Results of system analysis

AVZ 4.29 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete, Terminate
2836AVG Anti-SpywareCopyright ? 2007 GRISOFT s.r.o.??6573.55 kb, rsAh,
created: 2007-06-11 17:25:42,
modified: 2007-06-11 17:25:42
Command line:
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
c:\program files\rising\rav\ccenter.exe
Script: Quarantine, Delete, BC delete, Terminate
1340CCenterCopyright Rising 2002??108.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2006-10-10 10:42:43
Command line:
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
2032Windows Explorer(C) Microsoft Corporation. All rights reserved.??955.00 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2007-06-13 21:21:55
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete, Terminate
276AVG Anti-Spyware guardCopyright ? 2007 GRISOFT s.r.o.??305.55 kb, rsAh,
created: 2007-05-30 20:31:10,
modified: 2007-05-30 20:31:10
Command line:
c:\program files\rising\rav\ravmond.exe
Script: Quarantine, Delete, BC delete, Terminate
1372RavMondCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited??272.00 kb, rsAh,
created: 2006-10-10 10:41:01,
modified: 2007-01-12 11:01:01
Command line:
c:\program files\rising\rav\ravservice.exe
Script: Quarantine, Delete, BC delete, Terminate
360 Copyright (C) 2005??1256.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2007-05-21 08:31:25
Command line:
c:\program files\rising\rav\ravstub.exe
Script: Quarantine, Delete, BC delete, Terminate
1916Rising RavStubCopyright (c) 1998-2005 Rising Corp.??88.00 kb, rsAh,
created: 2006-10-10 10:41:01,
modified: 2007-01-12 11:01:02
Command line:
c:\program files\rising\rav\ravtray.exe
Script: Quarantine, Delete, BC delete, Terminate
2624RavNet TrayCopyright (C) 2003??856.00 kb, rsAh,
created: 2006-10-10 10:40:55,
modified: 2007-03-20 08:31:02
Command line:
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
1824Spooler SubSystem App? Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2005-06-11 07:53:32
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
2928SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1280.00 kb, rsAh,
created: 2007-02-27 11:39:26,
modified: 2007-02-27 11:39:26
Command line:
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
708Windows NT Logon Application(C) Microsoft Corporation. All rights reserved.??476.00 kb, rsAh,
created: 2004-08-08 11:33:53,
modified: 2004-08-08 11:33:53
Command line:
winlogon.exe
Detected:33, recognized as trusted 25
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS
Script: Quarantine, Delete, BC delete
38731776PDF Shell ExtensionCopyright 2000-2004 Adobe Systems, Inc.--2032
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS
Script: Quarantine, Delete, BC delete
268435456  --1824
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete
4194304AVG Anti-SpywareCopyright ? 2007 GRISOFT s.r.o.??2836
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
Script: Quarantine, Delete, BC delete
268435456AVG Anti-Spyware Scan EngineCopyright ? 2007 GRISOFT s.r.o.--2836, 276
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete
4194304AVG Anti-Spyware guardCopyright ? 2007 GRISOFT s.r.o.??276
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
Script: Quarantine, Delete, BC delete
38404096AVG Anti-Spyware shellexecutehookCopyright ? 2007 GRISOFT s.r.o.--2032, 2928
C:\Program Files\Rising\Rav\BDEngine.dll
Script: Quarantine, Delete, BC delete
17629184BDEngine Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--2624
C:\Program Files\Rising\Rav\BDEX.dll
Script: Quarantine, Delete, BC delete
17825792BDEngine 动态链接库Copyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--2624
C:\Program Files\Rising\Rav\BDLib.dll
Script: Quarantine, Delete, BC delete
18022400BDLibCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--2624
C:\Program Files\Rising\Rav\BWList.dll
Script: Quarantine, Delete, BC delete
268435456BWList DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1372
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
Script: Quarantine, Delete, BC delete
4194304CCenterCopyright Rising 2002??1340
C:\Program Files\Rising\Rav\CfgDll.dll
Script: Quarantine, Delete, BC delete
147587072CfgDllCopyright ? 2004 - 2006--1372
C:\Program Files\Rising\Rav\DLCenter.dll
Script: Quarantine, Delete, BC delete
268435456DLCenter DLLCopyright(C) 2005--360
C:\Program Files\Rising\Rav\engine.dll
Script: Quarantine, Delete, BC delete
161415168engineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\expscan.dll
Script: Quarantine, Delete, BC delete
158334976ExpScan.dllCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ExtFile.dll
Script: Quarantine, Delete, BC delete
180355072extFile Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\HookCont.dll
Script: Quarantine, Delete, BC delete
160628736HookCont Dynamic Link LibraryCopyright (C) 2007--1372
C:\Program Files\Rising\Rav\HOOKSYS.dll
Script: Quarantine, Delete, BC delete
150536192HOOKSYS Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\HookWeb.dll
Script: Quarantine, Delete, BC delete
156958720HookWebCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\libload.dll
Script: Quarantine, Delete, BC delete
319815680LibLoadCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372, 2624
C:\Program Files\Rising\Rav\MemMon.dll
Script: Quarantine, Delete, BC delete
158138368MemMonCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\mPorts.dll
Script: Quarantine, Delete, BC delete
158466048mPorts.dllCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\NvFile.dll
Script: Quarantine, Delete, BC delete
181338112NVFileCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\PostTrt.dll
Script: Quarantine, Delete, BC delete
170459136PostTrtCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\psapi.dll
Script: Quarantine, Delete, BC delete
1931149312Process Status HelperCopyright (C) Microsoft Corp. 1981-1996--1372
C:\Program Files\Rising\Rav\Ravmond.exe
Script: Quarantine, Delete, BC delete
4194304RavMondCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited??1372
C:\Program Files\Rising\Rav\RavService.exe
Script: Quarantine, Delete, BC delete
4194304 Copyright (C) 2005??360
C:\Program Files\Rising\Rav\RavStub.exe
Script: Quarantine, Delete, BC delete
4194304Rising RavStubCopyright (c) 1998-2005 Rising Corp.??1916
C:\Program Files\Rising\Rav\RavTray.exe
Script: Quarantine, Delete, BC delete
4194304RavNet TrayCopyright (C) 2003??2624
C:\Program Files\Rising\Rav\RavTray936.dll
Script: Quarantine, Delete, BC delete
11993088瑞星杀毒软件网络版托盘程序版权所有 (C) 2003--2624
C:\Program Files\Rising\Rav\RavUILib.dll
Script: Quarantine, Delete, BC delete
268435456RavUILib DLLAll Rights Reserved--2624
C:\Program Files\Rising\Rav\regmon.dll
Script: Quarantine, Delete, BC delete
154533888regmonCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\rfwctrl.dll
Script: Quarantine, Delete, BC delete
11993088RfwCtrl DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\RSAPPMGR.DLL
Script: Quarantine, Delete, BC delete
13238272Rising Application ManagerCopyright ? 2004 - 2005--1372
C:\Program Files\Rising\Rav\RSCOMMON.DLL
Script: Quarantine, Delete, BC delete
594542592Rising Common Function Dynamic Link LibraryCopyright (c) 1998-2007 Rising Corp.--1372, 1916
C:\Program Files\Rising\Rav\RsCommX.dll
Script: Quarantine, Delete, BC delete
7602176RsCommXCopyright ? 2002--1372, 360, 1916, 2624
C:\Program Files\Rising\Rav\RsLog.dll
Script: Quarantine, Delete, BC delete
150470656RsLog DLLCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\RsPPsys.dll
Script: Quarantine, Delete, BC delete
12058624RSPPSYS Dynamic Link LibraryCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\RsVM.dll
Script: Quarantine, Delete, BC delete
204013568RSVM Dynamic Link LibraryCopyright (C) 2006--1372
C:\Program Files\Rising\Rav\ScanEx.dll
Script: Quarantine, Delete, BC delete
181534720ScanEXCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ScanExec.dll
Script: Quarantine, Delete, BC delete
329973760ScanExecCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ScanMac.dll
Script: Quarantine, Delete, BC delete
330235904ScanMacCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\Scanner.dll
Script: Quarantine, Delete, BC delete
151781376RsScannerCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ScanNet.dll
Script: Quarantine, Delete, BC delete
178126848ScanNetCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ScanPack.dll
Script: Quarantine, Delete, BC delete
186908672Unpack EngineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\ScanSct.dll
Script: Quarantine, Delete, BC delete
186253312ScanSctCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\SpamEng.dll
Script: Quarantine, Delete, BC delete
160759808SpamEng Dynamic Link LibraryCopyright (C) 2004--1372
C:\Program Files\Rising\Rav\UnExe.dll
Script: Quarantine, Delete, BC delete
182910976UnExeCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\Uroutine.dll
Script: Quarantine, Delete, BC delete
269680640Unpack RoutineCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\Uscript.dll
Script: Quarantine, Delete, BC delete
181862400Unpack ScriptCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\Rising\Rav\VirusLib.dll
Script: Quarantine, Delete, BC delete
153223168VirusLibCopyright(c) 1998-2006 Beijing Rising Technology Corporation Limited--1372
C:\Program Files\SUPERAntiSpyware\deupx.dll
Script: Quarantine, Delete, BC delete
268435456deupx.dllCopyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com--2928
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
40435712ShellExecuteHook(c) Copyright 2004-2006 SuperAdBlocker.com --2032, 2928
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
268435456SUPERAntiSpyware WinLogon ProcessorCopyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com--708
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
4194304SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??2928
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
38207488Rising Shell Ext ModuleCopyright (c) 1998-2007 Rising Corp.--2032, 2928
Modules detected:345, recognized as trusted 289

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys
Script: Quarantine, Delete, BC delete
F98D2000001000 (4096)AVG7 Clean DriverCopyright ? 2006 GRISOFT, s.r.o.
C:\WINDOWS\system32\drivers\basetdi.sys
Script: Quarantine, Delete, BC delete
F853B000003000 (12288)basetdiCopyright(c) 1998-2007 Beijing Rising Technology Corporation Limited
C:\WINDOWS\System32\Drivers\DgiVecp.sys
Script: Quarantine, Delete, BC delete
F8AE700000F000 (61440)Windows 2k,XP IEEE-1284 parallel class driver for ECP, Byte, and Nibble modesCopyright ? 1998, 1999 by Samsung Electronics Co., Ltd.
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
F8A77000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F97A6000002000 (8192)
C:\Program Files\Rising\Rav\ExpScan.sys
Script: Quarantine, Delete, BC delete
F846E000015000 (86016)ExpScan.sysCopyright (C) 2004 Rising
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
F98DD000001000 (4096)
C:\Program Files\Rising\Rav\HOOKAPI.SYS
Script: Quarantine, Delete, BC delete
F85DF00000D000 (53248)HOOKAPI DriverCopyright (C) RFW Corp. 2000-2002
C:\Program Files\Rising\Rav\HOOKBASE.sys
Script: Quarantine, Delete, BC delete
F8AB7000009000 (36864)HookBaseCopyright (C) 2004
C:\Program Files\Rising\Rav\HOOKCONT.sys
Script: Quarantine, Delete, BC delete
F97CE000002000 (8192)HookContCopyright (C) 2007
C:\Program Files\Rising\Rav\HookReg.sys
Script: Quarantine, Delete, BC delete
F8563000004000 (16384)版权所有 (@) 2003
C:\Program Files\Rising\Rav\HookSys.sys
Script: Quarantine, Delete, BC delete
F84AB000026000 (155648)HooksysCopyright (C) 2007
C:\Program Files\Rising\Rav\MEMSCAN.sys
Script: Quarantine, Delete, BC delete
F854B000004000 (16384)MemScan DriverRising Corp. All rights reserved.
C:\WINDOWS\system32\Drivers\RsNTGdi.sys
Script: Quarantine, Delete, BC delete
F9829000001000 (4096)RsNTGDICopyright (c) 1998-2007 Rising Corp.
C:\Program Files\Rising\Rav\RSPPSYS.sys
Script: Quarantine, Delete, BC delete
F8533000003000 (12288)RSPPSYSCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
F9620000007000 (28672)SASDIFSVCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
F95F8000005000 (20480)SuperAntiSpyware(C) Copyright 2004-2006
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
F937000000C000 (49152)SASKUTIL.SYSCopyright (C) 2006
Modules detected - 135, recognized as trusted - 117

Services

ServiceDescriptionStatusFileGroupDependencies
AVG Anti-Spyware Guard
Service: Stop, Delete, Disable
AVG Anti-Spyware GuardRunningC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Script: Quarantine, Delete, BC delete
  
RavService
Service: Stop, Delete, Disable
RavServiceRunningC:\Program Files\Rising\Rav\RavService.exe
Script: Quarantine, Delete, BC delete
  
RsCCenter
Service: Stop, Delete, Disable
Rising Process Communication CenterRunningC:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
Script: Quarantine, Delete, BC delete
  
RsRavMon
Service: Stop, Delete, Disable
RsRavMon ServiceRunningC:\Program Files\Rising\Rav\Ravmond.exe
Script: Quarantine, Delete, BC delete
TDIRsCCenter
Adobe LM Service
Service: Stop, Delete, Disable
Adobe LM ServiceNot startedC:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Script: Quarantine, Delete, BC delete
  
Detected - 87, recognized as trusted - 82

Drivers

ServiceDescriptionStatusFileGroupDependencies
AVG Anti-Spyware Driver
Driver: Unload, Delete, Disable
AVG Anti-Spyware DriverRunningC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
  
AvgAsCln
Driver: Unload, Delete, Disable
AVG Anti-Spyware Clean DriverRunningC:\WINDOWS\system32\DRIVERS\AvgAsCln.sys
Script: Quarantine, Delete, BC delete
Base 
BaseTDI
Driver: Unload, Delete, Disable
BaseTDIRunningC:\WINDOWS\system32\drivers\basetdi.sys
Script: Quarantine, Delete, BC delete
 Tcpip
DgiVecp
Driver: Unload, Delete, Disable
Team MFP Comm DriverRunningC:\WINDOWS\system32\Drivers\DgiVecp.sys
Script: Quarantine, Delete, BC delete
 +Parallel Arbitrator
ExpScaner
Driver: Unload, Delete, Disable
ExpScanerRunningC:\Program Files\Rising\Rav\ExpScan.sys
Script: Quarantine, Delete, BC delete
TDIBaseTDI
HookCont
Driver: Unload, Delete, Disable
HookContRunningC:\Program Files\Rising\Rav\HOOKCONT.sys
Script: Quarantine, Delete, BC delete
TDI 
HookReg
Driver: Unload, Delete, Disable
HookRegRunningC:\Program Files\Rising\Rav\HookReg.sys
Script: Quarantine, Delete, BC delete
TDI 
HookSys
Driver: Unload, Delete, Disable
HookSysRunningC:\Program Files\Rising\Rav\HookSys.sys
Script: Quarantine, Delete, BC delete
TDI 
MEMSCAN
Driver: Unload, Delete, Disable
MEMSCANRunningC:\Program Files\Rising\Rav\MEMSCAN.sys
Script: Quarantine, Delete, BC delete
TDI 
RsNTGDI
Driver: Unload, Delete, Disable
RsNTGDIRunningC:\WINDOWS\system32\Drivers\RsNTGdi.sys
Script: Quarantine, Delete, BC delete
  
RSPPSYS
Driver: Unload, Delete, Disable
RSPPSYSRunningC:\Program Files\Rising\Rav\RSPPSYS.sys
Script: Quarantine, Delete, BC delete
TDIBaseTDI
SASDIFSV
Driver: Unload, Delete, Disable
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
  
SASENUM
Driver: Unload, Delete, Disable
SASENUMRunningC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
  
SASKUTIL
Driver: Unload, Delete, Disable
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\DOCUME~1\ke\LOCALS~1\Temp\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lbshndjh
Driver: Unload, Delete, Disable
lbshndjhNot startedC:\WINDOWS\\SystemRoot\System32\drivers\lbshndjh.sys
Script: Quarantine, Delete, BC delete
DMN 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PCIIde
Driver: Unload, Delete, Disable
PCIIdeNot startedPCIIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 185, recognized as trusted - 122

Autoruns

File nameStatusStartup methodDescription
C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, IMSCMig
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ISUSPM Startup
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, !AVG Anti-Spyware
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {57B86673-276A-48B2-BAE7-C6DBB3020EB8}
C:\Program Files\MSN Messenger\MsnMsgr.Exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, msnmsgr
C:\Program Files\Rising\Rav\RavTray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RavTray
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
C:\WINDOWS\Fonts\avwgjmn.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {AA1247C1-53DA-FF43-ABD3-345F323A48DA}
C:\WINDOWS\Fonts\ratbupi.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {67650011-3344-6688-4899-345FABCD1576}
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {32CD708B-60A7-4C00-9377-D73EAA495F0F}
autocheck autochk * bsmain
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager, BootExecute
Autoruns items detected - 71, recognized as trusted - 58

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
http://cn.widget.yahoo.com/index.htm?source=Cns
Script: Quarantine, Delete, BC delete
Extension module{6354ABE6-05F1-49ed-B850-E423120EC338}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{77BF5300-1474-4EC7-9980-D32B190E9B07}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
Script: Quarantine, Delete, BC delete
Extension moduleSkype add-on for IE(c) Skype Technologies. All rights reserved.{9A687CA6-D585-4947-9ED9-BE96071F5CD9}
Delete
Elements detected - 7, recognized as trusted - 3

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
加密上下文菜单{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
任务栏和「开始」菜单{0DF44EAA-FF21-4412-828E-260A8728E7F1}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
用户帐户{7A9D77BD-5403-11d2-8785-2E0420524153}
C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension Library版权所有? 1995-2003 Microsoft Corporation。保留所有权利。{00020D75-0000-0000-C000-000000000046}
C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
Script: Quarantine, Delete, BC delete
Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/Find版权所有? 1995-2003 Microsoft Corporation。保留所有权利。{0006F045-0000-0000-C000-000000000046}
C:\WINDOWS\system32\RavExt.dll
Script: Quarantine, Delete, BC delete
RISINGRising Shell Ext ModuleCopyright (c) 1998-2007 Rising Corp.{1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D}
C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
Script: Quarantine, Delete, BC delete
PowerWord ExplorerBarPowerWord Web Dictionary EngineCopyright 2002-2003{47B92A27-8252-420D-9630-378EF61434D7}
C:\Program Files\WinRAR\rarext.dll
Script: Quarantine, Delete, BC delete
WinRAR shell extension{B41DB860-8EE4-11D2-9906-E49FADC173CA}
C:\WINDOWS\system32\TudouUpload.dll
Script: Quarantine, Delete, BC delete
DllRegShlExt extensionDLL registration shell extensionCopyright 2000-2006 by Tudou.com{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
Elements detected - 183, recognized as trusted - 171

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
PRTdlink.dll
Script: Quarantine, Delete, BC delete
MonitorPRTmate
Elements detected - 11, recognized as trusted - 10

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 3, recognized as trusted - 3
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 18, recognized as trusted - 18
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.02288[1004] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.039166[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.043094[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1027LISTENING0.0.0.039070[184] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1979LISTENING0.0.0.037016[360] c:\program files\rising\rav\ravservice.exe
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.053418[1280] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6059LISTENING0.0.0.041202[1372] c:\program files\rising\rav\ravmond.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1096] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1096] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[764] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1044LISTENING----[1144] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1049LISTENING----[2588] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1280] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[1280] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[764] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
C:\WINDOWS\Downloaded Program Files\safeInput4jh.dll
Script: Quarantine, Delete, BC delete
{A3CD7F74-93C9-4BC4-B892-CCDF1514F714}
Delete
https://pbank.95559.com.cn/personbank/ocx/safe.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000}
Delete
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
C:\WINDOWS\Downloaded Program Files\safeInput4jh.dll
Script: Quarantine, Delete, BC delete
{ECCBA956-80E5-11D3-9285-0080ADB811C9}
Delete
https://pbank.95559.com.cn/personbank/ocx/safe_bankcomm.cab
Elements detected - 6, recognized as trusted - 3

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 25, recognized as trusted - 25

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 12, recognized as trusted - 12

HOSTS file

Hosts file record
127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
Script: Quarantine, Delete, BC delete
HandlerPowerWord Web Dictionary Engine (dic: PowerWord Asychronous Pluggable Protocol Handler)Copyright 2002-2003{C21F5C32-F57A-4A0D-8E0A-B672691C52D0}
Elements detected - 31, recognized as trusted - 30

Suspicious objects

FileDescriptionType
C:\Program Files\Rising\Rav\HOOKBASE.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook


AVZ Antiviral Toolkit log; AVZ version is 4.29
Scanning started at 2008-01-18 16:36:25
Database loaded: signatures - 145510, NN profile(s) - 2, microprograms of healing - 55, signature database released 16.01.2008 18:04
Heuristic microprograms loaded: 371
SPV microprograms loaded: 9
Digital signatures of system files loaded: 68572
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=082680)
 Kernel ntoskrnl.exe found in memory at address 804D8000
   SDT = 8055A680
   KiST = 804E36A8 (284)
Function NtCreateKey (29) intercepted (8056F7A9->F8AB780D), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtDeleteKey (3F) intercepted (80596136->F8AB783F), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtDeleteValueKey (41) intercepted (80594AAC->F8AB7826), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtOpenProcess (7A) intercepted (80573D06->F8AB77DB), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtSetValueKey (F7) intercepted (80574C8D->F8AB77F4), hook C:\Program Files\Rising\Rav\HOOKBASE.sys
Function NtTerminateProcess (101) intercepted (80585740->F98DD812), hook C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Functions checked: 284, intercepted: 6, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning memory
 Number of processes found: 32
 Number of modules loaded: 336
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Automatic update settings blocked
Checking - complete
Files scanned: 369, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 2008-01-18 16:37:49
Time of scanning: 00:01:27
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list