Jump to content

Free help from tech experts
Welcome to Geeks to Go forums. Create a FREE account now to gain access to all our features. Once registered and logged in, you will be able to create topics, post replies to existing topics, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. Best of all, registration and all assistance is 100% free! This message, and all ads will be removed once you sign in.
Create an Account Login to Account

pretty sure i have a virus but, scans don't find it [Solved]


  • This topic is locked This topic is locked

#16
death salad

death salad

    New Member

  • Member
  • Pip
  • 9 posts
computer didn't act to different, but it did take a while to startup





ComboFix 10-05-31.02 - computer 05/31/2010 16:23:13.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3062.1653 [GMT -7:00]
Running from: c:\users\computer\Desktop\ComboFix.exe
Command switches used :: c:\users\computer\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AVG
c:\program files\AVG\AVG9\avg.snu
c:\program files\AVG\AVG9\avg9us.chm
c:\program files\AVG\AVG9\avg9us.lng
c:\program files\AVG\AVG9\avgar9us.chm
c:\program files\AVG\AVG9\avgas9us.chm
c:\program files\AVG\AVG9\avgbat.bav
c:\program files\AVG\AVG9\avgdg9us.chm
c:\program files\AVG\AVG9\avgfw9us.chm
c:\program files\AVG\AVG9\avgidp9us.chm
c:\program files\AVG\AVG9\avgmwdef_us.mht
c:\program files\AVG\AVG9\avgst9us.chm
c:\program files\AVG\AVG9\avgtbas.tbp
c:\program files\AVG\AVG9\avgtrial_us.mht
c:\program files\AVG\AVG9\cf.dat
c:\program files\AVG\AVG9\contacts_us.html
c:\program files\AVG\AVG9\dfncfg.dat
c:\program files\AVG\AVG9\Firefox\Chrome\searchshield.jar
c:\program files\AVG\AVG9\Firefox\Components\ISearchShield.xpt
c:\program files\AVG\AVG9\Firefox\install.rdf
c:\program files\AVG\AVG9\Icons\alert_mask.png
c:\program files\AVG\AVG9\Icons\background_middle_gray.gif
c:\program files\AVG\AVG9\Icons\background_middle_green.gif
c:\program files\AVG\AVG9\Icons\background_middle_orange.gif
c:\program files\AVG\AVG9\Icons\background_middle_red.gif
c:\program files\AVG\AVG9\Icons\background_middle_yellow.gif
c:\program files\AVG\AVG9\Icons\background_top_gray.gif
c:\program files\AVG\AVG9\Icons\background_top_green.gif
c:\program files\AVG\AVG9\Icons\background_top_orange.gif
c:\program files\AVG\AVG9\Icons\background_top_red.gif
c:\program files\AVG\AVG9\Icons\background_top_yellow.gif
c:\program files\AVG\AVG9\Icons\block-doc.gif
c:\program files\AVG\AVG9\Icons\blocked.gif
c:\program files\AVG\AVG9\Icons\blocked12.png
c:\program files\AVG\AVG9\Icons\border_bottom_gray.gif
c:\program files\AVG\AVG9\Icons\border_bottom_green.gif
c:\program files\AVG\AVG9\Icons\border_bottom_orange.gif
c:\program files\AVG\AVG9\Icons\border_bottom_red.gif
c:\program files\AVG\AVG9\Icons\border_bottom_yellow.gif
c:\program files\AVG\AVG9\Icons\border_top_gray.gif
c:\program files\AVG\AVG9\Icons\border_top_green.gif
c:\program files\AVG\AVG9\Icons\border_top_orange.gif
c:\program files\AVG\AVG9\Icons\border_top_red.gif
c:\program files\AVG\AVG9\Icons\border_top_yellow.gif
c:\program files\AVG\AVG9\Icons\box_bottom_red.gif
c:\program files\AVG\AVG9\Icons\box_top_red.gif
c:\program files\AVG\AVG9\Icons\caution.gif
c:\program files\AVG\AVG9\Icons\caution12.png
c:\program files\AVG\AVG9\Icons\click_here_gray.gif
c:\program files\AVG\AVG9\Icons\click_here_green.gif
c:\program files\AVG\AVG9\Icons\click_here_orange.gif
c:\program files\AVG\AVG9\Icons\click_here_red.gif
c:\program files\AVG\AVG9\Icons\click_here_yellow.gif
c:\program files\AVG\AVG9\Icons\clock.gif
c:\program files\AVG\AVG9\Icons\clock12.png
c:\program files\AVG\AVG9\Icons\close.gif
c:\program files\AVG\AVG9\Icons\icons_blocked.gif
c:\program files\AVG\AVG9\Icons\icons_caution.gif
c:\program files\AVG\AVG9\Icons\icons_close.gif
c:\program files\AVG\AVG9\Icons\icons_safe.gif
c:\program files\AVG\AVG9\Icons\icons_unknown.gif
c:\program files\AVG\AVG9\Icons\icons_warning.gif
c:\program files\AVG\AVG9\Icons\LS_Logo_Results.gif
c:\program files\AVG\AVG9\Icons\safe.gif
c:\program files\AVG\AVG9\Icons\safe12.png
c:\program files\AVG\AVG9\Icons\unknown.gif
c:\program files\AVG\AVG9\Icons\vrsn-secured-lsfo.gif
c:\program files\AVG\AVG9\Icons\warning.gif
c:\program files\AVG\AVG9\Icons\warning12.png
c:\program files\AVG\AVG9\license_us.htm
c:\program files\AVG\AVG9\ph.dat
c:\program files\AVG\AVG9\sb.dat
c:\program files\AVG\AVG9\sb.dat.xcd
c:\program files\AVG\AVG9\sb2.dat
c:\program files\AVG\AVG9\sc.dat
c:\program files\AVG\AVG9\sc.dat.xcd
c:\program files\AVG\AVG9\setup.dat
c:\program files\AVG\AVG9\setupus.lns
c:\program files\AVG\AVG9\updatecomps.bak
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Mcafee(1)
c:\program files\Common Files\Mcafee(1)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(1)\NMC\readme.txt
c:\program files\Common Files\Mcafee(1)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(1)\SystemCore\vtp_catcache
c:\program files\Common Files\Mcafee(1)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(1)\VSCore\vscore.xml
c:\program files\Common Files\Mcafee(2)
c:\program files\Common Files\Mcafee(2)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(2)\NMC\readme.txt
c:\program files\Common Files\Mcafee(2)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(2)\SystemCore\vtp_catcache
c:\program files\Common Files\Mcafee(2)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(2)\VSCore\vscore.xml
c:\program files\Common Files\Mcafee(25)
c:\program files\Common Files\Mcafee(25)\NMC\nmcuicfg.dat
c:\program files\Common Files\Mcafee(25)\NMC\readme.txt
c:\program files\Common Files\Mcafee(25)\SystemCore\strings.bin
c:\program files\Common Files\Mcafee(25)\VSCore\strings.bin
c:\program files\Common Files\Mcafee(25)\VSCore\vscore.xml
c:\program files\McAfee(2)
c:\program files\McAfee(2)\MPF\1033\Readme.htm
c:\program files\McAfee(2)\MPF\mpf.dat
c:\program files\McAfee(2)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(2)\MSC\Help\mcafee.html
c:\program files\McAfee(2)\MSC\langmap.dat
c:\program files\McAfee(2)\MSC\mcscindx.dat
c:\program files\McAfee(2)\MSC\mscuicfg.dat
c:\program files\McAfee(2)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(2)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(2)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(2)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(2)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(2)\SiteAdvisor\contents.rdf
c:\program files\McAfee(2)\SiteAdvisor\default.txt
c:\program files\McAfee(2)\SiteAdvisor\elist.dat
c:\program files\McAfee(2)\SiteAdvisor\install.rdf
c:\program files\McAfee(2)\SiteAdvisor\Oem.txt
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(2)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(2)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvclean.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvnames.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\avvscan.dat
c:\program files\McAfee(2)\VirusScan\DAT\5902.0\mferuntime.dat
c:\program files\McAfee(2)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(2)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(2)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(21)
c:\program files\McAfee(21)\MPF\1033\Readme.htm
c:\program files\McAfee(21)\MPF\mpf.dat
c:\program files\McAfee(21)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(21)\MSC\Help\mcafee.html
c:\program files\McAfee(21)\MSC\langmap.dat
c:\program files\McAfee(21)\MSC\mcscindx.dat
c:\program files\McAfee(21)\MSC\mscuicfg.dat
c:\program files\McAfee(21)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(21)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(21)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(21)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(21)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(21)\SiteAdvisor\contents.rdf
c:\program files\McAfee(21)\SiteAdvisor\default.txt
c:\program files\McAfee(21)\SiteAdvisor\elist.dat
c:\program files\McAfee(21)\SiteAdvisor\install.rdf
c:\program files\McAfee(21)\SiteAdvisor\Oem.txt
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(21)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(21)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvclean.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvnames.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\avvscan.dat
c:\program files\McAfee(21)\VirusScan\DAT\5985.0\mferuntime.dat
c:\program files\McAfee(21)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(21)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(21)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(22).com
c:\program files\McAfee(22).com\Agent\mcscentr.adf
c:\program files\McAfee(3).com
c:\program files\McAfee(3).com\Agent\mcscentr.adf
c:\program files\McAfee(78)
c:\program files\McAfee(78)\MPF\1033\Readme.htm
c:\program files\McAfee(78)\MPF\mpf.dat
c:\program files\McAfee(78)\MSC\1033\Help\FWBlock.htm
c:\program files\McAfee(78)\MSC\Help\mcafee.html
c:\program files\McAfee(78)\MSC\langmap.dat
c:\program files\McAfee(78)\MSC\mcscindx.dat
c:\program files\McAfee(78)\MSC\mscuicfg.dat
c:\program files\McAfee(78)\MSC\oeminfo\MPF\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MPF\mpfUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\MQS\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MQS\mqsUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\msad\en-US\634-7\msaduc.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\Msccust.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\msccust64.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\subst.cab
c:\program files\McAfee(78)\MSC\oeminfo\MSC\en-us\subst64.cab
c:\program files\McAfee(78)\MSC\oeminfo\NMC\nmcUC.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\en-us\vsorsubt.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsodis.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsoena.cab
c:\program files\McAfee(78)\MSC\oeminfo\vso\oobe\vsoUC.cab
c:\program files\McAfee(78)\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee(78)\SiteAdvisor\contents.rdf
c:\program files\McAfee(78)\SiteAdvisor\default.txt
c:\program files\McAfee(78)\SiteAdvisor\elist.dat
c:\program files\McAfee(78)\SiteAdvisor\install.rdf
c:\program files\McAfee(78)\SiteAdvisor\Oem.txt
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee(78)\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee(78)\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvclean.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvnames.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\avvscan.dat
c:\program files\McAfee(78)\VirusScan\DAT\5902.0\mferuntime.dat
c:\program files\McAfee(78)\VirusScan\Engine\5400.1158\config.dat
c:\program files\McAfee(78)\VirusScan\Engine\5400.1158\signlic.txt
c:\program files\McAfee(78)\VirusScan\MVsUiCfg.dat
c:\program files\McAfee(79).com
c:\program files\McAfee(79).com\Agent\mcscentr.adf
c:\program files\McAfee.com
c:\program files\McAfee.com\Agent\mcagent.exe
c:\program files\McAfee.com\Agent\mcagntps.dll
c:\program files\McAfee.com\Agent\mcpatch.dll
c:\program files\McAfee.com\Agent\mcuilib.dll
c:\program files\McAfee.com\Agent\mcupdate.exe
c:\program files\McAfee.com\Agent\msclgmis.inf
c:\program files\McAfee.com\Shared\dunzip32.dll
c:\program files\McAfee.com\Shared\mcappins.exe
c:\program files\McAfee.com\Shared\mcappins.exe.manifest
c:\program files\McAfee.com\Shared\mcappins.inf
c:\program files\McAfee.com\Shared\mcinsres.dll
c:\program files\McAfee.com\Shared\mghtml.exe
c:\program files\McAfee.com\Shared\mghtml.exe.manifest
c:\program files\McAfee.com\Shared\mghtml.inf
c:\programdata\avg9
c:\programdata\avg9\Antispam\productid
c:\programdata\avg9\Antispam\rkd
c:\programdata\avg9\Antispam\sc1.bin
c:\programdata\avg9\Antispam\sc1.bin.full.2010.05.17.20.52.32
c:\programdata\avg9\Antispam\sc1.bin.full.2010.05.17.20.52.32.lkr1
c:\programdata\avg9\Antispam\sc1.bin.tmp
c:\programdata\avg9\Antispam\sc10.bin.full.2010.05.18.07.01.01
c:\programdata\avg9\Antispam\sc10.bin.tmp
c:\programdata\avg9\Antispam\sc14.bin.full.2006.06.27.17.01.01
c:\programdata\avg9\Antispam\sc17.bin.full.2010.05.16.11.22.20
c:\programdata\avg9\Antispam\sc17.bin.full.2010.05.16.11.22.20.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.14.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.14.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.15.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.15.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.18.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.18.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.21.01.02
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.21.01.02.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.22.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.22.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.23.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.16.23.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.01.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.01.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.04.01.02
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.04.01.02.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.05.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.05.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.06.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.06.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.07.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.07.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.09.01.00
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.09.01.00.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.14.00.59
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.14.00.59.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.18.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.18.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.20.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.20.01.01.lkr1
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.23.01.01
c:\programdata\avg9\Antispam\sc17.bin.incr.2010.05.17.23.01.01.lkr1
c:\programdata\avg9\Antispam\sc18.bin.full.2010.04.23.22.09.56
c:\programdata\avg9\Antispam\sc18.bin.full.2010.04.23.22.09.56.lkr1
c:\programdata\avg9\Antispam\sc18.bin.tmp1
c:\programdata\avg9\Antispam\sc18.bin.tmp2
c:\programdata\avg9\Antispam\sc2.bin
c:\programdata\avg9\Antispam\sc2.bin.full.2005.02.11.04.44.13
c:\programdata\avg9\Antispam\sc2.bin.full.2005.02.11.04.44.13.lkr1
c:\programdata\avg9\Antispam\sc21.bin.full.2010.05.13.17.35.19
c:\programdata\avg9\Antispam\sc21.bin.full.2010.05.13.17.35.19.lkr1
c:\programdata\avg9\Antispam\sc6.bin.full.2010.03.15.20.58.02
c:\programdata\avg9\Antispam\sc9.bin.full.2010.03.03.22.54.13
c:\programdata\avg9\Antispam\sc9.bin.full.2010.03.03.22.54.13.lkr1
c:\programdata\avg9\Antispam\sc9.bin.tmp
c:\programdata\avg9\Antispam\scoffset.bin.incr
c:\programdata\avg9\Antispam\scopt.tmp
c:\programdata\avg9\Antispam\spamcatcher.conf
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\a27ac756-7812-4046-a0f0-9cb05a1d3f86
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\avgcchff.dat
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\avgcchmf.dat
c:\programdata\avg9\Chjw\7a5e6fb65e6f69b9\c0b17072-e0a9-4300-990b-f0c2f7caabee
c:\programdata\avg9\Chjw\949ca48c9ca46a86\avgcchff.dat
c:\programdata\avg9\Chjw\949ca48c9ca46a86\avgcchmf.dat
c:\programdata\avg9\Chjw\chjwr.dat
c:\programdata\avg9\Chjw\cm-0-p.dat
c:\programdata\avg9\Chjw\cm-1-p.dat
c:\programdata\avg9\Chjw\cm-2-i.dat
c:\programdata\avg9\Chjw\cm-2-p.dat
c:\programdata\avg9\Chjw\cm-3-p.dat
c:\programdata\avg9\Chjw\cm-4-p.dat
c:\programdata\avg9\emc\Log\emc.log
c:\programdata\avg9\IDS\Config\agentStartup.xml
c:\programdata\avg9\IDS\Config\analyzerFilterConfig.xml
c:\programdata\avg9\IDS\Config\BehavioralEventProcessors.xml
c:\programdata\avg9\IDS\Config\BehavioralEvents.xml
c:\programdata\avg9\IDS\Config\Classifiers.xml
c:\programdata\avg9\IDS\Config\Correlations.xml
c:\programdata\avg9\IDS\Config\downloadManager.xml
c:\programdata\avg9\IDS\Config\downloads.xml
c:\programdata\avg9\IDS\Config\EN_US\Characteristics.xml
c:\programdata\avg9\IDS\Config\EN_US\internalListStrings.xml
c:\programdata\avg9\IDS\Config\EN_US\reportableEvents.xml
c:\programdata\avg9\IDS\Config\ExecutableEvents.xml
c:\programdata\avg9\IDS\Config\FileCoverage.xml
c:\programdata\avg9\IDS\Config\globalConfig.xml
c:\programdata\avg9\IDS\Config\internalList.zip
c:\programdata\avg9\IDS\Config\internalList.zip.bak
c:\programdata\avg9\IDS\Config\messages.xml
c:\programdata\avg9\IDS\Config\NetworkEvents.xml
c:\programdata\avg9\IDS\Config\ProductParameters.xml
c:\programdata\avg9\IDS\Config\quarantinedList.zip
c:\programdata\avg9\IDS\Config\quarantinedList.zip.bak
c:\programdata\avg9\IDS\Config\RegistryCoverage.xml
c:\programdata\avg9\IDS\Config\Relationships.xml
c:\programdata\avg9\IDS\Config\ReportableEventMappings.xml
c:\programdata\avg9\IDS\Config\SelfProtection.xml
c:\programdata\avg9\IDS\Config\userList.zip
c:\programdata\avg9\IDS\Config\userList.zip.bak
c:\programdata\avg9\IDS\log\AVGIDSAgent.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_boot.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_graph.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_malware.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_node.log
c:\programdata\avg9\IDS\log\AVGIDSAgent_removed.log
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AIM6_AIM6.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AIM6_AOLSOFTWARE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGEMC.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGEMC.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGTRAY.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGTRAY.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUI.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUI.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGUPD.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_AVG_AVG9_AVGWDSVC.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_BONJOUR_MDNSRESPONDER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_BONJOUR_MDNSRESPONDER.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_APPLE_MOBILE DEVICE SUPPORT_BIN_APPLEMOBILEDEVICESERVICE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_MCAFEE_MCSVCHOST_MCSVHOST.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_COMMON FILES_MCAFEE_MCSVCHOST_MCSVHOST.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_ITUNES_ITUNESHELPER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_LAVASOFT_AD-AWARE_AAWSERVICE.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_LAVASOFT_AD-AWARE_AAWSERVICE.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MALWAREBYTES' ANTI-MALWARE_MBAM.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MOZILLA FIREFOX_FIREFOX.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_MOZILLA FIREFOX_FIREFOX.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS MEDIA PLAYER_WMPLAYER.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS SIDEBAR_SIDEBAR.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAM FILES_WINDOWS SIDEBAR_SIDEBAR.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__PROGRAMDATA_KASPERSKY LAB SETUP FILES_KASPERSKY ANTI-VIRUS 2010 9.0.0.736_ENGLISH_SETUP.EXE.ndb
c:\programdata\avg9\IDS\profile\C__PROGRAMDATA_KASPERSKY LAB SETUP FILES_KASPERSKY ANTI-VIRUS 2010 9.0.0.736_ENGLISH_SETUP.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_LSASS.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SERVICES.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SERVICES.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SVCHOST.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_SVCHOST.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WERFAULT.EXE.ndb
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WERFAULT.EXE.ndb_ndb.bak
c:\programdata\avg9\IDS\profile\C__WINDOWS_SYSTEM32_WININIT.EXE.ndb
c:\programdata\avg9\IDS\profile\globalLoadable.bak
c:\programdata\avg9\IDS\profile\MalwareNetwork.bak
c:\programdata\avg9\IDS\profile\MalwareNetwork.xml
c:\programdata\avg9\IDS\profile\SYSTEM.ndb
c:\programdata\avg9\Log\avgam.log
c:\programdata\avg9\Log\avgam.log.lock
c:\programdata\avg9\Log\avgcfg.log
c:\programdata\avg9\Log\avgcfg.log.lock
c:\programdata\avg9\Log\avgchjw.log
c:\programdata\avg9\Log\avgchjw.log.lock
c:\programdata\avg9\Log\avgchjwsrv.log
c:\programdata\avg9\Log\avgchjwsrv.log.lock
c:\programdata\avg9\Log\avgcore.log
c:\programdata\avg9\Log\avgcore.log.1
c:\programdata\avg9\Log\avgcore.log.2
c:\programdata\avg9\Log\avgcore.log.3
c:\programdata\avg9\Log\avgcore.log.4
c:\programdata\avg9\Log\avgcore.log.5
c:\programdata\avg9\Log\avgcore.log.6
c:\programdata\avg9\Log\avgcore.log.lock
c:\programdata\avg9\Log\avgfrw.log
c:\programdata\avg9\Log\avgfrw.log.lock
c:\programdata\avg9\Log\avgfw.log
c:\programdata\avg9\Log\avgfw.log.lock
c:\programdata\avg9\Log\avgfw8db.log
c:\programdata\avg9\Log\avgfw8db.log.lock
c:\programdata\avg9\Log\avgfw8u.log
c:\programdata\avg9\Log\avgfw8u.log.lock
c:\programdata\avg9\Log\avgfwui.log
c:\programdata\avg9\Log\avgfwui.log.lock
c:\programdata\avg9\Log\avgldr.log
c:\programdata\avg9\Log\avgldr.log.lock
c:\programdata\avg9\Log\avglng.log
c:\programdata\avg9\Log\avglng.log.lock
c:\programdata\avg9\Log\avgns.log
c:\programdata\avg9\Log\avgns.log.lock
c:\programdata\avg9\Log\avgrs.log
c:\programdata\avg9\Log\avgrs.log.lock
c:\programdata\avg9\Log\avgscan.log
c:\programdata\avg9\Log\avgscan.log.lock
c:\programdata\avg9\Log\avgsched.log
c:\programdata\avg9\Log\avgsched.log.lock
c:\programdata\avg9\Log\avgsrm.log
c:\programdata\avg9\Log\avgsrm.log.lock
c:\programdata\avg9\Log\avgsrmac.log
c:\programdata\avg9\Log\avgsrmac.log.lock
c:\programdata\avg9\Log\avgsrmacstat.log
c:\programdata\avg9\Log\avgsrmacstat.log.lock
c:\programdata\avg9\Log\avgtdi.log
c:\programdata\avg9\Log\avgtdi.log.lock
c:\programdata\avg9\Log\avgui.log
c:\programdata\avg9\Log\avgui.log.lock
c:\programdata\avg9\Log\avgupd.log
c:\programdata\avg9\Log\avgupd.log.lock
c:\programdata\avg9\Log\avgwd.log
c:\programdata\avg9\Log\avgwd.log.lock
c:\programdata\avg9\Log\avgwdsvc.log
c:\programdata\avg9\Log\avgwdsvc.log.lock
c:\programdata\avg9\Log\commonpriv.log
c:\programdata\avg9\Log\commonpriv.log.1
c:\programdata\avg9\Log\commonpriv.log.lock
c:\programdata\avg9\Log\fixcfg.log
c:\programdata\avg9\Log\fixcfg.log.lock
c:\programdata\avg9\Log\history.xml
c:\programdata\avg9\Log\IDP\log\avgam_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\IDP\log\avgfws9_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\IDP\log\avgtray_idp_computer.log
c:\programdata\avg9\Log\IDP\log\avgui_idp_computer.log
c:\programdata\avg9\Log\IDP\log\avgwdsvc_idp_COMPUTER-PC$.log
c:\programdata\avg9\Log\vault.log
c:\programdata\avg9\Log\vault.log.lock
c:\programdata\avg9\Lsdb\Prev\prvglbl.dat
c:\programdata\avg9\scanlogs\I_00000001.log
c:\programdata\avg9\scanlogs\I_00000005.log
c:\programdata\avg9\scanlogs\I_00000006.log
c:\programdata\avg9\scanlogs\I_00000007.log
c:\programdata\avg9\scanlogs\I_00000008.log
c:\programdata\avg9\scanlogs\srm.idx
c:\programdata\avg9\Temp\17aa3fc5-cf8c-4357-950c-01457f769269-f7c-oopp.tmp
c:\programdata\avg9\Temp\40524d3a-865a-4a84-8be3-c2e2f847d52c-e1c-oopp.tmp
c:\programdata\avg9\Temp\787a1ea5-680a-4f31-a958-f35c22c04605-1008-oopp.tmp
c:\programdata\avg9\Temp\b6ec7eda-7e9a-4d41-bdc2-3680a6593d49-344-oopp.tmp
c:\programdata\avg9\Temp\c0dfddc4-9be8-498b-b40c-79070b62e8a7-344-oopp.tmp
c:\programdata\avg9\Temp\c3407ca5-c112-4123-ba8d-bedca06b7be7-10cc-oopp.tmp
c:\programdata\avg9\Temp\file9514.tmp
c:\programdata\avg9\update\backup\sb.dat
c:\programdata\avg9\update\backup\sb.dat.xcd
c:\programdata\avg9\update\backup\sb2.dat
c:\programdata\avg9\update\backup\sc.dat
c:\programdata\avg9\update\backup\sc.dat.xcd
c:\programdata\avg9\update\download\avg9infoavi.ctf
c:\programdata\avg9\update\download\avg9infowin.ctf
c:\programdata\avg9\update\download\x8xplsb_169rr.bin
c:\programdata\avg9\update\download\x8xplsb2_141w3.bin
c:\programdata\avg9\update\download\x8xplsc_22587.bin
c:\programdata\Viewpoint
c:\users\computer\AppData\Local\xgbeijmjo

.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-31 )))))))))))))))))))))))))))))))
.

2010-05-31 23:31 . 2010-05-31 23:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-31 21:57 . 2010-05-31 21:57 -------- d-----w- c:\users\computer\AppData\Local\Adobe
2010-05-27 07:35 . 2010-04-13 00:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-27 01:26 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-25 17:18 . 2010-05-25 17:18 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-05-24 20:32 . 2008-01-31 01:36 90112 ----a-w- c:\windows\unvise32.exe
2010-05-21 08:37 . 2010-05-22 05:17 -------- d-----w- c:\users\computer\AppData\Roaming\Auslogics
2010-05-21 08:37 . 2010-05-21 08:40 -------- d-----w- c:\program files\Auslogics
2010-05-19 10:01 . 2010-05-19 10:01 -------- d-----w- c:\windows\CheckSur
2010-05-18 10:21 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-18 10:20 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-18 10:01 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-18 10:00 . 2010-05-12 18:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 08:22 . 2010-05-18 08:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\users\computer\AppData\Roaming\Malwarebytes
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\programdata\Malwarebytes
2010-05-18 07:58 . 2010-05-18 10:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-09 13:14 . 2010-05-29 05:36 -------- d-----w- C:\PERRLA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-28 06:11 . 2009-09-12 07:24 -------- d-----w- c:\program files\McAfee
2010-05-27 07:35 . 2008-04-09 04:45 -------- d-----w- c:\program files\Java
2010-05-27 07:34 . 2009-09-12 10:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-05-27 00:47 . 2009-09-11 09:45 -------- d-----w- c:\programdata\McAfee
2010-05-27 00:44 . 2009-09-12 07:24 -------- d-----w- c:\program files\Common Files\McAfee
2010-05-27 00:44 . 2009-09-16 08:03 -------- d-----w- c:\programdata\Yahoo! Companion
2010-05-27 00:30 . 2009-09-11 11:51 1356 ----a-w- c:\users\computer\AppData\Local\d3d9caps.dat
2010-05-23 23:57 . 2009-09-20 06:43 -------- d-----w- c:\programdata\Soulseek
2010-05-23 06:30 . 2009-09-11 06:53 -------- d-----w- c:\program files\Common Files\AOL
2010-05-21 18:55 . 2009-09-11 06:41 77928 ----a-w- c:\users\computer\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-21 09:13 . 2006-11-02 06:37 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-05-21 09:13 . 2010-01-19 07:58 819200 ----a-w- c:\windows\system32\xvidcore.dll
2010-05-21 09:13 . 2010-01-19 07:58 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-05-21 09:13 . 2008-04-29 12:49 237568 ----a-w- c:\windows\system32\UCI32M29.dll
2010-05-21 09:13 . 2008-04-09 05:22 221184 ----a-w- c:\windows\system32\UCI32M22.dll
2010-05-21 09:09 . 2009-11-15 05:06 1196032 ----a-w- c:\windows\RtlUpd.exe
2010-05-21 09:09 . 2009-11-15 05:06 520192 ----a-w- c:\windows\RtlExUpd.dll
2010-05-21 09:08 . 2009-11-15 05:06 315392 ----a-w- c:\windows\HideWin.exe
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\taskMgrPrefs.exe
2010-05-21 09:08 . 2008-04-09 04:47 81920 ----a-w- c:\windows\Help\OEM\scripts\HPPhoneNumbers.exe
2010-05-21 09:08 . 2008-04-09 04:47 53248 ----a-w- c:\windows\Help\OEM\scripts\HPASL.exe
2010-05-21 09:08 . 2008-04-09 04:47 4096 ----a-w- c:\windows\Help\OEM\scripts\Interop.HelpPane.dll
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\launchAP.exe
2010-05-21 09:04 . 2009-10-25 22:30 81920 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 413696 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 401408 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041D\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 147456 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041E\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 397312 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0414\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 282624 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0411\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 196608 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0410\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 176128 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040e\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 73728 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040b\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 94208 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0408\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 253952 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0404\CNMur9I.dll
2010-05-19 18:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-18 09:46 . 2009-09-16 01:55 -------- d-----w- c:\programdata\Microsoft Help
2010-05-18 09:38 . 2009-09-12 10:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-18 09:38 . 2009-11-11 03:34 -------- d-----w- c:\program files\iTunes
2010-04-24 05:30 . 2010-04-24 05:30 -------- d-----w- c:\users\computer\AppData\Roaming\muvee Technologies
2010-04-23 17:32 . 2010-04-23 17:32 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-28 23:48 . 2010-03-28 23:48 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-03-28 23:47 . 2010-03-28 23:47 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2010-03-09 16:28 . 2010-03-31 17:32 833024 ----a-w- c:\windows\system32\wininet.dll
2010-03-09 16:25 . 2010-03-31 17:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 14:01 . 2010-03-31 17:32 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-03-04 18:54 . 2010-04-14 17:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2009-10-24 19:00 . 2009-10-24 19:00 22 --sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2010-05-21 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-05-21 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-03 178712]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]

c:\users\computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-19 1314704]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-03-26 93320]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

.
Contents of the 'Scheduled Tasks' folder

2010-05-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 01:51]

2010-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 19:22]

2010-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 19:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\computer\AppData\Roaming\Mozilla\Firefox\Profiles\ttggtg9q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-31 16:35
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(4948)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-05-31 16:38:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-31 23:38
ComboFix2.txt 2010-05-27 22:23

Pre-Run: 496,572,063,744 bytes free
Post-Run: 496,435,789,824 bytes free

- - End Of File - - 3EAB776F6B2B17F445B996A5B9D368B1
  • 0

Similar Topics: pretty sure i have a virus but, scans don't find it [Solved]     x


#17
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

Folder::
c:\program files\McAfee
c:\programdata\McAfee
c:\program files\COMMON files\mcafee

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...


Posted Image

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
  • 0

#18
death salad

death salad

    New Member

  • Member
  • Pip
  • 9 posts
took even longer to startup this time







ComboFix 10-05-31.02 - computer 05/31/2010 16:55:27.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3062.1699 [GMT -7:00]
Running from: c:\users\computer\Desktop\ComboFix.exe
Command switches used :: c:\users\computer\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\COMMON files\mcafee
c:\program files\COMMON files\mcafee\Core\mccore.inf
c:\program files\COMMON files\mcafee\Core\mccoreps.dll
c:\program files\COMMON files\mcafee\Core\McEvtBrk.dll
c:\program files\COMMON files\mcafee\Core\mchost.exe
c:\program files\COMMON files\mcafee\FWDriver\fwdrv.inf
c:\program files\COMMON files\mcafee\FWDriver\fwdrvins.exe
c:\program files\COMMON files\mcafee\FWDriver\fwdrvver.dll
c:\program files\COMMON files\mcafee\FWDriver\mpfp.cat
c:\program files\COMMON files\mcafee\FWDriver\mpfp.sys
c:\program files\COMMON files\mcafee\HackerWatch\HWAPI.dll
c:\program files\COMMON files\mcafee\HackerWatch\hwapi.inf
c:\program files\COMMON files\mcafee\HackerWatch\hwupdchk.exe
c:\program files\COMMON files\mcafee\Installer\mcinst.exe
c:\program files\COMMON files\mcafee\McProxy\McProxy.exe
c:\program files\COMMON files\mcafee\McProxy\McProxy.inf
c:\program files\COMMON files\mcafee\McProxy\Proxyver.dll
c:\program files\COMMON files\mcafee\McProxy\rmoldfile.inf
c:\program files\COMMON files\mcafee\MNA\1033\McUJGuiRes.dll
c:\program files\COMMON files\mcafee\MNA\1033\mnalang.inf
c:\program files\COMMON files\mcafee\MNA\McNaIns.dll
c:\program files\COMMON files\mcafee\MNA\McNAReg.dll
c:\program files\COMMON files\mcafee\MNA\McNARegPS.dll
c:\program files\COMMON files\mcafee\MNA\McNASvc.exe
c:\program files\COMMON files\mcafee\MNA\McNASvcPS.dll
c:\program files\COMMON files\mcafee\MNA\McUJ.dll
c:\program files\COMMON files\mcafee\MNA\McUJGui.exe
c:\program files\COMMON files\mcafee\MNA\McUJGuiPS.dll
c:\program files\COMMON files\mcafee\MNA\mna.inf
c:\program files\COMMON files\mcafee\MSC\mcbrwsr2.dll
c:\program files\COMMON files\mcafee\MSC\mccomctl.dll
c:\program files\COMMON files\mcafee\MSC\McDspWrp.dll
c:\program files\COMMON files\mcafee\MSC\McDspWrp.inf
c:\program files\COMMON files\mcafee\MSC\mcscrhlp.dll
c:\program files\COMMON files\mcafee\MSC\mcuc.inf
c:\program files\COMMON files\mcafee\MSC\McUICnt.exe
c:\program files\COMMON files\mcafee\MSC\mcutil.dll
c:\program files\COMMON files\mcafee\MSC\mcutil\9,15,101,0\mcutil.dll
c:\program files\COMMON files\mcafee\MSC\misplf.dll
c:\program files\COMMON files\mcafee\MSC\msccmn.inf
c:\program files\COMMON files\mcafee\MSC\sqlite3.dll
c:\program files\McAfee
c:\program files\McAfee\MBK\Arbus.Client.Base.dll
c:\program files\McAfee\MBK\Arbus.Client.BusinessObjects.dll
c:\program files\McAfee\MBK\Arbus.Client.PersonalArchivalEngine.Base.dll
c:\program files\McAfee\MBK\Arbus.Client.PersonalArchivalEngine.BusinessObjects.dll
c:\program files\McAfee\MBK\Arbus.Client.Resources.dll
c:\program files\McAfee\MBK\Arbus.Client.Test.TestingUtility.dll
c:\program files\McAfee\MBK\Arbus.Common.dll
c:\program files\McAfee\MBK\Arbus.Differential.dll
c:\program files\McAfee\MBK\Arbus.Interfacing.Library.dll
c:\program files\McAfee\MBK\Arbus.Server.dll
c:\program files\McAfee\MBK\Arbus.Utility.Compression.dll
c:\program files\McAfee\MBK\Arbus.Utility.Compression.SevenZip.dll
c:\program files\McAfee\MBK\Arbus.Utility.Encryption.BlowfishProvider.dll
c:\program files\McAfee\MBK\Arbus.Utility.Encryption.dll
c:\program files\McAfee\MBK\Arbus.Utility.WsCompression.dll
c:\program files\McAfee\MBK\Arbus.Windows.Controls.dll
c:\program files\McAfee\MBK\ArbusApplicationController.dll
c:\program files\McAfee\MBK\ArbusComLib.dll
c:\program files\McAfee\MBK\ArbusComLib.ini
c:\program files\McAfee\MBK\BlowfishOpimized.dll
c:\program files\McAfee\MBK\DefaultStore\ARBUSFILE.GDB
c:\program files\McAfee\MBK\Differential.dll
c:\program files\McAfee\MBK\EnterpriseLibrary.Security.Cryptography.config
c:\program files\McAfee\MBK\ErrorReporter.exe
c:\program files\McAfee\MBK\ErrorReporter.exe.config
c:\program files\McAfee\MBK\fbembed.dll
c:\program files\McAfee\MBK\FirebirdSql.Data.Firebird.dll
c:\program files\McAfee\MBK\hpCDE.NET.1.1.dll
c:\program files\McAfee\MBK\instLD.inf
c:\program files\McAfee\MBK\Interop.MBKAlertLib.dll
c:\program files\McAfee\MBK\Interop.MBKClientEncodeLib.dll
c:\program files\McAfee\MBK\Interop.MBKProvider.dll
c:\program files\McAfee\MBK\L10N.dll
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\program files\McAfee\MBK\MBackMonitor.exe.config
c:\program files\McAfee\MBK\MBKAlert.dll
c:\program files\McAfee\MBK\MBKAlertHelper.exe
c:\program files\McAfee\MBK\MBKAlertHelper.exe.config
c:\program files\McAfee\MBK\MBKClient.dll
c:\program files\McAfee\MBK\MBKCore.inf
c:\program files\McAfee\MBK\MBKInstaller.exe
c:\program files\McAfee\MBK\MBKInstaller.exe.config
c:\program files\McAfee\MBK\MBKLaunch.exe
c:\program files\McAfee\MBK\mbkloc.inf
c:\program files\McAfee\MBK\mbkmainLD.inf
c:\program files\McAfee\MBK\mbkmainLI.inf
c:\program files\McAfee\MBK\MBKProv.dll
c:\program files\McAfee\MBK\MBKRegister.exe
c:\program files\McAfee\MBK\mbksbt.inf
c:\program files\McAfee\MBK\McAfee.ico
c:\program files\McAfee\MBK\McAfeeDataBackup.exe
c:\program files\McAfee\MBK\McAfeeDataBackup.exe.config
c:\program files\McAfee\MBK\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll
c:\program files\McAfee\MBK\Microsoft.ApplicationBlocks.Updater.dll
c:\program files\McAfee\MBK\Microsoft.ApplicationBlocks.Updater.Downloaders.dll
c:\program files\McAfee\MBK\Microsoft.Practices.EnterpriseLibrary.Common.dll
c:\program files\McAfee\MBK\Microsoft.Practices.EnterpriseLibrary.Configuration.dll
c:\program files\McAfee\MBK\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll
c:\program files\McAfee\MBK\Microsoft.Web.Services2.dll
c:\program files\McAfee\MBK\msvcp60.dll
c:\program files\McAfee\MBK\nunit.framework.dll
c:\program files\McAfee\MBK\subst.inf
c:\program files\McAfee\MBK\substLI.inf
c:\program files\McAfee\MBK\testcompressionConfiguration.config
c:\program files\McAfee\MBK\UnmanagedResource.dll
c:\program files\McAfee\MBK\updaterconfiguration.config
c:\program files\McAfee\MBK\WSCompression.dll
c:\program files\McAfee\MBK\XPExplorerBar.dll
c:\program files\McAfee\MBK\XtraProgressBar.dll
c:\program files\McAfee\MBK\ZipNewProvider.dll
c:\program files\McAfee\MPF\1033\instLD.inf
c:\program files\McAfee\MPF\1033\L10N.dll
c:\program files\McAfee\MPF\1033\mpfHelp.inf
c:\program files\McAfee\MPF\1033\mpfloc.inf
c:\program files\McAfee\MPF\1033\subst.inf
c:\program files\McAfee\MPF\data\sports\DirServ.cfg
c:\program files\McAfee\MPF\data\sports\FTPServ.cfg
c:\program files\McAfee\MPF\data\sports\IMAPServ.cfg
c:\program files\McAfee\MPF\data\sports\NetBIOS.cfg
c:\program files\McAfee\MPF\data\sports\NTP.cfg
c:\program files\McAfee\MPF\data\sports\OS.cfg
c:\program files\McAfee\MPF\data\sports\Pop3Serv.cfg
c:\program files\McAfee\MPF\data\sports\RemAsst.cfg
c:\program files\McAfee\MPF\data\sports\RPCServ.cfg
c:\program files\McAfee\MPF\data\sports\SecWeb.cfg
c:\program files\McAfee\MPF\data\sports\SMTPServ.cfg
c:\program files\McAfee\MPF\data\sports\SQLServ.cfg
c:\program files\McAfee\MPF\data\sports\update\DirServ.cfg
c:\program files\McAfee\MPF\data\sports\update\FTPServ.cfg
c:\program files\McAfee\MPF\data\sports\update\IMAPServ.cfg
c:\program files\McAfee\MPF\data\sports\update\NetBIOS.cfg
c:\program files\McAfee\MPF\data\sports\update\NTP.cfg
c:\program files\McAfee\MPF\data\sports\update\OS.cfg
c:\program files\McAfee\MPF\data\sports\update\Pop3Serv.cfg
c:\program files\McAfee\MPF\data\sports\update\RemAsst.cfg
c:\program files\McAfee\MPF\data\sports\update\RPCServ.cfg
c:\program files\McAfee\MPF\data\sports\update\SecWeb.cfg
c:\program files\McAfee\MPF\data\sports\update\SMTPServ.cfg
c:\program files\McAfee\MPF\data\sports\update\SQLServ.cfg
c:\program files\McAfee\MPF\data\sports\update\UPNP.cfg
c:\program files\McAfee\MPF\data\sports\update\WebServ.cfg
c:\program files\McAfee\MPF\data\sports\UPNP.cfg
c:\program files\McAfee\MPF\data\sports\WebServ.cfg
c:\program files\McAfee\MPF\MC\MpfAlert.exe
c:\program files\McAfee\MPF\MC\MpfAltPS.dll
c:\program files\McAfee\MPF\MC\MpfMISP.dll
c:\program files\McAfee\MPF\MC\MPFOEM.dll
c:\program files\McAfee\MPF\MC\MPFP.dll
c:\program files\McAfee\MPF\MC\MPFPPS.dll
c:\program files\McAfee\MPF\mpfcore.inf
c:\program files\McAfee\MPF\mpfdata.inf
c:\program files\McAfee\MPF\mpfLD.inf
c:\program files\McAfee\MPF\mpfLI.inf
c:\program files\McAfee\MPF\mpfmspLI.inf
c:\program files\McAfee\MPF\mpfsbt.inf
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\MPF\mpfuc.dll
c:\program files\McAfee\MPF\mpfuc.inf
c:\program files\McAfee\MPF\mpfui.inf
c:\program files\McAfee\MPF\substLI.inf
c:\program files\McAfee\MPS\1033\instld.inf
c:\program files\McAfee\MPS\1033\keywords.inf
c:\program files\McAfee\MPS\1033\mpshelp.inf
c:\program files\McAfee\MPS\1033\MpsRes.dll
c:\program files\McAfee\MPS\1033\MpsRes.inf
c:\program files\McAfee\MPS\1033\subst.inf
c:\program files\McAfee\MPS\checkmps.dll
c:\program files\McAfee\MPS\IAEngine.dll
c:\program files\McAfee\MPS\IAImageReader.dll
c:\program files\McAfee\MPS\mctgrid.dll
c:\program files\McAfee\MPS\mps.dll
c:\program files\McAfee\MPS\MpsAlert.exe
c:\program files\McAfee\MPS\mpscfg.dll
c:\program files\McAfee\MPS\mpscfg.inf
c:\program files\McAfee\MPS\mpscnfg.inf
c:\program files\McAfee\MPS\mpscore.inf
c:\program files\McAfee\MPS\mpsdeflt.inf
c:\program files\McAfee\MPS\mpsevh.dll
c:\program files\McAfee\MPS\mpsld.inf
c:\program files\McAfee\MPS\mpsli.inf
c:\program files\McAfee\MPS\MPSMisp.dll
c:\program files\McAfee\MPS\mpsmisp.inf
c:\program files\McAfee\MPS\mpsmspap.dll
c:\program files\McAfee\MPS\mpsmsppv.inf
c:\program files\McAfee\MPS\mpspc.dll
c:\program files\McAfee\MPS\mpspii.dll
c:\program files\McAfee\MPS\mpspost.inf
c:\program files\McAfee\MPS\mpspv.dll
c:\program files\McAfee\MPS\mpssbt.inf
c:\program files\McAfee\MPS\mpsuc.dll
c:\program files\McAfee\MPS\mpsuc.inf
c:\program files\McAfee\MPS\mpsui.dll
c:\program files\McAfee\MPS\mpsui.inf
c:\program files\McAfee\MPS\mpsver.dll
c:\program files\McAfee\MPS\substli.inf
c:\program files\McAfee\MQC\1033\mcpLD.inf
c:\program files\McAfee\MQC\1033\mcqchelp.inf
c:\program files\McAfee\MQC\1033\mcqcres.inf
c:\program files\McAfee\MQC\1033\QcRes.dll
c:\program files\McAfee\MQC\McpAdmin.exe
c:\program files\McAfee\MQC\McpIns.dll
c:\program files\McAfee\MQC\mcpins.inf
c:\program files\McAfee\MQC\mcpLI.inf
c:\program files\McAfee\MQC\McpSched.dll
c:\program files\McAfee\MQC\mcqc.inf
c:\program files\McAfee\MQC\MRU.ini
c:\program files\McAfee\MQC\QcConsol.exe
c:\program files\McAfee\MQC\QCLite.dll
c:\program files\McAfee\MQC\QCMISP.dll
c:\program files\McAfee\MSC\1033\instLD.inf
c:\program files\McAfee\MSC\1033\instLDNMC.inf
c:\program files\McAfee\MSC\1033\mclocres.dll
c:\program files\McAfee\MSC\1033\McNDCoR.dll
c:\program files\McAfee\MSC\1033\McNDLor.dll
c:\program files\McAfee\MSC\1033\McNmcCoR.dll
c:\program files\McAfee\MSC\1033\McNmcLoR.dll
c:\program files\McAfee\MSC\1033\mschelp.inf
c:\program files\McAfee\MSC\1033\mscinres.dll
c:\program files\McAfee\MSC\1033\msclcres.inf
c:\program files\McAfee\MSC\1033\mscpstLD.inf
c:\program files\McAfee\MSC\1033\ndLD.inf
c:\program files\McAfee\MSC\1033\nmchelp.inf
c:\program files\McAfee\MSC\1033\nmclang.inf
c:\program files\McAfee\MSC\1033\nmcoem.inf
c:\program files\McAfee\MSC\1033\nmcpstld.inf
c:\program files\McAfee\MSC\Custom_Uninstall\mcregist.inf
c:\program files\McAfee\MSC\eulares.dll
c:\program files\McAfee\MSC\mcactwiz.dll
c:\program files\McAfee\MSC\mcaltlib.dll
c:\program files\McAfee\MSC\mccfgmgr.dll
c:\program files\McAfee\MSC\mccfgpv.dll
c:\program files\McAfee\MSC\mccobres.dll
c:\program files\McAfee\MSC\McDBMgr.dll
c:\program files\McAfee\MSC\mcdemenu.dll
c:\program files\McAfee\MSC\mcinfo.exe
c:\program files\McAfee\MSC\mclgview.exe
c:\program files\McAfee\MSC\McLogCnt.dll
c:\program files\McAfee\MSC\mcltvers.ini
c:\program files\McAfee\MSC\mcmismgr.dll
c:\program files\McAfee\MSC\mcmispps.dll
c:\program files\McAfee\MSC\mcmispps.inf
c:\program files\McAfee\MSC\mcmnumgr.dll
c:\program files\McAfee\MSC\mcmscins.dll
c:\program files\McAfee\MSC\mcmscsvc.exe
c:\program files\McAfee\MSC\mcmscver.dll
c:\program files\McAfee\MSC\McNDCP.dll
c:\program files\McAfee\MSC\McNDCPPS.dll
c:\program files\McAfee\MSC\McNDRes.dll
c:\program files\McAfee\MSC\McNDSv.dll
c:\program files\McAfee\MSC\McNDSVPS.dll
c:\program files\McAfee\MSC\McNDUI.exe
c:\program files\McAfee\MSC\McNDUIPS.dll
c:\program files\McAfee\MSC\McNmcCnt.dll
c:\program files\McAfee\MSC\McNmcCPS.dll
c:\program files\McAfee\MSC\McNmcIns.dll
c:\program files\McAfee\MSC\McNmcPrv.dll
c:\program files\McAfee\MSC\McNmcRes.dll
c:\program files\McAfee\MSC\McNmcSPS.dll
c:\program files\McAfee\MSC\McNmcSrv.dll
c:\program files\McAfee\MSC\McNmcUI.dll
c:\program files\McAfee\MSC\McNmcVer.dll
c:\program files\McAfee\MSC\mcprohlp.dll
c:\program files\McAfee\MSC\mcprotpv.dll
c:\program files\McAfee\MSC\mcprtcnt.dll
c:\program files\McAfee\MSC\mcregist.exe
c:\program files\McAfee\MSC\mcregobj\9,15,126,0\mcregobj.dll
c:\program files\McAfee\MSC\mcregoem.ini
c:\program files\McAfee\MSC\mcres.dll
c:\program files\McAfee\MSC\mcrgwcln.exe
c:\program files\McAfee\MSC\mcshell.exe
c:\program files\McAfee\MSC\mcshllps.dll
c:\program files\McAfee\MSC\Mcshlrtl.dll
c:\program files\McAfee\MSC\mcshlui.dll
c:\program files\McAfee\MSC\mcsubmgr\9,15,126,0\mcsubmgr.dll
c:\program files\McAfee\MSC\mcsvrcnt.exe
c:\program files\McAfee\MSC\mcsync.exe
c:\program files\McAfee\MSC\mcuicfg.dll
c:\program files\McAfee\MSC\mcuihost.exe
c:\program files\McAfee\MSC\mcuninst.exe
c:\program files\McAfee\MSC\mcupdmgr.exe
c:\program files\McAfee\MSC\mcupdui.exe
c:\program files\McAfee\MSC\McUpdUtl.exe
c:\program files\McAfee\MSC\McUpdUtl.exe.manifest
c:\program files\McAfee\MSC\mispreg.exe
c:\program files\McAfee\MSC\msccfmgr.inf
c:\program files\McAfee\MSC\mscdfoem.inf
c:\program files\McAfee\MSC\mscLD.inf
c:\program files\McAfee\MSC\mscLI.inf
c:\program files\McAfee\MSC\mscmisc.inf
c:\program files\McAfee\MSC\mscmnmgr.inf
c:\program files\McAfee\MSC\mscoobe.inf
c:\program files\McAfee\MSC\mscprmgr.inf
c:\program files\McAfee\MSC\mscpstLI.inf
c:\program files\McAfee\MSC\mscreg.inf
c:\program files\McAfee\MSC\mscrem.inf
c:\program files\McAfee\MSC\mscres.inf
c:\program files\McAfee\MSC\mscshll.inf
c:\program files\McAfee\MSC\mscsvc.inf
c:\program files\McAfee\MSC\mscuimgr.inf
c:\program files\McAfee\MSC\mscupd.inf
c:\program files\McAfee\MSC\ndLI.inf
c:\program files\McAfee\MSC\NMC\nmcLI.inf
c:\program files\McAfee\MSC\NMC\nmcsubst.inf
c:\program files\McAfee\MSC\nmcclnt.inf
c:\program files\McAfee\MSC\nmcins.inf
c:\program files\McAfee\MSC\nmcLD.inf
c:\program files\McAfee\MSC\nmcLI.inf
c:\program files\McAfee\MSC\nmcpre.inf
c:\program files\McAfee\MSC\nmcpstli.inf
c:\program files\McAfee\MSC\nmcres.inf
c:\program files\McAfee\MSC\nmcsrv.inf
c:\program files\McAfee\MSC\oem\634-2\mccobres.dll
c:\program files\McAfee\MSC\OemInfo\{0c1e738d-aab0-493f-ab41-c3924c7f57c2}\en-US\regurl.inf
c:\program files\McAfee\MSC\OemInfo\MBK\en-US\634-2\mbkoem.inf
c:\program files\McAfee\MSC\OemInfo\MBK\en-US\634-2\mbkrgw.inf
c:\program files\McAfee\MSC\OemInfo\MPF\en-US\634-2\mpffs.inf
c:\program files\McAfee\MSC\OemInfo\MPF\en-US\634-2\mpfoem.inf
c:\program files\McAfee\MSC\OemInfo\MPF\en-US\634-2\mpfrgw.inf
c:\program files\McAfee\MSC\OemInfo\MPF\en-US\634-2\mpfub.inf
c:\program files\McAfee\MSC\OemInfo\MPF\en-US\634-2\mpfus.inf
c:\program files\McAfee\MSC\OemInfo\MPS\en-US\634-2\mpsfs.inf
c:\program files\McAfee\MSC\OemInfo\MPS\en-US\634-2\mpsoem.inf
c:\program files\McAfee\MSC\OemInfo\MPS\en-US\634-2\mpsrgw.inf
c:\program files\McAfee\MSC\OemInfo\MPS\en-US\634-2\mpsub.inf
c:\program files\McAfee\MSC\OemInfo\MPS\en-US\634-2\mpsus.inf
c:\program files\McAfee\MSC\OemInfo\MSAD\en-US\634-2\msadoem.inf
c:\program files\McAfee\MSC\OemInfo\MSAD\en-US\634-2\msadrgw.inf
c:\program files\McAfee\MSC\OemInfo\MSC\en-US\634-2\mscoem.inf
c:\program files\McAfee\MSC\OemInfo\MSK\en-US\634-2\mskfs.inf
c:\program files\McAfee\MSC\OemInfo\MSK\en-US\634-2\mskoem.inf
c:\program files\McAfee\MSC\OemInfo\MSK\en-US\634-2\mskrgw.inf
c:\program files\McAfee\MSC\OemInfo\MSK\en-US\634-2\mskub.inf
c:\program files\McAfee\MSC\OemInfo\MSK\en-US\634-2\mskus.inf
c:\program files\McAfee\MSC\OemInfo\VSO\en-US\634-2\vsofs.inf
c:\program files\McAfee\MSC\OemInfo\VSO\en-US\634-2\vsooem.inf
c:\program files\McAfee\MSC\OemInfo\VSO\en-US\634-2\vsorgw.inf
c:\program files\McAfee\MSC\OemInfo\VSO\en-US\634-2\vsoub.inf
c:\program files\McAfee\MSC\OemInfo\VSO\en-US\634-2\vsous.inf
c:\program files\McAfee\MSC\oemmap.ini
c:\program files\McAfee\MSC\rwcoreui.dll
c:\program files\McAfee\MSC\rwcorres.dll
c:\program files\McAfee\MSC\rwdimens.ini
c:\program files\McAfee\MSC\rwoemres.dll
c:\program files\McAfee\MSC\sasetup.exe
c:\program files\McAfee\MSC\subst.inf
c:\program files\McAfee\MSHR\1033\mcshrhelp.inf
c:\program files\McAfee\MSHR\1033\mcshrres.inf
c:\program files\McAfee\MSHR\1033\ShrRes.dll
c:\program files\McAfee\MSHR\mcshr.inf
c:\program files\McAfee\MSHR\ShrCL.exe
c:\program files\McAfee\MSHR\ShrCore.dll
c:\program files\McAfee\MSHR\Shredder.ini
c:\program files\McAfee\MSHR\ShrMISP.dll
c:\program files\McAfee\MSK\1033\instLD.inf
c:\program files\McAfee\MSK\1033\mskhlp.inf
c:\program files\McAfee\MSK\1033\mskres.dll
c:\program files\McAfee\MSK\1033\mskres.inf
c:\program files\McAfee\MSK\1033\mskui.dll
c:\program files\McAfee\MSK\1033\subst.inf
c:\program files\McAfee\MSK\antphish.inf
c:\program files\McAfee\MSK\masecore.dll
c:\program files\McAfee\MSK\mcabimp.dll
c:\program files\McAfee\MSK\mskapbho.dll
c:\program files\McAfee\MSK\mskcmcnt.inf
c:\program files\McAfee\MSK\mskengn.dll
c:\program files\McAfee\MSK\Mskeuplg.dll
c:\program files\McAfee\MSK\mskLD.inf
c:\program files\McAfee\MSK\mskLI.inf
c:\program files\McAfee\MSK\mskmisp.dll
c:\program files\McAfee\MSK\mskmisp.inf
c:\program files\McAfee\MSK\mskoeplg.dll
c:\program files\McAfee\MSK\mskolplg.dll
c:\program files\McAfee\MSK\mskplg.inf
c:\program files\McAfee\MSK\mskplg32.inf
c:\program files\McAfee\MSK\mskpxplg.dll
c:\program files\McAfee\MSK\msksbt.inf
c:\program files\McAfee\MSK\MskSet.dll
c:\program files\McAfee\MSK\msksrv.inf
c:\program files\McAfee\MSK\msksrver.exe
c:\program files\McAfee\MSK\msktb.dll
c:\program files\McAfee\MSK\mskuc.dll
c:\program files\McAfee\MSK\mskuc.inf
c:\program files\McAfee\MSK\mskupd.dll
c:\program files\McAfee\MSK\mskwm.dll
c:\program files\McAfee\MSK\mskxagnt.exe
c:\program files\McAfee\MSK\mskxaif.dll
c:\program files\McAfee\MSK\rptspam.dll
c:\program files\McAfee\MSK\substLI.inf
c:\program files\McAfee\MSK\tbirdins.dll
c:\program files\McAfee\MSM\McSmpUi.dll
c:\program files\McAfee\MSM\McSmtFwk.exe
c:\program files\McAfee\MSM\McSmtMsg.inf
c:\program files\McAfee\MSM\McSmtStr.dll
c:\program files\McAfee\MSM\McSmtTsk.dll
c:\program files\McAfee\SiteAdvisor\apengine.dll
c:\program files\McAfee\SiteAdvisor\chrome.manifest
c:\program files\McAfee\SiteAdvisor\cntscan.dll
c:\program files\McAfee\SiteAdvisor\Components\IMcFFPlg.xpt
c:\program files\McAfee\SiteAdvisor\Components\McFFPlg.dll
c:\program files\McAfee\SiteAdvisor\contents.rdf
c:\program files\McAfee\SiteAdvisor\default.txt
c:\program files\McAfee\SiteAdvisor\elist.dat
c:\program files\McAfee\SiteAdvisor\ffplg.inf
c:\program files\McAfee\SiteAdvisor\ieplg.inf
c:\program files\McAfee\SiteAdvisor\install.rdf
c:\program files\McAfee\SiteAdvisor\mcbrwctl.dll
c:\program files\McAfee\SiteAdvisor\mcfrmwk.dll
c:\program files\McAfee\SiteAdvisor\McIEPlg.dll
c:\program files\McAfee\SiteAdvisor\McPlgUI.dll
c:\program files\McAfee\SiteAdvisor\McSACore.exe
c:\program files\McAfee\SiteAdvisor\McSACorePS.dll
c:\program files\McAfee\SiteAdvisor\msacmain.inf
c:\program files\McAfee\SiteAdvisor\sa_cache_sqlite.dll
c:\program files\McAfee\SiteAdvisor\sa_http_win32.dll
c:\program files\McAfee\SiteAdvisor\SA_indep.inf
c:\program files\McAfee\SiteAdvisor\SA_main.inf
c:\program files\McAfee\SiteAdvisor\sa_mbl.dll
c:\program files\McAfee\SiteAdvisor\sa_store_sqlite.dll
c:\program files\McAfee\SiteAdvisor\SA_win32.inf
c:\program files\McAfee\SiteAdvisor\sac.inf
c:\program files\McAfee\SiteAdvisor\sachook.inf
c:\program files\McAfee\SiteAdvisor\sacimg.inf
c:\program files\McAfee\SiteAdvisor\sacomm.inf
c:\program files\McAfee\SiteAdvisor\sacore.dll
c:\program files\McAfee\SiteAdvisor\sacore.inf
c:\program files\McAfee\SiteAdvisor\sacres.inf
c:\program files\McAfee\SiteAdvisor\safelocalization.inf
c:\program files\McAfee\SiteAdvisor\sahook.dll
c:\program files\McAfee\SiteAdvisor\saplugin.dll
c:\program files\McAfee\SiteAdvisor\sares.dll
c:\program files\McAfee\SiteAdvisor\SASet.dll
c:\program files\McAfee\SiteAdvisor\saSets.ini
c:\program files\McAfee\SiteAdvisor\SaSSHMod.dll
c:\program files\McAfee\SiteAdvisor\saupkeep.dll
c:\program files\McAfee\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee\SiteAdvisor\Scripts\blackpixel.gif
c:\program files\McAfee\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\corner-solid.gif
c:\program files\McAfee\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-background.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-top.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-xup.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonC.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonL.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonR.gif
c:\program files\McAfee\SiteAdvisor\Scripts\main.js
c:\program files\McAfee\SiteAdvisor\Scripts\mainff.js
c:\program files\McAfee\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcwedge.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_arrow_down.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_arrow_up.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_black.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_black_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_disabled.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_green_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_grey.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_grey_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_hs_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_red_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_yellow_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protectedmode.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protmode-off.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protmode-on.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_r_nox.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sa-logo-plus.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sa-logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee\SiteAdvisor\Scripts\safe_ff.js
c:\program files\McAfee\SiteAdvisor\Scripts\safe_ie.js
c:\program files\McAfee\SiteAdvisor\Scripts\safesearch.js
c:\program files\McAfee\SiteAdvisor\Scripts\saffplg.js
c:\program files\McAfee\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee\SiteAdvisor\Scripts\selected_tab.gif
c:\program files\McAfee\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonC.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonL.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonR.gif
c:\program files\McAfee\SiteAdvisor\Scripts\unselected_tab.gif
c:\program files\McAfee\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_r_nox.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee\SiteAdvisor\sqlite3.dll
c:\program files\McAfee\SiteAdvisor\subst.inf
c:\program files\McAfee\SiteAdvisor\uninstall.exe
c:\programdata\McAfee
c:\programdata\McAfee\dspwrp\SmartMessaging.db
c:\programdata\McAfee\HackerWatch\data\hwid.idx
c:\programdata\McAfee\HackerWatch\data\HwLocal.xdb
c:\programdata\McAfee\HackerWatch\data\HwShared.xdb
c:\programdata\McAfee\MCLOGS(133)\Common\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\Common\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(133)\Common\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\Explorer\Explorer000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mcinfo\mcinfo000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\McUpdate\McUpdate000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(133)\CoreTech\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(133)\HWAPI\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(133)\MasterInstaller\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\mcinsspt\mcinsspt\mcinsspt000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\mpfLI.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\msccmn.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\mscmisc.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\mscreg.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\mscupd.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\rmoldfile.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\sa_main.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\subst.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McInst\vsopost.inf000.log
c:\programdata\McAfee\MCLOGS(133)\McMSCIns\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\McMSCIns\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(133)\McSvcHost\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(133)\McSync\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(133)\McUICnt\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(133)\mfehidin.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcagent\mcagent001.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcagent\mcagent002.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcappcfg\mcappcfg000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(133)\MISP\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcupdate\mcupdate000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(133)\MISP\OOBESVC\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(133)\MPF\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\MPF\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(133)\MPF\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(133)\MPF\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(133)\MPF\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(133)\MPF\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(133)\Pearl\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\Explorer\Explorer000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\Install\Install000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\McInsUpd\McInsUpd000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(133)\VirusScan\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\Common\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\Common\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(5)\Common\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\Explorer\Explorer000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcinfo\mcinfo000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\McSmtFwk\McSmtFwk000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\McUpdate\McUpdate000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mcvsshld\mcvsshld000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(5)\CoreTech\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(5)\HomeNet\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\HWAPI\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(5)\MasterInstaller\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\mcinsspt\mcinsspt\mcinsspt000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\msccmn.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\mscmisc.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\mscreg.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\mscupd.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\rmoldfile.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\sa_main.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\subst.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McInst\vsopost.inf000.log
c:\programdata\McAfee\MCLOGS(5)\McMSCIns\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\McMSCIns\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(5)\mcsmttsk\McUpdate\McUpdate000.log
c:\programdata\McAfee\MCLOGS(5)\McSvcHost\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\McSync\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(5)\McUICnt\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(5)\mfehidin.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcagent\mcagent001.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcagent\mcagent002.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcappcfg\mcappcfg000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(5)\MISP\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcsvrcnt\mcsvrcnt000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcupdate\mcupdate000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(5)\MISP\OOBESVC\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\MPF\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\MPF\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(5)\MPF\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\MPF\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(5)\MPF\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(5)\MPF\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(5)\MPF\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(5)\Pearl\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\Install\Install000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\McInsUpd\McInsUpd000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(5)\VirusScan\mcvsshld\mcvsshld000.log
c:\programdata\McAfee\MCLOGS(64)\Common\Install\Install000.log
c:\programdata\McAfee\MCLOGS(64)\Common\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\Common\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(64)\Common\mcuihost\mcuihost000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\Explorer\Explorer000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\Install\Install000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcinfo\mcinfo000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\McSmtFwk\McSmtFwk000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcuihost\mcuihost000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\McUpdate\McUpdate000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(64)\CoreTech\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(64)\HomeNet\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\HWAPI\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(64)\MasterInstaller\Install\Install000.log
c:\programdata\McAfee\MCLOGS(64)\mcinsspt\mcinsspt\mcinsspt000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\mcpLI.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\MPFrgw.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\MQSrgw.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\MSADrgw.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\msccmn.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\mscmisc.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\mscreg.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\mscupd.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\nmcLD.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\nmcli32.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\rmoldfile.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\sa_main.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\subst.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\vsopost.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McInst\VSOrgw.inf000.log
c:\programdata\McAfee\MCLOGS(64)\McMSCIns\Install\Install000.log
c:\programdata\McAfee\MCLOGS(64)\McMSCIns\rundll32\rundll32000.log
c:\programdata\McAfee\MCLOGS(64)\mcsmttsk\McUpdate\McUpdate000.log
c:\programdata\McAfee\MCLOGS(64)\McSvcHost\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\McSync\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(64)\McUICnt\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS(64)\mfehidin.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcagent\mcagent001.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcagent\mcagent002.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcappcfg\mcappcfg000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcinsspt\mcinsspt000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(64)\MISP\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcsvrcnt\mcsvrcnt000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcsync\mcsync000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcuihost\mcuihost000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcupdate\mcupdate000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(64)\MISP\mcupdmgr\mcupdmgr001.log
c:\programdata\McAfee\MCLOGS(64)\MISP\OOBESVC\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\MPF\Install\Install000.log
c:\programdata\McAfee\MCLOGS(64)\MPF\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(64)\MPF\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\MPF\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(64)\MPF\McSvHost\McSvHost002.log
c:\programdata\McAfee\MCLOGS(64)\MPF\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS(64)\MPF\mpfalert\mpfalert000.log
c:\programdata\McAfee\MCLOGS(64)\MQS\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\Pearl\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\mcagent\mcagent000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\mchost\mchost000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\mcinst\mcinst000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\McInsUpd\McInsUpd000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\mcods\mcods000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\McSvHost\McSvHost000.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\McSvHost\McSvHost001.log
c:\programdata\McAfee\MCLOGS(64)\VirusScan\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS\Anti-Spam\MskSrver\MskSrver000.log
c:\programdata\McAfee\MCLOGS\Common\Install\log.ini
c:\programdata\McAfee\MCLOGS\Common\McUICnt\log.ini
c:\programdata\McAfee\MCLOGS\McInfo\McInfo000.log
c:\programdata\McAfee\MCLOGS\McInst\sa_main.inf000.log
c:\programdata\McAfee\MCLOGS\mcoemmgr\mcoemmgr\log.ini
c:\programdata\McAfee\MCLOGS\mcsmttsk\McUpdate\log.ini
c:\programdata\McAfee\MCLOGS\mcsmttsk\McUpdate\McUpdate002.log
c:\programdata\McAfee\MCLOGS\MISP\mcagent\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcagent\mcagent001.log
c:\programdata\McAfee\MCLOGS\MISP\mcmscsvc\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcmscsvc\mcmscsvc000.log
c:\programdata\McAfee\MCLOGS\MISP\mcmscsvc\mcmscsvc002.log
c:\programdata\McAfee\MCLOGS\MISP\mcnasvc\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcnasvc\mcnasvc000.log
c:\programdata\McAfee\MCLOGS\MISP\mcnasvc\mcnasvc001.log
c:\programdata\McAfee\MCLOGS\MISP\mcnasvc\mcnasvc002.log
c:\programdata\McAfee\MCLOGS\MISP\McSmtFwk\log.ini
c:\programdata\McAfee\MCLOGS\MISP\McSmtFwk\McSmtFwk001.log
c:\programdata\McAfee\MCLOGS\MISP\mcsvrcnt\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcsvrcnt\mcsvrcnt000.log
c:\programdata\McAfee\MCLOGS\MISP\mcsync\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcsync\McSync002.log
c:\programdata\McAfee\MCLOGS\MISP\mcupdate\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcupdate\McUpdate002.log
c:\programdata\McAfee\MCLOGS\MISP\mcupdmgr\log.ini
c:\programdata\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr001.log
c:\programdata\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr002.log
c:\programdata\McAfee\MCLOGS\MISP\MPFSrv\MPFSrv000.log
c:\programdata\McAfee\MCLOGS\MPF\MPFSrv\MPFSrv000.log
c:\programdata\McAfee\MCLOGS\MPFMISP\mcmscsvc\log.ini
c:\programdata\McAfee\MCLOGS\MPFMISP\mcmscsvc\mcmscsvc001.log
c:\programdata\McAfee\MCLOGS\MPFMISP\mcupdmgr\mcupdmgr000.log
c:\programdata\McAfee\MCLOGS\Mps\mcproxy\mcproxy000.log
c:\programdata\McAfee\MCLOGS\MpsConfig\McInfo\McInfo000.log
c:\programdata\McAfee\MCLOGS\MpsConfig\mcmscsvc\log.ini
c:\programdata\McAfee\MCLOGS\MpsConfig\mcmscsvc\mcmscsvc000.log
c:\programdata\McAfee\MCLOGS\MpsConfig\mcmscsvc\mcmscsvc001.log
c:\programdata\McAfee\MCLOGS\MpsConfig\mcmscsvc\mcmscsvc002.log
c:\programdata\McAfee\MCLOGS\MpsConfig\mcproxy\mcproxy000.log
c:\programdata\McAfee\MCLOGS\MpsConfig\McSmtFwk\log.ini
c:\programdata\McAfee\MCLOGS\MpsConfig\McSmtFwk\McSmtFwk000.log
c:\programdata\McAfee\MCLOGS\MpsConfig\McSmtFwk\McSmtFwk001.log
c:\programdata\McAfee\MCLOGS\MpsConfig\McSmtFwk\McSmtFwk002.log
c:\programdata\McAfee\MCLOGS\MpsPC\mcmscsvc\mcmscsvc000.log
c:\programdata\McAfee\MCLOGS\MpsPC\McSmtFwk\McSmtFwk000.log
c:\programdata\McAfee\MCLOGS\MpsPII\mcmscsvc\mcmscsvc000.log
c:\programdata\McAfee\MCLOGS\MpsPII\McSmtFwk\McSmtFwk000.log
c:\programdata\McAfee\MCLOGS\MpsPV\mcmscsvc\mcmscsvc000.log
c:\programdata\McAfee\MNA\NAData
c:\programdata\McAfee\MNM\NDData
c:\programdata\McAfee\MPF(134)\mpf.dat
c:\programdata\McAfee\MPF(6)\data\log.edb
c:\programdata\McAfee\MPF(6)\mpf.dat
c:\programdata\McAfee\MPF(65)\data\log.edb
c:\programdata\McAfee\MPF(65)\mpf.dat
c:\programdata\McAfee\MPF\data\History.dat
c:\programdata\McAfee\MPF\data\log.edb
c:\programdata\McAfee\MPF\data\sports\default.ini
c:\programdata\McAfee\MPF\data\sports\DirServ.usr
c:\programdata\McAfee\MPF\data\sports\FTPServ.usr
c:\programdata\McAfee\MPF\data\sports\IMAPServ.usr
c:\programdata\McAfee\MPF\data\sports\NetBIOS.usr
c:\programdata\McAfee\MPF\data\sports\NTP.usr
c:\programdata\McAfee\MPF\data\sports\OS.usr
c:\programdata\McAfee\MPF\data\sports\Pop3Serv.usr
c:\programdata\McAfee\MPF\data\sports\RemAsst.usr
c:\programdata\McAfee\MPF\data\sports\RPCServ.usr
c:\programdata\McAfee\MPF\data\sports\SecWeb.usr
c:\programdata\McAfee\MPF\data\sports\SMTPServ.usr
c:\programdata\McAfee\MPF\data\sports\SQLServ.usr
c:\programdata\McAfee\MPF\data\sports\UPNP.usr
c:\programdata\McAfee\MPF\data\sports\WebServ.usr
c:\programdata\McAfee\MPS\searchengines.ini
c:\programdata\McAfee\MSC\Cache\McSubDB.Bak
c:\programdata\McAfee\MSC\Logs\{1E1FEB0E-ABA0-4074-B363-BE2ADC6D4CE8}.log
c:\programdata\McAfee\MSC\Logs\{34144B7A-8AD8-4DF3-A766-A1D15615E4A9}.log
c:\programdata\McAfee\MSC\Logs\{96111A4D-9614-478E-AC99-079CCB2872C8}.log
c:\programdata\McAfee\MSC\Logs\{9B49996C-6291-4616-B5B4-03791ACB464C}.log
c:\programdata\McAfee\MSC\Logs\{B94E1AF4-CD9E-4C3C-9524-0270A17EFBEF}.log
c:\programdata\McAfee\MSC\Logs\{D7FB805D-8827-4A38-8241-340B5D18D9F7}.log
c:\programdata\McAfee\MSC\Logs\Events.dat
c:\programdata\McAfee\MSC\Logs\settings.dat
c:\programdata\McAfee\MSC\McConfig.dat
c:\programdata\McAfee\MSC\mcifolog.log
c:\programdata\McAfee\MSC\mcini.ini
c:\programdata\McAfee\MSC\McSetng.ini
c:\programdata\McAfee\MSC\McSubDB.Dat
c:\programdata\McAfee\MSC\McUsers.dat
c:\programdata\McAfee\MSC\Updates\Downloads\vso_dat\Index.cab
c:\programdata\McAfee\MSC\Updates\Downloads\vso_dat\index.xml
c:\programdata\McAfee\MSK\MSKWMDB.dat
c:\programdata\McAfee\MSK\SettingsDB.dat
c:\programdata\McAfee\SiteAdvisor\SA.dat
c:\programdata\McAfee\SiteAdvisor\SACore\sacore.db
c:\programdata\McAfee\SiteAdvisor\SACore\sacore_cache.db
c:\programdata\McAfee\SiteAdvisor\SACore\sacore_priv.db
c:\programdata\McAfee\SiteAdvisor\sasshmod.dll\log.txt
c:\programdata\McAfee\VirusScan(136)\Logs\computer_ODS.Log
c:\programdata\McAfee\VirusScan(136)\Logs\OAS.Log
c:\programdata\McAfee\VirusScan(67)\Data\VMapLogs.log
c:\programdata\McAfee\VirusScan(67)\Logs\computer_ODS.Log
c:\programdata\McAfee\VirusScan(67)\Logs\OAS.Log
c:\programdata\McAfee\VirusScan(67)\Logs\SYSTEM_ODS.Log
c:\programdata\McAfee\VirusScan\Data\mcvsrpt.dat
c:\programdata\McAfee\VirusScan\Logs\computer_ODS.Log
c:\programdata\McAfee\VirusScan\Logs\OAS.Log
c:\programdata\McAfee\WinCore\persist.mtk

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_McAfee SiteAdvisor Service
-------\Service_MSK80Service
-------\Service_McAfee SiteAdvisor Service
-------\Service_MSK80Service


((((((((((((((((((((((((( Files Created from 2010-05-01 to 2010-06-01 )))))))))))))))))))))))))))))))
.

2010-06-01 00:03 . 2010-06-01 00:03 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-01 00:03 . 2010-06-01 00:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-31 21:57 . 2010-05-31 21:57 -------- d-----w- c:\users\computer\AppData\Local\Adobe
2010-05-27 07:35 . 2010-04-13 00:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-27 01:26 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-25 17:18 . 2010-05-25 17:18 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-05-24 20:32 . 2008-01-31 01:36 90112 ----a-w- c:\windows\unvise32.exe
2010-05-21 08:37 . 2010-05-22 05:17 -------- d-----w- c:\users\computer\AppData\Roaming\Auslogics
2010-05-21 08:37 . 2010-05-21 08:40 -------- d-----w- c:\program files\Auslogics
2010-05-19 10:01 . 2010-05-19 10:01 -------- d-----w- c:\windows\CheckSur
2010-05-18 10:21 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-18 10:20 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-18 10:01 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-18 10:00 . 2010-05-12 18:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 08:22 . 2010-05-18 08:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\users\computer\AppData\Roaming\Malwarebytes
2010-05-18 07:58 . 2010-05-18 07:58 -------- d-----w- c:\programdata\Malwarebytes
2010-05-18 07:58 . 2010-05-18 10:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-09 13:14 . 2010-05-29 05:36 -------- d-----w- C:\PERRLA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 07:35 . 2008-04-09 04:45 -------- d-----w- c:\program files\Java
2010-05-27 07:34 . 2009-09-12 10:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-05-27 00:44 . 2009-09-16 08:03 -------- d-----w- c:\programdata\Yahoo! Companion
2010-05-27 00:30 . 2009-09-11 11:51 1356 ----a-w- c:\users\computer\AppData\Local\d3d9caps.dat
2010-05-23 23:57 . 2009-09-20 06:43 -------- d-----w- c:\programdata\Soulseek
2010-05-23 06:30 . 2009-09-11 06:53 -------- d-----w- c:\program files\Common Files\AOL
2010-05-21 18:55 . 2009-09-11 06:41 77928 ----a-w- c:\users\computer\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-21 09:13 . 2006-11-02 06:37 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-05-21 09:13 . 2010-01-19 07:58 819200 ----a-w- c:\windows\system32\xvidcore.dll
2010-05-21 09:13 . 2010-01-19 07:58 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-05-21 09:13 . 2008-04-29 12:49 237568 ----a-w- c:\windows\system32\UCI32M29.dll
2010-05-21 09:13 . 2008-04-09 05:22 221184 ----a-w- c:\windows\system32\UCI32M22.dll
2010-05-21 09:09 . 2009-11-15 05:06 1196032 ----a-w- c:\windows\RtlUpd.exe
2010-05-21 09:09 . 2009-11-15 05:06 520192 ----a-w- c:\windows\RtlExUpd.dll
2010-05-21 09:08 . 2009-11-15 05:06 315392 ----a-w- c:\windows\HideWin.exe
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\taskMgrPrefs.exe
2010-05-21 09:08 . 2008-04-09 04:47 81920 ----a-w- c:\windows\Help\OEM\scripts\HPPhoneNumbers.exe
2010-05-21 09:08 . 2008-04-09 04:47 53248 ----a-w- c:\windows\Help\OEM\scripts\HPASL.exe
2010-05-21 09:08 . 2008-04-09 04:47 4096 ----a-w- c:\windows\Help\OEM\scripts\Interop.HelpPane.dll
2010-05-21 09:08 . 2008-04-09 04:47 24576 ----a-w- c:\windows\Help\OEM\scripts\launchAP.exe
2010-05-21 09:04 . 2009-10-25 22:30 81920 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 413696 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0419\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 401408 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041D\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 147456 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\041E\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 397312 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0414\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 282624 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0411\CNMur9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 196608 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0410\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 176128 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040e\CNMlr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 73728 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\040b\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 94208 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0408\CNMsr9I.dll
2010-05-21 09:04 . 2009-10-25 22:30 253952 ----a-w- c:\programdata\CanonBJ\IJPrinter\CNMWindows\Canon MP190 series Printer\LanguageModules\0404\CNMur9I.dll
2010-05-19 18:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-18 09:46 . 2009-09-16 01:55 -------- d-----w- c:\programdata\Microsoft Help
2010-05-18 09:38 . 2009-09-12 10:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-18 09:38 . 2009-11-11 03:34 -------- d-----w- c:\program files\iTunes
2010-04-24 05:30 . 2010-04-24 05:30 -------- d-----w- c:\users\computer\AppData\Roaming\muvee Technologies
2010-04-23 17:32 . 2010-04-23 17:32 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-28 23:48 . 2010-03-28 23:48 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-03-28 23:47 . 2010-03-28 23:47 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2010-03-09 16:28 . 2010-03-31 17:32 833024 ----a-w- c:\windows\system32\wininet.dll
2010-03-09 16:25 . 2010-03-31 17:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 14:01 . 2010-03-31 17:32 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-03-04 18:54 . 2010-04-14 17:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2009-10-24 19:00 . 2009-10-24 19:00 22 --sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2010-05-21 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-05-21 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-03 178712]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]

c:\users\computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-19 1314704]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

.
Contents of the 'Scheduled Tasks' folder

2010-06-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 01:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\computer\AppData\Roaming\Mozilla\Firefox\Profiles\ttggtg9q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\users\computer\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-MSC - c:\program files\McAfee\MSC\mcuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-31 17:05
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-05-31 17:09:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-01 00:09
ComboFix2.txt 2010-05-31 23:38
ComboFix3.txt 2010-05-27 22:23

Pre-Run: 496,506,163,200 bytes free
Post-Run: 496,192,573,440 bytes free

- - End Of File - - A0F03B9C5C3BC6EEB3098704E8ABDC31
  • 0

#19
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
We're not finished yet.


  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.


If you used DeFogger
You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.

  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.


Here's my usual all clean post


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:[list=1]
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

After the above:

Now we need a free anti-virus program

Microsoft Security Essentials

Run a full scan and let us know what it finds.

Edited by ldtate, 31 May 2010 - 06:18 PM.

  • 0

#20
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured