Hello,
I'm having problems with my work PC (running XP professional), files are going missing which subsequently means some software programs are not working. The problem may have come from a Trojan which I assumed my AV had taken care of. I have ESET NOD32 anti virus and I would like to include the log from this.
Also to follow will be the malwarebytes log and the gmer log, however, I can't get the DSS program to work. I am disconnecting from the internet and turning off the AV however there seems to be some script protection still running, which I can't seem to disable.
Many thanks in advance.
ESET:
29/08/2012 14:34:44 Real-time file system protection file C:\WINDOWS\Installer\MSI1F1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:32 Real-time file system protection file C:\WINDOWS\Installer\MSI1F0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:30 Real-time file system protection file C:\WINDOWS\Installer\MSI1EF.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:28 Real-time file system protection file C:\WINDOWS\Installer\MSI1EB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:28 Real-time file system protection file C:\WINDOWS\Installer\MSI1ED.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:27 Real-time file system protection file C:\WINDOWS\Installer\MSI1EA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:27 Real-time file system protection file C:\WINDOWS\Installer\MSI1EC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
23/08/2012 12:09:06 Real-time file system protection file C:\WINDOWS\Installer\MSI3C0D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
23/08/2012 12:09:04 Real-time file system protection file C:\WINDOWS\Installer\MSI3C0C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
22/08/2012 11:03:26 Real-time file system protection file C:\WINDOWS\Installer\MSI202.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
22/08/2012 11:03:26 Real-time file system protection file C:\WINDOWS\Installer\MSI205.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
21/08/2012 16:30:33 HTTP filter archive http://sports-livez.com/channel/ch-5.php JS/TrojanDownloader.Iframe.NKE trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
21/08/2012 14:29:48 HTTP filter archive http://sports-livez.com/channel/ch-7.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
16/08/2012 08:08:58 Real-time file system protection file C:\WINDOWS\Installer\MSI1C8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:08:58 Real-time file system protection file C:\WINDOWS\Installer\MSI1C7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:08:40 Real-time file system protection file C:\WINDOWS\Installer\MSI1C4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:56 Real-time file system protection file C:\WINDOWS\Installer\MSI1C3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:52 Real-time file system protection file C:\WINDOWS\Installer\MSI1C2.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:44 Real-time file system protection file C:\WINDOWS\Installer\MSI1C1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:41 Real-time file system protection file C:\WINDOWS\Installer\MSI1BE.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1BC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1BB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:51 Real-time file system protection file C:\WINDOWS\Installer\MSICF5F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:39 Real-time file system protection file C:\WINDOWS\Installer\MSICF5E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:32 Real-time file system protection file C:\WINDOWS\Installer\MSICF5D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:13 Real-time file system protection file C:\WINDOWS\Installer\MSICF5C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:08 Real-time file system protection file C:\WINDOWS\Installer\MSICF5B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:02 Real-time file system protection file C:\WINDOWS\Installer\MSICF5A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:01 Real-time file system protection file C:\WINDOWS\Installer\MSICF59.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:24 Real-time file system protection file C:\WINDOWS\Installer\MSI91DD.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:20 Real-time file system protection file C:\WINDOWS\Installer\MSI91DC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:15 Real-time file system protection file C:\WINDOWS\Installer\MSI91DB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:11 Real-time file system protection file C:\WINDOWS\Installer\MSI91DA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:07 Real-time file system protection file C:\WINDOWS\Installer\MSI91D9.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:05 Real-time file system protection file C:\WINDOWS\Installer\MSI91D8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:05 Real-time file system protection file C:\WINDOWS\Installer\MSI91D7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
08/08/2012 15:58:36 Real-time file system protection file C:\WINDOWS\Installer\MSI6246.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
08/08/2012 15:58:32 Real-time file system protection file C:\WINDOWS\Installer\MSI6245.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:10 Real-time file system protection file C:\WINDOWS\Installer\MSI7BBB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:05 Real-time file system protection file C:\WINDOWS\Installer\MSI7BBA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:02 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB9.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:58 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB6.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
01/08/2012 15:48:37 Real-time file system protection file C:\WINDOWS\Installer\MSI3BE1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
01/08/2012 15:48:37 Real-time file system protection file C:\WINDOWS\Installer\MSI3BDE.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:49:02 Real-time file system protection file C:\WINDOWS\Installer\MSIC5E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:57 Real-time file system protection file C:\WINDOWS\Installer\MSIC5D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:52 Real-time file system protection file C:\WINDOWS\Installer\MSIC5C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:47 Real-time file system protection file C:\WINDOWS\Installer\MSIC5B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:43 Real-time file system protection file C:\WINDOWS\Installer\MSIC5A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:42 Real-time file system protection file C:\WINDOWS\Installer\MSIC58.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:41 Real-time file system protection file C:\WINDOWS\Installer\MSIC59.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
26/07/2012 15:36:34 Real-time file system protection file C:\WINDOWS\Installer\MSI3FA1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
26/07/2012 15:36:32 Real-time file system protection file C:\WINDOWS\Installer\MSI3FA0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:24:13 Real-time file system protection file C:\WINDOWS\Installer\MSI194.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:24:02 Real-time file system protection file C:\WINDOWS\Installer\MSI193.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:55 Real-time file system protection file C:\WINDOWS\Installer\MSI190.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:33 Real-time file system protection file C:\WINDOWS\Installer\MSI189.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:30 Real-time file system protection file C:\WINDOWS\Installer\MSI164.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:21 Real-time file system protection file C:\WINDOWS\Installer\MSI13C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:22:54 Real-time file system protection file C:\WINDOWS\Installer\MSI13B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:40 Real-time file system protection file C:\WINDOWS\Installer\MSI1A4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1A3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:19 Real-time file system protection file C:\WINDOWS\Installer\MSI1A1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:06 Real-time file system protection file C:\WINDOWS\Installer\MSI19F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:49 Real-time file system protection file C:\WINDOWS\Installer\MSI19C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:42 Real-time file system protection file C:\WINDOWS\Installer\MSI197.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:42 Real-time file system protection file C:\WINDOWS\Installer\MSI196.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:41 Real-time file system protection file C:\WINDOWS\Installer\MSI19A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:29 Real-time file system protection file C:\WINDOWS\Installer\MSIB4A0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:26 Real-time file system protection file C:\WINDOWS\Installer\MSIB496.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:11 Real-time file system protection file C:\WINDOWS\Installer\MSIB48D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:37:17 Real-time file system protection file C:\WINDOWS\Installer\MSIB47F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:34:43 Real-time file system protection file C:\WINDOWS\Installer\MSIB440.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:34:09 Real-time file system protection file C:\WINDOWS\Installer\MSIB423.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:57 Real-time file system protection file C:\WINDOWS\Installer\MSIB41A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:31 Real-time file system protection file C:\WINDOWS\Installer\MSIB411.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:08 Real-time file system protection file C:\WINDOWS\Installer\MSIB408.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:20 Real-time file system protection file C:\WINDOWS\Installer\MSI5A73.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:15 Real-time file system protection file C:\WINDOWS\Installer\MSI5A72.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:10 Real-time file system protection file C:\WINDOWS\Installer\MSI5A71.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:05 Real-time file system protection file C:\WINDOWS\Installer\MSI5A70.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:58 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:55 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:55 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:26 Real-time file system protection file C:\WINDOWS\Installer\MSI12B1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:21 Real-time file system protection file C:\WINDOWS\Installer\MSI12A5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:18 Real-time file system protection file C:\WINDOWS\Installer\MSI12A4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:14 Real-time file system protection file C:\WINDOWS\Installer\MSI12A3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI12A1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI129F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI12A0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:41 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:33 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:24 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:03 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD6.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:57 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:57 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:56 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:50 Real-time file system protection file C:\WINDOWS\Installer\MSI8177.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:46 Real-time file system protection file C:\WINDOWS\Installer\MSI8176.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:43 Real-time file system protection file C:\WINDOWS\Installer\MSI8175.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8174.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI816F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8173.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8172.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:16 Real-time file system protection file C:\WINDOWS\Installer\MSI4295.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:12 Real-time file system protection file C:\WINDOWS\Installer\MSI4294.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:08 Real-time file system protection file C:\WINDOWS\Installer\MSI4293.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:04 Real-time file system protection file C:\WINDOWS\Installer\MSI4292.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:01 Real-time file system protection file C:\WINDOWS\Installer\MSI4291.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:22:58 Real-time file system protection file C:\WINDOWS\Installer\MSI4290.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:22:58 Real-time file system protection file C:\WINDOWS\Installer\MSI428F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:26:09 Real-time file system protection file C:\WINDOWS\Installer\MSI352.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:26:05 Real-time file system protection file C:\WINDOWS\Installer\MSI34F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:50 Real-time file system protection file C:\WINDOWS\Installer\MSI34E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:39 Real-time file system protection file C:\WINDOWS\Installer\MSI34D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:09 Real-time file system protection file C:\WINDOWS\Installer\MSI34B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:06 Real-time file system protection file C:\WINDOWS\Installer\MSI346.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:06 Real-time file system protection file C:\WINDOWS\Installer\MSI347.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:05 Real-time file system protection file C:\WINDOWS\Installer\MSI348.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 12:46:59 HTTP filter archive http://sports-livez.com/sopcast/sop-1.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
02/07/2012 15:20:13 Real-time file system protection file C:\WINDOWS\Installer\MSI3450.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:20:06 Real-time file system protection file C:\WINDOWS\Installer\MSI3438.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:20:01 Real-time file system protection file C:\WINDOWS\Installer\MSI3436.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:58 Real-time file system protection file C:\WINDOWS\Installer\MSI3432.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:53 Real-time file system protection file C:\WINDOWS\Installer\MSI342F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:51 Real-time file system protection file C:\WINDOWS\Installer\MSI3426.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:51 Real-time file system protection file C:\WINDOWS\Installer\MSI342A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/06/2012 15:02:53 Real-time file system protection file C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\system32\msiexec.exe.
08/06/2012 14:07:19 HTTP filter archive http://sports-livez.com/channel/ch-8.php JS/TrojanDownloader.Iframe.NKE trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
08/06/2012 14:06:49 HTTP filter archive http://sports-livez.com/channel/ch-7.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe
Malwarebytes:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.30.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jacqui Scott :: WORKSTATION02 [administrator]
30/08/2012 08:48:02
mbam-log-2012-08-30 (08-48-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 315509
Time elapsed: 1 hour(s), 2 minute(s), 2 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-30 09:55:02
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.3.06
Running: fx2ut849.exe; Driver: C:\DOCUME~1\JACQUI~1\LOCALS~1\Temp\awdorpoc.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys
---- EOF - GMER 1.0.15 ----
I'm having problems with my work PC (running XP professional), files are going missing which subsequently means some software programs are not working. The problem may have come from a Trojan which I assumed my AV had taken care of. I have ESET NOD32 anti virus and I would like to include the log from this.
Also to follow will be the malwarebytes log and the gmer log, however, I can't get the DSS program to work. I am disconnecting from the internet and turning off the AV however there seems to be some script protection still running, which I can't seem to disable.
Many thanks in advance.
ESET:
29/08/2012 14:34:44 Real-time file system protection file C:\WINDOWS\Installer\MSI1F1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:32 Real-time file system protection file C:\WINDOWS\Installer\MSI1F0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:30 Real-time file system protection file C:\WINDOWS\Installer\MSI1EF.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:28 Real-time file system protection file C:\WINDOWS\Installer\MSI1EB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:28 Real-time file system protection file C:\WINDOWS\Installer\MSI1ED.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:27 Real-time file system protection file C:\WINDOWS\Installer\MSI1EA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
29/08/2012 14:34:27 Real-time file system protection file C:\WINDOWS\Installer\MSI1EC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
23/08/2012 12:09:06 Real-time file system protection file C:\WINDOWS\Installer\MSI3C0D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
23/08/2012 12:09:04 Real-time file system protection file C:\WINDOWS\Installer\MSI3C0C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
22/08/2012 11:03:26 Real-time file system protection file C:\WINDOWS\Installer\MSI202.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
22/08/2012 11:03:26 Real-time file system protection file C:\WINDOWS\Installer\MSI205.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
21/08/2012 16:30:33 HTTP filter archive http://sports-livez.com/channel/ch-5.php JS/TrojanDownloader.Iframe.NKE trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
21/08/2012 14:29:48 HTTP filter archive http://sports-livez.com/channel/ch-7.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
16/08/2012 08:08:58 Real-time file system protection file C:\WINDOWS\Installer\MSI1C8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:08:58 Real-time file system protection file C:\WINDOWS\Installer\MSI1C7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:08:40 Real-time file system protection file C:\WINDOWS\Installer\MSI1C4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:56 Real-time file system protection file C:\WINDOWS\Installer\MSI1C3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:52 Real-time file system protection file C:\WINDOWS\Installer\MSI1C2.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:44 Real-time file system protection file C:\WINDOWS\Installer\MSI1C1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:41 Real-time file system protection file C:\WINDOWS\Installer\MSI1BE.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1BC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
16/08/2012 08:07:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1BB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:51 Real-time file system protection file C:\WINDOWS\Installer\MSICF5F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:39 Real-time file system protection file C:\WINDOWS\Installer\MSICF5E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:32 Real-time file system protection file C:\WINDOWS\Installer\MSICF5D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:13 Real-time file system protection file C:\WINDOWS\Installer\MSICF5C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:08 Real-time file system protection file C:\WINDOWS\Installer\MSICF5B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:02 Real-time file system protection file C:\WINDOWS\Installer\MSICF5A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
15/08/2012 16:13:01 Real-time file system protection file C:\WINDOWS\Installer\MSICF59.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:24 Real-time file system protection file C:\WINDOWS\Installer\MSI91DD.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:20 Real-time file system protection file C:\WINDOWS\Installer\MSI91DC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:15 Real-time file system protection file C:\WINDOWS\Installer\MSI91DB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:11 Real-time file system protection file C:\WINDOWS\Installer\MSI91DA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:07 Real-time file system protection file C:\WINDOWS\Installer\MSI91D9.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:05 Real-time file system protection file C:\WINDOWS\Installer\MSI91D8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
09/08/2012 15:59:05 Real-time file system protection file C:\WINDOWS\Installer\MSI91D7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
08/08/2012 15:58:36 Real-time file system protection file C:\WINDOWS\Installer\MSI6246.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
08/08/2012 15:58:32 Real-time file system protection file C:\WINDOWS\Installer\MSI6245.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:10 Real-time file system protection file C:\WINDOWS\Installer\MSI7BBB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:05 Real-time file system protection file C:\WINDOWS\Installer\MSI7BBA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:49:02 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB9.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:58 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB8.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB7.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB6.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/08/2012 15:48:54 Real-time file system protection file C:\WINDOWS\Installer\MSI7BB5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
01/08/2012 15:48:37 Real-time file system protection file C:\WINDOWS\Installer\MSI3BE1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
01/08/2012 15:48:37 Real-time file system protection file C:\WINDOWS\Installer\MSI3BDE.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:49:02 Real-time file system protection file C:\WINDOWS\Installer\MSIC5E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:57 Real-time file system protection file C:\WINDOWS\Installer\MSIC5D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:52 Real-time file system protection file C:\WINDOWS\Installer\MSIC5C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:47 Real-time file system protection file C:\WINDOWS\Installer\MSIC5B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:43 Real-time file system protection file C:\WINDOWS\Installer\MSIC5A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:42 Real-time file system protection file C:\WINDOWS\Installer\MSIC58.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
31/07/2012 15:48:41 Real-time file system protection file C:\WINDOWS\Installer\MSIC59.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
26/07/2012 15:36:34 Real-time file system protection file C:\WINDOWS\Installer\MSI3FA1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
26/07/2012 15:36:32 Real-time file system protection file C:\WINDOWS\Installer\MSI3FA0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:24:13 Real-time file system protection file C:\WINDOWS\Installer\MSI194.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:24:02 Real-time file system protection file C:\WINDOWS\Installer\MSI193.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:55 Real-time file system protection file C:\WINDOWS\Installer\MSI190.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:33 Real-time file system protection file C:\WINDOWS\Installer\MSI189.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:30 Real-time file system protection file C:\WINDOWS\Installer\MSI164.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:23:21 Real-time file system protection file C:\WINDOWS\Installer\MSI13C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
25/07/2012 12:22:54 Real-time file system protection file C:\WINDOWS\Installer\MSI13B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:40 Real-time file system protection file C:\WINDOWS\Installer\MSI1A4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:36 Real-time file system protection file C:\WINDOWS\Installer\MSI1A3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:19 Real-time file system protection file C:\WINDOWS\Installer\MSI1A1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:03:06 Real-time file system protection file C:\WINDOWS\Installer\MSI19F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:49 Real-time file system protection file C:\WINDOWS\Installer\MSI19C.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:42 Real-time file system protection file C:\WINDOWS\Installer\MSI197.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:42 Real-time file system protection file C:\WINDOWS\Installer\MSI196.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
24/07/2012 15:02:41 Real-time file system protection file C:\WINDOWS\Installer\MSI19A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:29 Real-time file system protection file C:\WINDOWS\Installer\MSIB4A0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:26 Real-time file system protection file C:\WINDOWS\Installer\MSIB496.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:38:11 Real-time file system protection file C:\WINDOWS\Installer\MSIB48D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:37:17 Real-time file system protection file C:\WINDOWS\Installer\MSIB47F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:34:43 Real-time file system protection file C:\WINDOWS\Installer\MSIB440.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:34:09 Real-time file system protection file C:\WINDOWS\Installer\MSIB423.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:57 Real-time file system protection file C:\WINDOWS\Installer\MSIB41A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:31 Real-time file system protection file C:\WINDOWS\Installer\MSIB411.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/07/2012 15:33:08 Real-time file system protection file C:\WINDOWS\Installer\MSIB408.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:20 Real-time file system protection file C:\WINDOWS\Installer\MSI5A73.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:15 Real-time file system protection file C:\WINDOWS\Installer\MSI5A72.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:10 Real-time file system protection file C:\WINDOWS\Installer\MSI5A71.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:31:05 Real-time file system protection file C:\WINDOWS\Installer\MSI5A70.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:58 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:55 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
18/07/2012 15:30:55 Real-time file system protection file C:\WINDOWS\Installer\MSI5A6E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:26 Real-time file system protection file C:\WINDOWS\Installer\MSI12B1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:21 Real-time file system protection file C:\WINDOWS\Installer\MSI12A5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:18 Real-time file system protection file C:\WINDOWS\Installer\MSI12A4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:14 Real-time file system protection file C:\WINDOWS\Installer\MSI12A3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI12A1.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI129F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
12/07/2012 15:29:13 Real-time file system protection file C:\WINDOWS\Installer\MSI12A0.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:41 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDC.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:33 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDB.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:24 Real-time file system protection file C:\WINDOWS\Installer\MSIAFDA.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:29:03 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD6.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:57 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD3.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:57 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD4.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
11/07/2012 15:28:56 Real-time file system protection file C:\WINDOWS\Installer\MSIAFD5.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:50 Real-time file system protection file C:\WINDOWS\Installer\MSI8177.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:46 Real-time file system protection file C:\WINDOWS\Installer\MSI8176.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:43 Real-time file system protection file C:\WINDOWS\Installer\MSI8175.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8174.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI816F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8173.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
05/07/2012 15:23:39 Real-time file system protection file C:\WINDOWS\Installer\MSI8172.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:16 Real-time file system protection file C:\WINDOWS\Installer\MSI4295.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:12 Real-time file system protection file C:\WINDOWS\Installer\MSI4294.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:08 Real-time file system protection file C:\WINDOWS\Installer\MSI4293.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:04 Real-time file system protection file C:\WINDOWS\Installer\MSI4292.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:23:01 Real-time file system protection file C:\WINDOWS\Installer\MSI4291.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:22:58 Real-time file system protection file C:\WINDOWS\Installer\MSI4290.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
04/07/2012 15:22:58 Real-time file system protection file C:\WINDOWS\Installer\MSI428F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:26:09 Real-time file system protection file C:\WINDOWS\Installer\MSI352.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:26:05 Real-time file system protection file C:\WINDOWS\Installer\MSI34F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:50 Real-time file system protection file C:\WINDOWS\Installer\MSI34E.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:39 Real-time file system protection file C:\WINDOWS\Installer\MSI34D.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:09 Real-time file system protection file C:\WINDOWS\Installer\MSI34B.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:06 Real-time file system protection file C:\WINDOWS\Installer\MSI346.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:06 Real-time file system protection file C:\WINDOWS\Installer\MSI347.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 15:25:05 Real-time file system protection file C:\WINDOWS\Installer\MSI348.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
03/07/2012 12:46:59 HTTP filter archive http://sports-livez.com/sopcast/sop-1.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
02/07/2012 15:20:13 Real-time file system protection file C:\WINDOWS\Installer\MSI3450.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:20:06 Real-time file system protection file C:\WINDOWS\Installer\MSI3438.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:20:01 Real-time file system protection file C:\WINDOWS\Installer\MSI3436.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:58 Real-time file system protection file C:\WINDOWS\Installer\MSI3432.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:53 Real-time file system protection file C:\WINDOWS\Installer\MSI342F.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:51 Real-time file system protection file C:\WINDOWS\Installer\MSI3426.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
02/07/2012 15:19:51 Real-time file system protection file C:\WINDOWS\Installer\MSI342A.tmp probably a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe.
19/06/2012 15:02:53 Real-time file system protection file C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Toolbar.Widgi application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\system32\msiexec.exe.
08/06/2012 14:07:19 HTTP filter archive http://sports-livez.com/channel/ch-8.php JS/TrojanDownloader.Iframe.NKE trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
08/06/2012 14:06:49 HTTP filter archive http://sports-livez.com/channel/ch-7.php JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined WORKSTATION02\Jacqui Scott Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe
Malwarebytes:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.30.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jacqui Scott :: WORKSTATION02 [administrator]
30/08/2012 08:48:02
mbam-log-2012-08-30 (08-48-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 315509
Time elapsed: 1 hour(s), 2 minute(s), 2 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-30 09:55:02
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.3.06
Running: fx2ut849.exe; Driver: C:\DOCUME~1\JACQUI~1\LOCALS~1\Temp\awdorpoc.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys
---- EOF - GMER 1.0.15 ----