Hi
When I copied the text into avenger I'm pretty sure I included
Files to delete:
C:\WINDOWS\system32\cmcache.dat
ComboFix 07-10-11.3 - ALEX 2007-10-11 16:54:29.9 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.62 [GMT -7:00]
Running from: C:\Documents and Settings\ALEX\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\ALEX\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\System32\cmcache.dat
C:\WINDOWS\system32\drivers\dicn^hua.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\VisualRoute
C:\Program Files\VisualRoute\keyv8-FFFFFFFFB4CF4577-A.bin
C:\Program Files\VisualRoute\startup.ini
C:\Program Files\VisualRoute\trv80.bin
C:\Program Files\VisualRoute\vr\console.txt
C:\Program Files\VisualRoute\vr\dns\216.130.164.198.txt
C:\Program Files\VisualRoute\vr\hops\216.130.164.198.txt
C:\Program Files\VisualRoute\vr\mru.txt
C:\Program Files\VisualRoute\vr\rdns\198.32.160.100.txt
C:\Program Files\VisualRoute\vr\rdns\63.93.97.197.txt
C:\Program Files\VisualRoute\vr\rdns\63.93.97.42.txt
C:\Program Files\VisualRoute\vr\rdns\66.162.144.29.txt
C:\Program Files\VisualRoute\vr\rdns\66.192.255.2.txt
C:\Program Files\VisualRoute\vr\rdns\66.52.181.187.txt
C:\Program Files\VisualRoute\vr\whois\arin-198.32.160.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-216.130.164.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-63.93.97.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-66.162.144.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-66.192.240.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-66.192.250.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-66.192.255.0.txt
C:\Program Files\VisualRoute\vr\whois\arin-66.52.181.0.txt
C:\Program Files\VisualRoute\vr\whois\whois.arin.net-HANDLE-NET-198-32-0-0-1.txt
C:\Program Files\VisualRoute\vr\whois\whois.arin.net-HANDLE-NET-216-130-160-0-1.txt
C:\Program Files\VisualRoute\vr\whois\whois.arin.net-HANDLE-NET-63-93-96-0-1.txt
C:\Program Files\VisualRoute\vr\whois\whois.arin.net-HANDLE-NET-66-192-0-0-1.txt
C:\Program Files\VisualRoute\vr\whois\whois.arin.net-HANDLE-NET-66-52-0-0-1.txt
C:\WINDOWS\System32\cmcache.dat
C:\WINDOWS\system32\drivers\dicn^hua.sys
.
((((((((((((((((((((((((( Files Created from 2007-09-11 to 2007-10-11 )))))))))))))))))))))))))))))))
.
2007-10-08 15:52 <DIR> d-------- C:\WINDOWS\pss
2007-10-07 18:31 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-07 18:31 <DIR> d-------- C:\WINDOWS\ehome
2007-10-07 18:21 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2007-10-07 18:14 76,288 --a------ C:\WINDOWS\system32\avifil32.dll
2007-10-07 18:14 71,680 --a------ C:\WINDOWS\system32\browsewm.dll
2007-10-07 18:14 62,976 --a------ C:\WINDOWS\system32\browselc.dll
2007-10-07 18:14 59,904 --a------ C:\WINDOWS\system32\cabinet.dll
2007-10-07 18:14 49,152 --a------ C:\WINDOWS\system32\browser.dll
2007-10-07 18:14 6,656 --a------ C:\WINDOWS\system32\batt.dll
2007-10-07 18:13 74,810 --a------ C:\WINDOWS\system32\atl.dll
2007-10-07 18:13 38,912 --a------ C:\WINDOWS\system32\audiosrv.dll
2007-10-07 18:13 8,192 --a------ C:\WINDOWS\system32\autolfn.exe
2007-10-07 18:12 115,712 --a------ C:\WINDOWS\system32\apphelp.dll
2007-10-07 18:12 32,512 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2007-10-07 18:12 22,528 --a------ C:\WINDOWS\system32\at.exe
2007-10-07 18:12 14,366 --a------ C:\WINDOWS\system32\asfsipc.dll
2007-10-07 18:11 239,616 --a------ C:\WINDOWS\system32\adsnt.dll
2007-10-07 18:11 162,816 --a------ C:\WINDOWS\system32\adsldp.dll
2007-10-07 18:11 139,776 --a------ C:\WINDOWS\system32\adsldpc.dll
2007-10-07 18:11 91,648 --a------ C:\WINDOWS\system32\ahui.exe
2007-10-07 18:11 62,464 --a------ C:\WINDOWS\system32\adsmsext.dll
2007-10-07 18:11 41,984 --a------ C:\WINDOWS\system32\alg.exe
2007-10-07 18:10 59,392 --a------ C:\WINDOWS\system32\6to4svc.dll
2007-10-07 18:09 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2007-10-07 18:09 42,537 --a------ C:\WINDOWS\system32\keyboard.sys
2007-09-30 18:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-09-30 18:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-30 18:29 <DIR> d-------- C:\Documents and Settings\ALEX\Application Data\SUPERAntiSpyware.com
2007-09-30 17:54 3,470 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-29 17:57 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-28 23:34 <DIR> d-------- C:\Documents and Settings\ALEX\Application Data\AVG7
2007-09-28 23:29 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-09-28 23:29 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-09-28 23:29 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-09-28 23:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-09-28 23:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-09-28 22:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-28 16:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2007-09-28 15:39 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-09-28 15:39 <DIR> d-------- C:\Documents and Settings\Administrator\NetWorkSwitch.temp
2007-09-28 15:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-09-28 15:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2007-09-28 15:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Drag'n Drop CD
2007-09-27 18:50 68,608 --a------ C:\WINDOWS\system32\locator.exe
2007-09-27 18:50 68,608 --a--c--- C:\WINDOWS\system32\dllcache\locator.exe
2007-09-27 18:47 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-09-26 15:49 <DIR> d-------- C:\Program Files\Funk Software
2007-09-26 15:49 <DIR> d-------- C:\Program Files\Common Files\Funk Software
2007-09-26 15:48 <DIR> d-------- C:\Program Files\Linksys
2007-09-26 15:48 1,706,800 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-09-26 15:48 1,497,088 --a------ C:\WINDOWS\system32\cc3260mt.dll
2007-09-26 15:48 1,496,064 --a------ C:\WINDOWS\system32\cc3250mt.dll
2007-09-26 15:48 543,104 --a------ C:\WINDOWS\system32\drivers\BCMWL5.SYS
2007-09-26 15:48 94,208 --a------ C:\WINDOWS\system32\W32N50CT.DLL
2007-09-26 15:48 25,600 --a------ C:\WINDOWS\system32\borlndmm.dll
2007-09-26 15:48 17,142 --a------ C:\WINDOWS\system32\CBTNDIS5.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-08 05:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-08 05:02 27,840 ----a-w C:\WINDOWS\java\x.exe
2007-10-03 21:41 --------- d-----w C:\Program Files\Ivde
2007-10-01 03:55 --------- d-----w C:\Program Files\MBKWBar
2007-09-30 06:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-09-30 06:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-30 05:59 --------- d-----w C:\Program Files\Symantec
2007-09-30 05:56 --------- d-----w C:\Documents and Settings\ALEX\Application Data\Lavasoft
2007-09-26 22:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-10 03:41 --------- d-----w C:\Program Files\Microsoft Streets and Trips
2007-08-25 16:28 --------- d-----w C:\Program Files\MySpace
2007-08-24 04:57 --------- d-----w C:\Documents and Settings\ALEX\Application Data\MySpace
2007-08-17 02:12 --------- d-----w C:\Program Files\Opera
2007-07-31 02:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2004-11-04 19:02 41,648 -c--a-w C:\Documents and Settings\ALEX\Application Data\GDIPFONTCACHEV1.DAT
2002-09-08 18:11 56,832 -csha-w C:\Program Files\Thumbs.db
2001-08-18 12:00:00 94,784 -csh--w C:\WINDOWS\twain.dll
2001-08-18 12:00:00 46,592 -csh--w C:\WINDOWS\twain_32.dll
2001-08-18 12:00:00 995,383 --sh--w C:\WINDOWS\system32\mfc42.dll
2001-08-18 12:00:00 50,688 -csh--w C:\WINDOWS\system32\msvcirt.dll
2002-08-29 10:41:08 401,462 --sha-w C:\WINDOWS\system32\msvcp60.dll
2002-08-29 10:41:08 323,072 --sha-w C:\WINDOWS\system32\msvcrt.dll
2002-08-29 10:41:10 569,344 --sh--w C:\WINDOWS\system32\oleaut32.dll
2001-08-18 12:00:00 106,496 --sh--w C:\WINDOWS\system32\olepro32.dll
2001-08-18 12:00:00 9,728 -csh--w C:\WINDOWS\system32\regsvr32.exe
.
((((((((((((((((((((((((((((( snapshot@2007-10-10_17.59.46.04 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 262,144 2007-10-11 23:54:26 C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
----a-w 262,144 2007-10-11 00:37:40 C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [2002-04-15 18:35]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 C:\WINDOWS\system32\000StTHK.exe]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 03:37]
"S3Hotkey"="s3hotkey.exe" [2001-09-12 21:27 C:\WINDOWS\system32\s3hotkey.exe]
"S3TRAY2"="S3Tray2.exe" [2002-02-20 16:38 C:\WINDOWS\system32\S3Tray2.exe]
"TFNF5"="TFNF5.exe" [2001-08-03 18:08 C:\WINDOWS\system32\TFNF5.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2002-03-29 14:40]
"TFncKy"="TFncKy.exe" []
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-04-12 11:13]
"Tpwrtray"="TPWRTRAY.EXE" [2002-03-19 20:38 C:\WINDOWS\system32\TPWRTRAY.EXE]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 07:11]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-04-09 17:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 18:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 09:38]
"kmw_run.exe"="kmw_run.exe" [2003-05-27 14:48 C:\WINDOWS\system32\kmw_run.exe]
"MSWheel"="" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 04:03]
"Linksys Wireless-N Notebook Adapter"="C:\Program Files\Linksys\Wireless-N Network Monitor\WPC300N.exe" [2006-04-28 05:55]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-28 23:28]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 21:31]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 06:19:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
SpySubtract.lnk - C:\Program Files\interMute\SpySubtract\SpySub.exe [2005-02-01 19:49:19]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= c:\Program Files\interMute\SpySubtract\sshook.dll [2005-02-01 19:49 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\System32\DRIVERS\TVALG.SYS
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\System32\CBTNDIS5.SYS
R3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\System32\DRIVERS\KMW_KBD.sys
R3 KMW_SYS;Kensington MouseWorks Mouse filter driver;C:\WINDOWS\System32\DRIVERS\KMW_SYS.sys
R3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\System32\DRIVERS\odysseyIM4.sys
R3 TOSHIBASoftModem;TOSHIBA Software Modem;C:\WINDOWS\System32\DRIVERS\LTSM.sys
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\System32\DRIVERS\tsdhd.sys
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\System32\DRIVERS\KMW_USB.sys
S3 pciSd;pciSd;C:\WINDOWS\System32\DRIVERS\tossdpci.sys
S3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\System32\drivers\yacxgc.sys
S3 wlluc48;Wireless LAN PC Card Driver;C:\WINDOWS\System32\DRIVERS\wlluc48.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 01:05:18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-11 01:20:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
"2007-10-11 23:56:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-11 17:00:30
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-11 17:01:38
C:\ComboFix-quarantined-files.txt ... 2007-10-09 18:18
C:\ComboFix2.txt ... 2007-10-10 18:00
C:\ComboFix3.txt ... 2007-10-09 18:19
.
--- E O F ---
SDFix: Version 1.108
Run by ALEX on Thu 10/11/2007 at 05:54 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\grcbmvcv.exe.tmp - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 18 Aug 2001 94,784 ..SH. --- "C:\WINDOWS\twain.dll"
Sat 18 Aug 2001 46,592 ..SH. --- "C:\WINDOWS\twain_32.dll"
Sat 18 Aug 2001 995,383 ..SH. --- "C:\WINDOWS\system32\mfc42.dll"
Sat 18 Aug 2001 50,688 ..SH. --- "C:\WINDOWS\system32\msvcirt.dll"
Thu 29 Aug 2002 401,462 A.SH. --- "C:\WINDOWS\system32\msvcp60.dll"
Thu 29 Aug 2002 323,072 A.SH. --- "C:\WINDOWS\system32\msvcrt.dll"
Thu 29 Aug 2002 569,344 ..SH. --- "C:\WINDOWS\system32\oleaut32.dll"
Sat 18 Aug 2001 106,496 ..SH. --- "C:\WINDOWS\system32\olepro32.dll"
Sat 18 Aug 2001 9,728 ..SH. --- "C:\WINDOWS\system32\regsvr32.exe"
Sun 4 Dec 2005 3,285,296 A..H. --- "C:\Documents and Settings\ALEX\My Documents\keysetup13.exe"
Fri 4 Jul 2003 119,736 A..H. --- "C:\Documents and Settings\ALEX\My Documents\mtwlingo.exe"
Tue 26 Sep 2006 15,626,209 A..H. --- "C:\Documents and Settings\ALEX\My Documents\PICS 4 GDL.zip"
Sat 2 Aug 2003 391,213 A..H. --- "C:\Documents and Settings\ALEX\My Documents\wwmv0104b02.exe"
Sun 24 Dec 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 25 Sep 2002 0 A..H. --- "C:\Program Files\MSN\MSNCoreFiles.BAK.{FEC69D39-ADBA-4928-98F0-3571AA97ABDF}\BITF5.tmp"
Mon 6 Nov 2000 6,784 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\clcd16.dll"
Mon 6 Nov 2000 30,208 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\clcd32.dll"
Mon 6 Nov 2000 177,152 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\clokspl.exe"
Fri 18 Jun 1999 485,600 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\DPLAY61A.EXE"
Mon 6 Nov 2000 138,752 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\dplayerx.dll"
Mon 6 Nov 2000 34,304 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\drvmgt.dll"
Thu 2 Sep 1999 53,304 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\EBUEula.dll"
Thu 25 Nov 1999 2,560,000 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\empires2.exe"
Mon 28 Sep 1998 365,568 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\HA312W32.DLL"
Thu 30 Sep 1999 565,248 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\language.dll"
Mon 6 Nov 2000 67,584 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\mcp.dll"
Tue 3 Nov 1998 112,688 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\SHW32.DLL"
Wed 26 May 2004 19,968 ...H. --- "C:\Documents and Settings\ALEX\Application Data\Microsoft\Word\~WRL0003.tmp"
Sun 10 Jul 2005 28,672 ...H. --- "C:\Documents and Settings\ALEX\Application Data\Microsoft\Word\~WRL0004.tmp"
Mon 13 Jun 2005 585,216 ...H. --- "C:\Documents and Settings\ALEX\Application Data\Microsoft\Word\~WRL1077.tmp"
Sat 21 Dec 2002 4,650,695 A..H. --- "C:\Documents and Settings\ALEX\My Documents\3 SEMESTER\CD\kmd202_en.exe"
Tue 9 Sep 1997 29,184 ...H. --- "C:\Documents and Settings\ALEX\My Documents\Age of Empires II\Data\closedpw.exe"
Finished!
Alex