|
Re: c:\windows\avguard.exe
2008-11-06 13:44:50 A------- 107,546 C:\Qoobox\Quarantine\C\Documents and Settings\Mattias\Start Menu\Programs\Startup\lsass.exe.vir
2008-11-06 17:27:23 A------- 20 C:\Qoobox\Quarantine\C\WINDOWS\syscheck.vir
2008-11-06 17:27:24 A------- 237,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\wowformf436_130.dll.vir
2008-11-06 17:27:32 A------- 100,864 C:\Qoobox\Quarantine\C\WINDOWS\avguard.exe.vir
2008-11-06 17:30:42 A------- 456,192 C:\Qoobox\Quarantine\C\Program Files\NetMeeting\Winlog.exe.vir
2008-11-09 23:54:01 A------- 760 C:\Qoobox\Quarantine\catchme.log
2008-11-09 23:57:24 A------- 4,962 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-11-09 23:58:42 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
2008-11-09 23:58:42 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
2008-11-09 23:58:42 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat
2008-11-10 15:35:22 A------- 678,622 C:\Qoobox\Quarantine\[4]-Submit_2008-11-10@15.35.zip
2008-11-10 15:36:39 A------- 1,048 C:\Qoobox\Quarantine\Registry_backups\Legacy_RPCHE.reg.dat
2008-11-10 15:36:39 A------- 1,098 C:\Qoobox\Quarantine\Registry_backups\Legacy_WOWSYSTEMCODE.reg.dat
2008-11-10 15:36:40 A------- 2,814 C:\Qoobox\Quarantine\Registry_backups\Service_RPCHE.reg.dat
2008-11-10 15:36:40 A------- 3,490 C:\Qoobox\Quarantine\Registry_backups\Service_wowsystemcode.reg.dat
2008-11-10 15:36:52 A------- 287,051 C:\Qoobox\Quarantine\C\WINDOWS\_avguard_.exe.zip
|