c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\upgrades\upmeal.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\upgrades\upwaitress.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\audrey.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\audrey.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\cake4.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\cake4.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\cake6.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\cake6.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\ira.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\ira.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\planner_bg.jpg
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\planning_end_note.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\points_heart.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\small_PLANNER_Flowers01.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\small_PLANNER_Flowers02.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\small_PLANNER_Flowers03.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\small_PLANNER_Flowers07.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upaudrey.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upcake4.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upcake6.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upflowers1.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upflowers2.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upflowers3.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upflowers7.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\uphoneymoon1.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\uphoneymoon2.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\uphoneymoon3.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\uphoneymoon4.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upira.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upquiche.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_Asparagus.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_Chicken.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_CrackersAndCheese.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_Fish.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_Shrimp.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\upWD_Planner_Steakl.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\wp_down.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\images\Wedding Panning\wp_over.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\resources.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\arcade1.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\basicSetting.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\closeconfirm.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\game1.1.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\game1.2.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\game1.3.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\game1.4.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\game1.5.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\gametrust_connectdialog.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\helpmenu1.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\helpmenu2.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\hiscore.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\hiscoreinfo.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\hiscoresubmit.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\LevelDefines.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\LevelDialogGenerator.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\LevelManager.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\luaDebug.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\mainloop.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\ok.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\pause.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\pausemenu.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\planning_tutorial.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\privacy.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\quitdialog.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\selection1.1.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\selection1.2.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\selection1.3.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\selection1.4.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\selection1.5.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\SelectionDefines.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\SelectionDialogGenerator.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\selection scripts\SelectionManager.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\style.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\upgrade1.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\upgrades.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\upsell.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\upsellfinal.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\userdata.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\scripts\yesno.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\settings.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\splash\aol_web_logo.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\splash\IE_fullcolor.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\splash\playfirst_logo.jpg
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\splash\Thumbs.db
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\strings.xml
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\ui_scripts\common\coordinates.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\ui_scripts\common\style.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\ui_scripts\screens\main_menu_scrn.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\upsell\logo.png
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\upsell\upsell_img_1.jpg
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\upsell\upsell_img_2.jpg
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\upsell\upsell_img_3.jpg
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\assets\xsellstyle.lua
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\bin\bin2c
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\bin\luac
c:\windows\Downloaded Program Files\WeddingDash.1.0.0.50\weddingdashlongnamenospace.exe
c:\windows\system32\kill.exe
c:\windows\tempf.txt
c:\windows\viassary-hp.reg
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-11-20 to 2010-12-20 )))))))))))))))))))))))))))))))
.
2010-12-18 18:35 . 2010-11-29 21:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-18 18:35 . 2010-12-18 18:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-12-18 18:35 . 2010-12-18 18:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-18 18:35 . 2010-11-29 21:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-10 06:11 . 2010-12-10 06:11 398744 ----a-r- c:\windows\system32\cpnprt2.cid
2010-12-07 13:02 . 2007-11-05 23:06 278016 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-12-07 13:02 . 2007-11-05 23:07 118272 ----a-w- c:\windows\system32\hpz3l5mu.dll
2010-12-07 12:33 . 2007-01-17 08:37 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
2010-12-07 12:33 . 2007-01-17 08:37 49920 ----a-w- c:\windows\system32\drivers\HPZid412.sys
2010-12-07 12:33 . 2007-11-06 18:10 271704 ----a-w- c:\windows\system32\hpzids01.dll
2010-12-07 12:33 . 2007-10-31 02:35 729088 ----a-w- c:\windows\system32\hpwwiax4.dll
2010-12-07 12:33 . 2007-10-31 02:35 593920 ----a-w- c:\windows\system32\hpwtscl3.dll
2010-12-07 12:33 . 2007-01-17 08:37 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-12-07 12:33 . 2007-01-17 08:37 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-12-07 12:33 . 2007-01-17 08:31 294912 ----a-w- c:\windows\system32\hpovst11.dll
2010-12-05 17:18 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-05 17:18 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-05 17:18 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-05 17:18 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-05 17:18 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-05 17:18 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-05 17:18 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-05 17:18 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-05 17:18 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-05 16:54 . 2010-12-05 16:54 -------- d-----w- c:\program files\Conduit
2010-12-05 16:54 . 2010-12-05 16:54 -------- d-----w- c:\program files\ZoneAlarm_Security
2010-12-05 16:54 . 2010-12-05 16:54 -------- d-----w- c:\program files\CheckPoint
2010-12-05 16:54 . 2010-09-02 13:20 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-12-05 16:54 . 2010-09-02 13:20 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-12-05 16:54 . 2010-09-02 13:20 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-12-05 16:54 . 2010-12-05 16:55 -------- d-----w- c:\windows\system32\ZoneLabs
2010-12-04 00:07 . 2010-12-04 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-28 03:56 . 2010-11-28 03:56 -------- d-----w- c:\windows\system32\LogFiles
2010-11-23 15:20 . 2009-08-06 23:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-11-23 15:20 . 2009-08-06 23:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-11-22 15:49 . 2004-08-04 02:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-11-22 03:39 . 2010-11-22 03:39 -------- d-----w- c:\program files\WorksBkup
2010-11-22 03:24 . 2004-08-04 03:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-11-22 03:23 . 2004-08-04 03:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-11-22 01:54 . 2010-11-22 01:54 -------- d-----w- c:\program files\JRE
2010-11-22 01:54 . 2010-11-22 01:54 -------- d-----w- c:\program files\OpenOffice.org 3
2010-11-22 01:25 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-11-22 01:05 . 2010-11-22 01:05 -------- d-----w- c:\program files\Shop to Win 9
2010-11-22 01:04 . 2010-11-22 01:04 -------- d-----w- c:\program files\PriceGong
2010-11-21 23:06 . 2010-11-21 23:08 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-11-21 23:03 . 2010-12-07 12:33 -------- dc----w- c:\windows\system32\DRVSTORE
2010-11-21 22:50 . 2010-11-23 15:44 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-11-21 08:47 . 2008-07-09 07:38 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-11-21 08:35 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-11-21 08:34 . 2010-11-21 08:34 -------- d-----w- c:\windows\system32\Lang
2010-11-21 08:34 . 2004-11-02 15:58 163840 ----a-w- c:\windows\system32\igfxres.dll
2010-11-21 08:33 . 2004-08-04 11:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-11-21 08:32 . 2010-12-20 16:56 -------- d-----w- c:\documents and settings\HP_Owner.SEVILLA
2010-11-21 08:31 . 2002-01-04 15:15 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-11-21 08:30 . 2010-11-21 08:30 -------- d-----w- c:\windows\system32\RTCOM
2010-11-21 05:09 . 2010-12-05 16:45 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-07 16:23 . 2010-10-07 16:23 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-10-07 16:23 . 2010-10-07 16:23 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-10-07 16:23 . 2010-10-07 16:23 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-10-07 16:23 . 2010-10-07 16:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-09-30 19:35 . 2005-11-03 23:12 73728 ----a-w- c:\windows\ALCFDRTM.VER
2006-12-05 01:30 . 2006-12-05 01:31 774144 ----a-w- c:\program files\RngInterstitial.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2002-01-04 15:09 . 2004-10-14 21:54 253952 c:\hp\drivers\hplsbwatcher\bak\lsburnwatcher.exe
2002-01-04 15:09 . 2004-10-14 21:54 253952 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
2003-05-08 16:00 . 2003-05-08 16:00 49152 c:\program files\bak\OpwareSE2.exe
2005-11-03 03:01 . 2005-11-03 03:01 50792 c:\program files\Common Files\AOL\1147752597\ee\bak\AOLSoftware.exe
2005-11-30 15:40 . 2005-11-30 15:40 136808 c:\program files\Common Files\AOL\1147752597\ee\services\sscFirewallPlugin\ver1_10_3_1\bak\SSCRun.exe
2002-01-04 15:07 . 2002-01-04 15:07 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
2002-01-04 15:07 . 2002-01-04 15:07 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
2004-06-07 18:53 . 2004-06-07 18:53 49152 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\bak\hphupd06.exe
2004-06-07 18:53 . 2004-06-07 18:53 49152 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
2006-06-14 20:24 . 2006-06-14 20:24 278528 c:\program files\iTunes\bak\iTunesHelper.exe
2010-11-18 00:59 . 2010-11-18 00:59 421160 c:\program files\iTunes\iTunesHelper.exe
2002-01-04 14:45 . 2002-01-04 14:45 32881 c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
2002-01-04 14:45 . 2002-01-04 14:45 32881 c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
2006-05-23 20:32 . 2005-11-04 21:49 988712 c:\program files\mcafee.com\personal firewall\bak\MPfTray.exe
2002-01-04 15:15 . 2006-05-17 22:04 282624 c:\program files\QuickTime\bak\qttask.exe
2010-09-08 15:17 . 2010-09-08 15:17 421888 c:\program files\QuickTime\QTTask.exe
2006-05-28 02:27 . 2004-11-11 04:15 111816 c:\program files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe
2004-04-14 20:43 . 2004-04-14 20:43 233472 c:\windows\SMINST\bak\RECGUARD.EXE
2004-04-14 20:43 . 2004-04-14 20:43 233472 c:\windows\SMINST\Recguard.exe
2002-01-04 14:48 . 1998-05-07 16:04 52736 c:\windows\system\bak\hpsysdrv.exe
2002-01-04 14:48 . 1998-05-07 16:04 52736 c:\windows\system\hpsysdrv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0095C290-A428-4BDD-B98C-E0A116F1C702}]
2010-11-22 01:05 647168 ----a-w- c:\program files\Shop to Win 9\ShoppingBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}]
2010-03-28 19:47 353656 ----a-w- c:\program files\PriceGong\2.1.0\PriceGongIE.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2010-12-01 15:27 2735200 ----a-w- c:\program files\ZoneAlarm_Security\tbZone.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2002-01-04 32881]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-18 61952]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2002-01-04 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"SoundMan"="SOUNDMAN.EXE" [2004-10-13 77824]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-13 2742272]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-18 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-09-02 738808]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
c:\documents and settings\Aracely\Start Menu\Programs\Startup\
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2002-1-4 36864]
c:\documents and settings\HP_Owner.SEVILLA\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0a\aoltray.exe [2009-4-17 156784]
Auto Detect.lnk - c:\program files\iConcepts Music Express\MEAutoDetect.exe [2008-9-21 374104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
SpySubtract.lnk - c:\program files\InterMute\SpySubtract\sslaunch.exe [2002-1-4 73728]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2002-1-4 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/5/2010 1:18 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/5/2010 1:18 PM 17744]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [9/2/2010 8:26 AM 26872]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [9/2/2010 8:26 AM 493048]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/3/2010 8:08 PM 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-11-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
2010-11-21 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 16:50]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-04 00:07]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-04 00:07]
2010-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3336513925-2205304878-719255350-1009Core1cac6718a1f0bd8.job
- c:\documents and settings\HP_Owner.SEVILLAHOME\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-01 22:48]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3336513925-2205304878-719255350-1009UA.job
- c:\documents and settings\HP_Owner.SEVILLAHOME\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-01 22:48]
2010-12-20 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2009-03-26 10:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: Add To HP Organize... - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
TCP: {0ECC7E3F-0561-49F6-91DD-645E548FFE70} = 167.206.245.130,167.206.245.129
FF - ProfilePath - c:\documents and settings\HP_Owner.SEVILLA\Application Data\Mozilla\Firefox\Profiles\7jew4l4q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?ilc=1
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
FF - Ext: ZoneAlarm Security Engine: {FFB96CC1-7EB3-449D-B827-DB661701C6BB} - c:\program files\CheckPoint\ZAForceField\TrustChecker
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-20 13:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(600)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(656)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'explorer.exe'(1884)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\AGRSMMSG.exe
c:\windows\SOUNDMAN.EXE
c:\windows\ALCWZRD.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\InterMute\SpySubtract\SpySub.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2010-12-20 13:37:20 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-20 17:36
Pre-Run: 111,425,753,088 bytes free
Post-Run: 111,628,419,072 bytes free
- - End Of File - - 59E239A176E7975F143BA1AAB27DC077