Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SKYNET.DLL... twice the round


  • This topic is locked This topic is locked
13 replies to this topic

#1 pendrakhis

pendrakhis

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 27 June 2009 - 04:08 PM

Okay... so I have run Malwarebytes with the latest version... done the ATF cleaner and the Superantispyware... here are the logs...

Malwarebytes' Anti-Malware 1.38
Database version: 2341
Windows 6.0.6001 Service Pack 1

27/06/2009 11:47:04 AM
mbam-log-2009-06-27 (11-47-04).txt

Scan type: Quick Scan
Objects scanned: 90143
Time elapsed: 4 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\System32\SKYNETwlivwivx.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\System32\SKYNETwlivwivx.dll (Trojan.TDSS) -> Quarantined and deleted successfully.


And SAS

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/27/2009 at 01:24 PM

Application Version : 4.26.1002

Core Rules Database Version : 3959
Trace Rules Database Version: 1901

Scan type : Quick Scan
Total Scan Time : 00:49:29

Memory items scanned : 615
Memory threats detected : 1
Registry items scanned : 566
Registry threats detected : 0
File items scanned : 45415
File threats detected : 40

Rootkit.Agent/Gen-Skynet
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\SKYNETWLIVWIVX.DLL
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\SKYNETWLIVWIVX.DLL

Adware.Tracking Cookie
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@apmebf[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@atdmt[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@serving-sys[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@mediaplex[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@trafficmp[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@fastclick[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@microsoftwga.112.2o7[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@ads.cnn[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@realmedia[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@burstbeacon[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@247realmedia[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@microsoftwindows.112.2o7[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@stopzilla[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@adserver.adtechus[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@doubleclick[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@smartadserver[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@waterfrontmedia.112.2o7[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@2o7[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@bs.serving-sys[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@cdn4.specificclick[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@questionmarket[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@ad.yieldmanager[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@serving-sys[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@media.adrevolver[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@advertising[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@tribalfusion[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@questionmarket[3].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@videoegg.adbureau[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@www.stopzilla[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@advertising[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@208.122.40[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@socialmedia[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@media6degrees[1].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@adbrite[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@www.burstnet[3].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@adrevolver[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@ad.yieldmanager[2].txt
C:\Users\Adrian Dorsey\AppData\Roaming\Microsoft\Windows\Cookies\adrian_dorsey@revsci[1].txt

Keylogger.Actual Spy
C:\Program Files\ACSPMonitor

Both pick it up and I reboot for final removal but it returns. AVG does not pick it up at all.

BC AdBot (Login to Remove)

 


#2 Sprachinseln

Sprachinseln

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wexford, PA
  • Local time:02:05 PM

Posted 27 June 2009 - 05:24 PM

I had similar issues with the same Trojan. Nothing worked in removing it, except AVAST. I downloaded the free home edition, unloaded my Symantec product, installed and updated AVAST, and ran it.

It found all 4 occurrences and deleted them.

Give it a try.

#3 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 27 June 2009 - 06:17 PM

Install RootRepeal

Click here - Official Rootrepeal Site, and download RootRepeal.zip. I recommend downloading to your desktop.
Fatdcuk at Malwarebytes posted a comprehensive tutorial - Self Help guide can be found here if needed.: Malwarebytes Removal and Self Help Guides.
Click RootRepeal.exe to open the scanner.
Click the Report tab, now click on Scan. A Window will open asking what to include in the scan.
Check the following items:
Drivers
Files
Processes
SSDT
Stealth Objects
Hidden Services

Click OK
Scan your C Drive (Or your current system drive) and click OK. The scan will begin. This my take a moment, so please be patient. When the scan completes, click Save Report.
Name the log RootRepeal.txt and save it to your Documents folder - (Default folder).
Paste the log into your next reply.

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#4 pendrakhis

pendrakhis
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 27 June 2009 - 11:45 PM

RootRepeal kept crashing the comp and causing reboot- fell back to Avast.... here is the log results LOL

27/06/2009 9:35:46 PM general Started: 27.06.2009, 21:35:46
27/06/2009 9:35:46 PM general Running setup_av_pro-537 (1335)
27/06/2009 9:35:46 PM system Operating system: Windows Vista ver 6.0, build 6001, sp 1.0 [Service Pack 1]
27/06/2009 9:35:46 PM system Memory: 48% load. Phys:1077432/2086672K free, Page:3078360/4194303K free, Virt:2020200/2097024K free
27/06/2009 9:35:46 PM system Computer WinName: ADRIANDORSEY-PC
27/06/2009 9:35:46 PM system Windows Net User: AdrianDorsey-PC\Adrian Dorsey
27/06/2009 9:35:46 PM general Cmdline: /sfx /sfxstorage "C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784" /srcpath "C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_IN~1.TM~" /sfxname "setupeng"
27/06/2009 9:35:46 PM general DldSrc set to sfx
27/06/2009 9:35:46 PM general Old version: ffffffff (-1)
27/06/2009 9:35:46 PM general Install check: SetupVersion does NOT exist
27/06/2009 9:35:46 PM general SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 0
27/06/2009 9:35:46 PM registry Get registry: Software\Microsoft\Internet Explorer\Version=8.0.6001.18783
27/06/2009 9:35:46 PM general Operation set to INST_OP_INSTALL
27/06/2009 9:35:46 PM general GUID: ad1f3669-2686-4b44-a3f9-8feb87e84c9c
27/06/2009 9:35:46 PM general SelectCurrent: selected server 'tmp sfx storage' from 'sfx'
27/06/2009 9:35:46 PM internet SYNCER: Type: use IE settings
27/06/2009 9:35:46 PM internet SYNCER: Auth: another authentication, use WinInet
27/06/2009 9:35:54 PM file Destination folder: C:\Program Files\Alwil Software\Avast4
27/06/2009 9:35:54 PM package LoadProductVpu: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\prod-av_pro.vpu
27/06/2009 9:35:54 PM package LoadPartInfo: jrog = jrog-131 returned 00000000
27/06/2009 9:35:54 PM package LoadPartInfo: news = news-50 returned 00000000
27/06/2009 9:35:54 PM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
27/06/2009 9:35:54 PM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
27/06/2009 9:35:54 PM package LoadPartInfo: vps = vps-9060700 returned 00000000
27/06/2009 9:35:54 PM package LoadProductVpu: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\prod-av_pro.vpu ended with 00000000
27/06/2009 9:35:54 PM package Part prg_av_pro-537 was set to be installed
27/06/2009 9:35:54 PM package Part vps-9060700 was set to be installed
27/06/2009 9:35:54 PM package Part news-50 was set to be installed
27/06/2009 9:35:54 PM package Part setup_av_pro-537 was set to be installed
27/06/2009 9:35:54 PM package Part jrog-131 was set to be installed
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 153 & 0 = 153
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 153 & 0 = 153
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM general Operation set to INST_OP_INSTALL
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:35:54 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM general Selected group: Skins
27/06/2009 9:36:10 PM general Selected group: Instant Messaging
27/06/2009 9:36:10 PM general Selected group: P2P Shield
27/06/2009 9:36:10 PM general Selected group: Internet Mail
27/06/2009 9:36:10 PM general Selected group: Outlook/Exchange
27/06/2009 9:36:10 PM general Selected group: Network Shield
27/06/2009 9:36:10 PM general Selected group: Web Shield
27/06/2009 9:36:10 PM general Selected group: Standard Shield
27/06/2009 9:36:10 PM general Selected group: English language extension
27/06/2009 9:36:10 PM general Selected group: English help
27/06/2009 9:36:10 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:36:10 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: setif_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: setup_av_pro-537.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:36:10 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:36:11 PM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;f)
27/06/2009 9:36:11 PM package LoadProductVpu: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\prod-av_pro.vpu
27/06/2009 9:36:11 PM package LoadPartInfo: jrog = jrog-131 returned 00000000
27/06/2009 9:36:11 PM package LoadPartInfo: news = news-50 returned 00000000
27/06/2009 9:36:11 PM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
27/06/2009 9:36:11 PM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
27/06/2009 9:36:11 PM package LoadPartInfo: vps = vps-9060700 returned 00000000
27/06/2009 9:36:11 PM package LoadProductVpu: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\prod-av_pro.vpu ended with 00000000
27/06/2009 9:36:12 PM package FilterOutExistingFiles: 154 & 0 = 154
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_core-4d6.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_dll409-1a4.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_hlp409-3b0.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: av_pro_skins-14.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: avscan-360.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: winsys-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: winsysgui-2.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: vps-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: vpsm-9060700.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: news409-37.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package IsFullOkay: jrog-131.vpu - not okay (doesn't exist)
27/06/2009 9:36:12 PM package Packages before download
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: av_pro_core-4d6.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\av_pro_core-4d6.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: av_pro_dll409-1a4.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\av_pro_dll409-1a4.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: av_pro_hlp409-3b0.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\av_pro_hlp409-3b0.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: av_pro_skins-14.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\av_pro_skins-14.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: avscan-360.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\avscan-360.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: winsys-2.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\winsys-2.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: winsysgui-2.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\winsysgui-2.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: vps-9060700.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9060700.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: vpsm-9060700.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9060700.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: news409-37.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\news409-37.vpu, returned 0x00000000
27/06/2009 9:36:12 PM internet Used server: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784
27/06/2009 9:36:12 PM file GetFileWithRetry: jrog-131.vpu downloaded and verified
27/06/2009 9:36:12 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\jrog-131.vpu, returned 0x00000000
27/06/2009 9:36:13 PM general setup: updated
27/06/2009 9:36:13 PM general setif: updated
27/06/2009 9:36:13 PM file SetExistingFilesBitmap: Setting group av_pro_sysx because of existing file C:\Windows\system32\OleAcc.dll
27/06/2009 9:36:13 PM file SetExistingFilesBitmap: 1055->5->5
27/06/2009 9:36:13 PM package FilterOutExistingFiles: 154 & 5 = 150
27/06/2009 9:36:13 PM package Extracting from av_pro_core-4d6.vpu
27/06/2009 9:36:13 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\background.bmp
27/06/2009 9:36:13 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\background.bmp
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Aavm4h.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Aavm4h.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AavmGuih.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AavmGuih.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AavmRpch.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AavmRpch.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhResMai.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhResMai.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ahResMes.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ahResMes.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhResNS.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhResNS.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhResOut.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhResOut.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ahResP2P.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ahResP2P.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhResStd.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhResStd.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhResWS.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhResWS.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhRuiMai.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhRuiMai.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ahRuiMes.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ahRuiMes.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhRuiNS.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhRuiNS.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhRuiOut.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhRuiOut.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ahRuiP2P.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ahRuiP2P.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhRuiStd.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhRuiStd.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AhRuiWS.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AhRuiWS.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashBase.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashBase.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashCfgP.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashCfgP.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashCfgT.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashCfgT.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashChest.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashChest.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashOutXt.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashOutXt.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashShA64.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashShA64.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashShell.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashShell.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSODBC.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSODBC.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSXML.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSXML.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashTask.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashTask.dll
27/06/2009 9:36:14 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashUInt.dll
27/06/2009 9:36:14 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashUInt.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswAux.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswAux.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswIdle.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswIdle.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswInteg.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswInteg.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswMonVD.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswMonVD.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswRawFS.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswRawFS.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswRes.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswRes.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\avCommEx.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\avCommEx.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AVSSHOOK.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AVSSHOOK.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\XT1922.dll
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\XT1922.dll
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashAvast.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashAvast.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashBug.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashBug.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashChest.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashChest.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashCnsnt.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashCnsnt.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashDisp.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashDisp.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashLogV.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashLogV.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashQuick.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashQuick.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashServ.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashServ.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashUpd.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashUpd.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
27/06/2009 9:36:15 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
27/06/2009 9:36:15 PM file Direct move of file: C:\Windows\system32\aswBoot.exe
27/06/2009 9:36:15 PM file Installed file:C:\Windows\system32\aswBoot.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswChLic.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswChLic.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMem64.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMem64.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\sched.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\sched.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\VisthAux.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\VisthAux.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\VisthLic.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\VisthLic.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Data\report\background.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Data\report\background.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\chest.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\chest.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\lense.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\lense.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Data\report\logo.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Data\report\logo.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\logo.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\logo.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\oranz.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\oranz.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\resident.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\resident.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\setting.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\setting.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\slogan.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\slogan.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\spacer.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\spacer.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\update.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\update.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\virusdat.gif
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\virusdat.gif
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AavmKer4.inf
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AavmKer4.inf
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswFsBlk.inf
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswFsBlk.inf
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AswMon2.inf
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AswMon2.inf
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AswMonFlt.inf
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AswMonFlt.inf
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\main_01.jpg
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\main_01.jpg
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\images\main_02.jpg
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\images\main_02.jpg
27/06/2009 9:36:16 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\AVASTSS.scr
27/06/2009 9:36:16 PM file Installed file:C:\Program Files\Alwil Software\Avast4\AVASTSS.scr
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\Aavmker4.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\Aavmker4.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\Aavmker4.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\Aavmker4.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswFsBlk.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswFsBlk.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswFsBlk.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswFsBlk.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswFsBlk.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswFsBlk.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMon2.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMon2.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon2.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon2.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswMonDS.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswMonDS.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMonFlt.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMonFlt.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMonFlt.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMonFlt.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswMonFlt.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswMonFlt.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswRdr.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswRdr.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AswRdr.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AswRdr.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswRdr.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswRdr.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswSP.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswSP.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\aswSP.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\aswSP.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswSP.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswSP.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswTdi.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswTdi.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswTdi.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswTdi.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Setup\INF\AswTdi.sys
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Setup\INF\AswTdi.sys
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\wdp-ash-updscript.vbs
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\wdp-ash-updscript.vbs
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DefTasks.xml
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DefTasks.xml
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\Data\report\avast.xsl
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\Data\report\avast.xsl
27/06/2009 9:36:17 PM package Extracting from av_pro_dll409-1a4.vpu
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\Base.dll
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\Base.dll
27/06/2009 9:36:17 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\Boot.dll
27/06/2009 9:36:17 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\Boot.dll
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\Lang.dll
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\Lang.dll
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\LangMai.dll
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\LangMai.dll
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\image001.gif
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\image001.gif
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\virfound.gif
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\virfound.gif
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\11001.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\11001.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\400.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\400.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\401.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\401.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\407.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\407.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\502.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\502.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\504.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\504.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\aswClnTg.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\aswClnTg.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\aswInfTg.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\aswInfTg.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\Blocked.htm
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\Blocked.htm
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\ENHANCED.HTM
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\ENHANCED.HTM
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\aswClnTg.txt
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\aswClnTg.txt
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\aswInfTg.txt
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\aswInfTg.txt
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\License.txt
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\License.txt
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\Readme.txt
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\Readme.txt
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\hover.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\hover.wav
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\malfound.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\malfound.wav
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\press.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\press.wav
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\ready.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\ready.wav
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\suspic.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\suspic.wav
27/06/2009 9:36:18 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\virfound.wav
27/06/2009 9:36:18 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\virfound.wav
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\vpsupd.wav
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\vpsupd.wav
27/06/2009 9:36:19 PM package Extracting from av_pro_hlp409-3b0.vpu
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HELP\CheckListSimple.chm
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HELP\CheckListSimple.chm
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\ENGLISH\HELP\help.chm
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\ENGLISH\HELP\help.chm
27/06/2009 9:36:19 PM package Extracting from av_pro_skins-14.vpu
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\__snake.aswf
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\__snake.aswf
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\__strike.aswf
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\__strike.aswf
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\__vizer.aswf
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\__vizer.aswf
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\low res.asws
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\low res.asws
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\silver panel.asws
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\silver panel.asws
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\DATA\Skin\SZC-KDE.asws
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\DATA\Skin\SZC-KDE.asws
27/06/2009 9:36:19 PM package Extracting from avscan-360.vpu
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswCmnB.dll
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswCmnB.dll
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswCmnS.dll
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswCmnS.dll
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswEngin.dll
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswEngin.dll
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswScan.dll
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswScan.dll
27/06/2009 9:36:19 PM file Direct move of file: C:\Program Files\Alwil Software\Avast4\aswRunDll.exe
27/06/2009 9:36:19 PM file Installed file:C:\Program Files\Alwil Software\Avast4\aswRunDll.exe
27/06/2009 9:36:19 PM package Extracting from winsysgui-2.vpu
27/06/2009 9:36:20 PM file Direct move of file: C:\Windows\system32\actskin4.ocx
27/06/2009 9:36:20 PM file Installed file:C:\Windows\system32\actskin4.ocx
27/06/2009 9:36:20 PM package program: installed 150 files (20419662 bytes), removed 0 files
27/06/2009 9:36:20 PM general news: updated
27/06/2009 9:36:31 PM package vps: updated [9060700]
27/06/2009 9:36:31 PM system Uninstalling Aavmker4.sys
27/06/2009 9:36:31 PM system Reboot set by changed resident C:\Windows\system32\drivers\aswMonFlt.sys
27/06/2009 9:36:31 PM system Driver file copied: C:\Windows\system32\drivers\aswMonFlt.sys
27/06/2009 9:36:31 PM system Reboot set by changed resident C:\Windows\system32\drivers\aswSP.sys
27/06/2009 9:36:31 PM system Driver file copied: C:\Windows\system32\drivers\aswSP.sys
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\DisplayName=avast! Self Protection
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\ErrorControl=1
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\Type=1
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\Start=1
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\Parameters\ProgramFolder=\Device\HarddiskVolume1\Program Files\Alwil Software\Avast4
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswSP\Parameters\ProgramFolder2=\DosDevices\C:\Program Files\Alwil Software\Avast4
27/06/2009 9:36:31 PM system Reboot set by changed resident C:\Windows\system32\drivers\aswFsBlk.sys
27/06/2009 9:36:31 PM system Driver file copied: C:\Windows\system32\drivers\aswFsBlk.sys
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\DisplayName=aswFsBlk
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\ErrorControl=1
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\ImagePath=system32\DRIVERS\aswFsBlk.sys
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Type=2
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Start=2
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Group=FSFilter Activity Monitor
27/06/2009 9:36:31 PM system Service 'aswFsBlk' load order set id=2 in group 'FSFilter Activity Monitor'
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Tag=2
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Instances\DefaultInstance=aswFsBlk Instance
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Instances\aswFsBlk Instance\Altitude=388400
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Instances\aswFsBlk Instance\Flags=0
27/06/2009 9:36:31 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswFsBlk\Description=avast! mini-filter driver (aswFsBlk)
27/06/2009 9:36:31 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32\psapi.dll=1
27/06/2009 9:36:31 PM file File set as shared dll: C:\Windows\system32\psapi.dll
27/06/2009 9:36:31 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32\MSVCP71.dll=9
27/06/2009 9:36:31 PM file File set as shared dll: C:\Windows\system32\MSVCP71.dll
27/06/2009 9:36:31 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32\MSVCR71.dll=10
27/06/2009 9:36:31 PM file File set as shared dll: C:\Windows\system32\MSVCR71.dll
27/06/2009 9:36:31 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32\MFC71.dll=5
27/06/2009 9:36:31 PM file File set as shared dll: C:\Windows\system32\MFC71.dll
27/06/2009 9:36:32 PM file File registered: C:\Windows\system32\actskin4.ocx
27/06/2009 9:36:32 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32\actskin4.ocx=1
27/06/2009 9:36:32 PM file File set as shared dll: C:\Windows\system32\actskin4.ocx
27/06/2009 9:36:32 PM system File copied: C:\Windows\system32\AvastSS.scr
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Label=Feb2009
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4DataFolder=C:\Program Files\Alwil Software\Avast4\DATA
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4SkinFolder=C:\Program Files\Alwil Software\Avast4\DATA\Skin
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Version=4.8
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\VersionShort=4.8
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\SetupVersion=1335
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4ProgramFolder=C:\Program Files\Alwil Software\Avast4
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\Product=av_pro
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\OSPlatform=2
27/06/2009 9:36:32 PM registry Set registry: Software\Alwil Software\Avast\4.0\OSVersion=393216
27/06/2009 9:36:32 PM registry Set registry: .csk\=cskfile
27/06/2009 9:36:32 PM registry Set registry: .csk\Content Type=application/copernic-csk
27/06/2009 9:36:32 PM registry Set registry: .asws\=aswsfile
27/06/2009 9:36:32 PM registry Set registry: .asws\Content Type=application/avast-asws
27/06/2009 9:36:32 PM registry Set registry: aswsfile\=avast! Skin
27/06/2009 9:36:32 PM registry Set registry: aswsfile\EditFlags=65536
27/06/2009 9:36:32 PM registry Set registry: aswsfile\BrowserFlags=8
27/06/2009 9:36:32 PM registry Set registry: aswsfile\shell\=
27/06/2009 9:36:32 PM registry Set registry: aswsfile\shell\open\=
27/06/2009 9:36:32 PM registry Set registry: aswsfile\shell\open\command\="C:\Program Files\Alwil Software\Avast4\ashSimpl.exe" "%1"
27/06/2009 9:36:32 PM registry Set registry: .aswcs\=aswsfile
27/06/2009 9:36:32 PM registry Set registry: .aswcs\Content Type=application/avast-aswcs
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\=avast! Compressed Skin
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\EditFlags=65536
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\BrowserFlags=8
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\shell\=
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\shell\open\=
27/06/2009 9:36:32 PM registry Set registry: aswcsfile\shell\open\command\="C:\Program Files\Alwil Software\Avast4\ashSimpl.exe" "%1"
27/06/2009 9:36:32 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\App Paths\ashAvast.exe\Path=C:\Program Files\Alwil Software\Avast4
27/06/2009 9:36:32 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\App Paths\ashAvast.exe\=C:\Program Files\Alwil Software\Avast4\ashAvast.exe
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\EventLog\Antivirus\avast!\CategoryCount=3
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\EventLog\Antivirus\avast!\CategoryMessageFile=C:\Program Files\Alwil Software\Avast4\aswRes.dll
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\EventLog\Antivirus\avast!\EventMessageFile=C:\Program Files\Alwil Software\Avast4\aswRes.dll
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\EventLog\Antivirus\avast!\CategoryCount=7
27/06/2009 9:36:32 PM system Service avast! Antivirus dependency aswMonFlt;RpcSS;
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Antivirus\Description=Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.
27/06/2009 9:36:32 PM system Service avast! Antivirus NOT updated, error code: 0x00000424
27/06/2009 9:36:32 PM system Setting dependency for avast! Antivirus to aswMonFlt;RpcSS;
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Antivirus\Description=Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.
27/06/2009 9:36:32 PM system Service avast! Antivirus installed
27/06/2009 9:36:32 PM system Reboot set by non-installed service "avast! Antivirus"
27/06/2009 9:36:32 PM system Service avast! Antivirus dependency aswMonFlt;RpcSS;
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Antivirus\Description=Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.
27/06/2009 9:36:32 PM system Service avast! Antivirus updated
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswUpdSv\Description=Provides automatic updating for the avast! antivirus.
27/06/2009 9:36:32 PM system Service aswUpdSv installed
27/06/2009 9:36:32 PM system Service aswUpdSv dependency (null)
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswUpdSv\Description=Provides automatic updating for the avast! antivirus.
27/06/2009 9:36:32 PM system Service aswUpdSv updated
27/06/2009 9:36:32 PM registry Set registry: SOFTWARE\Microsoft\Exchange\Client\Extensions\avast! 4=4.0;C:\Program Files\Alwil Software\Avast4\ashOutXt.dll;1;10000111111000
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Mail Scanner\Description=Implements mail scanning for avast! antivirus.
27/06/2009 9:36:32 PM system Service avast! Mail Scanner installed
27/06/2009 9:36:32 PM system Service avast! Mail Scanner dependency avast! Antivirus
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Mail Scanner\Description=Implements mail scanning for avast! antivirus.
27/06/2009 9:36:32 PM system Service avast! Mail Scanner updated
27/06/2009 9:36:32 PM system Reboot set by changed resident C:\Windows\system32\drivers\aswTdi.sys
27/06/2009 9:36:32 PM system Driver file copied: C:\Windows\system32\drivers\aswTdi.sys
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\DisplayName=avast! Network Shield Support
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\ErrorControl=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\Type=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\Group=PNP_TDI
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\Start=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswTdi\Tag=2
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Web Scanner\Description=Implements web (HTTP) scanning for avast! antivirus.
27/06/2009 9:36:32 PM system Service avast! Web Scanner installed
27/06/2009 9:36:32 PM system Service avast! Web Scanner dependency avast! Antivirus
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\avast! Web Scanner\Description=Implements web (HTTP) scanning for avast! antivirus.
27/06/2009 9:36:32 PM system Service avast! Web Scanner updated
27/06/2009 9:36:32 PM system Driver file copied: C:\Windows\system32\drivers\aswRdr.sys
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswRdr\DisplayName=aswRdr
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswRdr\ErrorControl=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswRdr\Type=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswRdr\Start=1
27/06/2009 9:36:32 PM registry Set registry: SYSTEM\CurrentControlSet\Services\aswRdr\Group=PNP_TDI
27/06/2009 9:36:32 PM file Shortcut for ashAvast.exe installed in C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Antivirus
27/06/2009 9:36:32 PM file Shortcut for help.chm installed in C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Antivirus
27/06/2009 9:36:32 PM file Shortcut for ashAvast.exe installed in C:\Users\Public\Desktop
27/06/2009 9:36:32 PM registry Set registry: *\shellex\ContextMenuHandlers\avast\(null)={472083B0-C522-11CF-8763-00608CC02F24}
27/06/2009 9:36:32 PM registry Set registry: avast\ShellEx\ContextMenuHandlers\(null)={472083B0-C522-11CF-8763-00608CC02F24}
27/06/2009 9:36:32 PM registry Set registry: Folder\shellex\ContextMenuHandlers\avast\(null)={472083B0-C522-11CF-8763-00608CC02F24}
27/06/2009 9:36:32 PM registry Set registry: CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\(null)=avast
27/06/2009 9:36:32 PM registry Set registry: CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32\(null)=C:\Program Files\Alwil Software\Avast4\ashShell.dll
27/06/2009 9:36:32 PM registry Set registry: CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32\ReleaseName=C:\Program Files\Alwil Software\Avast4\ashShell.dll
27/06/2009 9:36:32 PM registry Set registry: CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32\ThreadingModel=Apartment
27/06/2009 9:36:32 PM registry Set registry: SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{472083B0-C522-11CF-8763-00608CC02F24}=avast
27/06/2009 9:36:32 PM registry Set registry: SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{472083B0-C522-11CF-8763-00608CC02F24}=avast
27/06/2009 9:36:32 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Run\avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
27/06/2009 9:36:32 PM file Fix security on: C:\Program Files\Alwil Software\Avast4\*.*
27/06/2009 9:36:33 PM file Fix security on: C:\Program Files\Alwil Software\Avast4\ENGLISH\*.*
27/06/2009 9:36:33 PM file Fix security on: C:\Program Files\Alwil Software\Avast4\ENGLISH\HELP\*.*
27/06/2009 9:36:33 PM file Fix security on: C:\Program Files\Alwil Software\Avast4\ENGLISH\HtmlData\*.*
27/06/2009 9:36:33 PM file Fix security on: C:\Program Files\Alwil Software\Avast4\images\*.*
27/06/2009 9:36:33 PM system RemoveFileAcess(C:\Windows\system32\OleAcc.dll), SetNamedSecurityInfo returned 0x00000005
27/06/2009 9:36:33 PM system RemoveFileAcess(C:\Windows\system32\psapi.dll), SetNamedSecurityInfo returned 0x00000005
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\DisplayName=avast! Antivirus
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\DisplayVersion=4.8
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\HelpLink=http://www.avast.com
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\HelpTelephone=
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\UrlInfoAbout=http://www.avast.com
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\UrlUpdateInfo=http://www.avast.com
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\InstallLocation=C:\PROGRA~1\ALWILS~1\Avast4
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\InstallSource=C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_IN~1.TM~
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\Publisher=Alwil Software
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\VersionMajor=4
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\VersionMinor=8
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\DisplayIcon=C:\Program Files\Alwil Software\Avast4\ashAvast.exe
27/06/2009 9:36:33 PM registry Set registry: Software\Microsoft\Windows\CurrentVersion\Uninstall\avast!\UninstallString=C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
27/06/2009 9:36:33 PM general License key generated Demo
27/06/2009 9:36:42 PM system Executing:C:\Program Files\Alwil Software\Avast4\sched.exe /A:*
27/06/2009 9:36:43 PM system Executed:C:\Program Files\Alwil Software\Avast4\sched.exe /A:*
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Label=Feb2009
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4DataFolder=C:\Program Files\Alwil Software\Avast4\DATA
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4SkinFolder=C:\Program Files\Alwil Software\Avast4\DATA\Skin
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Version=4.8
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\VersionShort=4.8
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\SetupVersion=1335
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Avast4ProgramFolder=C:\Program Files\Alwil Software\Avast4
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\Product=av_pro
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\OSPlatform=2
27/06/2009 9:36:46 PM registry Set registry: Software\Alwil Software\Avast\4.0\OSVersion=393216
27/06/2009 9:36:46 PM package Transferred: files 0, bytes 0, time 217 ms
27/06/2009 9:36:46 PM package Retries: total 0, files 0, servers 1
27/06/2009 9:36:46 PM file NeedReboot=true
27/06/2009 9:36:46 PM system Delete on reboot(C:\PROGRA~1\ALWILS~1\Avast4\Setup\reboot.txt)
27/06/2009 9:36:46 PM system Delete on reboot(C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_SF~1.TM~\AVAST~1.SET)
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\avscan-360.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\av_pro_core-4d6.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\av_pro_dll409-1a4.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\av_pro_hlp409-3b0.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\av_pro_skins-14.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\jollyroger.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\jrog-131.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\news409-37.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\part-jrog-131.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\part-news-50.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\part-prg_av_pro-537.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\part-setup_av_pro-537.vpu
27/06/2009 9:36:46 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\part-vps-9060700.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\prod-av_pro.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\servers.def
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\servers.def.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\setif_av_pro-537.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\setup.ovr
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\setup_av_pro-537.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\vps-9060700.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\vpsm-9060700.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\winsys-2.vpu
27/06/2009 9:36:47 PM file Direct delete of file: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_sfx.tm~a05784\winsysgui-2.vpu
27/06/2009 9:36:47 PM system Delete on reboot(C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_SF~1.TM~)
27/06/2009 9:36:47 PM file MoveFileEx(C:\PROGRA~1\ALWILS~1\Avast4\Setup\reboot.txt, NULL)
27/06/2009 9:36:47 PM file MoveFileEx(C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_SF~1.TM~\AVAST~1.SET, NULL)
27/06/2009 9:36:47 PM file MoveFileEx(C:\Users\ADRIAN~1\AppData\Local\Temp\_AV_SF~1.TM~, NULL)
27/06/2009 9:36:47 PM general Return code: 0x20000000 [Something done]
27/06/2009 9:36:47 PM general Stopped: 27.06.2009, 21:36:47
27/06/2009 10:48:02 PM general Started: 27.06.2009, 22:48:02
27/06/2009 10:48:02 PM general Running setup_av_pro-537 (1335)
27/06/2009 10:48:02 PM system Operating system: Windows Vista ver 6.0, build 6001, sp 1.0 [Service Pack 1]
27/06/2009 10:48:02 PM system Memory: 42% load. Phys:1209024/2086672K free, Page:3567864/4194303K free, Virt:2021288/2097024K free
27/06/2009 10:48:02 PM system Computer WinName: ADRIANDORSEY-PC
27/06/2009 10:48:02 PM system Windows Net User: SYSTEM
27/06/2009 10:48:02 PM general Cmdline: /downloadpkgs /noreboot /updatevps /verysilent /limitcpu
27/06/2009 10:48:02 PM general DldSrc set to inet
27/06/2009 10:48:02 PM general Operation set to INST_OP_UPDATE_GET_PACKAGES
27/06/2009 10:48:02 PM general Old version: 537 (1335)
27/06/2009 10:48:02 PM registry Deleted registry: Software\Alwil Software\Avast\4.0\UpdateReady
27/06/2009 10:48:02 PM system Using temp: C:\Windows\TEMP\_av_proI.tm~a03768 (128126M free)
27/06/2009 10:48:02 PM general SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 1
27/06/2009 10:48:02 PM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;p)
27/06/2009 10:48:02 PM system Computer DnsName: AdrianDorsey-PC
27/06/2009 10:48:02 PM system Computer Ip Addr: 192.168.2.4
27/06/2009 10:48:02 PM system Installed in: C:\Program Files\Alwil Software\Avast4 (128126M free)
27/06/2009 10:48:02 PM internet SYNCER: Type: use IE settings
27/06/2009 10:48:02 PM internet SYNCER: Auth: another authentication, use WinInet
27/06/2009 10:48:02 PM package Part prg_av_pro-537 is installed
27/06/2009 10:48:02 PM package Part vps-9060700 is installed
27/06/2009 10:48:02 PM package Part news-50 is installed
27/06/2009 10:48:02 PM package Part setup_av_pro-537 is installed
27/06/2009 10:48:02 PM package Part jrog-145 is installed
27/06/2009 10:48:02 PM general Old version: 537 (1335)
27/06/2009 10:48:02 PM general GUID: ad1f3669-2686-4b44-a3f9-8feb87e84c9c
27/06/2009 10:48:08 PM general Server definition(s) loaded for 'main': 260 (maintenance:0)
27/06/2009 10:48:08 PM general SelectCurrent: selected server 'Download689 AVAST Server' from 'main'
27/06/2009 10:48:08 PM internet SYNCER: Type: use IE settings
27/06/2009 10:48:08 PM internet SYNCER: Auth: another authentication, use WinInet
27/06/2009 10:48:08 PM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;f)
27/06/2009 10:48:11 PM internet Used server: http://74.54.217.178/iavs4x
27/06/2009 10:48:16 PM general Server definition(s) loaded for 'main': 260 (maintenance:0)
27/06/2009 10:48:16 PM general SelectCurrent: selected server 'Download902 AVAST Server' from 'main'
27/06/2009 10:48:16 PM internet SYNCER: Type: use IE settings
27/06/2009 10:48:16 PM internet SYNCER: Auth: another authentication, use WinInet
27/06/2009 10:48:16 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:16 PM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu
27/06/2009 10:48:16 PM package LoadPartInfo: jrog = jrog-145 returned 00000000
27/06/2009 10:48:16 PM package LoadPartInfo: news = news-50 returned 00000000
27/06/2009 10:48:16 PM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
27/06/2009 10:48:16 PM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
27/06/2009 10:48:16 PM package LoadPartInfo: vps = vps-9062700 returned 00000000
27/06/2009 10:48:16 PM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu ended with 00000000
27/06/2009 10:48:16 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:16 PM file GetFileWithRetry: part-vps-9062700.vpu downloaded and verified
27/06/2009 10:48:16 PM package Part vps-9062700 was set to be installed
27/06/2009 10:48:16 PM package DeleteObsoletePackages: Removed part-vps-9060700.vpu
27/06/2009 10:48:16 PM package Packages before download
27/06/2009 10:48:17 PM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vps-9060700.vpu, size: 25900594. md5: F8E25FC9C069206D957B8E23E3B68BFC, computemd5 returned 0x00000000, sig: 5961AA50D99C6D307EC9C2B8C7F28672B28E723CA6139532A3693D7E3CBF2A5D2F0DEE77C1C5C1F8 returned 0x00000000
27/06/2009 10:48:17 PM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9060700.vpu, size: 133. md5: 1515EC83725C62F25F4137ED4C5CA820, computemd5 returned 0x00000000, sig: 4E31F129446F57EC04A18DA2184CF799AF09C6CE7282B15858E91A149E63542A53A5234B07313D9F returned 0x00000000
27/06/2009 10:48:17 PM general Part of license key: S9999999T9902A1106
27/06/2009 10:48:17 PM package IsFullOkay: vps-9062700.vpu - not okay (doesn't exist)
27/06/2009 10:48:18 PM package IsFullOkay: vpsm-9062700.vpu - not okay (doesn't exist)
27/06/2009 10:48:18 PM package IsFullOkay: vpsm-9062700.vpu - not okay (doesn't exist)
27/06/2009 10:48:18 PM package Packages before download
27/06/2009 10:48:19 PM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vps-9060700.vpu, size: 25900594. md5: F8E25FC9C069206D957B8E23E3B68BFC, computemd5 returned 0x00000000, sig: 5961AA50D99C6D307EC9C2B8C7F28672B28E723CA6139532A3693D7E3CBF2A5D2F0DEE77C1C5C1F8 returned 0x00000000
27/06/2009 10:48:19 PM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9060700.vpu, size: 133. md5: 1515EC83725C62F25F4137ED4C5CA820, computemd5 returned 0x00000000, sig: 4E31F129446F57EC04A18DA2184CF799AF09C6CE7282B15858E91A149E63542A53A5234B07313D9F returned 0x00000000
27/06/2009 10:48:19 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:20 PM file GetFileWithRetry: vps-9060800-9060700.vpu downloaded and verified
27/06/2009 10:48:20 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9060800-9060700.vpu, returned 0x00000000
27/06/2009 10:48:22 PM package PerformDiff: Ok
27/06/2009 10:48:22 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:22 PM file GetFileWithRetry: vps-9060900-9060800.vpu downloaded and verified
27/06/2009 10:48:22 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9060900-9060800.vpu, returned 0x00000000
27/06/2009 10:48:23 PM package PerformDiff: Ok
27/06/2009 10:48:23 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:23 PM file GetFileWithRetry: vps-9061000-9060900.vpu downloaded and verified
27/06/2009 10:48:23 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061000-9060900.vpu, returned 0x00000000
27/06/2009 10:48:23 PM package PerformDiff: Ok
27/06/2009 10:48:24 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:24 PM file GetFileWithRetry: vps-9061100-9061000.vpu downloaded and verified
27/06/2009 10:48:24 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061100-9061000.vpu, returned 0x00000000
27/06/2009 10:48:24 PM package PerformDiff: Ok
27/06/2009 10:48:24 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:24 PM file GetFileWithRetry: vps-9061200-9061100.vpu downloaded and verified
27/06/2009 10:48:24 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061200-9061100.vpu, returned 0x00000000
27/06/2009 10:48:24 PM package PerformDiff: Ok
27/06/2009 10:48:25 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:25 PM file GetFileWithRetry: vps-9061300-9061200.vpu downloaded and verified
27/06/2009 10:48:25 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061300-9061200.vpu, returned 0x00000000
27/06/2009 10:48:25 PM package PerformDiff: Ok
27/06/2009 10:48:25 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:25 PM file GetFileWithRetry: vps-9061400-9061300.vpu downloaded and verified
27/06/2009 10:48:25 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061400-9061300.vpu, returned 0x00000000
27/06/2009 10:48:26 PM package PerformDiff: Ok
27/06/2009 10:48:26 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:26 PM file GetFileWithRetry: vps-9061500-9061400.vpu downloaded and verified
27/06/2009 10:48:26 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061500-9061400.vpu, returned 0x00000000
27/06/2009 10:48:26 PM package PerformDiff: Ok
27/06/2009 10:48:27 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:27 PM file GetFileWithRetry: vps-9061600-9061500.vpu downloaded and verified
27/06/2009 10:48:27 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061600-9061500.vpu, returned 0x00000000
27/06/2009 10:48:27 PM package PerformDiff: Ok
27/06/2009 10:48:28 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:28 PM file GetFileWithRetry: vps-9061700-9061600.vpu downloaded and verified
27/06/2009 10:48:28 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061700-9061600.vpu, returned 0x00000000
27/06/2009 10:48:28 PM package PerformDiff: Ok
27/06/2009 10:48:28 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:28 PM file GetFileWithRetry: vps-9061800-9061700.vpu downloaded and verified
27/06/2009 10:48:28 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061800-9061700.vpu, returned 0x00000000
27/06/2009 10:48:28 PM package PerformDiff: Ok
27/06/2009 10:48:29 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:29 PM file GetFileWithRetry: vps-9061900-9061800.vpu downloaded and verified
27/06/2009 10:48:29 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9061900-9061800.vpu, returned 0x00000000
27/06/2009 10:48:29 PM package PerformDiff: Ok
27/06/2009 10:48:29 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:29 PM file GetFileWithRetry: vps-9062000-9061900.vpu downloaded and verified
27/06/2009 10:48:29 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062000-9061900.vpu, returned 0x00000000
27/06/2009 10:48:29 PM package PerformDiff: Ok
27/06/2009 10:48:30 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:30 PM file GetFileWithRetry: vps-9062100-9062000.vpu downloaded and verified
27/06/2009 10:48:30 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062100-9062000.vpu, returned 0x00000000
27/06/2009 10:48:30 PM package PerformDiff: Ok
27/06/2009 10:48:30 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:30 PM file GetFileWithRetry: vps-9062200-9062100.vpu downloaded and verified
27/06/2009 10:48:30 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062200-9062100.vpu, returned 0x00000000
27/06/2009 10:48:30 PM package PerformDiff: Ok
27/06/2009 10:48:31 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:31 PM file GetFileWithRetry: vps-9062300-9062200.vpu downloaded and verified
27/06/2009 10:48:31 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062300-9062200.vpu, returned 0x00000000
27/06/2009 10:48:31 PM package PerformDiff: Ok
27/06/2009 10:48:31 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:31 PM file GetFileWithRetry: vps-9062400-9062300.vpu downloaded and verified
27/06/2009 10:48:31 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062400-9062300.vpu, returned 0x00000000
27/06/2009 10:48:31 PM package PerformDiff: Ok
27/06/2009 10:48:32 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:32 PM file GetFileWithRetry: vps-9062500-9062400.vpu downloaded and verified
27/06/2009 10:48:32 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062500-9062400.vpu, returned 0x00000000
27/06/2009 10:48:32 PM package PerformDiff: Ok
27/06/2009 10:48:32 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:32 PM file GetFileWithRetry: vps-9062600-9062500.vpu downloaded and verified
27/06/2009 10:48:32 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062600-9062500.vpu, returned 0x00000000
27/06/2009 10:48:32 PM package PerformDiff: Ok
27/06/2009 10:48:33 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:48:33 PM file GetFileWithRetry: vps-9062700-9062600.vpu downloaded and verified
27/06/2009 10:48:33 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062700-9062600.vpu, returned 0x00000000
27/06/2009 10:48:33 PM package PerformDiff: Ok
27/06/2009 10:49:12 PM package DeleteObsoletePackages: Removed vps-9060700.vpu
27/06/2009 10:49:13 PM internet Used server: http://download902.avast.com/iavs4x
27/06/2009 10:49:13 PM file GetFileWithRetry: vpsm-9062700.vpu downloaded and verified
27/06/2009 10:49:13 PM package DldPackage: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9062700.vpu, returned 0x00000000
27/06/2009 10:49:13 PM package DeleteObsoletePackages: Removed vpsm-9060700.vpu
27/06/2009 10:49:13 PM package Transferred: files 24, bytes 1237100, time 9919 ms
27/06/2009 10:49:13 PM package Retries: total 0, files 0, servers 2
27/06/2009 10:49:13 PM package Submit: files 0, bytes 0, time 0 ms
27/06/2009 10:49:13 PM package Submit success: files 0, bytes 0, time 0 ms
27/06/2009 10:49:13 PM internet Sending stats 'http://download902.avast.com/cgi-bin/iavs4stats.cgi': 00000000 204
27/06/2009 10:49:13 PM file NeedReboot=false
27/06/2009 10:49:13 PM general Return code: 0x20000000 [Something done]
27/06/2009 10:49:13 PM general Stopped: 27.06.2009, 22:49:13
27/06/2009 10:49:14 PM general Started: 27.06.2009, 22:49:14
27/06/2009 10:49:14 PM general Running setup_av_pro-537 (1335)
27/06/2009 10:49:14 PM system Operating system: Windows Vista ver 6.0, build 6001, sp 1.0 [Service Pack 1]
27/06/2009 10:49:14 PM system Memory: 41% load. Phys:1220068/2086672K free, Page:3529420/4194303K free, Virt:2021288/2097024K free
27/06/2009 10:49:14 PM system Computer WinName: ADRIANDORSEY-PC
27/06/2009 10:49:14 PM system Windows Net User: SYSTEM
27/06/2009 10:49:14 PM general Cmdline: /refresh /noreboot /updatevps /verysilent /limitcpu
27/06/2009 10:49:14 PM general Operation set to INST_OP_UPDATE_INSTALL_PACKAGES
27/06/2009 10:49:14 PM general Old version: 537 (1335)
27/06/2009 10:49:14 PM registry Deleted registry: Software\Alwil Software\Avast\4.0\UpdateReady
27/06/2009 10:49:14 PM system Using temp: C:\Windows\TEMP\_av_proI.tm~a02284 (128126M free)
27/06/2009 10:49:14 PM general SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 1
27/06/2009 10:49:14 PM system Installed in: C:\Program Files\Alwil Software\Avast4 (128126M free)
27/06/2009 10:49:14 PM internet SYNCER: Type: use IE settings
27/06/2009 10:49:14 PM internet SYNCER: Auth: another authentication, use WinInet
27/06/2009 10:49:14 PM package Part prg_av_pro-537 is installed
27/06/2009 10:49:14 PM package Part vps-9062700 is installed
27/06/2009 10:49:14 PM package Part news-50 is installed
27/06/2009 10:49:14 PM package Part setup_av_pro-537 is installed
27/06/2009 10:49:14 PM package Part jrog-145 is installed
27/06/2009 10:49:14 PM general Old version: 537 (1335)
27/06/2009 10:49:14 PM general GUID: ad1f3669-2686-4b44-a3f9-8feb87e84c9c
27/06/2009 10:49:14 PM general Entering:UpdateInstallPackages
27/06/2009 10:49:14 PM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu
27/06/2009 10:49:14 PM package LoadPartInfo: jrog = jrog-145 returned 00000000
27/06/2009 10:49:14 PM package LoadPartInfo: news = news-50 returned 00000000
27/06/2009 10:49:14 PM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
27/06/2009 10:49:14 PM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
27/06/2009 10:49:14 PM package LoadPartInfo: vps = vps-9062700 returned 00000000
27/06/2009 10:49:14 PM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu ended with 00000000
27/06/2009 10:49:15 PM package ArePartsInstallable: 1
27/06/2009 10:49:55 PM package vps: updated [9062700]
27/06/2009 10:49:55 PM package Transferred: files 0, bytes 0, time 0 ms
27/06/2009 10:49:55 PM package Retries: total 0, files 0, servers 0
27/06/2009 10:49:55 PM file NeedReboot=false
27/06/2009 10:49:55 PM general Return code: 0x20000000 [Something done]
27/06/2009 10:49:55 PM general Stopped: 27.06.2009, 22:49:55
28/06/2009 12:39:24 AM general Started: 28.06.2009, 00:39:24
28/06/2009 12:39:24 AM general Running setup_av_pro-537 (1335)
28/06/2009 12:39:24 AM system Operating system: Windows Vista ver 6.0, build 6001, sp 1.0 [Service Pack 1]
28/06/2009 12:39:24 AM system Memory: 47% load. Phys:1105492/2086672K free, Page:3028240/4194303K free, Virt:2024704/2097024K free
28/06/2009 12:39:24 AM system Computer WinName: ADRIANDORSEY-PC
28/06/2009 12:39:24 AM system Windows Net User: AdrianDorsey-PC\Adrian Dorsey
28/06/2009 12:39:24 AM general Cmdline: /downloadpkgs /noreboot /updatevps /silent /progress
28/06/2009 12:39:24 AM general DldSrc set to inet
28/06/2009 12:39:24 AM general Operation set to INST_OP_UPDATE_GET_PACKAGES
28/06/2009 12:39:24 AM general Old version: 537 (1335)
28/06/2009 12:39:24 AM registry Deleted registry: Software\Alwil Software\Avast\4.0\UpdateReady
28/06/2009 12:39:24 AM system Using temp: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_proI.tm~a05748 (128156M free)
28/06/2009 12:39:24 AM general SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 1
28/06/2009 12:39:24 AM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;p)
28/06/2009 12:39:24 AM system Computer DnsName: AdrianDorsey-PC
28/06/2009 12:39:24 AM system Computer Ip Addr: 192.168.2.4
28/06/2009 12:39:24 AM system Installed in: C:\Program Files\Alwil Software\Avast4 (128156M free)
28/06/2009 12:39:25 AM internet SYNCER: Type: use IE settings
28/06/2009 12:39:25 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:39:25 AM package Part prg_av_pro-537 is installed
28/06/2009 12:39:25 AM package Part vps-9062700 is installed
28/06/2009 12:39:25 AM package Part news-50 is installed
28/06/2009 12:39:25 AM package Part setup_av_pro-537 is installed
28/06/2009 12:39:25 AM package Part jrog-145 is installed
28/06/2009 12:39:25 AM general Old version: 537 (1335)
28/06/2009 12:39:25 AM general GUID: ad1f3669-2686-4b44-a3f9-8feb87e84c9c
28/06/2009 12:39:26 AM general Server definition(s) loaded for 'main': 260 (maintenance:0)
28/06/2009 12:39:26 AM general SelectCurrent: selected server 'Download729 AVAST Server' from 'main'
28/06/2009 12:39:26 AM internet SYNCER: Type: use IE settings
28/06/2009 12:39:26 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:39:26 AM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;f)
28/06/2009 12:39:26 AM internet Used server: http://75.126.120.204/iavs4x
28/06/2009 12:39:28 AM general Server definition(s) loaded for 'main': 260 (maintenance:0)
28/06/2009 12:39:28 AM general SelectCurrent: selected server 'Download747 AVAST Server' from 'main'
28/06/2009 12:39:28 AM internet SYNCER: Type: use IE settings
28/06/2009 12:39:28 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:39:28 AM internet Used server: http://208.43.71.144/iavs4x
28/06/2009 12:39:28 AM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu
28/06/2009 12:39:28 AM package LoadPartInfo: jrog = jrog-145 returned 00000000
28/06/2009 12:39:28 AM package LoadPartInfo: news = news-50 returned 00000000
28/06/2009 12:39:28 AM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
28/06/2009 12:39:28 AM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
28/06/2009 12:39:28 AM package LoadPartInfo: vps = vps-9062700 returned 00000000
28/06/2009 12:39:28 AM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu ended with 00000000
28/06/2009 12:39:28 AM general Part of license key: W24355896H1400A0511
28/06/2009 12:39:29 AM package Packages before download
28/06/2009 12:39:29 AM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062700.vpu, size: 26389072. md5: 0E825D11C292632517A16863C34E65FE, computemd5 returned 0x00000000, sig: 60F50FD566B7333B1A3B5C2EC2D11A585C14F3BB899267DAF8FF7F5BF6F6F5F43F5EB582E15CE34A returned 0x00000000
28/06/2009 12:39:29 AM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9062700.vpu, size: 133. md5: 795A91EA8DE101343E768317439A4BD9, computemd5 returned 0x00000000, sig: 4FB97F9345D1BEDB612A4EEF52C4812084E5AC4E8E94D3967CBAE866327CC955928F1973AA77BAEA returned 0x00000000
28/06/2009 12:39:32 AM package Transferred: files 2, bytes 20, time 562 ms
28/06/2009 12:39:32 AM package Retries: total 0, files 0, servers 2
28/06/2009 12:39:32 AM package Submit: files 0, bytes 0, time 0 ms
28/06/2009 12:39:32 AM package Submit success: files 0, bytes 0, time 0 ms
28/06/2009 12:39:32 AM file NeedReboot=false
28/06/2009 12:39:32 AM general Return code: 0x20000001 [Nothing done]
28/06/2009 12:39:32 AM general Stopped: 28.06.2009, 00:39:32
28/06/2009 12:41:28 AM general Started: 28.06.2009, 00:41:28
28/06/2009 12:41:28 AM general Running setup_av_pro-537 (1335)
28/06/2009 12:41:28 AM system Operating system: Windows Vista ver 6.0, build 6001, sp 1.0 [Service Pack 1]
28/06/2009 12:41:28 AM system Memory: 47% load. Phys:1101124/2086672K free, Page:3025196/4194303K free, Virt:2024704/2097024K free
28/06/2009 12:41:28 AM system Computer WinName: ADRIANDORSEY-PC
28/06/2009 12:41:28 AM system Windows Net User: AdrianDorsey-PC\Adrian Dorsey
28/06/2009 12:41:28 AM general Cmdline: /downloadpkgs /noreboot /updatevps /silent /progress
28/06/2009 12:41:28 AM general DldSrc set to inet
28/06/2009 12:41:28 AM general Operation set to INST_OP_UPDATE_GET_PACKAGES
28/06/2009 12:41:28 AM general Old version: 537 (1335)
28/06/2009 12:41:28 AM registry Deleted registry: Software\Alwil Software\Avast\4.0\UpdateReady
28/06/2009 12:41:28 AM system Using temp: C:\Users\ADRIAN~1\AppData\Local\Temp\_av_proI.tm~a04316 (128156M free)
28/06/2009 12:41:28 AM general SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 1
28/06/2009 12:41:28 AM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;p)
28/06/2009 12:41:28 AM system Computer DnsName: AdrianDorsey-PC
28/06/2009 12:41:28 AM system Computer Ip Addr: 192.168.2.4
28/06/2009 12:41:28 AM system Installed in: C:\Program Files\Alwil Software\Avast4 (128156M free)
28/06/2009 12:41:28 AM internet SYNCER: Type: use IE settings
28/06/2009 12:41:28 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:41:28 AM package Part prg_av_pro-537 is installed
28/06/2009 12:41:28 AM package Part vps-9062700 is installed
28/06/2009 12:41:28 AM package Part news-50 is installed
28/06/2009 12:41:28 AM package Part setup_av_pro-537 is installed
28/06/2009 12:41:28 AM package Part jrog-145 is installed
28/06/2009 12:41:28 AM general Old version: 537 (1335)
28/06/2009 12:41:28 AM general GUID: ad1f3669-2686-4b44-a3f9-8feb87e84c9c
28/06/2009 12:41:29 AM general Server definition(s) loaded for 'main': 260 (maintenance:0)
28/06/2009 12:41:29 AM general SelectCurrent: selected server 'Download965 AVAST Server' from 'main'
28/06/2009 12:41:29 AM internet SYNCER: Type: use IE settings
28/06/2009 12:41:29 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:41:30 AM internet SYNCER: Agent=Syncer/4.80 (av_pro-1335;f)
28/06/2009 12:41:30 AM internet Used server: http://74.86.245.116/iavs4x
28/06/2009 12:41:31 AM general Server definition(s) loaded for 'main': 260 (maintenance:0)
28/06/2009 12:41:31 AM general SelectCurrent: selected server 'Download749 AVAST Server' from 'main'
28/06/2009 12:41:31 AM internet SYNCER: Type: use IE settings
28/06/2009 12:41:31 AM internet SYNCER: Auth: another authentication, use WinInet
28/06/2009 12:41:32 AM internet Used server: http://208.43.71.148/iavs4x
28/06/2009 12:41:32 AM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu
28/06/2009 12:41:32 AM package LoadPartInfo: jrog = jrog-145 returned 00000000
28/06/2009 12:41:32 AM package LoadPartInfo: news = news-50 returned 00000000
28/06/2009 12:41:32 AM package LoadPartInfo: program = prg_av_pro-537 returned 00000000
28/06/2009 12:41:32 AM package LoadPartInfo: setup = setup_av_pro-537 returned 00000000
28/06/2009 12:41:32 AM package LoadPartInfo: vps = vps-9062700 returned 00000000
28/06/2009 12:41:32 AM package LoadProductVpu: C:\Program Files\Alwil Software\Avast4\Setup\prod-av_pro.vpu ended with 00000000
28/06/2009 12:41:32 AM general Part of license key: W24355896H1400A0511
28/06/2009 12:41:32 AM package Packages before download
28/06/2009 12:41:32 AM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vps-9062700.vpu, size: 26389072. md5: 0E825D11C292632517A16863C34E65FE, computemd5 returned 0x00000000, sig: 60F50FD566B7333B1A3B5C2EC2D11A585C14F3BB899267DAF8FF7F5BF6F6F5F43F5EB582E15CE34A returned 0x00000000
28/06/2009 12:41:32 AM package Vpu: C:\Program Files\Alwil Software\Avast4\Setup\vpsm-9062700.vpu, size: 133. md5: 795A91EA8DE101343E768317439A4BD9, computemd5 returned 0x00000000, sig: 4FB97F9345D1BEDB612A4EEF52C4812084E5AC4E8E94D3967CBAE866327CC955928F1973AA77BAEA returned 0x00000000
28/06/2009 12:41:32 AM package Transferred: files 2, bytes 20, time 515 ms
28/06/2009 12:41:32 AM package Retries: total 0, files 0, servers 2
28/06/2009 12:41:32 AM package Submit: files 0, bytes 0, time 0 ms
28/06/2009 12:41:32 AM package Submit success: files 0, bytes 0, time 0 ms
28/06/2009 12:41:32 AM file NeedReboot=false
28/06/2009 12:41:32 AM general Return code: 0x20000001 [Nothing done]
28/06/2009 12:41:32 AM general Stopped: 28.06.2009, 00:41:32

#5 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 28 June 2009 - 04:13 PM

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#6 pendrakhis

pendrakhis
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 29 June 2009 - 05:01 AM

God I hope this is the log. Seems to be. It has the items that were listed on Dr. Web during the scan process. I notice one of the trojans came in through an album download which one of my kids did not too long ago. Ugh... Rebooted as requested afterward.

Dr. Web log report

1623___1.qit/data032\data002;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine\1623___1.qit/data032;Adware.SpywareStorm;;
data032;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine;Archive contains infected objects;;
1623___1.qit;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
ComboFix[11.exe/data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine\ComboFix[11.exe/data002;Program.PsExec.171;;
data002;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine;Archive contains infected objects;;
ComboFix[11.exe;C:\Documents and Settings\Adrian Dorsey\DoctorWeb\Quarantine;Container contains infected objects;Moved.;
rise against (from new album).mp3;C:\Documents and Settings\Adrian Dorsey\Shared;Trojan.WMALoader;Cured.;


The Root Repeal just does not want to work. It starts to scan and then freezes and sometimes the whole computer just reboots on its own. Should I keep trying?

#7 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 29 June 2009 - 06:59 AM

No, we will abandon Rootrepeal.

Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#8 pendrakhis

pendrakhis
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 30 June 2009 - 08:47 AM

Ok... did the smitfraudfix as you requested and selected #1- Search and hit enter... a quick window pops up that indicates Access Denied and disappears just as fast. Did this about half a dozen times or so. Finally I tried just saving it instead of running and opened it with Run as Aministrator and it worked. Here is the log.

SmitFraudFix v2.423

Scan done at 9:38:39.86, 30/06/2009
Run from C:\Users\Adrian Dorsey\Documents\Anti-malware\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe

Now... I have noticed that I am able to use google again without difficulty... so something is definitely working in favor of a good report with what we have done so far. That was my big clue that something was wrong and malwarebytes alone was not solving the issue. Another feature that appears to have been corrected is being able to copy and paste to microsoft word which was not working either for the last several months. A window kept popping up saying I had no room, even with a single word copied and ready to paste. I had to paste to notepad... reselect all... and then paste onto microsoft word.

I hope this is progress.... haha...

#9 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 30 June 2009 - 09:31 AM

Is that the full log from SmitFraudFix? It should have more information listed below.

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#10 pendrakhis

pendrakhis
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 02 July 2009 - 05:36 PM

I ran it again... I hope this is everything.

SmitFraudFix v2.423

Scan done at 18:32:55.23, 02/07/2009
Run from C:\Users\Adrian Dorsey\Documents\Anti-malware\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\vVX1000.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Curse\CurseClient.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Works\WksWP.exe
c:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Microsoft Works\wkgdcach.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Adrian Dorsey\Documents\Anti-malware\SmitfraudFix\Policies.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

hosts


C:\


C:\Windows


C:\Windows\system


C:\Windows\Web


C:\Windows\system32


C:\Windows\system32\LogFiles


C:\Users\Adrian Dorsey


C:\Users\ADRIAN~1\AppData\Local\Temp


C:\Users\Adrian Dorsey\Application Data


Start Menu


C:\Users\ADRIAN~1\FAVORI~1


Desktop


C:\Program Files


Corrupted keys


Desktop Components



o4Patch
!!!Attention, following keys are not inevitably infected!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



Agent.OMZ.Fix
!!!Attention, following keys are not inevitably infected!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


404Fix
!!!Attention, following keys are not inevitably infected!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
"LoadAppInit_DLLs"=dword:00000001


Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\Windows\\system32\\userinit.exe,"

RK

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]




DNS

Description: Intel® PRO/100 VE Network Connection
DNS Server Search Order: 192.168.2.1
DNS Server Search Order: 192.168.2.1
DNS Server Search Order: 65.24.7.10
DNS Server Search Order: 65.24.7.11

HKLM\SYSTEM\CCS\Services\Tcpip\..\{ABF5AF59-F52D-4819-9C89-95B431C7A111}: DhcpNameServer=192.168.2.1 192.168.2.1 65.24.7.10 65.24.7.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{ABF5AF59-F52D-4819-9C89-95B431C7A111}: DhcpNameServer=154.11.129.187 154.11.129.59 154.11.129.187 154.11.129.59
HKLM\SYSTEM\CS2\Services\Tcpip\..\{ABF5AF59-F52D-4819-9C89-95B431C7A111}: DhcpNameServer=192.168.2.1 192.168.2.1 65.24.7.10 65.24.7.11
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1 65.24.7.10 65.24.7.11
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=154.11.129.187 154.11.129.59 154.11.129.187 154.11.129.59
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1 65.24.7.10 65.24.7.11


Scanning for wininet.dll infection


End

#11 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 02 July 2009 - 09:00 PM

It looks like you have two antivirus packages install. That can cause problems because they can conflict with each other.

Please retry rootrepeal. If it does start, we need to move you to the HJT forum.

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#12 pendrakhis

pendrakhis
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:05 PM

Posted 05 July 2009 - 06:20 PM

Tried rootrepeal and the same thing happens... it freezes up as soon as it starts scanning the files. The two anti virus packages... I had AVG for awhile. Then at the start of this whole thing I tried Avast... Can you advise which one I should perhaps keep and the other to leave installed? Thank you.

#13 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:02:05 PM

Posted 05 July 2009 - 07:01 PM

The both rank the same to me. I have used both - Avast being the last.

Please follow this guide from step (6). Post a HJT log to the HJT forum and a Team member will be along to help you as soon as possible. You may wish to post a link back to this topic to see what was discussed thus far.

If you need any help with the guide, please let me know.

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#14 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,963 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:02:05 PM

Posted 05 July 2009 - 10:04 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/t/239158/skynetdll-judgement-day/ you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a HJT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the HJT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the HJT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond. Please be patient. It may take a while to get a response but your log will be reviewed and answered as soon as possible

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users