ComboFix 09-07-22.07 - Owner 07/23/2009 7:28.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.203 [GMT -8:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090722-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
FILE ::
"c:\documents and settings\Owner\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_all.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_dl.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_next.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_prev.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\WebUpdater.exe
c:\documents and settings\Owner\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk
.
--------------- FCopy ---------------
c:\winnt\ServicePackFiles\i386\grpconv.exe --> c:\winnt\system32\grpconv.exe
c:\winnt\ServicePackFiles\i386\grpconv.exe --> c:\winnt\system32\dllcache\grpconv.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.
2009-07-23 15:28 . 2008-04-14 00:12 39424 ----a-w- c:\winnt\system32\grpconv.exe
2009-07-23 15:28 . 2008-04-14 00:12 39424 ----a-w- c:\winnt\system32\dllcache\grpconv.exe
2009-07-17 03:10 . 2009-07-17 03:10 -------- d-----w- c:\program files\Safer Networking
2009-07-17 03:03 . 2009-07-17 03:03 -------- d-----w- c:\program files\Trend Micro
2009-07-16 19:07 . 2009-07-16 19:07 -------- d-sh--w- c:\winnt\system32\config\systemprofile\IETldCache
2009-07-14 23:29 . 2009-07-22 18:42 -------- d-----w- c:\program files\iWin Games
2009-07-09 03:00 . 2009-07-09 03:00 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2009-07-09 02:34 . 2009-07-09 02:34 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-07-09 02:25 . 2009-07-09 02:25 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-07-09 02:23 . 2009-07-09 02:23 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-07-09 02:20 . 2009-06-02 10:12 102912 ------w- c:\winnt\system32\dllcache\iecompat.dll
2009-07-09 02:19 . 2009-07-09 02:20 -------- d-----w- c:\winnt\ie8updates
2009-07-09 02:18 . 2009-04-30 21:22 12800 ------w- c:\winnt\system32\dllcache\xpshims.dll
2009-07-09 02:18 . 2009-04-30 21:22 246272 ------w- c:\winnt\system32\dllcache\ieproxy.dll
2009-07-09 02:15 . 2009-07-09 02:18 -------- dc-h--w- c:\winnt\ie8
2009-07-09 00:05 . 2009-07-09 00:05 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-06 02:30 . 2009-07-06 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Meridian93
2009-07-02 21:37 . 2009-07-02 21:37 -------- d-----w- c:\documents and settings\Owner\Application Data\Home Sweet Home Christmas
2009-06-29 23:11 . 2009-06-29 03:48 2653064 -c--a-w- c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}\DriverScanner_Setup.exe
2009-06-29 23:11 . 2009-06-29 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-06-29 23:11 . 2009-06-29 23:11 -------- d-----w- c:\documents and settings\Owner\Application Data\Uniblue
2009-06-29 23:11 . 2009-06-29 23:11 -------- d-----w- c:\program files\Uniblue
2009-06-29 23:09 . 2009-06-29 23:11 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-06-28 00:22 . 2009-03-03 18:51 98304 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-06-28 00:22 . 2004-12-20 20:17 147456 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2009-06-27 00:15 . 2009-06-27 00:15 -------- d-----w- c:\documents and settings\Owner\Freeze Tag - Dream Machine
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-23 15:41 . 2008-06-26 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\iWin Games
2009-07-22 19:21 . 2009-04-02 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-16 23:40 . 2009-07-16 23:41 2558464 ----a-w- c:\winnt\Internet Logs\xDB18.tmp
2009-07-16 22:30 . 2009-07-16 22:31 2557440 ----a-w- c:\winnt\Internet Logs\xDB17.tmp
2009-07-16 21:55 . 2009-07-16 21:56 2556928 ----a-w- c:\winnt\Internet Logs\xDB16.tmp
2009-07-16 19:35 . 2008-09-21 22:26 21621722 ----a-w- c:\winnt\Internet Logs\tvDebug.Zip
2009-07-16 19:33 . 2009-07-16 19:35 2586624 ----a-w- c:\winnt\Internet Logs\xDB15.tmp
2009-07-16 18:35 . 2009-07-16 18:35 1063647 ----a-w- c:\winnt\system32\rn.tmp
2009-07-16 07:33 . 2008-01-15 17:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-15 16:41 . 2008-08-23 18:07 -------- d-----w- c:\program files\Flock
2009-07-10 03:30 . 2008-12-03 07:05 -------- d-----w- c:\documents and settings\Owner\Application Data\EleFun Games
2009-07-10 03:28 . 2008-05-28 18:29 1278089 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\MostFun_HalloweenNight\IAF.dll
2009-07-10 03:28 . 2008-08-25 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2009-07-10 03:28 . 2008-01-13 07:14 -------- d-----w- c:\program files\MostFun
2009-07-10 02:27 . 2008-08-20 18:10 1278089 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\MostFun_BrickshooterEgypt\IAF.dll
2009-07-08 02:05 . 2008-07-01 16:29 -------- d-----w- c:\documents and settings\Owner\Application Data\Flood Light Games
2009-07-08 02:05 . 2008-07-01 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Flood Light Games
2009-07-08 01:50 . 2009-07-08 01:50 2557952 ----a-w- c:\winnt\Internet Logs\xDB14.tmp
2009-07-08 01:47 . 2008-06-26 06:41 -------- d-----w- c:\program files\iWin.com
2009-07-06 02:29 . 2008-07-27 17:05 -------- d-----w- c:\documents and settings\Owner\Application Data\Meridian93
2009-07-06 02:28 . 2008-09-18 01:18 1278089 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\MostFun_KeyWords\IAF.dll
2009-07-05 22:02 . 2006-05-07 17:29 -------- d-----w- c:\documents and settings\Owner\Application Data\PlayFirst
2009-07-05 22:02 . 2006-05-07 17:29 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-01 08:10 . 2009-07-01 08:11 2558976 ----a-w- c:\winnt\Internet Logs\xDB13.tmp
2009-06-28 00:22 . 2009-04-18 01:27 -------- d-----w- c:\program files\Zylom Games
2009-06-21 23:11 . 2009-06-21 23:12 2536960 ----a-w- c:\winnt\Internet Logs\xDB12.tmp
2009-06-21 00:48 . 2009-02-09 00:17 -------- d-----w- c:\documents and settings\Owner\Application Data\JewelMatch2
2009-06-17 04:20 . 2009-06-17 03:36 444952 ----a-w- c:\winnt\system32\wrap_oal.dll
2009-06-17 04:20 . 2009-06-17 03:36 109080 ----a-w- c:\winnt\system32\OpenAL32.dll
2009-06-17 03:41 . 2003-10-14 21:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-17 03:40 . 2009-06-17 03:40 -------- d-----w- c:\program files\OpenAL 1.1 SDK
2009-06-17 03:36 . 2009-06-17 03:36 -------- d-----w- c:\program files\OpenAL
2009-06-14 15:44 . 2009-06-14 15:45 2513920 ----a-w- c:\winnt\Internet Logs\xDB11.tmp
2009-06-12 02:20 . 2009-06-12 02:20 -------- d-----w- c:\documents and settings\Owner\Application Data\Cat's Eye Games
2009-06-03 22:00 . 2009-06-03 22:01 2475008 ----a-w- c:\winnt\Internet Logs\xDB10.tmp
2009-06-03 06:14 . 2009-06-03 06:19 2479616 ----a-w- c:\winnt\Internet Logs\xDBF.tmp
2009-06-03 00:51 . 2008-10-25 00:06 -------- d-----w- c:\documents and settings\Owner\Application Data\Gogii Games
2009-06-03 00:51 . 2008-10-25 00:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Gogii Games
2009-06-02 02:19 . 2006-06-19 05:40 -------- d-----w- c:\documents and settings\All Users\Application Data\MumboJumbo
2009-06-01 17:02 . 2009-06-01 17:02 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-01 17:02 . 2009-03-16 17:42 15688 ----a-w- c:\winnt\system32\lsdelete.exe
2009-05-28 00:24 . 2009-05-28 00:24 -------- d-----w- c:\documents and settings\Owner\Application Data\Boomzap
2009-05-22 05:24 . 2009-05-22 05:25 2457088 ----a-w- c:\winnt\Internet Logs\xDBE.tmp
2009-05-21 02:01 . 2009-05-21 02:15 2480640 ----a-w- c:\winnt\Internet Logs\xDB113.tmp
2009-05-14 17:14 . 2009-05-14 17:15 2463744 ----a-w- c:\winnt\Internet Logs\xDBD.tmp
2009-05-13 05:15 . 2005-06-18 06:49 915456 ----a-w- c:\winnt\system32\wininet.dll
2009-05-09 04:45 . 2009-05-09 05:00 2484736 ----a-w- c:\winnt\Internet Logs\xDB112.tmp
2009-05-08 01:23 . 2008-09-15 21:00 1278089 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\MostFun_SupermarketMania\IAF.dll
2009-05-07 15:32 . 1980-01-01 05:00 345600 ----a-w- c:\winnt\system32\localspl.dll
2009-04-29 02:03 . 2009-04-29 02:04 2463232 ----a-w- c:\winnt\Internet Logs\xDBC.tmp
2009-04-29 00:04 . 2008-09-15 21:00 1278089 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\MostFun_JennysFishShop\IAF.dll
2009-04-27 16:38 . 2009-04-27 16:38 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-27 16:38 . 2009-03-16 16:38 64160 ----a-w- c:\winnt\system32\drivers\Lbd.sys
2009-04-26 19:16 . 2009-04-26 19:16 2442752 ----a-w- c:\winnt\Internet Logs\xDBB.tmp
2006-07-16 15:49 . 2005-02-05 21:48 2855080 -c--a-w- c:\program files\aawsepersonal.exe
2005-02-02 07:46 . 2005-02-02 07:46 485386 -c--a-w- c:\program files\KennyChesney_MeAndYou.wav
2005-01-30 19:12 . 2005-01-30 19:12 4354084 -c--a-w- c:\program files\spybotsd13.exe
2004-08-03 05:47 . 2004-08-03 05:49 15817 -c--a-w- c:\program files\halting.mid
2004-08-03 05:39 . 2004-06-28 04:09 8946 -c--a-w- c:\program files\DannyBoy.mid
2004-08-02 06:47 . 2004-08-02 06:49 19697 -c--a-w- c:\program files\Dueling_Banjoes.mid
2004-08-02 06:16 . 2004-08-02 06:24 24037 -c--a-w- c:\program files\aughrim.mid
2004-08-02 06:03 . 2004-08-02 06:06 34015 -c--a-w- c:\program files\CottonEyedJoe.mid
2004-08-02 05:11 . 2004-08-02 05:13 37370 -c--a-w- c:\program files\Eyeofthetiger.mid
2004-08-02 05:10 . 2004-08-02 05:10 24227 -c--a-w- c:\program files\everythingido.mid
2004-07-26 03:07 . 2004-07-26 03:07 3718222 ----a-w- c:\program files\supersleuth.exe
2004-07-25 19:28 . 2004-07-25 19:28 4547319 -c--a-w- c:\program files\AOLSlingo_Setup.exe
2004-07-04 06:53 . 2004-07-04 06:53 2543056 -c--a-w- c:\program files\RumbleCubeInstall.exe
2003-12-25 05:13 . 2003-12-25 05:13 24122368 -c--a-w- c:\program files\CJXP75LE.exe
2003-12-18 07:28 . 2003-12-18 07:28 670392 -c--a-w- c:\program files\to_all_good_night.zip
2003-12-17 16:49 . 2003-12-17 16:49 1897672 -c--a-w- c:\program files\winzip81.exe
2009-04-24 04:38 . 2008-06-25 20:55 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-22_19.26.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 23:46 . 2009-07-22 23:46 16384 c:\winnt\Temp\Perflib_Perfdata_788.dat
+ 1980-01-01 05:00 . 2008-04-14 00:11 110080 c:\winnt\system32\imm32.dll
+ 1980-01-01 05:00 . 2008-04-14 00:11 110080 c:\winnt\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\progra~1\AIM\aim.exe" [2004-03-12 61440]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-31 313472]
"spc_w"="c:\program files\NZSearch\hcm.exe" [2004-05-13 258114]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-02 39408]
"oovoo.exe"="c:\program files\ooVoo\oovoo.exe" [2009-03-30 14612272]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
"AOL Fast Start"="c:\program files\America Online 9.0f\AOL.EXE" [2005-07-12 50776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"HostManager"="c:\program files\Common Files\AOL\1127920375\ee\AOLSoftware.exe" [2008-06-24 41824]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2008-02-13 2065648]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-06 520024]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"Logitech Utility"="Logi_MwX.Exe" - c:\winnt\LOGI_MWX.EXE [2003-11-07 19968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"OOBEDDDemise"="erase" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-14 39264]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2004-2-14 45056]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2005-3-17 331776]
Icatch(VI) SnapDetect.lnk.disabled [2004-12-4 507]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-8-11 757760]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-2-19 169472]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\winnt\pss\AOL Companion.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
backup=c:\winnt\pss\Event Reminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\winnt\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MostFun.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MostFun.lnk
backup=c:\winnt\pss\MostFun.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Common Files\\AOL\\1127920375\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
"c:\\Program Files\\America Online 9.0f\\waol.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Abacast\\Abaclient.exe"=
"c:\\Program Files\\Conference\\Conference.dll"=
"c:\\Program Files\\Common Files\\AOL\\1127920375\\EE\\aolsoftware.exe"=
"c:\\WINNT\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP

oVoo UDP port 443
"37674:TCP"= 37674:TCP

oVoo TCP port 37674
"37674:UDP"= 37674:UDP

oVoo UDP port 37674
"37675:UDP"= 37675:UDP

oVoo UDP port 37675
R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [3/16/2009 8:38 AM 64160]
R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [11/6/2008 7:03 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [11/6/2008 7:03 AM 20560]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [7/9/2009 12:21 PM 78104]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/11/2007 10:43 PM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 11:06 AM 1029456]
S2 gupdate1c9b3e768b5fac6;Google Update Service (gupdate1c9b3e768b5fac6);c:\program files\Google\Update\GoogleUpdate.exe [4/2/2009 3:04 PM 133104]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\winnt\system32\drivers\mr97310v.sys [1/8/2005 7:41 PM 116078]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\winnt\system32\rundll32.exe" "c:\winnt\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-13 c:\winnt\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 16:40]
2009-07-10 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 21:42]
2009-07-22 c:\winnt\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-02 17:44]
2009-07-23 c:\winnt\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:04]
2009-07-23 c:\winnt\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:04]
2009-07-22 c:\winnt\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 03:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{D38C2142-9CC3-4A3B-A85C-EE07D51E6F45} - (no file)
.
------- Supplementary Scan -------
.
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
Trusted Zone: gamehouse.com
DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fashion-dash/fashiondashweb.1.0.0.21.cab
DPF: {055B4212-4C81-448E-AFA9-C3CA4AAE8F95} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dairy-dash/DairyDashWeb.1.0.0.16.cab
DPF: {068BFA33-99F4-4BA9-887D-182386FA2931} - hxxp://download.playfirst.com/play/game/spongebobdash/SpongeBobDinerDashWeb.1.0.0.17.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/EmeraldCityConfidential_Web.1.0.0.9.cab
DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} - hxxps://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} - hxxp://aolsvc.aol.com/onlinegames/free-trial-cooking-dash/CookingDashWeb.1.0.0.9.cab
DPF: {1CDFA4E8-3396-439D-8C9D-AD0E32DE94B6} - hxxp://cdn.ll.neoedge.com/webgames/TastyPlanet/tastyplanet.1.0.0.4.cab
DPF: {21BB8360-F943-447E-98F3-3C22345375A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-chocolatier/ChocolatierWeb.1.0.0.13.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-of-shark-island/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} - hxxp://download.playfirst.com/play/game/trijinx/TriJinx.1.0.0.86.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://aol.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} - hxxp://aolsvc.aol.com/onlinegames/trypiratepoppers/PiratePoppers.1.0.0.32.cab
DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} - hxxp://games.bigfishgames.com/en_nightshift-legacy-the-jaguars-eye/online/Nightshift2Web.1.0.0.9.cab
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} - hxxp://aolsvc.aol.com/onlinegames/free-trial-the-great-chocolate-chase/greatchocolatechaseweb.1.0.0.12.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {74EF5274-F439-2168-B543-14745B625C72} - hxxp://aolsvc.aol.com/onlinegames/free-trial-wedding-dash-2/WeddingDash2Web.1.0.0.11.cab
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dream-chronicles/dreamweb.1.0.0.6.cab
DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-solitaire-secret-island/SpinTopGamesLauncher.cab
DPF: {7D492D61-303A-45C3-8A55-63449339943D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-the-nightshift-code/NightShiftCodeWeb.1.0.0.5.cab
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://www.shockwave.com/content/ghostfrenzy/sis/axhost.cab
DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} - hxxp://games.bigfishgames.com/en_butterflyescape/online/GenimoWebGamesControl.cab
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-pi-the-lottery-ticket/SpinTopGamesLauncher.cab
DPF: {AB1AB4F8-C30F-4FB4-A030-1C9F5513831F} - hxxp://media.grab.com/media/6364d3/games/files/669/lregameloader6.cab
DPF: {B12213CD-4189-415D-A054-7999528459F7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-word-travels/pixelstormlauncher.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://209.67.146.69/ePlayer/2_0/ACNePlayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-delicious-winter-edition/zylomplayer.cab
DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} - hxxp://aolsvc.aol.com/onlinegames/free-trial-pet-shop-hop/petshophopweb.1.0.0.16.cab
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://download.playfirst.com/play/game/chocolatier2/Chocolatier2Web.1.0.0.10.cab
DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-sandscript/SandScript.1.0.0.21.cab
DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} - hxxp://aolsvc.aol.com/onlinegames/dinerdash/DinerDash.1.0.0.93.cab
DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dream-chronicles-2/dream2web.1.0.0.13.cab
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://aolsvc.aol.com/onlinegames/oberonmajongescape/PTGameLauncher.cab
DPF: {F135A813-7152-4532-AC8D-28AC2136DFC7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-parking-dash/parkingdash.1.0.0.10.cab
DPF: {F46BD8B1-DE4C-4A4F-B6F6-8FB68D25342D} - hxxp://download.playfirst.com/play/game/mahjongroadshow/MahjongRoadshowWeb.1.0.0.16.cab
DPF: {FCB28D51-A017-46B2-9FB3-F7BFD53B2E42} - hxxp://aolsvc.aol.com/onlinegames/free-trial-decadence-by-design/Chocolatier3Web.1.0.0.6.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\krs9njpc.default\
FF - prefs.js: browser.search.selectedEngine - Verizon
FF - prefs.js: browser.startup.homepage - hxxp://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=7.0unattached&bm=ho_central
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\plugins\NPAbacheck.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-23 07:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
OOBEDDDemise = cmd /x /c erase c:\winnt\System32\oobe\msoobe.exe?e?0?E?2?\?o?o?b?e?\?h???E??????:?w????0?E???????E?????????????x??????w????7??w???? K?c??????E???E????wH/??P???????P????????-??????????????????T?????????E??????0C?x????????^?w?n??p????:?w????Ho??????????????D??????w???????w????7??w????????????C
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-23 7:50
ComboFix-quarantined-files.txt 2009-07-23 15:50
ComboFix2.txt 2009-07-23 00:08
ComboFix3.txt 2009-07-22 19:55
ComboFix4.txt 2007-06-15 15:17
Pre-Run: 84,861,136,896 bytes free
Post-Run: 84,847,534,080 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
319 --- E O F --- 2009-07-16 20:43
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Thursday, July 23, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, July 23, 2009 23:13:47
Records in database: 2522654
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
Scan statistics:
Files scanned: 184427
Threat name: 4
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 03:47:21
File name / Threat name / Threats count
C:\Program Files\iWin.com\Golden Hearts Juice Bar\GLWorker.exe Infected: Trojan-Spy.Win32.SCKeyLog.by 1
C:\Program Files\iWin.com\Season Match\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.bc 1
C:\Program Files\iWin.com\The Scruffs\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.ae 1
C:\Program Files\iWin.com\The Scruffs\GLWorker.exe Infected: Trojan-Spy.Win32.SCKeyLog.es 1
The selected area was scanned.
DDS (Ver_09-06-26.01) - NTFSx86
Run by Owner at 19:14:08.45 on Thu 07/23/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.143 [GMT -8:00]
AV: avast! antivirus 4.8.1335 [VPS 090723-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\AOL\1127920375\ee\AOLSoftware.exe
C:\WINNT\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ooVoo\oovoo.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\America Online 9.0f\waol.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINNT\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\America Online 9.0f\shellmon.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Owner\Desktop\Logs and Fixes\dds.scr
============== Pseudo HJT Report ===============
BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\compan~1\installs\cpn\ycomp5_5_7_0.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - No File
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - No File
BHO: PaltalkWebLogin: {502c3ba4-2c3e-4317-bc29-c0445e82b1f9} - c:\program files\common files\paltalk\PaltalkWebLogin.dll
BHO: PPCScamBHO Class: {7e3659a6-4bc5-4d93-b3fd-8b5acc2feded} - c:\program files\peoplepc\toolbar\ScamGrd.dll
BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll
BHO: {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No File
BHO: {ACB3E0B7-7D0C-40B7-99B3-3EEACDF86BFB} - No File
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
BHO: {D38C2142-9CC3-4A3B-A85C-EE07D51E6F45} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: &Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\compan~1\installs\cpn\ycomp5_5_7_0.dll
TB: {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No File
TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\winnt\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [AIM] c:\progra~1\aim\aim.exe -cnetwait.odl
uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [spc_w] "c:\program files\nzsearch\hcm.exe" -w
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [oovoo.exe] c:\program files\oovoo\oovoo.exe /minimized
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [AOL Fast Start] "c:\program files\america online 9.0f\AOL.EXE" -b
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [HostManager] c:\program files\common files\aol\1127920375\ee\AOLSoftware.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [VerizonServicepoint.exe] "c:\program files\verizon\vsp\VerizonServicepoint.exe" /AUTORUN
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Verizon_McciTrayApp] c:\program files\verizon\McciTrayApp.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [OOBEDDDemise] cmd /x /c erase c:\winnt\system32\oobe\msoobe.exe
mRunOnce: [Uninstall Adobe Download Manager] "c:\program files\nos\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\broderbund\printmaster\pmremind.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Icatch(VI) SnapDetect.lnk.disabled
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\progra~1\aim\aim.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\PartyPoker.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\winnt\system32\Shdocvw.dll
Trusted Zone: gamehouse.com
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fashion-dash/fashiondashweb.1.0.0.21.cab
DPF: {055B4212-4C81-448E-AFA9-C3CA4AAE8F95} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dairy-dash/DairyDashWeb.1.0.0.16.cab
DPF: {068BFA33-99F4-4BA9-887D-182386FA2931} - hxxp://download.playfirst.com/play/game/spongebobdash/SpongeBobDinerDashWeb.1.0.0.17.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/EmeraldCityConfidential_Web.1.0.0.9.cab
DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} - hxxps://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} - hxxp://aolsvc.aol.com/onlinegames/free-trial-cooking-dash/CookingDashWeb.1.0.0.9.cab
DPF: {1CDFA4E8-3396-439D-8C9D-AD0E32DE94B6} - hxxp://cdn.ll.neoedge.com/webgames/TastyPlanet/tastyplanet.1.0.0.4.cab
DPF: {21BB8360-F943-447E-98F3-3C22345375A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-chocolatier/ChocolatierWeb.1.0.0.13.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-of-shark-island/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} - hxxp://download.playfirst.com/play/game/trijinx/TriJinx.1.0.0.86.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/yinst/yinst_current.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://aol.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {38A5F6F0-0B64-421B-A553-3D49A76ECDCD} - hxxp://download.playfirst.com/play/game/mythicmarbles/MythicMarbles.1.0.0.3.cab
DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} - hxxp://aolsvc.aol.com/onlinegames/trypiratepoppers/PiratePoppers.1.0.0.32.cab
DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - hxxp://aolcc.aol.com/computercheckup/qdiagcc.cab
DPF: {4C226336-4032-489F-9674-67E74225979B}
DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} - hxxp://games.bigfishgames.com/en_nightshift-legacy-the-jaguars-eye/online/Nightshift2Web.1.0.0.9.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://www.shockwave.com/content/dinerdash2/sis/DinerDash2.1.0.0.67.cab
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} - hxxp://aolsvc.aol.com/onlinegames/free-trial-the-great-chocolate-chase/greatchocolatechaseweb.1.0.0.12.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182383902421
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {74EF5274-F439-2168-B543-14745B625C72} - hxxp://aolsvc.aol.com/onlinegames/free-trial-wedding-dash-2/WeddingDash2Web.1.0.0.11.cab
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dream-chronicles/dreamweb.1.0.0.6.cab
DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-solitaire-secret-island/SpinTopGamesLauncher.cab
DPF: {7D492D61-303A-45C3-8A55-63449339943D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-the-nightshift-code/NightShiftCodeWeb.1.0.0.5.cab
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://verizon.oberon-media.com/online/online2/luxor_2/mjolauncher.cab
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://www.shockwave.com/content/ghostfrenzy/sis/axhost.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} - hxxp://games.bigfishgames.com/en_butterflyescape/online/GenimoWebGamesControl.cab
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-pi-the-lottery-ticket/SpinTopGamesLauncher.cab
DPF: {AB1AB4F8-C30F-4FB4-A030-1C9F5513831F} - hxxp://media.grab.com/media/6364d3/games/files/669/lregameloader6.cab
DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} - hxxp://www.worldwinner.com/games/v67/swapit/swapit.cab
DPF: {B12213CD-4189-415D-A054-7999528459F7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-word-travels/pixelstormlauncher.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://209.67.146.69/ePlayer/2_0/ACNePlayer.cab
DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-zenerchi/ZenerchiWeb.1.0.0.10.cab
DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} - hxxp://aolsvc.aol.com/onlinegames/free-trial-diner-dash-flo-on-the-go/ddfotg.1.0.0.33.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-delicious-winter-edition/zylomplayer.cab
DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} - hxxp://aolsvc.aol.com/onlinegames/free-trial-pet-shop-hop/petshophopweb.1.0.0.16.cab
DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} - hxxp://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://gamerival.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://download.playfirst.com/play/game/chocolatier2/Chocolatier2Web.1.0.0.10.cab
DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-sandscript/SandScript.1.0.0.21.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://www.shockwave.com/content/cinematycoon/sis/cinematycoon.cab
DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} - hxxp://aolsvc.aol.com/onlinegames/sonydavincicode/DVCDownloaderControl.cab
DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} - hxxp://aolsvc.aol.com/onlinegames/dinerdash/DinerDash.1.0.0.93.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dream-chronicles-2/dream2web.1.0.0.13.cab
DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} - hxxp://aolsvc.aol.com/onlinegames/free-trial-wedding-dash/WeddingDash.1.0.0.47.cab
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://aolsvc.aol.com/onlinegames/oberonmajongescape/PTGameLauncher.cab
DPF: {F135A813-7152-4532-AC8D-28AC2136DFC7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-parking-dash/parkingdash.1.0.0.10.cab
DPF: {F46BD8B1-DE4C-4A4F-B6F6-8FB68D25342D} - hxxp://download.playfirst.com/play/game/mahjongroadshow/MahjongRoadshowWeb.1.0.0.16.cab
DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} - hxxp://aolsvc.aol.com/onlinegames/free-trial-sweetopia/Sweetopia.1.0.0.22.cab
DPF: {FCB28D51-A017-46B2-9FB3-F7BFD53B2E42} - hxxp://aolsvc.aol.com/onlinegames/free-trial-decadence-by-design/Chocolatier3Web.1.0.0.6.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxsrvc.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\krs9njpc.default\
FF - prefs.js: browser.search.selectedEngine - Verizon
FF - prefs.js: browser.startup.homepage - hxxp://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=7.0unattached&bm=ho_central
FF - plugin: c:\documents and settings\all users\application data\zylom\zylomgamesplayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\NPAbacheck.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [2009-3-16 64160]
R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2008-11-6 114768]
R1 vsdatant;vsdatant;c:\winnt\system32\vsdatant.sys [2008-8-21 353672]
R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2008-11-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-11-6 138680]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-7-9 78104]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-3-11 24652]
R2 vsmon;TrueVector Internet Monitor;c:\winnt\system32\zonelabs\vsmon.exe -service --> c:\winnt\system32\zonelabs\vsmon.exe -service [?]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S2 gupdate1c9b3e768b5fac6;Google Update Service (gupdate1c9b3e768b5fac6);c:\program files\google\update\GoogleUpdate.exe [2009-4-2 133104]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-11-6 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-11-6 352920]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-7-23 66056]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\winnt\system32\drivers\mr97310v.sys [2005-1-8 116078]
=============== Created Last 30 ================
2009-07-23 09:20 410,984 a------- c:\winnt\system32\deploytk.dll
2009-07-23 07:28 39,424 a------- c:\winnt\system32\grpconv.exe
2009-07-23 07:28 39,424 a------- c:\winnt\system32\dllcache\grpconv.exe
2009-07-23 07:26 <DIR> --ds---- C:\ComboFix
2009-07-22 14:33 <DIR> a-dshr-- C:\cmdcons
2009-07-22 11:51 <DIR> --d----- c:\winnt\system32\dllcache\cache
2009-07-22 07:19 219,648 a------- c:\winnt\PEV.exe
2009-07-22 07:19 161,792 a------- c:\winnt\SWREG.exe
2009-07-22 07:19 98,816 a------- c:\winnt\sed.exe
2009-07-16 19:10 <DIR> --d----- c:\program files\Safer Networking
2009-07-16 19:03 <DIR> --d----- c:\program files\Trend Micro
2009-07-16 12:42 118 a------- c:\winnt\system32\MRT.INI
2009-07-16 10:35 1,063,647 a------- c:\winnt\system32\rn.tmp
2009-07-14 15:29 <DIR> --d----- c:\program files\iWin Games
2009-07-08 19:00 <DIR> --dsh--- c:\documents and settings\owner\PrivacIE
2009-07-08 18:23 <DIR> --dsh--- c:\documents and settings\owner\IETldCache
2009-07-08 18:20 102,912 -------- c:\winnt\system32\dllcache\iecompat.dll
2009-07-08 18:19 <DIR> --d----- c:\winnt\ie8updates
2009-07-08 18:18 12,800 -------- c:\winnt\system32\dllcache\xpshims.dll
2009-07-08 18:18 246,272 -------- c:\winnt\system32\dllcache\ieproxy.dll
2009-07-08 18:15 <DIR> -cd-h--- c:\winnt\ie8
2009-07-05 18:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Meridian93
2009-07-02 13:37 <DIR> --d----- c:\docume~1\owner\applic~1\Home Sweet Home Christmas
2009-06-29 15:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DriverScanner
2009-06-29 15:11 <DIR> --d----- c:\program files\Uniblue
2009-06-29 15:11 <DIR> --d----- c:\docume~1\owner\applic~1\Uniblue
2009-06-29 15:09 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-06-26 16:15 <DIR> --d----- c:\documents and settings\owner\Freeze Tag - Dream Machine
==================== Find3M ====================
2009-06-16 20:20 444,952 a------- c:\winnt\system32\wrap_oal.dll
2009-06-16 20:20 109,080 a------- c:\winnt\system32\OpenAL32.dll
2009-06-01 09:02 15,688 a------- c:\winnt\system32\lsdelete.exe
2009-05-12 21:15 915,456 a------- c:\winnt\system32\wininet.dll
2009-05-12 21:15 915,456 a------- c:\winnt\system32\dllcache\cache\wininet.dll
2009-05-12 21:15 5,936,128 -------- c:\winnt\system32\dllcache\mshtml.dll
2009-05-12 21:15 915,456 -------- c:\winnt\system32\dllcache\wininet.dll
2009-05-07 07:32 345,600 a------- c:\winnt\system32\localspl.dll
2009-05-07 07:32 345,600 -------- c:\winnt\system32\dllcache\localspl.dll
2009-04-30 13:22 1,985,024 -------- c:\winnt\system32\dllcache\iertutil.dll
2009-04-30 13:22 11,064,832 -------- c:\winnt\system32\dllcache\ieframe.dll
2009-04-30 13:22 1,207,808 -------- c:\winnt\system32\dllcache\urlmon.dll
2009-04-30 13:22 25,600 -------- c:\winnt\system32\dllcache\jsproxy.dll
2009-04-30 13:22 385,536 -------- c:\winnt\system32\dllcache\iedkcs32.dll
2009-04-30 03:21 173,056 -------- c:\winnt\system32\dllcache\ie4uinit.exe
2009-04-28 20:55 133,120 a------- c:\winnt\system32\dllcache\extmgr.dll
2009-04-28 01:05 13,824 -------- c:\winnt\system32\dllcache\ieudinit.exe
2009-03-31 14:34 28,772 a------- c:\docume~1\owner\applic~1\wklnhst.dat
2008-03-08 10:11 389,120 a------- c:\documents and settings\owner\GoToAssist_phone__268_en.exe
2008-01-16 10:40 110 a------- c:\docume~1\alluse~1\applic~1\MostFunGameId.bin
2007-02-23 16:13 77,456 ac------ c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
2006-09-14 17:03 7,238 ac------ c:\docume~1\owner\applic~1\unins000.dat
2006-09-14 17:00 673,546 a------- c:\docume~1\owner\applic~1\unins000.exe
2006-07-16 07:49 2,855,080 ac------ c:\program files\aawsepersonal.exe
2005-02-01 23:46 485,386 ac------ c:\program files\KennyChesney_MeAndYou.wav
2005-01-30 11:12 4,354,084 ac------ c:\program files\spybotsd13.exe
2004-08-02 21:47 15,817 ac------ c:\program files\halting.mid
2004-08-02 21:39 8,946 ac------ c:\program files\DannyBoy.mid
2004-08-01 22:47 19,697 ac------ c:\program files\Dueling_Banjoes.mid
2004-08-01 22:16 24,037 ac------ c:\program files\aughrim.mid
2004-08-01 22:03 34,015 ac------ c:\program files\CottonEyedJoe.mid
2004-08-01 21:11 37,370 ac------ c:\program files\Eyeofthetiger.mid
2004-08-01 21:10 24,227 ac------ c:\program files\everythingido.mid
2004-07-25 19:07 3,718,222 a------- c:\program files\supersleuth.exe
2004-07-25 11:28 4,547,319 ac------ c:\program files\AOLSlingo_Setup.exe
2004-07-03 22:53 2,543,056 ac------ c:\program files\RumbleCubeInstall.exe
2004-06-13 15:01 169,504 ac------ c:\docume~1\owner\applic~1\shb.dat
2004-01-01 13:01 1,024 ac------ c:\documents and settings\owner\UserInfo.dat
2003-12-24 21:13 24,122,368 ac------ c:\program files\CJXP75LE.exe
2003-12-17 23:28 670,392 ac------ c:\program files\to_all_good_night.zip
2003-12-17 08:49 1,897,672 ac------ c:\program files\winzip81.exe
2009-04-02 19:13 32,768 a--sh--- c:\winnt\system32\config\systemprofile\local settings\history\history.ie5\mshist012009040220090403\index.dat
============= FINISH: 19:15:37.34 ===============