c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a585\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwattrs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwfiles.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwfindx.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\desktop.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\main.wkg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bw_info.tmp
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwattrs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfiles.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfiles.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfindx.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwipak.bwz
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwncdesc.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\avp.vnd
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\BW_datapak.bif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\BW_datapak.bis
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\fssign2.def
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\gen001.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\krndos.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\krnjava.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\ocr.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\orioneng.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\orionfin.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\sign.def
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj011.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj012.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj017.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj021.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp008.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp011.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp017.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp020.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus002.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus004.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus005.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus006.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus007.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus009.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus013.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus015.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus018.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus019.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm002.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm004.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm999.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\BWEvents.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\chninfo.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\ChnReg.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\cluster.cfg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\segrules.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\Stats.tmp
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\UserProf.bak
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\UserProf.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\background.gif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\browser.htm
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\cache.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\desktop-4476822.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\desktop.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbwce.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbweng.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbwupst.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\gen.bif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\gen.bis
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\HostCache.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\InfoCenter.GIF
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\InfoCenter.htm
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\inuse.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\L0000001.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\main.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\S0000000.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\S0000001.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\shopping.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\test.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\UpgradePubKey.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\UsrPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\wg1.wkg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Misc\Backup\chandir.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Misc\Backup\chandir.idx
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\banner_setup_370x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\banner_setup_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\fsbwres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\ico_uninstall.ico
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\gui\gres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\banner.gif
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\helpinst.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\splash.jpg
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\common\banner_vs_common_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\banner_advanced_591x59.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\banner_advanced_788x72.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\fsavauires.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\e-mail\banner_email_scan_rprt_582x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\e-mail\fsesres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\scan_clean\background.bmp_380x392.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\scan_clean\fsavures.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\securitynews\banner_virus_news_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\securitynews\fsavvnres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\flyer\flyer.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_level_369x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_level_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_main_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_main_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\plugins\virusspy\ieshield.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\avabtres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\bmp_about_406x259.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\bmp_splash_208x320.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\banner_start-up_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\banner_start-up_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\bmp_background_353x340.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\fsswgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\banner_tnb_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\banner_tnb_610x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\tnbutil.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\common\banner_vs_common_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\banner_advanced_591x59.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\banner_advanced_788x72.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\fsavauires.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\banner_alert_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\banner_app_cont_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\fsdfwpi2.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\e-mail\banner_email_scan_rprt_582x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\e-mail\fsesres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\scan_clean\background.bmp_380x392.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\scan_clean\fsavures.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\securitynews\banner_virus_news_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\securitynews\fsavvnres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\flyer\flyer.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_level_369x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_level_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_main_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_main_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fshttps.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fspcinst.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fspcmsie.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\spam\fsscmso.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\virusspy\ieshield.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\avabtres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\bmp_about_406x259.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\bmp_splash_208x320.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\banner_start-up_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\banner_start-up_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\bmp_background_353x340.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\fsswgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\banner_tnb_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\banner_tnb_610x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\tnbutil.custom
c:\program files\F-Secure Internet Security\Common\custom\uninst.log
c:\program files\F-Secure Internet Security\Common\fsbw.cr
c:\program files\F-Secure Internet Security\Common\fsbw.dpf
c:\program files\F-Secure Internet Security\Common\fsbwares.csy
c:\program files\F-Secure Internet Security\Common\fsbwares.dan
c:\program files\F-Secure Internet Security\Common\fsbwares.deu
c:\program files\F-Secure Internet Security\Common\fsbwares.ell
c:\program files\F-Secure Internet Security\Common\fsbwares.eng
c:\program files\F-Secure Internet Security\Common\fsbwares.esn
c:\program files\F-Secure Internet Security\Common\fsbwares.fin
c:\program files\F-Secure Internet Security\Common\fsbwares.fra
c:\program files\F-Secure Internet Security\Common\fsbwares.hun
c:\program files\F-Secure Internet Security\Common\fsbwares.ita
c:\program files\F-Secure Internet Security\Common\fsbwares.nld
c:\program files\F-Secure Internet Security\Common\fsbwares.nor
c:\program files\F-Secure Internet Security\Common\fsbwares.plk
c:\program files\F-Secure Internet Security\Common\fsbwares.ptb
c:\program files\F-Secure Internet Security\Common\fsbwares.ptg
c:\program files\F-Secure Internet Security\Common\fsbwares.slv
c:\program files\F-Secure Internet Security\Common\fsbwares.sve
c:\program files\F-Secure Internet Security\Common\fsbwares.trk
c:\program files\F-Secure Internet Security\Common\fsbwih.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BACKWEB_PLUG-IN_-_4476822
-------\Legacy_FSBWSYS
-------\Service_BackWeb Plug-in - 4476822
-------\Service_fsbwsys
((((((((((((((((((((((((( Files Created from 2009-06-21 to 2009-07-21 )))))))))))))))))))))))))))))))
.
2009-07-19 11:01 . 2009-07-02 07:59 353048 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-07-19 11:01 . 2009-07-02 08:00 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-07-18 13:47 . 2009-07-18 13:47 -------- d-----w- c:\program files\Trend Micro
2009-07-18 06:40 . 2009-07-18 06:40 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-07-18 06:40 . 2009-07-19 05:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-18 06:40 . 2009-07-19 05:49 -------- d-----w- c:\program files\NOS
2009-07-14 20:41 . 2009-07-14 20:41 -------- d-----w- c:\program files\ERUNT
2009-07-14 15:56 . 2009-07-14 15:56 -------- d-----w- C:\Rooter$
2009-07-11 19:32 . 2009-07-02 08:00 327688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-11 19:32 . 2009-07-02 08:00 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-11 19:32 . 2009-07-02 08:00 906520 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgemc.exe
2009-07-11 19:32 . 2009-07-11 19:31 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-11 19:32 . 2009-07-02 08:00 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-11 19:32 . 2009-07-02 07:59 1204504 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-11 19:32 . 2009-07-02 07:59 337176 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-11 19:32 . 2009-07-02 07:59 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-11 19:32 . 2009-07-02 07:59 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-11 19:30 . 2009-07-02 07:59 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-11 19:30 . 2009-07-02 07:59 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-07 14:16 . 2009-07-13 12:19 -------- d-----w- c:\documents and settings\All Users\Application Data\14334684
2009-07-07 14:15 . 2009-07-07 14:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\documents and settings\user\Application Data\Virgin Broadband
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\program files\Virgin Broadband
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Virgin Broadband
2009-06-27 15:47 . 2009-06-27 15:47 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 14:13 . 2006-04-09 19:03 -------- d-----w- c:\program files\Electronic Arts
2009-07-18 14:10 . 2007-09-15 15:04 -------- d-----w- c:\documents and settings\user\Application Data\Teleca
2009-07-18 14:10 . 2006-06-28 16:18 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-07-18 14:03 . 2007-12-27 09:05 -------- d-----w- c:\documents and settings\user\Application Data\Samsung
2009-07-18 07:19 . 2009-03-06 20:41 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 07:19 . 2005-07-02 11:54 -------- d-----w- c:\program files\Java
2009-07-18 06:52 . 2002-08-23 01:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-18 06:29 . 2002-08-23 00:46 -------- d-----w- c:\program files\Common Files\Real
2009-07-16 16:34 . 2009-02-27 08:44 -------- d-----w- c:\documents and settings\user\Application Data\Spotify
2009-07-14 20:27 . 2007-07-26 00:13 -------- d-----w- c:\program files\DivX
2009-07-14 16:29 . 2005-07-01 21:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 16:29 . 2005-07-01 21:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-11 19:31 . 2008-12-08 09:41 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 14:38 . 2008-12-08 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-02 08:00 . 2008-12-08 09:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-02 08:00 . 2006-12-05 17:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:55 . 2002-08-23 10:25 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2002-08-23 10:24 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 07:12 . 2005-07-11 18:11 -------- d-----w- c:\program files\Google
2009-06-07 13:53 . 2005-11-22 16:43 -------- d-----w- c:\documents and settings\user\Application Data\PC Suite
2009-06-03 19:27 . 2002-08-23 10:25 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2002-08-29 06:14 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 08:57 . 2008-12-08 09:41 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:44 . 2002-08-23 10:24 344064 ----a-w- c:\windows\system32\localspl.dll
2005-05-11 18:39 . 2005-07-01 11:23 41578 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2005-05-11 18:40 . 2005-07-01 11:23 48228 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2005-05-11 18:39 . 2005-07-01 11:23 159340 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-17_12.08.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-21 07:36 . 2009-07-21 07:36 40960 c:\windows\temp\rtdrvmon.exe
+ 2009-07-21 07:36 . 2009-07-21 07:36 16384 c:\windows\temp\Perflib_Perfdata_508.dat
+ 2009-07-18 15:42 . 2009-07-18 15:42 88590 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 148888 c:\windows\system32\javaws.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 148888 c:\windows\system32\javaws.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 144792 c:\windows\system32\javaw.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 144792 c:\windows\system32\javaw.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 144792 c:\windows\system32\java.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 144792 c:\windows\system32\java.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 1563648 c:\windows\Installer\9fa55.msi
+ 2009-07-18 06:53 . 2009-07-18 06:53 3938816 c:\windows\Installer\1e472.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-02 1948440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-18 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2006-5-17 2297856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-02 08:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorrectConnect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CorrectConnect.lnk
backup=c:\windows\pss\CorrectConnect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ashden^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\Ashden\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\NETGEAR\\WG111v2\\WG111v2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/12/2008 10:41 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/12/2008 10:41 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [08/12/2008 10:41 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/12/2008 10:41 298776]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [27/03/2006 17:53 167808]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [06/10/2007 09:05 729416]
S3 sea3bus;Sony Ericsson Device 0A3 driver (WDM);c:\windows\system32\drivers\sea3bus.sys [11/10/2007 21:46 61600]
S3 sea3mdfl;Sony Ericsson Device 0A3 USB WMC Modem Filter;c:\windows\system32\drivers\sea3mdfl.sys [12/10/2007 17:58 9392]
S3 sea3mdm;Sony Ericsson Device 0A3 USB WMC Modem Driver;c:\windows\system32\drivers\sea3mdm.sys [12/10/2007 17:58 97152]
S3 sea3mgmt;Sony Ericsson Device 0A3 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea3mgmt.sys [29/10/2007 17:32 88656]
S3 sea3obex;Sony Ericsson Device 0A3 USB WMC OBEX Interface;c:\windows\system32\drivers\sea3obex.sys [28/10/2007 00:08 86464]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-07-21 c:\windows\Tasks\User_Feed_Synchronization-{714F03FE-5240-49DC-A08A-034F406D58A1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.virginmedia.com/
IE: &Search - ?p=ZUman000
Trusted Zone: bet365.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {360E40AA-EE8B-4101-BA67-0CAD3F7A48DD} - hxxp://www.riverbelle.co.uk/download_helper/Nyoko.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\yeh0ch5l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-GB
fficial
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-21 08:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(492)
c:\windows\system32\RtlGina2.dll
c:\windows\system32\WlNotify.dll
- - - - - - - > 'explorer.exe'(832)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-21 8:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-21 07:46
ComboFix2.txt 2009-07-21 06:30
ComboFix3.txt 2009-07-19 15:25
ComboFix4.txt 2009-07-18 07:41
ComboFix5.txt 2009-07-21 07:20
Pre-Run: 35,152,883,712 bytes free
Post-Run: 35,047,350,272 bytes free
1057 --- E O F --- 2009-07-15 06:32
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwattrs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwfiles.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\_bwfindx.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2005\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\2006\desktop.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiav\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\fiis\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\main.wkg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\MS CD\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 470\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\PEX 471\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\Solarsoft\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveav\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\sveis\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a5e3\telmex_av\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bw_info.tmp
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwattrs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfiles.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfiles.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwfindx.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwipak.bwz
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\_bwncdesc.zip
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\avp.vnd
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\BW_datapak.bif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\BW_datapak.bis
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\fssign2.def
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\gen001.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\krndos.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\krnjava.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\ocr.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\orioneng.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\orionfin.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\sign.def
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj011.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj012.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj017.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\troj021.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp008.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp011.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp017.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\unp020.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus002.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus004.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus005.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus006.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus007.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus009.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus013.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus015.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus018.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\virus019.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm002.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm004.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\1060a6ae\worm999.avc
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\BWEvents.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\chninfo.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\ChnReg.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\cluster.cfg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\segrules.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\Stats.tmp
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\UserProf.bak
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\6278\UserProf.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\background.gif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\browser.htm
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\bwsetup.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\cache.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\cert.db
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\DefPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\desktop-4476822.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\desktop.ico
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbwce.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbweng.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbwupst.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\gen.bif
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\gen.bis
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\GenFlash\1\info.iad
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\HostCache.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\InfoCenter.GIF
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\InfoCenter.htm
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\inuse.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\L0000001.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\main.log
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\S0000000.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\S0000001.FCS
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\shopping.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.idx
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\test.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\UpgradePubKey.txt
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\UsrPrefs.ini
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\wg1.wkg
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Misc\Backup\chandir.dat
c:\program files\F-Secure Internet Security\backweb\4476822\Users\Default\Misc\Backup\chandir.idx
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\banner_setup_370x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\banner_setup_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\fsbwres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsbw\ico_uninstall.ico
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\fsma\fsmres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\gui\gres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\banner.gif
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\helpinst.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\Common\help\splash.jpg
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\common\banner_vs_common_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\banner_advanced_591x59.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\banner_advanced_788x72.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\advanced\fsavauires.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\e-mail\banner_email_scan_rprt_582x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\e-mail\fsesres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\scan_clean\background.bmp_380x392.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\scan_clean\fsavures.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\securitynews\banner_virus_news_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\dialogs\securitynews\fsavvnres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\flyer\flyer.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_level_369x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_level_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_main_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\banner_main_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\main\fsavgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\fsgui\plugins\virusspy\ieshield.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\avabtres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\bmp_about_406x259.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\splash\bmp_splash_208x320.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\banner_start-up_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\banner_start-up_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\bmp_background_353x340.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\start-up wizard\fsswgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\banner_tnb_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\banner_tnb_610x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FAV\tnb\tnbutil.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\common\banner_vs_common_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\banner_advanced_591x59.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\banner_advanced_788x72.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\advanced\fsavauires.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\banner_alert_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\banner_app_cont_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\alert_application\fsdfwpi2.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\e-mail\banner_email_scan_rprt_582x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\e-mail\fsesres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\scan_clean\background.bmp_380x392.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\scan_clean\fsavures.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\securitynews\banner_virus_news_422x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\dialogs\securitynews\fsavvnres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\flyer\flyer.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_level_369x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_level_492x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_main_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\banner_main_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-csy.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-dan.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-deu.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ell.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-eng.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-esn.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-fin.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-fra.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-hun.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ita.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-nld.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-nor.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-plk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ptb.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-ptg.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-slv.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-sve.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres-trk.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\main\fsavgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fshttps.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fspcinst.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\parental\fspcmsie.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\spam\fsscmso.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\fsgui\plugins\virusspy\ieshield.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\avabtres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\bmp_about_406x259.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\splash\bmp_splash_208x320.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\banner_start-up_563x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\banner_start-up_750x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\bmp_background_353x340.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\start-up wizard\fsswgres.custom
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\banner_tnb_458x60.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\banner_tnb_610x74.bmp
c:\program files\F-Secure Internet Security\Common\custom\custom1\FIS\tnb\tnbutil.custom
c:\program files\F-Secure Internet Security\Common\custom\uninst.log
c:\program files\F-Secure Internet Security\Common\fsbw.cr
c:\program files\F-Secure Internet Security\Common\fsbw.dpf
c:\program files\F-Secure Internet Security\Common\fsbwares.csy
c:\program files\F-Secure Internet Security\Common\fsbwares.dan
c:\program files\F-Secure Internet Security\Common\fsbwares.deu
c:\program files\F-Secure Internet Security\Common\fsbwares.ell
c:\program files\F-Secure Internet Security\Common\fsbwares.eng
c:\program files\F-Secure Internet Security\Common\fsbwares.esn
c:\program files\F-Secure Internet Security\Common\fsbwares.fin
c:\program files\F-Secure Internet Security\Common\fsbwares.fra
c:\program files\F-Secure Internet Security\Common\fsbwares.hun
c:\program files\F-Secure Internet Security\Common\fsbwares.ita
c:\program files\F-Secure Internet Security\Common\fsbwares.nld
c:\program files\F-Secure Internet Security\Common\fsbwares.nor
c:\program files\F-Secure Internet Security\Common\fsbwares.plk
c:\program files\F-Secure Internet Security\Common\fsbwares.ptb
c:\program files\F-Secure Internet Security\Common\fsbwares.ptg
c:\program files\F-Secure Internet Security\Common\fsbwares.slv
c:\program files\F-Secure Internet Security\Common\fsbwares.sve
c:\program files\F-Secure Internet Security\Common\fsbwares.trk
c:\program files\F-Secure Internet Security\Common\fsbwih.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BACKWEB_PLUG-IN_-_4476822
-------\Legacy_FSBWSYS
-------\Service_BackWeb Plug-in - 4476822
-------\Service_fsbwsys
((((((((((((((((((((((((( Files Created from 2009-06-21 to 2009-07-21 )))))))))))))))))))))))))))))))
.
2009-07-19 11:01 . 2009-07-02 07:59 353048 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-07-19 11:01 . 2009-07-02 08:00 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-07-18 13:47 . 2009-07-18 13:47 -------- d-----w- c:\program files\Trend Micro
2009-07-18 06:40 . 2009-07-18 06:40 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-07-18 06:40 . 2009-07-19 05:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-18 06:40 . 2009-07-19 05:49 -------- d-----w- c:\program files\NOS
2009-07-14 20:41 . 2009-07-14 20:41 -------- d-----w- c:\program files\ERUNT
2009-07-14 15:56 . 2009-07-14 15:56 -------- d-----w- C:\Rooter$
2009-07-11 19:32 . 2009-07-02 08:00 327688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-11 19:32 . 2009-07-02 08:00 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-11 19:32 . 2009-07-02 08:00 906520 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgemc.exe
2009-07-11 19:32 . 2009-07-11 19:31 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-11 19:32 . 2009-07-02 08:00 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-11 19:32 . 2009-07-02 07:59 1204504 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-11 19:32 . 2009-07-02 07:59 337176 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-11 19:32 . 2009-07-02 07:59 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-11 19:32 . 2009-07-02 07:59 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-11 19:30 . 2009-07-02 07:59 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-11 19:30 . 2009-07-02 07:59 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-07 14:16 . 2009-07-13 12:19 -------- d-----w- c:\documents and settings\All Users\Application Data\14334684
2009-07-07 14:15 . 2009-07-07 14:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\documents and settings\user\Application Data\Virgin Broadband
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\program files\Virgin Broadband
2009-06-29 14:32 . 2009-06-29 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Virgin Broadband
2009-06-27 15:47 . 2009-06-27 15:47 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 14:13 . 2006-04-09 19:03 -------- d-----w- c:\program files\Electronic Arts
2009-07-18 14:10 . 2007-09-15 15:04 -------- d-----w- c:\documents and settings\user\Application Data\Teleca
2009-07-18 14:10 . 2006-06-28 16:18 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-07-18 14:03 . 2007-12-27 09:05 -------- d-----w- c:\documents and settings\user\Application Data\Samsung
2009-07-18 07:19 . 2009-03-06 20:41 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 07:19 . 2005-07-02 11:54 -------- d-----w- c:\program files\Java
2009-07-18 06:52 . 2002-08-23 01:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-18 06:29 . 2002-08-23 00:46 -------- d-----w- c:\program files\Common Files\Real
2009-07-16 16:34 . 2009-02-27 08:44 -------- d-----w- c:\documents and settings\user\Application Data\Spotify
2009-07-14 20:27 . 2007-07-26 00:13 -------- d-----w- c:\program files\DivX
2009-07-14 16:29 . 2005-07-01 21:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 16:29 . 2005-07-01 21:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-11 19:31 . 2008-12-08 09:41 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 14:38 . 2008-12-08 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-02 08:00 . 2008-12-08 09:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-02 08:00 . 2006-12-05 17:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:55 . 2002-08-23 10:25 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2002-08-23 10:24 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 07:12 . 2005-07-11 18:11 -------- d-----w- c:\program files\Google
2009-06-07 13:53 . 2005-11-22 16:43 -------- d-----w- c:\documents and settings\user\Application Data\PC Suite
2009-06-03 19:27 . 2002-08-23 10:25 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2002-08-29 06:14 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 08:57 . 2008-12-08 09:41 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:44 . 2002-08-23 10:24 344064 ----a-w- c:\windows\system32\localspl.dll
2005-05-11 18:39 . 2005-07-01 11:23 41578 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2005-05-11 18:40 . 2005-07-01 11:23 48228 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2005-05-11 18:39 . 2005-07-01 11:23 159340 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-17_12.08.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-21 07:36 . 2009-07-21 07:36 40960 c:\windows\temp\rtdrvmon.exe
+ 2009-07-21 07:36 . 2009-07-21 07:36 16384 c:\windows\temp\Perflib_Perfdata_508.dat
+ 2009-07-18 15:42 . 2009-07-18 15:42 88590 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 148888 c:\windows\system32\javaws.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 148888 c:\windows\system32\javaws.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 144792 c:\windows\system32\javaw.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 144792 c:\windows\system32\javaw.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 144792 c:\windows\system32\java.exe
- 2009-03-06 20:41 . 2009-03-06 20:41 144792 c:\windows\system32\java.exe
+ 2009-07-18 07:19 . 2009-07-18 07:19 1563648 c:\windows\Installer\9fa55.msi
+ 2009-07-18 06:53 . 2009-07-18 06:53 3938816 c:\windows\Installer\1e472.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-02 1948440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-18 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2006-5-17 2297856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-02 08:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorrectConnect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CorrectConnect.lnk
backup=c:\windows\pss\CorrectConnect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ashden^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\Ashden\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\NETGEAR\\WG111v2\\WG111v2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/12/2008 10:41 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/12/2008 10:41 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [08/12/2008 10:41 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/12/2008 10:41 298776]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [27/03/2006 17:53 167808]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [06/10/2007 09:05 729416]
S3 sea3bus;Sony Ericsson Device 0A3 driver (WDM);c:\windows\system32\drivers\sea3bus.sys [11/10/2007 21:46 61600]
S3 sea3mdfl;Sony Ericsson Device 0A3 USB WMC Modem Filter;c:\windows\system32\drivers\sea3mdfl.sys [12/10/2007 17:58 9392]
S3 sea3mdm;Sony Ericsson Device 0A3 USB WMC Modem Driver;c:\windows\system32\drivers\sea3mdm.sys [12/10/2007 17:58 97152]
S3 sea3mgmt;Sony Ericsson Device 0A3 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea3mgmt.sys [29/10/2007 17:32 88656]
S3 sea3obex;Sony Ericsson Device 0A3 USB WMC OBEX Interface;c:\windows\system32\drivers\sea3obex.sys [28/10/2007 00:08 86464]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-07-21 c:\windows\Tasks\User_Feed_Synchronization-{714F03FE-5240-49DC-A08A-034F406D58A1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.virginmedia.com/
IE: &Search - ?p=ZUman000
Trusted Zone: bet365.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {360E40AA-EE8B-4101-BA67-0CAD3F7A48DD} - hxxp://www.riverbelle.co.uk/download_helper/Nyoko.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\yeh0ch5l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-GB

.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-21 08:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(492)
c:\windows\system32\RtlGina2.dll
c:\windows\system32\WlNotify.dll
- - - - - - - > 'explorer.exe'(832)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-21 8:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-21 07:46
ComboFix2.txt 2009-07-21 06:30
ComboFix3.txt 2009-07-19 15:25
ComboFix4.txt 2009-07-18 07:41
ComboFix5.txt 2009-07-21 07:20
Pre-Run: 35,152,883,712 bytes free
Post-Run: 35,047,350,272 bytes free
1057 --- E O F --- 2009-07-15 06:32