1. Combofix log:
ComboFix 10-08-21.04 - GAL 08/22/2010 0:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.440 [GMT -4:00]
Running from: c:\program files\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\GAL\Application Data\PriceGong
c:\documents and settings\GAL\Application Data\PriceGong\Data\1.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\a.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\b.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\c.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\d.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\e.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\f.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\g.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\h.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\i.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\J.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\k.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\l.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\m.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\n.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\o.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\p.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\q.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\r.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\s.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\t.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\u.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\v.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\w.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\x.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\y.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\z.xml
C:\install.exe
.
---- Previous Run -------
.
c:\docume~1\GAL\LOCALS~1\Temp\NewsFeed[21].dll
c:\documents and settings\GAL\Application Data\PriceGong\Data\1.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\a.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\b.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\c.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\d.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\e.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\f.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\g.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\h.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\i.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\J.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\k.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\l.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\m.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\n.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\o.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\p.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\q.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\r.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\s.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\t.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\u.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\v.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\w.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\x.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\y.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\z.xml
c:\documents and settings\GAL\Local Settings\Temp\NewsFeed[21].dll
.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-22 04:17 . 2010-08-22 04:18 3820648 ----a-r- c:\program files\ComboFix.exe
2010-08-18 15:19 . 2010-08-18 15:19 340456 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-18 15:19 . 2010-08-18 15:19 170512 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 15:19 . 2010-08-18 15:19 170584 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 15:19 . 2010-08-18 15:19 340520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-17 15:00 . 2010-08-19 00:28 -------- d-----w- C:\HTC
2010-08-14 13:17 . 2010-08-14 13:17 192776 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-11 02:53 . 2010-08-11 03:00 102135128 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Extractor.exe
2010-08-09 23:51 . 2010-08-09 23:51 -------- d-----w- c:\windows\system32\wbem\Repository
2010-08-09 23:31 . 2010-08-09 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\RegTask
2010-08-09 23:30 . 2010-08-09 23:51 -------- d-----w- c:\program files\RegTask
2010-08-09 23:20 . 2010-08-09 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic(2)
2010-08-09 23:20 . 2010-08-09 23:51 -------- d-----w- c:\program files\Common Files\ParetoLogic(2)
2010-08-09 22:42 . 2010-08-09 22:46 -------- d-----w- c:\documents and settings\All Users\Application Data\FileCure
2010-08-09 22:42 . 2010-08-09 22:42 -------- d-----w- c:\program files\ParetoLogic
2010-08-08 15:31 . 2010-08-08 15:31 -------- d-----w- c:\program files\CCleaner
2010-08-08 15:26 . 2010-08-08 15:26 -------- d-----w- c:\program files\Defraggler
2010-08-07 21:39 . 2010-08-07 21:39 10827096 ----a-w- c:\program files\BlackBerryMediaSync.exe
2010-08-06 13:05 . 2010-08-06 13:05 388096 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-06 13:04 . 2010-08-06 13:04 -------- d-----w- c:\program files\Trend Micro
2010-08-06 13:04 . 2010-08-06 13:04 1402880 ----a-w- c:\program files\HiJackThis.msi
2010-08-04 11:40 . 2010-08-04 11:40 503808 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\msvcp71.dll
2010-08-04 11:40 . 2010-08-04 11:40 499712 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\jmc.dll
2010-08-04 11:40 . 2010-08-04 11:40 348160 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\msvcr71.dll
2010-08-04 11:40 . 2010-08-04 11:40 61440 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-35418798-n\decora-sse.dll
2010-08-04 11:40 . 2010-08-04 11:40 12800 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-35418798-n\decora-d3d.dll
2010-08-04 01:38 . 2010-08-04 01:38 1821192 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\vcredist_x86.exe
2010-08-04 01:38 . 2010-08-04 01:38 400728 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\BBDesktopInstaller.exe
2010-08-04 01:38 . 2010-08-04 01:38 2959376 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\dotnetfx35setup.exe
2010-08-04 01:38 . 2010-08-04 01:38 128472 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Helper.exe
2010-08-03 20:04 . 2010-08-09 23:57 256 ----a-w- c:\documents and settings\GAL\pool.bin
2010-08-02 20:59 . 2010-08-02 21:00 -------- d-----w- c:\program files\RapidShareManager
2010-08-02 20:59 . 2010-08-02 20:59 3238968 ----a-w- c:\program files\RapidShareManager2WindowsSetup.exe
2010-08-01 13:31 . 2010-08-01 13:31 53248 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{3360D505-B0AA-4284-92DF-F872AF90A448}\ARPPRODUCTICON.exe
2010-07-31 23:10 . 2010-07-31 23:10 711168 ----a-w- c:\documents and settings\GAL\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv307hw-1007080-0-main.dll
2010-07-30 03:04 . 2010-07-30 03:04 2224872 ----a-w- c:\program files\GoogleToolbarInstaller_en32_signed.exe
2010-07-30 03:03 . 2010-07-30 03:03 519960 ----a-w- c:\program files\Mats_Run.IEAddon.exe
2010-07-30 02:53 . 2010-07-30 02:53 -------- d-----w- c:\documents and settings\GAL\Application Data\ElevatedDiagnostics
2010-07-27 13:43 . 2010-07-27 13:43 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-24 12:03 . 2010-07-24 12:03 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 04:36 . 2010-05-10 23:04 -------- d-----w- c:\documents and settings\GAL\Application Data\Skype
2010-08-22 04:02 . 2010-05-10 23:05 -------- d-----w- c:\documents and settings\GAL\Application Data\skypePM
2010-08-20 04:31 . 2010-05-11 16:05 -------- d-----w- c:\program files\lx_cats
2010-08-18 23:52 . 2010-05-12 01:28 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-08-17 04:22 . 2010-06-29 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-08-12 15:10 . 2010-06-28 02:22 -------- d-----w- c:\documents and settings\GAL\Application Data\Research In Motion
2010-08-11 07:44 . 2009-04-15 14:01 -------- d-----w- c:\program files\Microsoft Works
2010-08-11 03:14 . 2010-06-30 23:48 -------- d-----w- c:\program files\Common Files\Research In Motion
2010-08-11 03:12 . 2010-06-28 00:44 -------- d-----w- c:\program files\Research In Motion
2010-08-11 03:12 . 2010-07-01 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Research In Motion
2010-08-08 13:00 . 2010-06-28 02:23 256 ----a-w- c:\windows\system32\pool.bin
2010-08-03 16:02 . 2010-07-14 20:38 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-07-30 03:06 . 2009-04-15 14:05 -------- d-----w- c:\program files\Google
2010-07-30 00:04 . 2010-07-30 00:04 32173810 ----a-w- c:\documents and settings\All Users\SPL241.tmp
2010-07-29 15:05 . 2010-06-29 21:03 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 15:05 . 2010-06-29 21:03 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-22 18:31 . 2010-07-22 18:31 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2010-07-22 18:16 . 2010-05-12 04:16 -------- d-----w- c:\program files\trademanager
2010-07-21 22:59 . 2010-07-21 22:54 2605008 ----a-w- c:\documents and settings\GAL\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-07-20 00:00 . 2010-07-20 00:00 -------- d-----w- c:\program files\TranslatorBar_1
2010-07-20 00:00 . 2010-07-20 00:00 -------- d-----w- c:\program files\Conduit
2010-07-14 20:40 . 2010-07-14 20:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2010-07-14 20:39 . 2010-07-14 20:30 -------- d-----w- c:\documents and settings\GAL\Application Data\Logitech
2010-07-14 20:39 . 2010-07-14 20:39 -------- d-----w- c:\documents and settings\GAL\Application Data\Leadertech
2010-07-14 20:39 . 2010-07-14 20:39 53248 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-07-14 20:39 . 2010-07-14 20:31 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-07-14 20:38 . 2010-07-14 20:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-07-14 20:34 . 2010-07-14 20:33 -------- d-----w- c:\program files\Logitech
2010-07-14 20:31 . 2010-07-14 20:30 -------- d-----w- c:\documents and settings\GAL\Application Data\Logishrd
2010-07-14 20:30 . 2010-07-14 20:30 23242528 ----a-w- c:\program files\setpoint610.exe
2010-07-09 02:46 . 2010-07-08 19:47 -------- d-----w- c:\documents and settings\All Users\Application Data\inFlow Inventory
2010-07-09 02:02 . 2010-05-10 23:35 -------- d-----w- c:\program files\Microsoft SQL Server
2010-07-09 01:58 . 2010-05-10 23:26 -------- d-----w- c:\program files\Microsoft.NET
2010-07-09 01:29 . 2010-07-09 01:29 32768 ----a-w- c:\documents and settings\GAL\.exe
2010-07-01 04:04 . 2010-07-01 04:04 -------- d-----w- c:\documents and settings\GAL\Application Data\Blackberry Desktop
2010-06-30 12:31 . 2009-04-15 05:42 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-29 21:31 . 2010-06-29 21:31 109072 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2010-06-29 21:31 . 2010-06-29 21:31 133720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-29 21:31 . 2010-06-29 21:31 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-06-29 21:31 . 2010-06-29 21:31 315408 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\5.1\klif.sys
2010-06-29 20:57 . 2010-06-29 20:57 -------- d-----w- c:\program files\Kaspersky Lab
2010-06-29 20:51 . 2009-04-15 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-06-29 20:48 . 2010-05-10 19:17 -------- d-----w- c:\program files\Symantec
2010-06-29 20:41 . 2010-06-29 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\DesktopMgr.exe
2010-06-24 12:22 . 2009-04-15 05:42 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2009-04-15 05:42 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2009-04-15 05:42 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2009-04-15 05:42 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-04-15 01:56 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2009-04-15 05:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-12 04:17 . 2010-05-10 19:12 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-06-12 04:17 . 2010-06-12 04:18 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{22249312-26C2-492E-B0B5-E73EFF2939D8}\PostBuild.exe
2010-06-10 21:00 . 2010-06-10 21:00 503808 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\msvcp71.dll
2010-06-10 21:00 . 2010-06-10 21:00 499712 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\jmc.dll
2010-06-10 21:00 . 2010-06-10 21:00 348160 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\msvcr71.dll
2010-06-10 21:00 . 2010-06-10 21:00 61440 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35d2b6a0-n\decora-sse.dll
2010-06-10 21:00 . 2010-06-10 21:00 12800 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35d2b6a0-n\decora-d3d.dll
2010-06-10 20:59 . 2010-06-10 21:00 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-07 12:57 . 2010-06-07 12:57 76712 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-06-01 19:00 . 2010-06-01 19:00 3584 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-05-31 03:15 . 2010-05-10 19:06 92344 ----a-w- c:\documents and settings\GAL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-29 16:14 . 2010-05-13 23:44 298 ----a-w- c:\documents and settings\GAL\Application Data\wklnhst.dat
2010-05-14 02:30 . 2010-05-14 02:29 1364522 ----a-w- c:\program files\wrar393.exe
2010-05-13 22:57 . 2010-05-13 22:57 12894680 ----a-w- c:\program files\word2007-kb974631-fullfile-x86-glb.exe
2010-05-13 13:12 . 2010-05-13 13:12 5835264 ----a-w- c:\program files\MAXEN_eMule0.50a-Installer.exe
2010-05-12 04:15 . 2010-05-12 04:15 16777272 ----a-w- c:\program files\AliIM2010_TradeManager(6.18.30).exe
2010-05-12 01:28 . 2010-05-12 01:28 7886336 ----a-w- c:\program files\setup.msi
2010-05-11 23:45 . 2010-05-11 23:45 5520400 ----a-w- c:\program files\WindowsSearch-KB940157-XP-x86-enu.exe
2010-05-10 23:43 . 2010-05-10 23:43 12383736 ----a-w- c:\program files\picasa36-setup.exe
2010-05-10 23:02 . 2010-05-10 23:02 1704744 ----a-w- c:\program files\SkypeSetup.exe
2006-04-06 21:29 . 2010-05-11 15:15 3275752 ----a-w- c:\program files\Babylon50_Setup.exe
.
ComboFix 10-08-21.04 - GAL 08/22/2010 0:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.440 [GMT -4:00]
Running from: c:\program files\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\GAL\Application Data\PriceGong
c:\documents and settings\GAL\Application Data\PriceGong\Data\1.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\a.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\b.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\c.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\d.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\e.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\f.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\g.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\h.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\i.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\J.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\k.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\l.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\m.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\n.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\o.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\p.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\q.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\r.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\s.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\t.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\u.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\v.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\w.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\x.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\y.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\z.xml
C:\install.exe
.
---- Previous Run -------
.
c:\docume~1\GAL\LOCALS~1\Temp\NewsFeed[21].dll
c:\documents and settings\GAL\Application Data\PriceGong\Data\1.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\a.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\b.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\c.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\d.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\e.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\f.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\g.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\h.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\i.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\J.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\k.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\l.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\m.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\n.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\o.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\p.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\q.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\r.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\s.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\t.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\u.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\v.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\w.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\x.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\y.xml
c:\documents and settings\GAL\Application Data\PriceGong\Data\z.xml
c:\documents and settings\GAL\Local Settings\Temp\NewsFeed[21].dll
.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-22 04:17 . 2010-08-22 04:18 3820648 ----a-r- c:\program files\ComboFix.exe
2010-08-18 15:19 . 2010-08-18 15:19 340456 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-18 15:19 . 2010-08-18 15:19 170512 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 15:19 . 2010-08-18 15:19 170584 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 15:19 . 2010-08-18 15:19 340520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-17 15:00 . 2010-08-19 00:28 -------- d-----w- C:\HTC
2010-08-14 13:17 . 2010-08-14 13:17 192776 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-11 02:53 . 2010-08-11 03:00 102135128 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Extractor.exe
2010-08-09 23:51 . 2010-08-09 23:51 -------- d-----w- c:\windows\system32\wbem\Repository
2010-08-09 23:31 . 2010-08-09 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\RegTask
2010-08-09 23:30 . 2010-08-09 23:51 -------- d-----w- c:\program files\RegTask
2010-08-09 23:20 . 2010-08-09 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic(2)
2010-08-09 23:20 . 2010-08-09 23:51 -------- d-----w- c:\program files\Common Files\ParetoLogic(2)
2010-08-09 22:42 . 2010-08-09 22:46 -------- d-----w- c:\documents and settings\All Users\Application Data\FileCure
2010-08-09 22:42 . 2010-08-09 22:42 -------- d-----w- c:\program files\ParetoLogic
2010-08-08 15:31 . 2010-08-08 15:31 -------- d-----w- c:\program files\CCleaner
2010-08-08 15:26 . 2010-08-08 15:26 -------- d-----w- c:\program files\Defraggler
2010-08-07 21:39 . 2010-08-07 21:39 10827096 ----a-w- c:\program files\BlackBerryMediaSync.exe
2010-08-06 13:05 . 2010-08-06 13:05 388096 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-06 13:04 . 2010-08-06 13:04 -------- d-----w- c:\program files\Trend Micro
2010-08-06 13:04 . 2010-08-06 13:04 1402880 ----a-w- c:\program files\HiJackThis.msi
2010-08-04 11:40 . 2010-08-04 11:40 503808 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\msvcp71.dll
2010-08-04 11:40 . 2010-08-04 11:40 499712 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\jmc.dll
2010-08-04 11:40 . 2010-08-04 11:40 348160 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-79298873-n\msvcr71.dll
2010-08-04 11:40 . 2010-08-04 11:40 61440 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-35418798-n\decora-sse.dll
2010-08-04 11:40 . 2010-08-04 11:40 12800 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-35418798-n\decora-d3d.dll
2010-08-04 01:38 . 2010-08-04 01:38 1821192 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\vcredist_x86.exe
2010-08-04 01:38 . 2010-08-04 01:38 400728 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\BBDesktopInstaller.exe
2010-08-04 01:38 . 2010-08-04 01:38 2959376 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\dotnetfx35setup.exe
2010-08-04 01:38 . 2010-08-04 01:38 128472 ----a-w- c:\documents and settings\GAL\Application Data\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Helper.exe
2010-08-03 20:04 . 2010-08-09 23:57 256 ----a-w- c:\documents and settings\GAL\pool.bin
2010-08-02 20:59 . 2010-08-02 21:00 -------- d-----w- c:\program files\RapidShareManager
2010-08-02 20:59 . 2010-08-02 20:59 3238968 ----a-w- c:\program files\RapidShareManager2WindowsSetup.exe
2010-08-01 13:31 . 2010-08-01 13:31 53248 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{3360D505-B0AA-4284-92DF-F872AF90A448}\ARPPRODUCTICON.exe
2010-07-31 23:10 . 2010-07-31 23:10 711168 ----a-w- c:\documents and settings\GAL\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv307hw-1007080-0-main.dll
2010-07-30 03:04 . 2010-07-30 03:04 2224872 ----a-w- c:\program files\GoogleToolbarInstaller_en32_signed.exe
2010-07-30 03:03 . 2010-07-30 03:03 519960 ----a-w- c:\program files\Mats_Run.IEAddon.exe
2010-07-30 02:53 . 2010-07-30 02:53 -------- d-----w- c:\documents and settings\GAL\Application Data\ElevatedDiagnostics
2010-07-27 13:43 . 2010-07-27 13:43 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-24 12:03 . 2010-07-24 12:03 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 04:36 . 2010-05-10 23:04 -------- d-----w- c:\documents and settings\GAL\Application Data\Skype
2010-08-22 04:02 . 2010-05-10 23:05 -------- d-----w- c:\documents and settings\GAL\Application Data\skypePM
2010-08-20 04:31 . 2010-05-11 16:05 -------- d-----w- c:\program files\lx_cats
2010-08-18 23:52 . 2010-05-12 01:28 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-08-17 04:22 . 2010-06-29 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-08-12 15:10 . 2010-06-28 02:22 -------- d-----w- c:\documents and settings\GAL\Application Data\Research In Motion
2010-08-11 07:44 . 2009-04-15 14:01 -------- d-----w- c:\program files\Microsoft Works
2010-08-11 03:14 . 2010-06-30 23:48 -------- d-----w- c:\program files\Common Files\Research In Motion
2010-08-11 03:12 . 2010-06-28 00:44 -------- d-----w- c:\program files\Research In Motion
2010-08-11 03:12 . 2010-07-01 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Research In Motion
2010-08-08 13:00 . 2010-06-28 02:23 256 ----a-w- c:\windows\system32\pool.bin
2010-08-03 16:02 . 2010-07-14 20:38 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-07-30 03:06 . 2009-04-15 14:05 -------- d-----w- c:\program files\Google
2010-07-30 00:04 . 2010-07-30 00:04 32173810 ----a-w- c:\documents and settings\All Users\SPL241.tmp
2010-07-29 15:05 . 2010-06-29 21:03 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 15:05 . 2010-06-29 21:03 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-22 18:31 . 2010-07-22 18:31 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2010-07-22 18:16 . 2010-05-12 04:16 -------- d-----w- c:\program files\trademanager
2010-07-21 22:59 . 2010-07-21 22:54 2605008 ----a-w- c:\documents and settings\GAL\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-07-20 00:00 . 2010-07-20 00:00 -------- d-----w- c:\program files\TranslatorBar_1
2010-07-20 00:00 . 2010-07-20 00:00 -------- d-----w- c:\program files\Conduit
2010-07-14 20:40 . 2010-07-14 20:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2010-07-14 20:39 . 2010-07-14 20:30 -------- d-----w- c:\documents and settings\GAL\Application Data\Logitech
2010-07-14 20:39 . 2010-07-14 20:39 -------- d-----w- c:\documents and settings\GAL\Application Data\Leadertech
2010-07-14 20:39 . 2010-07-14 20:39 53248 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-07-14 20:39 . 2010-07-14 20:31 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-07-14 20:38 . 2010-07-14 20:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-07-14 20:34 . 2010-07-14 20:33 -------- d-----w- c:\program files\Logitech
2010-07-14 20:31 . 2010-07-14 20:30 -------- d-----w- c:\documents and settings\GAL\Application Data\Logishrd
2010-07-14 20:30 . 2010-07-14 20:30 23242528 ----a-w- c:\program files\setpoint610.exe
2010-07-09 02:46 . 2010-07-08 19:47 -------- d-----w- c:\documents and settings\All Users\Application Data\inFlow Inventory
2010-07-09 02:02 . 2010-05-10 23:35 -------- d-----w- c:\program files\Microsoft SQL Server
2010-07-09 01:58 . 2010-05-10 23:26 -------- d-----w- c:\program files\Microsoft.NET
2010-07-09 01:29 . 2010-07-09 01:29 32768 ----a-w- c:\documents and settings\GAL\.exe
2010-07-01 04:04 . 2010-07-01 04:04 -------- d-----w- c:\documents and settings\GAL\Application Data\Blackberry Desktop
2010-06-30 12:31 . 2009-04-15 05:42 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-29 21:31 . 2010-06-29 21:31 109072 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2010-06-29 21:31 . 2010-06-29 21:31 133720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-29 21:31 . 2010-06-29 21:31 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-06-29 21:31 . 2010-06-29 21:31 315408 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\5.1\klif.sys
2010-06-29 20:57 . 2010-06-29 20:57 -------- d-----w- c:\program files\Kaspersky Lab
2010-06-29 20:51 . 2009-04-15 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-06-29 20:48 . 2010-05-10 19:17 -------- d-----w- c:\program files\Symantec
2010-06-29 20:41 . 2010-06-29 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-06-28 00:46 . 2010-06-28 00:46 69632 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{CE86E2F5-850C-4207-94A3-A58D647B1733}\DesktopMgr.exe
2010-06-24 12:22 . 2009-04-15 05:42 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2009-04-15 05:42 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2009-04-15 05:42 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2009-04-15 05:42 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-04-15 01:56 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2009-04-15 05:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-12 04:17 . 2010-05-10 19:12 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-06-12 04:17 . 2010-06-12 04:18 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{22249312-26C2-492E-B0B5-E73EFF2939D8}\PostBuild.exe
2010-06-10 21:00 . 2010-06-10 21:00 503808 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\msvcp71.dll
2010-06-10 21:00 . 2010-06-10 21:00 499712 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\jmc.dll
2010-06-10 21:00 . 2010-06-10 21:00 348160 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-191d0841-n\msvcr71.dll
2010-06-10 21:00 . 2010-06-10 21:00 61440 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35d2b6a0-n\decora-sse.dll
2010-06-10 21:00 . 2010-06-10 21:00 12800 ----a-w- c:\documents and settings\GAL\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-35d2b6a0-n\decora-d3d.dll
2010-06-10 20:59 . 2010-06-10 21:00 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-07 12:57 . 2010-06-07 12:57 76712 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-06-01 19:00 . 2010-06-01 19:00 3584 ----a-r- c:\documents and settings\GAL\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-05-31 03:15 . 2010-05-10 19:06 92344 ----a-w- c:\documents and settings\GAL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-29 16:14 . 2010-05-13 23:44 298 ----a-w- c:\documents and settings\GAL\Application Data\wklnhst.dat
2010-05-14 02:30 . 2010-05-14 02:29 1364522 ----a-w- c:\program files\wrar393.exe
2010-05-13 22:57 . 2010-05-13 22:57 12894680 ----a-w- c:\program files\word2007-kb974631-fullfile-x86-glb.exe
2010-05-13 13:12 . 2010-05-13 13:12 5835264 ----a-w- c:\program files\MAXEN_eMule0.50a-Installer.exe
2010-05-12 04:15 . 2010-05-12 04:15 16777272 ----a-w- c:\program files\AliIM2010_TradeManager(6.18.30).exe
2010-05-12 01:28 . 2010-05-12 01:28 7886336 ----a-w- c:\program files\setup.msi
2010-05-11 23:45 . 2010-05-11 23:45 5520400 ----a-w- c:\program files\WindowsSearch-KB940157-XP-x86-enu.exe
2010-05-10 23:43 . 2010-05-10 23:43 12383736 ----a-w- c:\program files\picasa36-setup.exe
2010-05-10 23:02 . 2010-05-10 23:02 1704744 ----a-w- c:\program files\SkypeSetup.exe
2006-04-06 21:29 . 2010-05-11 15:15 3275752 ----a-w- c:\program files\Babylon50_Setup.exe
.