Vous êtes sur la page 1sur 25

Absent (events: 158) 8/27/2009 7:35:36 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/27/2009 7:37:17 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.

SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/29/2009 8:36:08 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/29/2009 8:37:33 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/30/2009 7:47:46 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/30/2009 7:49:10 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/30/2009 11:04:40 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/30/2009 11:06:06 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/31/2009 10:13:46 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/31/2009 10:15:10 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/31/2009 12:08:23 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 8/31/2009 12:09:49 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 8:54:11 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 8:55:37 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 7:23:09 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 7:24:35 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 8:01:54 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/1/2009 8:03:19 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/2/2009 9:01:46 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/2/2009 9:03:12 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/3/2009 8:42:41 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/3/2009 8:44:07 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/3/2009 8:33:34 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/3/2009 8:34:58 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/5/2009 8:28:20 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/5/2009 8:29:45 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/6/2009 9:51:45 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/6/2009 7:57:25 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/6/2009 7:58:50 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/7/2009 8:28:15 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS

Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/7/2009 8:29:41 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/8/2009 9:12:49 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/8/2009 9:14:14 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/9/2009 9:02:23 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/9/2009 9:03:47 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/10/2009 9:13:19 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/10/2009 9:14:44 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/12/2009 8:23:32 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/12/2009 8:24:58 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/12/2009 2:46:30 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/12/2009 2:47:54 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/12/2009 5:12:44 PM Start driver C:\DOCUMENTS AND SETTINGS\MY-PC\LOCAL SE TTINGS\TEMP\NTH11B.TMP Allowed: KLPrivileges/KLPermissionAppAccess/KLPermission ProcManage/KLDrvStart 9/13/2009 9:17:20 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/13/2009 9:18:43 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/13/2009 2:25:47 PM Start driver C:\DOCUMENTS AND SETTINGS\MY-PC\LOCAL SE TTINGS\TEMP\AMSF2.TMP Allowed: KLPrivileges/KLPermissionAppAccess/KLPermission ProcManage/KLDrvStart 9/13/2009 3:32:01 PM Start driver C:\DOCUMENTS AND SETTINGS\MY-PC\LOCAL SE TTINGS\TEMP\ZGXF3.TMP Allowed: KLPrivileges/KLPermissionAppAccess/KLPermission ProcManage/KLDrvStart 9/13/2009 3:33:29 PM Start driver C:\DOCUMENTS AND SETTINGS\MY-PC\LOCAL SE TTINGS\TEMP\XDSF4.TMP Allowed: KLPrivileges/KLPermissionAppAccess/KLPermission ProcManage/KLDrvStart 9/14/2009 9:19:11 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/14/2009 9:20:34 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/15/2009 9:30:01 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/15/2009 9:31:26 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/15/2009 9:51:46 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/15/2009 10:01:06 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/15/2009 10:02:30 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/16/2009 9:10:03 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/16/2009 9:11:27 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 8:29:55 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 8:31:40 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS

Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 8:42:25 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 8:44:09 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 3:59:06 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/17/2009 4:00:31 PM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/19/2009 8:21:02 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/19/2009 8:22:30 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/19/2009 9:10:38 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/19/2009 9:12:06 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/24/2009 10:15:38 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/24/2009 10:17:03 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/26/2009 8:23:57 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\WILPAR.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/26/2009 8:25:24 AM Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLDrvStart 9/26/2009 1:11:31 PM Detected: Trojan.generic 9/26/2009 1:11:31 PM Detected: Trojan.generic 9/26/2009 1:11:31 PM Not terminated: Trojan.generic 9/26/2009 1:11:31 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:33 PM Detected: Trojan.generic 9/26/2009 1:11:33 PM Detected: Trojan.generic 9/26/2009 1:11:33 PM Not terminated: Trojan.generic 9/26/2009 1:11:33 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:35 PM Detected: Trojan.generic 9/26/2009 1:11:35 PM Detected: Trojan.generic 9/26/2009 1:11:35 PM Not terminated: Trojan.generic 9/26/2009 1:11:35 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:37 PM Detected: Trojan.generic 9/26/2009 1:11:37 PM Detected: Trojan.generic 9/26/2009 1:11:37 PM Not terminated: Trojan.generic 9/26/2009 1:11:37 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:39 PM Detected: Trojan.generic 9/26/2009 1:11:39 PM Detected: Trojan.generic 9/26/2009 1:11:39 PM Not terminated: Trojan.generic 9/26/2009 1:11:39 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:41 PM Detected: Trojan.generic 9/26/2009 1:11:41 PM Detected: Trojan.generic 9/26/2009 1:11:41 PM Not terminated: Trojan.generic 9/26/2009 1:11:41 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:43 PM Detected: Trojan.generic 9/26/2009 1:11:43 PM Detected: Trojan.generic 9/26/2009 1:11:43 PM Not terminated: Trojan.generic 9/26/2009 1:11:43 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:45 PM Detected: Trojan.generic 9/26/2009 1:11:45 PM Detected: Trojan.generic 9/26/2009 1:11:45 PM Not terminated: Trojan.generic 9/26/2009 1:11:45 PM Cannot be quarantined: Trojan.generic 9/26/2009 1:11:47 PM Detected: Trojan.generic 9/26/2009 1:11:47 PM Detected: Trojan.generic 9/26/2009 1:11:47 PM Not terminated: Trojan.generic

9/26/2009 1:11:47 PM 9/26/2009 1:11:50 PM 9/26/2009 1:11:50 PM 9/26/2009 1:11:50 PM 9/26/2009 1:11:50 PM 9/26/2009 1:11:52 PM 9/26/2009 1:11:52 PM 9/26/2009 1:11:52 PM 9/26/2009 1:11:52 PM 9/26/2009 1:11:54 PM 9/26/2009 1:11:54 PM 9/26/2009 1:11:54 PM 9/26/2009 1:11:54 PM 9/26/2009 1:11:56 PM 9/26/2009 1:11:56 PM 9/26/2009 1:11:56 PM 9/26/2009 1:11:56 PM 9/26/2009 1:11:58 PM 9/26/2009 1:11:58 PM 9/26/2009 1:11:58 PM 9/26/2009 1:11:58 PM 9/26/2009 1:12:00 PM 9/26/2009 1:12:00 PM 9/26/2009 1:12:00 PM 9/26/2009 1:12:00 PM 9/26/2009 1:12:02 PM 9/26/2009 1:12:02 PM 9/26/2009 1:12:02 PM 9/26/2009 1:12:02 PM 9/26/2009 1:12:04 PM 9/26/2009 1:12:04 PM 9/26/2009 1:12:04 PM 9/26/2009 1:12:04 PM 9/26/2009 1:12:06 PM 9/26/2009 1:12:06 PM 9/26/2009 1:12:06 PM 9/26/2009 1:12:06 PM 9/26/2009 1:12:08 PM 9/26/2009 1:12:08 PM 9/26/2009 1:12:08 PM 9/26/2009 1:12:08 PM 9/26/2009 1:12:10 PM 9/26/2009 1:12:10 PM 9/26/2009 1:12:10 PM 9/26/2009 1:12:10 PM 9/26/2009 1:12:12 PM 9/26/2009 1:12:12 PM 9/26/2009 1:12:12 PM 9/26/2009 1:12:12 PM 9/26/2009 1:12:14 PM 9/26/2009 1:12:14 PM 9/26/2009 1:12:14 PM 9/26/2009 1:12:14 PM Absent (events: 158) 9/26/2009 8:23:26 AM 9/26/2009 8:23:26 AM 9/26/2009 8:23:26 AM 9/24/2009 10:15:10 AM 9/24/2009 10:15:10 AM 9/24/2009 10:15:10 AM

Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.generic Cannot be quarantined: Trojan.generic Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started started started started started

9/19/2009 9:10:08 AM 9/19/2009 9:10:08 AM 9/19/2009 9:10:08 AM 9/19/2009 8:20:30 AM 9/19/2009 8:20:30 AM 9/19/2009 8:20:30 AM 9/17/2009 3:58:39 PM 9/17/2009 3:58:39 PM 9/17/2009 3:58:39 PM 9/17/2009 8:41:58 AM 9/17/2009 8:41:57 AM 9/17/2009 8:41:57 AM 9/17/2009 8:29:27 AM 9/17/2009 8:29:27 AM 9/17/2009 8:29:27 AM 9/16/2009 9:09:36 AM 9/16/2009 9:09:36 AM 9/16/2009 9:09:36 AM 9/15/2009 10:00:36 AM 9/15/2009 10:00:36 AM 9/15/2009 10:00:36 AM 9/15/2009 9:50:20 AM 9/15/2009 9:50:20 AM 9/15/2009 9:50:20 AM 9/15/2009 9:29:35 AM 9/15/2009 9:29:35 AM 9/15/2009 9:29:35 AM 9/14/2009 9:18:43 AM 9/14/2009 9:18:43 AM 9/14/2009 9:18:43 AM 9/13/2009 9:16:54 AM 9/13/2009 9:16:54 AM 9/13/2009 9:16:54 AM 9/12/2009 2:46:06 PM 9/12/2009 2:46:06 PM 9/12/2009 2:46:06 PM 9/12/2009 8:23:08 AM 9/12/2009 8:23:08 AM 9/12/2009 8:23:08 AM 9/10/2009 9:12:57 AM 9/10/2009 9:12:57 AM 9/10/2009 9:12:57 AM 9/9/2009 9:02:00 AM 9/9/2009 9:02:00 AM 9/9/2009 9:02:00 AM 9/8/2009 9:12:27 AM 9/8/2009 9:12:27 AM 9/8/2009 9:12:27 AM 9/7/2009 8:27:54 AM 9/7/2009 8:27:54 AM 9/7/2009 8:27:54 AM 9/6/2009 7:57:06 PM 9/6/2009 7:57:06 PM 9/6/2009 7:57:06 PM 9/6/2009 9:50:12 AM 9/6/2009 9:50:12 AM 9/6/2009 9:50:12 AM 9/5/2009 8:27:56 AM 9/5/2009 8:27:56 AM 9/5/2009 8:27:56 AM

Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Firewall Task started Proactive Defense Task Application Filtering Task Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started Proactive Defense Task Application Filtering Task Firewall Task started

started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started started

9/3/2009 8:33:13 PM Proactive Defense Task started 9/3/2009 8:33:13 PM Application Filtering Task started 9/3/2009 8:33:13 PM Firewall Task started 9/3/2009 8:42:20 AM Proactive Defense Task started 9/3/2009 8:42:20 AM Application Filtering Task started 9/3/2009 8:42:20 AM Firewall Task started 9/2/2009 9:01:24 AM Proactive Defense Task started 9/2/2009 9:01:24 AM Application Filtering Task started 9/2/2009 9:01:24 AM Firewall Task started 9/1/2009 8:01:33 PM Proactive Defense Task started 9/1/2009 8:01:33 PM Application Filtering Task started 9/1/2009 8:01:33 PM Firewall Task started 9/1/2009 7:22:48 PM Proactive Defense Task started 9/1/2009 7:22:48 PM Application Filtering Task started 9/1/2009 7:22:48 PM Firewall Task started 9/1/2009 8:53:50 AM Proactive Defense Task started 9/1/2009 8:53:49 AM Application Filtering Task started 9/1/2009 8:53:49 AM Firewall Task started 8/31/2009 12:08:03 PM Proactive Defense Task started 8/31/2009 12:08:03 PM Application Filtering Task started 8/31/2009 12:08:03 PM Firewall Task started 8/31/2009 10:13:24 AM Proactive Defense Task started 8/31/2009 10:13:24 AM Application Filtering Task started 8/31/2009 10:13:24 AM Firewall Task started 8/30/2009 11:04:17 AM Proactive Defense Task started 8/30/2009 11:04:17 AM Application Filtering Task started 8/30/2009 11:04:17 AM Firewall Task started 8/30/2009 7:47:24 AM Proactive Defense Task started 8/30/2009 7:47:24 AM Application Filtering Task started 8/30/2009 7:47:24 AM Firewall Task started 8/29/2009 8:35:43 AM Proactive Defense Task started 8/29/2009 8:35:43 AM Application Filtering Task started 8/29/2009 8:35:43 AM Firewall Task started 8/27/2009 7:35:06 PM Proactive Defense Task started 8/27/2009 7:35:06 PM Application Filtering Task started 8/27/2009 7:35:06 PM Firewall Task started Absent (events: 158) 9/17/2009 4:08:41 PM Placed in group Trusted/MICROSOFT Absent (events: 158) 9/15/2009 1:53:46 PM Placed in group Trusted/MICROSOFT Absent (events: 158) 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero .exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend 9/12/2009 4:59:50 PM Suspend another process c:\program files\ahead\nero\nero

.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSus pend Absent (events: 158) 9/1/2009 8:05:30 PM Placed in group Trusted/MICROSOFT Absent (events: 158) 8/29/2009 5:47:37 PM Access to critical system objects Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLCriticalCOMAccess 8/29/2009 5:47:33 PM Access to critical system objects Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLCriticalCOMAccess Absent (events: 158) 9/12/2009 2:53:48 PM Placed in group Trusted/MICROSOFT Absent (events: 158) 9/15/2009 9:46:35 AM Placed in group Trusted/MICROSOFT 9/12/2009 2:30:15 PM Placed in group Trusted Absent (events: 158) 9/14/2009 2:52:18 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:52:25 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:52:53 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 2:52:53 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 2:52:53 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 2:52:52 PM Windows shutdown Allowed: KLPrivileges/KL PermissionSystem/KLPermissionStrange/KLWindowsShutDown 9/14/2009 2:52:52 PM Placed in group Low Restricted Absent (events: 158) 9/14/2009 2:57:09 PM Placed in group Trusted/NERO Absent (events: 158) 9/12/2009 2:22:58 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:13 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:13 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:14 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:14 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:19 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:22 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:24 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:31 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:39 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:52 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:53 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:58:17 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:58:28 PM Placed in group Trusted/IGOR PAVLOV Absent (events: 158) 9/14/2009 2:58:17 PM Placed in group Trusted/NERO

Absent (events: 158) 9/12/2009 2:24:18 PM Placed in group Trusted/NERO Absent (events: 158) 9/12/2009 9:04:21 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 9:04:21 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 9:04:21 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess Absent (events: 158) 9/12/2009 5:40:59 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:40:59 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:59 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:59 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:59 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 5:40:59 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:40:59 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:40:14 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:40:14 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:14 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:14 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:14 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:40:14 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 5:40:14 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:40:14 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:14:11 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:14:11 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:14:11 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:14:11 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/12/2009 5:14:11 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 5:14:11 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:14:11 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/12/2009 5:12:43 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/10/2009 5:00:12 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 5:00:12 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend

9/10/2009 5:00:12 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/10/2009 5:00:12 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/10/2009 5:00:12 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/10/2009 5:00:11 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 5:00:11 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 3:57:17 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 3:57:17 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/10/2009 3:57:17 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/10/2009 3:57:17 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/10/2009 3:57:17 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/10/2009 3:57:17 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 3:57:17 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/10/2009 3:54:29 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/10/2009 3:53:46 PM Placed in group Trusted/GARENA INTERACTIVE Absent (events: 158) 9/10/2009 3:57:16 PM Placed in group Low Restricted Absent (events: 158) 9/10/2009 8:34:59 PM Placed in group Trusted/MOZILLA Absent (events: 158) 9/5/2009 3:08:53 PM Placed in group Low Restricted Absent (events: 158) 8/27/2009 7:37:18 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 8/27/2009 7:35:58 PM Windows shutdown Allowed: KLPrivileges/KL PermissionSystem/KLPermissionStrange/KLWindowsShutDown 8/27/2009 7:35:57 PM Placed in group Low Restricted Absent (events: 158) 8/29/2009 5:47:20 PM Placed in group Low Restricted Absent (events: 158) 9/14/2009 1:29:24 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 8:40:18 AM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/9/2009 5:02:45 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/9/2009 2:48:16 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/7/2009 7:36:53 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/7/2009 9:02:58 AM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/5/2009 8:04:55 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/5/2009 8:31:39 AM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/3/2009 3:35:16 PM Use browsers API Allowed: KLPrivileges/KL PermissionSystem/KLPermissionHiddenNetAct/KLUseBrowserAPI

9/3/2009 3:35:16 PM Access to internal browser data Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLShellWindowsAcceess 9/3/2009 3:35:16 PM Access to internal browser data Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLShellWindowsAcceess 9/2/2009 5:00:44 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/1/2009 8:03:39 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/1/2009 2:29:21 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 8/30/2009 6:41:57 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 8/29/2009 5:49:25 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 8/29/2009 5:48:51 PM Placed in group Low Restricted Absent (events: 158) 8/29/2009 5:48:53 PM Placed in group Low Restricted Absent (events: 158) 8/29/2009 6:23:07 PM Placed in group Low Restricted Absent (events: 158) 9/5/2009 9:49:42 AM Placed in group Trusted Absent (events: 158) 9/5/2009 3:03:43 PM Placed in group Low Restricted Absent (events: 158) 9/7/2009 9:10:02 AM Placed in group Low Restricted Absent (events: 158) 9/7/2009 2:36:15 PM Placed in group Low Restricted Absent (events: 158) 9/9/2009 9:06:30 AM Placed in group Trusted/REALNETWORKS Absent (events: 158) 9/9/2009 9:06:38 AM Placed in group Trusted/REALNETWORKS Absent (events: 158) 9/10/2009 2:39:16 PM Placed in group Trusted/GARENA INTERACTIVE Absent (events: 158) 9/12/2009 5:12:17 PM Placed in group Low Restricted 9/10/2009 3:54:09 PM Placed in group Low Restricted Absent (events: 158) 9/12/2009 2:21:36 PM Autorun Denied: KLPrivileges/KLSelfStart 9/12/2009 2:21:14 PM Autorun Denied: KLPrivileges/KLSelfStart 9/12/2009 2:21:13 PM Placed in group Untrusted Absent (events: 158) 9/12/2009 2:23:38 PM Placed in group Trusted/NERO Absent (events: 158) 9/12/2009 2:24:53 PM Placed in group Trusted/NERO Absent (events: 158) 9/12/2009 2:31:47 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 2:31:47 PM Windows shutdown Allowed: KLPrivileges/KL PermissionSystem/KLPermissionStrange/KLWindowsShutDown 9/12/2009 2:31:30 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 2:31:30 PM Windows shutdown Allowed: KLPrivileges/KL PermissionSystem/KLPermissionStrange/KLWindowsShutDown 9/12/2009 2:30:59 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/12/2009 2:30:58 PM Windows shutdown Allowed: KLPrivileges/KL PermissionSystem/KLPermissionStrange/KLWindowsShutDown 9/12/2009 2:30:53 PM Placed in group Low Restricted Absent (events: 158) 9/12/2009 2:31:02 PM Placed in group Trusted

Absent (events: 158) 9/12/2009 2:34:11 PM Placed in group Trusted/AHEAD SOFTWARE Absent (events: 158) 9/12/2009 4:59:32 PM Low level disk access Device\Harddisk3\DR9 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 4:59:32 PM Low level disk access Device\Harddisk2\DR4 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 4:59:32 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 4:59:32 PM Low level disk access Device\Harddisk1\DR3 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 4:59:32 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 4:59:32 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:40:52 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:37:14 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:35:32 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:35:19 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\Harddisk3\DR7 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\Harddisk2\DR5 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\CdRom0 Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\Harddisk1\DR3 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:46 PM Low level disk access Device\Harddisk0\DR0 Allowed: KLPrivileges/KLPermissionSystem/KLPermissionSysObjAccess/KLLLDiskAccess 9/12/2009 2:34:45 PM Placed in group Low Restricted Absent (events: 158) 9/12/2009 2:52:08 PM Placed in group Trusted/SUN MICROSYSTEMS Absent (events: 158) 9/12/2009 2:52:32 PM Placed in group Trusted/SUN MICROSYSTEMS Absent (events: 158) 9/12/2009 2:52:35 PM Placed in group Trusted/YAHOO Absent (events: 158) 9/12/2009 2:52:38 PM Placed in group Low Restricted Absent (events: 158) 9/12/2009 2:53:20 PM Placed in group Trusted/SUN MICROSYSTEMS Absent (events: 158) 9/12/2009 2:54:26 PM Placed in group Trusted/SUN MICROSYSTEMS Absent (events: 158) 9/12/2009 2:54:50 PM Placed in group Trusted/SUN MICROSYSTEMS Absent (events: 158) 9/12/2009 2:54:52 PM Placed in group Trusted/YAHOO Absent (events: 158) 9/12/2009 2:54:53 PM Placed in group Low Restricted Absent (events: 158) 9/13/2009 4:19:23 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 4:19:23 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 4:19:23 PM Suspend another process h:\dota\war3.exe Allowed:

KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 4:19:23 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 4:19:23 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 4:19:23 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/13/2009 4:19:22 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 4:19:22 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 3:34:26 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 3:34:26 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 3:34:26 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 3:34:26 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 3:34:26 PM Suspend another process h:\dota\war3.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLSuspend 9/13/2009 3:34:26 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/13/2009 3:34:26 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 3:34:26 PM Code intrusion h:\dota\war3.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/13/2009 3:33:28 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/13/2009 3:31:58 PM Placed in group Trusted/GARENA INTERACTIVE Absent (events: 158) 9/13/2009 3:32:20 PM Placed in group Low Restricted Absent (events: 158) 9/26/2009 10:00:55 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/26/2009 8:51:20 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/24/2009 4:15:27 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/24/2009 2:56:50 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/24/2009 2:25:50 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/24/2009 1:53:02 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/24/2009 10:27:49 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 12:57:27 PM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 11:58:29 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 11:55:59 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 11:55:42 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 11:44:20 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 10:58:36 AM Setting debug privileges Allowed: KLPrivi leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 10:41:31 AM Setting debug privileges Allowed: KLPrivi

leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 10:12:41 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 9:01:05 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 8:38:10 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 8:35:10 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/19/2009 8:25:51 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 7:24:26 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 4:29:17 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 4:12:17 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 10:30:55 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 10:26:10 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 10:25:28 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 9:27:42 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 8:56:19 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/17/2009 8:32:31 AM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 7:26:26 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 7:09:55 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 6:55:28 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 6:04:12 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 5:06:59 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 4:47:12 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 4:37:08 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 3:45:12 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 2:31:50 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 2:10:49 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/16/2009 1:36:16 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:59:24 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:57:18 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:31:16 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:28:13 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:26:43 PM Setting debug privileges Allowed:

KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi

leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:25:31 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 4:24:55 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 3:16:41 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 2:51:41 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 2:49:29 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 7:17:51 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 7:13:53 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 6:54:41 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 6:19:42 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 5:12:49 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 5:07:03 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 4:39:51 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 3:06:57 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 3:06:55 PM Placed in group Low Restricted 9/14/2009 2:13:09 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 2:13:08 PM Placed in group Low Restricted Absent (events: 158) 9/14/2009 2:51:13 PM Placed in group Trusted/NERO Absent (events: 158) 9/14/2009 2:57:46 PM Placed in group Trusted/MICROSOFT Absent (events: 158) 9/16/2009 6:45:25 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:29:35 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/15/2009 7:29:34 PM Placed in group Low Restricted 9/14/2009 6:16:02 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 6:01:01 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/14/2009 6:00:59 PM Placed in group Low Restricted Absent (events: 158) 9/15/2009 9:53:57 AM Placed in group Trusted Absent (events: 158) 9/15/2009 9:58:30 AM Placed in group Low Restricted Absent (events: 158) 9/15/2009 10:01:15 AM Placed in group Low Restricted Absent (events: 158) 9/17/2009 8:38:17 AM Placed in group Low Restricted Absent (events: 158) 9/17/2009 11:01:29 AM Placed in group Trusted/NERO Absent (events: 158) 9/26/2009 8:26:58 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY Absent (events: 158) 9/26/2009 8:36:56 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY

KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi

KLPrivi KLPrivi KLPrivi KLPrivi

Absent (events: 158) 9/26/2009 8:36:57 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY Absent (events: 158) 9/26/2009 8:37:06 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY Absent (events: 158) 9/26/2009 8:37:16 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY Absent (events: 158) 9/26/2009 8:37:40 AM Placed in group Trusted/ORENBURG RESOURCES Absent (events: 158) 9/26/2009 8:37:40 AM Placed in group Trusted/GOOGLE Absent (events: 158) 9/26/2009 8:44:39 AM Placed in group Trusted/SHENZHEN QVOD TECHNOLOGY Absent (events: 158) 9/26/2009 8:50:54 AM Placed in group Trusted/GOOGLE Absent (events: 158) 9/26/2009 8:50:57 AM Placed in group Trusted/GOOGLE Absent (events: 158) 9/26/2009 1:08:26 PM Placed in group Low Restricted 9/26/2009 1:08:26 PM Code intrusion f:\c\settings\cl.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion f:\c\settings\cl.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Setting debug privileges Allowed: leges/KLPermissionSystem/KLPermissionPrivileges/KLSetDbgPrivilege 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject

KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi KLPrivi

9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject

Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi Allowed: KLPrivi

9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:26 PM Code intrusion c:\windows\explorer.exe Allowed: KLPrivi leges/KLPermissionAppAccess/KLPermissionProcEmbed/KLCodeInject 9/26/2009 1:08:37 PM F:\C\SETTINGS\CL.EXE Detected: Trojan.generic 9/26/2009 1:08:37 PM F:\C\SETTINGS\CL.EXE Detected: Trojan.generic 9/26/2009 1:08:37 PM F:\C\SETTINGS\CL.EXE Not terminated: Trojan.g eneric 9/26/2009 1:08:39 PM F:\C\SETTINGS\CL.EXE Detected: Trojan.generic 9/26/2009 1:08:39 PM F:\C\SETTINGS\CL.EXE Detected: Trojan.generic

9/26/2009 1:08:39 eneric 9/26/2009 1:08:39 rojan.generic 9/26/2009 1:08:41 9/26/2009 1:08:41 9/26/2009 1:08:41 eneric 9/26/2009 1:08:41 rojan.generic 9/26/2009 1:08:43 9/26/2009 1:08:43 9/26/2009 1:08:43 eneric 9/26/2009 1:08:43 rojan.generic 9/26/2009 1:08:45 9/26/2009 1:08:45 9/26/2009 1:08:45 eneric 9/26/2009 1:08:46 rojan.generic 9/26/2009 1:08:47 9/26/2009 1:08:47 9/26/2009 1:08:47 eneric 9/26/2009 1:08:50 9/26/2009 1:08:51 9/26/2009 1:08:51 eneric 9/26/2009 1:08:51 rojan.generic 9/26/2009 1:08:53 9/26/2009 1:08:53 9/26/2009 1:08:53 eneric 9/26/2009 1:08:53 rojan.generic 9/26/2009 1:08:55 9/26/2009 1:08:55 9/26/2009 1:08:55 eneric 9/26/2009 1:08:55 rojan.generic 9/26/2009 1:08:57 9/26/2009 1:08:57 9/26/2009 1:08:57 eneric 9/26/2009 1:08:57 rojan.generic 9/26/2009 1:08:59 9/26/2009 1:09:00 9/26/2009 1:09:00 eneric 9/26/2009 1:09:00 rojan.generic 9/26/2009 1:09:02 9/26/2009 1:09:02 9/26/2009 1:09:02 eneric

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g

9/26/2009 1:09:02 rojan.generic 9/26/2009 1:09:04 9/26/2009 1:09:04 9/26/2009 1:09:04 eneric 9/26/2009 1:09:06 9/26/2009 1:09:06 9/26/2009 1:09:06 eneric 9/26/2009 1:09:07 rojan.generic 9/26/2009 1:09:09 9/26/2009 1:09:09 9/26/2009 1:09:09 eneric 9/26/2009 1:09:09 rojan.generic 9/26/2009 1:09:11 9/26/2009 1:09:11 9/26/2009 1:09:11 eneric 9/26/2009 1:09:11 rojan.generic 9/26/2009 1:09:13 9/26/2009 1:09:13 9/26/2009 1:09:13 eneric 9/26/2009 1:09:13 rojan.generic 9/26/2009 1:09:15 9/26/2009 1:09:15 9/26/2009 1:09:15 eneric 9/26/2009 1:09:15 rojan.generic 9/26/2009 1:09:18 9/26/2009 1:09:18 9/26/2009 1:09:18 eneric 9/26/2009 1:09:20 9/26/2009 1:09:20 9/26/2009 1:09:20 eneric 9/26/2009 1:09:20 rojan.generic 9/26/2009 1:09:22 9/26/2009 1:09:22 9/26/2009 1:09:22 eneric 9/26/2009 1:09:22 rojan.generic 9/26/2009 1:09:24 9/26/2009 1:09:24 9/26/2009 1:09:24 eneric 9/26/2009 1:09:24 rojan.generic 9/26/2009 1:09:26 9/26/2009 1:09:26

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic

9/26/2009 1:09:26 eneric 9/26/2009 1:09:26 rojan.generic 9/26/2009 1:09:28 9/26/2009 1:09:29 9/26/2009 1:09:29 eneric 9/26/2009 1:09:29 rojan.generic 9/26/2009 1:09:31 9/26/2009 1:09:31 9/26/2009 1:09:31 eneric 9/26/2009 1:09:33 9/26/2009 1:09:33 9/26/2009 1:09:33 eneric 9/26/2009 1:09:35 9/26/2009 1:09:35 9/26/2009 1:09:35 eneric 9/26/2009 1:09:35 rojan.generic 9/26/2009 1:09:37 9/26/2009 1:09:37 9/26/2009 1:09:37 eneric 9/26/2009 1:09:37 rojan.generic 9/26/2009 1:09:39 9/26/2009 1:09:39 9/26/2009 1:09:40 eneric 9/26/2009 1:09:40 rojan.generic 9/26/2009 1:09:42 9/26/2009 1:09:42 9/26/2009 1:09:42 eneric 9/26/2009 1:09:42 rojan.generic 9/26/2009 1:09:44 9/26/2009 1:09:44 9/26/2009 1:09:44 eneric 9/26/2009 1:09:44 rojan.generic 9/26/2009 1:09:46 9/26/2009 1:09:46 9/26/2009 1:09:46 eneric 9/26/2009 1:09:49 9/26/2009 1:09:49 9/26/2009 1:09:49 eneric 9/26/2009 1:09:49 rojan.generic 9/26/2009 1:09:51 9/26/2009 1:09:51

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic

9/26/2009 1:09:51 eneric 9/26/2009 1:09:51 rojan.generic 9/26/2009 1:09:53 9/26/2009 1:09:53 9/26/2009 1:09:53 eneric 9/26/2009 1:09:53 rojan.generic 9/26/2009 1:09:55 9/26/2009 1:09:55 9/26/2009 1:09:55 eneric 9/26/2009 1:09:55 rojan.generic 9/26/2009 1:09:57 9/26/2009 1:09:57 9/26/2009 1:09:58 eneric 9/26/2009 1:09:58 rojan.generic 9/26/2009 1:10:00 9/26/2009 1:10:00 9/26/2009 1:10:00 eneric 9/26/2009 1:10:00 rojan.generic 9/26/2009 1:10:02 9/26/2009 1:10:02 9/26/2009 1:10:02 eneric 9/26/2009 1:10:04 9/26/2009 1:10:05 9/26/2009 1:10:05 eneric 9/26/2009 1:10:05 rojan.generic 9/26/2009 1:10:07 9/26/2009 1:10:07 9/26/2009 1:10:07 eneric 9/26/2009 1:10:07 rojan.generic 9/26/2009 1:10:09 9/26/2009 1:10:09 9/26/2009 1:10:09 eneric 9/26/2009 1:10:09 rojan.generic 9/26/2009 1:10:11 9/26/2009 1:10:11 9/26/2009 1:10:11 eneric 9/26/2009 1:10:11 rojan.generic 9/26/2009 1:10:13 9/26/2009 1:10:13 9/26/2009 1:10:13 eneric

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g

9/26/2009 1:10:13 rojan.generic 9/26/2009 1:10:16 9/26/2009 1:10:16 9/26/2009 1:10:16 eneric 9/26/2009 1:10:18 9/26/2009 1:10:18 9/26/2009 1:10:18 eneric 9/26/2009 1:10:18 rojan.generic 9/26/2009 1:10:20 9/26/2009 1:10:20 9/26/2009 1:10:20 eneric 9/26/2009 1:10:20 rojan.generic 9/26/2009 1:10:22 9/26/2009 1:10:22 9/26/2009 1:10:22 eneric 9/26/2009 1:10:22 rojan.generic 9/26/2009 1:10:24 9/26/2009 1:10:24 9/26/2009 1:10:24 eneric 9/26/2009 1:10:24 rojan.generic 9/26/2009 1:10:26 9/26/2009 1:10:26 9/26/2009 1:10:26 eneric 9/26/2009 1:10:26 rojan.generic 9/26/2009 1:10:28 9/26/2009 1:10:28 9/26/2009 1:10:28 eneric 9/26/2009 1:10:30 9/26/2009 1:10:30 9/26/2009 1:10:30 eneric 9/26/2009 1:10:30 rojan.generic 9/26/2009 1:10:32 9/26/2009 1:10:32 9/26/2009 1:10:32 eneric 9/26/2009 1:10:32 rojan.generic 9/26/2009 1:10:34 9/26/2009 1:10:34 9/26/2009 1:10:34 eneric 9/26/2009 1:10:34 rojan.generic 9/26/2009 1:10:36 9/26/2009 1:10:36

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic

9/26/2009 1:10:36 eneric 9/26/2009 1:10:36 rojan.generic 9/26/2009 1:10:38 9/26/2009 1:10:38 9/26/2009 1:10:38 eneric 9/26/2009 1:10:38 rojan.generic 9/26/2009 1:10:40 9/26/2009 1:10:40 9/26/2009 1:10:40 eneric 9/26/2009 1:10:42 9/26/2009 1:10:42 9/26/2009 1:10:42 eneric 9/26/2009 1:10:42 rojan.generic 9/26/2009 1:10:44 9/26/2009 1:10:44 9/26/2009 1:10:44 eneric 9/26/2009 1:10:44 rojan.generic 9/26/2009 1:10:46 9/26/2009 1:10:46 9/26/2009 1:10:46 eneric 9/26/2009 1:10:46 rojan.generic 9/26/2009 1:10:48 9/26/2009 1:10:48 9/26/2009 1:10:48 eneric 9/26/2009 1:10:48 rojan.generic 9/26/2009 1:10:50 9/26/2009 1:10:50 9/26/2009 1:10:50 eneric 9/26/2009 1:10:50 rojan.generic 9/26/2009 1:10:52 9/26/2009 1:10:52 9/26/2009 1:10:52 eneric 9/26/2009 1:10:52 rojan.generic 9/26/2009 1:10:54 9/26/2009 1:10:54 9/26/2009 1:10:54 eneric 9/26/2009 1:10:56 9/26/2009 1:10:56 9/26/2009 1:10:56 eneric 9/26/2009 1:10:56 rojan.generic

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T

9/26/2009 1:10:58 9/26/2009 1:10:58 9/26/2009 1:10:58 eneric 9/26/2009 1:10:58 rojan.generic 9/26/2009 1:11:00 9/26/2009 1:11:00 9/26/2009 1:11:00 eneric 9/26/2009 1:11:00 rojan.generic 9/26/2009 1:11:02 9/26/2009 1:11:02 9/26/2009 1:11:02 eneric 9/26/2009 1:11:02 rojan.generic 9/26/2009 1:11:04 9/26/2009 1:11:04 9/26/2009 1:11:04 eneric 9/26/2009 1:11:04 rojan.generic 9/26/2009 1:11:06 9/26/2009 1:11:06 9/26/2009 1:11:06 eneric 9/26/2009 1:11:08 9/26/2009 1:11:08 9/26/2009 1:11:08 eneric 9/26/2009 1:11:08 rojan.generic 9/26/2009 1:11:10 9/26/2009 1:11:10 9/26/2009 1:11:10 eneric 9/26/2009 1:11:10 rojan.generic 9/26/2009 1:11:12 9/26/2009 1:11:12 9/26/2009 1:11:12 eneric 9/26/2009 1:11:12 rojan.generic 9/26/2009 1:11:14 9/26/2009 1:11:14 9/26/2009 1:11:14 eneric 9/26/2009 1:11:14 rojan.generic 9/26/2009 1:11:16 9/26/2009 1:11:16 9/26/2009 1:11:16 eneric 9/26/2009 1:11:16 rojan.generic 9/26/2009 1:11:18 9/26/2009 1:11:18

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic

9/26/2009 1:11:18 eneric 9/26/2009 1:11:20 9/26/2009 1:11:20 9/26/2009 1:11:20 eneric 9/26/2009 1:11:20 rojan.generic 9/26/2009 1:11:23 9/26/2009 1:11:23 9/26/2009 1:11:23 eneric 9/26/2009 1:11:23 rojan.generic 9/26/2009 1:11:25 9/26/2009 1:11:25 9/26/2009 1:11:25 eneric 9/26/2009 1:11:25 rojan.generic 9/26/2009 1:11:27 9/26/2009 1:11:27 9/26/2009 1:11:27 eneric 9/26/2009 1:11:27 rojan.generic 9/26/2009 1:11:29 9/26/2009 1:11:29 9/26/2009 1:11:29 eneric 9/26/2009 1:11:29 rojan.generic Absent (events: 9/26/2009 1:11:33 9/26/2009 1:11:32

PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM PM

F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE F:\C\SETTINGS\CL.EXE

Not terminated: Trojan.g Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T Detected: Trojan.generic Detected: Trojan.generic Not terminated: Trojan.g Cannot be quarantined: T

158) PM Autorun Denied: KLPrivileges/KLSelfStart PM Placed in group Untrusted

Vous aimerez peut-être aussi