(1/7/2009 10:23:07 AM) (--A-) (865ca0f8296540ad5c1493ae7fcbe3a8)
C:\WINDOWS\system32\ZoneLabs\fbl.dll (169984 bytes) (Check Point Software Technologies LTD)
(7/2/2010 4:52:38 AM) (--A-) (48a487428d3685f2077250fad279b120)
C:\WINDOWS\system32\vswmi.dll (43008 bytes) (Check Point Software Technologies LTD)
(1/7/2009 10:23:10 AM) (--A-) (dc9af641b6cc3cdd26d571fa8bfab0a1)
C:\WINDOWS\system32\zlcomm.dll (69120 bytes) (Check Point Software Technologies LTD)
(7/2/2010 4:52:35 AM) (--A-) (91192aa3ccd9ab58479f20d5415a43ee)
C:\WINDOWS\system32\ZLCommDB.dll (103936 bytes) (Check Point Software Technologies LTD)
(7/2/2010 4:52:35 AM) (--A-) (ffcf2d668cd1e1a3816fd2b5d3cc78b0)
C:\WINDOWS\system32\ZoneLabs\VSRULEDB.DLL (1790464 bytes) (Check Point Software Technologies
LTD) (1/7/2009 10:23:12 AM) (--A-) (b878b46a658fc2e2b1396f34c9da801c)
C:\WINDOWS\system32\ZoneLabs\vsvault.dll (173056 bytes) (Check Point Software Technologies
LTD) (7/2/2010 4:52:40 AM) (--A-) (04d75fbb76e4bda51a57d60fcbade4b6)
C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll (99328 bytes) (Check Point Software
Technologies LTD) (7/2/2010 4:52:41 AM) (--A-) (84ff6b064a730e55cecf0b70cbcade3d)
C:\WINDOWS\system32\ZoneLabs\qrbase.dll (722392 bytes) (Check Point Software Technologies
LTD) (7/2/2010 4:52:41 AM) (--A-) (9639147d86058dbd944da82edace4279)
C:\WINDOWS\system32\ZoneLabs\scheduler.dll (135680 bytes) (Check Point Software Technologies
LTD) (7/2/2010 4:52:39 AM) (--A-) (23aa080554045624d38f46ab4bfe2f5b)
C:\WINDOWS\system32\ZoneLabs\zlupdate.dll (141824 bytes) (Check Point Software Technologies
LTD) (7/2/2010 4:52:39 AM) (--A-) (d6a2253c5cece39ed4488b398fd4b6b1)
C:\WINDOWS\system32\ZoneLabs\camupd.dll (75776 bytes) (Check Point Software Technologies
LTD) (7/2/2010 4:52:42 AM) (--A-) (11a1a5941d203f5da52ceafea89bb992)
C:\WINDOWS\system32\ieframe.dll (6067200 bytes) (Microsoft Corporation) (8/13/2007 8:54:10
PM) (--A-) (bc88680edb207514d8009bd98761b6bb)
C:\WINDOWS\system32\WPDShServiceObj.dll (133632 bytes) (Microsoft Corporation) (10/18/2006
11:47:22 PM) (--A-) (045e228f71c31901084b64be59093499)
C:\WINDOWS\system32\PortableDeviceTypes.dll (166912 bytes) (Microsoft Corporation)
(10/18/2006 11:47:18 PM) (--A-) (22358578cb321f3325496a3723029409)
C:\WINDOWS\system32\PortableDeviceApi.dll (284160 bytes) (Microsoft Corporation) (10/18/2006
11:47:18 PM) (--A-) (9d45b2201d0ecf9f42136c7b99deb8b2)
C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll (89088 bytes)
(Microsoft Corporation) (2/15/2009 5:47:40 PM) (--A-) (eee7f12d9ff46f68fbc0da059a359e9e)
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll (22024 bytes) (Microsoft
Corporation) (7/25/2008 12:16:40 PM) (--A-) (de5003632f20c69a07b8dfbc83f460e4)
C:\WINDOWS\system32\zpeng25.dll (1238528 bytes) (Check Point Software Technologies LTD)
(1/7/2009 10:23:08 AM) (--A-) (2a1f3a456e08e69073f979b2a53b1134)
C:\WINDOWS\system32\VSPUBAPI.dll (302592 bytes) (Check Point Software Technologies LTD)
(1/7/2009 10:23:06 AM) (--A-) (b8387a77ab4b7bccb8f291d335725cc9)
C:\WINDOWS\system32\ZoneLabs\lib\pyd\zpui.pyd (281600 bytes) (Check Point Software
Technologies LTD) (7/2/2010 4:52:25 AM) (--A-) (2e8d91755727839cb2b27f3036532204)
C:\WINDOWS\system32\ZoneLabs\lib\pyd\_ctypes.pyd (81408 bytes) (Check Point Software
Technologies LTD) (7/2/2010 4:52:26 AM) (--A-) (99cda7006585bbcf9cc7e5981e4b3e00)
C:\WINDOWS\system32\ZoneLabs\lib\pyd\pyexpat.pyd (135168 bytes) (Check Point Software
Technologies LTD) (7/2/2010 4:52:25 AM) (--A-) (f85cb596820e9cc90a408a3f4f7fa2fb)
C:\WINDOWS\system32\vsmonapi.dll (108032 bytes) (Check Point Software Technologies LTD)
(1/7/2009 10:23:05 AM) (--A-) (dc7fb9c4d92a9b1c7b94b4d46dd51435)
C:\WINDOWS\system32\ZoneLabs\FFApi.dll (284136 bytes) (Check Point Software Technologies)
(7/2/2010 4:52:44 AM) (--A-) (1e2ff2dab11e82e758fd83df83f7c600)
C:\WINDOWS\system32\HPOMem05.dll (40448 bytes) (Hewlett-Packard Co.) (5/2/2008 12:31:47 AM)
(--A-) (ad1ebc05039c04472b357ff89f901cb1)
C:\WINDOWS\system32\HPOCNT05.dll (118784 bytes) (Unknown) (5/2/2008 12:31:47 AM) (--A-)
(c8df6ce06aa90bf61f922ed24b1dcdb1)
C:\WINDOWS\system32\hpoidr07.dll (73728 bytes) (HP) (2/17/2008 1:28:05 AM) (--A-)
(b43e6ad2bd7f22e6fdbf749fb292e909)
C:\WINDOWS\system32\hpoipr07.dll (53248 bytes) (HP) (5/2/2008 12:31:34 AM) (--A-)
(3b2ab41c33433590243111f223d159a4)
C:\WINDOWS\system32\hpotap05.dll (40960 bytes) (Hewlett-Packard Co.) (5/2/2008 12:31:39 AM)
(--A-) (0cee07e854f8cd707f28a825c99d0dd5)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpoui05.DLL (407044 bytes) (Unknown) (10/24/2001
1:03:20 PM) (--A-) (043e46f254971dd9ea4423ed6709f12f)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPOWIN05.dll (221184 bytes) (Unknown) (10/24/2001
1:03:20 PM) (--A-) (870643e3d01ee20cbfad500c72e952f1)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPOCNT05.dll (118784 bytes) (Unknown) (10/24/2001
1:03:20 PM) (--A-) (c8df6ce06aa90bf61f922ed24b1dcdb1)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPOMON05.dll (49152 bytes) (Unknown) (10/24/2001
1:03:20 PM) (--A-) (29ffbace6f4613a7a97d128c49c1e82b)
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPOSRL05.DLL (389120 bytes) (Unknown) (10/24/2001
1:03:18 PM) (--A-) (bc565ed415a08b12e9884ac3ed6907f8)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpontu05.DLL (213820 bytes) (Hewlett-Packard
Company) (10/24/2001 1:03:20 PM) (--A-) (b73327c232fe2a0e23f839c4911b02ce)
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPOrsu05.dll (36864 bytes) (Unknown) (10/24/2001
1:03:20 PM) (--A-) (845f9232357dad3af0c1757c20bedb55)
C:\WINDOWS\system32\SFMAN32.DLL (51200 bytes) (Creative Technology Ltd.) (2/16/2008 7:06:18
AM) (--A-) (235781d67706e492073363e587d3b4de)
C:\WINDOWS\system32\wpdshext.dll (2603008 bytes) (Microsoft Corporation) (10/18/2006
11:47:22 PM) (--A-) (81d2a27c916c7830743e4afa454099f7)
C:\WINDOWS\system32\Audiodev.dll (276992 bytes) (Microsoft Corporation) (10/18/2006 11:47:08
PM) (--A-) (4c48f1b30a82583caee0da02dd7259ee)
Value: Ad-Watch
Data: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: avast5
Data: C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: Adobe Reader Speed Launcher
Data: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: Adobe ARM
Data: "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: ZoneAlarm Client