ComboFix 08-06-10.5 - Nelson 2008-06-12 2:55:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.177 [GMT -3:00]
Running from: C:\Documents and Settings\Nelson\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Documents and Settings\All Users\Application Data\ZangoSA
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Nelson\Application Data\ShoppingReport
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Nelson\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Nelson\Application Data\STEM32~1
C:\Documents and Settings\Nelson\Application Data\TSKS~1
C:\Documents and Settings\Nelson\Application Data\WeatherDPA
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\SearchWeather.xml
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\Weather_XML\Default
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\Weather_XML\Genera1
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\Weather_XML\General
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Links
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Display
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Loading
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen2
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen3
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\soaperror
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Version
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherDPA\WeatherPreferences
C:\Documents and Settings\Nelson\Application Data\WeatherDPA\Weather\WeatherStartup.xml
C:\Documents and Settings\Nelson\Application Data\Zango
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\1.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\1063425.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\1383582.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\1400453.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3251993.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3340762.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3404705.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3472949.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3875091.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3893245.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\3893642.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\648665.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\731481.sdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\domains.txt
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\1000068240
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\10915
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\114249
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\116250
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\14723
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\1491
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\15032
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\15473
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\16087
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\168810
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\17040
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\188810
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\1959
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\21119
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\21124
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\21669
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\216889
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\21846
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\243256
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\24996
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\25509
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\25735
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\26479
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\27503
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\290893
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\292137
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\31690
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\32137
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\33420
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\34123
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\352
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\37602
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\39947
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\42208
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\427075
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\42861
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\43118
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\43120
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\44228
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\44458
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\44896
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\46777
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\490133
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\521057
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\52335
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\52968
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\52974
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\52977
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\529776
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\54385
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\55266
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\555618
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\56412
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\56613
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\567106
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\57137
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\58965
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\59872
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\59905
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\60425
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\60785
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\62159
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\64446
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\64495
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\64517
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\64989
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\6565
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\65770
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\6635
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\67469
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\68055
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\68257
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\69911
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\70652
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\732186
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\738121
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\738235
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\744260
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\744816
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\745304
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\745440
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\748176
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\752154
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\753317
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\753335
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\77468
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\79079
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\79132
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\79246
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\79257
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\81566
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\82120
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\83139
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\8443
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\90358
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93110
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93811
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93958
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\94844
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\95610
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\95701
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\998
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\dynamic\ustat\367f.dat
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\btntrans.idx
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\btntrans1.dat
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\buttondir.txt
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\components.cdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\cursors.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\d_icons_weather.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\default.cdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_categorize.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_comparison.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_favorites.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_Games.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_Hide.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_hsskin.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_jemster.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_Mails.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_new.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_premium.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_reun.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_ringtones.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_searchfor.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_searchgo.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_weather.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\editblbuttons.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\email-t1-bg.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\icons2.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\ie_games_icon.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\ie_video.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\keywords.idx
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\keywords1.dat
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\layout.cdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\linkpathlegal.txt
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\progress.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\s_icons_buttons.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\sales_buttons.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\sdfmodifier.xml
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\t2_bg.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\theweb.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\top7.cdf
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\Top7_theweb.mnu
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\tsd_bg.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\zango_btn.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\1\zango_ie_menu.res
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\progress.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
C:\Documents and Settings\Nelson\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\ymante~1
C:\Program Files\JavaCore
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\network monitor
C:\Program Files\outlook
C:\Program Files\outlook\v.tmp
C:\Program Files\VirusHeat 4.4
C:\Program Files\VirusHeat 4.4\vpp.ini
C:\Temp\1cb
C:\Temp\sanR24
C:\WINDOWS\BMe366517b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\icroso~1
C:\WINDOWS\pskt.ini
C:\WINDOWS\smss.exe
C:\WINDOWS\system32\527631
C:\WINDOWS\system32\afinding.exe
C:\WINDOWS\system32\andt.sys
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\bxdwtauv.ini
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\comsa32.sys
C:\WINDOWS\system32\ddgkaibf.ini
C:\WINDOWS\system32\DelSelf.bat
C:\WINDOWS\system32\demososu.ini
C:\WINDOWS\system32\dhrxjqgm.ini
C:\WINDOWS\system32\drmgs.sys
C:\WINDOWS\system32\gfggh.ini
C:\WINDOWS\system32\gfggh.ini2
C:\WINDOWS\system32\ggjjl.ini
C:\WINDOWS\system32\ggjjl.ini2
C:\WINDOWS\system32\htmjixly.ini
C:\WINDOWS\system32\iDlo01
C:\WINDOWS\system32\iexplorer.dll .dbt
C:\WINDOWS\system32\Indt2.sys
C:\WINDOWS\system32\ipckhcjc.ini
C:\WINDOWS\system32\ivtdnqdm.ini
C:\WINDOWS\system32\jkuyqgcs.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pdxlluui.ini
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\pofkfhwg.ini
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tlterjql.ini
C:\WINDOWS\system32\tlterjql.ini2
C:\WINDOWS\system32\tlterjql.tmp
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\univrs32.dat
C:\WINDOWS\system32\urmprgyt.ini
C:\WINDOWS\system32\uvosgiuj.ini
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\system32\WServing.exe
C:\WINDOWS\system32\ynxdvmqs.ini
C:\WINDOWS\system32\ywphjwxo.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFINDING
-------\Legacy_CMDSERVICE
-------\Legacy_NWSAPAGENT
-------\Legacy_PERFMONS
-------\Legacy_ROUTING
-------\Legacy_WSERVING
-------\Service_AFinding
-------\Service_NwSapAgent
-------\Service_perfmons
-------\Service_Routing
-------\Service_WServing
((((((((((((((((((((((((( Files Created from 2008-05-12 to 2008-06-12 )))))))))))))))))))))))))))))))
.
2008-06-12 02:57 . 2008-06-12 02:57 19,451 --a------ C:\Documents and Settings\Nelson\Application Data\nafegoro.exe
2008-06-12 02:57 . 2008-06-12 02:57 19,121 --a------ C:\Program Files\Common Files\qukoser.com
2008-06-12 02:57 . 2008-06-12 02:57 18,298 --a------ C:\WINDOWS\system32\ixugafytaj.db
2008-06-12 02:57 . 2008-06-12 02:57 16,208 --a------ C:\Program Files\Common Files\hebipuf.dat
2008-06-12 02:57 . 2008-06-12 02:57 16,154 --a------ C:\WINDOWS\dyqaqafago.exe
2008-06-12 02:57 . 2008-06-12 02:57 15,367 --a------ C:\Program Files\Common Files\qapeb.bat
2008-06-12 02:57 . 2008-06-12 02:57 14,441 --a------ C:\WINDOWS\yxic.vbs
2008-06-12 02:57 . 2008-06-12 02:57 14,195 --a------ C:\Documents and Settings\All Users\Application Data\uqojo.bat
2008-06-12 02:57 . 2008-06-12 02:57 14,159 --a------ C:\Program Files\Common Files\ehyqi.com
2008-06-12 02:57 . 2008-06-12 02:57 13,563 --a------ C:\WINDOWS\system32\ejirufocyq.reg
2008-06-12 02:57 . 2008-06-12 02:57 13,162 --a------ C:\WINDOWS\puziminicu.lib
2008-06-12 02:57 . 2008-06-12 02:57 12,710 --a------ C:\Program Files\Common Files\dogepirela.dat
2008-06-12 02:57 . 2008-06-12 02:57 12,709 --a------ C:\WINDOWS\system32\ezemax.bin
2008-06-12 02:57 . 2008-06-12 02:57 12,051 --a------ C:\Program Files\Common Files\azagotitox.dat
2008-06-12 02:57 . 2008-06-12 02:57 11,323 --a------ C:\Program Files\Common Files\uceg.bin
2008-06-12 02:57 . 2008-06-12 02:57 11,201 --a------ C:\Documents and Settings\Nelson\Application Data\razyjazep.dat
2008-06-12 02:57 . 2008-06-12 02:57 10,759 --a------ C:\WINDOWS\avijadyda.bin
2008-06-12 02:57 . 2008-06-12 02:57 10,492 --a------ C:\WINDOWS\system32\utiha.dl
2008-06-10 17:29 . 2008-06-10 17:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-09 19:32 . 2008-06-09 19:32 19,982 --a------ C:\WINDOWS\system32\alimoj.bin
2008-06-09 19:32 . 2008-06-09 19:32 19,324 --a------ C:\Documents and Settings\All Users\Application Data\koligogid.sys
2008-06-09 19:32 . 2008-06-09 19:32 13,963 --a------ C:\Documents and Settings\All Users\Application Data\urebyme.bat
2008-06-09 19:32 . 2008-06-09 19:32 11,384 --a------ C:\Program Files\Common Files\hurure.exe
2008-06-08 14:58 . 2008-06-08 14:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-06-08 01:13 . 2008-06-08 01:13 11,472 --a------ C:\WINDOWS\depafupaxy.bat
2008-06-07 16:51 . 2008-06-07 16:51 19,629 --a------ C:\WINDOWS\ocoq.pif
2008-06-07 16:51 . 2008-06-07 16:51 19,301 --a------ C:\Documents and Settings\Nelson\Application Data\yxubetedo.dll
2008-06-07 16:51 . 2008-06-07 16:51 18,853 --a------ C:\Documents and Settings\Nelson\Application Data\acemyrufu.vbs
2008-06-07 16:51 . 2008-06-07 16:51 18,842 --a------ C:\Documents and Settings\All Users\Application Data\ibiwukuj.dll
2008-06-07 16:51 . 2008-06-07 16:51 15,309 --a------ C:\WINDOWS\kowibajy.bat
2008-06-07 16:51 . 2008-06-07 16:51 13,571 --a------ C:\WINDOWS\ududo.com
2008-06-07 16:51 . 2008-06-07 16:51 13,526 --a------ C:\WINDOWS\system32\atuwitegoc.lib
2008-06-07 16:51 . 2008-06-07 16:51 12,755 --a------ C:\WINDOWS\system32\nawok.inf
2008-06-07 16:51 . 2008-06-07 16:51 12,039 --a------ C:\WINDOWS\ivah.reg
2008-06-07 16:51 . 2008-06-07 16:51 11,560 --a------ C:\WINDOWS\otexyn.db
2008-06-07 16:51 . 2008-06-07 16:51 10,864 --a------ C:\WINDOWS\qybelohajo.pif
2008-06-07 16:51 . 2008-06-07 16:51 10,166 --a------ C:\WINDOWS\ocyjeh.inf
2008-06-07 16:51 . 2008-06-07 16:51 10,036 --a------ C:\Documents and Settings\Nelson\Application Data\onisikugab.bat
2008-06-05 12:26 . 2008-06-05 12:26 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Apple Computer
2008-06-04 01:31 . 2008-06-04 01:31 17,872 --a------ C:\WINDOWS\juzihelebu.dl
2008-06-04 01:31 . 2008-06-04 01:31 17,092 --a------ C:\Program Files\Common Files\akuvax.exe
2008-06-04 01:31 . 2008-06-04 01:31 16,172 --a------ C:\Documents and Settings\Nelson\Application Data\aqod.exe
2008-06-04 01:31 . 2008-06-04 01:31 14,926 --a------ C:\WINDOWS\viwalat._sy
2008-06-04 01:31 . 2008-06-04 01:31 14,849 --a------ C:\WINDOWS\igelasax.scr
2008-06-04 01:31 . 2008-06-04 01:31 14,836 --a------ C:\WINDOWS\aguc.vbs
2008-06-04 01:31 . 2008-06-04 01:31 14,025 --a------ C:\Program Files\Common Files\ketarisytu.bin
2008-06-04 01:31 . 2008-06-04 01:31 13,784 --a------ C:\WINDOWS\yzypaf.lib
2008-06-04 01:31 . 2008-06-04 01:31 12,926 --a------ C:\WINDOWS\emymu.inf
2008-06-04 01:31 . 2008-06-04 01:31 12,907 --a------ C:\Program Files\Common Files\begalof.vbs
2008-06-04 01:31 . 2008-06-04 01:31 12,723 --a------ C:\Documents and Settings\Nelson\Application Data\uvarivyje.exe
2008-06-04 01:31 . 2008-06-04 01:31 12,035 --a------ C:\Documents and Settings\All Users\Application Data\yhijizuxo.bin
2008-06-04 01:31 . 2008-06-04 01:31 11,651 --a------ C:\Documents and Settings\Nelson\Application Data\irekope.dat
2008-06-04 01:31 . 2008-06-04 01:31 11,387 --a------ C:\Documents and Settings\All Users\Application Data\zyhyqonow.com
2008-06-04 01:31 . 2008-06-04 01:31 11,034 --a------ C:\Documents and Settings\Nelson\Application Data\ligeq.scr
2008-06-04 01:29 . 2008-06-04 01:33 <DIR> d-------- C:\Program Files\XPSecurityCenter
2008-05-23 23:05 . 2008-05-23 23:05 17,182 --a------ C:\WINDOWS\system32\tmp1_629381227526.bk
2008-05-23 23:05 . 2008-05-23 23:05 17,182 --a------ C:\WINDOWS\system32\tmp0_422795235185.bk
2008-05-23 23:05 . 2008-05-23 23:05 14,278 --a------ C:\WINDOWS\system32\tmp3_627854819371.bk
2008-05-23 23:05 . 2008-05-23 23:05 14,254 --a------ C:\WINDOWS\system32\tmp4_390692515739.bk
2008-05-23 23:04 . 2008-05-23 23:04 158,000 --a------ C:\WINDOWS\system32\tmp4_715322757392.bk
2008-05-23 23:04 . 2008-05-23 23:04 149,313 --a------ C:\WINDOWS\system32\tmp3_337259498750.bk
2008-05-23 23:03 . 2008-05-23 23:03 153,644 --a------ C:\WINDOWS\system32\tmp4_860614713190.bk
2008-05-23 23:03 . 2008-05-23 23:03 118,819 --a------ C:\WINDOWS\system32\tmp1_182421618388.bk
2008-05-23 23:03 . 2008-05-23 23:03 118,819 --a------ C:\WINDOWS\system32\tmp0_39741992288.bk
2008-05-23 23:02 . 2008-05-23 23:03 149,313 --a------ C:\WINDOWS\system32\tmp3_448527431844.bk
2008-05-23 23:02 . 2008-05-23 23:02 25,891 --a------ C:\WINDOWS\system32\tmp1_85762513686.bk
2008-05-23 23:02 . 2008-05-23 23:02 25,891 --a------ C:\WINDOWS\system32\tmp0_620542584225.bk
2008-05-23 11:34 . 2008-05-23 11:34 155,096 --a------ C:\WINDOWS\system32\tmp4_4398837541.bk
2008-05-23 11:33 . 2008-05-23 11:33 153,644 --a------ C:\WINDOWS\system32\tmp4_585636587632.bk
2008-05-23 11:33 . 2008-05-23 11:33 152,569 --a------ C:\WINDOWS\system32\tmp1_118278307770.bk
2008-05-23 11:33 . 2008-05-23 11:33 152,569 --a------ C:\WINDOWS\system32\tmp0_464603867575.bk
2008-05-23 11:33 . 2008-05-23 11:33 149,313 --a------ C:\WINDOWS\system32\tmp3_836619575341.bk
2008-05-23 11:33 . 2008-05-23 11:33 130,435 --a------ C:\WINDOWS\system32\tmp1_675723577304.bk
2008-05-23 11:33 . 2008-05-23 11:33 130,435 --a------ C:\WINDOWS\system32\tmp0_222390337781.bk
2008-05-23 11:33 . 2008-05-23 11:33 121,725 --a------ C:\WINDOWS\system32\tmp3_178375439274.bk
2008-05-23 00:04 . 2008-05-23 00:05 155,096 --a------ C:\WINDOWS\system32\tmp4_402418862164.bk
2008-05-23 00:04 . 2008-05-23 00:04 130,435 --a------ C:\WINDOWS\system32\tmp1_299601353370.bk
2008-05-23 00:04 . 2008-05-23 00:04 130,435 --a------ C:\WINDOWS\system32\tmp0_40727148678.bk
2008-05-23 00:04 . 2008-05-23 00:04 121,725 --a------ C:\WINDOWS\system32\tmp3_559036645400.bk
2008-05-23 00:03 . 2008-05-23 00:04 153,644 --a------ C:\WINDOWS\system32\tmp4_277536395813.bk
2008-05-23 00:03 . 2008-05-23 00:03 152,569 --a------ C:\WINDOWS\system32\tmp1_794916868319.bk
2008-05-23 00:03 . 2008-05-23 00:03 149,313 --a------ C:\WINDOWS\system32\tmp3_557492786068.bk
2008-05-23 00:02 . 2008-05-23 00:03 152,569 --a------ C:\WINDOWS\system32\tmp0_364634267813.bk
2008-05-22 11:33 . 2008-05-22 11:33 153,644 --a------ C:\WINDOWS\system32\tmp4_701057237097.bk
2008-05-22 11:33 . 2008-05-22 11:33 152,217 --a------ C:\WINDOWS\system32\tmp3_455059372167.bk
2008-05-22 11:32 . 2008-05-22 11:32 158,025 --a------ C:\WINDOWS\system32\tmp3_198705868666.bk
2008-05-22 11:32 . 2008-05-22 11:32 155,096 --a------ C:\WINDOWS\system32\tmp4_330528547415.bk
2008-05-22 11:32 . 2008-05-22 11:32 150,763 --a------ C:\WINDOWS\system32\tmp1_136840430215.bk
2008-05-22 11:32 . 2008-05-22 11:32 126,038 --a------ C:\WINDOWS\system32\tmp0_64473280213.bk
2008-05-22 11:32 . 2008-05-22 11:32 115,915 --a------ C:\WINDOWS\system32\tmp1_151363247351.bk
2008-05-22 11:32 . 2008-05-22 11:32 4,070 --a------ C:\WINDOWS\system32\tmp0_103372654603.bk
2008-05-22 00:05 . 2008-05-22 00:05 153,644 --a------ C:\WINDOWS\system32\tmp4_450552248349.bk
2008-05-22 00:04 . 2008-05-22 00:04 155,096 --a------ C:\WINDOWS\system32\tmp4_37534799659.bk
2008-05-22 00:04 . 2008-05-22 00:05 152,217 --a------ C:\WINDOWS\system32\tmp3_26865129235.bk
2008-05-22 00:04 . 2008-05-22 00:04 115,915 --a------ C:\WINDOWS\system32\tmp1_78987570844.bk
2008-05-22 00:04 . 2008-05-22 00:04 115,915 --a------ C:\WINDOWS\system32\tmp0_335726649258.bk
2008-05-22 00:03 . 2008-05-22 00:04 158,025 --a------ C:\WINDOWS\system32\tmp3_66373332646.bk
2008-05-22 00:03 . 2008-05-22 00:03 150,763 --a------ C:\WINDOWS\system32\tmp1_758098823952.bk
2008-05-22 00:03 . 2008-05-22 00:03 150,763 --a------ C:\WINDOWS\system32\tmp0_650799623984.bk
2008-05-21 11:33 . 2008-05-21 11:34 155,096 --a------ C:\WINDOWS\system32\tmp4_774094482253.bk
2008-05-21 11:33 . 2008-05-21 11:33 153,669 --a------ C:\WINDOWS\system32\tmp3_878556537333.bk
2008-05-21 11:32 . 2008-05-21 11:32 156,548 --a------ C:\WINDOWS\system32\tmp4_782856742233.bk
2008-05-21 11:32 . 2008-05-21 11:32 127,490 --a------ C:\WINDOWS\system32\tmp0_607562203951.bk
2008-05-21 11:32 . 2008-05-21 11:33 117,367 --a------ C:\WINDOWS\system32\tmp1_568977684927.bk
2008-05-21 11:31 . 2008-05-21 11:31 153,669 --a------ C:\WINDOWS\system32\tmp3_422934586249.bk
2008-05-21 11:31 . 2008-05-21 11:31 137,695 --a------ C:\WINDOWS\system32\tmp1_418856228568.bk
2008-05-21 11:31 . 2008-05-21 11:31 8,426 --a------ C:\WINDOWS\system32\tmp0_497670854858.bk
2008-05-21 00:02 . 2008-05-21 00:02 157,412 --a------ C:\WINDOWS\system32\tmp4_510079731537.bk
2008-05-21 00:02 . 2008-05-21 00:02 153,057 --a------ C:\WINDOWS\system32\tmp3_10739511477.bk
2008-05-21 00:02 . 2008-05-21 00:03 150,112 --a------ C:\WINDOWS\system32\tmp4_647424494318.bk
2008-05-21 00:02 . 2008-05-21 00:02 147,217 --a------ C:\WINDOWS\system32\tmp3_806921361815.bk
2008-05-21 00:02 . 2008-05-21 00:02 118,015 --a------ C:\WINDOWS\system32\tmp1_584267121383.bk
2008-05-21 00:02 . 2008-05-21 00:02 118,015 --a------ C:\WINDOWS\system32\tmp0_166800661919.bk
2008-05-21 00:01 . 2008-05-21 00:01 4,135 --a------ C:\WINDOWS\system32\tmp1_399093781974.bk
2008-05-21 00:01 . 2008-05-21 00:01 4,135 --a------ C:\WINDOWS\system32\tmp0_34462790455.bk
2008-05-20 15:43 . 2008-05-20 15:43 147,836 --a------ C:\WINDOWS\system32\tmp4_447067576852.bk
2008-05-20 15:43 . 2008-05-20 15:43 113,013 --a------ C:\WINDOWS\system32\tmp3_157281729542.bk
2008-05-20 15:43 . 2008-05-20 15:43 111,559 --a------ C:\WINDOWS\system32\tmp1_157437139152.bk
2008-05-20 15:43 . 2008-05-20 15:43 111,559 --a------ C:\WINDOWS\system32\tmp0_890047128728.bk
2008-05-20 15:42 . 2008-05-20 15:43 150,740 --a------ C:\WINDOWS\system32\tmp4_111595743688.bk
2008-05-20 15:42 . 2008-05-20 15:42 146,409 --a------ C:\WINDOWS\system32\tmp3_172578787717.bk
2008-05-20 15:42 . 2008-05-20 15:42 25,891 --a------ C:\WINDOWS\system32\tmp1_49237547327.bk
2008-05-20 15:42 . 2008-05-20 15:42 25,891 --a------ C:\WINDOWS\system32\tmp0_118477752991.bk
2008-05-20 04:13 . 2008-05-20 04:13 142,053 --a------ C:\WINDOWS\system32\tmp3_666623542542.bk
2008-05-20 04:13 . 2008-05-20 04:13 115,915 --a------ C:\WINDOWS\system32\tmp1_803452895611.bk
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 06:23 19,204,896 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-12 06:23 --------- d-----w C:\Program Files\Incomplete
2008-06-12 06:22 --------- d-----w C:\Documents and Settings\Nelson\Application Data\LimeWire
2008-06-12 06:20 --------- d-----w C:\Program Files\LimeWire
2008-06-12 06:18 526,112 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-12 06:18 33,620 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-12 06:18 258,140 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-12 05:57 12,514 ----a-w C:\Program Files\Common Files\vylopyxyka._sy
2008-06-09 22:32 19,166 ----a-w C:\WINDOWS\afut.vbs
2008-06-09 22:32 17,632 ----a-w C:\WINDOWS\belixo.dll
2008-06-09 22:32 16,579 ----a-w C:\WINDOWS\system32\ijikuxir.exe
2008-06-09 22:32 13,536 ----a-w C:\WINDOWS\ojis.scr
2008-06-09 22:32 13,196 ----a-w C:\WINDOWS\mydi.dll
2008-06-09 22:32 12,974 ----a-w C:\WINDOWS\system32\quvegery.bat
2008-06-09 22:32 12,718 ----a-w C:\WINDOWS\peqaq.dll
2008-06-09 22:32 11,981 ----a-w C:\WINDOWS\ytyje.reg
2008-06-09 22:32 10,446 ----a-w C:\WINDOWS\system32\imyxopeku.bin
2008-06-09 22:32 10,271 ----a-w C:\WINDOWS\system32\xozisuquv.exe
2008-06-08 17:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-08 17:59 --------- d-----w C:\Program Files\USBToolbox
2008-06-07 19:51 15,341 ----a-w C:\Program Files\Common Files\yfaci.inf
2008-06-07 19:51 13,773 ----a-w C:\Program Files\Common Files\yfeluk.db
2008-06-07 17:15 --------- d-----w C:\Program Files\Google
2008-06-04 04:31 19,111 ----a-w C:\Program Files\Common Files\adinijo._dl
2008-06-04 04:31 17,593 ----a-w C:\Program Files\Common Files\litan.inf
2008-05-09 21:29 --------- d-----w C:\Documents and Settings\Nelson\Application Data\Apple Computer
2008-05-09 15:11 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
2008-05-05 09:30 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-05-05 08:23 --------- d-----w C:\Program Files\DivX
2008-05-05 04:59 --------- d-----w C:\Documents and Settings\Nelson\Application Data\AVGTOOLBAR
2008-05-05 02:04 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-05 02:00 --------- d-----w C:\Program Files\AVG
2008-04-29 01:12 22 ----a-w C:\Documents and Settings\Nelson\xrt_collect.zip
2008-04-28 15:52 1,189 ----a-w C:\Documents and Settings\Nelson\xrt_log.dat
2008-04-15 21:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-04-15 21:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-27 01:18 49,152 ----a-r C:\WINDOWS\system32\inetwh32.dll
2008-03-27 01:18 1,044,480 ----a-r C:\WINDOWS\system32\roboex32.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-15 22:38 687,592 ----a-w C:\WINDOWS\system32\atmtd.dll
2005-07-30 00:24 472 --sha-r C:\WINDOWS\TmVsc29uIEtoYW4\nApPwZ6RKHQCsqb.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{51D81DD5-55B7-497F-95DB-D356429BB54E}"= "C:\Program Files\NetProject\wamdl.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{51d81dd5-55b7-497f-95db-d356429bb54e}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{51D81DD5-55B7-497F-95DB-D356429BB54E}"= C:\Program Files\NetProject\wamdl.dll [ ]
[HKEY_CLASSES_ROOT\clsid\{51d81dd5-55b7-497f-95db-d356429bb54e}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 18:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-02 15:30 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 20:48 528384]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 20:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 20:30 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 04:13 385024]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 08:42 144784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 18:10 267048]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"e05562e7"="C:\WINDOWS\system32\vuatwdxb.dll" [ ]
"BMe366517b"="C:\WINDOWS\system32\cmnduvkf.dll" [ ]
"XP SecurityCenter"="C:\Program Files\XPSecurityCenter\xpsecuritycenter.exe" [2008-05-26 22:37 524548]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
C:\Documents and Settings\Nelson\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-02-08 18:32:57 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 01:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-08 00:02:56 113664]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520]
Wireless Configuration Utility.lnk - C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\OEM\WlanCU.exe [2003-08-08 16:24:02 425984]
Wireless PCI_CardBus utility V1.01.exe.lnk - C:\Program Files\Customer\Wireless PCI_CardBus utility V1.01\Wireless PCI_CardBus utility V1.01.exe [2008-03-12 18:40:06 913408]
Wireless USB utility V1.01.exe.lnk - C:\Program Files\Customer\Wireless USB utility V1.01\Wireless USB utility V1.01.exe [2008-03-12 18:44:17 913408]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{4d51e91c-e917-4b7f-89ff-abe471e16927}"= C:\WINDOWS\system32\uyhjw.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxxvvs]
cbxxvvs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
S3 qcmdmxp;HTC Proprietary USB Driver (PID 0B03);C:\WINDOWS\system32\DRIVERS\qcmdmxp.sys [2006-12-27 08:38]
S3 qcserxp;HTC Diagnostic Port (PID 0B03);C:\WINDOWS\system32\DRIVERS\qcserxp.sys [2006-12-27 08:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
"2008-06-12 06:17:51 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-12 03:20:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-06-12 3:25:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-12 06:25:26
Pre-Run: 17,340,928,000 bytes free
Post-Run: 20,327,645,184 bytes free
598