I have a trojan which i can't remove by any means known to me!
I've got nod32 AVP and for like 8 years i haven't had any trojan or virus passed it. Today, this sirefef.EF somehow passed it and it's making mess on my computer. On a start scan it finds it and always says that i need to reboot so nod can finish deleting the file but that just goes on and on after every reboot.
First of all my internet is working like 14.4k dial up (i've got 18 mbit cable). My network connection icon is always showing "acquiring network address", and the whole system is very slow atm. Sometimes wherever i click on google or address bar in browser it redirects me to hoot.com or similar junk websites.
I tried Malwarebytes. It scanned and found it but couldn't clean it.
[quote=nod32]
OTL LOG
OTL logfile created on: 1/21/2012 8:54:00 PM - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\thumb\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.43% Memory free 3.85 Gb Paging File | 3.23 Gb Available in Paging File | 84.02% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 19.04 Gb Free Space | 12.78% Space Free | Partition Type: NTFS Computer Name: THUMBZ | User Name: thumb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/01/21 19:53:43 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\thumb\Desktop\OTL.exe PRC - [2011/12/30 16:59:44 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2009/09/29 12:03:46 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe PRC - [2009/09/29 12:02:52 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe PRC - [2008/04/29 12:25:50 | 000,671,863 | ---- | M] (E-MU Systems) -- C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe PRC - [2008/04/14 04:42:38 | 000,014,336 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\svchost.exe PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008/03/20 14:35:04 | 000,023,040 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CtHelper.exe PRC - [2008/03/05 23:04:12 | 000,188,416 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe PRC - [2007/12/10 23:56:00 | 000,709,632 | ---- | M] (Softshape Development) -- C:\Program Files\Chameleon Clock\ChamClock.exe PRC - [2007/05/21 09:51:10 | 000,135,233 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe PRC - [2007/05/21 09:50:56 | 000,065,605 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe PRC - [2007/05/15 08:53:12 | 000,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011/12/30 16:59:44 | 002,124,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2011/11/17 01:02:58 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll MOD - [2009/01/10 23:15:44 | 000,159,744 | ---- | M] () -- C:\WINDOWS\system32\mmfinfo.dll MOD - [2009/01/10 23:14:06 | 000,023,552 | ---- | M] () -- C:\WINDOWS\system32\mkunicode.dll MOD - [2008/06/20 17:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll MOD - [2008/04/14 04:42:46 | 000,033,280 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\kmddsp.tsp MOD - [2008/04/14 04:42:38 | 000,014,336 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\svchost.exe MOD - [2008/04/14 04:42:06 | 000,064,000 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\SAMLIB.dll MOD - [2008/04/14 04:42:04 | 000,118,784 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\NTMARTA.DLL MOD - [2008/04/13 22:09:26 | 002,897,920 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\xpsp2res.dll MOD - [2007/05/15 08:53:12 | 000,876,544 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\libeay32.dll MOD - [2007/05/15 08:53:12 | 000,159,744 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\ssleay32.dll MOD - [2007/05/15 08:53:12 | 000,024,691 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_auth.so MOD - [1996/06/11 00:01:00 | 000,014,336 | ---- | M] () -- C:\Program Files\Chameleon Clock\DelphiMM.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (swwd) SRV - File not found [Auto | Stopped] -- -- (SQLAgent$LG_LP2) SRV - File not found [Auto | Stopped] -- -- (mbackmonitor) SRV - File not found [Auto | Stopped] -- -- (kservice) SRV - File not found [Auto | Stopped] -- -- (EMSCR) SRV - File not found [Auto | Stopped] -- -- (datasvr2) SRV - File not found [Auto | Stopped] -- -- (cxusb) SRV - File not found [Auto | Stopped] -- -- (BrUsbSer) SRV - File not found [Auto | Stopped] -- -- (appnnode) SRV - File not found [Auto | Stopped] -- -- (AlKernel) SRV - File not found [Auto | Stopped] -- -- (aiclient) SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009/09/29 12:11:10 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV - [2009/09/29 12:03:46 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2008/04/14 04:42:38 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\WINDOWS\system32\armoucfltr.dll -- (PhilCam8116) SRV - [2007/05/21 09:51:10 | 000,135,233 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp) SRV - [2007/05/21 09:50:56 | 000,065,605 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog) SRV - [2007/05/15 08:53:12 | 000,020,543 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -- (ForcewareWebInterface) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2010/10/28 14:26:46 | 000,033,792 | ---- | M] (Novation DMS Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvnusbaudio.sys -- (NvnUsbAudio) DRV - [2010/09/02 16:49:08 | 000,013,312 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pneteth.sys -- (pneteth) DRV - [2010/08/25 01:26:39 | 000,643,072 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2010/06/23 17:07:06 | 000,100,736 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\windows\System32\drivers\nvatabus.sys -- (nvatabus) DRV - [2010/06/14 08:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2010/04/27 03:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm) DRV - [2010/04/27 03:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM) DRV - [2010/04/27 03:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) DRV - [2010/03/18 10:02:08 | 000,037,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2010/03/18 10:01:52 | 000,038,864 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2010/03/18 10:01:12 | 000,010,448 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE) DRV - [2009/12/01 09:51:24 | 000,031,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\androidusb.sys -- (androidusb) DRV - [2009/10/16 12:10:10 | 000,007,168 | ---- | M] (Novation Digital Music Systems Limited) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\automap.sys -- (automap) DRV - [2009/09/29 12:05:54 | 000,096,408 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2009/09/29 12:02:58 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv) DRV - [2009/09/29 11:56:32 | 000,116,008 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon) DRV - [2009/03/18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2008/03/20 16:55:16 | 000,802,840 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k) DRV - [2008/03/20 16:54:42 | 000,095,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia) DRV - [2008/03/20 16:52:50 | 000,159,256 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k) DRV - [2008/03/20 16:52:22 | 000,014,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k) DRV - [2008/03/20 16:51:56 | 000,129,560 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv) DRV - [2008/03/20 16:49:30 | 000,524,824 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM) DRV - [2008/03/20 16:48:56 | 000,511,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k) DRV - [2008/03/20 16:40:38 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS) DRV - [2008/03/20 16:40:38 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEXFIFX.sys -- (CTEXFIFX) DRV - [2008/03/20 16:38:06 | 000,134,168 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\windows\System32\drivers\CTEDSPIO.SYS -- (CTEDSPIO.SYS) DRV - [2008/03/20 16:38:06 | 000,134,168 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEDSPIO.sys -- (CTEDSPIO) DRV - [2008/03/20 16:37:36 | 000,309,784 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\windows\System32\drivers\CTEDSPSY.SYS -- (CTEDSPSY.SYS) DRV - [2008/03/20 16:37:36 | 000,309,784 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEDSPSY.sys -- (CTEDSPSY) DRV - [2008/03/20 16:37:10 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS) DRV - [2008/03/20 16:37:10 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTHWIUT.sys -- (CTHWIUT) DRV - [2008/03/20 16:36:44 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CT20XUT.SYS -- (CT20XUT.SYS) DRV - [2008/03/20 16:36:44 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CT20XUT.sys -- (CT20XUT) DRV - [2008/03/20 16:36:14 | 000,099,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTERFXFX.SYS -- (CTERFXFX.SYS) DRV - [2008/03/20 16:36:14 | 000,099,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTERFXFX.sys -- (CTERFXFX) DRV - [2008/03/20 16:32:36 | 000,259,096 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTEDSPFX.SYS -- (CTEDSPFX.SYS) DRV - [2008/03/20 16:32:36 | 000,259,096 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEDSPFX.sys -- (CTEDSPFX) DRV - [2008/03/20 16:26:30 | 000,163,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTEAPSFX.SYS -- (CTEAPSFX.SYS) DRV - [2008/03/20 16:26:30 | 000,163,352 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEAPSFX.sys -- (CTEAPSFX) DRV - [2008/03/20 16:25:44 | 000,534,040 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTSBLFX.SYS -- (CTSBLFX.SYS) DRV - [2008/03/20 16:25:44 | 000,534,040 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTSBLFX.sys -- (CTSBLFX) DRV - [2008/03/20 16:23:44 | 000,528,920 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\windows\System32\drivers\CTAUDFX.SYS -- (CTAUDFX.SYS) DRV - [2008/03/20 16:23:44 | 000,528,920 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTAUDFX.sys -- (CTAUDFX) DRV - [2008/03/20 16:23:08 | 000,098,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\windows\System32\drivers\COMMONFX.SYS -- (COMMONFX.SYS) DRV - [2008/03/20 16:23:08 | 000,098,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COMMONFX.sys -- (COMMONFX) DRV - [2007/12/25 16:08:36 | 000,014,336 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Amusbprt.sys -- (Amusbprt) DRV - [2007/05/21 03:43:12 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2007/05/21 03:43:08 | 000,046,080 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2007/01/24 16:46:48 | 000,008,704 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Amfilter.sys -- (Amfilter) DRV - [2006/11/02 06:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB) DRV - [2006/10/18 09:31:38 | 000,105,472 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\nvata.sys -- (nvata) DRV - [2005/12/18 13:18:56 | 000,033,792 | ---- | M] (Team H2O) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cledx.sys -- (CLEDX) DRV - [2004/08/12 11:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor) DRV - [2003/12/27 19:42:12 | 000,137,216 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\d344bus.sys -- (d344bus) DRV - [2003/12/27 01:38:10 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\windows\System32\Drivers\d344prt.sys -- (d344prt) DRV - [2001/11/27 16:46:10 | 000,010,880 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DFUUsb.sys -- (DfuUsb) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.facebook.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 87.255.6.117:80 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: [email protected]:1.0 FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: [email protected]:3.2.1.3 FF - prefs.js..extensions.enabledItems: [email protected]:0.6.2 FF - prefs.js..extensions.enabledItems: {113c2360-15a3-11de-8c30-0800200c9a66}:0.9 FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties" FF - prefs.js..network.proxy.http: "176.9.1.72" FF - prefs.js..network.proxy.http_port: 80 FF - prefs.js..network.proxy.type: 4 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\thumb\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\thumb\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 16:59:45 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/10 00:13:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/08/25 01:11:55 | 000,000,000 | ---D | M] [2010/08/25 00:40:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\thumb\Application Data\Mozilla\Extensions [2011/12/23 15:03:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\thumb\Application Data\Mozilla\Firefox\Profiles\c9tc4cg6.default\extensions [2010/08/25 14:34:55 | 000,000,000 | ---D | M] ("Vfox3") -- C:\Documents and Settings\thumb\Application Data\Mozilla\Firefox\Profiles\c9tc4cg6.default\extensions\{113c2360-15a3-11de-8c30-0800200c9a66} [2010/08/29 14:02:49 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Documents and Settings\thumb\Application Data\Mozilla\Firefox\Profiles\c9tc4cg6.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492} [2010/08/25 14:33:22 | 000,000,000 | ---D | M] ("Strata40") -- C:\Documents and Settings\thumb\Application Data\Mozilla\Firefox\Profiles\c9tc4cg6.default\extensions\[email protected] [2010/08/25 14:33:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\thumb\Application Data\Mozilla\Firefox\Profiles\c9tc4cg6.default\extensions\[email protected]\chrome\mozapps\extensions [2011/11/10 18:09:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions () (No name found) -- C:\DOCUMENTS AND SETTINGS\THUMB\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\C9TC4CG6.DEFAULT\EXTENSIONS\[email protected] [2011/12/30 16:59:45 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011/06/17 03:39:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010/08/26 14:42:09 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll [2011/08/31 11:38:58 | 000,082,944 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll [2011/10/02 11:26:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011/11/10 18:09:14 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml O1 HOSTS File: ([2010/04/30 13:56:09 | 000,001,798 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 practivate.adobe.com O1 - Hosts: 127.0.0.1 ereg.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 127.0.0.1 wip3.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O1 - Hosts: 127.0.0.1 adobe.activate.com O1 - Hosts: 127.0.0.1 adobeereg.com O1 - Hosts: 127.0.0.1 www.adobeereg.com O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com O1 - Hosts: 127.0.0.1 125.252.224.90 O1 - Hosts: 127.0.0.1 125.252.224.91 O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com O2 - BHO: (GetRight IE Helper) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [CTHelper] C:\windows\System32\CtHelper.exe (Creative Technology Ltd) O4 - HKLM..\Run: [CTxfiHlp] C:\windows\System32\Ctxfihlp.exe (Creative Technology Ltd) O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [LClock] C:\Program Files\LClock\LClock.exe File not found O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.) O4 - HKCU..\Run: [HomeAlarm] C:\Program Files\Chameleon Clock\ChamClock.exe (Softshape Development) O4 - HKCU..\Run: [SetDefaultMIDI] C:\windows\System32\MIDIDEF.EXE (Creative Technology Ltd) O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 01 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 1C 00 00 00 [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRDownload.htm () O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRBrowse.htm () O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found O13 - gopher Prefix: missing O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.216.1.30 89.216.1.50 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9224FAC0-07C7-442B-8943-653C190475E6}: DhcpNameServer = 89.216.1.30 89.216.1.50 O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\thumb\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\thumb\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/08/25 00:23:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Bin\assetup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/01/21 19:59:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\thumb\Application Data\Malwarebytes [2012/01/21 19:59:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/01/21 19:59:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/01/21 19:59:12 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys [2012/01/21 19:59:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/01/21 19:53:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\thumb\Desktop\OTL.exe [2012/01/21 17:36:49 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\thumb\Local Settings\Application Data\6bff5816 [2012/01/10 02:15:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Xvid [2012/01/10 02:15:32 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid [2012/01/10 02:12:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ffdshow [2012/01/10 02:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow [2012/01/08 19:32:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2012/01/08 19:32:17 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012/01/08 16:42:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NVIDIA [2012/01/08 16:39:10 | 000,000,000 | ---D | C] -- C:\windows\System32\WindowsPowerShell [2012/01/08 16:39:05 | 000,000,000 | ---D | C] -- C:\windows\$968930Uinstall_KB968930$ [2012/01/08 16:35:34 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search [2012/01/08 16:35:34 | 000,000,000 | ---D | C] -- C:\windows\System32\GroupPolicy [2012/01/03 01:46:54 | 000,000,000 | ---D | C] -- C:\samples [2011/12/30 16:22:14 | 000,000,000 | ---D | C] -- C:\Program Files\FLAC [2011/12/30 16:22:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FLAC [2011/12/27 01:54:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Badoo [2010/08/25 02:04:04 | 000,137,216 | ---- | C] ( ) -- C:\windows\System32\drivers\d344bus.sys [2010/08/25 02:04:04 | 000,005,248 | ---- | C] ( ) -- C:\windows\System32\drivers\d344prt.sys [2008/03/20 14:35:52 | 000,034,816 | ---- | C] ( ) -- C:\windows\System32\a3d.dll [2008/03/20 14:19:40 | 000,012,800 | ---- | C] ( ) -- C:\windows\System32\killapps.exe [1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ] [1 C:\Documents and Settings\thumb\*.tmp files -> C:\Documents and Settings\thumb\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/01/21 20:30:06 | 000,000,021 | ---- | M] () -- C:\windows\tpcsd [2012/01/21 20:25:59 | 000,000,000 | -HS- | M] () -- C:\windows\System32\dds_log_trash.cmd [2012/01/21 20:25:55 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat [2012/01/21 20:24:46 | 000,011,564 | ---- | M] () -- C:\windows\System32\DVCState-{00000001-00000000-00000006-00001102-00000008-40021102}.rfx [2012/01/21 20:24:46 | 000,001,104 | ---- | M] () -- C:\windows\System32\BMXCtrlState-{00000001-00000000-00000006-00001102-00000008-40021102}.rfx [2012/01/21 20:24:46 | 000,001,104 | ---- | M] () -- C:\windows\System32\BMXBkpCtrlState-{00000001-00000000-00000006-00001102-00000008-40021102}.rfx [2012/01/21 20:24:46 | 000,000,064 | ---- | M] () -- C:\windows\System32\BMXStateBkp-{00000001-00000000-00000006-00001102-00000008-40021102}.rfx [2012/01/21 20:24:46 | 000,000,064 | ---- | M] () -- C:\windows\System32\BMXState-{00000001-00000000-00000006-00001102-00000008-40021102}.rfx [2012/01/21 19:59:14 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/01/21 19:53:43 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\thumb\Desktop\OTL.exe [2012/01/21 18:09:12 | 000,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl [2012/01/19 01:56:22 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\thumb\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk [2012/01/17 13:49:14 | 000,033,492 | ---- | M] () -- C:\JimFitzpatrick-Che-1968.jpg [2012/01/15 23:23:21 | 000,028,906 | ---- | M] () -- C:\Parks and Recreation.1.torrent [2012/01/13 04:40:57 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\thumb\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/01/13 02:18:07 | 000,011,489 | ---- | M] () -- C:\The_Increasingly_Poor_Decisions_of_Todd_Margaret_Season_1.torrent [2012/01/11 02:31:45 | 000,135,256 | ---- | M] () -- C:\windows\System32\nvdrsdb0.bin [2012/01/11 02:31:45 | 000,000,001 | ---- | M] () -- C:\windows\System32\nvdrssel.bin [2012/01/10 02:09:57 | 000,135,252 | ---- | M] () -- C:\windows\System32\nvdrsdb1.bin [2012/01/08 19:36:39 | 003,587,696 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT [2012/01/08 17:15:27 | 000,525,866 | ---- | M] () -- C:\windows\System32\perfh009.dat [2012/01/08 17:15:27 | 000,095,722 | ---- | M] () -- C:\windows\System32\perfc009.dat [2012/01/08 16:40:08 | 000,000,575 | ---- | M] () -- C:\windows\imsins.BAK [2012/01/05 02:51:59 | 000,067,906 | ---- | M] () -- C:\av-61.gif [2012/01/03 01:12:22 | 000,025,310 | ---- | M] () -- C:\Terriers.Season.1.HDTVRip [Funnyguy263].torrent [2011/12/30 23:24:19 | 000,000,000 | -H-- | M] () -- C:\descript.ion [2011/12/30 16:22:14 | 000,001,525 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FLAC Frontend.lnk [2011/12/27 01:54:28 | 000,001,100 | ---- | M] () -- C:\Documents and Settings\thumb\Desktop\Badoo.Desktop.lnk [1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ] [1 C:\Documents and Settings\thumb\*.tmp files -> C:\Documents and Settings\thumb\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/01/21 20:30:06 | 000,000,021 | ---- | C] () -- C:\windows\tpcsd [2012/01/21 20:10:07 | 000,000,000 | -HS- | C] () -- C:\windows\System32\dds_log_trash.cmd [2012/01/21 19:59:14 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk [2012/01/17 13:49:13 | 000,033,492 | ---- | C] () -- C:\JimFitzpatrick-Che-1968.jpg [2012/01/17 01:15:23 | 000,028,906 | ---- | C] () -- C:\Parks and Recreation.1.torrent [2012/01/13 02:18:06 | 000,011,489 | ---- | C] () -- C:\The_Increasingly_Poor_Decisions_of_Todd_Margaret_Season_1.torrent [2012/01/05 02:51:57 | 000,067,906 | ---- | C] () -- C:\av-61.gif [2012/01/03 01:12:21 | 000,025,310 | ---- | C] () -- C:\Terriers.Season.1.HDTVRip [Funnyguy263].torrent [2011/12/30 16:22:14 | 000,001,525 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FLAC Frontend.lnk [2011/12/27 01:54:28 | 000,001,100 | ---- | C] () -- C:\Documents and Settings\thumb\Desktop\Badoo.Desktop.lnk [2011/12/27 01:54:27 | 000,001,306 | ---- | C] () -- C:\Documents and Settings\thumb\Start Menu\Programs\Badoo Desktop.lnk [2011/12/15 05:39:42 | 000,042,392 | ---- | C] () -- C:\windows\System32\xfcodec.dll [2011/08/20 10:52:44 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\thumb\Application Data\Adobe IllExport Filter CS5 Prefs [2011/05/06 15:35:30 | 004,369,408 | ---- | C] () -- C:\windows\System32\pdftk.exe [2011/05/06 15:35:30 | 001,503,232 | ---- | C] () -- C:\windows\System32\ptj.exe [2011/05/06 15:35:30 | 001,103,360 | ---- | C] () -- C:\windows\System32\cidfont.dll [2011/05/06 15:35:30 | 000,235,008 | ---- | C] () -- C:\windows\System32\office.exe [2011/04/23 16:49:08 | 000,110,592 | ---- | C] () -- C:\windows\System32\FsUsbExDevice.Dll [2011/04/23 16:49:08 | 000,036,608 | ---- | C] () -- C:\windows\System32\FsUsbExDisk.Sys [2011/03/27 23:32:42 | 000,179,713 | ---- | C] () -- C:\windows\LOOP.EXE [2011/02/02 00:07:45 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\thumb\Application Data\Adobe BMP Format CS5 Prefs [2011/01/29 02:21:29 | 000,000,062 | ---- | C] () -- C:\Documents and Settings\thumb\Application Data\VoiceSFX.ini [2011/01/29 02:21:04 | 000,000,066 | ---- | C] () -- C:\windows\System32\MASHTWTY.SYS [2011/01/16 04:06:05 | 000,000,191 | ---- | C] () -- C:\windows\wcpfrep.ini [2010/10/15 21:24:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\thumb\Application Data\AVSDVDPlayer.m3u [2010/10/15 18:52:36 | 000,645,632 | ---- | C] () -- C:\windows\System32\xvidcore.dll [2010/10/15 18:52:36 | 000,240,640 | ---- | C] () -- C:\windows\System32\xvidvfw.dll [2010/09/18 15:26:29 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\thumb\Application Data\$_hpcst$.hpc [2010/09/16 11:42:02 | 000,000,034 | ---- | C] () -- C:\windows\System32\mnprxpd2c.bin [2010/09/05 22:19:09 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\thumb\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/08/29 23:20:22 | 000,354,816 | ---- | C] () -- C:\windows\System32\psisdecd.dll [2010/08/26 15:18:28 | 002,494,464 | ---- | C] () -- C:\windows\AF_Osc.dat [2010/08/25 15:25:34 | 000,086,016 | ---- | C] () -- C:\windows\System32\SYNSOPOS.exe [2010/08/25 13:56:04 | 000,000,016 | ---- | C] () -- C:\windows\System32\msvcsv60.dll [2010/08/25 13:56:04 | 000,000,016 | ---- | C] () -- C:\windows\msocreg32.dat [2010/08/25 13:47:20 | 000,163,840 | ---- | C] () -- C:\windows\System32\ArtFfct.dll [2010/08/25 13:36:22 | 000,002,892 | ---- | C] () -- C:\windows\System32\audcon.sys [2010/08/25 13:36:08 | 000,000,045 | ---- | C] () -- C:\windows\System32\SYNSOPOS.exe.cfg [2010/08/25 02:13:01 | 000,004,161 | ---- | C] () -- C:\windows\ODBCINST.INI [2010/08/25 02:11:39 | 003,587,696 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT [2010/08/25 01:26:39 | 000,096,384 | ---- | C] () -- C:\windows\System32\drivers\sptd3821.sys [2010/08/25 01:23:41 | 000,335,872 | ---- | C] () -- C:\windows\System32\ldf252.dll [2010/08/25 01:05:21 | 000,001,542 | ---- | C] () -- C:\windows\WINCMD.INI [2010/08/25 01:04:35 | 000,002,560 | ---- | C] () -- C:\windows\CTXFIRES.DLL [2010/08/25 01:01:29 | 000,135,256 | ---- | C] () -- C:\windows\System32\nvdrsdb0.bin [2010/08/25 01:01:27 | 000,135,252 | ---- | C] () -- C:\windows\System32\nvdrsdb1.bin [2010/08/25 01:01:27 | 000,000,001 | ---- | C] () -- C:\windows\System32\nvdrssel.bin [2010/08/25 00:42:37 | 000,049,152 | R--- | C] () -- C:\windows\System32\ChCfg.exe [2010/08/25 00:40:37 | 000,000,664 | ---- | C] () -- C:\windows\System32\d3d9caps.dat [2010/08/25 00:40:28 | 000,000,000 | ---- | C] () -- C:\windows\nsreg.dat [2010/08/25 00:37:02 | 000,001,732 | R--- | C] () -- C:\windows\System32\drivers\nvphy.bin [2010/08/25 00:36:32 | 000,015,374 | ---- | C] () -- C:\windows\Ascd_log.ini [2010/08/25 00:36:23 | 000,005,810 | R--- | C] () -- C:\windows\System32\drivers\ASACPI.sys [2010/08/25 00:36:22 | 000,015,133 | ---- | C] () -- C:\windows\Ascd_tmp.ini [2010/08/25 00:36:11 | 000,012,536 | ---- | C] () -- C:\windows\System32\drivers\ASUSHWIO.SYS [2010/08/25 00:31:22 | 000,002,048 | --S- | C] () -- C:\windows\bootstat.dat [2010/08/25 00:20:10 | 000,021,640 | ---- | C] () -- C:\windows\System32\emptyregdb.dat [2010/08/25 00:19:33 | 000,052,836 | ---- | C] () -- C:\windows\System32\zlib1.dll [2010/08/25 00:19:25 | 000,162,304 | ---- | C] () -- C:\windows\System32\libpng13.dll [2010/08/08 05:52:53 | 000,000,202 | ---- | C] () -- C:\windows\msmmdx9.ini [2010/03/10 20:53:59 | 000,000,382 | ---- | C] () -- C:\windows\System32\Oeminfo.ini [2009/03/20 18:31:36 | 004,425,326 | ---- | C] () -- C:\windows\System32\libavcodec.dll [2009/03/19 22:36:48 | 000,557,469 | ---- | C] () -- C:\windows\System32\libmplayer.dll [2009/03/02 20:10:48 | 000,079,872 | ---- | C] () -- C:\windows\System32\ff_vfw.dll [2009/03/02 20:10:22 | 000,098,304 | ---- | C] () -- C:\windows\System32\ff_wmv9.dll [2009/03/02 17:19:36 | 000,183,296 | ---- | C] () -- C:\windows\System32\ff_samplerate.dll [2009/03/02 17:19:30 | 000,178,688 | ---- | C] () -- C:\windows\System32\ff_libmad.dll [2009/03/02 17:19:14 | 000,113,152 | ---- | C] () -- C:\windows\System32\ff_unrar.dll [2009/03/02 17:18:32 | 000,257,024 | ---- | C] () -- C:\windows\System32\ff_libdts.dll [2009/03/02 17:18:28 | 000,142,848 | ---- | C] () -- C:\windows\System32\ff_liba52.dll [2009/03/02 15:54:20 | 000,328,334 | ---- | C] () -- C:\windows\System32\ff_kernelDeint.dll [2009/03/02 15:45:14 | 000,146,098 | ---- | C] () -- C:\windows\System32\libmpeg2_ff.dll [2009/03/02 15:42:54 | 000,425,040 | ---- | C] () -- C:\windows\System32\TomsMoComp_ff.dll [2009/03/02 15:35:56 | 000,898,465 | ---- | C] () -- C:\windows\System32\ff_x264.dll [2009/01/10 23:17:32 | 000,163,840 | ---- | C] () -- C:\windows\System32\ts.dll [2009/01/10 23:16:56 | 000,148,480 | ---- | C] () -- C:\windows\System32\mkx.dll [2009/01/10 23:16:50 | 000,108,032 | ---- | C] () -- C:\windows\System32\avi.dll [2009/01/10 23:16:14 | 000,141,312 | ---- | C] () -- C:\windows\System32\mp4.dll [2009/01/10 23:16:04 | 000,335,872 | ---- | C] () -- C:\windows\System32\gdsmux.exe [2009/01/10 23:15:54 | 000,120,832 | ---- | C] () -- C:\windows\System32\ogm.dll [2009/01/10 23:15:44 | 000,159,744 | ---- | C] () -- C:\windows\System32\mmfinfo.dll [2009/01/10 23:15:36 | 000,103,424 | ---- | C] () -- C:\windows\System32\dsmux.exe [2009/01/10 23:15:32 | 000,102,400 | ---- | C] () -- C:\windows\System32\avss.dll [2009/01/10 23:15:28 | 000,246,784 | ---- | C] () -- C:\windows\System32\dxr.dll [2009/01/10 23:15:12 | 000,097,280 | ---- | C] () -- C:\windows\System32\avs.dll [2009/01/10 23:15:06 | 000,135,168 | ---- | C] () -- C:\windows\System32\mkv2vfr.exe [2009/01/10 23:14:08 | 000,079,360 | ---- | C] () -- C:\windows\System32\mkzlib.dll [2009/01/10 23:14:06 | 000,023,552 | ---- | C] () -- C:\windows\System32\mkunicode.dll [2008/07/09 09:05:24 | 000,020,480 | ---- | C] () -- C:\windows\System32\ac3config.exe [2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\windows\System32\structuredqueryschematrivial.bin [2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\windows\System32\structuredqueryschema.bin [2008/04/14 04:55:28 | 000,001,804 | ---- | C] () -- C:\windows\System32\Dcache.bin [2008/03/20 15:02:24 | 000,097,461 | ---- | C] () -- C:\windows\System32\instwdm.ini [2008/03/20 15:02:24 | 000,000,054 | ---- | C] () -- C:\windows\System32\ctzapxx.ini [2008/03/20 14:36:48 | 000,043,520 | ---- | C] () -- C:\windows\System32\CTBurst.dll [2008/03/20 14:35:06 | 000,041,472 | ---- | C] () -- C:\windows\System32\psconv.exe [2008/03/20 14:25:22 | 000,325,821 | ---- | C] () -- C:\windows\System32\ctdlang.dat [2008/03/20 14:25:22 | 000,046,273 | ---- | C] () -- C:\windows\System32\ctdnlstr.dat [2008/03/20 14:22:24 | 000,016,384 | ---- | C] () -- C:\windows\System32\regplib.exe [2008/03/20 14:21:58 | 000,149,838 | ---- | C] () -- C:\windows\System32\ctbas2w.dat [2008/03/20 14:20:12 | 000,274,587 | ---- | C] () -- C:\windows\System32\ctsbas2w.dat [2008/03/20 14:20:02 | 000,115,166 | ---- | C] () -- C:\windows\System32\CTBASICW.DAT [2008/03/20 14:20:00 | 000,241,084 | ---- | C] () -- C:\windows\System32\CTSBASW.DAT [2008/03/20 14:19:44 | 000,313,207 | ---- | C] () -- C:\windows\System32\ctstatic.dat [2008/03/20 14:19:44 | 000,053,932 | ---- | C] () -- C:\windows\System32\ctdaught.dat [2008/03/20 14:19:42 | 000,007,680 | ---- | C] () -- C:\windows\System32\enlocstr.exe [2007/10/25 16:26:10 | 000,005,632 | ---- | C] () -- C:\windows\System32\drivers\StarOpen.sys [2007/10/13 10:30:20 | 000,000,137 | ---- | C] () -- C:\windows\System32\Registration.ini [2006/12/31 06:57:08 | 000,004,569 | ---- | C] () -- C:\windows\System32\secupd.dat [2006/10/02 16:25:18 | 000,000,307 | ---- | C] () -- C:\windows\System32\kill.ini [2005/06/16 17:17:16 | 000,071,680 | ---- | C] () -- C:\windows\System32\ctmmactl.dll [2003/12/27 19:43:24 | 000,068,608 | ---- | C] () -- C:\windows\daemon.dll [2001/08/23 13:00:00 | 013,107,200 | ---- | C] () -- C:\windows\System32\oembios.bin [2001/08/23 13:00:00 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat [2001/08/23 13:00:00 | 000,525,866 | ---- | C] () -- C:\windows\System32\perfh009.dat [2001/08/23 13:00:00 | 000,272,128 | ---- | C] () -- C:\windows\System32\perfi009.dat [2001/08/23 13:00:00 | 000,218,003 | ---- | C] () -- C:\windows\System32\dssec.dat [2001/08/23 13:00:00 | 000,095,722 | ---- | C] () -- C:\windows\System32\perfc009.dat [2001/08/23 13:00:00 | 000,046,258 | ---- | C] () -- C:\windows\System32\mib.bin [2001/08/23 13:00:00 | 000,028,626 | ---- | C] () -- C:\windows\System32\perfd009.dat [2001/08/23 13:00:00 | 000,004,463 | ---- | C] () -- C:\windows\System32\oembios.dat [2001/08/23 13:00:00 | 000,000,741 | ---- | C] () -- C:\windows\System32\noise.dat [color=#E56717]========== LOP Check ==========[/color] [2010/08/25 01:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems [2010/08/25 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Arturia [2011/12/27 01:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Badoo [2011/01/22 01:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH [2010/08/25 15:25:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eLicenser [2010/08/25 01:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET [2010/11/13 02:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN [2011/11/11 17:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KORG [2010/10/18 21:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Locktime [2010/08/26 01:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy [2010/08/26 01:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe [2011/04/23 16:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung [2011/09/30 18:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Slate Digital [2010/08/25 02:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Steinberg [2010/08/25 13:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Syncrosoft [2011/01/22 00:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temporary [2010/08/26 02:31:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip [2010/08/25 13:30:03 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{7D55A338-9946-4B03-9D84-8FD1472DA229} [2011/01/21 18:39:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{C2686527-0D57-4F0B-ADAB-EE203CA30FC6} [2010/08/25 01:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\ACD Systems [2011/01/22 00:17:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Antares [2011/12/07 14:45:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Audacity [2011/09/04 15:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Azureus [2010/10/16 02:34:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\BSplayer [2010/10/16 00:45:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\BSplayer Pro [2010/10/23 14:18:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Daichi [2011/12/08 02:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Dropbox [2010/08/25 01:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\EmuPatchMixDSP [2011/01/15 02:31:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\FabFilter [2011/03/27 23:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\fltk.org [2010/08/26 14:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Foxit Software [2010/11/13 02:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\GARMIN [2011/10/09 22:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\GetRight Pro [2010/10/19 21:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\HateML [2010/09/19 01:55:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\iZotope [2011/11/11 18:03:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\KORG [2010/08/25 01:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Leadertech [2010/10/18 21:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Locktime [2011/03/21 03:18:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\MixVibes [2011/04/11 00:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Opera [2010/08/26 01:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\PACE Anti-Piracy [2010/08/26 23:25:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Publish Providers [2011/04/23 19:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Samsung [2010/12/31 21:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Schism Tracker [2011/05/20 14:15:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Softland [2010/08/26 23:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Sony [2011/06/18 04:04:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2010/08/25 02:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Steinberg [2010/10/15 18:47:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Thinstall [2010/11/13 19:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Trillian [2010/10/20 16:46:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\TS3Client [2012/01/21 18:07:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\uTorrent [2010/12/25 04:10:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\VST3 Presets [2011/01/15 02:32:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Waves [2010/08/26 01:10:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Waves Audio [2011/01/15 02:32:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\Waves Preferences [2011/10/19 12:09:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\thumb\Application Data\XnView [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 1291 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:nMsL6MbtxfhFPkoAi8RLTxRv @Alternate Data Stream - 1256 bytes -> C:\Program Files\Common Files\System:fUpAvm7wHRKDpekHg < End of report >
Malwarebytes log scan #1
Malwarebytes Anti-Malware (Trial) 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.21.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 thumb :: THUMBZ [administrator] Protection: Enabled 1/21/2012 8:01:23 PM mbam-log-2012-01-21 (20-01-23).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207549 Time elapsed: 6 minute(s), 10 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 15 HKCR\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\MyNewsBarLauncher.IE5BarLauncherBHO.1 (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\MyNewsBarLauncher.IE5BarLauncherBHO (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\MyNewsBarLauncher.IE5BarLauncher.1 (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCR\MyNewsBarLauncher.IE5BarLauncher (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. Registry Values Detected: 5 HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Data: ;áĂzÊ;XA³0öm»Áµ -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Data: VShareTB -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Data: -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Data: -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> Quarantined and deleted successfully. Registry Data Items Detected: 1 HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 5 C:\Program Files\vShare.tv plugin\BarLcher.dll (PUP.VShareRedir) -> Quarantined and deleted successfully. C:\Documents and Settings\thumb\Local Settings\Temporary Internet Files\Content.IE5\03LRS2BP\3[1].exe (Rootkit.0Access) -> Quarantined and deleted successfully. C:\Documents and Settings\NetworkService\Local Settings\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. C:\Documents and Settings\thumb\Local Settings\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. C:\WINDOWS\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. (end)
Malwarebytes log scan #2
Malwarebytes Anti-Malware (Trial) 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.21.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 thumb :: THUMBZ [administrator] Protection: Enabled 1/21/2012 8:13:20 PM mbam-log-2012-01-21 (20-13-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207366 Time elapsed: 9 minute(s), 47 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 1 C:\WINDOWS\system32\JRAID.dll (Rootkit.0Access) -> Delete on reboot. Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 3 HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 4 C:\WINDOWS\system32\JRAID.dll (Rootkit.0Access) -> Delete on reboot. C:\Documents and Settings\NetworkService\Local Settings\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. C:\Documents and Settings\thumb\Local Settings\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. C:\WINDOWS\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Delete on reboot. (end)
And Malwarebytes protection log
2012/01/21 20:01:18 +0100 THUMBZ thumb MESSAGE Starting protection 2012/01/21 20:01:24 +0100 THUMBZ thumb MESSAGE Protection started successfully 2012/01/21 20:01:27 +0100 THUMBZ thumb MESSAGE Starting IP protection 2012/01/21 20:01:30 +0100 THUMBZ thumb MESSAGE Executing scheduled update: Daily 2012/01/21 20:01:32 +0100 THUMBZ thumb MESSAGE Database already up-to-date 2012/01/21 20:01:34 +0100 THUMBZ thumb MESSAGE IP Protection started successfully 2012/01/21 20:02:41 +0100 THUMBZ thumb IP-BLOCK 89.28.75.196 (Type: outgoing) 2012/01/21 20:02:46 +0100 THUMBZ thumb IP-BLOCK 89.28.75.196 (Type: outgoing) 2012/01/21 20:03:27 +0100 THUMBZ thumb IP-BLOCK 89.28.75.196 (Type: outgoing) 2012/01/21 20:05:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:52 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:52 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:54 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:55 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:56 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:56 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:56 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:57 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:58 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:58 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:58 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:58 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:58 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:59 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:59 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:59 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:05:59 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:02 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:11 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:14 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:14 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:14 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:15 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:16 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:17 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:19 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:19 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:22 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:23 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:27 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:30 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:31 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:31 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:31 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:31 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:32 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:32 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:32 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:32 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:34 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:34 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:34 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:35 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:35 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:06:38 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:06:39 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:40 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:40 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:41 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:41 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:42 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:42 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:43 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:43 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:43 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:44 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:44 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:44 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:45 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:46 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:46 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:46 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:46 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:47 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:47 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:47 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:48 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:48 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:48 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:49 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:49 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:49 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:49 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:49 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:50 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:51 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:51 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:51 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:51 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:06:53 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:07:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:01 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:04 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:04 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:04 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:04 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:06 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:07 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:09 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:11 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:13 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:21 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:22 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:23 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:27 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:28 +0100 THUMBZ thumb IP-BLOCK 93.190.140.59 (Type: outgoing) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:29 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:07:30 +0100 THUMBZ thumb IP-BLOCK 93.190.140.59 (Type: outgoing) 2012/01/21 20:07:30 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:31 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:31 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:31 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:31 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:32 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:32 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:32 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:33 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:33 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:07:33 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:34 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:34 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:34 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:34 +0100 THUMBZ thumb IP-BLOCK 93.190.140.59 (Type: outgoing) 2012/01/21 20:07:35 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:35 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:35 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:35 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:35 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 93.190.140.59 (Type: outgoing) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:36 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:37 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:37 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:07:39 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:07:41 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:07:52 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:08:03 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:08:04 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:08:05 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:08:24 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:08:26 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:08:31 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:08:33 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:11:56 +0100 THUMBZ thumb MESSAGE Starting protection 2012/01/21 20:12:13 +0100 THUMBZ thumb MESSAGE Protection started successfully 2012/01/21 20:12:16 +0100 THUMBZ thumb MESSAGE Starting IP protection 2012/01/21 20:12:21 +0100 THUMBZ thumb MESSAGE IP Protection started successfully 2012/01/21 20:12:45 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: incoming) 2012/01/21 20:12:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:49 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:51 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:52 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:52 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:52 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:53 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:53 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:53 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:53 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:12:54 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:12:57 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:00 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:01 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:02 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: outgoing) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:03 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:04 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:04 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:04 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:05 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:05 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:06 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:07 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:07 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:08 +0100 THUMBZ thumb IP-BLOCK 89.28.123.127 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:09 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:10 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:10 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:10 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:10 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:18 +0100 THUMBZ thumb IP-BLOCK 193.105.135.93 (Type: outgoing) 2012/01/21 20:13:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:19 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:20 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:21 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:22 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:23 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:24 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:25 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:26 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:27 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:28 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:33 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: incoming) 2012/01/21 20:13:41 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: outgoing) 2012/01/21 20:13:44 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: outgoing) 2012/01/21 20:13:50 +0100 THUMBZ thumb IP-BLOCK 89.28.43.171 (Type: outgoing) 2012/01/21 20:27:04 +0100 THUMBZ MESSAGE Starting protection 2012/01/21 20:27:40 +0100 THUMBZ thumb MESSAGE Protection started successfully 2012/01/21 20:27:44 +0100 THUMBZ thumb MESSAGE Starting IP protection 2012/01/21 20:27:57 +0100 THUMBZ thumb MESSAGE IP Protection started successfully 2012/01/21 20:28:19 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\lhidflt2.dll Rootkit.0Access QUARANTINE 2012/01/21 20:28:19 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\lhidflt2.dll Rootkit.0Access DENY 2012/01/21 20:29:07 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\vrservice.dll Rootkit.0Access QUARANTINE 2012/01/21 20:29:07 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\vrservice.dll Rootkit.0Access DENY 2012/01/21 20:30:03 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\retrowdsvc.dll Rootkit.0Access QUARANTINE 2012/01/21 20:30:03 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\retrowdsvc.dll Rootkit.0Access DENY 2012/01/21 20:31:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\eabusb.dll Rootkit.0Access QUARANTINE 2012/01/21 20:31:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\eabusb.dll Rootkit.0Access DENY 2012/01/21 20:32:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\FileDisk.dll Rootkit.0Access QUARANTINE 2012/01/21 20:32:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\FileDisk.dll Rootkit.0Access DENY 2012/01/21 20:33:07 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\NETw3x32.dll Rootkit.0Access QUARANTINE 2012/01/21 20:33:07 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\NETw3x32.dll Rootkit.0Access DENY 2012/01/21 20:34:06 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\cmbatt.dll Rootkit.0Access QUARANTINE 2012/01/21 20:34:08 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\cmbatt.dll Rootkit.0Access DENY 2012/01/21 20:35:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\vstor2.dll Rootkit.0Access QUARANTINE 2012/01/21 20:35:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\vstor2.dll Rootkit.0Access DENY 2012/01/21 20:36:03 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\CrystalSysInfo.dll Rootkit.0Access QUARANTINE 2012/01/21 20:36:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\CrystalSysInfo.dll Rootkit.0Access DENY 2012/01/21 20:37:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\stisvc.dll Rootkit.0Access QUARANTINE 2012/01/21 20:37:05 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\stisvc.dll Rootkit.0Access DENY 2012/01/21 20:38:19 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:38:19 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:47:51 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:48:17 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:49:32 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:53:04 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:30 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:31 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:55:48 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:56:25 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW 2012/01/21 20:57:24 +0100 THUMBZ thumb DETECTION C:\WINDOWS\system32\armoucfltr.dll Rootkit.0Access ALLOW