26-08-2008 20:06:08 Tilladt (based on user decision) value "PCMService" (new data: ""C:\Programmer\Medion Home Cinema XL II\PowerCinema\PCMService.exe"") Tilføjet in System Startup global entry! 11-09-2008 15:48:33 Tilladt (based on user decision) value "BootExecute" (new data: "autocheck autochk * sprecovr \SystemRoot\sprecovr.txt ") Ændret in Session manager! 11-09-2008 15:52:35 Tilladt (based on user decision) value "TSClientMSIUninstaller" (new data: "cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"") Tilføjet in System Startup user entry! 11-09-2008 15:52:37 Tilladt (based on user decision) value "TSClientAXDisabler" (new data: "cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat"") Tilføjet in System Startup user entry! 11-09-2008 15:52:38 Tilladt (based on user decision) value "dimsntfy" (new data: "") Tilføjet in Winlogon Notifiers! 11-09-2008 16:00:51 Tilladt (based on user decision) value "TSClientMSIUninstaller" (new data: "") Slettet in System Startup user entry! 11-09-2008 16:00:51 Tilladt (based on user decision) value "TSClientAXDisabler" (new data: "") Slettet in System Startup user entry! 11-09-2008 16:00:56 Tilladt (based on user decision) value "BluetoothAuthenticationAgent" (new data: "rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent") Tilføjet in System Startup global entry! 11-09-2008 16:01:04 Tilladt (based on user decision) value "Local Page" (new data: "C:\WINDOWS\system32\blank.htm") Ændret in Browser page! 11-09-2008 16:01:04 Tilladt (based on user whitelist) value "BootExecute" (new data: "autocheck autochk * ") Ændret in Session manager! 11-09-2008 16:01:07 Tilladt (based on user decision) value "BootExecute" (new data: "") Slettet in Session manager! 11-09-2008 16:01:09 Tilladt (based on user decision) value "ExcludeFromKnownDlls" (new data: "") Slettet in Session manager! 18-10-2008 19:55:14 Forhindret (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 19-11-2008 09:41:30 Forhindret (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 19-11-2008 14:33:19 Tilladt (based on user decision) value "msisetup" (new data: "C:\Programmer\Sony Setup\Vegas Movie Studio Platinum 9.0\setup.exe -l enu") Tilføjet in System Startup user entry! 19-11-2008 14:33:23 Tilladt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP000.TMP\"") Tilføjet in System Startup global entry! 19-11-2008 14:33:35 Tilladt (based on user decision) value "wextract_cleanup0" (new data: "") Slettet in System Startup global entry! 19-11-2008 14:33:38 Tilladt (based on user decision) value "msisetup" (new data: "") Slettet in System Startup user entry! 15-12-2008 10:22:16 Forhindret (based on user decision) value "Shockwave Updater" (new data: "C:\WINDOWS\system32\Macromed\SHOCKW~2\SWHELP~1.EXE -Update -1020023 -encarta.exe12.0") Tilføjet in System Startup user entry! 20-12-2008 23:03:08 Forhindret (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 08-01-2009 18:52:41 Tilladt (based on user decision) value "Zboard" (new data: "C:\Programmer\Ideazon\ZEngine\Zboard.exe") Tilføjet in System Startup global entry! 19-01-2009 23:05:46 Forhindret (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 19-02-2009 15:21:45 Forhindret (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 16-03-2009 20:51:40 Tilladt (based on user decision) value "Spyware Doctor" (new data: ""C:\Armor\Spyware Doctor\swdoctor.exe" /Q") Tilføjet in System Startup user entry! 16-03-2009 21:00:01 Tilladt (based on user decision) value "Dit" (new data: "") Slettet in System Startup global entry! 16-03-2009 21:00:04 Tilladt (based on user decision) value "Cmaudio" (new data: "") Slettet in System Startup global entry! 16-03-2009 21:00:05 Tilladt (based on user decision) value "BluetoothAuthenticationAgent" (new data: "") Slettet in System Startup global entry! 22-03-2009 16:04:31 Tilladt (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") Tilføjet in System Startup user entry! 23-03-2009 13:31:02 Tilladt (based on user decision) value "FlashPlayerUpdate" (new data: "") Slettet in System Startup user entry! 23-03-2009 19:42:40 Tilladt (based on user decision) value "Sony Ericsson PC Suite" (new data: ""C:\Programmer\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon") Tilføjet in System Startup user entry! 23-03-2009 21:38:04 Tilladt (based on user decision) value "msisetup" (new data: "F:\Applications\MM\Setup\Setup.exe -l dan") Tilføjet in System Startup user entry! 23-03-2009 21:58:22 Tilladt (based on user decision) value "QuickTime Task" (new data: ""C:\Programmer\QuickTime\QTTask.exe" -atboottime") Tilføjet in System Startup global entry! 23-03-2009 21:59:36 Tilladt (based on user whitelist) value "msisetup" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:53 Tilladt (based on user whitelist) value "uTorrent" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:53 Tilladt (based on user decision) value "DAEMON Tools Lite" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "Spyware Doctor" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "Sony Ericsson PC Suite" (new data: "") Slettet in System Startup user entry! 24-03-2009 14:11:54 Tilladt (based on user whitelist) value "Adobe Reader Speed Launcher" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "NeroFilterCheck" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "InCD" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "PCMService" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "Zboard" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:11:54 Tilladt (based on user decision) value "QuickTime Task" (new data: "") Slettet in System Startup global entry! 24-03-2009 14:12:02 Tilladt (based on user decision) value "MSConfig" (new data: "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto") Tilføjet in System Startup global entry! 24-03-2009 18:10:11 Tilladt (based on user whitelist) value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP000.TMP\"") Tilføjet in System Startup global entry! 24-03-2009 18:10:17 Tilladt (based on user decision) value "wextract_cleanup1" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP002.TMP\"") Tilføjet in System Startup global entry! 24-03-2009 18:10:23 Tilladt (based on user decision) value "wextract_cleanup2" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP001.TMP\"") Tilføjet in System Startup global entry! 24-03-2009 18:10:24 Tilladt (based on user decision) value "wextract_cleanup1" (new data: "") Slettet in System Startup global entry! 24-03-2009 18:10:28 Tilladt (based on user decision) value "wextract_cleanup2" (new data: "") Slettet in System Startup global entry! 24-03-2009 18:11:55 Tilladt (based on user decision) value "avast!" (new data: "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe") Tilføjet in System Startup global entry! 24-03-2009 18:12:00 Tilladt (based on user decision) value "BootExecute" (new data: "autocheck autochk * aswBoot.exe /A:"*" /L:"English" /KBD:2 ") Ændret in Session manager! 24-03-2009 18:12:03 Tilladt (based on user whitelist) value "wextract_cleanup0" (new data: "") Slettet in System Startup global entry! 25-03-2009 13:01:42 Tilladt (based on user whitelist) value "BootExecute" (new data: "autocheck autochk * ") Ændret in Session manager! 26-03-2009 09:39:26 Tilladt (based on user decision) value "MSConfig" (new data: "") Slettet in System Startup global entry! 27-03-2009 18:06:55 Tilladt (based on user whitelist) value "uTorrent" (new data: ""C:\Programmer\uTorrent\uTorrent.exe"") Tilføjet in System Startup user entry! 31-03-2009 22:48:42 Tilladt (based on user whitelist) value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP000.TMP\"") Tilføjet in System Startup global entry! 31-03-2009 22:48:45 Tilladt (based on user decision) value "wextract_cleanup1" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\Thor\LOKALE~1\Temp\IXP001.TMP\"") Tilføjet in System Startup global entry! 31-03-2009 22:54:33 Tilladt (based on user decision) value "reader_s" (new data: "C:\Documents and Settings\Thor\reader_s.exe") Tilføjet in System Startup user entry! 31-03-2009 22:54:38 Tilladt (based on user decision) value "reader_s" (new data: "C:\WINDOWS\System32\reader_s.exe") Tilføjet in System Startup global entry! 31-03-2009 22:54:38 Tilladt (based on user whitelist) value "wextract_cleanup0" (new data: "") Slettet in System Startup global entry! 31-03-2009 22:54:39 Tilladt (based on user decision) value "wextract_cleanup1" (new data: "") Slettet in System Startup global entry! 31-03-2009 22:54:39 Tilladt (based on user decision) value "wextract_cleanup2" (new data: "") Slettet in System Startup global entry! 31-03-2009 22:54:39 Tilladt (based on user decision) value "wextract_cleanup3" (new data: "") Slettet in System Startup global entry! 31-03-2009 22:54:42 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:14 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:16 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:20 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:22 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:27 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:29 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:40 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:43 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:46 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:49 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:52 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:55:54 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:55:58 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:00 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:04 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:06 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:09 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:12 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:16 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:18 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:22 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:24 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:27 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:30 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:33 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:36 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:40 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:43 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:46 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:49 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:52 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:56:55 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:56:58 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:00 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:04 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:06 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:10 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:12 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:16 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:18 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:21 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:24 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:28 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:30 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:34 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:37 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:41 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:43 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:47 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:49 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:53 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:57:55 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:57:59 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:02 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:06 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:08 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:13 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:16 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:20 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:22 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:26 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:29 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:29 Tilladt (based on user decision) value "reader_s" (new data: "") Slettet in System Startup user entry! 31-03-2009 22:58:29 Tilladt (based on user decision) value "BootExecute" (new data: "autocheck autochk * aswBoot.exe /M:202edecc63e ") Ændret in Session manager! 31-03-2009 22:58:39 Tilladt (based on user decision) value "reader_s" (new data: "C:\Documents and Settings\Thor\reader_s.exe") Tilføjet in System Startup user entry! 31-03-2009 22:58:44 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:58:49 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:58:54 Tilladt (based on user decision) value "reader_s" (new data: "") Slettet in System Startup global entry! 31-03-2009 22:58:55 Tilladt (based on user decision) value "reader_s" (new data: "C:\WINDOWS\System32\reader_s.exe") Tilføjet in System Startup global entry! 31-03-2009 22:59:00 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:59:03 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:59:06 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:59:09 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:59:12 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 22:59:14 Tilladt (based on user decision) value "BootExecute" (new data: "autocheck autochk * aswBoot.exe /M:202edecc63e /A:"*" /L:"English" /KBD:2 ") Ændret in Session manager! 31-03-2009 22:59:16 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\afisicx.exe! 31-03-2009 22:59:18 Encountered and terminated Win32.Delf.rtk in C:\WINDOWS\system32\tpszxyd.sys! 31-03-2009 23:27:10 Tilladt (based on user whitelist) value "BootExecute" (new data: "autocheck autochk * ") Ændret in Session manager! 01-04-2009 16:29:32 Tilladt (based on user decision) value "reader_s" (new data: "") Slettet in System Startup user entry! 01-04-2009 16:29:32 Tilladt (based on user decision) value "reader_s" (new data: "") Slettet in System Startup global entry! 01-04-2009 16:29:40 Tilladt (based on user decision) value "MSConfig" (new data: "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto") Tilføjet in System Startup global entry! 01-04-2009 18:04:23 Tilladt (based on user decision) value "BootExecute" (new data: "autocheck autochk * aswBoot.exe /A:"*" /L:"English" /KBD:2 ") Ændret in Session manager! 01-04-2009 19:45:30 Tilladt (based on user whitelist) value "BootExecute" (new data: "autocheck autochk * ") Ændret in Session manager! 03-04-2009 17:01:22 Tilladt (based on user decision) value "MSConfig" (new data: "") Slettet in System Startup global entry!