ZoneAlarm Logging Client v7.0.362.000
Windows XP-5.1.2600-Service Pack 3-SP
type,date,time,source,destination,transport (Security)
type,date,time,virus name,file name,mode,e-mail id (Anti-Virus)
type,date,time,source,destination,action,service (IM Security)
type,date,time,source,destination,program,action (Malicious Code Protection)
type,date,time,action,product,file,event,subevent,class,data,data,... (OSFirewall)
type,date,time,name,type,mode (Anti-Spyware)
PE,2009/08/23,19:47:14 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
OSFW,2009/08/23,19:51:42 -5:00 GMT,UNKNOWN(0),AOL Software,C:\PROGRAM FILES\AOL 9.0\aol.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\AOL 9.0\waol.exe
PE,2009/08/23,19:52:16 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,255.255.255.255:67,N/A
FWROUTE,2009/08/23,19:52:16 -5:00 GMT,172.130.150.235:1032,205.188.146.145:53,UDP
FWROUTE,2009/08/23,19:52:16 -5:00 GMT,205.188.66.165:0,172.130.150.235:0,ICMP (type:11/subtype:0)
PE,2009/08/23,19:52:16 -5:00 GMT,AOL Connectivity Service,C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe,172.130.150.1:7427,N/A
PE,2009/08/23,19:52:16 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,205.188.146.145:53,N/A
PE,2009/08/23,19:52:26 -5:00 GMT,AOL Software,C:\PROGRAM FILES\AOL 9.0\waol.exe,205.188.66.253:13784,N/A
PE,2009/08/23,19:52:50 -5:00 GMT,AOL TopSpeed,C:\PROGRAM FILES\COMMON FILES\AOL\TopSpeed\3.0\aoltpsd3.exe,64.12.115.41:5192,N/A
FWIN,2009/08/23,19:53:32 -5:00 GMT,213.245.173.15:10554,172.130.150.235:41170,UDP
FWIN,2009/08/23,19:54:14 -5:00 GMT,203.211.100.240:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,19:54:20 -5:00 GMT,98.25.30.192:1257,172.130.150.235:41170,UDP
FWIN,2009/08/23,19:56:04 -5:00 GMT,78.29.164.126:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,19:58:46 -5:00 GMT,199.88.23.150:27779,172.130.150.235:41170,UDP
FWIN,2009/08/23,19:59:34 -5:00 GMT,91.107.141.244:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:00:14 -5:00 GMT,64.178.255.5:3054,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:00:50 -5:00 GMT,174.101.209.251:41170,172.130.150.235:41170,UDP
PE,2009/08/23,20:02:20 -5:00 GMT,ZoneAlarm Client,C:\PROGRAM FILES\ZONE LABS\ZONEALARM\zlclient.exe,204.212.170.210:53,N/A
FWIN,2009/08/23,20:03:54 -5:00 GMT,99.239.245.154:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:05:08 -5:00 GMT,86.177.76.187:53004,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:05:24 -5:00 GMT,172.129.27.48:0,172.130.150.235:0,ICMP (type:8/subtype:0)
FWIN,2009/08/23,20:05:32 -5:00 GMT,70.188.7.2:6515,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:05:36 -5:00 GMT,74.75.186.47:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:08:24 -5:00 GMT,75.66.14.77:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:08:44 -5:00 GMT,67.52.237.100:33935,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:12:24 -5:00 GMT,190.52.235.137:21541,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:13:38 -5:00 GMT,68.48.67.78:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:13:58 -5:00 GMT,98.15.189.29:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:14:22 -5:00 GMT,96.241.11.96:50046,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:15:00 -5:00 GMT,68.58.54.101:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:15:30 -5:00 GMT,172.130.59.137:0,172.130.150.235:0,ICMP (type:8/subtype:0)
FWIN,2009/08/23,20:16:56 -5:00 GMT,24.179.111.51:22270,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:17:10 -5:00 GMT,174.16.21.128:41170,172.130.150.235:41170,UDP
OSFW,2009/08/23,20:19:10 -5:00 GMT,UNKNOWN(0),Windows NT Logon Application,C:\WINDOWS\system32\winlogon.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\LOGON.SCR
FWIN,2009/08/23,20:20:40 -5:00 GMT,24.2.30.109:41169,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:21:00 -5:00 GMT,216.197.146.40:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:21:12 -5:00 GMT,70.252.130.56:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:21:18 -5:00 GMT,72.226.74.4:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:22:26 -5:00 GMT,79.77.96.110:50099,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:23:08 -5:00 GMT,86.42.203.186:62319,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:23:36 -5:00 GMT,76.4.155.254:10064,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:27:06 -5:00 GMT,97.115.237.158:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:28:22 -5:00 GMT,24.2.30.109:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:30:46 -5:00 GMT,74.171.32.11:54013,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:35:14 -5:00 GMT,99.181.125.49:56552,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:35:28 -5:00 GMT,96.24.102.83:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:36:08 -5:00 GMT,218.30.22.82:4600,172.130.150.235:1434,UDP
FWIN,2009/08/23,20:36:12 -5:00 GMT,213.22.218.205:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:37:40 -5:00 GMT,72.226.54.111:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:41:12 -5:00 GMT,74.75.186.47:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:41:52 -5:00 GMT,68.146.159.251:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:43:58 -5:00 GMT,75.185.58.101:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:45:30 -5:00 GMT,68.58.54.101:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:46:52 -5:00 GMT,74.240.178.21:50297,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:52:28 -5:00 GMT,69.124.212.214:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:53:38 -5:00 GMT,68.59.79.53:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:54:06 -5:00 GMT,98.88.2.133:50642,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:54:20 -5:00 GMT,24.112.120.117:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:54:32 -5:00 GMT,98.15.189.29:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:56:32 -5:00 GMT,173.183.212.174:41170,172.130.150.235:41170,UDP
FWIN,2009/08/23,20:59:32 -5:00 GMT,96.241.11.96:50046,172.130.150.235:41170,UDP
OSFW,2009/08/23,21:08:28 -5:00 GMT,UNKNOWN(0),Services and Controller app,C:\WINDOWS\system32\services.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
OSFW,2009/08/23,21:08:52 -5:00 GMT,UNKNOWN(0),Windows Explorer,C:\WINDOWS\explorer.exe,PROCESS,SPAWNPROCESS,SRC,C:\PROGRAM FILES\ZONE LABS\ZONEALARM\zlclient.exe,7462b386-4da32e6b-3d1ef052-4e663a23,08f-d9ce1d6a-b5944fe9
OSFW,2009/08/23,21:08:54 -5:00 GMT,UNKNOWN(0),AOL Software,C:\PROGRAM FILES\AOL 9.0\aol.exe,PROCESS,SPAWNPROCESS,SRC,C:\PROGRAM FILES\AOL 9.0\waol.exe,4ce73530-8fb8b025-986240bf-ec3e9f84,4,ee7
OSFW,2009/08/23,21:11:02 -5:00 GMT,UNKNOWN(0),waolmon,C:\PROGRAM FILES\AOL 9.0\shellmon.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\AOL 9.0\waol.exe
PE,2009/08/23,21:16:50 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
FWROUTE,2009/08/23,21:17:24 -5:00 GMT,205.188.66.138:0,172.132.70.208:0,ICMP (type:11/subtype:0)
PE,2009/08/23,21:17:44 -5:00 GMT,AOL TopSpeed,C:\PROGRAM FILES\COMMON FILES\AOL\TopSpeed\3.0\aoltpsd3.exe,64.12.115.25:5192,N/A
OSFW,2009/08/23,21:29:40 -5:00 GMT,UNKNOWN(0),Windows NT Logon Application,C:\WINDOWS\system32\winlogon.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\LOGONUI.EXE
OSFW,2009/08/23,21:31:54 -5:00 GMT,UNKNOWN(0),Services and Controller app,C:\WINDOWS\system32\services.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
OSFW,2009/08/23,21:32:32 -5:00 GMT,UNKNOWN(0),waolmon,C:\PROGRAM FILES\AOL 9.0\shellmon.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\AOL 9.0\waol.exe
PE,2009/08/23,21:33:16 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
FWROUTE,2009/08/23,21:33:50 -5:00 GMT,172.162.240.247:1034,205.188.146.145:53,UDP
FWROUTE,2009/08/23,21:33:50 -5:00 GMT,172.162.240.247:1035,205.188.146.145:53,UDP
FWROUTE,2009/08/23,21:33:50 -5:00 GMT,64.12.7.165:0,172.162.240.247:0,ICMP (type:11/subtype:0)
PE,2009/08/23,21:35:00 -5:00 GMT,AOL TopSpeed,C:\PROGRAM FILES\COMMON FILES\AOL\TopSpeed\3.0\aoltpsd3.exe,64.12.115.17:5192,N/A
OSFW,2009/08/23,22:10:42 -5:00 GMT,UNKNOWN(0),Services and Controller app,C:\WINDOWS\system32\services.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
OSFW,2009/08/23,22:11:04 -5:00 GMT,UNKNOWN(0),Windows Explorer,C:\WINDOWS\explorer.exe,PROCESS,SPAWNPROCESS,SRC,C:\PROGRAM FILES\ZONE LABS\ZONEALARM\zlclient.exe,7462b386-4da32e6b-3d1ef052-4e663a23,08f-d9ce1d6a-b5944fe9
OSFW,2009/08/23,22:11:18 -5:00 GMT,UNKNOWN(0),waolmon,C:\PROGRAM FILES\AOL 9.0\shellmon.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\AOL 9.0\waol.exe
PE,2009/08/23,22:11:18 -5:00 GMT,Generic Host Process for Win32 Services,C:\WINDOWS\system32\svchost.exe,0.0.0.0:135,N/A
FWROUTE,2009/08/23,22:12:32 -5:00 GMT,205.188.70.70:0,172.129.89.223:0,ICMP (type:11/subtype:0)
FWIN,2009/08/23,22:24:48 -5:00 GMT,202.107.196.99:2992,172.129.89.223:1434,UDP
OSFW,2009/08/23,22:25:40 -5:00 GMT,UNKNOWN(0),waolmon,C:\PROGRAM FILES\AOL 9.0\shellmon.exe,PROCESS,OPENPROCESS,DST,C:\Program Files\AOL 9.0\waol.exe
FWROUTE,2009/08/23,22:26:06 -5:00 GMT,64.12.7.166:0,172.162.26.141:0,ICMP (type:11/subtype:0)
FWIN,2009/08/23,22:27:30 -5:00 GMT,221.192.199.41:12200,172.162.26.141:8090,TCP (flags:S)
FWIN,2009/08/23,22:32:56 -5:00 GMT,221.192.199.41:12200,172.162.26.141:9000,TCP (flags:S)
FWIN,2009/08/23,22:33:04 -5:00 GMT,74.63.225.44:12200,172.162.26.141:7212,TCP (flags:S)
FWIN,2009/08/23,23:03:46 -5:00 GMT,61.152.175.122:6000,172.162.26.141:1433,TCP (flags:S)
FWIN,2009/08/23,23:38:02 -5:00 GMT,66.220.107.216:32721,172.162.26.141:21363,UDP
FWIN,2009/08/23,23:38:08 -5:00 GMT,66.220.107.216:39419,172.162.26.141:21363,UDP
FWIN,2009/08/23,23:42:30 -5:00 GMT,74.63.225.44:12200,172.162.26.141:8090,TCP (flags:S)
FWIN,2009/08/23,23:49:50 -5:00 GMT,221.192.199.41:12200,172.162.26.141:8090,TCP (flags:S)
FWIN,2009/08/23,23:53:26 -5:00 GMT,99.135.151.130:41423,172.162.26.141:38143,UDP
OSFW,2009/08/24,00:08:36 -5:00 GMT,UNKNOWN(0),Windows NT Logon Application,C:\WINDOWS\system32\winlogon.exe,PROCESS,SPAWNPROCESS,SRC,C:\WINDOWS\SYSTEM32\LOGON.SCR
FWIN,2009/08/24,00:16:18 -5:00 GMT,221.192.199.41:12200,172.162.26.141:9000,TCP (flags:S)
FWIN,2009/08/24,00:28:38 -5:00 GMT,61.147.107.56:6000,172.162.26.141:2967,TCP (flags:S)
FWIN,2009/08/24,00:46:16 -5:00 GMT,209.149.52.17:6000,172.162.26.141:2967,TCP (flags:S)
FWIN,2009/08/24,01:03:34 -5:00 GMT,74.63.225.44:12200,172.162.26.141:9788,TCP (flags:S)
FWIN,2009/08/24,01:05:50 -5:00 GMT,172.162.21.226:4003,172.162.26.141:80,TCP (flags:S)
FWIN,2009/08/24,01:06:12 -5:00 GMT,172.162.21.226:4057,172.162.26.141:443,TCP (flags:S)
FWIN,2009/08/24,01:19:54 -5:00 GMT,68.8.27.198:49063,172.162.26.141:38143,UDP
man with the goatee in the island of M right now. probably a pawnmaster in the ----net right now.