my most humble apologies Soya. Yes, sorry, that was yahelite’s log, here is comodo’s:
Date/Time :2007-04-20 11:16:23
Severity :Medium
Reporter :Network Monitor
Description:Inbound Policy Violation (Access Denied, ICMP = UNREACHABLE)
Protocol:ICMP
IncomingSource: xx.xx.xxx.x
Destination: xxx.xxx.x.xx
Message: UNREACHABLE
Reason: Network Control Rule ID = 5
Date/Time :2007-04-20 10:42:12
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (svchost.exe)
Application: C:\WINDOWS\system32\svchost.exe
Parent: C:\WINDOWS\system32\services.exe
Protocol: UDP
InDestination: xxx.xxx.x.xx::dhcp(68)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of the Parent application C:\WINDOWS\system32\services.exe in memory.
Date/Time :2007-04-20 10:26:21
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (DesktopX.exe)
Application: C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xx.xxx.x.xx::http(80)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe in memory.
Date/Time :2007-04-20 10:26:20
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (DesktopX.exe)
Application: C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe
Parent: C:\WINDOWS\explorer.exeP
rotocol: UDP
OutDestination: xx.xxx.x.xx::dns(53)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe in memory.
Date/Time :2007-04-20 10:23:03
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (CavMUD.exe)
Application: C:\Program Files\Comodo\Comodo AntiVirus\CavMUD.exe
Parent: C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe
Protocol: UDP
OutDestination: xx.xxx.x.xx::dns(53)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of the Parent application C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe in memory.
Date/Time :2007-04-20 10:19:01
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (YahooMessenger.exe)
Application: C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xx.xxx.xxx.xxx::https(443)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe in memory.
Date/Time :2007-04-20 10:18:33
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (iexplore.exe)
Application: C:\Program Files\Internet Explorer\iexplore.exe
Parent: C:\WINDOWS\system32\svchost.exe
Protocol: TCP
OutDestination: xxx.xxx.xxx.xxx::http(80)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Internet Explorer\iexplore.exe in memory.
Date/Time :2007-04-20 10:17:59
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (CavEmSrv.exe)
Application: C:\Program Files\Comodo\Comodo AntiVirus\CavEmSrv.exe
Parent: C:\Program Files\Outlook Express\msimn.exe
Protocol: TCP
OutDestination: xxx.xxx.x.xxx::pop-3(110)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Comodo\Comodo AntiVirus\CavEmSrv.exe in memory.
Date/Time :2007-04-20 10:17:54
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msimn.exe)
Application: C:\Program Files\Outlook Express\msimn.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xxx.x.x.x::59165
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\Outlook Express\msimn.exe in memory.
Date/Time :2007-04-20 10:17:27
Severity :Medium
Reporter :Network Monitor
Description:Inbound Policy Violation (Access Denied, ICMP = UNREACHABLE)
Protocol:ICMP
IncomingSource: xx.xx.xxx.x
Destination: xxx.xxx.x.xx
Message: UNREACHABLE
Reason: Network Control Rule ID = 5
Date/Time :2007-04-20 10:17:23
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msnmsgr.exe)
Application: C:\Program Files\MSN Messenger\msnmsgr.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xxx.xx.xxx.13::http(80)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\MSN Messenger\msnmsgr.exe in memory.
Date/Time :2007-04-20 10:17:23
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (xns5.exe)
Application: C:\Program Files\X-NetStat Professional\xns5.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP
OutDestination: xx.xxx.x.xx::dns(53)
Details: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe modified the memory of C:\Program Files\X-NetStat Professional\xns5.exe in memory.
Date/Time :2007-04-20 10:16:59
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msnmsgr.exe)
Application: C:\Program Files\MSN Messenger\msnmsgr.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xx.xx.xxx.xx::http(80)
Details: C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe has loaded C:\Program Files\Stardock\Object Desktop\DesktopX\dx0.dll into the Parent application C:\WINDOWS\explorer.exe using a global hook which could be used by keyloggers to steal private information.
Date/Time :2007-04-20 10:16:58
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msnmsgr.exe)
Application: C:\Program Files\MSN Messenger\msnmsgr.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP
OutDestination: xx.xxx.x.xx::dns(53)
Details: C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe has loaded C:\Program Files\Stardock\Object Desktop\DesktopX\dx0.dll into the Parent application C:\WINDOWS\explorer.exe using a global hook which could be used by keyloggers to steal private information.
Date/Time :2007-04-20 10:16:43
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msnmsgr.exe)
Application: C:\Program Files\MSN Messenger\msnmsgr.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xx.x.xx.xx::1863
Details: C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe has loaded C:\Program Files\Stardock\Object Desktop\DesktopX\dx0.dll into the Parent application C:\WINDOWS\explorer.exe using a global hook which could be used by keyloggers to steal private information.
Date/Time :2007-04-20 09:58:26
Severity :Medium
Reporter :Network Monitor
Description:Inbound Policy Violation (Access Denied, ICMP = UNREACHABLE)
Protocol:ICMP
IncomingSource: xx.xx.xxx.x
Destination: xxx.xxx.x.xx
Message: UNREACHABLE
Reason: Network Control Rule ID = 5
Date/Time :2007-04-20 09:08:01
Severity :Medium
Reporter :Network Monitor
Description:Inbound Policy Violation (Access Denied, ICMP = UNREACHABLE)
Protocol:ICMP
IncomingSource: xx.xx.xxx.x
Destination: xxx.xxx.x.xx
Message: UNREACHABLE
Reason: Network Control Rule ID = 5
Date/Time :2007-04-20 08:55:35
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (msnmsgr.exe)
Application: C:\Program Files\MSN Messenger\msnmsgr.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP In
Destination: xxx.xxx.x.xx::52072
Details: C:\Program Files\Stardock\Object Desktop\DesktopX\WidgetManager.exe has modified the the User interface of the Parent application C:\WINDOWS\explorer.exe by sending special Window messages.
Date/Time :2007-04-20 08:55:21
Severity :High
Reporter :Application Behavior
AnalysisDescription: Suspicious Behaviour (YahooMessenger.exe)
Application: C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: TCP
OutDestination: xxx.xxx.xxx.xxx::5050
Details: C:\Program Files\Stardock\Object Desktop\DesktopX\WidgetManager.exe has modified the the User interface of the Parent application C:\WINDOWS\explorer.exe by sending special Window messages.
whew, the only difference i can find in anything is the firewall and antivirus.
Thanks again,
Domino