Type,Date/Time,Action,Description
Program Guard,22/03/2008 08:12:29,Allowed,C:\WINDOWS\system32\vedxg6ame4.exe(2220) wants to start C:\WINDOWS\system32\drwtsn32.exe(0)
Firewall: User decision,22/03/2008 08:09:56,Allowed,"C:\WINDOWS\system32\krmvovwp.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:09:55,Allowed,C:\WINDOWS\TEMP\un.bat
Autorun Detected,22/03/2008 08:09:52,Allowed,C:\WINDOWS\Temp\comsvr32.exe
Autorun Detected,22/03/2008 08:09:45,Allowed,C:\WINDOWS\system32\krmvovwp.exe
Program Guard,22/03/2008 08:09:43,Allowed,C:\WINDOWS\17PHolmes27.exe
Program Guard,22/03/2008 08:09:43,Allowed,C:\WINDOWS\system32\krmvovwp.exe
Firewall: User decision,22/03/2008 08:09:42,Allowed,"C:\Program Files\tmp1.exe, Outgoing access allowed, Port: 53"
Firewall: User decision,22/03/2008 08:09:37,Allowed,"C:\Program Files\tmp3.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:09:36,Allowed,C:\WINDOWS\system32\vedxga5me3.exe(3688) wants to start C:\WINDOWS\17PHolmes27.exe(0)
Program Guard,22/03/2008 08:09:35,Allowed,C:\WINDOWS\system32\vedxga8me6.exe(1712) wants to start C:\WINDOWS\system32\cmd.exe(0)
Firewall: User decision,22/03/2008 08:09:33,Allowed,"C:\Program Files\tmp1.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:09:24,Allowed,C:\WINDOWS\Temp\comsvr32.exe(3580) wants to start C:\WINDOWS\system32\krmvovwp.exe(0)
Firewall: Automatic decision,22/03/2008 08:09:22,Allowed,"C:\Program Files\tmp2.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:09:22,Allowed,C:\Program Files\tmp1.exe(3948) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Program Guard,22/03/2008 08:09:22,Allowed,C:\Program Files\tmp3.exe(1760) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Firewall: User decision,22/03/2008 08:09:22,Allowed,"C:\Program Files\tmp2.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 08:09:08,Allowed,"C:\WINDOWS\system32\vedxga5me3.exe, Outgoing access allowed, Port: 80"
Firewall: Automatic decision,22/03/2008 08:09:08,Allowed,"C:\WINDOWS\system32\vedxga8me6.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 08:09:08,Allowed,"C:\WINDOWS\system32\vedxg6ame4.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:09:07,Allowed,C:\Program Files\tmp1.exe(3724) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Program Guard,22/03/2008 08:09:05,Allowed,C:\Program Files\tmp2.exe(1292) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Firewall: User decision,22/03/2008 08:09:04,Allowed,"C:\WINDOWS\Temp\comsvr32.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 08:09:03,Allowed,"C:\WINDOWS\system32\vedxga5me3.exe, Outgoing access allowed, Port: 53"
Firewall: User decision,22/03/2008 08:08:41,Allowed,"C:\WINDOWS\system32\vedxga8me6.exe, Incoming access allowed, Port: 10100"
Autorun Detected,22/03/2008 08:08:32,Allowed,C:\WINDOWS\system32\vedxg6ame4.exe
Program Guard,22/03/2008 08:08:30,Allowed,C:\WINDOWS\system32\vedxga8me6.exe
Program Guard,22/03/2008 08:08:29,Allowed,C:\WINDOWS\system32\dllgh8jkd1q7.exe(4036) wants to allocate memory in C:\WINDOWS\system32\vedxga5me3.exe(3688)
Program Guard,22/03/2008 08:08:29,Allowed,C:\WINDOWS\system32\vedxga8me6.exe
Program Guard,22/03/2008 08:08:29,Allowed,C:\WINDOWS\Temp\comsvr32.exe
Firewall: User decision,22/03/2008 08:08:23,Allowed,"C:\WINDOWS\system32\vedxga3me2.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:08:13,Allowed,C:\Documents and Settings\LocalService\Application Data\mcrupdate.exe(3940) wants to allocate memory in C:\Program Files\Internet Explorer\IEXPLORE.EXE(2980)
Program Guard,22/03/2008 08:08:13,Allowed,C:\WINDOWS\system32\vedxg6ame4.exe
Program Guard,22/03/2008 08:08:09,Allowed,C:\WINDOWS\system32\vedxga5me3.exe
Program Guard,22/03/2008 08:08:08,Allowed,C:\WINDOWS\Installer\{2e5046f3-209a-4d05-8d36-f94a1c19bbb5}\zip.dll
Program Guard,22/03/2008 08:08:07,Allowed,C:\WINDOWS\Temp\bx18dxv.dat
Program Guard,22/03/2008 08:07:41,Allowed,C:\WINDOWS\system32\vedxga3me2.exe
Program Guard,22/03/2008 08:07:30,Allowed,C:\Program Files\instaler.exe(2032) wants to start C:\WINDOWS\system32\rundll32.exe(0)
Program Guard,22/03/2008 08:07:10,Allowed,C:\Program Files\tmp0.exe
Program Guard,22/03/2008 08:07:10,Allowed,C:\WINDOWS\system32\vedxga4me1.exe
Program Guard,22/03/2008 08:07:10,Allowed,C:\WINDOWS\system32\vedxga4me1.exe
Program Guard,22/03/2008 08:06:53,Allowed,C:\WINDOWS\system32\maxpaynowti.exe
Program Guard,22/03/2008 08:06:51,Allowed,C:\WINDOWS\system32\dllgh8jkd1q7.exe(1920) wants to start C:\WINDOWS\system32\vedxga4me1.exe(0)
Program Guard,22/03/2008 08:06:50,Allowed,C:\Program Files\antiviirus.exe(3976) wants to start C:\Program Files\tmp0.exe(0)
Program Guard,22/03/2008 08:06:47,Allowed,C:\Program Files\instaler.exe
Program Guard,22/03/2008 08:06:47,Allowed,C:\WINDOWS\system32\dllgh8jkd1q7.exe(4036) wants to start C:\WINDOWS\system32\vedxga4me1.exe(0)
Program Guard,22/03/2008 08:06:45,Allowed,C:\WINDOWS\system32\dllgh8jkd1q5.exe(3408) wants to start C:\WINDOWS\system32\maxpaynowti.exe(0)
Firewall: Automatic decision,22/03/2008 08:06:42,Allowed,"C:\Program Files\Internet Explorer\IEXPLORE.EXE, Outgoing access allowed, Port: 25"
Program Guard,22/03/2008 08:06:41,Blocked,C:\Program Files\BraveSentry\BraveSentry.exe
Autorun Detected,22/03/2008 08:06:33,Allowed,C:\Program Files\antiviirus.exe
Firewall: User decision,22/03/2008 08:06:33,Allowed,"C:\WINDOWS\system32\dllgh8jkd1q5.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:06:24,Allowed,C:\WINDOWS\system32\dllgh8jkd1q2.exe(2476) wants to start C:\Program Files\BraveSentry\BraveSentry.exe(0)
Program Guard,22/03/2008 08:06:24,Allowed,C:\Program Files\antiviirus.exe
Program Guard,22/03/2008 08:06:21,Allowed,C:\Documents and Settings\LocalService\Application Data\mcrupdate.exe
Firewall: User decision,22/03/2008 08:06:20,Allowed,"C:\Program Files\tmp547968.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 08:06:16,Allowed,"C:\WINDOWS\system32\dllgh8jkd1q7.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:06:16,Allowed,C:\Documents and Settings\LocalService\Application Data\printer.exe(3632) wants to start C:\Documents and Settings\LocalService\Application Data\mcrupdate.exe(0)
Firewall: User decision,22/03/2008 08:06:16,Allowed,"C:\WINDOWS\Temp\mso13.exe, Outgoing access allowed, Port: 53"
Firewall: User decision,22/03/2008 08:06:11,Allowed,"C:\WINDOWS\system32\dllgh8jkd1q7.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:06:10,Allowed,C:\WINDOWS\system32\dllgh8jkd1q5.exe
Autorun Detected,22/03/2008 08:06:10,Allowed,C:\WINDOWS\system32\dllgh8jkd1q5.exe
Program Guard,22/03/2008 08:06:10,Allowed,C:\Program Files\tmp547968.exe(2784) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Program Guard,22/03/2008 08:06:10,Allowed,C:\Program Files\tmp515578.exe(2620) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Firewall: User decision,22/03/2008 08:06:10,Allowed,"C:\Program Files\tmp515578.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:06:04,Allowed,C:\WINDOWS\Temp\mso13.exe(2356) wants to start C:\WINDOWS\system32\rundll32.exe(0)
Firewall: User decision,22/03/2008 08:06:02,Allowed,"C:\WINDOWS\system32\dllgh8jkd1q2.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 08:05:58,Allowed,"C:\WINDOWS\system32\dllgh8jkd1q7.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:05:58,Allowed,C:\WINDOWS\system32\dllgh8jkd1q6.exe
Program Guard,22/03/2008 08:05:53,Allowed,C:\Documents and Settings\LocalService\Application Data\printer.exe(3632) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Program Guard,22/03/2008 08:05:51,Allowed,C:\Program Files\tmp577687.exe
Program Guard,22/03/2008 08:05:49,Allowed,C:\Program Files\tmp575218.exe
Program Guard,22/03/2008 08:05:49,Allowed,C:\Program Files\tmp556781.exe
Program Guard,22/03/2008 08:05:44,Allowed,C:\Program Files\tmp555546.exe
Program Guard,22/03/2008 08:05:41,Allowed,C:\Program Files\tmp555531.exe
Program Guard,22/03/2008 08:05:39,Allowed,C:\Program Files\tmp555421.exe
Program Guard,22/03/2008 08:05:38,Allowed,C:\Program Files\tmp553906.exe
Program Guard,22/03/2008 08:05:38,Allowed,C:\Program Files\tmp555453.exe
Program Guard,22/03/2008 08:05:38,Allowed,C:\Program Files\tmp553453.exe
Program Guard,22/03/2008 08:05:38,Allowed,C:\Program Files\tmp535578.exe
Program Guard,22/03/2008 08:05:38,Allowed,C:\WINDOWS\Temp\mso13.exe(2356) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(2468)
Autorun Detected,22/03/2008 08:05:30,Allowed,C:\WINDOWS\system32\dllgh8jkd1q2.exe
Program Guard,22/03/2008 08:05:24,Allowed,C:\WINDOWS\system32\dllgh8jkd1q7.exe
Program Guard,22/03/2008 08:05:24,Allowed,C:\Program Files\tmp516593.exe
Program Guard,22/03/2008 08:05:24,Allowed,C:\WINDOWS\Temp\2468.tmp
Program Guard,22/03/2008 08:05:24,Allowed,C:\WINDOWS\Temp\msram.exe(2560) wants to remotely control C:\WINDOWS\system32\svchost.exe(1076)
Program Guard,22/03/2008 08:03:27,Allowed,C:\Program Files\tmp515578.exe
Program Guard,22/03/2008 08:03:26,Allowed,C:\WINDOWS\system32\dllgh8jkd1q2.exe
Program Guard,22/03/2008 08:03:26,Allowed,C:\WINDOWS\Temp\mso13.exe
Program Guard,22/03/2008 08:03:12,Allowed,C:\WINDOWS\system32\dllgh8jkd1q1.exe
New Browser Helper Object Detected,22/03/2008 08:03:10,Allowed,C:\WINDOWS\system32\msram.dll
FGCatchUrl
Firewall: Automatic decision,22/03/2008 08:03:08,Allowed,"C:\WINDOWS\system32\rundll32.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:03:08,Allowed,C:\WINDOWS\Temp\codec.exe(3228) wants to start C:\WINDOWS\Temp\mso13.exe(0)
Firewall: Automatic decision,22/03/2008 08:03:08,Allowed,"C:\WINDOWS\system32\rundll32.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:02:58,Allowed,C:\WINDOWS\Installer\{18026afb-b693-4d43-ad6a-50e75de36dfc}\ChkAlrt.dll
Firewall: User decision,22/03/2008 08:02:58,Allowed,"C:\WINDOWS\Temp\codec.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:02:58,Allowed,c:\tempdel.bat
Firewall: Automatic decision,22/03/2008 08:02:58,Allowed,"C:\WINDOWS\Temp\codec.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:02:53,Allowed,C:\WINDOWS\Temp\codec.exe
Firewall: Automatic decision,22/03/2008 08:02:53,Allowed,"C:\WINDOWS\Temp\iframestat.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 08:02:52,Allowed,"C:\WINDOWS\Temp\iframestat.exe, Outgoing access allowed, Port: 53"
Firewall: User decision,22/03/2008 08:02:47,Allowed,"C:\Documents and Settings\LocalService\Application Data\printer.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 08:02:47,Allowed,"C:\Documents and Settings\LocalService\Application Data\printer.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:02:47,Allowed,C:\WINDOWS\Temp\rUdKGSSK.exe(2216) wants to start C:\WINDOWS\system32\rundll32.exe(0)
Program Guard,22/03/2008 08:02:47,Allowed,C:\WINDOWS\Temp\msram.exe(2560) wants to start C:\WINDOWS\Temp\codec.exe(0)
Autorun Detected,22/03/2008 08:02:44,Allowed,C:\WINDOWS\Temp\iframestat.exe
Program Guard,22/03/2008 08:02:44,Allowed,C:\WINDOWS\TEMP\A.bat
Autorun Detected,22/03/2008 08:02:42,Allowed,C:\Documents and Settings\LocalService\Application Data\printer.exe
Program Guard,22/03/2008 08:02:28,Allowed,C:\WINDOWS\Temp\msram.exe
Program Guard,22/03/2008 08:02:17,Allowed,C:\WINDOWS\Temp\babkinepaxnut.exe
Program Guard,22/03/2008 08:02:17,Allowed,C:\WINDOWS\Temp\iframestat.exe(1912) wants to start C:\WINDOWS\system32\netsh.exe(0)
Program Guard,22/03/2008 08:02:11,Allowed,C:\Documents and Settings\LocalService\Application Data\printer.exe
Program Guard,22/03/2008 08:02:07,Allowed,C:\WINDOWS\Temp\newoxo.exe(2404) wants to start C:\WINDOWS\Temp\msram.exe(0)
Program Guard,22/03/2008 08:02:05,Allowed,C:\WINDOWS\Temp\iframestat.exe
Program Guard,22/03/2008 08:02:04,Allowed,C:\WINDOWS\Temp\installs.exe(3340) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 08:01:49,Allowed,C:\WINDOWS\Temp\lokocash.exe(3024) wants to start C:\Documents and Settings\LocalService\Application Data\printer.exe(0)
Program Guard,22/03/2008 08:01:44,Allowed,C:\WINDOWS\system32\bskl463.exe
Program Guard,22/03/2008 08:01:44,Allowed,C:\WINDOWS\Temp\installs.exe
Firewall: Automatic decision,22/03/2008 08:01:44,Allowed,"C:\WINDOWS\system32\svchost.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:01:44,Allowed,C:\WINDOWS\Temp\newoxo.exe(2404) wants to remotely control C:\WINDOWS\system32\svchost.exe(1076)
Firewall: Automatic decision,22/03/2008 08:01:44,Allowed,"C:\Program Files\Internet Explorer\IEXPLORE.EXE, Incoming access allowed, Port: 53157"
Program Guard,22/03/2008 08:01:39,Allowed,C:\WINDOWS\Temp\lokocash.exe
Program Guard,22/03/2008 08:01:37,Allowed,C:\WINDOWS\system32\bskl374.exe(1940) wants to allocate memory in C:\WINDOWS\system32\winlogon.exe(628)
Program Guard,22/03/2008 08:01:35,Allowed,C:\WINDOWS\Temp\newoxo.exe
Program Guard,22/03/2008 08:01:31,Allowed,C:\WINDOWS\system32\bskl374.exe
Program Guard,22/03/2008 08:01:30,Allowed,C:\WINDOWS\Temp\sh.exe
Program Guard,22/03/2008 08:01:27,Allowed,C:\WINDOWS\system32\bskl414.exe(2260) wants to start C:\WINDOWS\Temp\sh.exe(0)
Program Guard,22/03/2008 08:01:26,Allowed,C:\WINDOWS\TEMP\uninst0061659.bat
Firewall: Automatic decision,22/03/2008 08:01:23,Allowed,"C:\Program Files\Internet Explorer\IEXPLORE.EXE, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:01:23,Allowed,C:\WINDOWS\system32\bskl414.exe
Program Guard,22/03/2008 08:01:23,Allowed,C:\WINDOWS\system32\bskl428.exe(4028) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 08:01:23,Allowed,C:\WINDOWS\Temp\csrssc.exe(2680) wants to remotely control C:\Program Files\Internet Explorer\IEXPLORE.EXE(3720)
Firewall: Automatic decision,22/03/2008 08:01:23,Allowed,"C:\WINDOWS\system32\bskl428.exe, Outgoing access allowed, Port: 80"
Firewall: Automatic decision,22/03/2008 08:01:23,Allowed,"C:\Program Files\Internet Explorer\IEXPLORE.EXE, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 08:01:15,Allowed,C:\WINDOWS\Temp\1A80.tmp(4032) wants to start C:\WINDOWS\system32\cmd.exe(0)
Firewall: User decision,22/03/2008 08:01:13,Allowed,"C:\WINDOWS\system32\bskl428.exe, Incoming access allowed, Port: 10100"
Program Guard,22/03/2008 08:01:08,Allowed,C:\WINDOWS\TEMP\_it.bat
Program Guard,22/03/2008 08:01:06,Allowed,C:\WINDOWS\Temp\1A80.tmp
Program Guard,22/03/2008 08:01:04,Allowed,C:\WINDOWS\system32\bskl428.exe
Program Guard,22/03/2008 08:01:02,Allowed,C:\WINDOWS\system32\bskl452.exe(2904) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 08:01:00,Allowed,C:\WINDOWS\system32\bskl406.exe(2232) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 08:00:58,Allowed,C:\WINDOWS\Temp\BN2.tmp(2468) wants to start C:\WINDOWS\system32\cmd.exe(0)
Firewall: User decision,22/03/2008 08:00:54,Allowed,"C:\WINDOWS\Temp\csrssc.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 08:00:54,Allowed,"C:\WINDOWS\Temp\csrssc.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 08:00:54,Allowed,"C:\WINDOWS\system32\bskl468.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 08:00:54,Allowed,"C:\WINDOWS\system32\bskl468.exe, Outgoing access allowed, Port: 80"
Program Guard,22/03/2008 08:00:48,Allowed,C:\WINDOWS\TEMP\7hjhffd.bat
Program Guard,22/03/2008 08:00:46,Allowed,C:\WINDOWS\system32\drivers\grande48.sys
Autorun Detected,22/03/2008 08:00:41,Allowed,C:\WINDOWS\Temp\csrssc.exe
Autorun Detected,22/03/2008 08:00:40,Allowed,C:\WINDOWS\System32\drivers\Fkr85.sys
Program Guard,22/03/2008 08:00:27,Allowed,C:\WINDOWS\Temp\2972649635.exe(1452) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 08:00:24,Allowed,C:\WINDOWS\system32\bskl452.exe
Autorun Detected,22/03/2008 08:00:23,Allowed,C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
Autorun Detected,22/03/2008 08:00:20,Allowed,C:\WINDOWS\system32\drivers\grande48.sys
Firewall: Automatic decision,22/03/2008 08:00:15,Allowed,"C:\WINDOWS\system32\svchost.exe, Outgoing access allowed, Port: 25"
Firewall: Automatic decision,22/03/2008 08:00:15,Allowed,"C:\WINDOWS\system32\svchost.exe, Outgoing access allowed, Port: 2546"
Program Guard,22/03/2008 08:00:13,Allowed,C:\WINDOWS\Temp\BN2.tmp
Autorun Detected,22/03/2008 08:00:06,Allowed,C:\WINDOWS\system32\drivers\spools.exe
Program Guard,22/03/2008 08:00:06,Allowed,C:\WINDOWS\system32\p2hhr.bat
Program Guard,22/03/2008 08:00:01,Allowed,C:\WINDOWS\system32\bskl406.exe
Program Guard,22/03/2008 07:59:53,Allowed,C:\WINDOWS\Temp\winlogan.exe(2912) wants to start C:\WINDOWS\Temp\2972649635.exe(0)
Program Guard,22/03/2008 07:59:50,Allowed,C:\WINDOWS\system32\bskl387.exe(2536) wants to start C:\WINDOWS\Temp\BN2.tmp(0)
Firewall: Automatic decision,22/03/2008 07:59:39,Allowed,"C:\WINDOWS\system32\bskl230.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 07:59:39,Allowed,"C:\WINDOWS\system32\bskl230.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 07:59:39,Allowed,C:\WINDOWS\system32\bskl468.exe(3168) wants to set global hook to (C:\WINDOWS\system32\ftpdll.dll)
Program Guard,22/03/2008 07:59:33,Allowed,C:\WINDOWS\system32\bskl468.exe(3168) wants to start C:\WINDOWS\system32\reg.exe(0)
Firewall: Automatic decision,22/03/2008 07:59:26,Allowed,"C:\WINDOWS\Temp\winlogan.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 07:59:26,Allowed,"C:\WINDOWS\Temp\winlogan.exe, Outgoing access allowed, Port: 53"
Firewall: User decision,22/03/2008 07:59:25,Allowed,"C:\WINDOWS\system32\bskl387.exe, Outgoing access allowed, Port: 80"
Autorun Detected,22/03/2008 07:59:20,Allowed,C:\WINDOWS\Temp\winlogan.exe
Program Guard,22/03/2008 07:59:18,Allowed,C:\WINDOWS\system32\bskl468.exe
Program Guard,22/03/2008 07:59:06,Allowed,C:\WINDOWS\Temp\winlogan.exe
Program Guard,22/03/2008 07:58:59,Allowed,C:\WINDOWS\TEMP\removeMe6744.bat(0) wants to start C:\WINDOWS\system32\ping.exe(0)
Program Guard,22/03/2008 07:58:57,Allowed,C:\WINDOWS\Temp\2369524635.exe
Program Guard,22/03/2008 07:58:53,Allowed,C:\WINDOWS\system32\bskl387.exe
New Browser Helper Object Detected,22/03/2008 07:58:48,Allowed,C:\WINDOWS\system32\Kf9467g.dll
C:\WINDOWS\system32\Kf9467g.dll
Program Guard,22/03/2008 07:58:45,Allowed,C:\WINDOWS\TEMP\removeMe6744.bat
New Browser Helper Object Detected,22/03/2008 07:58:42,Allowed,C:\WINDOWS\system32\H4dj24g.dll
C:\WINDOWS\system32\H4dj24g.dll
Firewall: Automatic decision,22/03/2008 07:58:22,Allowed,"C:\WINDOWS\system32\regsvr32.exe, Outgoing access allowed, Port: 80"
Firewall: Automatic decision,22/03/2008 07:58:21,Allowed,"C:\WINDOWS\system32\regsvr32.exe, Outgoing access allowed, Port: 53"
Program Guard,22/03/2008 07:58:20,Allowed,C:\WINDOWS\system32\bskl446.exe(280) wants to start C:\WINDOWS\system32\cmd.exe(0)
Program Guard,22/03/2008 07:58:18,Allowed,C:\WINDOWS\system32\bskl230.exe(1132) wants to start C:\WINDOWS\system32\regsvr32.exe(0)
Program Guard,22/03/2008 07:58:15,Allowed,C:\WINDOWS\system32\bskl230.exe
Program Guard,22/03/2008 07:58:07,Allowed,C:\WINDOWS\system32\bskl446.exe
Program Guard,22/03/2008 07:58:06,Allowed,C:\WINDOWS\system32\winlast.exe(1928) wants to start C:\WINDOWS\system32\bskl446.exe(0)
Firewall: User decision,22/03/2008 07:57:54,Allowed,"C:\WINDOWS\system32\winlast.exe, Outgoing access allowed, Port: 53"
Firewall: Automatic decision,22/03/2008 07:57:44,Allowed,"C:\Documents and Settings\Malekal_morte\Desktop\winlast.exe, Outgoing access allowed, Port: 80"
Firewall: User decision,22/03/2008 07:57:44,Allowed,"C:\Documents and Settings\Malekal_morte\Desktop\winlast.exe, Outgoing access allowed, Port: 53"
Autorun Detected,22/03/2008 07:57:39,Allowed,C:\Documents and Settings\Malekal_morte\Desktop\winlast.exe
Program Guard,22/03/2008 07:57:20,Allowed,C:\Documents and Settings\Malekal_morte\Desktop\winlast.exe
Service started,22/03/2008 07:55:42,None,C:\Program Files\Tall Emu\Online Armor\oasrv.exe
System boot,22/03/2008 07:55:42,None,System boot at: 22/03/2008 07:54:35