22.59.lkr1
c:\programdata\avg8\Antispam\sc1.bin.tmp
c:\programdata\avg8\Antispam\sc14.bin.full.2006.06.27.17.01.01
c:\programdata\avg8\Antispam\sc18.bin.full.2008.12.11.02.26.00
c:\programdata\avg8\Antispam\sc18.bin.full.2008.12.11.02.26.00.lkr1
c:\programdata\avg8\Antispam\sc18.bin.tmp1
c:\programdata\avg8\Antispam\sc18.bin.tmp2
c:\programdata\avg8\Antispam\sc2.bin
c:\programdata\avg8\Antispam\sc2.bin.full.2005.02.11.04.44.13
c:\programdata\avg8\Antispam\sc2.bin.full.2005.02.11.04.44.13.lkr1
c:\programdata\avg8\Antispam\sc5.bin.full.2007.01.28.16.09.00
c:\programdata\avg8\Antispam\sc5.bin.full.2007.01.28.16.09.00.lkr1
c:\programdata\avg8\Antispam\sc6.bin.full.2007.02.13.01.23.26
c:\programdata\avg8\Antispam\scdns.bin
c:\programdata\avg8\Antispam\scoffset.bin.incr
c:\programdata\avg8\Antispam\spamcatcher.conf
c:\programdata\avg8\AvgAm\avgam.lck
c:\programdata\avg8\Cfg\krnl.cfg
c:\programdata\avg8\Cfg\mail.cfg
c:\programdata\avg8\Cfg\malrep.cfg
c:\programdata\avg8\Cfg\scan.cfg
c:\programdata\avg8\Cfg\sched.cfg
c:\programdata\avg8\Cfg\setup.cfg
c:\programdata\avg8\Cfg\update.cfg
c:\programdata\avg8\Cfg\updatecomps.cfg.old
c:\programdata\avg8\Cfg\user.cfg
c:\programdata\avg8\CfgAll\changecfgreg.cfg
c:\programdata\avg8\CfgAll\fw.cfg
c:\programdata\avg8\CfgAll\updateall.cfg
c:\programdata\avg8\emc\Log\emc.log
c:\programdata\avg8\Log\amlog.cfg
c:\programdata\avg8\Log\avgam.log
c:\programdata\avg8\Log\avgam.log.lock
c:\programdata\avg8\Log\avgcore.log
c:\programdata\avg8\Log\avgcore.log.1
c:\programdata\avg8\Log\avgcore.log.10
c:\programdata\avg8\Log\avgcore.log.2
c:\programdata\avg8\Log\avgcore.log.3
c:\programdata\avg8\Log\avgcore.log.4
c:\programdata\avg8\Log\avgcore.log.5
c:\programdata\avg8\Log\avgcore.log.6
c:\programdata\avg8\Log\avgcore.log.7
c:\programdata\avg8\Log\avgcore.log.8
c:\programdata\avg8\Log\avgcore.log.9
c:\programdata\avg8\Log\avgcore.log.lock
c:\programdata\avg8\Log\avgfrw.log
c:\programdata\avg8\Log\avgfrw.log.lock
c:\programdata\avg8\Log\avgfw8u.log
c:\programdata\avg8\Log\avgfw8u.log.1
c:\programdata\avg8\Log\avgfw8u.log.2
c:\programdata\avg8\Log\avgfw8u.log.3
c:\programdata\avg8\Log\avgfw8u.log.4
c:\programdata\avg8\Log\avgfw8u.log.lock
c:\programdata\avg8\Log\avgldr.log
c:\programdata\avg8\Log\avgldr.log.lock
c:\programdata\avg8\Log\avglng.log
c:\programdata\avg8\Log\avglng.log.lock
c:\programdata\avg8\Log\avgns.log
c:\programdata\avg8\Log\avgns.log.1
c:\programdata\avg8\Log\avgns.log.lock
c:\programdata\avg8\Log\avgrs.log
c:\programdata\avg8\Log\avgrs.log.1
c:\programdata\avg8\Log\avgrs.log.2
c:\programdata\avg8\Log\avgrs.log.lock
c:\programdata\avg8\Log\avgscan.log
c:\programdata\avg8\Log\avgscan.log.lock
c:\programdata\avg8\Log\avgsched.log
c:\programdata\avg8\Log\avgsched.log.1
c:\programdata\avg8\Log\avgsched.log.2
c:\programdata\avg8\Log\avgsched.log.3
c:\programdata\avg8\Log\avgsched.log.4
c:\programdata\avg8\Log\avgsched.log.5
c:\programdata\avg8\Log\avgsched.log.lock
c:\programdata\avg8\Log\avgsrm.log
c:\programdata\avg8\Log\avgsrm.log.lock
c:\programdata\avg8\Log\avgui.log
c:\programdata\avg8\Log\avgui.log.lock
c:\programdata\avg8\Log\avguilog.cfg
c:\programdata\avg8\Log\avgupd.log
c:\programdata\avg8\Log\avgupd.log.lock
c:\programdata\avg8\Log\avgwd.log
c:\programdata\avg8\Log\avgwd.log.1
c:\programdata\avg8\Log\avgwd.log.lock
c:\programdata\avg8\Log\avgwdsvc.log
c:\programdata\avg8\Log\avgwdsvc.log.lock
c:\programdata\avg8\Log\cfgexlog.cfg
c:\programdata\avg8\Log\cfglog.cfg
c:\programdata\avg8\Log\commonpriv.log
c:\programdata\avg8\Log\commonpriv.log.lock
c:\programdata\avg8\Log\commonpub.log
c:\programdata\avg8\Log\commonpub.log.lock
c:\programdata\avg8\Log\corelog.cfg
c:\programdata\avg8\Log\fixcfg.log
c:\programdata\avg8\Log\fixcfg.log.lock
c:\programdata\avg8\Log\history.xml
c:\programdata\avg8\Log\ldrlog.cfg
c:\programdata\avg8\Log\lnglog.cfg
c:\programdata\avg8\Log\nslog.cfg
c:\programdata\avg8\Log\privlog.cfg
c:\programdata\avg8\Log\publog.cfg
c:\programdata\avg8\Log\rslog.cfg
c:\programdata\avg8\Log\scanlog.cfg
c:\programdata\avg8\Log\schedlog.cfg
c:\programdata\avg8\Log\srmlog.cfg
c:\programdata\avg8\Log\systoolslog.cfg
c:\programdata\avg8\Log\updlog.cfg
c:\programdata\avg8\Log\vaultlog.cfg
c:\programdata\avg8\Log\wdlog.cfg
c:\programdata\avg8\Log\wdsvclog.cfg
c:\programdata\avg8\scanlogs\I_00000005.log
c:\programdata\avg8\scanlogs\I_00000006.log
c:\programdata\avg8\scanlogs\I_00000007.log
c:\programdata\avg8\scanlogs\I_00000008.log
c:\programdata\avg8\scanlogs\I_00000009.log
c:\programdata\avg8\scanlogs\I_00000010.log
c:\programdata\avg8\scanlogs\I_00000011.log
c:\programdata\avg8\scanlogs\I_00000012.log
c:\programdata\avg8\scanlogs\srm.idx
c:\programdata\avg8\update\backup\avginet.dll
c:\programdata\avg8\update\backup\avgiproxy.exe
c:\programdata\avg8\update\backup\avgtdix.sys
c:\programdata\avg8\update\backup\avgupd.dll
c:\programdata\avg8\update\backup\avgupd.exe
c:\programdata\avg8\update\backup\incavi.avm
c:\programdata\avg8\update\backup\sb.dat
c:\programdata\avg8\update\backup\sb2.dat
c:\programdata\avg8\update\backup\sc.dat
c:\programdata\avg8\update\download\avginfoavi.ctf
c:\programdata\avg8\update\download\avginfowin.ctf
c:\programdata\avg8\update\download\u7avi1448u1435sc.bin
c:\programdata\avg8\update\download\u7avi1450u1435dv.bin
c:\programdata\avg8\update\download\u7avi1451u1435q4.bin
c:\programdata\avg8\update\download\u7avi1452u1435fs.bin
c:\programdata\avg8\update\download\u7avi1453u1435pt.bin
c:\programdata\avg8\update\download\u7avi1454u1435k.bin
c:\programdata\avg8\update\download\u7avi1464u1435q8.bin
c:\programdata\avg8\update\download\u7avi1465u1435w9.bin
c:\programdata\avg8\update\download\u7avi1466u1435y9.bin
c:\programdata\avg8\update\download\u7iavi2001u1971y2.bin
c:\programdata\avg8\update\download\u7iavi2003u2001dv.bin
c:\programdata\avg8\update\download\u7iavi2004u200365.bin
c:\programdata\avg8\update\download\u7iavi2006u2004au.bin
c:\programdata\avg8\update\download\u7iavi2007u2006ft.bin
c:\programdata\avg8\update\download\u7iavi2008u2007pu.bin
c:\programdata\avg8\update\download\u7iavi2009u2008el.bin
c:\programdata\avg8\update\download\u7iavi2010u2009k.bin
c:\programdata\avg8\update\download\u7iavi2011u2010i9.bin
c:\programdata\avg8\update\download\u7iavi2024u2004b0.bin
c:\programdata\avg8\update\download\u7iavi2025u2024w9.bin
c:\programdata\avg8\update\download\u7iavi2026u2025eq.bin
c:\programdata\avg8\update\download\u7iavi2027u2026ya.bin
c:\programdata\avg8\update\download\u7iavi2028u2027iv.bin
c:\programdata\avg8\update\download\w8core281r2737d.bin
c:\programdata\avg8\update\download\w8fw284r26862.bin
c:\programdata\avg8\update\download\w8hlpus277r2737o.bin
c:\programdata\avg8\update\download\w8krnl284r27662.bin
c:\programdata\avg8\update\download\w8setup2807a.bin
c:\programdata\avg8\update\download\w8tdix284r26662.bin
c:\programdata\avg8\update\download\w8upd283r276us.bin
c:\programdata\avg8\update\download\x8xplsb_45d432a.bin
c:\programdata\avg8\update\download\x8xplsb2_553k.bin
c:\programdata\avg8\update\download\x8xplsb2_56es.bin
c:\programdata\avg8\update\download\x8xplsb2_60a1.bin
c:\programdata\avg8\update\download\x8xplsc_68d65mb.bin
c:\programdata\avg8\update\download\x8xplsc_69d68ol.bin
c:\programdata\avg8\update\prepare\incavi.avm
c:\programdata\avg8\update\prepare\sb.dat.prepare
c:\programdata\avg8\update\prepare\sc.dat.prepare
c:\programdata\Symantec
c:\programdata\Symantec\LiveUpdate\Settings.LiveUpdate
c:\users\All Users\avg8\Antispam\productid
c:\users\All Users\avg8\Antispam\rkd
c:\users\All Users\avg8\Antispam\sc1.bin
c:\users\All Users\avg8\Antispam\sc1.bin.full.2009.03.26.05.22.59
c:\users\All Users\avg8\Antispam\sc1.bin.full.2009.03.26.05.22.59.lkr1
c:\users\All Users\avg8\Antispam\sc1.bin.tmp
c:\users\All Users\avg8\Antispam\sc14.bin.full.2006.06.27.17.01.01
c:\users\All Users\avg8\Antispam\sc18.bin.full.2008.12.11.02.26.00
c:\users\All Users\avg8\Antispam\sc18.bin.full.2008.12.11.02.26.00.lkr1
c:\users\All Users\avg8\Antispam\sc18.bin.tmp1
c:\users\All Users\avg8\Antispam\sc18.bin.tmp2
c:\users\All Users\avg8\Antispam\sc2.bin
c:\users\All Users\avg8\Antispam\sc2.bin.full.2005.02.11.04.44.13
c:\users\All Users\avg8\Antispam\sc2.bin.full.2005.02.11.04.44.13.lkr1
c:\users\All Users\avg8\Antispam\sc5.bin.full.2007.01.28.16.09.00
c:\users\All Users\avg8\Antispam\sc5.bin.full.2007.01.28.16.09.00.lkr1
c:\users\All Users\avg8\Antispam\sc6.bin.full.2007.02.13.01.23.26
c:\users\All Users\avg8\Antispam\scdns.bin
c:\users\All Users\avg8\Antispam\scoffset.bin.incr
c:\users\All Users\avg8\Antispam\spamcatcher.conf
c:\users\All Users\avg8\AvgAm\avgam.lck
c:\users\All Users\avg8\Cfg\krnl.cfg
c:\users\All Users\avg8\Cfg\mail.cfg
c:\users\All Users\avg8\Cfg\malrep.cfg
c:\users\All Users\avg8\Cfg\scan.cfg
c:\users\All Users\avg8\Cfg\sched.cfg
c:\users\All Users\avg8\Cfg\setup.cfg
c:\users\All Users\avg8\Cfg\update.cfg
c:\users\All Users\avg8\Cfg\updatecomps.cfg.old
c:\users\All Users\avg8\Cfg\user.cfg
c:\users\All Users\avg8\CfgAll\changecfgreg.cfg
c:\users\All Users\avg8\CfgAll\fw.cfg
c:\users\All Users\avg8\CfgAll\updateall.cfg
c:\users\All Users\avg8\emc\Log\emc.log
c:\users\All Users\avg8\Log\amlog.cfg
c:\users\All Users\avg8\Log\avgam.log
c:\users\All Users\avg8\Log\avgam.log.lock
c:\users\All Users\avg8\Log\avgcore.log
c:\users\All Users\avg8\Log\avgcore.log.1
c:\users\All Users\avg8\Log\avgcore.log.10
c:\users\All Users\avg8\Log\avgcore.log.2
c:\users\All Users\avg8\Log\avgcore.log.3
c:\users\All Users\avg8\Log\avgcore.log.4
c:\users\All Users\avg8\Log\avgcore.log.5
c:\users\All Users\avg8\Log\avgcore.log.6
c:\users\All Users\avg8\Log\avgcore.log.7
c:\users\All Users\avg8\Log\avgcore.log.8
c:\users\All Users\avg8\Log\avgcore.log.9
c:\users\All Users\avg8\Log\avgcore.log.lock
c:\users\All Users\avg8\Log\avgfrw.log
c:\users\All Users\avg8\Log\avgfrw.log.lock
c:\users\All Users\avg8\Log\avgfw8u.log
c:\users\All Users\avg8\Log\avgfw8u.log.1
c:\users\All Users\avg8\Log\avgfw8u.log.2
c:\users\All Users\avg8\Log\avgfw8u.log.3
c:\users\All Users\avg8\Log\avgfw8u.log.4
c:\users\All Users\avg8\Log\avgfw8u.log.lock
c:\users\All Users\avg8\Log\avgldr.log
c:\users\All Users\avg8\Log\avgldr.log.lock
c:\users\All Users\avg8\Log\avglng.log
c:\users\All Users\avg8\Log\avglng.log.lock
c:\users\All Users\avg8\Log\avgns.log
c:\users\All Users\avg8\Log\avgns.log.1
c:\users\All Users\avg8\Log\avgns.log.lock
c:\users\All Users\avg8\Log\avgrs.log
c:\users\All Users\avg8\Log\avgrs.log.1
c:\users\All Users\avg8\Log\avgrs.log.2
c:\users\All Users\avg8\Log\avgrs.log.lock
c:\users\All Users\avg8\Log\avgscan.log
c:\users\All Users\avg8\Log\avgscan.log.lock
c:\users\All Users\avg8\Log\avgsched.log
c:\users\All Users\avg8\Log\avgsched.log.1
c:\users\All Users\avg8\Log\avgsched.log.2
c:\users\All Users\avg8\Log\avgsched.log.3
c:\users\All Users\avg8\Log\avgsched.log.4
c:\users\All Users\avg8\Log\avgsched.log.5
c:\users\All Users\avg8\Log\avgsched.log.lock
c:\users\All Users\avg8\Log\avgsrm.log
c:\users\All Users\avg8\Log\avgsrm.log.lock
c:\users\All Users\avg8\Log\avgui.log
c:\users\All Users\avg8\Log\avgui.log.lock
c:\users\All Users\avg8\Log\avguilog.cfg
c:\users\All Users\avg8\Log\avgupd.log
c:\users\All Users\avg8\Log\avgupd.log.lock
c:\users\All Users\avg8\Log\avgwd.log
c:\users\All Users\avg8\Log\avgwd.log.1
c:\users\All Users\avg8\Log\avgwd.log.lock
c:\users\All Users\avg8\Log\avgwdsvc.log
c:\users\All Users\avg8\Log\avgwdsvc.log.lock
c:\users\All Users\avg8\Log\cfgexlog.cfg
c:\users\All Users\avg8\Log\cfglog.cfg
c:\users\All Users\avg8\Log\commonpriv.log
c:\users\All Users\avg8\Log\commonpriv.log.lock
c:\users\All Users\avg8\Log\commonpub.log
c:\users\All Users\avg8\Log\commonpub.log.lock
c:\users\All Users\avg8\Log\corelog.cfg
c:\users\All Users\avg8\Log\fixcfg.log
c:\users\All Users\avg8\Log\fixcfg.log.lock
c:\users\All Users\avg8\Log\history.xml
c:\users\All Users\avg8\Log\ldrlog.cfg
c:\users\All Users\avg8\Log\lnglog.cfg
c:\users\All Users\avg8\Log\nslog.cfg
c:\users\All Users\avg8\Log\privlog.cfg
c:\users\All Users\avg8\Log\publog.cfg
c:\users\All Users\avg8\Log\rslog.cfg
c:\users\All Users\avg8\Log\scanlog.cfg
c:\users\All Users\avg8\Log\schedlog.cfg
c:\users\All Users\avg8\Log\srmlog.cfg
c:\users\All Users\avg8\Log\systoolslog.cfg
c:\users\All Users\avg8\Log\updlog.cfg
c:\users\All Users\avg8\Log\vaultlog.cfg
c:\users\All Users\avg8\Log\wdlog.cfg
c:\users\All Users\avg8\Log\wdsvclog.cfg
c:\users\All Users\avg8\scanlogs\I_00000005.log
c:\users\All Users\avg8\scanlogs\I_00000006.log
c:\users\All Users\avg8\scanlogs\I_00000007.log
c:\users\All Users\avg8\scanlogs\I_00000008.log
c:\users\All Users\avg8\scanlogs\I_00000009.log
c:\users\All Users\avg8\scanlogs\I_00000010.log
c:\users\All Users\avg8\scanlogs\I_00000011.log
c:\users\All Users\avg8\scanlogs\I_00000012.log
c:\users\All Users\avg8\scanlogs\srm.idx
c:\users\All Users\avg8\update\backup\avginet.dll
c:\users\All Users\avg8\update\backup\avgiproxy.exe
c:\users\All Users\avg8\update\backup\avgtdix.sys
c:\users\All Users\avg8\update\backup\avgupd.dll
c:\users\All Users\avg8\update\backup\avgupd.exe
c:\users\All Users\avg8\update\backup\incavi.avm
c:\users\All Users\avg8\update\backup\sb.dat
c:\users\All Users\avg8\update\backup\sb2.dat
c:\users\All Users\avg8\update\backup\sc.dat
c:\users\All Users\avg8\update\download\avginfoavi.ctf
c:\users\All Users\avg8\update\download\avginfowin.ctf
c:\users\All Users\avg8\update\download\u7avi1448u1435sc.bin
c:\users\All Users\avg8\update\download\u7avi1450u1435dv.bin
c:\users\All Users\avg8\update\download\u7avi1451u1435q4.bin
c:\users\All Users\avg8\update\download\u7avi1452u1435fs.bin
c:\users\All Users\avg8\update\download\u7avi1453u1435pt.bin
c:\users\All Users\avg8\update\download\u7avi1454u1435k.bin
c:\users\All Users\avg8\update\download\u7avi1464u1435q8.bin
c:\users\All Users\avg8\update\download\u7avi1465u1435w9.bin
c:\users\All Users\avg8\update\download\u7avi1466u1435y9.bin
c:\users\All Users\avg8\update\download\u7iavi2001u1971y2.bin
c:\users\All Users\avg8\update\download\u7iavi2003u2001dv.bin
c:\users\All Users\avg8\update\download\u7iavi2004u200365.bin
c:\users\All Users\avg8\update\download\u7iavi2006u2004au.bin
c:\users\All Users\avg8\update\download\u7iavi2007u2006ft.bin
c:\users\All Users\avg8\update\download\u7iavi2008u2007pu.bin
c:\users\All Users\avg8\update\download\u7iavi2009u2008el.bin
c:\users\All Users\avg8\update\download\u7iavi2010u2009k.bin
c:\users\All Users\avg8\update\download\u7iavi2011u2010i9.bin
c:\users\All Users\avg8\update\download\u7iavi2024u2004b0.bin
c:\users\All Users\avg8\update\download\u7iavi2025u2024w9.bin
c:\users\All Users\avg8\update\download\u7iavi2026u2025eq.bin
c:\users\All Users\avg8\update\download\u7iavi2027u2026ya.bin
c:\users\All Users\avg8\update\download\u7iavi2028u2027iv.bin
c:\users\All Users\avg8\update\download\w8core281r2737d.bin
c:\users\All Users\avg8\update\download\w8fw284r26862.bin
c:\users\All Users\avg8\update\download\w8hlpus277r2737o.bin
c:\users\All Users\avg8\update\download\w8krnl284r27662.bin
c:\users\All Users\avg8\update\download\w8setup2807a.bin
c:\users\All Users\avg8\update\download\w8tdix284r26662.bin
c:\users\All Users\avg8\update\download\w8upd283r276us.bin
c:\users\All Users\avg8\update\download\x8xplsb_45d432a.bin
c:\users\All Users\avg8\update\download\x8xplsb2_553k.bin
c:\users\All Users\avg8\update\download\x8xplsb2_56es.bin
c:\users\All Users\avg8\update\download\x8xplsb2_60a1.bin
c:\users\All Users\avg8\update\download\x8xplsc_68d65mb.bin
c:\users\All Users\avg8\update\download\x8xplsc_69d68ol.bin
c:\users\All Users\avg8\update\prepare\incavi.avm
c:\users\All Users\avg8\update\prepare\sb.dat.prepare
c:\users\All Users\avg8\update\prepare\sc.dat.prepare
c:\users\Jim & Amy\AppData\Roaming\aAvgApi
c:\users\Jim & Amy\AppData\Roaming\aAvgApi\avgapi.log
c:\windows\System32\drivers\Avg
c:\windows\System32\drivers\Avg\avi7.avg
c:\windows\System32\drivers\Avg\incavi.avm
c:\windows\System32\drivers\Avg\microavi.avg
c:\windows\System32\drivers\Avg\miniavi.avg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AVGFWFD
-------\Legacy_AVGLDX86
-------\Legacy_AVGRKX86
-------\Legacy_AVGTDIX
-------\Service_avg8emc
-------\Service_avg8wd
-------\Service_Avgfwfd
-------\Service_avgfws8
-------\Service_AvgLdx86
-------\Service_AvgRkx86
-------\Service_AvgTdiX
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.
2009-03-29 19:15 . 2009-03-29 19:19 <DIR> d-------- C:\4676
2009-03-29 19:07 . 2009-03-29 19:08 <DIR> d-------- C:\3341
2009-03-29 19:06 . 2009-03-30 17:19 <DIR> d-------- C:\Tools-AV
2009-03-28 23:12 . 2009-03-28 23:12 <DIR> d-------- c:\windows\System32\Adobe
2009-03-28 20:48 . 2008-06-19 20:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-03-28 20:48 . 2008-06-19 20:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-03-28 20:48 . 2008-06-19 20:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-03-28 20:48 . 2008-06-19 20:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-03-28 20:48 . 2008-06-19 20:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-03-28 20:48 . 2008-06-19 20:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-03-28 20:48 . 2008-06-19 20:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-03-28 20:48 . 2008-06-19 20:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-03-28 19:02 . 2008-07-27 13:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-03-28 19:02 . 2008-07-27 13:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-03-28 19:02 . 2008-07-27 13:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-03-28 19:02 . 2008-07-27 13:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-03-28 19:02 . 2008-07-27 13:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-03-27 17:09 . 2009-03-27 17:09 <DIR> d-------- c:\program files\Real
2009-03-25 19:51 . 2009-03-25 19:58 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-03-23 11:15 . 2009-03-23 11:15 <DIR> d-------- c:\users\Jim & Amy\AppData\Roaming\Amazon
2009-03-23 11:05 . 2009-03-23 11:05 <DIR> d-------- c:\program files\Amazon
2009-03-19 21:42 . 2009-03-19 21:42 <DIR> d-------- c:\program files\iPod
2009-03-19 21:42 . 2008-04-17 12:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2009-03-19 21:42 . 2009-01-15 12:19 23,848 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2009-03-19 21:41 . 2009-03-19 21:42 <DIR> d-------- c:\users\All Users\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-19 21:41 . 2009-03-19 21:42 <DIR> d-------- c:\programdata\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-19 21:18 . 2009-03-19 21:18 <DIR> d-------- c:\program files\Bonjour
2009-03-19 12:25 . 2009-03-19 12:25 <DIR> d-------- c:\users\Jim & Amy\AppData\Roaming\eMusic
2009-03-19 12:25 . 2009-03-19 12:25 <DIR> d-------- c:\program files\eMusic
2009-03-19 12:25 . 2009-03-19 12:25 <DIR> d-------- c:\program files\Conduit
2009-03-19 12:23 . 2009-03-19 12:23 <DIR> d-------- c:\program files\eMusic Download Manager
2009-03-17 07:01 . 2009-03-26 07:41 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-14 18:36 . 2009-03-14 18:36 <DIR> d-------- c:\users\All Users\Downloaded Installations
2009-03-14 18:36 . 2009-03-14 18:36 <DIR> d-------- c:\programdata\Downloaded Installations
2009-03-14 18:35 . 2009-03-14 18:35 325,640 --a------ c:\windows\System32\drivers\avgldx86.sys
2009-03-14 18:35 . 2009-03-26 09:10 108,552 --a------ c:\windows\System32\drivers\avgtdix.sys
2009-03-14 18:35 . 2009-03-14 18:35 12,552 --a------ c:\windows\System32\drivers\avgrkx86.sys
2009-03-14 18:35 . 2009-03-14 18:35 10,520 --a------ c:\windows\System32\avgrsstx.dll
2009-03-14 18:33 . 2009-03-14 18:33 23,832 --a------ c:\windows\System32\drivers\avgfwd6x.sys
2009-03-11 13:10 . 2008-12-15 22:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 13:10 . 2009-02-08 22:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 13:10 . 2008-11-26 23:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-11 13:10 . 2008-12-16 00:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 13:10 . 2008-12-16 00:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 13:10 . 2008-12-16 00:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-05 23:59 . 2009-03-05 23:59 1,900,544 --a------ c:\windows\System32\usbaaplrc.dll
2009-03-05 23:59 . 2009-03-05 23:59 36,864 --a------ c:\windows\System32\drivers\usbaapl.sys
2009-02-15 22:36 . 2008-12-04 23:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-15 22:36 . 2008-12-04 23:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-15 22:36 . 2008-12-04 23:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-15 22:36 . 2008-12-04 23:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-15 22:36 . 2008-12-04 23:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-13 23:22 . 2009-02-13 23:22 <DIR> d-------- c:\users\Jim & Amy\AppData\Roaming\Home Sweet Home 2
2009-02-13 05:07 . 2009-02-13 05:55 <DIR> d-------- c:\users\Jim & Amy\AppData\Roaming\iWin_JanesRealty
2009-02-11 00:22 . 2009-01-14 22:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 00:22 . 2009-01-15 01:11 827,392 --a------ c:\windows\System32\wininet.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 15:43 --------- d-----w c:\program files\CONEXANT
2009-03-29 00:10 --------- d-----w c:\program files\Java
2009-03-20 02:42 --------- d-----w c:\program files\iTunes
2009-03-20 02:42 --------- d-----w c:\program files\Common Files\Apple
2009-03-12 18:19 --------- d-----w c:\program files\Windows Mail
2009-02-14 04:48 --------- d---a-w c:\programdata\TEMP
2009-02-14 04:21 --------- d-----w c:\program files\iWin.com
2009-02-05 14:01 --------- d-----w c:\programdata\CanonIJPLM
2009-02-03 05:29 --------- d-----w c:\program files\EA GAMES
2009-01-28 00:23 --------- d-----w c:\users\Jim & Amy\AppData\Roaming\Apple Computer
2009-01-28 00:22 --------- d-----w c:\programdata\Apple Computer
2009-01-28 00:20 --------- d-----w c:\program files\QuickTime
2009-01-28 00:17 --------- d-----w c:\program files\Apple Software Update
2009-01-28 00:16 --------- d-----w c:\programdata\Apple
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\Downloaded Installations ----
2009-03-14 18:36 7775232 --a------ c:\programdata\Downloaded Installations\{49AD8D2A-1643-458B-9EE7-7C091FDE10A5}\AVG_IDS_setup.msi
---- Directory of c:\users\All Users\Downloaded Installations ----
2009-03-14 18:36 7775232 --a------ c:\users\All Users\Downloaded Installations\{49AD8D2A-1643-458B-9EE7-7C091FDE10A5}\AVG_IDS_setup.msi
---- Directory of c:\users\Jim & Amy\AppData\Roaming\Home Sweet Home 2 ----
2009-02-13 23:47 477 --a------ c:\users\Jim & Amy\AppData\Roaming\Home Sweet Home 2\profile_0.dat
2009-02-13 23:46 10056 --a------ c:\users\Jim & Amy\AppData\Roaming\Home Sweet Home 2\amy0\layouts.dat
2009-02-13 23:41 422 --a------ c:\users\Jim & Amy\AppData\Roaming\Home Sweet Home 2\amy0\my_portfolio_scrapbook.dat
((((((((((((((((((((((((((((( SnapShot@2009-03-30_ 4.06.08.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 22:31:52 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-03-30 16:56:57 51,200 ----a-w c:\windows\inf\infpub.dat
- 2009-03-29 22:31:52 86,016 ----a-w c:\windows\inf\infstrng.dat
+ 2009-03-30 16:56:56 86,016 ----a-w c:\windows\inf\infstrng.dat
- 2009-03-30 09:02:27 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-30 22:29:05 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-03-30 09:02:26 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-30 22:29:08 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-03-30 08:56:57 101,144 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-30 09:07:54 101,144 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-30 08:56:57 595,446 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-30 09:07:54 595,446 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-30 08:51:24 5,900 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4043121322-1403154492-1806109776-1000_UserData.bin
+ 2009-03-30 09:03:58 6,028 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4043121322-1403154492-1806109776-1000_UserData.bin
- 2009-03-30 08:51:24 75,292 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-30 09:03:58 75,380 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-29 22:17:51 266,862 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-03-30 22:12:16 268,324 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9ee802e8-c931-47ab-b570-aa8f791598ca}"= "c:\program files\eMusic\tbeMu1.dll" [2009-03-19 1883672]
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
2009-03-19 12:25 1883672 --a------ c:\program files\eMusic\tbeMu1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9ee802e8-c931-47ab-b570-aa8f791598ca}"= "c:\program files\eMusic\tbeMu1.dll" [2009-03-19 1883672]
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9EE802E8-C931-47AB-B570-AA8F791598CA}"= "c:\program files\eMusic\tbeMu1.dll" [2009-03-19 1883672]
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-13 29744]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152]
"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2007-03-07 189440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2008-01-18 40072]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2008-03-14 2342912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{86367820-44C7-4283-9935-2F5A4B486E35}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{98A297AB-DD68-4787-9FC9-7114907DC7BE}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BFFAD669-7660-45DE-A40C-1D38AE0E296D}"= UDP:c:\program files\iWin Games\iWinGames.exe:iWin Games application.
"{499F8F0A-653C-4952-9E78-D4B980993612}"= TCP:c:\program files\iWin Games\iWinGames.exe:iWin Games application.
"{51167223-CA62-482E-B251-EC309DC89581}"= UDP:c:\program files\iWin Games\WebUpdater.exe:iWin Games updater.
"{4540F48F-787C-4BC3-8E40-64D4DFF18B7B}"= TCP:c:\program files\iWin Games\WebUpdater.exe:iWin Games updater.
"{F8324F2C-91E0-49F6-9C98-07954AF74CD9}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{13886B5E-6F50-4EA1-8054-480770A55424}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7963E0EE-D7C4-4474-883F-1D075A091057}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{56B37B53-344E-479A-AC3E-5E58611EB18D}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [2008-12-17 78104]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-22 33752]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-14 29744]
S3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\System32\drivers\mausbft.sys [2009-01-21 119808]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=WM&Br=EM&Loc=ENG_US&Sys=DTP&M=W3653
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search -
http://edits.mywebse...?p=ZJxdm128YYUSIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-30 17:29:18
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\M-Audio\Fast Track USB\MAUSBFTInst.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-03-30 17:33:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-30 22:33:17
ComboFix2.txt 2009-03-30 09:07:29
Pre-Run: 189,905,440,768 bytes free
Post-Run: 190,088,081,408 bytes free
819 --- E O F --- 2009-03-30 20:25:38