Results of system analysis

AVZ 4.29 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\documents and settings\brian norris\local settings\application data\aijtzvo.exe
Script: Quarantine, Delete, BC delete, Terminate
1484  ??313.50 kb, rsAh,
created: 2/7/2008 11:55:30 AM,
modified: 2/7/2008 11:55:30 AM
Command line:
"C:\documents and settings\brian norris\local settings\application data\aijtzvo.exe" aijtzvo
c:\documents and settings\brian norris\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
836???????????? ??????? AVZ???????????? ??????? AVZ??715.50 kb, rsAh,
created: 12/13/2007 3:28:04 PM,
modified: 12/13/2007 3:28:04 PM
Command line:
"C:\Documents and Settings\Brian Norris\Desktop\AVZ4\avz4\avz.exe"
c:\winnt\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
1176Windows ExplorerCopyright (C) Microsoft Corp. 1981-1999??237.27 kb, rsAh,
created: 8/22/2002 8:06:45 PM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\Explorer.EXE
c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
1652FirefoxMozilla Corporation??7471.11 kb, rsAh,
created: 1/6/2008 11:47:03 AM,
modified: 11/28/2007 2:11:50 PM
Command line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
c:\winnt\system32\lexbces.exe
Script: Quarantine, Delete, BC delete, Terminate
552LexBce Service(C) 1993 - 2002 Lexmark International, Inc.??296.00 kb, rsAh,
created: 10/14/2002 2:03:18 PM,
modified: 10/14/2002 2:03:18 PM
Command line:
C:\WINNT\system32\LEXBCES.EXE
c:\winnt\system32\lexpps.exe
Script: Quarantine, Delete, BC delete, Terminate
616LEXPPS.EXE(C) 1993 - 2002 Lexmark International, Inc.??170.50 kb, rsAh,
created: 10/14/2002 2:00:42 PM,
modified: 10/14/2002 2:00:42 PM
Command line:
LEXPPS.EXE
c:\program files\lexmark x74-x75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete, Terminate
1456Lexmark X74-X75 Button Manager(C) 2002 Lexmark International, Inc.??56.00 kb, rsAh,
created: 10/14/2002 2:09:12 PM,
modified: 10/14/2002 2:09:12 PM
Command line:
"C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
c:\program files\lexmark x74-x75\lxbbbmon.exe
Script: Quarantine, Delete, BC delete, Terminate
1504Lexmark X74-X75 Button Monitor(C) 2002 Lexmark International, Inc.??48.00 kb, rsAh,
created: 10/14/2002 2:22:04 PM,
modified: 10/14/2002 2:22:04 PM
Command line:
"C:\Program Files\Lexmark X74-X75\lxbbbmon.exe"
c:\winnt\mixer.exe
Script: Quarantine, Delete, BC delete, Terminate
1432MixerCopyright (C) 1997-2001??1188.00 kb, rsAh,
created: 8/25/2002 1:31:57 PM,
modified: 11/15/2001 10:08:40 AM
Command line:
"C:\WINNT\Mixer.exe" /startup
c:\program files\common files\real\update_ob\realsched.exe
Script: Quarantine, Delete, BC delete, Terminate
1476RealNetworks SchedulerCopyright © RealNetworks, Inc. 1995-2004??176.04 kb, rsAh,
created: 12/9/2005 6:14:41 PM,
modified: 12/9/2005 6:14:41 PM
Command line:
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
c:\winnt\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
580Spooler SubSystem AppCopyright (C) Microsoft Corp. 1981-1999??44.27 kb, rsAh,
created: 4/21/2002 8:37:53 AM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\system32\spoolsv.exe
c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
1496SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1288.00 kb, rsAh,
created: 6/21/2007 2:06:28 PM,
modified: 6/21/2007 2:06:28 PM
Command line:
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
412Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\system32\svchost -k rpcss
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
632Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\System32\svchost.exe -k netsvcs
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
888Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\system32\svchost.exe -k wugroup
C:\WINNT\System
Script: Quarantine, Delete, BC delete, Terminate
8  ??0.00 kb, rsAh,
created: 4/21/2002 8:32:04 AM,
modified: 10/3/2005 9:15:12 PM
Command line:
c:\winnt\system32\zonelabs\vsmon.exe
Script: Quarantine, Delete, BC delete, Terminate
440TrueVector ServiceCopyright © 1998-2006, Zone Labs, LLC??73.80 kb, rsAh,
created: 4/18/2007 4:56:35 PM,
modified: 3/8/2007 11:01:58 PM
Command line:
C:\WINNT\system32\ZoneLabs\vsmon.exe -service
c:\winnt\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
204Windows NT Logon ApplicationCopyright (C) Microsoft Corp. 1981-1999??178.27 kb, rsAh,
created: 12/2/2004 1:10:03 PM,
modified: 8/24/2004 5:59:10 PM
Command line:
winlogon.exe
c:\winnt\system32\wbem\winmgmt.exe
Script: Quarantine, Delete, BC delete, Terminate
876Windows Management InstrumentationCopyright (C) Microsoft Corp. 1995-1999??192.08 kb, rsAh,
created: 8/22/2002 8:11:40 PM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\System32\WBEM\WinMgmt.exe
d:\apps\netgear\wlancfg4.exe
Script: Quarantine, Delete, BC delete, Terminate
1580  ??1140.50 kb, rsAh,
created: 12/27/2005 2:51:40 PM,
modified: 3/20/2003 7:13:18 PM
Command line:
c:\winnt\system32\wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
1752Windows Update Automatic Updates© Microsoft Corporation. All rights reserved.??51.84 kb, rsAh,
created: 5/22/2002 10:29:18 PM,
modified: 7/30/2007 6:19:16 PM
Command line:
"C:\WINNT\system32\wuauclt.exe"
c:\program files\zone labs\zonealarm\zlclient.exe
Script: Quarantine, Delete, BC delete, Terminate
1464ZoneAlarm ClientCopyright © 1998-2006, Zone Labs, LLC??897.73 kb, rsAh,
created: 4/18/2007 4:56:56 PM,
modified: 3/8/2007 11:02:00 PM
Command line:
"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
Detected:30, recognized as trusted 20
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\documents and settings\brian norris\local settings\application data\aijtzvo.exe
Script: Quarantine, Delete, BC delete
4194304  ??1484
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Script: Quarantine, Delete, BC delete
4194304RealNetworks SchedulerCopyright © RealNetworks, Inc. 1995-2004??1476
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete
4194304Lexmark X74-X75 Button Manager(C) 2002 Lexmark International, Inc.??1456
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
Script: Quarantine, Delete, BC delete
4194304Lexmark X74-X75 Button Monitor(C) 2002 Lexmark International, Inc.??1504
C:\Program Files\SUPERAntiSpyware\deupx.dll
Script: Quarantine, Delete, BC delete
268435456deupx.dllCopyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com--1496
C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
Script: Quarantine, Delete, BC delete
64552960SUPERAntiSpyware Context Menu Extension(C) Copyright 2006-2007 SUPERAdBlocker.com and SUPERAntiSpyware.com--1176
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
46333952ShellExecuteHook(c) Copyright 2004-2006 SuperAdBlocker.com --1176, 1496
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
268435456SUPERAntiSpyware WinLogon ProcessorCopyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com--204
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
4194304SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1496
C:\Program Files\Zone Labs\ZoneAlarm\cam.zap
Script: Quarantine, Delete, BC delete
22675456Anti-Virus Monitoring ModuleCopyright © 1998-2006, Zone Labs, LLC--1464
C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
Script: Quarantine, Delete, BC delete
1392508928IMsecure Plugin ModuleCopyright © 1998-2006, Zone Labs, LLC--1464
C:\WINNT\Mixer.exe
Script: Quarantine, Delete, BC delete
4194304MixerCopyright (C) 1997-2001??1432
C:\WINNT\system32\Avsmcpa.cpl
Script: Quarantine, Delete, BC delete
63045632  --1176
C:\WINNT\system32\CLBCATQ.DLL
Script: Quarantine, Delete, BC delete
2002386944 Copyright (C) Microsoft Corp. 1995-1999--1484, 836, 1176, 1652, 1432, 1476, 580, 1496, 412, 632, 888, 440, 204, 876, 1752, 1464
C:\WINNT\System32\cmnprop.dll
Script: Quarantine, Delete, BC delete
268435456CMAudio Property PageCopyright (C) C-Media Corp. 1998-2000--1432
C:\WINNT\system32\lex2kusb.dll
Script: Quarantine, Delete, BC delete
22609920LEX2KUSB DLL(C) 1993 - 2002 Lexmark International, Inc.--552
C:\WINNT\system32\LEXBCE.DLL
Script: Quarantine, Delete, BC delete
1660944384LexBce Client(C) 1993 - 2002 Lexmark International, Inc.--616, 580
C:\WINNT\system32\LEXBCES.EXE
Script: Quarantine, Delete, BC delete
4194304LexBce Service(C) 1993 - 2002 Lexmark International, Inc.??552
C:\WINNT\system32\LEXLMPM.DLL
Script: Quarantine, Delete, BC delete
268435456LEXLMPM DLL(C) 1993 - 2002 Lexmark International, Inc.--580
C:\WINNT\system32\lexp2p32.dll
Script: Quarantine, Delete, BC delete
268435456LEXP2P32 DLL(C) 1993 - 2002 Lexmark International, Inc.--552
C:\WINNT\system32\LEXPPS.EXE
Script: Quarantine, Delete, BC delete
4194304LEXPPS.EXE(C) 1993 - 2002 Lexmark International, Inc.??616
C:\WINNT\system32\LIBEAY32_0.9.6l.dll
Script: Quarantine, Delete, BC delete
65273856  --440, 1464
C:\WINNT\system32\LXBBpwr.dll
Script: Quarantine, Delete, BC delete
26279936Lexmark ColorFine POR MonitorCopyright © 2000 Lexmark International, Inc.--580
C:\WINNT\system32\PLOTMAN.CPL
Script: Quarantine, Delete, BC delete
1658716160Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.--1176
C:\WINNT\system32\spool\PRTPROCS\W32X86\LXBBPP5C.dll
Script: Quarantine, Delete, BC delete
22675456Lexmark X74-X75 Print ProcessorCopyright (C) Lexmark International 2002--580
C:\WINNT\system32\STYLEMAN.CPL
Script: Quarantine, Delete, BC delete
1645871104Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.--1176
C:\WINNT\system32\VSDATA.dll
Script: Quarantine, Delete, BC delete
67108864TrueVector Service DLLCopyright © 1998-2006, Zone Labs, LLC--440, 1464
c:\winnt\system32\wuauserv.dll
Script: Quarantine, Delete, BC delete
4456448Windows Update AutoUpdate Service© Microsoft Corporation. All rights reserved.--888
C:\WINNT\system32\zlcomm.dll
Script: Quarantine, Delete, BC delete
1382023168ZLCommCopyright © 1998-2006, Zone Labs, LLC--440, 1464
C:\WINNT\system32\ZLCommDB.dll
Script: Quarantine, Delete, BC delete
1384120320ZLCommDBCopyright © 1998-2006, Zone Labs, LLC--440, 1464
C:\WINNT\system32\ZoneLabs\imsecure.dll
Script: Quarantine, Delete, BC delete
1390411776TrueVector ServiceCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\srescan.dll
Script: Quarantine, Delete, BC delete
62455808srescanCopyright © 2006--440
C:\WINNT\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
Script: Quarantine, Delete, BC delete
65011712HttpBlocker plug-inCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
Script: Quarantine, Delete, BC delete
34537472ZoneAlarm IMsecure components for securing MSN/AIM-OSCAR/YIM protocolsCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\zlsre.dll
Script: Quarantine, Delete, BC delete
62062592zlsreCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\zpeng24.dll
Script: Quarantine, Delete, BC delete
503316480Python CoreCopyright © 2001-2004 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.--440, 1464
D:\APPS\CuteFTP\CuteShell.dll
Script: Quarantine, Delete, BC delete
72744960CuteShell DLLCopyright (C) 1999--1176
D:\Apps\NetGear\W32N50.DLL
Script: Quarantine, Delete, BC delete
268435456WinDis 32 API & Platform Compatibility DLLCopyright © 1997-2001 Printing Communications Assoc., Inc.--1580
D:\Apps\NetGear\wlancfg4.EXE
Script: Quarantine, Delete, BC delete
4194304  ??1580
Modules detected:327, recognized as trusted 288

Kernel space modules

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINNT\System32\Drivers\Cdr4_2K.SYS
Script: Quarantine, Delete, BC delete
ED06000000B000 (45056)CDR4 CD and DVD Burning Helper DriverCopyright (c) 1994-2005 Sonic Solutions
C:\WINNT\System32\Drivers\Cdralw2k.SYS
Script: Quarantine, Delete, BC delete
ED2E8000007000 (28672)CDRAL for Windows 2000 Kernel DriverCopyright (c) 1994-2005 Sonic Solutions
C:\WINNT\system32\drivers\cmaudio.sys
Script: Quarantine, Delete, BC delete
BFC99000058000 (360448)C-Media Audio WDM DriverCopyright (C) C-Media Inc. 1998-2001
C:\WINNT\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
BE8B4000016000 (90112)
C:\WINNT\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
ED640000001000 (4096)
C:\Program Files\Common Files\Network Associates\McShield\NaiFiltr.sys
Script: Quarantine, Delete, BC delete
ED388000006000 (24576)
NaiFsRec.sys
Script: Quarantine, Delete, BC delete
ED506000002000 (8192)
D:\Apps\NetGear\PCANDIS5.SYS
Script: Quarantine, Delete, BC delete
BC152000004000 (16384)PCAUSA NDIS 5.0 Protocol DriverCopyright © 1995-2001 Printing Communications Assoc., Inc. (PCAUSA)
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
ED3E0000007000 (28672)SASDIFSVCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
ED2B0000005000 (20480)SuperAntiSpyware(C) Copyright 2004-2006
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
ED1E000000C000 (49152)SASKUTIL.SYSCopyright (C) 2006
srescan.sys
Script: Quarantine, Delete, BC delete
BFEB1000014000 (81920)
C:\WINNT\system32\drivers\tmcomm.sys
Script: Quarantine, Delete, BC delete
BCEF1000012000 (73728)TrendMicro Common ModuleCopyright (C) 2005-2006 Trend Micro Incorporated. All rights reserved.
C:\WINNT\system32\Drivers\viaide.sys
Script: Quarantine, Delete, BC delete
ED504000002000 (8192)VIA PCI IDE Bus DriverCopyright (C) Microsoft Corp. 2000-2005
C:\WINNT\System32\Drivers\VIAPFD.SYS
Script: Quarantine, Delete, BC delete
ED60C000001000 (4096)VIA PFD driverCopyright (C) VIA Technologies, Inc. 2001-2005
Modules detected - 109, recognized as trusted - 94

Services

ServiceDescriptionStatusFileGroupDependencies
LexBceS
Service: Stop, Delete, Disable
LexBce ServerRunningC:\WINNT\system32\LEXBCES.EXE
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
IISADMIN
Service: Stop, Delete, Disable
IIS Admin ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 RPCSS
MSFTPSVC
Service: Stop, Delete, Disable
FTP Publishing ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
SMTPSVC
Service: Stop, Delete, Disable
Simple Mail Transport Protocol (SMTP)Not startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
W3SVC
Service: Stop, Delete, Disable
World Wide Web Publishing ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
WMDM PMSP Service
Service: Stop, Delete, Disable
WMDM PMSP ServiceNot startedC:\WINNT\System32\mspmspsv.exe
Script: Quarantine, Delete, BC delete
  
Detected - 63, recognized as trusted - 57

Drivers

ServiceDescriptionStatusFileGroupDependencies
Cdr4_2K
Driver: Unload, Delete, Disable
Cdr4_2KRunningC:\WINNT\system32\Drivers\Cdr4_2K.sys
Script: Quarantine, Delete, BC delete
Filter 
Cdralw2k
Driver: Unload, Delete, Disable
Cdralw2kRunningC:\WINNT\system32\Drivers\Cdralw2k.sys
Script: Quarantine, Delete, BC delete
Filter 
cmpci
Driver: Unload, Delete, Disable
C-Media PCI Audio Driver (WDM)RunningC:\WINNT\system32\drivers\cmaudio.sys
Script: Quarantine, Delete, BC delete
  
NaiFiltr
Driver: Unload, Delete, Disable
NaiFiltrRunningC:\Program Files\Common Files\Network Associates\McShield\NaiFiltr.sys
Script: Quarantine, Delete, BC delete
  
NaiFsRec
Driver: Unload, Delete, Disable
NaiFsRecRunningC:\WINNT\system32\drivers\NaiFsRec.sys
Script: Quarantine, Delete, BC delete
  
SASDIFSV
Driver: Unload, Delete, Disable
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
  
SASENUM
Driver: Unload, Delete, Disable
SASENUMRunningC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
  
SASKUTIL
Driver: Unload, Delete, Disable
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
  
srescan
Driver: Unload, Delete, Disable
srescanRunningC:\WINNT\system32\ZoneLabs\srescan.sys
Script: Quarantine, Delete, BC delete
  
tmcomm
Driver: Unload, Delete, Disable
tmcommRunningC:\WINNT\system32\drivers\tmcomm.sys
Script: Quarantine, Delete, BC delete
ExtendedBase 
viaide
Driver: Unload, Delete, Disable
viaideRunningC:\WINNT\System32\DRIVERS\viaide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
VIAPFD
Driver: Unload, Delete, Disable
VIAPFDRunningC:\WINNT\System32\Drivers\VIAPFD.SYS
Script: Quarantine, Delete, BC delete
Base 
USB_RNDIS_2K
Driver: Unload, Delete, Disable
Westell WireSpeed Dual Connect ModemNot startedC:\WINNT\system32\DRIVERS\usb8023k.sys
Script: Quarantine, Delete, BC delete
NDIS 
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic116x
Driver: Unload, Delete, Disable
aic116xNot startedaic116x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ami0nt
Driver: Unload, Delete, Disable
ami0ntNot startedami0nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
BusLogic
Driver: Unload, Delete, Disable
BusLogicNot startedBusLogic.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqarry2
Driver: Unload, Delete, Disable
cpqarry2Not startedcpqarry2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqfcalm
Driver: Unload, Delete, Disable
cpqfcalmNot startedcpqfcalm.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqfws2e
Driver: Unload, Delete, Disable
cpqfws2eNot startedcpqfws2e.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
deckzpsx
Driver: Unload, Delete, Disable
deckzpsxNot starteddeckzpsx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ENDETECT
Driver: Unload, Delete, Disable
ENDETECTNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\ENDETECT.SYS
Script: Quarantine, Delete, BC delete
  
Fd16_700
Driver: Unload, Delete, Disable
Fd16_700Not startedFd16_700.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
fireport
Driver: Unload, Delete, Disable
fireportNot startedfireport.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
flashpnt
Driver: Unload, Delete, Disable
flashpntNot startedflashpnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
IntelIde
Driver: Unload, Delete, Disable
IntelIdeNot startedIntelIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ipsraidn
Driver: Unload, Delete, Disable
ipsraidnNot startedipsraidn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
L2XPSR
Driver: Unload, Delete, Disable
L2XPSRNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\L2XPSR.SYS
Script: Quarantine, Delete, BC delete
  
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lp6nds35
Driver: Unload, Delete, Disable
lp6nds35Not startedlp6nds35.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ncrc710
Driver: Unload, Delete, Disable
Ncrc710Not startedNcrc710.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
NTSTPL1
Driver: Unload, Delete, Disable
NTSTPL1Not startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\NTSTPL1.SYS
Script: Quarantine, Delete, BC delete
  
NTSTPL2
Driver: Unload, Delete, Disable
NTSTPL2Not startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\NTSTPL2.SYS
Script: Quarantine, Delete, BC delete
  
OlCamudp
Driver: Unload, Delete, Disable
OLYMPUS Digital CameraNot startedC:\WINNT\system32\Drivers\olcamudp.sys
Script: Quarantine, Delete, BC delete
Base 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql2100
Driver: Unload, Delete, Disable
ql2100Not startedql2100.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sglfb
Driver: Unload, Delete, Disable
sglfbNot startedsglfb.sys
Script: Quarantine, Delete, BC delete
Video 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TAPBIND
Driver: Unload, Delete, Disable
TAPBINDNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\TAPBIND1.SYS
Script: Quarantine, Delete, BC delete
  
tga
Driver: Unload, Delete, Disable
tgaNot startedtga.sys
Script: Quarantine, Delete, BC delete
Video 
ultra66
Driver: Unload, Delete, Disable
ultra66Not startedultra66.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
UNDPX2A
Driver: Unload, Delete, Disable
UNDPX2ANot startedC:\WINNT\system32\drivers\UNDPX2A.SYS
Script: Quarantine, Delete, BC delete
  
viafilter
Driver: Unload, Delete, Disable
VIA USB FilterNot startedC:\WINNT\System32\Drivers\viausb.sys
Script: Quarantine, Delete, BC delete
extend base 
WLAN_USB
Driver: Unload, Delete, Disable
Wireless LAN USB DriverNot startedC:\WINNT\system32\DRIVERS\MA111nd5.sys
Script: Quarantine, Delete, BC delete
NDIS 
XIRLINK
Driver: Unload, Delete, Disable
Veo PC CameraNot startedC:\WINNT\system32\DRIVERS\ucdnt.sys
Script: Quarantine, Delete, BC delete
  
Detected - 180, recognized as trusted - 112

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TkBellExe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Lexmark X74-X75
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
C:\WINNT\Mixer.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, C-Media Mixer
C:\WINNT\System32\NeroCheck.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NeroCheck
D:\Apps\Microsoft Office\Office\OSA9.EXE
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk,
D:\Apps\NetGear\wlancfg.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk,
D:\apps\quicktime\qttask.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
c:\documents and settings\brian norris\local settings\application data\aijtzvo.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, aijtzvo
Autoruns items detected - 59, recognized as trusted - 48

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
D:\Apps\AOL\aim.exe
Script: Quarantine, Delete, BC delete
Extension moduleAOL Instant MessengerCopyright © 1996-2006 America Online, Inc.{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
Delete
Elements detected - 5, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
D:\APPS\CuteFTP\CuteShell.dll
Script: Quarantine, Delete, BC delete
CuteFTP Shell ExtensionCuteShell DLLCopyright (C) 1999{8f7261d0-d2b9-11d2-9909-00605205b24c}
C:\Program Files\Real\RealPlayer\rpshell.dll
Script: Quarantine, Delete, BC delete
Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsCopyright © RealNetworks, Inc. 2001-2004{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
Elements detected - 165, recognized as trusted - 160

Print system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINNT\system32\LEXLMPM.DLL
Script: Quarantine, Delete, BC delete
MonitorLexmark Network PortLEXLMPM DLL(C) 1993 - 2002 Lexmark International, Inc.
Elements detected - 9, recognized as trusted - 8

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusExe fileDescriptionGUID
Detected - 2, recognized as trusted - 2
Transport protocol providers (TSP, LSP)
ManufacturerExe fileDescription
Detected - 23, recognized as trusted - 23
Automatic SPI settings check results
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[0]   
139LISTENING0.0.0.018590[0]   
445LISTENING0.0.0.018613[0]   
1025LISTENING0.0.0.00[0]   
1026LISTENING0.0.0.00[0]   
1027LISTENING0.0.0.02205[0]   
3006LISTENING0.0.0.035031[0]   
3006CLOSE_WAIT87.242.90.13780[0]   
4301ESTABLISHED127.0.0.14302[0]   
4302LISTENING0.0.0.02272[0]   
4302ESTABLISHED127.0.0.14301[0]   
4303ESTABLISHED127.0.0.14304[0]   
4304LISTENING0.0.0.010353[0]   
4304ESTABLISHED127.0.0.14303[0]   
4377LISTENING0.0.0.018590[0]   
4377CLOSE_WAIT87.242.90.13580[0]   
4379LISTENING0.0.0.02076[0]   
4379CLOSE_WAIT89.108.66.15680[0]   
UDP ports
137LISTENING----[0]   
138LISTENING----[0]   
445LISTENING----[0]   
500LISTENING----[0]   
3001LISTENING----[0]   
3026LISTENING----[0]   

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
DirectAnimation Java Classes
Delete
file://C:\WINNT\Java\classes\dajava.cab
Microsoft XML Parser for Java
Delete
file://C:\WINNT\Java\classes\xmldso.cab
{31564D57-0000-0010-8000-00AA00389B71}
Delete
http://codecs.microsoft.com/codecs/i386/wmvax.cab
{9F1C11AA-197B-4942-BA54-47A8489BB47F}
Delete
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37487.6239583333
{CEBC955E-58AF-11D2-A30A-00A0C903492B}
Delete
http://windowsupdate.microsoft.com/R980/V31Controls/x86/nt5/en/actsetup.cab
C:\WINNT\Downloaded Program Files\dwa7W.dll
Script: Quarantine, Delete, BC delete
{E008A543-CEFB-4559-912F-C27C2B89F13B}
Delete
https://webmail.belk.com/belkmail04.belkinc.com/dwa7W.cab
Elements detected - 12, recognized as trusted - 6

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINNT\system32\PLOTMAN.CPL
Script: Quarantine, Delete, BC delete
Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.
C:\WINNT\system32\plugincpl131_10.cpl
Script: Quarantine, Delete, BC delete
JavaPluginCopyright ¨ 2000
C:\WINNT\system32\STYLEMAN.CPL
Script: Quarantine, Delete, BC delete
Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.
Elements detected - 25, recognized as trusted - 22

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 12, recognized as trusted - 12

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
Elements detected - 23, recognized as trusted - 23

Suspicious objects

FileDescriptionType
C:\WINNT\wt\webdriver\webdriver.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 006FD3AC 00000000 001D2F2B 00272AA7 712704)
C:\WINNT\wt\webdriver\wthost.exe
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 0060E2B4 00000000 0020D925 00212AD5 61440)
C:\WINNT\wt\webdriver\wthostctl.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 0069ECE8 00000000 001FEDBA 001FD6E2 57344)
C:\WINNT\wt\webdriver\wtmulti.jar
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 02F4D35A 07D6A835 0018AF0B 0007EBC1 18306)
C:\WINNT\wt\webdriver\wtwmplug.ax
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 008115DC 00000000 001B4030 001F13B0 53248)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent.b ( 0063DC41 00000000 001C177E 00205A85 36864)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 006FD3AC 00000000 001D2F2B 00272AA7 712704)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 0060E2B4 00000000 0020D925 00212AD5 61440)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 0069ECE8 00000000 001FEDBA 001FD6E2 57344)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.jar
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 02F4D35A 07D6A835 0018AF0B 0007EBC1 18306)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 0074B40A 00000000 001CF561 00201841 53248)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ax
Script: Quarantine, Delete, BC delete
Suspicion by File scannerSuspicion for Spy.WildTangent ( 008115DC 00000000 001B4030 001F13B0 53248)
C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for Spy.WindTangent
C:\WINNT\wt\webdriver\4.1.1\webdriver.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for Spy.WindTangent


AVZ Antiviral Toolkit log; AVZ version is 4.29
Scanning started at 2/10/2008 9:05:05 AM
Database loaded: signatures - 149090, NN profile(s) - 2, microprograms of healing - 55, signature database released 09.02.2008 22:28
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 68697
Heuristic analyzer mode: Medium heuristics level
Healing mode: enabled
Windows version: 5.0.2195, Service Pack 3 ; AVZ is launched with administrator rights
System Recovery: enabled
1. Searching for Rootkits and programs intercepting API functions
 >>>> Probable masking of an executable file's name 1496 superantispyware.exe, real name - SUPERAntiSpywar
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=080820)
 Kernel ntoskrnl.exe found in memory at address 80400000
   SDT = 80480820
   KiST = 80472128 (248)
Functions checked: 248, intercepted: 0, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: the extended monitoring driver (AVZPM) is not installed
2. Scanning memory
 Number of processes found: 29
 Number of modules loaded: 302
Memory checking - complete
3. Scanning disks
C:\WINNT\wt\webdriver\webdriver.dll >>> suspicion for Spy.WildTangent ( 006FD3AC 00000000 001D2F2B 00272AA7 712704)
C:\WINNT\wt\webdriver\wthost.exe >>> suspicion for Spy.WildTangent ( 0060E2B4 00000000 0020D925 00212AD5 61440)
C:\WINNT\wt\webdriver\wthostctl.dll >>> suspicion for Spy.WildTangent ( 0069ECE8 00000000 001FEDBA 001FD6E2 57344)
C:\WINNT\wt\webdriver\wtmulti.jar >>> suspicion for Spy.WildTangent ( 02F4D35A 07D6A835 0018AF0B 0007EBC1 18306)
C:\WINNT\wt\webdriver\wtwmplug.ax >>> suspicion for Spy.WildTangent ( 008115DC 00000000 001B4030 001F13B0 53248)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll >>> suspicion for Spy.WildTangent.b ( 0063DC41 00000000 001C177E 00205A85 36864)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll >>> suspicion for Spy.WildTangent ( 006FD3AC 00000000 001D2F2B 00272AA7 712704)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe >>> suspicion for Spy.WildTangent ( 0060E2B4 00000000 0020D925 00212AD5 61440)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll >>> suspicion for Spy.WildTangent ( 0069ECE8 00000000 001FEDBA 001FD6E2 57344)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.jar >>> suspicion for Spy.WildTangent ( 02F4D35A 07D6A835 0018AF0B 0007EBC1 18306)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll >>> suspicion for Spy.WildTangent ( 0074B40A 00000000 001CF561 00201841 53248)
C:\WINNT\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ax >>> suspicion for Spy.WildTangent ( 008115DC 00000000 001B4030 001F13B0 53248)
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
>>> C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll HSC: suspicion for Spy.WindTangent
>>> C:\WINNT\wt\webdriver\4.1.1\webdriver.dll HSC: suspicion for Spy.WindTangent
Checking complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed RemoteRegistry (Remote Registry Service)
>> Services: potentially dangerous service allowed TlntSvr (Telnet)
>> Services: potentially dangerous service allowed Messenger (Messenger)
>> Services: potentially dangerous service allowed Alerter (Alerter)
>> Services: potentially dangerous service allowed Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed mnmsrvc (NetMeeting Remote Desktop Sharing)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements
>> Security: terminal connections to the PC are allowed
>> Security: sending Remote Assistant queries is enabled
Checking complete
9. Troubleshooting wizard
 >>  Internet Explorer - automatic queries of ActiveX operating elements are allowed
Checking complete
Files scanned: 81883, extracted from archives: 46922, malicious programs found 0, suspicions - 12
Scanning finished at 2/10/2008 9:17:51 AM
Time of scanning: 00:12:49
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
Creating archive of files from Quarantine
Creating archive of files from Quarantine - complete
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list