AVZ 4.29 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\documents and settings\brian norris\desktop\avz4\avz4\avz.exe | Script: Quarantine, Delete, BC delete, Terminate 1128 | ???????????? ??????? AVZ | ???????????? ??????? AVZ | ?? | 715.50 kb, rsAh, | created: 12/13/2007 3:28:04 PM, modified: 12/13/2007 3:28:04 PM Command line: "C:\Documents and Settings\Brian Norris\Desktop\AVZ4\avz4\avz.exe" c:\winnt\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 1168 | Windows Explorer | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 237.27 kb, rsAh, | created: 8/22/2002 8:06:45 PM, modified: 7/22/2002 2:05:04 PM Command line: C:\WINNT\Explorer.EXE c:\program files\mozilla firefox\firefox.exe | Script: Quarantine, Delete, BC delete, Terminate 1164 | Firefox | Mozilla Corporation | ?? | 7471.11 kb, rsAh, | created: 1/6/2008 11:47:03 AM, modified: 11/28/2007 2:11:50 PM Command line: "C:\Program Files\Mozilla Firefox\firefox.exe" c:\winnt\system32\lexbces.exe | Script: Quarantine, Delete, BC delete, Terminate 552 | LexBce Service | (C) 1993 - 2002 Lexmark International, Inc. | ?? | 296.00 kb, rsAh, | created: 10/14/2002 2:03:18 PM, modified: 10/14/2002 2:03:18 PM Command line: C:\WINNT\system32\LEXBCES.EXE c:\winnt\system32\lexpps.exe | Script: Quarantine, Delete, BC delete, Terminate 628 | LEXPPS.EXE | (C) 1993 - 2002 Lexmark International, Inc. | ?? | 170.50 kb, rsAh, | created: 10/14/2002 2:00:42 PM, modified: 10/14/2002 2:00:42 PM Command line: LEXPPS.EXE c:\program files\lexmark x74-x75\lxbbbmgr.exe | Script: Quarantine, Delete, BC delete, Terminate 1296 | Lexmark X74-X75 Button Manager | (C) 2002 Lexmark International, Inc. | ?? | 56.00 kb, rsAh, | created: 10/14/2002 2:09:12 PM, modified: 10/14/2002 2:09:12 PM Command line: "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" c:\program files\lexmark x74-x75\lxbbbmon.exe | Script: Quarantine, Delete, BC delete, Terminate 1316 | Lexmark X74-X75 Button Monitor | (C) 2002 Lexmark International, Inc. | ?? | 48.00 kb, rsAh, | created: 10/14/2002 2:22:04 PM, modified: 10/14/2002 2:22:04 PM Command line: "C:\Program Files\Lexmark X74-X75\lxbbbmon.exe" c:\winnt\mixer.exe | Script: Quarantine, Delete, BC delete, Terminate 1252 | Mixer | Copyright (C) 1997-2001 | ?? | 1188.00 kb, rsAh, | created: 8/25/2002 1:31:57 PM, modified: 11/15/2001 10:08:40 AM Command line: "C:\WINNT\Mixer.exe" /startup c:\program files\common files\real\update_ob\realsched.exe | Script: Quarantine, Delete, BC delete, Terminate 1324 | RealNetworks Scheduler | Copyright © RealNetworks, Inc. 1995-2004 | ?? | 176.04 kb, rsAh, | created: 12/9/2005 6:14:41 PM, modified: 12/9/2005 6:14:41 PM Command line: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot c:\winnt\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 580 | Spooler SubSystem App | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 44.27 kb, rsAh, | created: 4/21/2002 8:37:53 AM, modified: 7/22/2002 2:05:04 PM Command line: C:\WINNT\system32\spoolsv.exe c:\program files\superantispyware\superantispyware.exe | Script: Quarantine, Delete, BC delete, Terminate 1340 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1288.00 kb, rsAh, | created: 6/21/2007 2:06:28 PM, modified: 6/21/2007 2:06:28 PM Command line: "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" c:\winnt\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 612 | Generic Host Process for Win32 Services | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 7.77 kb, rsAh, | created: 12/7/1999 7:00:00 AM, modified: 12/7/1999 7:00:00 AM Command line: C:\WINNT\System32\svchost.exe -k netsvcs c:\winnt\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 412 | Generic Host Process for Win32 Services | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 7.77 kb, rsAh, | created: 12/7/1999 7:00:00 AM, modified: 12/7/1999 7:00:00 AM Command line: C:\WINNT\system32\svchost -k rpcss c:\winnt\system32\svchost.exe | Script: Quarantine, Delete, BC delete, Terminate 888 | Generic Host Process for Win32 Services | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 7.77 kb, rsAh, | created: 12/7/1999 7:00:00 AM, modified: 12/7/1999 7:00:00 AM Command line: C:\WINNT\system32\svchost.exe -k wugroup C:\WINNT\System | Script: Quarantine, Delete, BC delete, Terminate 8 | | | ?? | 0.00 kb, rsAh, | created: 4/21/2002 8:32:04 AM, modified: 10/3/2005 9:15:12 PM Command line: c:\winnt\system32\zonelabs\vsmon.exe | Script: Quarantine, Delete, BC delete, Terminate 440 | TrueVector Service | Copyright © 1998-2006, Zone Labs, LLC | ?? | 73.80 kb, rsAh, | created: 4/18/2007 4:56:35 PM, modified: 3/8/2007 11:01:58 PM Command line: c:\winnt\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 204 | Windows NT Logon Application | Copyright (C) Microsoft Corp. 1981-1999 | ?? | 178.27 kb, rsAh, | created: 12/2/2004 1:10:03 PM, modified: 8/24/2004 5:59:10 PM Command line: winlogon.exe c:\winnt\system32\wbem\winmgmt.exe | Script: Quarantine, Delete, BC delete, Terminate 868 | Windows Management Instrumentation | Copyright (C) Microsoft Corp. 1995-1999 | ?? | 192.08 kb, rsAh, | created: 8/22/2002 8:11:40 PM, modified: 7/22/2002 2:05:04 PM Command line: C:\WINNT\System32\WBEM\WinMgmt.exe d:\apps\netgear\wlancfg4.exe | Script: Quarantine, Delete, BC delete, Terminate 1400 | | | ?? | 1140.50 kb, rsAh, | created: 12/27/2005 2:51:40 PM, modified: 3/20/2003 7:13:18 PM Command line: c:\winnt\system32\wuauclt.exe | Script: Quarantine, Delete, BC delete, Terminate 1556 | Windows Update Automatic Updates | © Microsoft Corporation. All rights reserved. | ?? | 51.84 kb, rsAh, | created: 5/22/2002 10:29:18 PM, modified: 7/30/2007 6:19:16 PM Command line: "C:\WINNT\system32\wuauclt.exe" c:\program files\zone labs\zonealarm\zlclient.exe | Script: Quarantine, Delete, BC delete, Terminate 1304 | ZoneAlarm Client | Copyright © 1998-2006, Zone Labs, LLC | ?? | 897.73 kb, rsAh, | created: 4/18/2007 4:56:56 PM, modified: 3/8/2007 11:02:00 PM Command line: Detected:30, recognized as trusted 21
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\Common Files\Real\Update_OB\realsched.exe | Script: Quarantine, Delete, BC delete 4194304 | RealNetworks Scheduler | Copyright © RealNetworks, Inc. 1995-2004 | ?? | 1324
| C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe | Script: Quarantine, Delete, BC delete 4194304 | Lexmark X74-X75 Button Manager | (C) 2002 Lexmark International, Inc. | ?? | 1296
| C:\Program Files\Lexmark X74-X75\lxbbbmon.exe | Script: Quarantine, Delete, BC delete 4194304 | Lexmark X74-X75 Button Monitor | (C) 2002 Lexmark International, Inc. | ?? | 1316
| C:\Program Files\SUPERAntiSpyware\deupx.dll | Script: Quarantine, Delete, BC delete 268435456 | deupx.dll | Copyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 1340
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete 268435456 | ShellExecuteHook | (c) Copyright 2004-2006 SuperAdBlocker.com | -- | 1168, 1340
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete 268435456 | SUPERAntiSpyware WinLogon Processor | Copyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 204
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete 4194304 | SUPERAntiSpyware | Copyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1340
| C:\Program Files\Zone Labs\ZoneAlarm\cam.zap | Script: Quarantine, Delete, BC delete 22675456 | Anti-Virus Monitoring Module | Copyright © 1998-2006, Zone Labs, LLC | -- | 1304
| C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap | Script: Quarantine, Delete, BC delete 1392508928 | IMsecure Plugin Module | Copyright © 1998-2006, Zone Labs, LLC | -- | 1304
| C:\WINNT\Mixer.exe | Script: Quarantine, Delete, BC delete 4194304 | Mixer | Copyright (C) 1997-2001 | ?? | 1252
| C:\WINNT\system32\CLBCATQ.DLL | Script: Quarantine, Delete, BC delete 2002386944 | | Copyright (C) Microsoft Corp. 1995-1999 | -- | 1128, 1168, 1164, 1252, 1324, 580, 1340, 612, 412, 888, 440, 204, 868, 1556, 1304
| C:\WINNT\System32\cmnprop.dll | Script: Quarantine, Delete, BC delete 268435456 | CMAudio Property Page | Copyright (C) C-Media Corp. 1998-2000 | -- | 1252
| C:\WINNT\system32\lex2kusb.dll | Script: Quarantine, Delete, BC delete 21561344 | LEX2KUSB DLL | (C) 1993 - 2002 Lexmark International, Inc. | -- | 552
| C:\WINNT\system32\LEXBCE.DLL | Script: Quarantine, Delete, BC delete 1660944384 | LexBce Client | (C) 1993 - 2002 Lexmark International, Inc. | -- | 628, 580
| C:\WINNT\system32\LEXBCES.EXE | Script: Quarantine, Delete, BC delete 4194304 | LexBce Service | (C) 1993 - 2002 Lexmark International, Inc. | ?? | 552
| C:\WINNT\system32\LEXLMPM.DLL | Script: Quarantine, Delete, BC delete 268435456 | LEXLMPM DLL | (C) 1993 - 2002 Lexmark International, Inc. | -- | 580
| C:\WINNT\system32\lexp2p32.dll | Script: Quarantine, Delete, BC delete 268435456 | LEXP2P32 DLL | (C) 1993 - 2002 Lexmark International, Inc. | -- | 552
| C:\WINNT\system32\LEXPPS.EXE | Script: Quarantine, Delete, BC delete 4194304 | LEXPPS.EXE | (C) 1993 - 2002 Lexmark International, Inc. | ?? | 628
| C:\WINNT\system32\LIBEAY32_0.9.6l.dll | Script: Quarantine, Delete, BC delete 65273856 | | | -- | 440, 1304
| C:\WINNT\system32\LXBBpwr.dll | Script: Quarantine, Delete, BC delete 26017792 | Lexmark ColorFine POR Monitor | Copyright © 2000 Lexmark International, Inc. | -- | 580
| C:\WINNT\system32\spool\PRTPROCS\W32X86\LXBBPP5C.dll | Script: Quarantine, Delete, BC delete 22413312 | Lexmark X74-X75 Print Processor | Copyright (C) Lexmark International 2002 | -- | 580
| C:\WINNT\system32\VSDATA.dll | Script: Quarantine, Delete, BC delete 67108864 | TrueVector Service DLL | Copyright © 1998-2006, Zone Labs, LLC | -- | 440, 1304
| c:\winnt\system32\wuauserv.dll | Script: Quarantine, Delete, BC delete 4456448 | Windows Update AutoUpdate Service | © Microsoft Corporation. All rights reserved. | -- | 888
| C:\WINNT\system32\zlcomm.dll | Script: Quarantine, Delete, BC delete 1382023168 | ZLComm | Copyright © 1998-2006, Zone Labs, LLC | -- | 440, 1304
| C:\WINNT\system32\ZLCommDB.dll | Script: Quarantine, Delete, BC delete 1384120320 | ZLCommDB | Copyright © 1998-2006, Zone Labs, LLC | -- | 440, 1304
| C:\WINNT\system32\ZoneLabs\imsecure.dll | Script: Quarantine, Delete, BC delete 1390411776 | TrueVector Service | Copyright © 1998-2006, Zone Labs, LLC | -- | 440
| C:\WINNT\system32\ZoneLabs\srescan.dll | Script: Quarantine, Delete, BC delete 62455808 | srescan | Copyright © 2006 | -- | 440
| C:\WINNT\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll | Script: Quarantine, Delete, BC delete 65011712 | HttpBlocker plug-in | Copyright © 1998-2006, Zone Labs, LLC | -- | 440
| C:\WINNT\system32\ZoneLabs\streamapi\imslsp\imslsp.dll | Script: Quarantine, Delete, BC delete 34537472 | ZoneAlarm IMsecure components for securing MSN/AIM-OSCAR/YIM protocols | Copyright © 1998-2006, Zone Labs, LLC | -- | 440
| C:\WINNT\system32\ZoneLabs\zlsre.dll | Script: Quarantine, Delete, BC delete 62062592 | zlsre | Copyright © 1998-2006, Zone Labs, LLC | -- | 440
| C:\WINNT\system32\zpeng24.dll | Script: Quarantine, Delete, BC delete 503316480 | Python Core | Copyright © 2001-2004 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC. | -- | 440, 1304
| D:\Apps\NetGear\W32N50.DLL | Script: Quarantine, Delete, BC delete 268435456 | WinDis 32 API & Platform Compatibility DLL | Copyright © 1997-2001 Printing Communications Assoc., Inc. | -- | 1400
| D:\Apps\NetGear\wlancfg4.EXE | Script: Quarantine, Delete, BC delete 4194304 | | | ?? | 1400
| Modules detected:305, recognized as trusted 272
| |
Module | Base address | Size in memory | Description | Manufacturer
C:\WINNT\System32\Drivers\Cdr4_2K.SYS | Script: Quarantine, Delete, BC delete ED060000 | 00B000 (45056) | CDR4 CD and DVD Burning Helper Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\WINNT\System32\Drivers\Cdralw2k.SYS | Script: Quarantine, Delete, BC delete ED2E8000 | 007000 (28672) | CDRAL for Windows 2000 Kernel Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\WINNT\system32\drivers\cmaudio.sys | Script: Quarantine, Delete, BC delete BFC99000 | 058000 (360448) | C-Media Audio WDM Driver | Copyright (C) C-Media Inc. 1998-2001
| C:\WINNT\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete BE8B4000 | 016000 (90112) |
| C:\WINNT\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete ED641000 | 001000 (4096) |
| D:\Apps\NetGear\PCANDIS5.SYS | Script: Quarantine, Delete, BC delete BCEBD000 | 004000 (16384) | PCAUSA NDIS 5.0 Protocol Driver | Copyright © 1995-2001 Printing Communications Assoc., Inc. (PCAUSA)
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, BC delete ED3F0000 | 007000 (28672) | SASDIFSV | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASENUM.SYS | Script: Quarantine, Delete, BC delete ED2B0000 | 005000 (20480) | SuperAntiSpyware | (C) Copyright 2004-2006
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete ED1E0000 | 00C000 (49152) | SASKUTIL.SYS | Copyright (C) 2006
| srescan.sys | Script: Quarantine, Delete, BC delete BFEB1000 | 014000 (81920) |
| C:\WINNT\system32\drivers\tmcomm.sys | Script: Quarantine, Delete, BC delete BCEF1000 | 012000 (73728) | TrendMicro Common Module | Copyright (C) 2005-2006 Trend Micro Incorporated. All rights reserved.
| C:\WINNT\system32\Drivers\viaide.sys | Script: Quarantine, Delete, BC delete ED504000 | 002000 (8192) | VIA PCI IDE Bus Driver | Copyright (C) Microsoft Corp. 2000-2005
| C:\WINNT\System32\Drivers\VIAPFD.SYS | Script: Quarantine, Delete, BC delete ED60D000 | 001000 (4096) | VIA PFD driver | Copyright (C) VIA Technologies, Inc. 2001-2005
| Modules detected - 107, recognized as trusted - 94
| |
Service | Description | Status | File | Group | Dependencies
LexBceS | Service: Stop, Delete, Disable LexBce Server | Running | C:\WINNT\system32\LEXBCES.EXE | Script: Quarantine, Delete, BC delete SpoolerGroup | RPCSS
| IISADMIN | Service: Stop, Delete, Disable IIS Admin Service | Not started | C:\WINNT\System32\inetsrv\inetinfo.exe | Script: Quarantine, Delete, BC delete | RPCSS
| MSFTPSVC | Service: Stop, Delete, Disable FTP Publishing Service | Not started | C:\WINNT\System32\inetsrv\inetinfo.exe | Script: Quarantine, Delete, BC delete | IISADMIN
| SMTPSVC | Service: Stop, Delete, Disable Simple Mail Transport Protocol (SMTP) | Not started | C:\WINNT\System32\inetsrv\inetinfo.exe | Script: Quarantine, Delete, BC delete | IISADMIN
| W3SVC | Service: Stop, Delete, Disable World Wide Web Publishing Service | Not started | C:\WINNT\System32\inetsrv\inetinfo.exe | Script: Quarantine, Delete, BC delete | IISADMIN
| WMDM PMSP Service | Service: Stop, Delete, Disable WMDM PMSP Service | Not started | C:\WINNT\System32\mspmspsv.exe | Script: Quarantine, Delete, BC delete |
| Detected - 63, recognized as trusted - 57
| |
File name | Status | Startup method | Description
C:\Program Files\Common Files\Real\Update_OB\realsched.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TkBellExe
| C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Lexmark X74-X75
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
| C:\WINNT\Mixer.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, C-Media Mixer
| C:\WINNT\System32\NeroCheck.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NeroCheck
| D:\Apps\Microsoft Office\Office\OSA9.EXE | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk,
| D:\Apps\NetGear\wlancfg.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk,
| D:\apps\quicktime\qttask.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
| Autoruns items detected - 58, recognized as trusted - 48
| |
File name | Type | Description | Manufacturer | CLSID
D:\Apps\AOL\aim.exe | Script: Quarantine, Delete, BC delete Extension module | AOL Instant Messenger | Copyright © 1996-2006 America Online, Inc. | {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} | Delete Elements detected - 5, recognized as trusted - 4
| |
File name | Destination | Description | Manufacturer | CLSID
deskpan.dll | Script: Quarantine, Delete, BC delete Display Panning CPL Extension | {42071714-76d4-11d1-8b24-00a0c9068ff3}
| Shell extensions for file compression | {764BF0E1-F219-11ce-972D-00AA00A14F56}
| Encryption Context Menu | {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
| D:\APPS\CuteFTP\CuteShell.dll | Script: Quarantine, Delete, BC delete CuteFTP Shell Extension | CuteShell DLL | Copyright (C) 1999 | {8f7261d0-d2b9-11d2-9909-00605205b24c}
| C:\Program Files\Real\RealPlayer\rpshell.dll | Script: Quarantine, Delete, BC delete Shell Extensions for RealOne Player | RealPlayer Shell Extensions | Copyright © RealNetworks, Inc. 2001-2004 | {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
| Elements detected - 165, recognized as trusted - 160
| |
File name | Type | Name | Description | Manufacturer
C:\WINNT\system32\LEXLMPM.DLL | Script: Quarantine, Delete, BC delete Monitor | Lexmark Network Port | LEXLMPM DLL | (C) 1993 - 2002 Lexmark International, Inc.
| Elements detected - 9, recognized as trusted - 8
| |
File name | Job name | Job status | Description | Manufacturer
Elements detected - 0, recognized as trusted - 0
| |
Manufacturer | Status | EXE file | Description | GUID
Detected - 2, recognized as trusted - 2
| |
Manufacturer | EXE file | Description
Detected - 23, recognized as trusted - 23
| |
Port | Status | Remote Host | Remote Port | Application | Notes
TCP ports
| 135 | LISTENING | 0.0.0.0 | 0 | [0] |
| 139 | LISTENING | 0.0.0.0 | 43099 | [0] |
| 445 | LISTENING | 0.0.0.0 | 43174 | [0] |
| 1025 | LISTENING | 0.0.0.0 | 0 | [0] |
| 1026 | LISTENING | 0.0.0.0 | 0 | [0] |
| 1027 | LISTENING | 0.0.0.0 | 43154 | [0] |
| 3008 | ESTABLISHED | 127.0.0.1 | 3009 | [0] |
| 3009 | ESTABLISHED | 127.0.0.1 | 3008 | [0] |
| 3009 | LISTENING | 0.0.0.0 | 43042 | [0] |
| 3010 | ESTABLISHED | 127.0.0.1 | 3011 | [0] |
| 3011 | ESTABLISHED | 127.0.0.1 | 3010 | [0] |
| 3011 | LISTENING | 0.0.0.0 | 51254 | [0] |
| 3025 | TIME_WAIT | 72.232.218.60 | 80 | [0] |
| UDP ports
| 137 | LISTENING | -- | -- | [0] |
| 138 | LISTENING | -- | -- | [0] |
| 445 | LISTENING | -- | -- | [0] |
| 500 | LISTENING | -- | -- | [0] |
| 3001 | LISTENING | -- | -- | [0] |
| |
File name | Description | Manufacturer | CLSID | Source URL
DirectAnimation Java Classes | Delete file://C:\WINNT\Java\classes\dajava.cab
| Microsoft XML Parser for Java | Delete file://C:\WINNT\Java\classes\xmldso.cab
| {31564D57-0000-0010-8000-00AA00389B71} | Delete http://codecs.microsoft.com/codecs/i386/wmvax.cab
| {9F1C11AA-197B-4942-BA54-47A8489BB47F} | Delete http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37487.6239583333
| {CEBC955E-58AF-11D2-A30A-00A0C903492B} | Delete http://windowsupdate.microsoft.com/R980/V31Controls/x86/nt5/en/actsetup.cab
| C:\WINNT\Downloaded Program Files\dwa7W.dll | Script: Quarantine, Delete, BC delete {E008A543-CEFB-4559-912F-C27C2B89F13B} | Delete https://webmail.belk.com/belkmail04.belkinc.com/dwa7W.cab
| Elements detected - 12, recognized as trusted - 6
| |
File name | Description | Manufacturer
C:\WINNT\system32\PLOTMAN.CPL | Script: Quarantine, Delete, BC delete Autodesk Hardcopy Plotter Manager | Copyright (C) 1998-1999 Autodesk, Inc.
| C:\WINNT\system32\plugincpl131_10.cpl | Script: Quarantine, Delete, BC delete JavaPlugin | Copyright ¨ 2000
| C:\WINNT\system32\STYLEMAN.CPL | Script: Quarantine, Delete, BC delete Autodesk Hardcopy Plotter Manager | Copyright (C) 1998-1999 Autodesk, Inc.
| Elements detected - 25, recognized as trusted - 22
| |
File name | Description | Manufacturer | CLSID
Elements detected - 12, recognized as trusted - 12
| |
Hosts file record
|
File name | Type | Description | Manufacturer | CLSID
Elements detected - 23, recognized as trusted - 23
| |
File | Description | Type
C:\WINNT\System32\vsdatant.sys | Script: Quarantine, Delete, BC delete Suspicion for Rootkit | Kernel-mode hook
| C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll | Script: Quarantine, Delete, BC delete Suspicion by Heuristic analysis | HSC: suspicion for Spy.WindTangent
| C:\WINNT\wt\webdriver\4.1.1\webdriver.dll | Script: Quarantine, Delete, BC delete Suspicion by Heuristic analysis | HSC: suspicion for Spy.WindTangent
| |
AVZ Antiviral Toolkit log; AVZ version is 4.29 Scanning started at 2/10/2008 10:06:39 AM Database loaded: signatures - 149090, NN profile(s) - 2, microprograms of healing - 55, signature database released 09.02.2008 22:28 Heuristic microprograms loaded: 370 SPV microprograms loaded: 9 Digital signatures of system files loaded: 68697 Heuristic analyzer mode: Maximum heuristics level Healing mode: disabled Windows version: 5.0.2195, Service Pack 3 ; AVZ is launched with administrator rights System Restore: enabled 1. Searching for Rootkits and programs intercepting API functions >>>> Probable masking of executable file's name 1340 superantispyware.exe, real name - SUPERAntiSpywar 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully SDT found (RVA=080820) Kernel ntoskrnl.exe found in memory at address 80400000 SDT = 80480820 KiST = 80472128 (248) Function NtConnectPort (1B) intercepted (804C5930->BE9E8E60), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreateFile (20) intercepted (804A6FB2->BE9E5820), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreateKey (23) intercepted (80511CAA->BE9F0690), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreatePort (28) intercepted (804C642C->BE9E91F0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreateProcess (29) intercepted (804E20C4->BE9EF480), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreateSection (2B) intercepted (804CAF6A->BE9F2CE0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtCreateWaitablePort (31) intercepted (804C644A->BE9E92D0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtDeleteFile (34) intercepted (804A0D36->BE9E5EA0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtDeleteKey (35) intercepted (8051206E->BE9F16A0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtDeleteValueKey (37) intercepted (8051228A->BE9F12E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtDuplicateObject (3A) intercepted (804D6002->BE9EF1F0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtLoadKey (56) intercepted (805140B0->BE9F19E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtOpenFile (64) intercepted (804A8256->BE9E5CF0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtOpenProcess (6A) intercepted (804DE984->BE9EEF40), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtOpenThread (6F) intercepted (804DEC44->BE9EED60), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtReplaceKey (A9) intercepted (80514564->BE9F1CD0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtRequestWaitReplyPort (B0) intercepted (804C4D48->BE9E8B00), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtRestoreKey (B4) intercepted (80513A56->BE9F1F80), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtSecureConnectPort (B8) intercepted (80433698->BE9E9010), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtSetInformationFile (C2) intercepted (804A91FA->BE9E6010), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtSetValueKey (D7) intercepted (80513DF4->BE9F0E67), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Function NtTerminateProcess (E0) intercepted (804E312C->BE9EF8E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted Functions checked: 248, intercepted: 22, restored: 0 1.3 Checking IDT and SYSENTER Analysis for CPU 1 Checking IDT and SYSENTER - complete 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed 2. Scanning memory Number of processes found: 29 Analyzer: process under analysis is 552 C:\WINNT\system32\LEXBCES.EXE [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder Analyzer: process under analysis is 628 C:\WINNT\system32\LEXPPS.EXE [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Located in system folder [ES]:Loads RASAPI DLL - may use dialing ? Analyzer: process under analysis is 1296 C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe [ES]:Application has no visible windows [ES]:Registered in autoruns !! Analyzer: process under analysis is 1316 C:\Program Files\Lexmark X74-X75\lxbbbmon.exe [ES]:Application has no visible windows Analyzer: process under analysis is 1324 C:\Program Files\Common Files\Real\Update_OB\realsched.exe [ES]:Contains network functionality [ES]:Application has no visible windows [ES]:Registered in autoruns !! Number of modules loaded: 281 Scanning memory - complete 3. Scanning disks 4. Checking Winsock Layered Service Provider (SPI/LSP) LSP settings checked. No errors detected 5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs) 6. Searching for opened TCP/UDP ports used by malicious programs Checking disabled by user 7. Heuristic system check >>> C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll HSC: suspicion for Spy.WindTangent >>> C:\WINNT\wt\webdriver\4.1.1\webdriver.dll HSC: suspicion for Spy.WindTangent Checking - complete 8. Searching for vulnerabilities >> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry Service) >> Services: potentially dangerous service allowed: TlntSvr (Telnet) >> Services: potentially dangerous service allowed: Messenger (Messenger) >> Services: potentially dangerous service allowed: Alerter (Alerter) >> Services: potentially dangerous service allowed: Schedule (Task Scheduler) >> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements >> Security: terminal connections to the PC are allowed >> Security: sending Remote Assistant queries is enabled Checking - complete 9. Troubleshooting wizard >> Internet Explorer - automatic queries of ActiveX operating elements are allowed Checking - complete Files scanned: 310, extracted from archives: 0, malicious software found 0, suspicions - 0 Scanning finished at 2/10/2008 10:07:21 AM Time of scanning: 00:00:44 If you have a suspicion on presence of viruses or questions on the suspected objects, you can address http://virusinfo.info conference System Analysis in progressAdd commands to script:
Script commands