ComboFix 10-05-31.02 - computer 05/31/2010 16:23:13.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3062.1653 [GMT -7:00]
Running from: c:\users\computer\Desktop\ComboFix.exe
Command switches used :: c:\users\computer\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AVG
c:\program files\AVG\AVG9\avg.snu
c:\program files\AVG\AVG9\avg9us.chm
c:\program files\AVG\AVG9\avg9us.lng
c:\program files\AVG\AVG9\avgar9us.chm
c:\program files\AVG\AVG9\avgas9us.chm
c:\program files\AVG\AVG9\avgbat.bav
c:\program files\AVG\AVG9\avgdg9us.chm
c:\program files\AVG\AVG9\avgfw9us.chm
c:\program files\AVG\AVG9\avgidp9us.chm
c:\program files\AVG\AVG9\avgmwdef_us.mht
c:\program files\AVG\AVG9\avgst9us.chm
c:\program files\AVG\AVG9\avgtbas.tbp
c:\program files\AVG\AVG9\avgtrial_us.mht
c:\program files\AVG\AVG9\cf.dat
c:\program files\AVG\AVG9\contacts_us.html
c:\program files\AVG\AVG9\dfncfg.dat
c:\program files\AVG\AVG9\Firefox\Chrome\searchshield.jar
c:\program files\AVG\AVG9\Firefox\Components\ISearchShield.xpt
c:\program files\AVG\AVG9\Firefox\install.rdf
c:\program files\AVG\AVG9\Icons\alert_mask.png
c:\program files\AVG\AVG9\Icons\background_middle_gray.gif
c:\program files\AVG\AVG9\Icons\background_middle_green.gif
c:\program files\AVG\AVG9\Icons\background_middle_orange.gif
c:\program files\AVG\AVG9\Icons\background_middle_red.gif
c:\program files\AVG\AVG9\Icons\background_middle_yellow.gif
c:\program files\AVG\AVG9\Icons\background_top_gray.gif
c:\program files\AVG\AVG9\Icons\background_top_green.gif
c:\program files\AVG\AVG9\Icons\background_top_orange.gif
c:\program files\AVG\AVG9\Icons\background_top_red.gif
c:\program files\AVG\AVG9\Icons\background_top_yellow.gif
c:\program files\AVG\AVG9\Icons\block-doc.gif
c:\program files\AVG\AVG9\Icons\blocked.gif
c:\program files\AVG\AVG9\Icons\blocked12.png
c:\program files\AVG\AVG9\Icons\border_bottom_gray.gif
c:\program files\AVG\AVG9\Icons\border_bottom_green.gif
c:\program files\AVG\AVG9\Icons\border_bottom_orange.gif
c:\program files\AVG\AVG9\Icons\border_bottom_red.gif
c:\program files\AVG\AVG9\Icons\border_bottom_yellow.gif
c:\program files\AVG\AVG9\Icons\border_top_gray.gif
c:\program files\AVG\AVG9\Icons\border_top_green.gif
c:\program files\AVG\AVG9\Icons\border_top_orange.gif
c:\program files\AVG\AVG9\Icons\border_top_red.gif
c:\program files\AVG\AVG9\Icons\border_top_yellow.gif
c:\program files\AVG\AVG9\Icons\box_bottom_red.gif
c:\program files\AVG\AVG9\Icons\box_top_red.gif
c:\program files\AVG\AVG9\Icons\caution.gif
c:\program files\AVG\AVG9\Icons\caution12.png
c:\program files\AVG\AVG9\Icons\click_here_gray.gif
c:\program files\AVG\AVG9\Icons\click_here_green.gif
c:\program files\AVG\AVG9\Icons\click_here_orange.gif
c:\program files\AVG\AVG9\Icons\click_here_red.gif
c:\program files\AVG\AVG9\Icons\click_here_yellow.gif
c:\program files\AVG\AVG9\Icons\clock.gif
c:\program files\AVG\AVG9\Icons\clock12.png
c:\program files\AVG\AVG9\Icons\close.gif
c:\program files\AVG\AVG9\Icons\icons_blocked.gif
c:\program files\AVG\AVG9\Icons\icons_caution.gif
c:\program files\AVG\AVG9\Icons\icons_close.gif
c:\program files\AVG\AVG9\Icons\icons_safe.gif
c:\program files\AVG\AVG9\Icons\icons_unknown.gif
c:\program files\AVG\AVG9\Icons\icons_warning.gif
c:\program files\AVG\AVG9\Icons\LS_Logo_Results.gif
c:\program files\AVG\AVG9\Icons\safe.gif
c:\program files\AVG\AVG9\Icons\safe12.png
c:\program files\AVG\AVG9\Icons\unknown.gif
c:\program files\AVG\AVG9\Icons\vrsn-secured-lsfo.gif
c:\program files\AVG\AVG9\Icons\warning.gif
c:\program files\AVG\AVG9\Icons\warning12.png
c:\program files\AVG\AVG9\license_us.htm
c:\program files\AVG\AVG9\ph.dat
c:\program files\AVG\AVG9\sb.dat
c:\program files\AVG\AVG9\sb.dat.xcd
c:\program files\AVG\AVG9\sb2.dat
c:\program files\AVG\AVG9\sc.dat
c:\program files\AVG\AVG9\sc.dat.xcd
c:\program files\AVG\AVG9\setup.dat
c:\program files\AVG\AVG9\setupus.lns
c:\program files\AVG\AVG9\updatecomps.bak
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Mcafee(1)
c:\program files\Common Files\Mcafee(1)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(1)\NMC\readme.txt
c:\program files\Common Files\Mcafee(1)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(1)\SystemCore\vtp_catcache
c:\program files\Common Files\Mcafee(1)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(1)\VSCore\vscore.xml
c:\program files\Common Files\Mcafee(2)
c:\program files\Common Files\Mcafee(2)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(2)\NMC\readme.txt
c:\program files\Common Files\Mcafee(2)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(2)\SystemCore\vtp_catcache
c:\program files\Common Files\Mcafee(2)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(2)\VSCore\vscore.xml
c:\program files\Common Files\Mcafee(25)
c:\program files\Common Files\Mcafee(25)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(25)\NMC\readme.txt
c:\program files\Common Files\Mcafee(25)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(25)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(25)\VSCore\vscore.xml
c:\program files\McAfee(2)
c:\program files\McAfee(2)\MPF\1033\Readme.htm
c:\program files\McAfee(2)\MPF\mpf.dat
c:\program files\McAfee(2)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(2)\MSC\Help\mcafee.html
c:\program files\McAfee(2)\MSC\langmap.dat
c:\program files\McAfee(2)\MSC\mcscindx.dat
c:\program files\McAfee(2)\MSC\mscuicfg.dat
c:\program files\McAfee(2)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(2)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(2)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(2)\SiteAdvisor\contents.rdf
c:\program files\McAfee(2)\SiteAdvisor\default.txt
c:\program files\McAfee(2)\SiteAdvisor\elist.dat
c:\program files\McAfee(2)\SiteAdvisor\install.rdf
c:\program files\McAfee(2)\SiteAdvisor\Oem.txt
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(2)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvclean.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvnames.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvscan.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\mferuntime.dat
c:\program files\McAfee(2)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(2)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(2)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(21)
c:\program files\McAfee(21)\MPF\1033\Readme.htm
c:\program files\McAfee(21)\MPF\mpf.dat
c:\program files\McAfee(21)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(21)\MSC\Help\mcafee.html
c:\program files\McAfee(21)\MSC\langmap.dat
c:\program files\McAfee(21)\MSC\mcscindx.dat
c:\program files\McAfee(21)\MSC\mscuicfg.dat
c:\program files\McAfee(21)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(21)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(21)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(21)\SiteAdvisor\contents.rdf
c:\program files\McAfee(21)\SiteAdvisor\default.txt
c:\program files\McAfee(21)\SiteAdvisor\elist.dat
c:\program files\McAfee(21)\SiteAdvisor\install.rdf
c:\program files\McAfee(21)\SiteAdvisor\Oem.txt
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(21)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvclean.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvnames.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvscan.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\mferuntime.dat
c:\program files\McAfee(21)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(21)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(21)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(22).com
c:\program files\McAfee(22).com\Agent\mcscentr.adf
c:\program files\McAfee(3).com
c:\program files\McAfee(3).com\Agent\mcscentr.adf
c:\program files\McAfee(78)
c:\program files\McAfee(78)\MPF\1033\Readme.htm
c:\program files\McAfee(78)\MPF\mpf.dat
c:\program files\McAfee(78)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(78)\MSC\Help\mcafee.html
c:\program files\McAfee(78)\MSC\langmap.dat
c:\program files\McAfee(78)\MSC\mcscindx.dat
c:\program files\McAfee(78)\MSC\mscuicfg.dat
c:\program files\McAfee(78)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(78)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(78)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(78)\SiteAdvisor\contents.rdf
c:\program files\McAfee(78)\SiteAdvisor\default.txt
c:\program files\McAfee(78)\SiteAdvisor\elist.dat
c:\program files\McAfee(78)\SiteAdvisor\install.rdf
c:\program files\McAfee(78)\SiteAdvisor\Oem.txt
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(78)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvclean.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvnames.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvscan.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\mferuntime.dat
c:\program files\McAfee(78)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(78)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(78)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(79).com
c:\program files\McAfee(79).com\Agent\mcscentr.adf
c:\program files\McAfee.com
c:\program files\McAfee.com\Agent\mcagent.exe
c:\program files\McAfee.com\Agent\mcagntps.dll
c:\program files\McAfee.com\Agent\mcpatch.dll
c:\program files\McAfee.com\Agent\mcuilib.dll
c:\program files\McAfee.com\Agent\mcupdate.exe
c:\program files\McAfee.com\Agent\msclgmis.inf
c:\program files\McAfee.com\Shared\dunzip32.dll
c:\program files\McAfee.com\Shared\mcappins.exe
c:\program files\McAfee.com\Shared\mcappins.exe.manifest
c:\program files\McAfee.com\Shared\mcappins.inf
c:\program files\McAfee.com\Shared\mcinsres.dll
c:\program files\McAfee.com\Shared\mghtml.exe
c:\program files\McAfee.com\Shared\mghtml.exe.manifest
c:\program files\McAfee.com\Shared\mghtml.inf
c:\programdata\avg9
c:\programdata\avg9\Antispam\productid
c:\programdata\avg9\Antispam\rkd
c:\programdata\avg9\Antispam\sc1.bin
c:\programdata\avg9\Antispam\sc1.bin.full.2010.05.17.20.52.32
c:\programdata\avg9\Antispam\sc1.bin.full.2010.05.17.20.52.32.lkr1
c:\programdata\avg9\Antispam\sc1.bin.tmp
c:\programdata\avg9\Antispam\sc10.bin.full.2010.05.18.07.01.01
c:\programdata\avg9\Antispam\sc10.bin.tmp
c:\programdata\avg9\Antispam\sc14.bin.full.2006.06.27.17.01.01
c:\programdata\avg9\Antispam\sc17.bin.full.2010.05.16.11.22.20
c:\programdata\avg9\Antispam\sc17.bin.full.2010.05.16.11.22.20.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.14.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.14.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.15.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.15.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.18.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.18.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.21.01.02
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.21.01.02.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.22.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.22.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.23.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.23.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.01.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.01.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.04.01.02
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.04.01.02.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.05.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.05.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.06.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.06.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.07.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.07.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.09.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.09.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.14.00.59
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.14.00.59.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.18.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.18.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.20.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.20.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.23.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.23.01.01.lkr1
c:\programdata\avg9\Antispam\sc18.bin.full.2010.04.23.22.09.56
c:\programdata\avg9\Antispam\sc18.bin.full.2010.04.23.22.09.56.lkr1
c:\programdata\avg9\Antispam\sc18.bin.tmp1
c:\programdata\avg9\Antispam\sc18.bin.tmp2
c:\programdata\avg9\Antispam\sc2.bin
c:\programdata\avg9\Antispam\sc2.bin.full.2005.02.11.04.44.13
c:\programdata\avg9\Antispam\sc2.bin.full.2005.02.11.04.44.13.lkr1
c:\programdata\avg9\Antispam\sc21.bin.full.2010.05.13.17.35.19
c:\programdata\avg9\Antispam\sc21.bin.full.2010.05.13.17.35.19.lkr1
c:\programdata\avg9\Antispam\sc6.bin.full.2010.03.15.20.58.02
c:\programdata\avg9\Antispam\sc9.bin.full.2010.03.03.22.54.13
c:\programdata\avg9\Antispam\sc9.bin.full.2010.03.03.22.54.13.lkr1
c:\programdata\avg9\Antispam\sc9.bin.tmp
c:\programdata\avg9\Antispam\scoffset.bin.incr
c:\programdata\avg9\Antispam\scopt.tmp
c:\programdata\avg9\Antispam\spamcatcher.conf
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\a27ac756-7812-4046-a0f0-9cb05a1d3f86
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\avgcchff.dat
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\avgcchmf.dat
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\c0b17072-e0a9-4300-990b-f0c2f7caabee
c:\programdata\avg9\Chjw\949ca48c9ca46a86\avgcchff.dat
c:\programdata\avg9\Chjw\949ca48c9ca46a86\avgcchmf.dat
c:\programdata\avg9\Chjw\chjwr.dat
c:\programdata\avg9\Chjw\cm-0-p.dat
c:\programdata\avg9\Chjw\cm-1-p.dat
c:\programdata\avg9\Chjw\cm-2-i.dat
c:\programdata\avg9\Chjw\cm-2-p.dat
c:\programdata\avg9\Chjw\cm-3-p.dat
c:\programdata\avg9\Chjw\cm-4-p.dat
c:\programdata\avg9\emc\Log\emc.log
c:\programdata\avg9\IDS\Config\agentStartup.xml
c:\programdata\avg9\IDS\Config\analyzerFilterConfig.xml
c:\programdata\avg9\IDS\Config\BehavioralEventProcessors.xml
c:\programdata\avg9\IDS\Config\BehavioralEvents.xml
c:\programdata\avg9\IDS\Config\Classifiers.xml
c:\programdata\avg9\IDS\Config\Correlations.xml
c:\programdata\avg9\IDS\Config\downloadManager.xml
c:\programdata\avg9\IDS\Config\downloads.xml
c:\programdata\avg9\IDS\Config\EN_US\Characteristics.xml
c:\programdata\avg9\IDS\Config\EN_US\internalListStrings.xml
c:\programdata\avg9\IDS\Config\EN_US\reportableEvents.xml
c:\programdata\avg9\IDS\Config\ExecutableEvents.xml
c:\programdata\avg9\IDS\Config\FileCoverage.xml
c:\programdata\avg9\IDS\Config\globalConfig.xml
c:\programdata\avg9\IDS\Config\internalList.zip
c:\programdata\avg9\IDS\Config\internalList.zip.bak
c:\programdata\avg9\IDS\Config\messages.xml
c:\programdata\avg9\IDS\Config\NetworkEvents.xml
c:\programdata\avg9\IDS\Config\ProductParameters.xml
c:\programdata\avg9\IDS\Config\quarantinedList.zip
c:\programdata\avg9\IDS\Config\quarantinedList.zip.bak
c:\programdata\avg9\IDS\Config\RegistryCoverage.xml
c:\programdata\avg9\IDS\Config\Relationships.xml
c:\programdata\avg9\IDS\Config\ReportableEventMappings.xml
c:\programdata\avg9\IDS\Config\SelfProtection.xml
c:\programdata\avg9\IDS\Config\userList.zip
c:\programdata\avg9\IDS\Config\userList.zip.bak
c:\programdata\avg9\IDS\log\AVGIDSAgent.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_boot.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_graph.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_malware.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_node.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_removed.log
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AIM6_AIM6.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AIM6_AOLSOFTWARE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGEMC.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGEMC.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGTRAY.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGTRAY.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUI.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUI.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUPD.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGWDSVC.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_BONJOUR_MDNSRESPONDER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_BONJOUR_MDNSRESPONDER.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_APPLE_MOBILE DEVICE SUPPORT_BIN_APPLEMOBILEDEVICESERVICE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_MCAFEE_MCSVCHOST_MCSVHOST.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_MCAFEE_MCSVCHOST_MCSVHOST.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_ITUNES_ITUNESHELPER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_LAVASOFT_AD-AWARE_AAWSERVICE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_LAVASOFT_AD-AWARE_AAWSERVICE.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MALWAREBYTES' ANTI-MALWARE_MBAM.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MOZILLA FIREFOX_FIREFOX.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MOZILLA FIREFOX_FIREFOX.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS MEDIA PLAYER_WMPLAYER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS SIDEBAR_SIDEBAR.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS SIDEBAR_SIDEBAR.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAMDATA_KASPERSKY LAB SETUP FILES_KASPERSKY ANTI-VIRUS 2010 9.0.0.736_ENGLISH_SETUP.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAMDATA_KASPERSKY LAB SETUP FILES_KASPERSKY ANTI-VIRUS 2010 9.0.0.736_ENGLISH_SETUP.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_LSASS.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SERVICES.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SERVICES.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SVCHOST.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SVCHOST.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WERFAULT.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WERFAULT.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WININIT.EXE.ndb
c:\programdata\avg9\IDS\profile\globalLoadable.bak
c:\programdata\avg9\IDS\profile\MalwareNetwork.bak
c:\programdata\avg9\IDS\profile\MalwareNetwork.xml
c:\programdata\avg9\IDS\profile\SYSTEM.ndb
c:\programdata\avg9\Log\avgam.log
c:\programdata\avg9\Log\avgam.log.lock
c:\programdata\avg9\Log\avgcfg.log
c:\programdata\avg9\Log\avgcfg.log.lock
c:\programdata\avg9\Log\avgchjw.log
c:\programdata\avg9\Log\avgchjw.log.lock
c:\programdata\avg9\Log\avgchjwsrv.log
c:\programdata\avg9\Log\avgchjwsrv.log.lock
c:\programdata\avg9\Log\avgcore.log
c:\programdata\avg9\Log\avgcore.log.1
c:\programdata\avg9\Log\avgcore.log.2
c:\programdata\avg9\Log\avgcore.log.3
c:\programdata\avg9\Log\avgcore.log.4
c:\programdata\avg9\Log\avgcore.log.5
c:\programdata\avg9\Log\avgcore.log.6
c:\programdata\avg9\Log\avgcore.log.lock
c:\programdata\avg9\Log\avgfrw.log
c:\programdata\avg9\Log\avgfrw.log.lock
c:\programdata\avg9\Log\avgfw.log
c:\programdata\avg9\Log\avgfw.log.lock
c:\programdata\avg9\Log\avgfw8db.log
c:\programdata\avg9\Log\avgfw8db.log.lock
c:\programdata\avg9\Log\avgfw8u.log
c:\programdata\avg9\Log\avgfw8u.log.lock
c:\programdata\avg9\Log\avgfwui.log
c:\programdata\avg9\Log\avgfwui.log.lock
c:\programdata\avg9\Log\avgldr.log
c:\programdata\avg9\Log\avgldr.log.lock
c:\programdata\avg9\Log\avglng.log
c:\programdata\avg9\Log\avglng.log.lock
c:\programdata\avg9\Log\avgns.log
c:\programdata\avg9\Log\avgns.log.lock
c:\programdata\avg9\Log\avgrs.log
c:\programdata\avg9\Log\avgrs.log.lock
c:\programdata\avg9\Log\avgscan.log
c:\programdata\avg9\Log\avgscan.log.lock
c:\programdata\avg9\Log\avgsched.log
c:\programdata\avg9\Log\avgsched.log.lock
c:\programdata\avg9\Log\avgsrm.log
c:\programdata\avg9\Log\avgsrm.log.lock
c:\programdata\avg9\Log\avgsrmac.log
c:\programdata\avg9\Log\avgsrmac.log.lock
c:\programdata\avg9\Log\avgsrmacstat.log
c:\programdata\avg9\Log\avgsrmacstat.log.lock
c:\programdata\avg9\Log\avgtdi.log
c:\programdata\avg9\Log\avgtdi.log.lock
c:\programdata\avg9\Log\avgui.log
c:\programdata\avg9\Log\avgui.log.lock
c:\programdata\avg9\Log\avgupd.log
c:\programdata\avg9\Log\avgupd.log.lock
c:\programdata\avg9\Log\avgwd.log
c:\programdata\avg9\Log\avgwd.log.lock
c:\programdata\avg9\Log\avgwdsvc.log
c:\programdata\avg9\Log\avgwdsvc.log.lock
c:\programdata\avg9\Log\commonpriv.log
c:\programdata\avg9\Log\commonpriv.log.1
c:\programdata\avg9\Log\commonpriv.log.lock
c:\programdata\avg9\Log\fixcfg.log
c:\programdata\avg9\Log\fixcfg.log.lock
c:\programdata\avg9\Log\history.xml
c:\programdata\avg9\Log\IDP\log\avgam_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\IDP\log\avgfws9_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\IDP\log\avgtray_idp_computer.log
c:\programdata\avg9\Log\IDP\log\avgui_idp_computer.log
c:\programdata\avg9\Log\IDP\log\avgwdsvc_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\vault.log
c:\programdata\avg9\Log\vault.log.lock
c:\programdata\avg9\Lsdb\Prev\prvglbl.dat
c:\programdata\avg9\scanlogs\I_00000001.log
c:\programdata\avg9\scanlogs\I_00000005.log
c:\programdata\avg9\scanlogs\I_00000006.log
c:\programdata\avg9\scanlogs\I_00000007.log
c:\programdata\avg9\scanlogs\I_00000008.log
c:\programdata\avg9\scanlogs\srm.idx
c:\programdata\avg9\Temp\17aa3fc5-cf8c-4357-950c-01457f769269-f7c-oopp.tmp
c:\programdata\avg9\Temp\40524d3a-865a-4a84-8be3-c2e2f847d52c-e1c-oopp.tmp
c:\programdata\avg9\Temp\787a1ea5-680a-4f31-a958-f35c22c04605-1008-oopp.tmp
c:\programdata\avg9\Temp\b6ec7eda-7e9a-4d41-bdc2-3680a6593d49-344-oopp.tmp
c:\programdata\avg9\Temp\c0dfddc4-9be8-498b-b40c-79070b62e8a7-344-oopp.tmp
c:\programdata\avg9\Temp\c3407ca5-c112-4123-ba8d-bedca06b7be7-10cc-oopp.tmp
c:\programdata\avg9\Temp\file9514.tmp
c:\programdata\avg9\update\backup\sb.dat
c:\programdata\avg9\update\backup\sb.dat.xcd
c:\programdata\avg9\update\backup\sb2.dat
c:\programdata\avg9\update\backup\sc.dat
c:\programdata\avg9\update\backup\sc.dat.xcd
c:\programdata\avg9\update\download\avg9infoavi.ctf
c:\programdata\avg9\update\download\avg9infowin.ctf
c:\programdata\avg9\update\download\x8xplsb_169rr.bin
c:\programdata\avg9\update\download\x8xplsb2_141w3.bin
c:\programdata\avg9\update\download\x8xplsc_22587.bin
c:\programdata\Viewpoint
c:\users\computer\AppData\Local\xgbeijmjo
.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-31 )))))))))))))))))))))))))))))))
.
2010-05-31 23:31 . 2010-05-31 23:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-31 21:57 . 2010-05-31 21:57 -------- d-----w- c:\users\computer\AppData\Local\Adobe
2010-05-27 07:35 . 2010-04-13 00:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-27 01:26 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-25 17:18 . 2010-05-25 17:18 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-05-24 20:32 . 2008-01-31 01:36 90112 ----a-w- c:\windows\unvise32.exe
2010-05-21 08:37 . 2010-05-22 05:17 -------- d-----w- c:\users\computer\AppData\Roaming\Auslogics
2010-05-21 08:37 . 2010-05-21 08:40 -------- d-----w- c:\program files\Auslogics
2010-05-19 10:01 . 2010-05-19 10:01 -------- d-----w- c:\windows\CheckSur
2010-05-18 10:21 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-18 10:20 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-18 10:01 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-18 10:00 . 2010-05-12 18:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 08:22 . 2010-05-18 08:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\users\computer\AppData\Roaming\Malwarebytes
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\programdata\Malwarebytes
2010-05-18 07:58 . 2010-05-18 10:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-09 13:14 . 2010-05-29 05:36 -------- d-----w- C:\PERRLA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-28 06:11 . 2009-09-12 07:24 -------- d-----w- c:\program files\McAfee
2010-05-27 07:35 . 2008-04-09 04:45 -------- d-----w- c:\program files\Java
2010-05-27 07:34 . 2009-09-12 10:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-05-27 00:47 . 2009-09-11 09:45 -------- d-----w- c:\programdata\McAfee
2010-05-27 00:44 . 2009-09-12 07:24 -------- d-----w- c:\program files\Common Files\McAfee
2010-05-27 00:44 . 2009-09-16 08:03 -------- d-----w- c:\programdata\Yahoo! Companion
2010-05-27 00:30 . 2009-09-11 11:51 1356 ----a-w- c:\users\computer\AppData\Local\d3d9caps.dat
2010-05-23 23:57 . 2009-09-20 06:43 -------- d-----w- c:\programdata\Soulseek
2010-05-23 06:30 . 2009-09-11 06:53 -------- d-----w- c:\program files\Common Files\AOL
2010-05-21 18:55 . 2009-09-11 06:41 77928 ----a-w- c:\users\computer\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-21 09:13 . 2006-11-02 06:37 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-05-21 09:13 . 2010-01-19 07:58 819200 ----a-w- c:\windows\system32\xvidcore.dll
2010-05-21 09:13 . 2010-01-19 07:58 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-05-21 09:13 . 2008-04-29 12:49 237568 ----a-w- c:\windows\system32\UCI32M29.dll
2010-05-21 09:13 . 2008-04-09 05:22 221184 ----a-w- c:\windows\system32\UCI32M22.dll
2010-05-21 09:09 . 2009-11-15 05:06 1196032 ----a-w- c:\windows\RtlUpd.exe
2010-05-21 09:09 . 2009-11-15 05:06 520192 ----a-w- c:\windows\RtlExUpd.dll
2010-05-21 09:08 . 2009-11-15 05:06 315392 ----a-w- c:\windows\HideWin.exe
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\taskMgrPrefs.exe
2010-05-21 09:08 . 2008-04-09 04:47 81920 ----a-w- c:\windows\Help\OEM\scripts\HPPhoneNumbers.exe
2010-05-21 09:08 . 2008-04-09 04:47 53248 ----a-w- c:\windows\Help\OEM\scripts\HPASL.exe
2010-05-21 09:08 . 2008-04-09 04:47 4096 ----a-w- c:\windows\Help\OEM\scripts\Interop.HelpPane.dll
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\launchAP.exe
2010-05-21 09:04 . 2009-10-25 22:30 81920 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 413696 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 401408 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041D\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 147456 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041E\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 397312 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0414\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 282624 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0411\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 196608 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0410\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 176128 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040e\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 73728 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040b\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 94208 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0408\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 253952 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0404\CNMur9I.dll
2010-05-19 18:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-18 09:46 . 2009-09-16 01:55 -------- d-----w- c:\programdata\Microsoft Help
2010-05-18 09:38 . 2009-09-12 10:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-18 09:38 . 2009-11-11 03:34 -------- d-----w- c:\program files\iTunes
2010-04-24 05:30 . 2010-04-24 05:30 -------- d-----w- c:\users\computer\AppData\Roaming\muvee Technologies
2010-04-23 17:32 . 2010-04-23 17:32 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-28 23:48 . 2010-03-28 23:48 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-03-28 23:47 . 2010-03-28 23:47 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2010-03-09 16:28 . 2010-03-31 17:32 833024 ----a-w- c:\windows\system32\wininet.dll
2010-03-09 16:25 . 2010-03-31 17:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 14:01 . 2010-03-31 17:32 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-03-04 18:54 . 2010-04-14 17:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2009-10-24 19:00 . 2009-10-24 19:00 22 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2010-05-21 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-05-21 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-03 178712]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
c:\users\computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-19 1314704]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-03-26 93320]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
.
Contents of the 'Scheduled Tasks' folder
2010-05-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 01:51]
2010-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 19:22]
2010-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 19:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\computer\AppData\Roaming\Mozilla\Firefox\Profiles\ttggtg9q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-31 16:35
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4948)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-05-31 16:38:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-31 23:38
ComboFix2.txt 2010-05-27 22:23
Pre-Run: 496,572,063,744 bytes free
Post-Run: 496,435,789,824 bytes free
- - End Of File - - 3EAB776F6B2B17F445B996A5B9D368B1