Status: Deleted (events: 19) 6/25/2012 6:01:10 PM Deleted Trojan program Trojan-FakeAV.Win32.SmartFixer.vw C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{002BF558-CD3A-39B4-4D68-C20C1643AD63}-dtGLRaRIQlqmHTD.exe High 6/25/2012 6:01:10 PM Deleted Trojan program Trojan-FakeAV.Win32.SmartFixer.vw C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{002BF558-CD3A-39B4-4D68-C20C1643AD63}-dtGLRaRIQlqmHTD.exe//PE-Crypt.XorPE High 6/25/2012 6:01:36 PM Deleted Trojan program Trojan-Ransom.Win32.Mbro.kdm C:\Documents and Settings\wooly7\AppData\Local\opcbkffp.exe High 6/25/2012 6:07:01 PM Deleted Trojan program Trojan-Downloader.JS.Expack.rl C:\Documents and Settings\wooly7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QMZXS6QW\main[7].htm High 6/25/2012 6:07:21 PM Deleted Trojan program Backdoor.Win32.ZAccess.tui C:\Documents and Settings\wooly7\AppData\Local\Temp\15D0.tmp High 6/25/2012 6:07:21 PM Deleted Trojan program Backdoor.Win32.ZAccess.tus C:\Documents and Settings\wooly7\AppData\Local\Temp\6028.tmp High 6/25/2012 6:07:36 PM Deleted Trojan program HEUR:Trojan.Win32.Generic C:\Documents and Settings\wooly7\AppData\Local\Temp\7993.tmp High 6/25/2012 6:07:40 PM Deleted Trojan program Trojan-Ransom.Win32.Mbro.keg C:\Documents and Settings\wooly7\AppData\Local\Temp\8316.tmp High 6/25/2012 6:15:22 PM Deleted Trojan program Backdoor.Win32.ZAccess.mbg C:\Documents and Settings\wooly7\AppData\Local\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\00000001.@ High 6/25/2012 6:15:29 PM Deleted Trojan program Trojan.Win32.Small.bmph C:\Documents and Settings\wooly7\AppData\Local\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\80000000.@ High 6/25/2012 6:15:26 PM Deleted Trojan program HEUR:Trojan.Win32.Generic C:\Documents and Settings\wooly7\AppData\Local\VirtualStore\Windows\System32\sname High 6/25/2012 6:15:34 PM Deleted Trojan program Trojan.Win32.Zapchast.acdo C:\Documents and Settings\wooly7\AppData\Local\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\800000cb.@ High 6/25/2012 7:28:02 PM Deleted Trojan program HEUR:Trojan.Win32.Generic C:\Qoobox\Quarantine\C\Users\wooly7\AppData\Local\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\n.vir High 6/25/2012 7:28:10 PM Deleted Trojan program HEUR:Trojan.Win32.Generic C:\Qoobox\Quarantine\C\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\n.vir High 6/25/2012 7:28:06 PM Deleted Trojan program Trojan.Win32.Small.bmpj C:\Qoobox\Quarantine\C\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\80000000.@.vir High 6/26/2012 12:16:24 AM Deleted Trojan program Backdoor.Win32.ZAccess.mbg C:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\00000001.@ High 6/25/2012 9:16:44 PM Deleted Trojan program Trojan.Win32.Small.bmph c:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\80000000.@ High 6/25/2012 9:16:44 PM Deleted Trojan program Trojan.Win32.Zapchast.acdo c:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\800000cb.@ High 6/25/2012 9:28:02 PM Deleted Trojan program Trojan-PSW.Win32.FireThief.akk C:\_OTL\MovedFiles\06222012_061836\C_Users\wooly7\AppData\Local\Google\ElevatedDiagnostics\zhjqlthc.dll High Status: Quarantined (events: 5) 6/25/2012 6:15:17 PM Quarantined unknown threat UDS:DangerousObject.Multi.Generic C:\Documents and Settings\wooly7\AppData\Local\pcfonbel.exe High 6/25/2012 6:29:58 PM Quarantined unknown threat UDS:DangerousObject.Multi.Generic C:\Documents and Settings\wooly7\AppData\Local\Temp\pkg_0ll.exe High 6/25/2012 8:58:42 PM Quarantined unknown threat UDS:DangerousObject.Multi.Generic C:\Documents and Settings\wooly7\AppData\Roaming\A52F65.exe High 6/25/2012 8:58:42 PM Quarantined unknown threat UDS:DangerousObject.Multi.Generic C:\Users\wooly7\AppData\Roaming\A52F65.exe High 6/25/2012 9:28:12 PM Quarantined Trojan program HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\06222012_061836\C_Users\wooly7\AppData\Roaming\weavi.dll High Status: Disinfected (events: 3) 6/25/2012 6:15:48 PM Disinfected Trojan program Exploit.Java.CVE-2012-0507.jv C:\Documents and Settings\wooly7\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\2462e402-33f3d17c High 6/25/2012 6:15:48 PM Disinfected Trojan program Exploit.Java.CVE-2012-0507.jv C:\Documents and Settings\wooly7\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\2462e402-33f3d17c/pira/pirc.class High 6/25/2012 8:36:27 PM Disinfected Trojan program Rootkit.Boot.SST.b \Device\Harddisk0\DR0 High Status: Detected (events: 3) 6/25/2012 10:52:06 PM Detected Trojan program Trojan.Win32.Small.bmph C:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\80000000.@ High 6/25/2012 10:52:07 PM Detected Trojan program Trojan.Win32.Zapchast.acdo C:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\800000cb.@ High 6/26/2012 5:48:43 AM Detected Trojan program Backdoor.Win32.ZAccess.mbg c:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\00000001.@ High Status: Will be deleted when the computer is restarted (events: 2) 6/26/2012 5:44:10 AM Will be deleted when the computer is restarted Trojan program Trojan.Win32.Small.bmph c:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\80000000.@ High 6/26/2012 5:44:31 AM Will be deleted when the computer is restarted Trojan program Trojan.Win32.Zapchast.acdo c:\Windows\Installer\{1c976c55-a72f-556b-16ee-3f7bb61aebdc}\U\800000cb.@ High