Sie sind auf Seite 1von 115

Date: Two weeks ago (events: 524)

My Protection (events: 11)


8/15/2010 9:38:04 PM Databases are obsolete Kaspersky Internet Security
8/15/2010 7:36:16 PM Protection is not running Kaspersky Internet Secur
ity
8/15/2010 7:30:54 PM Databases are obsolete Kaspersky Internet Security
8/15/2010 6:57:26 PM Protection is not running Kaspersky Internet Secur
ity
8/15/2010 5:28:15 PM Databases are obsolete Kaspersky Internet Security
8/15/2010 3:06:05 PM Protection is not running Kaspersky Internet Secur
ity
8/15/2010 6:47:11 AM Databases are obsolete Kaspersky Internet Security
8/15/2010 6:29:42 AM Databases are obsolete Kaspersky Internet Security
8/15/2010 3:09:45 AM Databases are obsolete Kaspersky Internet Security
8/15/2010 3:08:16 AM Protection is not running Kaspersky Internet Secur
ity
8/15/2010 2:25:40 AM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
File Anti-Virus
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
File Anti-Virus
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
File Anti-Virus
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
File Anti-Virus
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
File Anti-Virus
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/15/2010 7:30:49 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/15/2010 2:25:41 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Anti-Spam
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Anti-Spam
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Anti-Spam
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Anti-Spam
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Anti-Spam
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 297)
8/15/2010 8:46:05 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 8:45:20 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 8:45:19 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 8:45:08 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 8:44:28 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 8:44:28 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 8:44:15 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 9:39:25 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/15/2010 9:38:16 PM Microsoft DirectX Diagnostic Tool Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Application Control
8/15/2010 7:32:18 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/15/2010 7:31:46 PM AU_.EXE Placed in group Low Restricted High val
ue of threat rating calculated heuristically
8/15/2010 7:31:45 PM uninstall_plugin.exe Placed in group Low Rest
ricted High value of threat rating calculated heuristically
8/15/2010 7:31:29 PM INSTALL_FLASH_PLAYER.EXE Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Application Control
8/15/2010 6:39:15 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 6:39:01 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 6:18:35 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 6:18:29 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 5:42:34 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 5:42:23 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 5:30:22 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 5:29:39 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 5:29:33 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Application Control
8/15/2010 2:12:24 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 2:12:06 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 1:43:25 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 1:43:16 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 1:12:20 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 12:19:41 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 12:19:05 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 11:05:06 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 11:04:58 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 10:57:09 AM Allowed: Using program interfaces of other process
FIREFOX.VBS Using program interfaces of other process c:\documents and
settings\bagoes\local settings\temp\firefox.vbs Using program interfaces
of other process
8/15/2010 10:57:09 AM Allowed: Access to critical system objects FIREFOX.
VBS Access to critical system objects Access to critical syste
m objects
8/15/2010 10:53:45 AM Allowed: Using system program interfaces (DNS) INSTALL_
INSTALL_FLASH_PLAYER.EXE Use DNS caching system for conversion fiashpia
yer.soft-2010.net Using system program interfaces (DNS)
8/15/2010 10:51:56 AM Allowed: Using program interfaces of other process
FIREFOX.VBS Using program interfaces of other process c:\documents and
settings\bagoes\local settings\temp\firefox.vbs Using program interfaces
of other process
8/15/2010 10:51:55 AM Allowed: Access to critical system objects FIREFOX.
VBS Access to critical system objects Access to critical syste
m objects
8/15/2010 10:51:54 AM FIREFOX.VBS Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 10:51:14 AM Adobe® Flash® Player Installer/Uninstaller 10.1 r53
Placed in group Trusted Signed by the digital signature of entrusted manufacture
rs
8/15/2010 10:49:47 AM Allowed: Using system program interfaces (DNS) INSTALL_
INSTALL_FLASH_PLAYER.EXE Use DNS caching system for conversion fiashpia
yer.soft-2010.net Using system program interfaces (DNS)
8/15/2010 10:49:47 AM INSTALL_INSTALL_FLASH_PLAYER.EXE Placed i
n group Low Restricted High value of threat rating calculated heuristically
8/15/2010 10:34:51 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 10:34:28 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 10:34:09 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 9:46:46 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 9:46:44 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 9:46:34 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 9:46:20 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 9:46:20 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 9:46:05 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 8:23:46 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 8:23:45 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 8:23:35 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 8:23:21 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 8:23:21 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 8:23:10 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 6:43:41 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 6:43:40 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 6:43:30 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 6:43:20 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 6:43:20 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 6:43:05 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 6:41:02 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 6:41:01 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 6:40:50 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 6:40:37 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 6:40:37 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 6:40:17 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 6:36:13 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 6:36:10 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 6:35:47 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 6:35:29 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 6:35:29 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 6:35:12 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 6:30:12 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/15/2010 6:29:25 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Application Control
8/15/2010 5:15:54 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 5:15:22 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 5:15:08 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:33:54 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 4:33:52 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 4:33:32 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 4:33:23 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 4:33:23 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 4:32:01 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 4:31:26 AM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/15/2010 4:31:25 AM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/15/2010 4:31:25 AM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/15/2010 4:31:19 AM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/15/2010 4:31:02 AM DrWatson Postmortem Debugger Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:27:37 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 4:27:34 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 4:27:23 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 4:27:12 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 4:27:12 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 4:26:55 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 4:26:13 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 4:26:13 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 4:24:39 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/15/2010 4:24:31 AM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 4:24:29 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/15/2010 4:24:22 AM Auto Update Utility Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:24:19 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/15/2010 4:24:17 AM HSUpdate Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:24:06 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 4:24:06 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 4:23:52 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 4:23:50 AM PBLauncher Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:13:40 AM Winamp Agent Placed in group Trusted Known on
the database of the known software
8/15/2010 4:13:08 AM Winamp Placed in group Trusted Signed by the di
gital signature of entrusted manufacturers
8/15/2010 4:12:58 AM EMusicClient Placed in group Trusted Known on
the database of the known software
8/15/2010 4:12:54 AM bundle3.exe Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:12:43 AM NS539.TMP Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:12:37 AM Winamp IE Toolbar Server Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:12:31 AM WINAMP_TOOLBAR_IE.EXE Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:12:31 AM NS536.TMP Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:12:28 AM BUNDLE2.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:12:01 AM TCP/IP Ping Command Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:12:01 AM NS52D.TMP Placed in group Trusted Known on
the database of the known software
8/15/2010 4:11:46 AM PX Install Application Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:11:44 AM PXSETUP.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:11:21 AM Winamp Installer Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:10:57 AM RealNetworks Helper Application Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:10:16 AM RealShare Launcher Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:10:15 AM RealConverter Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:09:56 AM RealNetworks Event Launcher Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:09:55 AM RealNetworks Scheduler Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:09:53 AM RealPlayer Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:09:22 AM REALPLAY_MOUNTPOINTS.EXE Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:09:21 AM setreg.exe Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:09:08 AM DEFENC.REG Placed in group Trusted Known on
the database of the known software
8/15/2010 4:09:08 AM defenc.exe Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:08:47 AM RealUpgrade Launcher Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:08:21 AM Allowed: Setting debug privileges UPGRADE.MSI
Setting debug privileges Setting debug privileges
8/15/2010 4:08:21 AM Allowed: Using program interfaces of other process
UPGRADE.MSI Using program interfaces of other process c:\documents and
settings\bagoes\local settings\temp\~rnsetu0\upgrade\upgrade.msi Using pr
ogram interfaces of other process
8/15/2010 4:08:21 AM Allowed: Exiting Microsoft Windows UPGRADE.MSI
Windows shutdown Exiting Microsoft Windows
8/15/2010 4:08:18 AM Allowed: Setting debug privileges UPGRADE.MSI
Setting debug privileges Setting debug privileges
8/15/2010 4:08:18 AM Allowed: Using program interfaces of other process
UPGRADE.MSI Using program interfaces of other process c:\documents and
settings\bagoes\local settings\temp\~rnsetu0\upgrade\upgrade.msi Using pr
ogram interfaces of other process
8/15/2010 4:08:18 AM Allowed: Exiting Microsoft Windows UPGRADE.MSI
Windows shutdown Exiting Microsoft Windows
8/15/2010 4:08:17 AM UPGRADE.MSI Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 4:07:45 AM CONVERTER_INSTALLER.EXE Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:06:37 AM Shell executable of Setup program Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:06:04 AM Adobe® Flash® Player Plugin Installer Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:05:51 AM Firefox Placed in group Trusted Signed by the di
gital signature of entrusted manufacturers
8/15/2010 4:05:27 AM setup.exe Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 4:05:14 AM Firefox Placed in group Trusted Signed by the di
gital signature of entrusted manufacturers
8/15/2010 4:04:27 AM Network Diagnostic for Windows XP Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 4:04:22 AM WebToolBar component Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 4:02:43 AM MATS_RUN.IEADDON.EXE Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:31:51 AM Internet Explorer Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:26:51 AM Safely Remove Hardware applet Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 3:24:32 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 3:24:32 AM PBLauncher Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:24:20 AM PBConfig.exe Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:23:23 AM Microsoft Application Error Reporting Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 3:22:39 AM Windows Error Reporting Dump Reporting Tool
Placed in group Trusted Signed by the digital signature of entrusted manufacture
rs
8/15/2010 3:21:18 AM Allowed: Using system program interfaces (DNS) update.e
xe Use DNS caching system for conversion info.cabalonline.co.id Using sy
stem program interfaces (DNS)
8/15/2010 3:21:14 AM update.exe Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:21:11 AM cabal.exe Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:20:51 AM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/15/2010 3:20:49 AM TODO: <File description> Placed in group
Low Restricted High value of threat rating calculated heuristically
8/15/2010 3:20:38 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 3:20:38 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 3:20:27 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 3:20:02 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/15/2010 3:20:02 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/15/2010 3:19:56 AM PointBlank Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:19:48 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/15/2010 3:19:48 AM PBLauncher Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:17:36 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/15/2010 3:17:16 AM Audition Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:16:38 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/15/2010 3:16:06 AM Audition Client Patcher Placed in group Low Rest
ricted High value of threat rating calculated heuristically
8/15/2010 3:11:18 AM Windows Genuine Advantage-Benachrichtigungen
Placed in group Low Restricted High value of threat rating calculated heuristic
ally
8/15/2010 3:11:01 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/15/2010 3:09:37 AM hpwuSchd Application Placed in group Trusted
Known on the database of the known software
8/15/2010 3:09:36 AM Userinit Logon Application Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Application Control
8/15/2010 3:07:55 AM Windows Logon UI Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:07:23 AM CROSSFIRE.EXE Placed in group Low Restricted
High value of threat rating calculated heuristically
8/15/2010 3:07:10 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:06:50 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:06:36 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:06:23 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:06:07 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:05:55 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:05:44 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:05:29 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:05:11 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:04:54 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:04:38 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:04:14 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:03:48 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:03:33 AM WMI Placed in group Trusted Signed by the di
gital signature of entrusted manufacturers
8/15/2010 3:03:31 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:03:14 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:03:04 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:02:50 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:02:50 AM Microsoft Office Excel Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:02:40 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:02:30 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:02:10 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:01:54 AM HP Customer Participation Program Placed i
n group Trusted Known on the database of the known software
8/15/2010 3:01:52 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:01:36 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:01:32 AM HP Digital Imaging Toolbox Placed in group
Trusted Known on the database of the known software
8/15/2010 3:01:31 AM HP Print Utility Placed in group Trusted
Known on the database of the known software
8/15/2010 3:01:24 AM HP Installer Setup Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:01:24 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:01:16 AM HP Installer Reconnect Plug-In Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 3:01:14 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:01:02 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:00:50 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:00:39 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:00:24 AM UPDATE.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 3:00:08 AM WebReg application Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 3:00:06 AM HP All-in-One Launcher Utility Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 3:00:05 AM hpqdirec.exe Placed in group Trusted Known on
the database of the known software
8/15/2010 3:00:01 AM TODO: <File description> Placed in group
Trusted Known on the database of the known software
8/15/2010 3:00:00 AM HP Installer Setup Wrapper/3rd party installer P
lug in Placed in group Trusted Signed by the digital signature of entrusted man
ufacturers
8/15/2010 2:59:39 AM GPCore COM object Placed in group Trusted
Known on the database of the known software
8/15/2010 2:59:29 AM Hewlett-Packard Product Assistant Placed i
n group Trusted Known on the database of the known software
8/15/2010 2:59:28 AM HP Installer CD Launch Plug-In Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:59:26 AM HP CUE Alert Popup Window Objects Placed i
n group Trusted Known on the database of the known software
8/15/2010 2:59:25 AM HP Installer Post Software Launcher Plug-In
Placed in group Trusted Signed by the digital signature of entrusted manufacture
rs
8/15/2010 2:59:23 AM HP CUE Status Root Placed in group Trusted
Known on the database of the known software
8/15/2010 2:59:21 AM HP Installer Setup Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:59:18 AM HP Installer Plug-In Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:59:11 AM DJ_SF_03_D2500_PRODUCTCONTEXT.MSI Placed i
n group Trusted Known on the database of the known software
8/15/2010 2:59:01 AM HP Digital Imaging Monitor Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:58:54 AM HPZFWX01.EXE Placed in group Trusted Known on
the database of the known software
8/15/2010 2:57:22 AM HPZDUI01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:57:07 AM YTB_7.0.5.0_1.4.1_HP_UBER_SETUP_.EXE Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:56:50 AM HpqSRmon Placed in group Trusted Known on
the database of the known software
8/15/2010 2:56:38 AM HP Autoplay Module Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:55:58 AM MSI47F.TMP Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:55:57 AM MSI47E.tmp Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:55:57 AM MSI47D.TMP Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:55:56 AM MSI47C.TMP Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:55:25 AM HP Smart Web Printing add-on for Internet Explor
er Placed in group Trusted Signed by the digital signature of entrusted man
ufacturers
8/15/2010 2:54:40 AM HP CUE DeviceDiscovery User Placed in group
Low Restricted High value of threat rating calculated heuristically
8/15/2010 2:54:39 AM HP CUE DeviceDiscovery Service Placed in group
Trusted Known on the database of the known software
8/15/2010 2:54:37 AM HP CUE Context Manager Objects Placed in group
Trusted Known on the database of the known software
8/15/2010 2:53:35 AM HP CUE Context Manager Objects Placed in group
Trusted Known on the database of the known software
8/15/2010 2:51:44 AM HPZARP01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:51:40 AM HPZCDL01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:51:28 AM HPZMSI01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:51:02 AM FIXERR1714.EXE Placed in group Trusted Known on
the database of the known software
8/15/2010 2:50:58 AM HPZRCV01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:50:51 AM HPZPRL01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:50:50 AM Verify Class ID Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:50:49 AM Windows Progman Group Converter Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:50:48 AM Run Once Wrapper Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:50:09 AM Attribute Utility Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:50:05 AM HPXPSCHK.EXE Placed in group Trusted Known on
the database of the known software
8/15/2010 2:49:58 AM HPZSUI01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:55 AM HPQBHP01.EXE Placed in group Trusted Known on
the database of the known software
8/15/2010 2:49:48 AM HPZCHK01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:44 AM HPZOPT01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:14 AM HPZWUP01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:12 AM HPZNOP01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:05 AM USBREADY.EXE Placed in group Trusted Known on
the database of the known software
8/15/2010 2:49:02 AM HPZREIN01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:49:00 AM HPZSHL01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:48:57 AM Y_HP_INTL_DETECT.EXE Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:48:56 AM HPZWRP01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:48:53 AM HPZPSC01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:46:07 AM Disk Defragmenter NTFS Module Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:46:06 AM Disk Defragmenter Module Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:40:51 AM Logon Screen Saver Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:30:52 AM HPZPNP01.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:30:42 AM HPZSETUP.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:30:35 AM HPZSTUB.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:30:29 AM Add Hardware Device Library Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:28:36 AM SETUP.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:28:29 AM Image Mastering API Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:28:29 AM Windows Shell Common Dll Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:46 AM Kaspersky Anti-Virus GUI Windows part Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:46 AM Kaspersky Internet Security Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:46 AM Windows Update Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:25:46 AM Windows® installer Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM CTF Loader Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Windows Security Center Notification App
Placed in group Trusted Signed by the digital signature of entrusted manufacture
rs
8/15/2010 2:25:45 AM Application Layer Gateway Service Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Windows Explorer Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Spooler SubSystem App Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Generic Host Process for Win32 Services Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM ATI External Event Utility EXE Module Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM LSA Shell (Export Version) Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Services and Controller app Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:45 AM Windows NT Logon Application Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:44 AM Client Server Runtime Process Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:44 AM Windows NT Session Manager Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 50)
8/15/2010 8:46:09 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 9:39:33 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 9:38:18 PM Denied Microsoft DirectX Diagnostic Tool Open
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:39:18 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:18:38 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 5:42:38 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 5:30:27 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 5:29:41 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:57:34 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:12:28 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 1:43:31 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 12:19:47 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 11:05:09 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 10:55:42 AM Denied Adobe® Flash® Player Installer/Uninstaller 10.1 r53
Open C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 10:51:58 AM Denied WMI Open C:\Program Files\Kaspersky Lab\K
aspersky Internet Security 2010\avp.exe
8/15/2010 10:51:15 AM Denied Adobe® Flash® Player Installer/Uninstaller 10.1 r53
Open C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 10:34:56 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 9:47:00 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 8:24:10 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:44:11 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:43:50 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:41:16 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:36:21 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 6:30:19 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 5:14:26 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:34:11 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:34:08 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:31:27 AM Denied DrWatson Postmortem Debugger Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:31:27 AM Denied DrWatson Postmortem Debugger Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:27:54 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:27:50 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:24:47 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:24:44 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:12:58 AM Denied Winamp Installer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:12:58 AM Denied Winamp Installer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:12:30 AM Denied BUNDLE2.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:12:29 AM Denied BUNDLE2.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:10:02 AM Denied RealPlayer Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:10:02 AM Denied RealPlayer Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:08:10 AM Denied CONVERTER_INSTALLER.EXE Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:08:10 AM Denied CONVERTER_INSTALLER.EXE Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:07:12 AM Denied Shell executable of Setup program Open
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 4:07:12 AM Denied Shell executable of Setup program Open
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 3:17:45 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 3:11:18 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:51:01 AM Denied HPZSETUP.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:50:07 AM Denied HPZSHL01.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:50:07 AM Denied HPZSHL01.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:49:08 AM Denied HPZSETUP.EXE Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/15/2010 2:46:09 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 74)
8/15/2010 8:46:57 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 8:46:56 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 8:46:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 8:46:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 8:46:05 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 8:45:20 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Proactive Defense
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Proactive Defense
8/15/2010 6:39:21 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 6:39:21 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 6:18:41 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 6:18:41 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 5:42:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 5:42:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 5:30:52 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 5:30:52 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 5:30:36 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 5:30:36 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Proactive Defense
8/15/2010 2:12:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 2:12:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 1:43:50 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 1:43:50 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 12:20:12 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 12:20:11 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 11:05:18 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 11:05:18 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 10:35:10 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 10:35:10 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 10:34:50 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/15/2010 10:34:30 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/15/2010 9:46:59 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 9:46:59 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 9:46:55 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 9:46:46 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 8:24:08 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 8:24:08 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 8:24:06 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 8:23:47 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:43:48 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:43:48 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:43:46 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:43:41 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:41:15 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:41:15 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:41:12 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:41:02 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:37:11 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 6:37:11 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 6:36:24 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:36:24 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 6:36:16 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:36:13 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Proactive Defense
8/15/2010 4:34:07 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:34:07 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:34:03 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 4:33:54 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 4:27:50 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:27:50 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:27:46 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 4:27:37 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 4:24:44 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:24:44 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/15/2010 4:24:39 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 4:24:31 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/15/2010 3:18:10 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 3:18:10 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/15/2010 3:17:57 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 3:17:57 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/15/2010 3:17:39 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/15/2010 3:17:37 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Proactive Defense
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 6)
8/15/2010 9:37:54 PM Application is not activated Kaspersky Internet Secur
ity
8/15/2010 7:30:44 PM Application is not activated Kaspersky Internet Secur
ity
8/15/2010 5:28:03 PM Application is not activated Kaspersky Internet Secur
ity
8/15/2010 6:28:37 AM Invalid key Kaspersky Internet Security
8/15/2010 6:28:37 AM Application is not activated Kaspersky Internet Secur
ity
8/15/2010 3:09:28 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
Firewall
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
Firewall
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
Firewall
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
Firewall
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
Firewall
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 6)
8/15/2010 9:37:58 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/15/2010 7:30:48 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/15/2010 5:28:06 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/15/2010 6:28:45 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/15/2010 3:09:34 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/15/2010 2:25:40 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 16)
8/15/2010 6:00:53 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/15/2010 5:58:17 PM Task started Kaspersky Internet Security
Rootkit Scan
8/15/2010 2:59:03 PM Task completed Kaspersky Internet Security
Quick Scan
8/15/2010 2:57:59 PM Task started Kaspersky Internet Security
Quick Scan
8/15/2010 9:37:10 AM Task stopped Kaspersky Internet Security
Full Scan
8/15/2010 9:14:32 AM Task started Kaspersky Internet Security
Full Scan
8/15/2010 7:02:47 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/15/2010 6:58:51 AM Task started Kaspersky Internet Security
Rootkit Scan
8/15/2010 3:41:30 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/15/2010 3:39:42 AM Task started Kaspersky Internet Security
Rootkit Scan
8/15/2010 3:15:44 AM Task stopped Kaspersky Internet Security
Virus Scan
8/15/2010 3:11:33 AM Task started Kaspersky Internet Security
Virus Scan
8/15/2010 2:57:42 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/15/2010 2:55:48 AM Task started Kaspersky Internet Security
Rootkit Scan
8/15/2010 2:26:59 AM Task stopped Kaspersky Internet Security
Full Scan
8/15/2010 2:26:11 AM Task started Kaspersky Internet Security
Full Scan
My Update Center (events: 28)
8/15/2010 6:43:20 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 6:23:20 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 6:03:20 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 5:43:21 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 3:04:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 2:44:09 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 2:24:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 2:04:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 1:43:53 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 1:23:53 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 1:03:56 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 12:43:54 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 12:23:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 12:03:53 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 11:43:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 11:23:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 11:03:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 10:43:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 10:23:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 10:03:55 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 9:43:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 9:23:57 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 9:03:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/15/2010 6:47:10 AM Task completed Kaspersky Internet Security
My Update Center Not all components were updated
8/15/2010 6:43:58 AM Task started Kaspersky Internet Security
My Update Center
8/15/2010 3:24:46 AM Task started Kaspersky Internet Security
My Update Center
8/15/2010 3:08:12 AM Task stopped Kaspersky Internet Security
My Update Center Operation cancelled by the user
8/15/2010 2:25:54 AM Task started Kaspersky Internet Security
My Update Center
Date: Last week (events: 1577)
My Protection (events: 63)
8/22/2010 11:16:11 PM Threats have been detected Kaspersky Internet Secur
ity
8/22/2010 8:44:57 PM Threats have been detected Kaspersky Internet Secur
ity
8/22/2010 8:34:40 PM Databases are obsolete Kaspersky Internet Security
8/22/2010 7:46:16 AM Protection is not running Kaspersky Internet Secur
ity
8/22/2010 6:05:57 AM Databases are obsolete Kaspersky Internet Security
8/22/2010 3:45:43 AM Protection is not running Kaspersky Internet Secur
ity
8/22/2010 2:15:00 AM Databases are obsolete Kaspersky Internet Security
8/21/2010 11:01:04 PM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 7:13:38 PM Databases are obsolete Kaspersky Internet Security
8/21/2010 6:15:53 PM Protection is not running Kaspersky Internet Secur
ity
8/22/2010 5:10:08 AM Databases are obsolete Kaspersky Internet Security
8/21/2010 8:51:35 PM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 7:37:00 PM Databases are obsolete Kaspersky Internet Security
8/21/2010 5:18:54 PM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 3:32:45 PM Threats have been detected Kaspersky Internet Secur
ity
8/21/2010 3:26:30 PM Databases are obsolete Kaspersky Internet Security
8/21/2010 3:23:57 PM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 2:14:57 PM Databases are obsolete Kaspersky Internet Security
8/21/2010 2:13:33 PM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 11:15:38 AM Databases are obsolete Kaspersky Internet Security
8/21/2010 6:44:59 AM Protection is not running Kaspersky Internet Secur
ity
8/21/2010 6:11:19 AM Databases are obsolete Kaspersky Internet Security
8/21/2010 5:29:43 AM Databases are obsolete Kaspersky Internet Security
8/20/2010 10:08:39 PM Protection is not running Kaspersky Internet Secur
ity
8/20/2010 8:44:17 PM Databases are obsolete Kaspersky Internet Security
8/20/2010 3:30:05 PM Protection is not running Kaspersky Internet Secur
ity
8/20/2010 12:43:54 PM Databases are obsolete Kaspersky Internet Security
8/20/2010 12:42:51 PM Protection is not running Kaspersky Internet Secur
ity
8/20/2010 11:20:12 AM Databases are obsolete Kaspersky Internet Security
8/20/2010 11:15:57 AM Protection is not running Kaspersky Internet Secur
ity
8/20/2010 10:55:40 AM Databases are obsolete Kaspersky Internet Security
8/19/2010 10:25:07 PM Protection is not running Kaspersky Internet Secur
ity
8/19/2010 8:54:57 PM Databases are obsolete Kaspersky Internet Security
8/19/2010 5:23:21 PM Protection is not running Kaspersky Internet Secur
ity
8/19/2010 4:24:29 PM Databases are obsolete Kaspersky Internet Security
8/19/2010 4:23:29 PM Protection is not running Kaspersky Internet Secur
ity
8/19/2010 1:52:27 PM Databases are obsolete Kaspersky Internet Security
8/19/2010 12:42:42 PM Protection is not running Kaspersky Internet Secur
ity
8/19/2010 11:01:54 AM Databases are obsolete Kaspersky Internet Security
8/18/2010 10:32:51 PM Protection is not running Kaspersky Internet Secur
ity
8/18/2010 9:20:59 PM Databases are obsolete Kaspersky Internet Security
8/18/2010 8:24:33 PM Databases are obsolete Kaspersky Internet Security
8/18/2010 5:47:57 PM Protection is not running Kaspersky Internet Secur
ity
8/18/2010 4:10:07 PM Databases are obsolete Kaspersky Internet Security
8/18/2010 4:08:11 PM Protection is not running Kaspersky Internet Secur
ity
8/18/2010 3:20:04 PM Databases are obsolete Kaspersky Internet Security
8/18/2010 3:07:08 PM Protection is not running Kaspersky Internet Secur
ity
8/18/2010 2:24:38 PM Databases are obsolete Kaspersky Internet Security
8/18/2010 12:31:59 PM Protection is not running Kaspersky Internet Secur
ity
8/18/2010 11:14:52 AM Databases are obsolete Kaspersky Internet Security
8/18/2010 5:16:33 AM Databases are obsolete Kaspersky Internet Security
8/17/2010 12:18:46 PM Databases are obsolete Kaspersky Internet Security
8/17/2010 12:17:11 PM Protection is not running Kaspersky Internet Secur
ity
8/17/2010 9:22:42 AM Databases are obsolete Kaspersky Internet Security
8/17/2010 7:02:10 AM Databases are obsolete Kaspersky Internet Security
8/17/2010 6:39:28 AM Protection is not running Kaspersky Internet Secur
ity
8/17/2010 5:44:42 AM Databases are obsolete Kaspersky Internet Security
8/16/2010 10:49:54 PM Protection is not running Kaspersky Internet Secur
ity
8/16/2010 8:24:22 PM Databases are obsolete Kaspersky Internet Security
8/16/2010 1:21:27 PM Databases are obsolete Kaspersky Internet Security
8/16/2010 12:20:38 PM Protection is not running Kaspersky Internet Secur
ity
8/16/2010 12:14:53 PM Databases are obsolete Kaspersky Internet Security
8/16/2010 9:37:19 AM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 38)
8/22/2010 11:17:07 PM Deleted: Net-Worm.Win32.Kido.ih Generic Host Process for
Win32 Services E:\autorun.inf
8/22/2010 11:16:11 PM Detected: Net-Worm.Win32.Kido.ih Generic Host Pro
cess for Win32 Services E:\autorun.inf
8/22/2010 8:45:23 PM Deleted: Net-Worm.Win32.Kido.ih Generic Host Process for
Win32 Services F:\autorun.inf
8/22/2010 8:44:57 PM Detected: Net-Worm.Win32.Kido.ih Generic Host Pro
cess for Win32 Services F:\autorun.inf
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
File Anti-Virus
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
File Anti-Virus
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
File Anti-Virus
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 7:36:55 PM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 2:14:49 PM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 11:15:32 AM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
File Anti-Virus
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
File Anti-Virus
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
File Anti-Virus
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
File Anti-Virus
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
File Anti-Virus
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
File Anti-Virus
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
File Anti-Virus
8/19/2010 4:24:25 PM Task started Kaspersky Internet Security
File Anti-Virus
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
File Anti-Virus
8/19/2010 11:01:48 AM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
File Anti-Virus
8/18/2010 5:16:27 AM Task started Kaspersky Internet Security
File Anti-Virus
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
File Anti-Virus
8/17/2010 9:22:37 AM Task started Kaspersky Internet Security
File Anti-Virus
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
File Anti-Virus
8/17/2010 5:44:37 AM Task started Kaspersky Internet Security
File Anti-Virus
8/16/2010 8:24:18 PM Task started Kaspersky Internet Security
File Anti-Virus
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
File Anti-Virus
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
File Anti-Virus
8/16/2010 9:37:13 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 7:36:56 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 2:14:50 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 11:15:33 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/19/2010 11:01:49 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/17/2010 9:22:38 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/17/2010 5:44:38 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/16/2010 8:24:19 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/16/2010 9:37:13 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/22/2010 2:14:55 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 7:36:56 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 2:14:50 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 11:15:33 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/20/2010 10:55:36 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/19/2010 11:01:49 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/17/2010 9:22:38 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/17/2010 5:44:38 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/16/2010 8:24:19 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/16/2010 9:37:13 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 7:36:56 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 2:14:50 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 11:15:33 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/19/2010 11:01:49 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/17/2010 9:22:38 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/17/2010 5:44:38 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/16/2010 8:24:19 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/16/2010 9:37:12 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Anti-Spam
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Anti-Spam
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Anti-Spam
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 7:36:55 PM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 2:14:49 PM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 11:15:32 AM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Anti-Spam
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Anti-Spam
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Anti-Spam
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Anti-Spam
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Anti-Spam
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
Anti-Spam
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Anti-Spam
8/19/2010 4:24:25 PM Task started Kaspersky Internet Security
Anti-Spam
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Anti-Spam
8/19/2010 11:01:48 AM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Anti-Spam
8/18/2010 5:16:27 AM Task started Kaspersky Internet Security
Anti-Spam
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Anti-Spam
8/17/2010 9:22:37 AM Task started Kaspersky Internet Security
Anti-Spam
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Anti-Spam
8/17/2010 5:44:37 AM Task started Kaspersky Internet Security
Anti-Spam
8/16/2010 8:24:18 PM Task started Kaspersky Internet Security
Anti-Spam
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Anti-Spam
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Anti-Spam
8/16/2010 9:37:12 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 514)
8/22/2010 8:35:59 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Application Control
8/22/2010 7:08:36 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 7:08:30 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 6:33:12 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 6:33:05 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 6:09:28 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 6:09:22 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 6:07:49 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 6:07:39 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 6:07:19 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 6:07:15 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Application Control
8/22/2010 3:22:57 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 3:22:49 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 2:31:52 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 2:31:46 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 2:16:39 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 2:16:24 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 2:16:19 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
Application Control
8/21/2010 9:57:17 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 9:57:06 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 7:56:38 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 7:56:32 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 7:35:21 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 7:35:14 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 7:15:22 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 7:15:03 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 7:14:59 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Application Control
8/21/2010 5:33:42 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 5:33:24 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 4:26:16 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 4:25:46 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 3:59:36 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 3:58:50 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 3:58:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 3:57:29 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 3:55:51 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 3:55:50 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 3:55:40 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 3:55:28 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 3:55:28 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 3:55:00 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 3:54:48 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/21/2010 3:54:48 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/21/2010 3:54:48 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/21/2010 3:54:48 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/21/2010 3:46:46 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 3:46:44 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 3:46:31 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 3:46:17 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 3:46:17 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 3:46:02 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 3:42:40 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 3:42:30 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 3:42:29 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 3:42:20 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 3:42:04 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 3:42:04 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 3:41:57 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/22/2010 5:12:01 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/22/2010 5:11:42 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/22/2010 5:11:24 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Application Control
8/21/2010 8:14:03 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 8:13:47 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 7:41:01 PM Microsoft Windows Malicious Software Removal Too
l Placed in group Trusted Signed by the digital signature of entrusted man
ufacturers
8/21/2010 7:40:40 PM MRTSTUB.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/21/2010 7:40:28 PM windows-kb890830-v3.10.exe Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/21/2010 7:40:16 PM Windows Control Panel Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/21/2010 7:38:24 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 7:36:55 PM Task started Kaspersky Internet Security
Application Control
8/21/2010 5:18:12 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/21/2010 5:18:12 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/21/2010 5:18:12 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/21/2010 5:18:08 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/21/2010 5:09:45 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/21/2010 5:09:45 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/21/2010 5:09:45 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\XDVA349.SYS Start driver
8/21/2010 5:09:41 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/21/2010 5:09:29 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/21/2010 5:09:26 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/21/2010 5:09:20 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/21/2010 3:27:50 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Application Control
8/21/2010 2:16:16 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 2:14:49 PM Task started Kaspersky Internet Security
Application Control
8/21/2010 1:33:59 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:33:49 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 1:32:51 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:32:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 1:29:21 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:29:12 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 1:18:29 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:18:17 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 1:11:11 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:10:36 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 1:10:15 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 1:06:11 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 1:06:07 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 1:06:05 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 1:05:57 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 1:05:43 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 1:05:43 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 1:05:34 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 12:14:11 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 12:14:04 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 12:14:01 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/21/2010 11:51:14 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 11:50:27 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 11:50:01 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 11:47:32 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 11:47:30 AM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 11:47:28 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 11:47:20 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 11:47:05 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 11:47:05 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 11:46:52 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 11:36:00 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 11:34:05 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 11:33:50 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 11:33:35 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 11:29:12 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 11:29:10 AM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 11:29:08 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 11:28:59 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 11:28:45 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 11:28:45 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 11:28:33 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 11:18:17 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 11:18:11 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 11:17:03 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/21/2010 11:16:58 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 11:15:32 AM Task started Kaspersky Internet Security
Application Control
8/21/2010 6:12:38 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Application Control
8/21/2010 5:34:28 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 5:34:26 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 5:34:17 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 5:34:04 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 5:34:04 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 5:33:56 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 5:32:04 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/21/2010 5:32:01 AM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/21/2010 5:32:00 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/21/2010 5:31:40 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/21/2010 5:31:04 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/21/2010 5:30:49 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/21/2010 5:30:49 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/21/2010 5:30:35 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Application Control
8/20/2010 8:59:55 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 8:59:47 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 8:45:37 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Application Control
8/20/2010 2:15:29 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 2:15:22 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 1:56:19 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 1:56:12 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 1:24:57 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 1:24:51 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 1:24:47 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/20/2010 1:24:47 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/20/2010 1:24:47 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/20/2010 1:24:43 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/20/2010 1:23:39 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 1:23:29 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 12:56:38 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/20/2010 12:56:26 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/20/2010 12:45:47 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/20/2010 12:45:47 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/20/2010 12:45:47 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\XDVA349.SYS Start driver
8/20/2010 12:45:37 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 12:45:14 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/20/2010 12:45:13 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/20/2010 12:44:42 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Application Control
8/20/2010 12:42:20 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/20/2010 12:42:20 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/20/2010 12:42:20 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/20/2010 12:42:16 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/20/2010 12:39:55 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/20/2010 12:39:55 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/20/2010 12:39:38 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 12:39:23 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/20/2010 12:38:55 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 12:38:50 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/20/2010 12:38:37 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/20/2010 12:38:37 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/20/2010 12:38:37 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/20/2010 12:38:33 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/20/2010 11:44:04 AM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/20/2010 11:44:03 AM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/20/2010 11:44:03 AM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 11:43:56 AM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/20/2010 11:43:54 AM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 11:43:48 AM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/20/2010 11:43:41 AM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/20/2010 11:43:41 AM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/20/2010 11:43:41 AM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/20/2010 11:43:38 AM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/20/2010 11:22:36 AM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/20/2010 11:22:36 AM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/20/2010 11:22:36 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\XDVA349.SYS Start driver
8/20/2010 11:22:26 AM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 11:22:07 AM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/20/2010 11:22:00 AM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/20/2010 11:21:36 AM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/20/2010 11:21:32 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Application Control
8/20/2010 11:10:46 AM DJ_SF_03_D2500_PRODUCTCONTEXT.MSI Placed i
n group Trusted Known on the database of the known software
8/20/2010 10:56:59 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
Application Control
8/19/2010 10:19:12 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 10:19:05 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 9:54:49 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 9:54:42 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 9:50:42 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 9:50:30 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 8:56:39 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 8:56:29 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 8:56:15 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Application Control
8/19/2010 4:56:51 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 4:56:42 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 4:52:31 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 4:52:25 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 4:38:09 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 4:38:02 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/19/2010 4:37:44 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 4:35:47 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/19/2010 4:35:46 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/19/2010 4:35:36 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/19/2010 4:35:22 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/19/2010 4:35:22 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/19/2010 4:35:16 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/19/2010 4:25:54 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Application Control
8/19/2010 4:21:48 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/19/2010 4:19:04 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/19/2010 4:19:00 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 4:18:59 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/19/2010 4:18:41 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/19/2010 4:18:22 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/19/2010 4:18:22 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/19/2010 4:18:15 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/19/2010 4:03:22 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 4:03:11 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 3:24:57 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 3:24:50 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 2:53:38 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 2:53:31 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 2:43:17 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 2:43:10 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 1:54:27 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 1:54:17 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 1:53:51 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 1:53:46 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Application Control
8/19/2010 11:04:46 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 11:04:37 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 11:03:36 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/19/2010 11:03:19 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/19/2010 11:03:13 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/19/2010 11:01:48 AM Task started Kaspersky Internet Security
Application Control
8/18/2010 9:33:55 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 9:33:47 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 9:33:32 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 9:24:42 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 9:24:40 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/18/2010 9:24:26 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/18/2010 9:24:15 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/18/2010 9:24:15 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/18/2010 9:22:53 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/18/2010 9:22:19 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Application Control
8/18/2010 9:17:14 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 9:17:10 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 9:17:08 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/18/2010 9:16:57 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/18/2010 9:16:38 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/18/2010 9:16:38 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/18/2010 9:16:26 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/18/2010 8:38:05 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 8:37:59 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 8:29:09 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 8:28:56 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 8:26:42 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 8:26:29 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 8:26:19 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 8:25:53 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Application Control
8/18/2010 5:00:48 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 5:00:44 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 5:00:42 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/18/2010 5:00:34 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/18/2010 5:00:18 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/18/2010 5:00:18 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/18/2010 5:00:13 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/18/2010 4:40:24 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 4:40:18 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 4:12:27 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 4:11:59 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 4:11:30 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/18/2010 4:11:26 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Application Control
8/18/2010 3:50:53 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 3:50:52 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/18/2010 3:50:42 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/18/2010 3:50:16 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/18/2010 3:50:16 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/18/2010 3:50:06 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/18/2010 3:46:06 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/18/2010 3:45:59 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 3:45:58 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/18/2010 3:45:48 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/18/2010 3:45:32 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/18/2010 3:45:32 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/18/2010 3:45:26 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/18/2010 3:21:24 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Application Control
8/18/2010 2:26:01 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Application Control
8/18/2010 11:16:26 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/18/2010 11:16:10 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Application Control
8/18/2010 6:02:12 AM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/18/2010 6:02:12 AM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/18/2010 6:02:06 AM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/18/2010 6:01:57 AM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/18/2010 6:01:52 AM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/18/2010 6:01:49 AM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/18/2010 5:19:14 AM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/18/2010 5:19:14 AM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/18/2010 5:19:14 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\XDVA349.SYS Start driver
8/18/2010 5:19:06 AM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/18/2010 5:18:46 AM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/18/2010 5:18:37 AM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/18/2010 5:17:57 AM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/18/2010 5:17:53 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
Application Control
8/17/2010 8:34:31 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 8:34:25 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 8:09:55 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 8:09:46 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 8:08:44 PM Allowed: Using system program interfaces (DNS) CK2.EXE
Use DNS caching system for conversion gamenoticeck2.lytogame.com Using sy
stem program interfaces (DNS)
8/17/2010 8:08:39 PM CK2.EXE Placed in group Low Restricted High val
ue of threat rating calculated heuristically
8/17/2010 6:55:40 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 6:55:40 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 6:55:39 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 6:55:31 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 6:55:28 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 6:55:18 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 5:18:06 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 5:17:59 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 5:17:39 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 5:17:33 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 5:11:27 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 5:11:10 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 4:46:51 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 4:46:39 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 4:30:06 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 4:30:06 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 4:30:06 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 4:30:03 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 3:56:34 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 3:56:34 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 3:56:33 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:56:27 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 3:56:25 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:56:20 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 3:55:33 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 3:55:33 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 3:55:32 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 3:55:30 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 3:15:54 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 3:15:54 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 3:15:53 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:15:46 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 3:15:44 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:15:41 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 3:15:33 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 3:15:33 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 3:15:33 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 3:15:24 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 3:12:45 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 3:12:45 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 3:12:44 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:12:38 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 3:12:35 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:12:32 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 3:12:25 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 3:12:25 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 3:12:25 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 3:12:21 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 3:03:03 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 3:03:02 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 3:03:02 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:02:55 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 3:02:53 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:02:51 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 3:02:43 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 3:02:43 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 3:02:43 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 3:02:39 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 3:01:33 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 3:01:33 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 3:01:32 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:01:24 PM Allowed: Using system program interfaces (DNS) HGWC.exe
Use DNS caching system for conversion patch.crossfire.web.id Using system pro
gram interfaces (DNS)
8/17/2010 3:01:22 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 3:01:14 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 3:01:02 PM Allowed: Pausing other processes and threads DrWatson
Postmortem Debugger Suspend another process c:\windows\system32\drwtsn32.exe
Pausing other processes and threads
8/17/2010 3:01:02 PM Allowed: Code intrusion DrWatson Postmortem Debugger
Code intrusion c:\windows\system32\drwtsn32.exe Code intrusion
8/17/2010 3:01:02 PM Allowed: Setting debug privileges DrWatson Postmor
tem Debugger Setting debug privileges Setting debug privileges
8/17/2010 3:01:00 PM Allowed: Pausing other processes and threads Microsof
t Application Error Reporting Suspend another process c:\windows\system32\dwwi
n.exe Pausing other processes and threads
8/17/2010 2:37:59 PM Allowed: Setting debug privileges CROSSFIRE.EXE
Setting debug privileges Setting debug privileges
8/17/2010 2:37:59 PM Allowed: Direct access to physical memory CROSSFIR
E.EXE Access to global memory Direct access to physical memory
8/17/2010 2:37:59 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\XDVA349.SYS Start driver
8/17/2010 2:37:55 PM Allowed: Using system program interfaces (DNS) CROSSFIR
E.EXE Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 2:37:51 PM XTRAP.XT Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/17/2010 2:31:13 PM HGWC.exe Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/17/2010 2:25:26 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/17/2010 2:25:19 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/17/2010 12:22:48 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 12:22:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 12:21:54 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 12:21:44 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 12:20:07 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Application Control
8/17/2010 11:38:27 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 11:38:17 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 9:24:35 AM Firefox Helper Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/17/2010 9:24:04 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/17/2010 9:23:53 AM UPDATER.EXE Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/17/2010 9:22:37 AM Task started Kaspersky Internet Security
Application Control
8/17/2010 8:57:25 AM MSI33B.TMP Placed in group Trusted Known on
the database of the known software
8/17/2010 7:54:50 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 7:54:43 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 7:51:57 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 7:51:49 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 7:05:57 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 7:05:50 AM Allowed: Using program interfaces of other process
RealUpgrade Launcher Using program interfaces of other process c:\progr
am files\real\realupgrade\realupgrade.exe Using program interfaces of othe
r process
8/17/2010 7:05:48 AM Allowed: Using system program interfaces (DNS) RealUpgr
ade Launcher Use DNS caching system for conversion client-software.real.com
Using system program interfaces (DNS)
8/17/2010 7:05:46 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 7:05:42 AM Allowed: Using program interfaces of other process
Internet Explorer Using program interfaces of other process c:\progr
am files\internet explorer\iexplore.exe Using program interfaces of other proces
s
8/17/2010 7:05:42 AM Allowed: Access to internal browser data Internet
Explorer Access to internal browser data Access to internal brows
er data
8/17/2010 7:05:31 AM Allowed: Using system program interfaces (DNS) Internet
Explorer Use DNS caching system for conversion ayodance.com Using sy
stem program interfaces (DNS)
8/17/2010 7:05:29 AM Allowed: Using program interfaces of other process
Internet Explorer Using program interfaces of other process c:\progr
am files\internet explorer\iexplore.exe Using program interfaces of other proces
s
8/17/2010 7:05:25 AM Allowed: Using system program interfaces (DNS) Internet
Explorer Use DNS caching system for conversion www.taazu.com Using sy
stem program interfaces (DNS)
8/17/2010 7:05:23 AM Allowed: Use command line of browser Audition
Use command line of browser HTTP://AYODANCE.COM/ Use command line of brow
ser
8/17/2010 7:04:16 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 7:03:48 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 7:03:33 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Application Control
8/17/2010 6:07:41 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 6:07:31 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 5:50:01 AM RBSOLNUPDATE.EXE Placed in group Low Rest
ricted High value of threat rating calculated heuristically
8/17/2010 5:49:54 AM RBSOLNUPDATEENU.3.3.0.EXE Placed in group
Trusted Known on the database of the known software
8/17/2010 5:49:37 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/17/2010 5:49:31 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/17/2010 5:49:29 AM Hewlett-Packard Product Assistant Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/17/2010 5:49:11 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/17/2010 5:46:02 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/17/2010 5:44:37 AM Task started Kaspersky Internet Security
Application Control
8/16/2010 10:48:35 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/16/2010 10:48:35 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/16/2010 8:31:21 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/16/2010 8:31:17 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 8:31:15 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/16/2010 8:31:00 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/16/2010 8:30:43 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/16/2010 8:30:43 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/16/2010 8:29:57 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/16/2010 8:29:26 PM Windows TaskManager Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/16/2010 8:25:45 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/16/2010 8:25:22 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/16/2010 8:24:24 PM Microsoft(C) Register Server Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/16/2010 8:24:18 PM Task started Kaspersky Internet Security
Application Control
8/16/2010 5:31:20 PM MSI1663.TMP Placed in group Trusted Known on
the database of the known software
8/16/2010 4:43:21 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/16/2010 3:55:00 PM Paint Placed in group Trusted Signed by the di
gital signature of entrusted manufacturers
8/16/2010 3:42:08 PM Microsoft Office Word Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/16/2010 3:33:59 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 3:33:49 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 3:08:15 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 3:08:04 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 2:33:38 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 2:33:29 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 2:21:53 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 2:21:46 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 1:31:22 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 1:31:13 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 1:30:11 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/16/2010 1:30:02 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/16/2010 1:29:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 1:27:37 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/16/2010 1:24:22 PM Allowed: Using system program interfaces (DNS) patcher_
cf2.exe Use DNS caching system for conversion patch.crossfire.web.id Using sy
stem program interfaces (DNS)
8/16/2010 1:24:19 PM patcher_cf2.exe Placed in group Trusted Signed b
y the digital signature of entrusted manufacturers
8/16/2010 1:23:49 PM Allowed: Using system program interfaces (DNS) TODO: <F
ile description> Use DNS caching system for conversion gamenoticecf.lyt
ogame.com Using system program interfaces (DNS)
8/16/2010 1:23:20 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/16/2010 1:22:48 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Application Control
8/16/2010 12:20:26 PM MSIFD.TMP Placed in group Trusted Known on
the database of the known software
8/16/2010 12:20:24 PM 2007 Microsoft Office component Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/16/2010 12:16:12 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Application Control
8/16/2010 12:09:15 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/16/2010 12:09:05 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/16/2010 9:42:25 AM HP Software Update Client Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/16/2010 9:38:46 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/16/2010 9:37:25 AM Adobe Gamma Loader Placed in group Trusted
Known on the database of the known software
8/16/2010 9:37:12 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 115)
8/22/2010 8:46:49 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 7:08:39 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 6:33:15 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 6:09:32 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 6:07:53 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 6:07:20 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 3:23:01 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 2:31:55 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 2:16:44 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 2:16:24 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 9:57:22 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:56:42 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:39:03 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:35:24 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:15:27 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:15:08 PM Denied Audition Client Patcher Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 5:33:47 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 4:26:19 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:59:42 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:56:06 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:47:09 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:42:43 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 5:12:05 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/22/2010 5:10:12 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 8:14:07 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 7:41:18 PM Denied Microsoft Windows Malicious Software Removal Too
l Open C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\
avp.exe
8/21/2010 7:37:05 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:51:51 PM Denied DrWatson Postmortem Debugger Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 3:32:23 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 2:16:26 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:34:06 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:32:55 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:29:26 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:18:33 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:11:17 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 1:06:15 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 12:14:14 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:51:19 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:47:36 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:34:09 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:29:15 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:21:17 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 11:17:11 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 6:12:51 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 5:34:42 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 5:32:07 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/21/2010 5:31:25 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 8:59:59 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 8:45:55 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 12:45:20 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 12:45:18 PM Denied HGWC.exe Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 11:21:43 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/20/2010 10:57:06 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 10:19:15 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 9:54:52 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 9:50:45 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 8:56:44 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:56:55 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:52:35 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:38:14 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:35:54 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:19:09 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 4:03:25 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 3:25:00 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 2:53:41 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 2:43:20 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 1:54:31 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 11:04:49 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 11:04:09 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/19/2010 11:03:42 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 9:34:00 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 9:24:51 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 9:22:31 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 9:17:19 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 8:38:09 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 8:29:12 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 8:26:47 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 8:25:59 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 5:00:52 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 4:40:27 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 4:12:31 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 4:11:34 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 3:51:07 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 3:46:09 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 3:21:35 PM Denied Firefox Open C:\Program Files\Kaspersky Lab\K
aspersky Internet Security 2010\avp.exe
8/18/2010 3:05:44 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 11:16:31 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 11:16:21 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/18/2010 5:17:57 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 12:22:51 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 12:21:59 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 12:20:12 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 11:38:34 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 9:24:08 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 7:54:53 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 7:52:02 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 7:06:01 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 7:04:22 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 7:03:37 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 6:07:45 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 5:49:48 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 5:46:07 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/17/2010 5:46:04 AM Denied Firefox Open C:\Program Files\Kaspersky Lab\K
aspersky Internet Security 2010\avp.exe
8/16/2010 8:31:26 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 8:24:28 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 3:34:04 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 3:08:20 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 2:33:41 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 2:21:57 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 1:31:26 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 1:30:18 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 1:22:57 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 12:16:19 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/16/2010 9:43:15 AM Denied WMI Open C:\Program Files\Kaspersky Lab\K
aspersky Internet Security 2010\avp.exe
8/16/2010 9:37:22 AM Denied Kaspersky Internet Security Modification
REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP9\Trace\Default
Proactive Defense (events: 347)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Proactive Defense
8/22/2010 7:08:43 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 7:08:43 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:33:18 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:33:18 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:09:35 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:09:35 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:08:14 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 6:08:14 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 6:08:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:08:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Proactive Defense
8/22/2010 3:23:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 3:23:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 2:31:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 2:31:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 2:17:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 2:17:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 2:16:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 2:16:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 2:14:55 AM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 9:57:34 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 9:57:34 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:56:47 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:56:47 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:35:27 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:35:27 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:15:59 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 7:15:59 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 7:15:40 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:15:40 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 5:33:59 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 5:33:59 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 4:26:22 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 4:26:22 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 3:59:56 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 3:59:56 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 3:59:36 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 3:59:34 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 3:59:33 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:58:50 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:56:22 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:56:22 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:56:02 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:55:51 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:47:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:47:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:47:04 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:46:46 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:42:42 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:42:42 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 3:42:40 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 3:42:30 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/22/2010 5:12:31 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 5:12:31 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/22/2010 5:12:20 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 5:12:20 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 8:14:25 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 8:14:25 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 8:14:22 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 8:14:22 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 7:36:56 PM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 5:11:24 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/21/2010 5:11:23 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 2:14:50 PM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 1:34:08 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:34:08 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:33:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:33:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:29:33 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:29:33 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:18:41 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:18:40 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:11:35 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:11:35 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 1:11:11 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 1:10:37 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 1:06:15 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 1:06:15 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 1:06:11 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 1:06:07 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 12:14:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 12:14:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:51:31 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:51:31 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:51:14 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:50:28 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:47:35 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 11:47:35 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 11:47:32 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 11:47:30 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 11:34:21 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:34:21 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:34:04 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:33:51 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:29:15 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 11:29:15 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 11:29:12 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 11:29:10 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 11:22:01 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 11:22:01 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 11:21:27 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:21:27 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/21/2010 11:21:13 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:18:17 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/21/2010 11:15:33 AM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Proactive Defense
8/21/2010 5:34:41 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 5:34:41 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 5:34:39 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 5:34:28 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 5:33:09 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 5:33:07 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/21/2010 5:32:14 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 5:32:14 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/21/2010 5:32:04 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 5:32:01 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Proactive Defense
8/20/2010 9:00:36 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/20/2010 9:00:36 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/20/2010 9:00:11 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 9:00:11 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Proactive Defense
8/20/2010 2:15:35 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 2:15:35 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:56:26 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:56:26 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:25:04 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:25:04 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:23:45 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 1:23:45 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 12:57:16 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/20/2010 12:57:16 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/20/2010 12:56:52 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 12:56:52 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/20/2010 12:46:55 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 12:46:55 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Proactive Defense
8/20/2010 12:40:21 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 12:40:21 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 11:44:30 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 11:44:30 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 11:23:42 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 11:23:42 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Proactive Defense
8/20/2010 10:55:36 AM Task started Kaspersky Internet Security
Proactive Defense
8/19/2010 10:19:18 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 10:19:18 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 9:54:55 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 9:54:55 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 9:50:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 9:50:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 8:57:15 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 8:57:15 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 8:56:58 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 8:56:58 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Proactive Defense
8/19/2010 4:57:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:57:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:52:38 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:52:38 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:38:27 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:38:27 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:38:09 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/19/2010 4:38:04 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/19/2010 4:36:53 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 4:36:52 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 4:36:10 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/19/2010 4:36:10 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/19/2010 4:35:51 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/19/2010 4:35:47 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Proactive Defense
8/19/2010 4:19:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/19/2010 4:19:08 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/19/2010 4:19:04 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/19/2010 4:19:00 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/19/2010 4:03:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 4:03:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 3:25:03 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 3:25:03 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 2:53:44 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 2:53:44 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 2:43:23 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 2:43:23 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 1:54:51 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 1:54:51 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 1:54:50 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 1:54:50 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Proactive Defense
8/19/2010 11:05:12 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 11:05:12 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/19/2010 11:04:53 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 11:04:53 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 11:03:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 11:03:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/19/2010 11:01:49 AM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 9:34:14 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 9:34:14 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 9:33:54 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 9:33:48 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 9:25:22 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 9:25:22 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 9:25:22 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 9:25:22 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 9:24:48 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 9:24:43 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 9:17:17 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 9:17:17 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 9:17:13 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 9:17:10 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 8:38:13 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:38:13 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:29:15 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:29:15 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:26:57 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:26:56 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 8:26:51 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 8:26:51 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 8:26:38 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 8:26:29 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 5:00:51 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 5:00:51 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 5:00:48 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 5:00:44 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 4:40:30 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 4:40:30 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 4:12:43 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 4:12:43 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 4:12:28 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 4:12:28 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 4:12:26 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 4:12:00 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 3:51:07 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 3:51:07 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 3:51:03 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 3:50:53 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 3:46:23 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 3:46:23 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 3:46:09 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 3:46:09 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/18/2010 3:46:05 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 3:45:59 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 11:17:13 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 11:17:13 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/18/2010 11:16:48 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 11:16:48 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Proactive Defense
8/18/2010 6:02:48 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/18/2010 6:02:48 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/18/2010 5:20:25 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/18/2010 5:20:25 AM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
Proactive Defense
8/17/2010 8:34:38 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 8:34:38 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 8:10:13 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 8:10:13 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 6:56:27 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 6:56:27 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 5:18:12 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:18:12 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:11:34 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:11:34 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 4:47:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 4:47:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 3:57:01 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:57:01 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:16:21 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:16:21 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:13:12 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:13:12 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:03:27 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:03:27 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:02:11 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 3:02:11 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 2:39:37 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 2:39:37 PM Detected: PDM.Keylogger CROSSFIRE.EXE Keylogger activi
ty kernel mode memory patch
8/17/2010 12:22:55 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 12:22:55 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 12:22:08 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 12:22:08 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 12:22:05 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 12:22:05 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Proactive Defense
8/17/2010 11:38:59 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 11:38:59 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 11:38:39 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 11:38:39 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 9:22:38 AM Task started Kaspersky Internet Security
Proactive Defense
8/17/2010 7:54:57 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:54:56 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:52:07 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:52:07 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:06:07 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:06:06 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:04:59 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:04:59 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 7:04:30 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 7:04:30 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Proactive Defense
8/17/2010 6:07:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 6:07:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:50:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:50:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/17/2010 5:50:08 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 5:50:08 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/17/2010 5:49:44 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/17/2010 5:49:38 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/17/2010 5:44:38 AM Task started Kaspersky Internet Security
Proactive Defense
8/16/2010 8:31:46 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/16/2010 8:31:46 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/16/2010 8:31:26 PM Detected: PDM.Keylogger PBLauncher Keylogger activi
ty kernel mode memory patch
8/16/2010 8:31:26 PM Detected: PDM.Keylogger PBLauncher Keylogger activi
ty kernel mode memory patch
8/16/2010 8:31:25 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/16/2010 8:31:25 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/16/2010 8:31:24 PM Allowed: PDM.Suspicious driver installation PBLaunch
er D:\GEMSCOOL\POINT BLANK\PBLAUNCHER.EXE
8/16/2010 8:31:21 PM Detected: PDM.Suspicious driver installation PBLaunch
er D:\GEMSCOOL\POINT BLANK\PBLAUNCHER.EXE
8/16/2010 8:31:21 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/16/2010 8:31:17 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/16/2010 8:24:19 PM Task started Kaspersky Internet Security
Proactive Defense
8/16/2010 3:34:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 3:34:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 3:08:40 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 3:08:40 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 2:33:44 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 2:33:44 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 2:22:01 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 2:22:01 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 1:31:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 1:31:31 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 1:30:56 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/16/2010 1:30:56 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/16/2010 1:30:42 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 1:30:42 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/16/2010 1:30:10 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/16/2010 1:30:04 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Proactive Defense
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Proactive Defense
8/16/2010 12:09:15 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/16/2010 9:37:13 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 34)
8/22/2010 8:34:29 PM Application is not activated Kaspersky Internet Secur
ity
8/22/2010 6:05:48 AM Application is not activated Kaspersky Internet Secur
ity
8/22/2010 2:14:50 AM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 7:13:28 PM Application is not activated Kaspersky Internet Secur
ity
8/22/2010 5:09:55 AM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 7:36:49 PM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 3:26:20 PM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 2:14:46 PM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 11:15:30 AM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 6:11:09 AM Application is not activated Kaspersky Internet Secur
ity
8/21/2010 5:29:35 AM Application is not activated Kaspersky Internet Secur
ity
8/20/2010 8:44:07 PM Application is not activated Kaspersky Internet Secur
ity
8/20/2010 12:43:45 PM Application is not activated Kaspersky Internet Secur
ity
8/20/2010 11:20:05 AM Application is not activated Kaspersky Internet Secur
ity
8/20/2010 10:55:30 AM Application is not activated Kaspersky Internet Secur
ity
8/19/2010 8:54:45 PM Application is not activated Kaspersky Internet Secur
ity
8/19/2010 4:24:21 PM Application is not activated Kaspersky Internet Secur
ity
8/19/2010 1:52:16 PM Application is not activated Kaspersky Internet Secur
ity
8/19/2010 11:01:46 AM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 9:20:48 PM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 8:24:25 PM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 4:09:58 PM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 3:19:55 PM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 2:24:29 PM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 11:14:43 AM Application is not activated Kaspersky Internet Secur
ity
8/18/2010 5:16:23 AM Application is not activated Kaspersky Internet Secur
ity
8/17/2010 12:18:38 PM Application is not activated Kaspersky Internet Secur
ity
8/17/2010 9:22:35 AM Application is not activated Kaspersky Internet Secur
ity
8/17/2010 7:02:02 AM Application is not activated Kaspersky Internet Secur
ity
8/17/2010 5:44:32 AM Application is not activated Kaspersky Internet Secur
ity
8/16/2010 8:24:12 PM Application is not activated Kaspersky Internet Secur
ity
8/16/2010 1:21:19 PM Application is not activated Kaspersky Internet Secur
ity
8/16/2010 12:14:45 PM Application is not activated Kaspersky Internet Secur
ity
8/16/2010 9:37:09 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
Firewall
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
Firewall
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
Firewall
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
Firewall
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
Firewall
8/21/2010 7:36:55 PM Task started Kaspersky Internet Security
Firewall
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
Firewall
8/21/2010 2:14:49 PM Task started Kaspersky Internet Security
Firewall
8/21/2010 11:15:32 AM Task started Kaspersky Internet Security
Firewall
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
Firewall
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
Firewall
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
Firewall
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
Firewall
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
Firewall
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
Firewall
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
Firewall
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
Firewall
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
Firewall
8/19/2010 11:01:48 AM Task started Kaspersky Internet Security
Firewall
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
Firewall
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
Firewall
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
Firewall
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
Firewall
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
Firewall
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
Firewall
8/18/2010 5:16:27 AM Task started Kaspersky Internet Security
Firewall
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
Firewall
8/17/2010 9:22:37 AM Task started Kaspersky Internet Security
Firewall
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
Firewall
8/17/2010 5:44:37 AM Task started Kaspersky Internet Security
Firewall
8/16/2010 8:24:18 PM Task started Kaspersky Internet Security
Firewall
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
Firewall
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
Firewall
8/16/2010 9:37:12 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 34)
8/22/2010 8:34:33 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/22/2010 6:05:50 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/22/2010 2:14:54 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 7:13:32 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/22/2010 5:10:01 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 7:36:56 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 3:26:24 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 2:14:50 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 11:15:33 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 6:11:12 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/21/2010 5:29:37 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/20/2010 8:44:10 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/20/2010 12:43:48 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/20/2010 11:20:07 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/20/2010 10:55:35 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/19/2010 8:54:49 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/19/2010 4:24:26 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/19/2010 1:52:20 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/19/2010 11:01:49 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 9:20:52 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 8:24:27 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 4:10:01 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 3:19:58 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 2:24:34 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 11:14:45 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/18/2010 5:16:28 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/17/2010 12:18:40 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/17/2010 9:22:38 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/17/2010 7:02:04 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/17/2010 5:44:38 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/16/2010 8:24:19 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/16/2010 1:21:21 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/16/2010 12:14:47 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/16/2010 9:37:13 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 74)
8/22/2010 9:06:10 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/22/2010 9:04:40 PM Task started Kaspersky Internet Security
Rootkit Scan
8/22/2010 8:47:51 PM Task completed Kaspersky Internet Security
Virus Scan
8/22/2010 8:46:48 PM Task started Kaspersky Internet Security
Virus Scan
8/22/2010 6:38:41 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/22/2010 6:36:02 AM Task started Kaspersky Internet Security
Rootkit Scan
8/22/2010 2:47:42 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/22/2010 2:45:04 AM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 7:45:28 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 7:43:42 PM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 7:39:06 PM Task completed Kaspersky Internet Security
Virus Scan
8/21/2010 7:39:03 PM Task started Kaspersky Internet Security
Virus Scan
8/21/2010 8:08:22 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 8:07:02 PM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 7:42:25 PM Task completed Kaspersky Internet Security
Virus Scan
8/21/2010 7:37:42 PM Task started Kaspersky Internet Security
Virus Scan
8/21/2010 3:58:16 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 3:56:35 PM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 3:33:34 PM Task completed Kaspersky Internet Security
Virus Scan
8/21/2010 3:32:22 PM Task started Kaspersky Internet Security
Virus Scan
8/21/2010 2:46:35 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 2:45:01 PM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 2:23:54 PM Task completed Kaspersky Internet Security
Virus Scan
8/21/2010 2:23:35 PM Task started Kaspersky Internet Security
Virus Scan
8/21/2010 11:47:59 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 11:45:44 AM Task started Kaspersky Internet Security
Rootkit Scan
8/21/2010 6:43:21 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/21/2010 6:41:24 AM Task started Kaspersky Internet Security
Rootkit Scan
8/20/2010 9:16:49 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/20/2010 9:14:22 PM Task started Kaspersky Internet Security
Rootkit Scan
8/20/2010 1:16:47 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/20/2010 1:14:00 PM Task started Kaspersky Internet Security
Rootkit Scan
8/20/2010 11:53:00 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/20/2010 11:50:19 AM Task started Kaspersky Internet Security
Rootkit Scan
8/19/2010 9:27:30 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/19/2010 9:24:59 PM Task started Kaspersky Internet Security
Rootkit Scan
8/19/2010 4:56:48 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/19/2010 4:54:35 PM Task started Kaspersky Internet Security
Rootkit Scan
8/19/2010 2:25:06 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/19/2010 2:22:31 PM Task started Kaspersky Internet Security
Rootkit Scan
8/19/2010 11:34:45 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/19/2010 11:32:00 AM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 9:53:33 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 9:51:03 PM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 8:57:18 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 8:54:39 PM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 4:42:40 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 4:40:12 PM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 3:54:07 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 3:50:13 PM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 2:56:48 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 2:54:43 PM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 11:47:30 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 11:44:57 AM Task started Kaspersky Internet Security
Rootkit Scan
8/18/2010 5:49:26 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/18/2010 5:46:38 AM Task started Kaspersky Internet Security
Rootkit Scan
8/17/2010 7:56:45 PM Task completed Kaspersky Internet Security
Virus Scan
8/17/2010 7:53:24 PM Task started Kaspersky Internet Security
Virus Scan
8/17/2010 6:31:22 PM Task completed Kaspersky Internet Security
Virus Scan
8/17/2010 6:30:39 PM Task started Kaspersky Internet Security
Virus Scan
8/17/2010 12:51:33 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/17/2010 12:48:52 PM Task started Kaspersky Internet Security
Rootkit Scan
8/17/2010 9:54:32 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/17/2010 9:52:49 AM Task started Kaspersky Internet Security
Rootkit Scan
8/17/2010 7:35:04 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/17/2010 7:32:17 AM Task started Kaspersky Internet Security
Rootkit Scan
8/17/2010 6:17:27 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/17/2010 6:14:47 AM Task started Kaspersky Internet Security
Rootkit Scan
8/16/2010 8:58:04 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/16/2010 8:54:26 PM Task started Kaspersky Internet Security
Rootkit Scan
8/16/2010 1:54:14 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/16/2010 1:51:33 PM Task started Kaspersky Internet Security
Rootkit Scan
8/16/2010 10:09:04 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/16/2010 10:07:24 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 188)
8/22/2010 11:49:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 11:29:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 11:09:44 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 10:49:44 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 10:29:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 10:09:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 9:49:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 9:29:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 9:09:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 8:49:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 7:41:05 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 7:21:05 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 7:01:05 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 6:41:05 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 6:21:05 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 3:30:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 3:10:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 2:50:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/22/2010 2:30:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 10:48:46 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 10:28:49 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 10:08:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 9:48:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 9:28:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 9:08:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 8:48:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 8:28:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 8:08:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 7:48:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 7:28:45 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 6:05:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 5:45:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 5:25:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 5:05:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:45:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:25:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:05:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 3:45:17 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 3:25:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 8:32:05 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 8:12:05 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 7:52:21 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 5:01:38 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:41:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:21:38 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 4:01:38 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 3:41:38 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 3:10:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 2:50:04 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 2:30:05 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 2:10:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 1:50:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 1:30:48 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 1:10:48 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 12:50:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 12:30:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 12:10:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 11:50:49 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 11:30:57 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/21/2010 6:26:26 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 9:59:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 9:39:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 9:19:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 8:59:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 3:19:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 2:59:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 2:39:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 2:19:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 1:59:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 1:39:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 1:19:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 12:59:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 12:35:22 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 12:15:21 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 11:55:22 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 11:35:23 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/20/2010 11:10:48 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 10:10:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 9:50:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 9:30:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 9:10:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 5:19:52 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 4:59:42 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 4:39:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 4:07:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 3:47:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 3:27:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 3:07:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 2:47:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 2:27:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 2:07:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 12:37:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 12:17:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 11:57:03 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 11:37:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/19/2010 11:17:03 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 10:16:06 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 9:56:06 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 9:36:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 9:19:49 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 8:59:42 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 8:39:42 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 5:45:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 5:25:19 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 5:05:17 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 4:45:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 4:25:16 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 3:55:15 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 3:35:12 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 2:59:47 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 2:39:49 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 12:30:00 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 12:10:00 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 11:50:00 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 11:30:00 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 6:31:40 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 6:11:41 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 5:51:40 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/18/2010 5:31:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 9:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 6:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 6:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 6:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 5:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 5:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 5:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 4:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 4:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 4:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 3:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 3:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 3:13:56 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 2:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 2:34:02 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 2:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 1:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 1:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 1:13:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 12:53:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 12:33:55 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 11:57:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 11:37:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 11:17:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 10:57:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 10:37:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 10:17:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 9:57:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 9:37:52 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:57:19 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:37:20 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 8:17:20 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:57:28 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:37:19 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 7:17:21 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 6:19:50 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/17/2010 5:59:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 10:39:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 10:19:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 9:59:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 9:39:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 9:19:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 8:59:30 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 8:39:33 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 5:16:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 4:56:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 4:36:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 4:16:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 3:56:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 3:36:38 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 3:16:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 2:56:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 2:36:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 2:16:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 1:56:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 1:36:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 11:52:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 11:32:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 11:12:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 10:52:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 10:32:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 10:12:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/16/2010 9:52:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Monday (events: 159)
My Protection (events: 5)
8/23/2010 3:17:28 PM Databases are obsolete Kaspersky Internet Security
8/23/2010 7:36:12 AM Protection is not running Kaspersky Internet Secur
ity
8/23/2010 6:07:43 AM Databases are obsolete Kaspersky Internet Security
8/23/2010 1:37:58 AM Databases are obsolete Kaspersky Internet Security
8/23/2010 1:36:54 AM Protection is not running Kaspersky Internet Secur
ity
File Anti-Virus (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
File Anti-Virus
8/23/2010 6:07:37 AM Task started Kaspersky Internet Security
File Anti-Virus
8/23/2010 1:37:52 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/23/2010 6:07:38 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/23/2010 1:37:53 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/23/2010 6:07:38 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/23/2010 1:37:53 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/23/2010 6:07:38 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/23/2010 1:37:53 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Anti-Spam
8/23/2010 6:07:37 AM Task started Kaspersky Internet Security
Anti-Spam
8/23/2010 1:37:52 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 26)
8/23/2010 11:39:44 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 11:39:35 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 11:16:56 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 11:16:50 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 11:02:18 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 11:02:12 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 10:05:55 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 10:05:48 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 9:32:48 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 9:32:39 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 3:18:49 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Application Control
8/23/2010 6:39:07 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 6:39:01 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 6:31:13 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 6:31:03 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 6:09:04 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/23/2010 6:07:37 AM Task started Kaspersky Internet Security
Application Control
8/23/2010 1:49:06 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/23/2010 1:48:55 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/23/2010 1:39:51 AM FLASHPLAYERUPDATE.EXE Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/23/2010 1:39:17 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/23/2010 1:38:08 AM NPSWF32_FlashUtil.exe Placed in group Trusted
Signed by the digital signature of entrusted manufacturers
8/23/2010 1:37:52 AM Task started Kaspersky Internet Security
Application Control
8/23/2010 1:29:59 AM Windows NT High Contrast Invocation Placed i
n group Trusted Signed by the digital signature of entrusted manufacturers
8/23/2010 12:09:13 AM 4shared Desktop Setup Placed in group Low Rest
ricted High value of threat rating calculated heuristically
Self-Defense (events: 34)
8/23/2010 11:39:47 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 11:16:59 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 11:02:22 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 10:05:58 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 9:32:53 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:59:14 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:59:07 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:59 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:52 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:45 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:38 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:31 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:23 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:16 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:09 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:58:01 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:54 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:46 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:38 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:31 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:24 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:16 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:09 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:57:01 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 4:56:49 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 3:18:53 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 6:39:10 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 6:31:17 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 6:09:09 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 1:49:10 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 1:42:56 AM Denied RealPlayer Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 1:39:53 AM Denied FLASHPLAYERUPDATE.EXE Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 1:39:22 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/23/2010 12:05:54 AM Denied Internet Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 25)
8/23/2010 11:39:51 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 11:39:51 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 11:17:03 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 11:17:03 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 11:02:25 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 11:02:24 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 10:06:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 10:06:01 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 9:33:19 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 9:33:19 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 9:33:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 9:33:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Proactive Defense
8/23/2010 6:39:13 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 6:39:13 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 6:31:59 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 6:31:59 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 6:31:27 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 6:31:27 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 6:07:38 AM Task started Kaspersky Internet Security
Proactive Defense
8/23/2010 1:49:24 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 1:49:24 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/23/2010 1:49:16 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 1:49:16 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/23/2010 1:37:53 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 3)
8/23/2010 3:17:19 PM Application is not activated Kaspersky Internet Secur
ity
8/23/2010 6:07:35 AM Application is not activated Kaspersky Internet Secur
ity
8/23/2010 1:37:50 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
Firewall
8/23/2010 6:07:37 AM Task started Kaspersky Internet Security
Firewall
8/23/2010 1:37:52 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 3)
8/23/2010 3:17:23 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/23/2010 6:07:38 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/23/2010 1:37:53 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 6)
8/23/2010 3:49:30 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/23/2010 3:47:34 PM Task started Kaspersky Internet Security
Rootkit Scan
8/23/2010 6:39:49 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/23/2010 6:37:49 AM Task started Kaspersky Internet Security
Rootkit Scan
8/23/2010 2:11:04 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/23/2010 2:08:04 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 39)
8/23/2010 11:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 11:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 11:12:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 10:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 10:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 10:12:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 9:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 9:32:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 9:12:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 8:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 8:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 8:12:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 7:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 7:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 7:12:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 6:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 6:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 6:12:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 5:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 5:32:51 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 5:12:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 4:52:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 4:32:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 4:12:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 3:52:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 3:32:37 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 7:22:51 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 7:02:51 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 6:42:51 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 6:22:54 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 2:53:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 2:33:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 2:13:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 1:53:07 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 1:29:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 1:09:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 12:49:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 12:29:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/23/2010 12:09:43 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Tuesday (events: 154)
My Protection (events: 9)
8/24/2010 11:46:24 PM Protection is not running Kaspersky Internet Secur
ity
8/24/2010 11:44:51 PM Databases are obsolete Kaspersky Internet Security
8/24/2010 10:08:24 PM Databases are obsolete Kaspersky Internet Security
8/24/2010 8:08:28 AM Protection is not running Kaspersky Internet Secur
ity
8/24/2010 7:32:08 AM Databases are obsolete Kaspersky Internet Security
8/24/2010 7:30:44 AM Databases are obsolete Kaspersky Internet Security
8/24/2010 6:08:17 AM Databases are obsolete Kaspersky Internet Security
8/24/2010 3:45:40 AM Protection is not running Kaspersky Internet Secur
ity
8/24/2010 12:24:00 AM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
File Anti-Virus
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
File Anti-Virus
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
File Anti-Virus
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
File Anti-Virus
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
File Anti-Virus
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/24/2010 10:08:20 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Anti-Spam
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Anti-Spam
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Anti-Spam
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Anti-Spam
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Anti-Spam
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 27)
8/24/2010 11:46:11 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Application Control
8/24/2010 10:43:59 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 10:43:49 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 10:10:40 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 10:10:30 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 10:09:46 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Application Control
8/24/2010 7:57:08 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 7:57:02 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 7:34:02 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 7:33:51 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 7:33:27 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Application Control
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Application Control
8/24/2010 6:10:12 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 6:10:04 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 6:09:37 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Application Control
8/24/2010 3:21:23 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 3:21:11 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 1:49:26 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 1:49:15 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 12:37:42 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/24/2010 12:37:27 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/24/2010 12:25:18 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 12)
8/24/2010 11:46:14 PM Denied Kaspersky Internet Security Modification
REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP9\Trace\Default
8/24/2010 10:44:03 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 10:10:44 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 10:09:54 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 7:57:11 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 7:34:06 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 7:33:33 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 6:10:16 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 3:21:29 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 1:49:30 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 12:37:46 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/24/2010 12:24:21 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 30)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Proactive Defense
8/24/2010 10:44:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 10:44:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 10:10:58 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 10:10:58 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 10:10:42 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 10:10:42 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Proactive Defense
8/24/2010 7:57:14 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 7:57:14 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 7:34:25 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 7:34:25 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 7:34:24 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 7:34:24 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Proactive Defense
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Proactive Defense
8/24/2010 6:10:35 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 6:10:35 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 6:10:31 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 6:10:31 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Proactive Defense
8/24/2010 3:21:48 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 3:21:48 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 1:49:39 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 1:49:39 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 12:38:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 12:38:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/24/2010 12:37:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 12:37:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 6)
8/24/2010 11:44:42 PM Application is not activated Kaspersky Internet Secur
ity
8/24/2010 10:08:16 PM Application is not activated Kaspersky Internet Secur
ity
8/24/2010 7:31:59 AM Application is not activated Kaspersky Internet Secur
ity
8/24/2010 7:30:36 AM Application is not activated Kaspersky Internet Secur
ity
8/24/2010 6:08:10 AM Application is not activated Kaspersky Internet Secur
ity
8/24/2010 12:23:49 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
Firewall
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
Firewall
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
Firewall
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
Firewall
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
Firewall
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 6)
8/24/2010 11:44:46 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/24/2010 10:08:19 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/24/2010 7:32:02 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/24/2010 7:30:39 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/24/2010 6:08:12 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/24/2010 12:23:54 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 8)
8/24/2010 10:41:08 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/24/2010 10:38:30 PM Task started Kaspersky Internet Security
Rootkit Scan
8/24/2010 8:04:47 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/24/2010 8:02:13 AM Task started Kaspersky Internet Security
Rootkit Scan
8/24/2010 6:40:55 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/24/2010 6:38:24 AM Task started Kaspersky Internet Security
Rootkit Scan
8/24/2010 12:56:39 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/24/2010 12:53:59 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 20)
8/24/2010 11:23:36 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 11:03:33 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 10:43:33 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 10:23:34 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 8:07:16 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 7:47:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 7:23:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 7:03:26 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 6:43:26 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 6:23:27 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 3:39:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 3:19:04 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 2:59:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 2:39:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 2:19:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 1:59:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 1:39:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 1:19:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 12:59:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/24/2010 12:39:02 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Wednesday (events: 195)
My Protection (events: 9)
8/25/2010 9:46:17 PM Databases are obsolete Kaspersky Internet Security
8/25/2010 4:16:16 PM Protection is not running Kaspersky Internet Secur
ity
8/25/2010 3:04:57 PM Databases are obsolete Kaspersky Internet Security
8/25/2010 7:44:39 AM Protection is not running Kaspersky Internet Secur
ity
8/25/2010 6:09:10 AM Databases are obsolete Kaspersky Internet Security
8/25/2010 3:40:47 AM Protection is not running Kaspersky Internet Secur
ity
8/25/2010 1:19:01 AM Databases are obsolete Kaspersky Internet Security
8/25/2010 1:17:36 AM Protection is not running Kaspersky Internet Secur
ity
8/25/2010 12:18:49 AM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 5)
8/25/2010 9:46:10 PM Task started Kaspersky Internet Security
File Anti-Virus
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
File Anti-Virus
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
File Anti-Virus
8/25/2010 1:18:55 AM Task started Kaspersky Internet Security
File Anti-Virus
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 5)
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/25/2010 1:18:56 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 5)
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/25/2010 3:04:50 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/25/2010 1:18:57 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 5)
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/25/2010 1:18:56 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 5)
8/25/2010 9:46:10 PM Task started Kaspersky Internet Security
Anti-Spam
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Anti-Spam
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Anti-Spam
8/25/2010 1:18:55 AM Task started Kaspersky Internet Security
Anti-Spam
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 43)
8/25/2010 9:47:34 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
Application Control
8/25/2010 3:07:03 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 3:06:52 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 3:06:19 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Application Control
8/25/2010 6:24:01 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 6:23:53 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 6:11:50 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 6:11:39 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 6:10:29 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Application Control
8/25/2010 3:21:51 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 3:21:45 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 3:10:52 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 3:10:39 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:42:22 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:42:15 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:40:55 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:40:48 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:39:48 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:39:39 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:38:52 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:38:45 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:38:03 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:37:57 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:37:28 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:37:22 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:36:31 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:36:24 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:35:39 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:35:33 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:35:25 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:35:17 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:23:47 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:23:41 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:22:10 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:22:00 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/25/2010 1:20:38 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/25/2010 1:20:21 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/25/2010 1:18:55 AM Task started Kaspersky Internet Security
Application Control
8/25/2010 12:20:10 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 26)
8/25/2010 9:47:44 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 3:07:07 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 3:06:26 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 7:00:07 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:59 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:52 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:44 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:37 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:29 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:59:19 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:24:04 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 6:11:54 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 3:21:54 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 3:10:56 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:42:25 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:40:58 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:39:52 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:38:55 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:38:06 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:37:31 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:36:35 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:35:42 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:23:51 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:22:13 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 1:20:44 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/25/2010 12:20:20 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 43)
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
Proactive Defense
8/25/2010 3:07:26 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 3:07:26 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 3:07:20 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 3:07:20 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Proactive Defense
8/25/2010 6:24:07 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 6:24:07 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 6:12:27 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 6:12:27 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 6:12:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 6:12:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Proactive Defense
8/25/2010 3:21:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 3:21:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 3:11:01 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 3:11:01 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:42:28 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:42:28 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:41:02 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:41:02 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:39:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:39:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:38:57 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:38:57 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:38:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:38:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:37:34 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:37:34 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:36:38 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:36:38 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:35:46 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:35:46 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:23:54 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:23:54 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:22:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:22:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:21:20 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 1:21:20 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/25/2010 1:20:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:20:58 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/25/2010 1:18:57 AM Task started Kaspersky Internet Security
Proactive Defense
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 5)
8/25/2010 9:46:08 PM Application is not activated Kaspersky Internet Secur
ity
8/25/2010 3:04:46 PM Application is not activated Kaspersky Internet Secur
ity
8/25/2010 6:09:01 AM Application is not activated Kaspersky Internet Secur
ity
8/25/2010 1:18:53 AM Application is not activated Kaspersky Internet Secur
ity
8/25/2010 12:18:39 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 5)
8/25/2010 9:46:10 PM Task started Kaspersky Internet Security
Firewall
8/25/2010 3:04:49 PM Task started Kaspersky Internet Security
Firewall
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
Firewall
8/25/2010 1:18:55 AM Task started Kaspersky Internet Security
Firewall
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 5)
8/25/2010 9:46:11 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/25/2010 3:04:50 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/25/2010 6:09:03 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/25/2010 1:18:57 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/25/2010 12:18:46 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 10)
8/25/2010 10:17:50 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/25/2010 10:16:22 PM Task started Kaspersky Internet Security
Rootkit Scan
8/25/2010 3:37:54 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/25/2010 3:35:01 PM Task started Kaspersky Internet Security
Rootkit Scan
8/25/2010 6:41:39 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/25/2010 6:39:14 AM Task started Kaspersky Internet Security
Rootkit Scan
8/25/2010 1:51:44 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/25/2010 1:49:07 AM Task started Kaspersky Internet Security
Rootkit Scan
8/25/2010 12:50:29 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/25/2010 12:48:54 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 24)
8/25/2010 11:41:24 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 11:21:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 11:01:24 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 10:41:24 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 10:21:24 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 10:01:25 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 4:00:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 3:40:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 3:20:05 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 7:44:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 7:24:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 7:04:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 6:44:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 6:24:17 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 3:34:10 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 3:14:09 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 2:54:09 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 2:34:10 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 2:14:09 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 1:54:09 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 1:34:10 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 1:13:56 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 12:53:56 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/25/2010 12:34:00 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Thursday (events: 285)
My Protection (events: 10)
8/26/2010 7:11:59 PM Databases are obsolete Kaspersky Internet Security
8/26/2010 3:13:56 PM Databases are obsolete Kaspersky Internet Security
8/26/2010 9:32:16 AM Protection is not running Kaspersky Internet Secur
ity
8/26/2010 6:25:18 AM Databases are obsolete Kaspersky Internet Security
8/26/2010 3:27:13 AM Protection is not running Kaspersky Internet Secur
ity
8/26/2010 2:49:04 AM Databases are obsolete Kaspersky Internet Security
8/26/2010 1:28:06 AM Protection is not running Kaspersky Internet Secur
ity
8/26/2010 1:01:26 AM Databases are obsolete Kaspersky Internet Security
8/26/2010 12:05:06 AM Databases are obsolete Kaspersky Internet Security
8/26/2010 12:04:05 AM Protection is not running Kaspersky Internet Secur
ity
File Anti-Virus (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
File Anti-Virus
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
File Anti-Virus
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
File Anti-Virus
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
File Anti-Virus
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
File Anti-Virus
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Anti-Spam
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Anti-Spam
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Anti-Spam
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Anti-Spam
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Anti-Spam
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 61)
8/26/2010 11:41:10 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 11:41:01 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 11:23:59 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 11:23:51 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 10:29:09 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 10:29:01 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 10:18:56 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 10:18:50 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 9:41:24 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 9:41:17 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 9:15:44 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 9:15:31 PM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/26/2010 9:15:15 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 9:13:20 PM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/26/2010 9:13:20 PM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/26/2010 9:13:18 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/26/2010 9:13:01 PM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 9:12:59 PM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/26/2010 9:12:43 PM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/26/2010 9:12:30 PM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/26/2010 8:16:16 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 8:16:10 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 8:15:10 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 8:13:10 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 8:13:04 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 7:14:26 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 7:13:36 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 7:13:20 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Application Control
8/26/2010 3:31:51 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 3:31:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 3:15:17 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Application Control
8/26/2010 6:59:30 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 6:59:21 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 6:27:50 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 6:27:42 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 6:26:38 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Application Control
8/26/2010 3:02:58 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 3:02:51 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 3:02:01 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 3:01:54 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 2:50:23 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Application Control
8/26/2010 1:25:17 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 1:25:10 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 1:03:47 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 1:03:40 AM Denied: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/26/2010 1:03:30 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/26/2010 1:02:46 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Application Control
8/26/2010 12:51:52 AM Allowed: Code intrusion PointBlank Code intrusion
d:\gemscool\point blank\pointblank.exe Code intrusion
8/26/2010 12:51:52 AM Allowed: Setting debug privileges PointBlank
Setting debug privileges Setting debug privileges
8/26/2010 12:51:49 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\EAGLENT.SYS Start driver
8/26/2010 12:51:45 AM Denied: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/26/2010 12:51:43 AM Allowed: Low level disk access PointBlank Low leve
l disk access Device\Harddisk0\DR0 Low level disk access
8/26/2010 12:51:28 AM Allowed: Using system program interfaces (DNS) HSUpdate
Use DNS caching system for conversion file.pb.gemscool.com Using system pro
gram interfaces (DNS)
8/26/2010 12:43:52 AM Allowed: Using system program interfaces (DNS) PBLaunch
er Use DNS caching system for conversion update.pb.gemscool.com Using sy
stem program interfaces (DNS)
8/26/2010 12:06:26 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 63)
8/26/2010 11:41:14 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 11:24:02 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 10:29:13 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 10:18:59 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 9:41:27 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 9:15:48 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 9:13:22 PM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:16:19 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:13:14 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 7:14:31 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 7:13:26 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:45:19 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:45:11 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:45:04 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:57 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:50 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:43 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:37 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:30 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:23 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:16 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:09 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:44:02 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:54 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:47 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:40 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:33 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:26 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:19 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:12 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 4:43:03 PM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 3:31:55 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:46 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:38 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:30 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:23 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:15 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:07 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:19:00 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:52 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:44 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:37 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:29 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:22 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:14 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:18:06 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:59 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:51 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:43 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:36 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:28 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 8:17:19 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 6:59:33 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 6:27:54 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 6:26:46 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 3:03:01 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 3:02:06 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 2:50:32 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 1:25:20 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 1:05:16 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 1:02:52 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 12:51:53 AM Denied PointBlank Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/26/2010 12:05:11 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 66)
8/26/2010 11:41:19 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 11:41:19 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 11:24:06 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 11:24:05 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 10:29:16 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 10:29:16 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 10:19:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 10:19:02 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 9:41:30 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 9:41:30 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 9:15:59 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 9:15:59 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 9:15:44 PM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/26/2010 9:15:31 PM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/26/2010 9:13:46 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/26/2010 9:13:46 PM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/26/2010 9:13:17 PM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/26/2010 9:13:01 PM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/26/2010 8:16:23 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 8:16:23 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 8:13:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 8:13:17 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 7:15:23 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 7:15:23 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 7:14:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 7:14:48 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Proactive Defense
8/26/2010 3:32:16 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 3:32:16 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 3:32:07 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 3:32:07 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Proactive Defense
8/26/2010 6:59:37 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 6:59:37 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 6:28:34 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 6:28:34 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 6:28:06 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 6:28:06 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Proactive Defense
8/26/2010 3:03:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 3:03:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 3:02:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 3:02:19 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 3:02:17 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 3:02:17 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Proactive Defense
8/26/2010 1:25:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 1:25:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 1:05:46 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 1:05:46 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 1:05:26 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 1:05:26 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/26/2010 1:05:12 AM Allowed: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/26/2010 1:03:48 AM Detected: PDM.Suspicious driver installation Audition
D:\AYODANCE\AUDITION.EXE
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Proactive Defense
8/26/2010 12:52:29 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 12:52:29 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/26/2010 12:52:14 AM Detected: PDM.Keylogger PBLauncher Keylogger activi
ty kernel mode memory patch
8/26/2010 12:52:14 AM Detected: PDM.Keylogger PBLauncher Keylogger activi
ty kernel mode memory patch
8/26/2010 12:52:14 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/26/2010 12:52:14 AM Detected: PDM.Keylogger PointBlank Keylogger activi
ty kernel mode memory patch
8/26/2010 12:51:54 AM Allowed: PDM.Suspicious driver installation PBLaunch
er D:\GEMSCOOL\POINT BLANK\PBLAUNCHER.EXE
8/26/2010 12:51:49 AM Detected: PDM.Suspicious driver installation PBLaunch
er D:\GEMSCOOL\POINT BLANK\PBLAUNCHER.EXE
8/26/2010 12:51:49 AM Allowed: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/26/2010 12:51:45 AM Detected: PDM.Suspicious driver installation PointBla
nk D:\GEMSCOOL\POINT BLANK\POINTBLANK.EXE
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 6)
8/26/2010 7:11:50 PM Application is not activated Kaspersky Internet Secur
ity
8/26/2010 3:13:46 PM Application is not activated Kaspersky Internet Secur
ity
8/26/2010 6:25:09 AM Application is not activated Kaspersky Internet Secur
ity
8/26/2010 2:48:55 AM Application is not activated Kaspersky Internet Secur
ity
8/26/2010 1:01:18 AM Application is not activated Kaspersky Internet Secur
ity
8/26/2010 12:04:55 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
Firewall
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
Firewall
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
Firewall
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
Firewall
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
Firewall
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 6)
8/26/2010 7:11:55 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/26/2010 3:13:51 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/26/2010 6:25:12 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/26/2010 2:48:58 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/26/2010 1:01:21 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/26/2010 12:05:00 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 10)
8/26/2010 7:44:33 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/26/2010 7:42:04 PM Task started Kaspersky Internet Security
Rootkit Scan
8/26/2010 3:46:36 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/26/2010 3:44:01 PM Task started Kaspersky Internet Security
Rootkit Scan
8/26/2010 6:57:46 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/26/2010 6:55:23 AM Task started Kaspersky Internet Security
Rootkit Scan
8/26/2010 3:21:51 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/26/2010 3:19:09 AM Task started Kaspersky Internet Security
Rootkit Scan
8/26/2010 12:36:42 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/26/2010 12:35:08 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 27)
8/26/2010 11:47:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 11:27:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 11:07:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 10:47:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 10:27:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 10:07:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 9:47:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 9:27:08 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 9:07:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 8:47:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 8:27:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 8:07:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 7:47:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 7:27:07 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 4:09:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 3:49:03 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 3:29:04 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 7:40:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 7:20:26 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 7:00:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 6:40:32 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 3:24:12 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 3:04:12 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 1:16:35 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 1:00:13 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 12:40:11 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/26/2010 12:20:11 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Yesterday (events: 261)
My Protection (events: 7)
8/27/2010 7:34:06 PM Databases are obsolete Kaspersky Internet Security
8/27/2010 5:09:02 PM Protection is not running Kaspersky Internet Secur
ity
8/27/2010 3:57:35 PM Databases are obsolete Kaspersky Internet Security
8/27/2010 8:27:45 AM Protection is not running Kaspersky Internet Secur
ity
8/27/2010 5:56:35 AM Databases are obsolete Kaspersky Internet Security
8/27/2010 3:42:23 AM Protection is not running Kaspersky Internet Secur
ity
8/27/2010 12:13:53 AM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 4)
8/27/2010 7:34:00 PM Task started Kaspersky Internet Security
File Anti-Virus
8/27/2010 3:57:29 PM Task started Kaspersky Internet Security
File Anti-Virus
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
File Anti-Virus
8/27/2010 12:13:46 AM Task started Kaspersky Internet Security
File Anti-Virus
Mail Anti-Virus (events: 4)
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/27/2010 3:57:30 PM Task started Kaspersky Internet Security
Mail Anti-Virus
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
Mail Anti-Virus
8/27/2010 12:13:47 AM Task started Kaspersky Internet Security
Mail Anti-Virus
Web Anti-Virus (events: 4)
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/27/2010 3:57:30 PM Task started Kaspersky Internet Security
Web Anti-Virus
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
Web Anti-Virus
8/27/2010 12:13:47 AM Task started Kaspersky Internet Security
Web Anti-Virus
Network Attack Blocker (events: 4)
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/27/2010 3:57:30 PM Task started Kaspersky Internet Security
Network Attack Blocker
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
Network Attack Blocker
8/27/2010 12:13:47 AM Task started Kaspersky Internet Security
Network Attack Blocker
Anti-Spam (events: 4)
8/27/2010 7:34:00 PM Task started Kaspersky Internet Security
Anti-Spam
8/27/2010 3:57:29 PM Task started Kaspersky Internet Security
Anti-Spam
8/27/2010 5:56:29 AM Task started Kaspersky Internet Security
Anti-Spam
8/27/2010 12:13:46 AM Task started Kaspersky Internet Security
Anti-Spam
Application Control (events: 75)
8/27/2010 11:32:40 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 11:32:34 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 11:27:40 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 11:27:30 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 10:06:46 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 10:06:41 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 10:04:14 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 10:04:07 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 10:03:44 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 10:03:39 PM Allowed: Using program interfaces of other process
RealUpgrade Launcher Using program interfaces of other process c:\progr
am files\real\realupgrade\realupgrade.exe Using program interfaces of othe
r process
8/27/2010 10:03:37 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 10:03:35 PM Allowed: Using system program interfaces (DNS) RealUpgr
ade Launcher Use DNS caching system for conversion client-software.real.com
Using system program interfaces (DNS)
8/27/2010 10:03:34 PM Allowed: Access to password storage Internet Explore
r Access to protected storage Access to password storage
8/27/2010 10:03:28 PM Allowed: Using program interfaces of other process
Internet Explorer Using program interfaces of other process c:\progr
am files\internet explorer\iexplore.exe Using program interfaces of other proces
s
8/27/2010 10:03:28 PM Allowed: Access to internal browser data Internet
Explorer Access to internal browser data Access to internal brows
er data
8/27/2010 10:03:23 PM Allowed: Using system program interfaces (DNS) Internet
Explorer Use DNS caching system for conversion ayodance.com Using sy
stem program interfaces (DNS)
8/27/2010 10:03:22 PM Allowed: Using program interfaces of other process
Internet Explorer Using program interfaces of other process c:\progr
am files\internet explorer\iexplore.exe Using program interfaces of other proces
s
8/27/2010 10:03:18 PM Allowed: Using system program interfaces (DNS) Internet
Explorer Use DNS caching system for conversion www.taazu.com Using sy
stem program interfaces (DNS)
8/27/2010 10:03:17 PM Allowed: Use command line of browser Audition
Use command line of browser HTTP://AYODANCE.COM Use command line of brow
ser
8/27/2010 10:01:03 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 10:00:56 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 9:59:53 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 9:55:10 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 9:54:44 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 9:54:31 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 8:27:18 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 8:27:06 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 7:35:27 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
Application Control
8/27/2010 3:59:47 PM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 3:59:31 PM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 3:58:55 PM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/27/2010 3:57:29 PM Task started Kaspersky Internet Security
Application Control
8/27/2010 7:16:19 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 7:16:12 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 7:14:18 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 7:14:12 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 7:12:56 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 7:12:23 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:47:16 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:47:10 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:44:09 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:44:02 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:36:27 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:36:18 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:33:54 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:33:47 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:19:25 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:19:19 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:18:18 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:18:11 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 6:16:05 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 6:15:55 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 5:57:52 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
Application Control
8/27/2010 2:20:34 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 2:20:25 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 2:02:35 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 2:02:29 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 1:56:31 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 1:56:24 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 1:09:29 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 1:09:22 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:33:56 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 12:33:50 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:32:58 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 12:32:42 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:30:53 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 12:30:46 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:20:06 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 12:19:57 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:15:35 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/27/2010 12:15:13 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/27/2010 12:15:12 AM Allowed: Start driver Absent Start driver C:\WINDO
WS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
8/27/2010 12:13:46 AM Task started Kaspersky Internet Security
Application Control
Self-Defense (events: 34)
8/27/2010 11:32:43 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 11:27:44 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 10:06:49 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 10:04:17 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 10:03:47 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 10:01:06 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 9:54:48 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 8:27:23 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 7:35:43 PM Denied Firefox Open C:\Program Files\Kaspersky Lab\K
aspersky Internet Security 2010\avp.exe
8/27/2010 7:35:35 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 3:59:52 PM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 3:59:00 PM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 7:38:06 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 7:16:22 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 7:14:21 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 7:12:59 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:47:19 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:44:12 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:36:31 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:33:57 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:19:28 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:18:21 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 6:16:09 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 5:56:37 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 2:20:38 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 2:02:39 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 1:56:35 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 1:09:32 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:34:00 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:33:01 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:30:56 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:20:09 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:15:40 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/27/2010 12:15:21 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 68)
8/27/2010 11:32:47 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 11:32:47 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 11:27:49 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 11:27:49 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:06:53 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:06:53 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:04:21 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:04:21 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:03:49 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:03:49 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:01:09 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 10:01:09 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 9:54:57 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 9:54:57 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 8:27:42 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 8:27:42 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 8:27:31 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 8:27:31 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
Proactive Defense
8/27/2010 4:00:19 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 4:00:19 PM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 3:59:52 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 3:59:52 PM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 3:57:30 PM Task started Kaspersky Internet Security
Proactive Defense
8/27/2010 7:16:26 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 7:16:26 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 7:14:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 7:14:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 7:13:03 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 7:13:03 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:47:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:47:23 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:44:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:44:16 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:36:34 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:36:34 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:34:02 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:34:02 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:19:32 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:19:32 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:18:56 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 6:18:56 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 6:18:25 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:18:24 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:16:21 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 6:16:21 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
Proactive Defense
8/27/2010 2:20:41 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 2:20:40 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 2:02:41 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 2:02:41 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 1:56:38 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 1:56:38 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 1:09:35 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 1:09:35 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:34:03 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:34:03 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:33:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:33:04 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:31:00 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:31:00 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:20:11 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:20:11 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:16:08 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 12:16:08 AM Detected: PDM.Keylogger Absent Keylogger activity
kernel mode memory patch
8/27/2010 12:15:56 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:15:56 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/27/2010 12:13:47 AM Task started Kaspersky Internet Security
Proactive Defense
License (events: 4)
8/27/2010 7:33:58 PM Application is not activated Kaspersky Internet Secur
ity
8/27/2010 3:57:27 PM Application is not activated Kaspersky Internet Secur
ity
8/27/2010 5:56:23 AM Application is not activated Kaspersky Internet Secur
ity
8/27/2010 12:13:42 AM Application is not activated Kaspersky Internet Secur
ity
Firewall (events: 4)
8/27/2010 7:34:00 PM Task started Kaspersky Internet Security
Firewall
8/27/2010 3:57:29 PM Task started Kaspersky Internet Security
Firewall
8/27/2010 5:56:29 AM Task started Kaspersky Internet Security
Firewall
8/27/2010 12:13:46 AM Task started Kaspersky Internet Security
Firewall
IM Anti-Virus (events: 4)
8/27/2010 7:34:01 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/27/2010 3:57:30 PM Task started Kaspersky Internet Security
IM Anti-Virus
8/27/2010 5:56:30 AM Task started Kaspersky Internet Security
IM Anti-Virus
8/27/2010 12:13:46 AM Task started Kaspersky Internet Security
IM Anti-Virus
Objects Scan (events: 12)
8/27/2010 8:06:04 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/27/2010 8:04:11 PM Task started Kaspersky Internet Security
Rootkit Scan
8/27/2010 4:30:15 PM Task completed Kaspersky Internet Security
Rootkit Scan
8/27/2010 4:27:40 PM Task started Kaspersky Internet Security
Rootkit Scan
8/27/2010 8:21:39 AM Task completed Kaspersky Internet Security
Full Scan
8/27/2010 8:17:44 AM Task stopped Kaspersky Internet Security
Virus Scan
8/27/2010 8:13:39 AM Task started Kaspersky Internet Security
Virus Scan
8/27/2010 7:38:21 AM Task started Kaspersky Internet Security
Full Scan
8/27/2010 6:29:28 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/27/2010 6:26:36 AM Task started Kaspersky Internet Security
Rootkit Scan
8/27/2010 12:46:32 AM Task completed Kaspersky Internet Security
Rootkit Scan
8/27/2010 12:43:56 AM Task started Kaspersky Internet Security
Rootkit Scan
My Update Center (events: 33)
8/27/2010 11:49:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 11:29:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 11:09:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 10:49:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 10:29:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 10:09:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 9:49:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 9:29:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 9:09:31 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 8:49:29 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 8:29:16 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 8:09:14 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 7:49:16 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 4:52:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 4:32:43 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 4:12:44 PM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 8:11:44 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 7:51:48 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 7:31:38 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 7:11:38 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 6:51:38 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 6:31:38 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 6:11:41 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 3:28:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 3:09:00 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 2:48:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 2:28:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 2:09:03 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 1:48:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 1:28:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 1:08:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 12:48:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/27/2010 12:28:59 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
Date: Today (events: 84)
Application Control (events: 19)
8/28/2010 12:48:28 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 12:48:35 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 12:58:06 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 12:58:13 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 1:05:13 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 1:05:22 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 2:05:11 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 2:05:21 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 2:06:42 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 2:06:48 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 2:56:33 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 2:58:05 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 3:00:18 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 3:15:07 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 3:15:24 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
8/28/2010 3:54:53 AM Microsoft Help Center Service Placed in group
Trusted Signed by the digital signature of entrusted manufacturers
8/28/2010 4:03:28 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 4:35:26 AM Allowed: Using system program interfaces (DNS) Audition
Client Patcher Use DNS caching system for conversion notice.ayodance.com
Using system program interfaces (DNS)
8/28/2010 4:35:38 AM Allowed: Start driver Absent Start driver C:\DOCUM
E~1\BAGOES\LOCALS~1\TEMP\EAGLENT.SYS Start driver
Self-Defense (events: 30)
8/28/2010 12:48:38 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 12:58:16 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 1:05:25 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 2:05:26 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 2:06:51 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 2:59:12 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:00:23 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:15:29 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:20 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:30 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:37 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:44 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:52 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:51:59 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:06 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:13 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:21 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:28 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:35 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:42 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:49 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:52:57 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:04 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:10 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:18 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:25 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:32 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 3:53:39 AM Denied Disk Defragmenter NTFS Module Open C:\Progr
am Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 4:35:44 AM Denied Audition Open C:\Program Files\Kaspers
ky Lab\Kaspersky Internet Security 2010\avp.exe
8/28/2010 5:10:33 AM Denied Windows Explorer Open C:\Program Files
\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
Proactive Defense (events: 16)
8/28/2010 12:48:42 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 12:48:42 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 12:58:19 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 12:58:19 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 1:05:28 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 1:05:28 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 2:05:45 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 2:05:45 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 2:06:54 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 2:06:55 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 3:00:39 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 3:00:39 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 3:15:52 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 3:15:52 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 4:36:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
8/28/2010 4:36:09 AM Detected: PDM.Keylogger Audition Keylogger activi
ty kernel mode memory patch
Objects Scan (events: 2)
8/28/2010 5:10:43 AM Task started Kaspersky Internet Security
Full Scan
8/28/2010 5:18:44 AM Task completed Kaspersky Internet Security
Full Scan
My Update Center (events: 17)
8/28/2010 12:09:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 12:29:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 12:49:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 1:09:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 1:29:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 1:49:30 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 2:09:30 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 2:29:51 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 2:49:53 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 3:09:30 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 3:29:31 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 3:49:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 4:09:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 4:29:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 4:49:31 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 5:09:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing
8/28/2010 5:29:29 AM Task cannot be started Kaspersky Internet Security
My Update Center License is missing

Das könnte Ihnen auch gefallen