Results of system analysis

AVZ 4.29 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete, Terminate
2604AVG Anti-SpywareCopyright ? 2007 GRISOFT s.r.o.??6573.55 kb, rsAh,
created: 2007-06-11 17:25:42,
modified: 2007-06-11 17:25:42
Command line:
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
c:\program files\rising\rav\ccenter.exe
Script: Quarantine, Delete, BC delete, Terminate
1396CCenterCopyright Rising 2002??108.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2006-10-10 10:42:43
Command line:
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
800Windows Explorer(C) Microsoft Corporation. All rights reserved.??955.00 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2007-06-13 21:21:55
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete, Terminate
252AVG Anti-Spyware guardCopyright ? 2007 GRISOFT s.r.o.??305.55 kb, rsAh,
created: 2007-05-30 20:31:10,
modified: 2007-05-30 20:31:10
Command line:
c:\program files\java\jre1.5.0_09\bin\jucheck.exe
Script: Quarantine, Delete, BC delete, Terminate
3136Java(TM) Update CheckerCopyright ? 2004??236.11 kb, rsAh,
created: 2006-12-03 03:16:35,
modified: 2006-10-12 03:10:54
Command line:
-auto
c:\program files\rising\rav\ravmond.exe
Script: Quarantine, Delete, BC delete, Terminate
1492RavMondCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited??272.00 kb, rsAh,
created: 2006-10-10 10:41:01,
modified: 2007-01-12 11:01:01
Command line:
c:\program files\rising\rav\ravservice.exe
Script: Quarantine, Delete, BC delete, Terminate
344 Copyright (C) 2005??1256.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2007-05-21 08:31:25
Command line:
c:\program files\rising\rav\ravstub.exe
Script: Quarantine, Delete, BC delete, Terminate
1920Rising RavStubCopyright (c) 1998-2005 Rising Corp.??88.00 kb, rsAh,
created: 2006-10-10 10:41:01,
modified: 2007-01-12 11:01:02
Command line:
c:\program files\rising\rav\ravtray.exe
Script: Quarantine, Delete, BC delete, Terminate
2364RavNet TrayCopyright (C) 2003??856.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2007-03-20 08:31:02
Command line:
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1816Spooler SubSystem App? Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2005-06-11 07:53:32
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
2740SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1280.00 kb, rsAh,
created: 2007-02-27 11:39:26,
modified: 2007-02-27 11:39:26
Command line:
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
708Windows NT Logon Application(C) Microsoft Corporation. All rights reserved.??476.00 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2004-08-08 11:33:53
Command line:
winlogon.exe
Detected:33, recognized as trusted 24
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS
Script: Quarantine, Delete, BC delete
25296896PDF Shell ExtensionCopyright 2000-2004 Adobe Systems, Inc.--800
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS
Script: Quarantine, Delete, BC delete
268435456  --1816
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete
4194304AVG Anti-SpywareCopyright ? 2007 GRISOFT s.r.o.??2604
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
Script: Quarantine, Delete, BC delete
268435456AVG Anti-Spyware Scan EngineCopyright ? 2007 GRISOFT s.r.o.--2604, 252
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete
4194304AVG Anti-Spyware guardCopyright ? 2007 GRISOFT s.r.o.??252
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
Script: Quarantine, Delete, BC delete
23592960AVG Anti-Spyware shellexecutehookCopyright ? 2007 GRISOFT s.r.o.--800, 2740
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
Script: Quarantine, Delete, BC delete
4194304Java(TM) Update CheckerCopyright ? 2004??3136
C:\Program Files\Rising\Rav\BDEngine.dll
Script: Quarantine, Delete, BC delete
17629184BDEngine Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--2364
C:\Program Files\Rising\Rav\BDEX.dll
Script: Quarantine, Delete, BC delete
17825792BDEngine 动态链接库Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--2364
C:\Program Files\Rising\Rav\BDLib.dll
Script: Quarantine, Delete, BC delete
18022400BDLibCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--2364
C:\Program Files\Rising\Rav\BWList.dll
Script: Quarantine, Delete, BC delete
268435456BWList DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1492
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
Script: Quarantine, Delete, BC delete
4194304CCenterCopyright Rising 2002??1396
C:\Program Files\Rising\Rav\CfgDll.dll
Script: Quarantine, Delete, BC delete
147587072CfgDllCopyright ? 2004 - 2006--1492
C:\Program Files\Rising\Rav\DLCenter.dll
Script: Quarantine, Delete, BC delete
268435456DLCenter DLLCopyright(C) 2005--344
C:\Program Files\Rising\Rav\engine.dll
Script: Quarantine, Delete, BC delete
161415168engineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\expscan.dll
Script: Quarantine, Delete, BC delete
158334976ExpScan.dllCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ExtFile.dll
Script: Quarantine, Delete, BC delete
185008128extFile Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\HookCont.dll
Script: Quarantine, Delete, BC delete
160628736HookCont Dynamic Link LibraryCopyright (C) 2007--1492
C:\Program Files\Rising\Rav\HOOKSYS.dll
Script: Quarantine, Delete, BC delete
150536192HOOKSYS Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\HookWeb.dll
Script: Quarantine, Delete, BC delete
156958720HookWebCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\libload.dll
Script: Quarantine, Delete, BC delete
319815680LibLoadCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492, 2364
C:\Program Files\Rising\Rav\MemMon.dll
Script: Quarantine, Delete, BC delete
158138368MemMonCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\mPorts.dll
Script: Quarantine, Delete, BC delete
158466048mPorts.dllCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\NvFile.dll
Script: Quarantine, Delete, BC delete
185925632NVFileCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\PostTrt.dll
Script: Quarantine, Delete, BC delete
172556288PostTrtCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\psapi.dll
Script: Quarantine, Delete, BC delete
1931149312Process Status HelperCopyright (C) Microsoft Corp. 1981-1996--1492
C:\Program Files\Rising\Rav\Ravmond.exe
Script: Quarantine, Delete, BC delete
4194304RavMondCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited??1492
C:\Program Files\Rising\Rav\RavService.exe
Script: Quarantine, Delete, BC delete
4194304 Copyright (C) 2005??344
C:\Program Files\Rising\Rav\RavStub.exe
Script: Quarantine, Delete, BC delete
4194304Rising RavStubCopyright (c) 1998-2005 Rising Corp.??1920
C:\Program Files\Rising\Rav\RavTray.exe
Script: Quarantine, Delete, BC delete
4194304RavNet TrayCopyright (C) 2003??2364
C:\Program Files\Rising\Rav\RavTray936.dll
Script: Quarantine, Delete, BC delete
11993088瑞星杀毒软件网络版托盘程序版权所有 (C) 2003--2364
C:\Program Files\Rising\Rav\RavUILib.dll
Script: Quarantine, Delete, BC delete
268435456RavUILib DLLAll Rights Reserved--2364
C:\Program Files\Rising\Rav\regmon.dll
Script: Quarantine, Delete, BC delete
154533888regmonCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\rfwctrl.dll
Script: Quarantine, Delete, BC delete
10944512RfwCtrl DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\RSAPPMGR.DLL
Script: Quarantine, Delete, BC delete
13238272Rising Application ManagerCopyright ? 2004 - 2005--1492
C:\Program Files\Rising\Rav\RSCOMMON.DLL
Script: Quarantine, Delete, BC delete
594542592Rising Common Function Dynamic Link LibraryCopyright (c) 1998-2007 Rising Corp.--1492, 1920
C:\Program Files\Rising\Rav\RsCommX.dll
Script: Quarantine, Delete, BC delete
7602176RsCommXCopyright ? 2002--1492, 344, 1920, 2364
C:\Program Files\Rising\Rav\RsLog.dll
Script: Quarantine, Delete, BC delete
150470656RsLog DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\RsPPsys.dll
Script: Quarantine, Delete, BC delete
12058624RSPPSYS Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\RsVM.dll
Script: Quarantine, Delete, BC delete
204013568RSVM Dynamic Link LibraryCopyright (C) 2006--1492
C:\Program Files\Rising\Rav\ScanEx.dll
Script: Quarantine, Delete, BC delete
182321152ScanEXCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ScanExec.dll
Script: Quarantine, Delete, BC delete
329973760ScanExecCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ScanMac.dll
Script: Quarantine, Delete, BC delete
330235904ScanMacCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\Scanner.dll
Script: Quarantine, Delete, BC delete
151781376RsScannerCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ScanNet.dll
Script: Quarantine, Delete, BC delete
216268800ScanNetCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ScanPack.dll
Script: Quarantine, Delete, BC delete
187105280Unpack EngineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\ScanSct.dll
Script: Quarantine, Delete, BC delete
186449920ScanSctCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\SpamEng.dll
Script: Quarantine, Delete, BC delete
160759808SpamEng Dynamic Link LibraryCopyright (C) 2004--1492
C:\Program Files\Rising\Rav\UnExe.dll
Script: Quarantine, Delete, BC delete
179175424UnExeCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\Uroutine.dll
Script: Quarantine, Delete, BC delete
270729216Unpack RoutineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\Uscript.dll
Script: Quarantine, Delete, BC delete
178126848Unpack ScriptCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\Rising\Rav\VirusLib.dll
Script: Quarantine, Delete, BC delete
153223168VirusLibCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1492
C:\Program Files\SUPERAntiSpyware\deupx.dll
Script: Quarantine, Delete, BC delete
268435456deupx.dllCopyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com--2740
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
23789568ShellExecuteHook(c) Copyright 2004-2006 SuperAdBlocker.com --800, 2740
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
268435456SUPERAntiSpyware WinLogon ProcessorCopyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com--708
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
4194304SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??2740
C:\WINDOWS\system32\PRTdlink.dll
Script: Quarantine, Delete, BC delete
15925248  --1816
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
268435456Rising Shell Ext ModuleCopyright (c) 1998-2007 Rising Corp.--800, 2740
Modules detected:348, recognized as trusted 290

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys
Script: Quarantine, Delete, BC delete
F999A000001000 (4096)AVG7 Clean DriverCopyright ? 2006 GRISOFT, s.r.o.
C:\WINDOWS\system32\drivers\basetdi.sys
Script: Quarantine, Delete, BC delete
F852F000003000 (12288)basetdiCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited
C:\WINDOWS\System32\Drivers\DgiVecp.sys
Script: Quarantine, Delete, BC delete
F8A8F00000F000 (61440)Windows 2k,XP IEEE-1284 parallel class driver for ECP, Byte, and Nibble modesCopyright ? 1998, 1999 by Samsung Electronics Co., Ltd.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
F8A77000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F9794000002000 (8192)
C:\Program Files\Rising\Rav\ExpScan.sys
Script: Quarantine, Delete, BC delete
F8446000015000 (86016)ExpScan.sysCopyright (C) 2004 Rising
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
F998A000001000 (4096)
C:\Program Files\Rising\Rav\HOOKAPI.SYS
Script: Quarantine, Delete, BC delete
F930000000D000 (53248)HOOKAPI DriverCopyright (C) RFW Corp. 2000-2002
C:\Program Files\Rising\Rav\HOOKBASE.sys
Script: Quarantine, Delete, BC delete
F8A9F000009000 (36864)HookBaseCopyright (C) 2004
C:\Program Files\Rising\Rav\HOOKCONT.sys
Script: Quarantine, Delete, BC delete
F97B0000002000 (8192)HookContCopyright (C) 2007
C:\Program Files\Rising\Rav\HookReg.sys
Script: Quarantine, Delete, BC delete
F8603000004000 (16384)版权所有 (@) 2003
C:\Program Files\Rising\Rav\HookSys.sys
Script: Quarantine, Delete, BC delete
F84AB000026000 (155648)HooksysCopyright (C) 2007
C:\Program Files\Rising\Rav\MEMSCAN.sys
Script: Quarantine, Delete, BC delete
F85DB000004000 (16384)MemScan DriverRising Corp. All rights reserved.
C:\WINDOWS\system32\Drivers\RsNTGdi.sys
Script: Quarantine, Delete, BC delete
F9829000001000 (4096)RsNTGDICopyright (c) 1998-2007 Rising Corp.
C:\Program Files\Rising\Rav\RSPPSYS.sys
Script: Quarantine, Delete, BC delete
F851B000003000 (12288)RSPPSYSCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
F95E8000007000 (28672)SASDIFSVCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
F9648000005000 (20480)SuperAntiSpyware(C) Copyright 2004-2006
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
F935000000C000 (49152)SASKUTIL.SYSCopyright (C) 2006
Modules detected - 136, recognized as trusted - 118

Services

ServiceDescriptionStatusFileGroupDependencies
AVG Anti-Spyware Guard
Service: Stop, Delete, Disable
AVG Anti-Spyware GuardRunningC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete
  
RavService
Service: Stop, Delete, Disable
RavServiceRunningC:\Program Files\Rising\Rav\RavService.exe
Script: Quarantine, Delete, BC delete
  
RsCCenter
Service: Stop, Delete, Disable
Rising Process Communication CenterRunningC:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
Script: Quarantine, Delete, BC delete
  
RsRavMon
Service: Stop, Delete, Disable
RsRavMon ServiceRunningC:\Program Files\Rising\Rav\Ravmond.exe
Script: Quarantine, Delete, BC delete
TDIRsCCenter
Adobe LM Service
Service: Stop, Delete, Disable
Adobe LM ServiceNot startedC:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Script: Quarantine, Delete, BC delete
  
Detected - 87, recognized as trusted - 82

Drivers

ServiceDescriptionStatusFileGroupDependencies
AVG Anti-Spyware Driver
Driver: Unload, Delete, Disable
AVG Anti-Spyware DriverRunningC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
  
AvgAsCln
Driver: Unload, Delete, Disable
AVG Anti-Spyware Clean DriverRunningC:\WINDOWS\system32\DRIVERS\AvgAsCln.sys
Script: Quarantine, Delete, BC delete
Base 
BaseTDI
Driver: Unload, Delete, Disable
BaseTDIRunningC:\WINDOWS\system32\drivers\basetdi.sys
Script: Quarantine, Delete, BC delete
 Tcpip
DgiVecp
Driver: Unload, Delete, Disable
Team MFP Comm DriverRunningC:\WINDOWS\system32\Drivers\DgiVecp.sys
Script: Quarantine, Delete, BC delete
 +Parallel Arbitrator
ExpScaner
Driver: Unload, Delete, Disable
ExpScanerRunningC:\Program Files\Rising\Rav\ExpScan.sys
Script: Quarantine, Delete, BC delete
TDIBaseTDI
HookCont
Driver: Unload, Delete, Disable
HookContRunningC:\Program Files\Rising\Rav\HOOKCONT.sys
Script: Quarantine, Delete, BC delete
TDI 
HookReg
Driver: Unload, Delete, Disable
HookRegRunningC:\Program Files\Rising\Rav\HookReg.sys
Script: Quarantine, Delete, BC delete
TDI 
HookSys
Driver: Unload, Delete, Disable
HookSysRunningC:\Program Files\Rising\Rav\HookSys.sys
Script: Quarantine, Delete, BC delete
TDI 
MEMSCAN
Driver: Unload, Delete, Disable
MEMSCANRunningC:\Program Files\Rising\Rav\MEMSCAN.sys
Script: Quarantine, Delete, BC delete
TDI 
RsNTGDI
Driver: Unload, Delete, Disable
RsNTGDIRunningC:\WINDOWS\system32\Drivers\RsNTGdi.sys
Script: Quarantine, Delete, BC delete
  
RSPPSYS
Driver: Unload, Delete, Disable
RSPPSYSRunningC:\Program Files\Rising\Rav\RSPPSYS.sys
Script: Quarantine, Delete, BC delete
TDIBaseTDI
SASDIFSV
Driver: Unload, Delete, Disable
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
  
SASENUM
Driver: Unload, Delete, Disable
SASENUMRunningC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
  
SASKUTIL
Driver: Unload, Delete, Disable
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\DOCUME~1\ke\LOCALS~1\Temp\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lbshndjh
Driver: Unload, Delete, Disable
lbshndjhNot startedC:\WINDOWS\\SystemRoot\System32\drivers\lbshndjh.sys
Script: Quarantine, Delete, BC delete
DMN 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PCIIde
Driver: Unload, Delete, Disable
PCIIdeNot startedPCIIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 185, recognized as trusted - 122

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IMSCMig
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ISUSPM Startup
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, !AVG Anti-Spyware
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {57B86673-276A-48B2-BAE7-C6DBB3020EB8}
C:\Program Files\MSN Messenger\MsnMsgr.Exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
C:\Program Files\Rising\Rav\RavTray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RavTray
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
C:\WINDOWS\Fonts\avwgjmn.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AA1247C1-53DA-FF43-ABD3-345F323A48DA}
C:\WINDOWS\Fonts\avwlkmn.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B960356A-458E-DE24-BD50-268F589A56AB}
C:\WINDOWS\Fonts\avzxnmn.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E859245F-345D-BC13-AC4F-145D47DA34FE}
C:\WINDOWS\Fonts\gjcsdyc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {4FA10261-B890-F432-A453-69F1023513F4}
C:\WINDOWS\Fonts\gjfhbyc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2D908534-AD45-920F-AC89-4024FA9D26D2}
C:\WINDOWS\Fonts\hookhelp.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E159854F-6971-3456-6941-10235412974E}
C:\WINDOWS\Fonts\kaqhmzy.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {D7D81718-1314-5200-2597-58790101807D}
C:\WINDOWS\Fonts\kawdjzy.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {A8907901-1416-3389-9981-37217856998A}
C:\WINDOWS\Fonts\kvdxmma.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {DC87A354-ABC3-DEDE-FF33-3213FD7447CD}
C:\WINDOWS\Fonts\kvdxsoma.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {FD561258-45F3-A451-F908-A258458226DF}
C:\WINDOWS\Fonts\okmhfzy.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6A57CAD1-412F-9547-713F-9641FA3FC7A6}
C:\WINDOWS\Fonts\rarjfpi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6598FF45-DA60-F48A-BC43-10AC47853D56}
C:\WINDOWS\Fonts\ratbupi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {67650011-3344-6688-4899-345FABCD1576}
C:\WINDOWS\Fonts\rsmykpm.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {BE32FA58-3453-FA2D-BC49-F340348ACCEB}
C:\WINDOWS\Fonts\swrcgzc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {878A7521-FA87-34AB-34C2-4893F3AD34C8}
C:\WINDOWS\Fonts\wsmsfzx.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {892FADFA-BCDE-ACDF-CDEF-21054865CBA8}
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {32CD708B-60A7-4C00-9377-D73EAA495F0F}
C:\WINDOWS\system32\gjgfbyc.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2D30695F-C54D-32AD-BC43-5810F301A1D2}
C:\WINDOWS\system32\raqjipi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {94783410-4F90-34A0-7820-3230ACD05F49}
C:\WINDOWS\system32\sidjjzy.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {A8847374-8323-FADC-B443-4732ABCD378A}
C:\WINDOWS\system32\wszjdzx.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {45679330-4034-9021-7012-909856721374}
ImpsSensor.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ImpsSensor, DLLName
autocheck autochk * bsmain
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager, BootExecute
Autoruns items detected - 90, recognized as trusted - 58

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
http://cn.widget.yahoo.com/index.htm?source=Cns
Script: Quarantine, Delete, BC delete
Extension module{6354ABE6-05F1-49ed-B850-E423120EC338}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{77BF5300-1474-4EC7-9980-D32B190E9B07}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{9A687CA6-D585-4947-9ED9-BE96071F5CD9}
Delete
Elements detected - 7, recognized as trusted - 3

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
加密上下文菜单{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
任务栏和「开始」菜单{0DF44EAA-FF21-4412-828E-260A8728E7F1}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
用户帐户{7A9D77BD-5403-11d2-8785-2E0420524153}
C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension Library版权所有? 1995-2003 Microsoft Corporation。保留所有权利。{00020D75-0000-0000-C000-000000000046}
C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/Find版权所有? 1995-2003 Microsoft Corporation。保留所有权利。{0006F045-0000-0000-C000-000000000046}
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
RISINGRising Shell Ext ModuleCopyright (c) 1998-2007 Rising Corp.{1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D}
C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
Script: Quarantine, Delete, BC delete
PowerWord ExplorerBarPowerWord Web Dictionary EngineCopyright 2002-2003{47B92A27-8252-420D-9630-378EF61434D7}
C:\Program Files\WinRAR\rarext.dll
Script: Quarantine, Delete, BC delete
WinRAR shell extension{B41DB860-8EE4-11D2-9906-E49FADC173CA}
C:\WINDOWS\system32\TudouUpload.dll
Script: Quarantine, Delete, BC delete
DllRegShlExt extensionDLL registration shell extensionCopyright 2000-2006 by Tudou.com{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
Elements detected - 183, recognized as trusted - 171

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINDOWS\system32\PRTdlink.dll
Script: Quarantine, Delete, BC delete
MonitorPRTmate
Elements detected - 11, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 3, recognized as trusted - 3
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 18, recognized as trusted - 18
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.02112[1024] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.08195[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.039150[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1027LISTENING0.0.0.051366[2004] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1979LISTENING0.0.0.016429[344] c:\program files\rising\rav\ravservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.039145[1368] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6059LISTENING0.0.0.039006[1492] c:\program files\rising\rav\ravmond.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1120] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1120] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[768] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1032LISTENING----[1164] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1056LISTENING----[2088] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1108LISTENING----[344] c:\program files\rising\rav\ravservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1368] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1368] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[768] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\WINDOWS\Downloaded Program Files\MMCShell.dll
Script: Quarantine, Delete, BC delete
{05C1004E-2596-48E5-8E26-39362985EEB9}
Delete
http://p3p.sogou.com/MMCShell.cab
C:\WINDOWS\system32\CMBEdit.dll
Script: Quarantine, Delete, BC delete
CMBHtmlControl ModuleCopyright 2004{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
Delete
https://www.sz1.cmbchina.com/download/CMBEdit.cab
C:\WINDOWS\Downloaded Program Files\safeInput4jh.dll
Script: Quarantine, Delete, BC delete
{A3CD7F74-93C9-4BC4-B892-CCDF1514F714}
Delete
https://pbank.95559.com.cn/personbank/ocx/safe.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000}
Delete
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
C:\WINDOWS\Downloaded Program Files\safeInput4jh.dll
Script: Quarantine, Delete, BC delete
{ECCBA956-80E5-11D3-9285-0080ADB811C9}
Delete
https://pbank.95559.com.cn/personbank/ocx/safe_bankcomm.cab
Elements detected - 8, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 25, recognized as trusted - 25

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 12, recognized as trusted - 12

HOSTS file

Hosts file record
127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
Script: Quarantine, Delete, BC delete
HandlerPowerWord Web Dictionary Engine (dic: PowerWord Asychronous Pluggable Protocol Handler)Copyright 2002-2003{C21F5C32-F57A-4A0D-8E0A-B672691C52D0}
Elements detected - 31, recognized as trusted - 30

Suspicious objects

FileDescriptionType
C:\Program Files\Rising\Rav\HOOKBASE.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


AVZ Antiviral Toolkit log; AVZ version is 4.29
Scanning started at 2008-01-17 15:59:22
Database loaded: signatures - 145510, NN profile(s) - 2, microprograms of healing - 55, signature database released 16.01.2008 18:04
Heuristic microprograms loaded: 371
SPV microprograms loaded: 9
Digital signatures of system files loaded: 68572
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=082680)
 Kernel ntoskrnl.exe found in memory at address 804D8000
   SDT = 8055A680
   KiST = 804E36A8 (284)
Function NtCreateKey (29) intercepted (8056F7A9->F8A9F80D), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtDeleteKey (3F) intercepted (80596136->F8A9F83F), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtDeleteValueKey (41) intercepted (80594AAC->F8A9F826), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtOpenProcess (7A) intercepted (80573D06->F8A9F7DB), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtSetValueKey (F7) intercepted (80574C8D->F8A9F7F4), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtTerminateProcess (101) intercepted (80585740->F998A812), hook C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Functions checked: 284, intercepted: 6, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning memory
 Number of processes found: 32
Analyzer: process under analysis is 3136 C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Loads RASAPI DLL - may use dialing ?
 Number of modules loaded: 323
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Automatic update settings blocked
Checking - complete
Files scanned: 356, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 2008-01-17 16:00:39
Time of scanning: 00:01:19
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list