choconick
2009-02-02, 11:38
hello fellas,
my computer is infected by W32.Gammima.AG apparently according to Norton, the software keep saying it has been completely resolved, but the auto protection pop up and said it just block W32.Gammima.AG again, and it keep coming back everyday, omg, how am I suppose to fix this. I have COMODO installed as well.
thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:33:40 PM, on 2/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Brownie\BrstsWnd.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Program Files\Brownie\brpjp04a.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VIA\RAID\vialogsv.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.EXE
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\IPSBHO.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VRAID Log Service - Unknown owner - C:\Program Files\VIA\RAID\vialogsv.exe
--
End of file - 4518 bytes
Norton Antivirus 2009 protection history:
Category: Intrusion Prevention
Date & Time,Risk Level,Activity,Status,Recommended Action,Category
2/02/2009 5:11 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
2/02/2009 5:11 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
2/02/2009 5:11 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
Category: Resolved Security Risks
Date & Time,Risk Level,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State
31/01/2009 2:36 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 3:55 PM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.30.024,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 2:16 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
Category: Scan Results
Date & Time,Risk Level,Activity,Status,Recommended Action,Task Name,Scan Time,Total items scanned,Files & Directories,Registry Entries,Processes & Start-Up Items,Network & Browser Items,Other,Trusted Files,Skipped Files,Total Security Risks Detected,Total Security Risks Resolved,Total Security Risks Requiring Attention
27/01/2009 5:21 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:21 (d:h:m:s),"2,522",649,133,"1,634",12,4,157,0,0,0,0
27/01/2009 4:30 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:16 (d:h:m:s),"2,487",624,131,"1,626",12,4,0,570,0,0,0
27/01/2009 4:26 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:41 (d:h:m:s),"2,535",624,131,"1,674",12,4,0,0,0,0,0
30/01/2009 10:10 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:26 (d:h:m:s),"2,899",695,169,"1,929",12,4,176,0,0,0,0
1/02/2009 5:12 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:25 (d:h:m:s),"2,822",675,171,"1,870",12,4,198,0,0,0,0
30/01/2009 5:24 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:31 (d:h:m:s),"2,973",709,172,"1,986",12,4,176,0,0,0,0
28/01/2009 10:20 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:17 (d:h:m:s),"2,623",645,136,"1,736",12,4,156,0,0,0,0
2/02/2009 9:28 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:28 (d:h:m:s),"2,950",702,171,"1,971",12,4,203,0,0,0,0
29/01/2009 6:21 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:29 (d:h:m:s),"2,627",643,137,"1,741",12,4,156,0,0,0,0
29/01/2009 11:11 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:30 (d:h:m:s),"2,732",671,137,"1,818",12,4,156,0,0,0,0
1/02/2009 9:09 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:28 (d:h:m:s),"2,958",699,171,"1,982",12,4,194,0,0,0,0
31/01/2009 1:25 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:34 (d:h:m:s),"3,109",713,171,"2,119",12,4,196,0,0,0,0
28/01/2009 7:35 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:22 (d:h:m:s),"2,576",639,136,"1,695",12,4,157,0,0,0,0
30/01/2009 2:09 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:27 (d:h:m:s),"2,778",673,169,"1,830",12,4,177,0,0,0,0
Category: Quarantine
Date & Time,Risk Level,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State
31/01/2009 2:36 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 3:55 PM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.30.024,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 2:16 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
Category: System Activity Monitoring
Date & Time,Risk Level,Activity,Status,Recommended Action,Program,Last Updated,Affected Area,Modified resource,Target file
30/01/2009 2:53 PM,Low,"setupsg.exe made 25 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\drivers\scanner\lide25_11010wnenz\setupsg.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,"c:\documents and settings\fei\local settings\temp\wzse0.tmp\delsg.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\setupsg.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\usbscan.sys, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnql25\cnql1213.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\balco.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cfine2.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cisds.ds, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cnqu110.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\iop.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\itlib32.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\jda_cimg.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\libblc.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\msvcrt.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\nbs4mb.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\nbscor4m.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\rmslantc.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\rstcol.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\scanintf.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\scrprmv.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\sgui.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\sgui_res.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\tpm.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\twain_32.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\twunk_32.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\instal~1\setup.exe",
28/01/2009 12:55 PM,Low,"foobar2000_0.9.6.1.exe made 26 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",e:\software\foobar2000_0.9.6.1.exe,"Wednesday, 28 January 2009 12:55 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\nslcf.tmp\system.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\nsdialogs.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\uac.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\startmenu.dll, c:\program files\foobar2000\foobar2000.exe, c:\program files\foobar2000\shared.dll, c:\program files\foobar2000\shellext32.dll, c:\program files\foobar2000\foobar2000 shell associations updater.exe, c:\program files\foobar2000\components\foo_input_std.dll, c:\program files\foobar2000\components\foo_ui_std.dll, c:\program files\foobar2000\components\foo_cdda.dll, c:\program files\foobar2000\components\foo_albumlist.dll, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\foobar2000\DisplayIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\foobar2000\UninstallString, c:\program files\foobar2000\components\foo_dsp_std.dll, c:\program files\foobar2000\components\foo_rgscan.dll, c:\program files\foobar2000\components\foo_converter.dll, c:\program files\foobar2000\uninstall.exe, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000 - website.url, c:\documents and settings\all users\start menu\programs\foobar2000\uninstall.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\uninstall.lnk, c:\documents and settings\fei\application data\microsoft\internet explorer\quick launch\foobar2000.lnk, c:\documents and settings\fei\application data\microsoft\internet explorer\quick launch\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000 - website.url",
27/01/2009 3:53 PM,Low,"issetup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\ati\support\6-11-pre-r300_xp-2k_dd_ccc_wdm_38185\issetup.exe,"Tuesday, 27 January 2009 3:53 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
29/01/2009 10:01 PM,Low,"devcon32.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\nst7e.tmp\devcon32.exe,"Thursday, 29 January 2009 10:01 PM",System Configuration,c:\windows\system32\drivers\vclone.sys,
2/02/2009 5:50 PM,Low,"keygen.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required","c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\keygen\keygen.exe","Monday, 2 February 2009 5:50 PM",System Configuration,"c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\keygen\keygen.exe",
27/01/2009 3:54 PM,Low,"setup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\ati\support\6-11-pre-r300_xp-2k_dd_ccc_wdm_38185\driver\setup.exe,"Tuesday, 27 January 2009 3:54 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
29/01/2009 10:01 PM,Low,"setupvirtualclonedrive5301.exe made 31 modifications to your computer., Resource, Resource, Resource",Detected,"No Action Required, No Action Required",e:\software\setupvirtualclonedrive5301.exe,"Thursday, 29 January 2009 10:01 PM","System Configuration, Windows Startup Settings, Windows System Settings","c:\documents and settings\fei\local settings\temp\nst7e.tmp\installhelp.dll, c:\program files\elaborate bytes\virtualclonedrive\installhelp.dll, c:\program files\elaborate bytes\virtualclonedrive\devcon32.exe, c:\program files\elaborate bytes\virtualclonedrive\vcd-uninst.exe, c:\program files\elaborate bytes\virtualclonedrive\elbydvd.exe, c:\program files\elaborate bytes\virtualclonedrive\helplauncher.exe, \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\ElbyDelay\ImagePath, \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\ElbyDelay\Type, c:\program files\elaborate bytes\virtualclonedrive\vcddaemon.exe, c:\program files\elaborate bytes\virtualclonedrive\vcdmount.exe, c:\program files\elaborate bytes\virtualclonedrive\vcdprefs.exe, c:\documents and settings\fei\local settings\temp\nst7e.tmp\elbyvcdshell.dll, c:\program files\elaborate bytes\virtualclonedrive\elbyvcdshell.dll, c:\windows\system32\elbycdio.dll, c:\windows\system32\elbyvcd.dll, c:\windows\system32\drivers\elbycdio.sys, c:\windows\system32\drivers\elbydelay.sys, c:\documents and settings\fei\local settings\temp\nst7e.tmp\vclone.sys, c:\documents and settings\fei\local settings\temp\nst7e.tmp\devcon32.exe, \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VirtualCloneDrive, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualCloneDrive\UninstallString, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\uninstall.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\uninstall.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\manual.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\manual.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive revision history.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive revision history.lnk",C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
29/01/2009 6:40 PM,Low,"klcodec445s.tmp made 111 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\is-sp5a1.tmp\klcodec445s.tmp,"Thursday, 29 January 2009 6:40 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_regdll.tmp, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_shfoldr.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_iscrypt.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\ffspkcfg.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\wincpuid.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\psvince.dll, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.avi\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.divx\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpg\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpeg\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpe\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mp2v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m1v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.wmv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.asf\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ogm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ogv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mkv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mka\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mp4\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.hdmov\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.flv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2ts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2t\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3g2\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gp2\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gpp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mov\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.qt\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ra\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ram\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rmvb\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rmm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rpm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rt\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.smi\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.smil\DefaultIcon, c:\program files\k-lite codec pack\is-60phk.tmp, c:\program files\k-lite codec pack\is-s4dmb.tmp, c:\program files\k-lite codec pack\tools\is-jumf5.tmp, c:\program files\k-lite codec pack\ffdshow\is-k4m51.tmp, c:\program files\k-lite codec pack\ffdshow\is-g97h4.tmp, c:\program files\k-lite codec pack\ffdshow\is-sv5lr.tmp, c:\program files\k-lite codec pack\ffdshow\is-fp8mm.tmp, c:\program files\k-lite codec pack\ffdshow\is-oat96.tmp, c:\program files\k-lite codec pack\ffdshow\is-f57cu.tmp, c:\program files\k-lite codec pack\ffdshow\is-s2i3u.tmp, c:\program files\k-lite codec pack\ffdshow\is-328c3.tmp, c:\program files\k-lite codec pack\ffdshow\is-fv2v4.tmp, c:\program files\k-lite codec pack\ffdshow\is-rp8hj.tmp, c:\program files\k-lite codec pack\ffdshow\is-i5gu6.tmp, c:\program files\k-lite codec pack\media player classic\is-9dcc8.tmp, c:\program files\k-lite codec pack\media player classic\is-5i43n.tmp, c:\program files\k-lite codec pack\filters\is-1t7r9.tmp, c:\program files\k-lite codec pack\filters\is-h03sc.tmp, c:\program files\k-lite codec pack\filters\is-bq6q0.tmp, c:\program files\k-lite codec pack\filters\is-hnf7f.tmp, c:\program files\k-lite codec pack\filters\haali\is-lh290.tmp, c:\program files\k-lite codec pack\filters\haali\is-irm80.tmp, c:\program files\k-lite codec pack\filters\haali\is-p59n5.tmp, c:\program files\k-lite codec pack\filters\haali\is-2o185.tmp, c:\program files\k-lite codec pack\filters\haali\is-kgdng.tmp, c:\program files\k-lite codec pack\filters\haali\is-bi67e.tmp, c:\program files\k-lite codec pack\filters\haali\is-7db7e.tmp, c:\program files\k-lite codec pack\filters\haali\is-s90oi.tmp, c:\program files\k-lite codec pack\filters\is-mg34g.tmp, c:\windows\system32\is-418ff.tmp, c:\program files\k-lite codec pack\tools\is-ojaij.tmp, c:\program files\k-lite codec pack\tools\is-bf1vd.tmp, c:\program files\k-lite codec pack\tools\is-45vhp.tmp, c:\program files\k-lite codec pack\tools\is-2g68r.tmp, \REGISTRY\MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\pnm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1\UninstallString, c:\documents and settings\all users\start menu\programs\k-lite codec pack\media player classic.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\media player classic.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\reset to recommended settings.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\reset to recommended settings.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\cyberlink mpeg-2 decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\cyberlink mpeg-2 decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\directvobsub.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\directvobsub.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow audio decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow audio decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow video decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow video decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali media splitter.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali media splitter.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali video renderer.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali video renderer.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\mediainfo.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\mediainfo.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\vobsubstrip.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\vobsubstrip.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\faq.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\faq.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\website.url, c:\documents and settings\all users\start menu\programs\k-lite codec pack\uninstall\uninstall k-lite codec pack.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\uninstall\uninstall k-lite codec pack.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\website.url",
30/01/2009 2:53 PM,Low,"setup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\wzse0.tmp\instal~1\setup.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
2/02/2009 5:50 PM,Low,"adc.tmp made 62 modifications to your System Configuration., Resource, Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\is-ptudp.tmp\adc.tmp,"Monday, 2 February 2009 5:50 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\_isetup\_regdll.tmp, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\_isetup\_shfoldr.dll, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\adcmigrator.exe, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\sqlite3.dll, c:\program files\xemicomputers\active desktop calendar\is-cumrj.tmp, c:\program files\xemicomputers\active desktop calendar\is-h7pj3.tmp, c:\program files\xemicomputers\active desktop calendar\is-dvgls.tmp, c:\program files\xemicomputers\active desktop calendar\is-cur60.tmp, c:\program files\xemicomputers\active desktop calendar\is-npi1o.tmp, c:\program files\xemicomputers\active desktop calendar\is-qnv5o.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-v1o8a.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ohgng.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-jhd3k.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-aed1k.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-jsets.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-22bab.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-a504s.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-vgimq.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-mnbin.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-b3s9g.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-6atjo.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-2oh06.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ghpsi.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-u0m1o.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-6spg0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-tu3sg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-optl6.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-9h3jr.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-dd2td.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-7peuh.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-3j0qa.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-lrekg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-d823n.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-d7jd0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-5d1dn.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-595cg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ktmel.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ts62m.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-7svl4.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-a10oi.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-14kdv.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-9g5ea.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-j6bqa.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-2ma9e.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-h63le.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-3tfil.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-n5kb0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\today & pin icons\is-mt23u.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\today & pin icons\is-s2ssq.tmp, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Active Desktop Calendar_is1\UninstallString, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar on the web.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar on the web.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\uninstall active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\uninstall active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar help file.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar help file.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\readme.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\readme.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\license agreement.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\license agreement.lnk",
27/01/2009 3:38 PM,Low,"idriver.exe made 8 modifications to your System Configuration., Resource, Resource",Detected,"No Action Required, No Action Required",c:\program files\common files\installshield\driver\7\intel 32\idriver.exe,"Tuesday, 27 January 2009 3:38 PM","Windows Startup Settings, System Configuration","c:\documents and settings\all users\start menu\programs\administrative tools, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\isrt.dll, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\_isres.dll, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\_isuser.dll, c:\documents and settings\fei\local settings\temp\msi7.tmp, c:\documents and settings\fei\local settings\temp\msi8.tmp, c:\program files\via\setup\viaagp\agpdrvnt.dll, c:\windows\system32\difxapi.dll",
2/02/2009 5:49 PM,Low,"wrar380.exe made 23 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\wrar380.exe,"Monday, 2 February 2009 5:49 PM",System Configuration,"c:\program files\winrar\rar.exe, c:\program files\winrar\rarextloader.exe, c:\program files\winrar\uninstall.exe, c:\program files\winrar\unrar.exe, c:\program files\winrar\winrar.exe, c:\program files\winrar\formats\7zxa.dll, c:\program files\winrar\rarext.dll, c:\program files\winrar\rarext64.dll, c:\program files\winrar\formats\unacev2.dll, c:\program files\winrar\formats\7z.fmt, c:\program files\winrar\formats\ace.fmt, c:\program files\winrar\formats\arj.fmt, c:\program files\winrar\formats\bz2.fmt, c:\program files\winrar\formats\cab.fmt, c:\program files\winrar\formats\gz.fmt, c:\program files\winrar\formats\iso.fmt, c:\program files\winrar\formats\lzh.fmt, c:\program files\winrar\formats\tar.fmt, c:\program files\winrar\formats\uue.fmt, c:\program files\winrar\formats\z.fmt, c:\program files\winrar\default.sfx, c:\program files\winrar\wincon.sfx, c:\program files\winrar\zip.sfx",
27/01/2009 3:56 PM,Low,"install.exe made 45 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\program files\analog devices\soundmax\install.exe,"Tuesday, 27 January 2009 3:56 PM",System Configuration,"c:\windows\system32\drivers\set4d.tmp, c:\windows\system32\set51.tmp, c:\windows\lastgood\system32\drivers\stream.sys, c:\windows\temp\old4f.tmp, c:\windows\system32\drivers\stream.sys, c:\windows\system32\drivers\set53.tmp, c:\windows\system32\ksproxy.ax, c:\windows\system32\set55.tmp, c:\windows\system32\drivers\drmk.sys, c:\windows\system32\ksuser.dll, c:\windows\system32\drivers\set57.tmp, c:\windows\system32\set59.tmp, c:\windows\system32\drivers\portcls.sys, c:\windows\system32\drivers\set5d.tmp, c:\windows\lastgood\system32\wdmaud.drv, c:\windows\temp\old5b.tmp, c:\windows\system32\wdmaud.drv, c:\windows\lastgood\system32\drivers\ks.sys, c:\windows\system32\drivers\ks.sys, c:\windows\system32\drivers\smwdm.sys, c:\windows\system32\drivers\senfilt.sys, c:\windows\system32\drivers\aeaudio.sys, c:\windows\system32\a3d.dll, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSPCLOCK, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSPQM, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSKSSRV, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SYSAUDIO, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_KMIXER0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_KMIXER1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_WDMAUD, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SPLITTER0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SPLITTER1",
30/01/2009 2:53 PM,Low,"setupsg.exe made 21 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\wzse0.tmp\setupsg.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,"c:\canoscan\cnql25\cnql25\cnql1213.dll, c:\canoscan\cnql25\cnqsg110\balco.dll, c:\canoscan\cnql25\cnqsg110\cfine2.dll, c:\canoscan\cnql25\cnqsg110\cisds.ds, c:\canoscan\cnql25\cnqsg110\cnqu110.dll, c:\canoscan\cnql25\cnqsg110\iop.dll, c:\canoscan\cnql25\cnqsg110\itlib32.dll, c:\canoscan\cnql25\cnqsg110\jda_cimg.dll, c:\canoscan\cnql25\cnqsg110\libblc.dll, c:\canoscan\cnql25\cnqsg110\msvcrt.dll, c:\canoscan\cnql25\cnqsg110\nbs4mb.dll, c:\canoscan\cnql25\cnqsg110\nbscor4m.dll, c:\canoscan\cnql25\cnqsg110\rmslantc.dll, c:\canoscan\cnql25\cnqsg110\rstcol.dll, c:\canoscan\cnql25\cnqsg110\scanintf.dll, c:\canoscan\cnql25\cnqsg110\scrprmv.dll, c:\canoscan\cnql25\cnqsg110\sgui.dll, c:\canoscan\cnql25\cnqsg110\sgui_res.dll, c:\canoscan\cnql25\cnqsg110\tpm.dll, c:\canoscan\cnql25\cnqsg110\twain_32.dll, c:\canoscan\cnql25\cnqsg110\twunk_32.exe",
27/01/2009 4:02 PM,Low,"smax4.exe made 2 modifications to your computer., Resource",Detected,"No Action Required, No Action Required",c:\program files\analog devices\soundmax\smax4.exe,"Tuesday, 27 January 2009 4:02 PM",System Configuration,"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SoundMax",
2/02/2009 5:50 PM,Low,"adc.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\setup\adc.exe,"Monday, 2 February 2009 5:50 PM",System Configuration,c:\documents and settings\fei\local settings\temp\is-ptudp.tmp\adc.tmp,
29/01/2009 6:40 PM,Low,"klcodec445s.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\codecs\klcodec445s.exe,"Thursday, 29 January 2009 6:40 PM",System Configuration,c:\documents and settings\fei\local settings\temp\is-sp5a1.tmp\klcodec445s.tmp,
27/01/2009 3:54 PM,Low,"ikernel.exe made 9 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\program files\common files\installshield\engine\6\intel 32\ikernel.exe,"Tuesday, 27 January 2009 3:54 PM",System Configuration,"c:\program files\common files\installshield\engine\6\intel 32\ilog.dll, c:\program files\common files\installshield\engine\6\intel 32\ctor.dll, c:\program files\common files\installshield\engine\6\intel 32\objectps.dll, c:\program files\common files\installshield\engine\6\intel 32\iuser.dll, c:\program files\common files\installshield\iscript\iscript.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\aticim.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\isrt.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\_isres.dll, c:\documents and settings\fei\local settings\temp\{9b94be6f-7ca3-4c40-a266-62667ff746cc}\ati2saag.exe",
2/02/2009 5:49 PM,Low,"uninstall.exe made 17 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",c:\program files\winrar\uninstall.exe,"Monday, 2 February 2009 5:49 PM","System Configuration, Windows Startup Settings","\REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR.ZIP\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR.REV\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver\UninstallString, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver\DisplayIcon, c:\documents and settings\fei\start menu\programs\winrar\winrar.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\fei\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\fei\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\all users\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\all users\start menu\programs\winrar\console rar manual.lnk",
Category: Silent Mode
Date & Time,Risk Level,Activity,Status,Recommended Action
1/02/2009 8:33 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:48 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:15 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:15 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 6:56 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 5:31 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 5:27 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 2:54 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 2:54 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 1:58 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 1:20 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 12:08 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 11:31 AM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 11:27 AM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 10:41 AM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 8:28 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 7:31 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 7:28 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 6:43 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 6:42 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 6:41 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 11:08 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 10:22 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:25 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 9:23 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:22 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 9:09 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 8:32 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 8:31 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 7:49 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:24 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:18 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:10 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:10 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 3:48 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 3:38 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 3:37 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 10:51 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 10:49 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 9:29 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 9:27 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:55 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:55 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:42 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:41 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:38 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:37 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
Category: Norton Product Tamper Protection
Date & Time,Risk Level,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
31/01/2009 11:53 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 11:53 PM",c:\windows\explorer.exe,1952,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3112,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 11:18 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 11:18 PM",c:\windows\explorer.exe,1952,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3112,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 4:00 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 4:00 PM",c:\windows\explorer.exe,1976,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3080,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 1:45 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 1:45 PM",c:\windows\explorer.exe,1976,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,2244,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 3:55 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 3:55 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1588,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:18 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:18 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3416,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:16 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:16 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,4004,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:15 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:15 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,1540,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:15 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:15 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1588,Send Terminate Message to Window,Unauthorized access blocked
30/01/2009 12:52 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Friday, 30 January 2009 12:52 AM",c:\windows\explorer.exe,1892,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3956,Send Terminate Message to Window,Unauthorized access blocked
29/01/2009 10:00 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Thursday, 29 January 2009 10:00 PM",e:\software\setupvirtualclonedrive5301.exe,1340,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1344,Open Process,Unauthorized access logged
29/01/2009 11:50 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Thursday, 29 January 2009 11:50 AM",c:\windows\explorer.exe,1824,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2848,Send Terminate Message to Window,Unauthorized access blocked
28/01/2009 2:14 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Wednesday, 28 January 2009 2:14 PM",c:\windows\explorer.exe,1928,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3044,Send Terminate Message to Window,Unauthorized access blocked
28/01/2009 2:03 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Wednesday, 28 January 2009 2:03 PM",c:\windows\explorer.exe,1912,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2524,Send Terminate Message to Window,Unauthorized access blocked
27/01/2009 10:54 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Tuesday, 27 January 2009 10:54 PM",c:\windows\explorer.exe,1908,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2812,Send Terminate Message to Window,Unauthorized access blocked
27/01/2009 4:54 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:54 PM",c:\windows\system32\mrt.exe,1696,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 4:49 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:49 PM",c:\windows\softwaredistribution\download\0f4651f0d7e6cb55f0a983df3c4744d0\update\update.exe,2876,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 4:47 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:47 PM",c:\windows\system32\mrt.exe,2684,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 3:42 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 3:42 PM",c:\windows\system32\wbem\wmiadap.exe,1696,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,480,Open Process,Unauthorized access logged
27/01/2009 3:30 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 3:30 PM",c:\windows\system32\wbem\wmiadap.exe,2636,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1232,Open Process,Unauthorized access logged
my computer is infected by W32.Gammima.AG apparently according to Norton, the software keep saying it has been completely resolved, but the auto protection pop up and said it just block W32.Gammima.AG again, and it keep coming back everyday, omg, how am I suppose to fix this. I have COMODO installed as well.
thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:33:40 PM, on 2/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Brownie\BrstsWnd.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Program Files\Brownie\brpjp04a.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VIA\RAID\vialogsv.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.EXE
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\IPSBHO.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VRAID Log Service - Unknown owner - C:\Program Files\VIA\RAID\vialogsv.exe
--
End of file - 4518 bytes
Norton Antivirus 2009 protection history:
Category: Intrusion Prevention
Date & Time,Risk Level,Activity,Status,Recommended Action,Category
2/02/2009 5:11 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
2/02/2009 5:11 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
2/02/2009 5:11 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
2/02/2009 9:08 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
1/02/2009 5:01 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
1/02/2009 8:49 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 10:56 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
31/01/2009 12:50 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
30/01/2009 8:42 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090129.001,Detected,No Action Required,Intrusion Prevention
30/01/2009 10:07 AM,Low,Intrusion Prevention is monitoring 1312 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
30/01/2009 1:55 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
29/01/2009 6:10 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
29/01/2009 9:59 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:42 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 6:36 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:58 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 5:33 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 2:05 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090120.002,Detected,No Action Required,Intrusion Prevention
28/01/2009 10:19 AM,Low,Intrusion Prevention is monitoring 1311 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
28/01/2009 7:05 AM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 10:55 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20090115.001,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:28 PM,Low,Intrusion Prevention is monitoring 1308 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:12 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 4:02 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:34 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention has been enabled,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention Engine version: 4.1.0.61 Definitions Set version: 20080826.006,Detected,No Action Required,Intrusion Prevention
27/01/2009 3:27 PM,Low,Intrusion Prevention is monitoring 1178 signatures. Driver version: 9.0.0.172,Detected,No Action Required,Intrusion Prevention
Category: Resolved Security Risks
Date & Time,Risk Level,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State
31/01/2009 2:36 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 3:55 PM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.30.024,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 2:16 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
Category: Scan Results
Date & Time,Risk Level,Activity,Status,Recommended Action,Task Name,Scan Time,Total items scanned,Files & Directories,Registry Entries,Processes & Start-Up Items,Network & Browser Items,Other,Trusted Files,Skipped Files,Total Security Risks Detected,Total Security Risks Resolved,Total Security Risks Requiring Attention
27/01/2009 5:21 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:21 (d:h:m:s),"2,522",649,133,"1,634",12,4,157,0,0,0,0
27/01/2009 4:30 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:16 (d:h:m:s),"2,487",624,131,"1,626",12,4,0,570,0,0,0
27/01/2009 4:26 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:41 (d:h:m:s),"2,535",624,131,"1,674",12,4,0,0,0,0,0
30/01/2009 10:10 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:26 (d:h:m:s),"2,899",695,169,"1,929",12,4,176,0,0,0,0
1/02/2009 5:12 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:25 (d:h:m:s),"2,822",675,171,"1,870",12,4,198,0,0,0,0
30/01/2009 5:24 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:31 (d:h:m:s),"2,973",709,172,"1,986",12,4,176,0,0,0,0
28/01/2009 10:20 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:17 (d:h:m:s),"2,623",645,136,"1,736",12,4,156,0,0,0,0
2/02/2009 9:28 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:28 (d:h:m:s),"2,950",702,171,"1,971",12,4,203,0,0,0,0
29/01/2009 6:21 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:29 (d:h:m:s),"2,627",643,137,"1,741",12,4,156,0,0,0,0
29/01/2009 11:11 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:30 (d:h:m:s),"2,732",671,137,"1,818",12,4,156,0,0,0,0
1/02/2009 9:09 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:28 (d:h:m:s),"2,958",699,171,"1,982",12,4,194,0,0,0,0
31/01/2009 1:25 PM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:34 (d:h:m:s),"3,109",713,171,"2,119",12,4,196,0,0,0,0
28/01/2009 7:35 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:22 (d:h:m:s),"2,576",639,136,"1,695",12,4,157,0,0,0,0
30/01/2009 2:09 AM,Low,Idle Quick Scan results,Completed,Resolved - No Action,Idle Quick Scan,0:00:00:27 (d:h:m:s),"2,778",673,169,"1,830",12,4,177,0,0,0,0
Category: Quarantine
Date & Time,Risk Level,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State
31/01/2009 2:36 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 3:55 PM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.30.024,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
31/01/2009 2:16 AM,High,W32.Gammima.AG detected by Auto-Protect,Removed,Resolved - No Action,Auto-Protect,2009.01.29.051,108.2.4.3,W32.Gammima.AG,Virus,File Based,Fully removed
Category: System Activity Monitoring
Date & Time,Risk Level,Activity,Status,Recommended Action,Program,Last Updated,Affected Area,Modified resource,Target file
30/01/2009 2:53 PM,Low,"setupsg.exe made 25 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\drivers\scanner\lide25_11010wnenz\setupsg.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,"c:\documents and settings\fei\local settings\temp\wzse0.tmp\delsg.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\setupsg.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\usbscan.sys, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnql25\cnql1213.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\balco.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cfine2.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cisds.ds, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\cnqu110.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\iop.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\itlib32.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\jda_cimg.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\libblc.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\msvcrt.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\nbs4mb.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\nbscor4m.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\rmslantc.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\rstcol.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\scanintf.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\scrprmv.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\sgui.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\sgui_res.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\tpm.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\twain_32.dll, c:\documents and settings\fei\local settings\temp\wzse0.tmp\cnqsg110\twunk_32.exe, c:\documents and settings\fei\local settings\temp\wzse0.tmp\instal~1\setup.exe",
28/01/2009 12:55 PM,Low,"foobar2000_0.9.6.1.exe made 26 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",e:\software\foobar2000_0.9.6.1.exe,"Wednesday, 28 January 2009 12:55 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\nslcf.tmp\system.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\nsdialogs.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\uac.dll, c:\documents and settings\fei\local settings\temp\nslcf.tmp\startmenu.dll, c:\program files\foobar2000\foobar2000.exe, c:\program files\foobar2000\shared.dll, c:\program files\foobar2000\shellext32.dll, c:\program files\foobar2000\foobar2000 shell associations updater.exe, c:\program files\foobar2000\components\foo_input_std.dll, c:\program files\foobar2000\components\foo_ui_std.dll, c:\program files\foobar2000\components\foo_cdda.dll, c:\program files\foobar2000\components\foo_albumlist.dll, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\foobar2000\DisplayIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\foobar2000\UninstallString, c:\program files\foobar2000\components\foo_dsp_std.dll, c:\program files\foobar2000\components\foo_rgscan.dll, c:\program files\foobar2000\components\foo_converter.dll, c:\program files\foobar2000\uninstall.exe, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000 - website.url, c:\documents and settings\all users\start menu\programs\foobar2000\uninstall.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\uninstall.lnk, c:\documents and settings\fei\application data\microsoft\internet explorer\quick launch\foobar2000.lnk, c:\documents and settings\fei\application data\microsoft\internet explorer\quick launch\foobar2000.lnk, c:\documents and settings\all users\start menu\programs\foobar2000\foobar2000 - website.url",
27/01/2009 3:53 PM,Low,"issetup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\ati\support\6-11-pre-r300_xp-2k_dd_ccc_wdm_38185\issetup.exe,"Tuesday, 27 January 2009 3:53 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
29/01/2009 10:01 PM,Low,"devcon32.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\nst7e.tmp\devcon32.exe,"Thursday, 29 January 2009 10:01 PM",System Configuration,c:\windows\system32\drivers\vclone.sys,
2/02/2009 5:50 PM,Low,"keygen.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required","c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\keygen\keygen.exe","Monday, 2 February 2009 5:50 PM",System Configuration,"c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\keygen\keygen.exe",
27/01/2009 3:54 PM,Low,"setup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\ati\support\6-11-pre-r300_xp-2k_dd_ccc_wdm_38185\driver\setup.exe,"Tuesday, 27 January 2009 3:54 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
29/01/2009 10:01 PM,Low,"setupvirtualclonedrive5301.exe made 31 modifications to your computer., Resource, Resource, Resource",Detected,"No Action Required, No Action Required",e:\software\setupvirtualclonedrive5301.exe,"Thursday, 29 January 2009 10:01 PM","System Configuration, Windows Startup Settings, Windows System Settings","c:\documents and settings\fei\local settings\temp\nst7e.tmp\installhelp.dll, c:\program files\elaborate bytes\virtualclonedrive\installhelp.dll, c:\program files\elaborate bytes\virtualclonedrive\devcon32.exe, c:\program files\elaborate bytes\virtualclonedrive\vcd-uninst.exe, c:\program files\elaborate bytes\virtualclonedrive\elbydvd.exe, c:\program files\elaborate bytes\virtualclonedrive\helplauncher.exe, \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\ElbyDelay\ImagePath, \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\ElbyDelay\Type, c:\program files\elaborate bytes\virtualclonedrive\vcddaemon.exe, c:\program files\elaborate bytes\virtualclonedrive\vcdmount.exe, c:\program files\elaborate bytes\virtualclonedrive\vcdprefs.exe, c:\documents and settings\fei\local settings\temp\nst7e.tmp\elbyvcdshell.dll, c:\program files\elaborate bytes\virtualclonedrive\elbyvcdshell.dll, c:\windows\system32\elbycdio.dll, c:\windows\system32\elbyvcd.dll, c:\windows\system32\drivers\elbycdio.sys, c:\windows\system32\drivers\elbydelay.sys, c:\documents and settings\fei\local settings\temp\nst7e.tmp\vclone.sys, c:\documents and settings\fei\local settings\temp\nst7e.tmp\devcon32.exe, \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VirtualCloneDrive, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualCloneDrive\UninstallString, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\uninstall.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\uninstall.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\manual.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\manual.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive revision history.lnk, c:\documents and settings\all users\start menu\programs\elaborate bytes\virtualclonedrive\virtual clonedrive revision history.lnk",C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
29/01/2009 6:40 PM,Low,"klcodec445s.tmp made 111 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\is-sp5a1.tmp\klcodec445s.tmp,"Thursday, 29 January 2009 6:40 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_regdll.tmp, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_shfoldr.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\_isetup\_iscrypt.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\ffspkcfg.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\wincpuid.dll, c:\documents and settings\fei\local settings\temp\is-6e4n4.tmp\psvince.dll, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.avi\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.divx\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpg\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpeg\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mpe\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mp2v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m1v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2v\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.wmv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.asf\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ogm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ogv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mkv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mka\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mp4\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.hdmov\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.flv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2ts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.m2t\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mts\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3g2\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gp2\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.3gpp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.mov\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.qt\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ra\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.ram\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rmvb\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rmm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rpm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rt\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.rv\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.smi\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\mplayerc.smil\DefaultIcon, c:\program files\k-lite codec pack\is-60phk.tmp, c:\program files\k-lite codec pack\is-s4dmb.tmp, c:\program files\k-lite codec pack\tools\is-jumf5.tmp, c:\program files\k-lite codec pack\ffdshow\is-k4m51.tmp, c:\program files\k-lite codec pack\ffdshow\is-g97h4.tmp, c:\program files\k-lite codec pack\ffdshow\is-sv5lr.tmp, c:\program files\k-lite codec pack\ffdshow\is-fp8mm.tmp, c:\program files\k-lite codec pack\ffdshow\is-oat96.tmp, c:\program files\k-lite codec pack\ffdshow\is-f57cu.tmp, c:\program files\k-lite codec pack\ffdshow\is-s2i3u.tmp, c:\program files\k-lite codec pack\ffdshow\is-328c3.tmp, c:\program files\k-lite codec pack\ffdshow\is-fv2v4.tmp, c:\program files\k-lite codec pack\ffdshow\is-rp8hj.tmp, c:\program files\k-lite codec pack\ffdshow\is-i5gu6.tmp, c:\program files\k-lite codec pack\media player classic\is-9dcc8.tmp, c:\program files\k-lite codec pack\media player classic\is-5i43n.tmp, c:\program files\k-lite codec pack\filters\is-1t7r9.tmp, c:\program files\k-lite codec pack\filters\is-h03sc.tmp, c:\program files\k-lite codec pack\filters\is-bq6q0.tmp, c:\program files\k-lite codec pack\filters\is-hnf7f.tmp, c:\program files\k-lite codec pack\filters\haali\is-lh290.tmp, c:\program files\k-lite codec pack\filters\haali\is-irm80.tmp, c:\program files\k-lite codec pack\filters\haali\is-p59n5.tmp, c:\program files\k-lite codec pack\filters\haali\is-2o185.tmp, c:\program files\k-lite codec pack\filters\haali\is-kgdng.tmp, c:\program files\k-lite codec pack\filters\haali\is-bi67e.tmp, c:\program files\k-lite codec pack\filters\haali\is-7db7e.tmp, c:\program files\k-lite codec pack\filters\haali\is-s90oi.tmp, c:\program files\k-lite codec pack\filters\is-mg34g.tmp, c:\windows\system32\is-418ff.tmp, c:\program files\k-lite codec pack\tools\is-ojaij.tmp, c:\program files\k-lite codec pack\tools\is-bf1vd.tmp, c:\program files\k-lite codec pack\tools\is-45vhp.tmp, c:\program files\k-lite codec pack\tools\is-2g68r.tmp, \REGISTRY\MACHINE\SOFTWARE\Classes\rtsp\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\pnm\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1\UninstallString, c:\documents and settings\all users\start menu\programs\k-lite codec pack\media player classic.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\media player classic.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\codec tweak tool.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\reset to recommended settings.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\reset to recommended settings.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\cyberlink mpeg-2 decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\cyberlink mpeg-2 decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\directvobsub.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\directvobsub.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow audio decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow audio decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow video decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\ffdshow video decoder.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali media splitter.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali media splitter.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali video renderer.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\configuration\haali video renderer.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\mediainfo.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\mediainfo.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\vobsubstrip.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\tools\vobsubstrip.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\faq.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\faq.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\website.url, c:\documents and settings\all users\start menu\programs\k-lite codec pack\uninstall\uninstall k-lite codec pack.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\uninstall\uninstall k-lite codec pack.lnk, c:\documents and settings\all users\start menu\programs\k-lite codec pack\help\website.url",
30/01/2009 2:53 PM,Low,"setup.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\wzse0.tmp\instal~1\setup.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,c:\program files\common files\installshield\engine\6\intel 32\temp.000,
2/02/2009 5:50 PM,Low,"adc.tmp made 62 modifications to your System Configuration., Resource, Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\is-ptudp.tmp\adc.tmp,"Monday, 2 February 2009 5:50 PM","System Configuration, Windows Startup Settings","c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\_isetup\_regdll.tmp, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\_isetup\_shfoldr.dll, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\adcmigrator.exe, c:\documents and settings\fei\local settings\temp\is-gf1sh.tmp\sqlite3.dll, c:\program files\xemicomputers\active desktop calendar\is-cumrj.tmp, c:\program files\xemicomputers\active desktop calendar\is-h7pj3.tmp, c:\program files\xemicomputers\active desktop calendar\is-dvgls.tmp, c:\program files\xemicomputers\active desktop calendar\is-cur60.tmp, c:\program files\xemicomputers\active desktop calendar\is-npi1o.tmp, c:\program files\xemicomputers\active desktop calendar\is-qnv5o.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-v1o8a.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ohgng.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-jhd3k.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-aed1k.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-jsets.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-22bab.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-a504s.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-vgimq.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-mnbin.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-b3s9g.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-6atjo.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-2oh06.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ghpsi.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-u0m1o.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-6spg0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-tu3sg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-optl6.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-9h3jr.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-dd2td.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-7peuh.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-3j0qa.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-lrekg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-d823n.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-d7jd0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-5d1dn.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-595cg.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ktmel.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\calendar icons\is-ts62m.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-7svl4.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-a10oi.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-14kdv.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-9g5ea.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-j6bqa.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-2ma9e.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-h63le.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-3tfil.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\marking icons\is-n5kb0.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\today & pin icons\is-mt23u.tmp, c:\program files\xemicomputers\active desktop calendar\icon library\today & pin icons\is-s2ssq.tmp, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Active Desktop Calendar_is1\UninstallString, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar on the web.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar on the web.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\uninstall active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\uninstall active desktop calendar.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar help file.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\active desktop calendar help file.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\readme.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\readme.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\license agreement.lnk, c:\documents and settings\all users\start menu\programs\active desktop calendar\license agreement.lnk",
27/01/2009 3:38 PM,Low,"idriver.exe made 8 modifications to your System Configuration., Resource, Resource",Detected,"No Action Required, No Action Required",c:\program files\common files\installshield\driver\7\intel 32\idriver.exe,"Tuesday, 27 January 2009 3:38 PM","Windows Startup Settings, System Configuration","c:\documents and settings\all users\start menu\programs\administrative tools, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\isrt.dll, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\_isres.dll, c:\documents and settings\fei\local settings\temp\{20d4a895-748c-4d88-871c-fdb1695b0169}\_isuser.dll, c:\documents and settings\fei\local settings\temp\msi7.tmp, c:\documents and settings\fei\local settings\temp\msi8.tmp, c:\program files\via\setup\viaagp\agpdrvnt.dll, c:\windows\system32\difxapi.dll",
2/02/2009 5:49 PM,Low,"wrar380.exe made 23 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\wrar380.exe,"Monday, 2 February 2009 5:49 PM",System Configuration,"c:\program files\winrar\rar.exe, c:\program files\winrar\rarextloader.exe, c:\program files\winrar\uninstall.exe, c:\program files\winrar\unrar.exe, c:\program files\winrar\winrar.exe, c:\program files\winrar\formats\7zxa.dll, c:\program files\winrar\rarext.dll, c:\program files\winrar\rarext64.dll, c:\program files\winrar\formats\unacev2.dll, c:\program files\winrar\formats\7z.fmt, c:\program files\winrar\formats\ace.fmt, c:\program files\winrar\formats\arj.fmt, c:\program files\winrar\formats\bz2.fmt, c:\program files\winrar\formats\cab.fmt, c:\program files\winrar\formats\gz.fmt, c:\program files\winrar\formats\iso.fmt, c:\program files\winrar\formats\lzh.fmt, c:\program files\winrar\formats\tar.fmt, c:\program files\winrar\formats\uue.fmt, c:\program files\winrar\formats\z.fmt, c:\program files\winrar\default.sfx, c:\program files\winrar\wincon.sfx, c:\program files\winrar\zip.sfx",
27/01/2009 3:56 PM,Low,"install.exe made 45 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\program files\analog devices\soundmax\install.exe,"Tuesday, 27 January 2009 3:56 PM",System Configuration,"c:\windows\system32\drivers\set4d.tmp, c:\windows\system32\set51.tmp, c:\windows\lastgood\system32\drivers\stream.sys, c:\windows\temp\old4f.tmp, c:\windows\system32\drivers\stream.sys, c:\windows\system32\drivers\set53.tmp, c:\windows\system32\ksproxy.ax, c:\windows\system32\set55.tmp, c:\windows\system32\drivers\drmk.sys, c:\windows\system32\ksuser.dll, c:\windows\system32\drivers\set57.tmp, c:\windows\system32\set59.tmp, c:\windows\system32\drivers\portcls.sys, c:\windows\system32\drivers\set5d.tmp, c:\windows\lastgood\system32\wdmaud.drv, c:\windows\temp\old5b.tmp, c:\windows\system32\wdmaud.drv, c:\windows\lastgood\system32\drivers\ks.sys, c:\windows\system32\drivers\ks.sys, c:\windows\system32\drivers\smwdm.sys, c:\windows\system32\drivers\senfilt.sys, c:\windows\system32\drivers\aeaudio.sys, c:\windows\system32\a3d.dll, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSPCLOCK, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSPQM, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\MSKSSRV, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SYSAUDIO, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DRMKAUD2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_KMIXER0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_KMIXER1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_AEC2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SWMIDI2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC1, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_DMUSIC2, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_WDMAUD, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SPLITTER0, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\WDM_SPLITTER1",
30/01/2009 2:53 PM,Low,"setupsg.exe made 21 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\local settings\temp\wzse0.tmp\setupsg.exe,"Friday, 30 January 2009 2:53 PM",System Configuration,"c:\canoscan\cnql25\cnql25\cnql1213.dll, c:\canoscan\cnql25\cnqsg110\balco.dll, c:\canoscan\cnql25\cnqsg110\cfine2.dll, c:\canoscan\cnql25\cnqsg110\cisds.ds, c:\canoscan\cnql25\cnqsg110\cnqu110.dll, c:\canoscan\cnql25\cnqsg110\iop.dll, c:\canoscan\cnql25\cnqsg110\itlib32.dll, c:\canoscan\cnql25\cnqsg110\jda_cimg.dll, c:\canoscan\cnql25\cnqsg110\libblc.dll, c:\canoscan\cnql25\cnqsg110\msvcrt.dll, c:\canoscan\cnql25\cnqsg110\nbs4mb.dll, c:\canoscan\cnql25\cnqsg110\nbscor4m.dll, c:\canoscan\cnql25\cnqsg110\rmslantc.dll, c:\canoscan\cnql25\cnqsg110\rstcol.dll, c:\canoscan\cnql25\cnqsg110\scanintf.dll, c:\canoscan\cnql25\cnqsg110\scrprmv.dll, c:\canoscan\cnql25\cnqsg110\sgui.dll, c:\canoscan\cnql25\cnqsg110\sgui_res.dll, c:\canoscan\cnql25\cnqsg110\tpm.dll, c:\canoscan\cnql25\cnqsg110\twain_32.dll, c:\canoscan\cnql25\cnqsg110\twunk_32.exe",
27/01/2009 4:02 PM,Low,"smax4.exe made 2 modifications to your computer., Resource",Detected,"No Action Required, No Action Required",c:\program files\analog devices\soundmax\smax4.exe,"Tuesday, 27 January 2009 4:02 PM",System Configuration,"\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SoundMax",
2/02/2009 5:50 PM,Low,"adc.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\documents and settings\fei\desktop\xemicomputers.active.desktop.calendar.v7.69.090119.winall.incl.keygen-crd\setup\adc.exe,"Monday, 2 February 2009 5:50 PM",System Configuration,c:\documents and settings\fei\local settings\temp\is-ptudp.tmp\adc.tmp,
29/01/2009 6:40 PM,Low,"klcodec445s.exe modified your System Configuration., Resource",Detected,"No Action Required, No Action Required",e:\software\codecs\klcodec445s.exe,"Thursday, 29 January 2009 6:40 PM",System Configuration,c:\documents and settings\fei\local settings\temp\is-sp5a1.tmp\klcodec445s.tmp,
27/01/2009 3:54 PM,Low,"ikernel.exe made 9 modifications to your System Configuration., Resource",Detected,"No Action Required, No Action Required",c:\program files\common files\installshield\engine\6\intel 32\ikernel.exe,"Tuesday, 27 January 2009 3:54 PM",System Configuration,"c:\program files\common files\installshield\engine\6\intel 32\ilog.dll, c:\program files\common files\installshield\engine\6\intel 32\ctor.dll, c:\program files\common files\installshield\engine\6\intel 32\objectps.dll, c:\program files\common files\installshield\engine\6\intel 32\iuser.dll, c:\program files\common files\installshield\iscript\iscript.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\aticim.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\isrt.dll, c:\documents and settings\fei\local settings\temp\{43801800-cfee-11d2-a41b-006097b55ad3}\_isres.dll, c:\documents and settings\fei\local settings\temp\{9b94be6f-7ca3-4c40-a266-62667ff746cc}\ati2saag.exe",
2/02/2009 5:49 PM,Low,"uninstall.exe made 17 modifications to your computer., Resource, Resource",Detected,"No Action Required, No Action Required",c:\program files\winrar\uninstall.exe,"Monday, 2 February 2009 5:49 PM","System Configuration, Windows Startup Settings","\REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR.ZIP\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Classes\WinRAR.REV\DefaultIcon, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver\UninstallString, \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver\DisplayIcon, c:\documents and settings\fei\start menu\programs\winrar\winrar.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\fei\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\fei\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\fei\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\all users\start menu\programs\winrar\winrar help.lnk, c:\documents and settings\all users\start menu\programs\winrar\console rar manual.lnk, c:\documents and settings\all users\start menu\programs\winrar\console rar manual.lnk",
Category: Silent Mode
Date & Time,Risk Level,Activity,Status,Recommended Action
1/02/2009 8:33 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:51 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:48 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 7:15 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 7:15 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 6:56 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
1/02/2009 5:31 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
1/02/2009 5:27 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 2:54 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 2:54 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 1:58 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 1:20 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 12:08 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 11:31 AM,Low,Light Silent Mode turned on.,Completed,No Action Required
30/01/2009 11:27 AM,Low,Light Silent Mode turned off.,Completed,No Action Required
30/01/2009 10:41 AM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 8:28 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 7:31 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 7:28 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 6:43 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
29/01/2009 6:42 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
29/01/2009 6:41 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 11:08 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 10:22 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:25 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 9:23 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:22 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 9:09 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 9:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 8:32 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 8:31 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 7:49 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:24 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:18 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:10 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:10 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 4:09 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 3:48 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
28/01/2009 3:38 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
28/01/2009 3:37 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 10:51 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 10:49 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 9:29 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 9:27 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:55 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:55 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:42 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:41 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
27/01/2009 3:38 PM,Low,Light Silent Mode turned off.,Completed,No Action Required
27/01/2009 3:37 PM,Low,Light Silent Mode turned on.,Completed,No Action Required
Category: Norton Product Tamper Protection
Date & Time,Risk Level,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
31/01/2009 11:53 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 11:53 PM",c:\windows\explorer.exe,1952,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3112,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 11:18 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 11:18 PM",c:\windows\explorer.exe,1952,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3112,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 4:00 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 4:00 PM",c:\windows\explorer.exe,1976,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,3080,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 1:45 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 1:45 PM",c:\windows\explorer.exe,1976,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,2244,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 3:55 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 3:55 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1588,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:18 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:18 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3416,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:16 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:16 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,4004,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:15 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:15 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,1540,Send Terminate Message to Window,Unauthorized access blocked
31/01/2009 2:15 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Saturday, 31 January 2009 2:15 AM",c:\windows\explorer.exe,1724,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1588,Send Terminate Message to Window,Unauthorized access blocked
30/01/2009 12:52 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Friday, 30 January 2009 12:52 AM",c:\windows\explorer.exe,1892,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3956,Send Terminate Message to Window,Unauthorized access blocked
29/01/2009 10:00 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Thursday, 29 January 2009 10:00 PM",e:\software\setupvirtualclonedrive5301.exe,1340,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1344,Open Process,Unauthorized access logged
29/01/2009 11:50 AM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Thursday, 29 January 2009 11:50 AM",c:\windows\explorer.exe,1824,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2848,Send Terminate Message to Window,Unauthorized access blocked
28/01/2009 2:14 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Wednesday, 28 January 2009 2:14 PM",c:\windows\explorer.exe,1928,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\MCUI32.exe,3044,Send Terminate Message to Window,Unauthorized access blocked
28/01/2009 2:03 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Wednesday, 28 January 2009 2:03 PM",c:\windows\explorer.exe,1912,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2524,Send Terminate Message to Window,Unauthorized access blocked
27/01/2009 10:54 PM,Medium,Unauthorized access blocked (Send Terminate Message to Window),Blocked,No Action Required,"Tuesday, 27 January 2009 10:54 PM",c:\windows\explorer.exe,1908,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,2812,Send Terminate Message to Window,Unauthorized access blocked
27/01/2009 4:54 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:54 PM",c:\windows\system32\mrt.exe,1696,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 4:49 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:49 PM",c:\windows\softwaredistribution\download\0f4651f0d7e6cb55f0a983df3c4744d0\update\update.exe,2876,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 4:47 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 4:47 PM",c:\windows\system32\mrt.exe,2684,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,636,Open Process,Unauthorized access logged
27/01/2009 3:42 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 3:42 PM",c:\windows\system32\wbem\wmiadap.exe,1696,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,480,Open Process,Unauthorized access logged
27/01/2009 3:30 PM,Medium,Unauthorized access logged (Open Process),Logged,No Action Required,"Tuesday, 27 January 2009 3:30 PM",c:\windows\system32\wbem\wmiadap.exe,2636,C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe,1232,Open Process,Unauthorized access logged