Results of system analysis

AVZ 4.29 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\documents and settings\brian norris\desktop\avz4\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
1128???????????? ??????? AVZ???????????? ??????? AVZ??715.50 kb, rsAh,
created: 12/13/2007 3:28:04 PM,
modified: 12/13/2007 3:28:04 PM
Command line:
"C:\Documents and Settings\Brian Norris\Desktop\AVZ4\avz4\avz.exe"
c:\winnt\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
1168Windows ExplorerCopyright (C) Microsoft Corp. 1981-1999??237.27 kb, rsAh,
created: 8/22/2002 8:06:45 PM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\Explorer.EXE
c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
1164FirefoxMozilla Corporation??7471.11 kb, rsAh,
created: 1/6/2008 11:47:03 AM,
modified: 11/28/2007 2:11:50 PM
Command line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
c:\winnt\system32\lexbces.exe
Script: Quarantine, Delete, BC delete, Terminate
552LexBce Service(C) 1993 - 2002 Lexmark International, Inc.??296.00 kb, rsAh,
created: 10/14/2002 2:03:18 PM,
modified: 10/14/2002 2:03:18 PM
Command line:
C:\WINNT\system32\LEXBCES.EXE
c:\winnt\system32\lexpps.exe
Script: Quarantine, Delete, BC delete, Terminate
628LEXPPS.EXE(C) 1993 - 2002 Lexmark International, Inc.??170.50 kb, rsAh,
created: 10/14/2002 2:00:42 PM,
modified: 10/14/2002 2:00:42 PM
Command line:
LEXPPS.EXE
c:\program files\lexmark x74-x75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete, Terminate
1296Lexmark X74-X75 Button Manager(C) 2002 Lexmark International, Inc.??56.00 kb, rsAh,
created: 10/14/2002 2:09:12 PM,
modified: 10/14/2002 2:09:12 PM
Command line:
"C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
c:\program files\lexmark x74-x75\lxbbbmon.exe
Script: Quarantine, Delete, BC delete, Terminate
1316Lexmark X74-X75 Button Monitor(C) 2002 Lexmark International, Inc.??48.00 kb, rsAh,
created: 10/14/2002 2:22:04 PM,
modified: 10/14/2002 2:22:04 PM
Command line:
"C:\Program Files\Lexmark X74-X75\lxbbbmon.exe"
c:\winnt\mixer.exe
Script: Quarantine, Delete, BC delete, Terminate
1252MixerCopyright (C) 1997-2001??1188.00 kb, rsAh,
created: 8/25/2002 1:31:57 PM,
modified: 11/15/2001 10:08:40 AM
Command line:
"C:\WINNT\Mixer.exe" /startup
c:\program files\common files\real\update_ob\realsched.exe
Script: Quarantine, Delete, BC delete, Terminate
1324RealNetworks SchedulerCopyright © RealNetworks, Inc. 1995-2004??176.04 kb, rsAh,
created: 12/9/2005 6:14:41 PM,
modified: 12/9/2005 6:14:41 PM
Command line:
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
c:\winnt\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
580Spooler SubSystem AppCopyright (C) Microsoft Corp. 1981-1999??44.27 kb, rsAh,
created: 4/21/2002 8:37:53 AM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\system32\spoolsv.exe
c:\program files\superantispyware\superantispyware.exe
Script: Quarantine, Delete, BC delete, Terminate
1340SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1288.00 kb, rsAh,
created: 6/21/2007 2:06:28 PM,
modified: 6/21/2007 2:06:28 PM
Command line:
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
612Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\System32\svchost.exe -k netsvcs
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
412Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\system32\svchost -k rpcss
c:\winnt\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
888Generic Host Process for Win32 ServicesCopyright (C) Microsoft Corp. 1981-1999??7.77 kb, rsAh,
created: 12/7/1999 7:00:00 AM,
modified: 12/7/1999 7:00:00 AM
Command line:
C:\WINNT\system32\svchost.exe -k wugroup
C:\WINNT\System
Script: Quarantine, Delete, BC delete, Terminate
8  ??0.00 kb, rsAh,
created: 4/21/2002 8:32:04 AM,
modified: 10/3/2005 9:15:12 PM
Command line:
c:\winnt\system32\zonelabs\vsmon.exe
Script: Quarantine, Delete, BC delete, Terminate
440TrueVector ServiceCopyright © 1998-2006, Zone Labs, LLC??73.80 kb, rsAh,
created: 4/18/2007 4:56:35 PM,
modified: 3/8/2007 11:01:58 PM
Command line:
c:\winnt\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
204Windows NT Logon ApplicationCopyright (C) Microsoft Corp. 1981-1999??178.27 kb, rsAh,
created: 12/2/2004 1:10:03 PM,
modified: 8/24/2004 5:59:10 PM
Command line:
winlogon.exe
c:\winnt\system32\wbem\winmgmt.exe
Script: Quarantine, Delete, BC delete, Terminate
868Windows Management InstrumentationCopyright (C) Microsoft Corp. 1995-1999??192.08 kb, rsAh,
created: 8/22/2002 8:11:40 PM,
modified: 7/22/2002 2:05:04 PM
Command line:
C:\WINNT\System32\WBEM\WinMgmt.exe
d:\apps\netgear\wlancfg4.exe
Script: Quarantine, Delete, BC delete, Terminate
1400  ??1140.50 kb, rsAh,
created: 12/27/2005 2:51:40 PM,
modified: 3/20/2003 7:13:18 PM
Command line:
c:\winnt\system32\wuauclt.exe
Script: Quarantine, Delete, BC delete, Terminate
1556Windows Update Automatic Updates© Microsoft Corporation. All rights reserved.??51.84 kb, rsAh,
created: 5/22/2002 10:29:18 PM,
modified: 7/30/2007 6:19:16 PM
Command line:
"C:\WINNT\system32\wuauclt.exe"
c:\program files\zone labs\zonealarm\zlclient.exe
Script: Quarantine, Delete, BC delete, Terminate
1304ZoneAlarm ClientCopyright © 1998-2006, Zone Labs, LLC??897.73 kb, rsAh,
created: 4/18/2007 4:56:56 PM,
modified: 3/8/2007 11:02:00 PM
Command line:
Detected:30, recognized as trusted 21
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Script: Quarantine, Delete, BC delete
4194304RealNetworks SchedulerCopyright © RealNetworks, Inc. 1995-2004??1324
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete
4194304Lexmark X74-X75 Button Manager(C) 2002 Lexmark International, Inc.??1296
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
Script: Quarantine, Delete, BC delete
4194304Lexmark X74-X75 Button Monitor(C) 2002 Lexmark International, Inc.??1316
C:\Program Files\SUPERAntiSpyware\deupx.dll
Script: Quarantine, Delete, BC delete
268435456deupx.dllCopyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com--1340
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
268435456ShellExecuteHook(c) Copyright 2004-2006 SuperAdBlocker.com --1168, 1340
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
268435456SUPERAntiSpyware WinLogon ProcessorCopyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com--204
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
4194304SUPERAntiSpywareCopyright (C) 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com??1340
C:\Program Files\Zone Labs\ZoneAlarm\cam.zap
Script: Quarantine, Delete, BC delete
22675456Anti-Virus Monitoring ModuleCopyright © 1998-2006, Zone Labs, LLC--1304
C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
Script: Quarantine, Delete, BC delete
1392508928IMsecure Plugin ModuleCopyright © 1998-2006, Zone Labs, LLC--1304
C:\WINNT\Mixer.exe
Script: Quarantine, Delete, BC delete
4194304MixerCopyright (C) 1997-2001??1252
C:\WINNT\system32\CLBCATQ.DLL
Script: Quarantine, Delete, BC delete
2002386944 Copyright (C) Microsoft Corp. 1995-1999--1128, 1168, 1164, 1252, 1324, 580, 1340, 612, 412, 888, 440, 204, 868, 1556, 1304
C:\WINNT\System32\cmnprop.dll
Script: Quarantine, Delete, BC delete
268435456CMAudio Property PageCopyright (C) C-Media Corp. 1998-2000--1252
C:\WINNT\system32\lex2kusb.dll
Script: Quarantine, Delete, BC delete
21561344LEX2KUSB DLL(C) 1993 - 2002 Lexmark International, Inc.--552
C:\WINNT\system32\LEXBCE.DLL
Script: Quarantine, Delete, BC delete
1660944384LexBce Client(C) 1993 - 2002 Lexmark International, Inc.--628, 580
C:\WINNT\system32\LEXBCES.EXE
Script: Quarantine, Delete, BC delete
4194304LexBce Service(C) 1993 - 2002 Lexmark International, Inc.??552
C:\WINNT\system32\LEXLMPM.DLL
Script: Quarantine, Delete, BC delete
268435456LEXLMPM DLL(C) 1993 - 2002 Lexmark International, Inc.--580
C:\WINNT\system32\lexp2p32.dll
Script: Quarantine, Delete, BC delete
268435456LEXP2P32 DLL(C) 1993 - 2002 Lexmark International, Inc.--552
C:\WINNT\system32\LEXPPS.EXE
Script: Quarantine, Delete, BC delete
4194304LEXPPS.EXE(C) 1993 - 2002 Lexmark International, Inc.??628
C:\WINNT\system32\LIBEAY32_0.9.6l.dll
Script: Quarantine, Delete, BC delete
65273856  --440, 1304
C:\WINNT\system32\LXBBpwr.dll
Script: Quarantine, Delete, BC delete
26017792Lexmark ColorFine POR MonitorCopyright © 2000 Lexmark International, Inc.--580
C:\WINNT\system32\spool\PRTPROCS\W32X86\LXBBPP5C.dll
Script: Quarantine, Delete, BC delete
22413312Lexmark X74-X75 Print ProcessorCopyright (C) Lexmark International 2002--580
C:\WINNT\system32\VSDATA.dll
Script: Quarantine, Delete, BC delete
67108864TrueVector Service DLLCopyright © 1998-2006, Zone Labs, LLC--440, 1304
c:\winnt\system32\wuauserv.dll
Script: Quarantine, Delete, BC delete
4456448Windows Update AutoUpdate Service© Microsoft Corporation. All rights reserved.--888
C:\WINNT\system32\zlcomm.dll
Script: Quarantine, Delete, BC delete
1382023168ZLCommCopyright © 1998-2006, Zone Labs, LLC--440, 1304
C:\WINNT\system32\ZLCommDB.dll
Script: Quarantine, Delete, BC delete
1384120320ZLCommDBCopyright © 1998-2006, Zone Labs, LLC--440, 1304
C:\WINNT\system32\ZoneLabs\imsecure.dll
Script: Quarantine, Delete, BC delete
1390411776TrueVector ServiceCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\srescan.dll
Script: Quarantine, Delete, BC delete
62455808srescanCopyright © 2006--440
C:\WINNT\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
Script: Quarantine, Delete, BC delete
65011712HttpBlocker plug-inCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
Script: Quarantine, Delete, BC delete
34537472ZoneAlarm IMsecure components for securing MSN/AIM-OSCAR/YIM protocolsCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\ZoneLabs\zlsre.dll
Script: Quarantine, Delete, BC delete
62062592zlsreCopyright © 1998-2006, Zone Labs, LLC--440
C:\WINNT\system32\zpeng24.dll
Script: Quarantine, Delete, BC delete
503316480Python CoreCopyright © 2001-2004 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.--440, 1304
D:\Apps\NetGear\W32N50.DLL
Script: Quarantine, Delete, BC delete
268435456WinDis 32 API & Platform Compatibility DLLCopyright © 1997-2001 Printing Communications Assoc., Inc.--1400
D:\Apps\NetGear\wlancfg4.EXE
Script: Quarantine, Delete, BC delete
4194304  ??1400
Modules detected:305, recognized as trusted 272

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINNT\System32\Drivers\Cdr4_2K.SYS
Script: Quarantine, Delete, BC delete
ED06000000B000 (45056)CDR4 CD and DVD Burning Helper DriverCopyright (c) 1994-2005 Sonic Solutions
C:\WINNT\System32\Drivers\Cdralw2k.SYS
Script: Quarantine, Delete, BC delete
ED2E8000007000 (28672)CDRAL for Windows 2000 Kernel DriverCopyright (c) 1994-2005 Sonic Solutions
C:\WINNT\system32\drivers\cmaudio.sys
Script: Quarantine, Delete, BC delete
BFC99000058000 (360448)C-Media Audio WDM DriverCopyright (C) C-Media Inc. 1998-2001
C:\WINNT\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
BE8B4000016000 (90112)
C:\WINNT\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
ED641000001000 (4096)
D:\Apps\NetGear\PCANDIS5.SYS
Script: Quarantine, Delete, BC delete
BCEBD000004000 (16384)PCAUSA NDIS 5.0 Protocol DriverCopyright © 1995-2001 Printing Communications Assoc., Inc. (PCAUSA)
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
ED3F0000007000 (28672)SASDIFSVCopyright (C) 2006
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
ED2B0000005000 (20480)SuperAntiSpyware(C) Copyright 2004-2006
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
ED1E000000C000 (49152)SASKUTIL.SYSCopyright (C) 2006
srescan.sys
Script: Quarantine, Delete, BC delete
BFEB1000014000 (81920)
C:\WINNT\system32\drivers\tmcomm.sys
Script: Quarantine, Delete, BC delete
BCEF1000012000 (73728)TrendMicro Common ModuleCopyright (C) 2005-2006 Trend Micro Incorporated. All rights reserved.
C:\WINNT\system32\Drivers\viaide.sys
Script: Quarantine, Delete, BC delete
ED504000002000 (8192)VIA PCI IDE Bus DriverCopyright (C) Microsoft Corp. 2000-2005
C:\WINNT\System32\Drivers\VIAPFD.SYS
Script: Quarantine, Delete, BC delete
ED60D000001000 (4096)VIA PFD driverCopyright (C) VIA Technologies, Inc. 2001-2005
Modules detected - 107, recognized as trusted - 94

Services

ServiceDescriptionStatusFileGroupDependencies
LexBceS
Service: Stop, Delete, Disable
LexBce ServerRunningC:\WINNT\system32\LEXBCES.EXE
Script: Quarantine, Delete, BC delete
SpoolerGroupRPCSS
IISADMIN
Service: Stop, Delete, Disable
IIS Admin ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 RPCSS
MSFTPSVC
Service: Stop, Delete, Disable
FTP Publishing ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
SMTPSVC
Service: Stop, Delete, Disable
Simple Mail Transport Protocol (SMTP)Not startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
W3SVC
Service: Stop, Delete, Disable
World Wide Web Publishing ServiceNot startedC:\WINNT\System32\inetsrv\inetinfo.exe
Script: Quarantine, Delete, BC delete
 IISADMIN
WMDM PMSP Service
Service: Stop, Delete, Disable
WMDM PMSP ServiceNot startedC:\WINNT\System32\mspmspsv.exe
Script: Quarantine, Delete, BC delete
  
Detected - 63, recognized as trusted - 57

Drivers

ServiceDescriptionStatusFileGroupDependencies
Cdr4_2K
Driver: Unload, Delete, Disable
Cdr4_2KRunningC:\WINNT\system32\Drivers\Cdr4_2K.sys
Script: Quarantine, Delete, BC delete
Filter 
Cdralw2k
Driver: Unload, Delete, Disable
Cdralw2kRunningC:\WINNT\system32\Drivers\Cdralw2k.sys
Script: Quarantine, Delete, BC delete
Filter 
cmpci
Driver: Unload, Delete, Disable
C-Media PCI Audio Driver (WDM)RunningC:\WINNT\system32\drivers\cmaudio.sys
Script: Quarantine, Delete, BC delete
  
PCANDIS5
Driver: Unload, Delete, Disable
PCANDIS5 Protocol DriverRunningD:\Apps\NetGear\PCANDIS5.SYS
Script: Quarantine, Delete, BC delete
PNP_TDI 
SASDIFSV
Driver: Unload, Delete, Disable
SASDIFSVRunningC:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Script: Quarantine, Delete, BC delete
  
SASENUM
Driver: Unload, Delete, Disable
SASENUMRunningC:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Script: Quarantine, Delete, BC delete
  
SASKUTIL
Driver: Unload, Delete, Disable
SASKUTILRunningC:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Script: Quarantine, Delete, BC delete
  
srescan
Driver: Unload, Delete, Disable
srescanRunningC:\WINNT\system32\ZoneLabs\srescan.sys
Script: Quarantine, Delete, BC delete
  
tmcomm
Driver: Unload, Delete, Disable
tmcommRunningC:\WINNT\system32\drivers\tmcomm.sys
Script: Quarantine, Delete, BC delete
ExtendedBase 
viaide
Driver: Unload, Delete, Disable
viaideRunningC:\WINNT\System32\DRIVERS\viaide.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
VIAPFD
Driver: Unload, Delete, Disable
VIAPFDRunningC:\WINNT\System32\Drivers\VIAPFD.SYS
Script: Quarantine, Delete, BC delete
Base 
USB_RNDIS_2K
Driver: Unload, Delete, Disable
Westell WireSpeed Dual Connect ModemNot startedC:\WINNT\system32\DRIVERS\usb8023k.sys
Script: Quarantine, Delete, BC delete
NDIS 
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic116x
Driver: Unload, Delete, Disable
aic116xNot startedaic116x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ami0nt
Driver: Unload, Delete, Disable
ami0ntNot startedami0nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
BusLogic
Driver: Unload, Delete, Disable
BusLogicNot startedBusLogic.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqarry2
Driver: Unload, Delete, Disable
cpqarry2Not startedcpqarry2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqfcalm
Driver: Unload, Delete, Disable
cpqfcalmNot startedcpqfcalm.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cpqfws2e
Driver: Unload, Delete, Disable
cpqfws2eNot startedcpqfws2e.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
deckzpsx
Driver: Unload, Delete, Disable
deckzpsxNot starteddeckzpsx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ENDETECT
Driver: Unload, Delete, Disable
ENDETECTNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\ENDETECT.SYS
Script: Quarantine, Delete, BC delete
  
Fd16_700
Driver: Unload, Delete, Disable
Fd16_700Not startedFd16_700.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
fireport
Driver: Unload, Delete, Disable
fireportNot startedfireport.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
flashpnt
Driver: Unload, Delete, Disable
flashpntNot startedflashpnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
IntelIde
Driver: Unload, Delete, Disable
IntelIdeNot startedIntelIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ipsraidn
Driver: Unload, Delete, Disable
ipsraidnNot startedipsraidn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
L2XPSR
Driver: Unload, Delete, Disable
L2XPSRNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\L2XPSR.SYS
Script: Quarantine, Delete, BC delete
  
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
lp6nds35
Driver: Unload, Delete, Disable
lp6nds35Not startedlp6nds35.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ncrc710
Driver: Unload, Delete, Disable
Ncrc710Not startedNcrc710.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
NTSTPL1
Driver: Unload, Delete, Disable
NTSTPL1Not startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\NTSTPL1.SYS
Script: Quarantine, Delete, BC delete
  
NTSTPL2
Driver: Unload, Delete, Disable
NTSTPL2Not startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\NTSTPL2.SYS
Script: Quarantine, Delete, BC delete
  
OlCamudp
Driver: Unload, Delete, Disable
OLYMPUS Digital CameraNot startedC:\WINNT\system32\Drivers\olcamudp.sys
Script: Quarantine, Delete, BC delete
Base 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql2100
Driver: Unload, Delete, Disable
ql2100Not startedql2100.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sglfb
Driver: Unload, Delete, Disable
sglfbNot startedsglfb.sys
Script: Quarantine, Delete, BC delete
Video 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TAPBIND
Driver: Unload, Delete, Disable
TAPBINDNot startedC:\PROGRA~1\FRONTI~1\FRONTI~1\app\TAPBIND1.SYS
Script: Quarantine, Delete, BC delete
  
tga
Driver: Unload, Delete, Disable
tgaNot startedtga.sys
Script: Quarantine, Delete, BC delete
Video 
ultra66
Driver: Unload, Delete, Disable
ultra66Not startedultra66.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
UNDPX2A
Driver: Unload, Delete, Disable
UNDPX2ANot startedC:\WINNT\system32\drivers\UNDPX2A.SYS
Script: Quarantine, Delete, BC delete
  
viafilter
Driver: Unload, Delete, Disable
VIA USB FilterNot startedC:\WINNT\System32\Drivers\viausb.sys
Script: Quarantine, Delete, BC delete
extend base 
WLAN_USB
Driver: Unload, Delete, Disable
Wireless LAN USB DriverNot startedC:\WINNT\system32\DRIVERS\MA111nd5.sys
Script: Quarantine, Delete, BC delete
NDIS 
XIRLINK
Driver: Unload, Delete, Disable
Veo PC CameraNot startedC:\WINNT\system32\DRIVERS\ucdnt.sys
Script: Quarantine, Delete, BC delete
  
Detected - 180, recognized as trusted - 113

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, TkBellExe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Lexmark X74-X75
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
C:\WINNT\Mixer.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, C-Media Mixer
C:\WINNT\System32\NeroCheck.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, NeroCheck
D:\Apps\Microsoft Office\Office\OSA9.EXE
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk,
D:\Apps\NetGear\wlancfg.exe
Script: Quarantine, Delete, BC delete
ActiveShortcut in Autoruns folderC:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk,
D:\apps\quicktime\qttask.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
Autoruns items detected - 58, recognized as trusted - 48

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
D:\Apps\AOL\aim.exe
Script: Quarantine, Delete, BC delete
Extension moduleAOL Instant MessengerCopyright © 1996-2006 America Online, Inc.{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
Delete
Elements detected - 5, recognized as trusted - 4

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
D:\APPS\CuteFTP\CuteShell.dll
Script: Quarantine, Delete, BC delete
CuteFTP Shell ExtensionCuteShell DLLCopyright (C) 1999{8f7261d0-d2b9-11d2-9909-00605205b24c}
C:\Program Files\Real\RealPlayer\rpshell.dll
Script: Quarantine, Delete, BC delete
Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsCopyright © RealNetworks, Inc. 2001-2004{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
Elements detected - 165, recognized as trusted - 160

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
C:\WINNT\system32\LEXLMPM.DLL
Script: Quarantine, Delete, BC delete
MonitorLexmark Network PortLEXLMPM DLL(C) 1993 - 2002 Lexmark International, Inc.
Elements detected - 9, recognized as trusted - 8

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 2, recognized as trusted - 2
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
Detected - 23, recognized as trusted - 23
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[0]   
139LISTENING0.0.0.043099[0]   
445LISTENING0.0.0.043174[0]   
1025LISTENING0.0.0.00[0]   
1026LISTENING0.0.0.00[0]   
1027LISTENING0.0.0.043154[0]   
3008ESTABLISHED127.0.0.13009[0]   
3009ESTABLISHED127.0.0.13008[0]   
3009LISTENING0.0.0.043042[0]   
3010ESTABLISHED127.0.0.13011[0]   
3011ESTABLISHED127.0.0.13010[0]   
3011LISTENING0.0.0.051254[0]   
3025TIME_WAIT72.232.218.6080[0]   
UDP ports
137LISTENING----[0]   
138LISTENING----[0]   
445LISTENING----[0]   
500LISTENING----[0]   
3001LISTENING----[0]   

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
DirectAnimation Java Classes
Delete
file://C:\WINNT\Java\classes\dajava.cab
Microsoft XML Parser for Java
Delete
file://C:\WINNT\Java\classes\xmldso.cab
{31564D57-0000-0010-8000-00AA00389B71}
Delete
http://codecs.microsoft.com/codecs/i386/wmvax.cab
{9F1C11AA-197B-4942-BA54-47A8489BB47F}
Delete
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37487.6239583333
{CEBC955E-58AF-11D2-A30A-00A0C903492B}
Delete
http://windowsupdate.microsoft.com/R980/V31Controls/x86/nt5/en/actsetup.cab
C:\WINNT\Downloaded Program Files\dwa7W.dll
Script: Quarantine, Delete, BC delete
{E008A543-CEFB-4559-912F-C27C2B89F13B}
Delete
https://webmail.belk.com/belkmail04.belkinc.com/dwa7W.cab
Elements detected - 12, recognized as trusted - 6

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINNT\system32\PLOTMAN.CPL
Script: Quarantine, Delete, BC delete
Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.
C:\WINNT\system32\plugincpl131_10.cpl
Script: Quarantine, Delete, BC delete
JavaPluginCopyright ¨ 2000
C:\WINNT\system32\STYLEMAN.CPL
Script: Quarantine, Delete, BC delete
Autodesk Hardcopy Plotter ManagerCopyright (C) 1998-1999 Autodesk, Inc.
Elements detected - 25, recognized as trusted - 22

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 12, recognized as trusted - 12

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
Elements detected - 23, recognized as trusted - 23

Suspicious objects

FileDescriptionType
C:\WINNT\System32\vsdatant.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for Spy.WindTangent
C:\WINNT\wt\webdriver\4.1.1\webdriver.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for Spy.WindTangent


AVZ Antiviral Toolkit log; AVZ version is 4.29
Scanning started at 2/10/2008 10:06:39 AM
Database loaded: signatures - 149090, NN profile(s) - 2, microprograms of healing - 55, signature database released 09.02.2008 22:28
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 68697
Heuristic analyzer mode: Maximum heuristics level
Healing mode: disabled
Windows version: 5.0.2195, Service Pack 3 ; AVZ is launched with administrator rights
System Restore: enabled
1. Searching for Rootkits and programs intercepting API functions
 >>>> Probable masking of executable file's name 1340 superantispyware.exe, real name - SUPERAntiSpywar
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=080820)
 Kernel ntoskrnl.exe found in memory at address 80400000
   SDT = 80480820
   KiST = 80472128 (248)
Function NtConnectPort (1B) intercepted (804C5930->BE9E8E60), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreateFile (20) intercepted (804A6FB2->BE9E5820), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreateKey (23) intercepted (80511CAA->BE9F0690), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreatePort (28) intercepted (804C642C->BE9E91F0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreateProcess (29) intercepted (804E20C4->BE9EF480), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreateSection (2B) intercepted (804CAF6A->BE9F2CE0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtCreateWaitablePort (31) intercepted (804C644A->BE9E92D0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtDeleteFile (34) intercepted (804A0D36->BE9E5EA0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtDeleteKey (35) intercepted (8051206E->BE9F16A0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtDeleteValueKey (37) intercepted (8051228A->BE9F12E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtDuplicateObject (3A) intercepted (804D6002->BE9EF1F0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtLoadKey (56) intercepted (805140B0->BE9F19E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtOpenFile (64) intercepted (804A8256->BE9E5CF0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtOpenProcess (6A) intercepted (804DE984->BE9EEF40), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtOpenThread (6F) intercepted (804DEC44->BE9EED60), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtReplaceKey (A9) intercepted (80514564->BE9F1CD0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtRequestWaitReplyPort (B0) intercepted (804C4D48->BE9E8B00), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtRestoreKey (B4) intercepted (80513A56->BE9F1F80), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtSecureConnectPort (B8) intercepted (80433698->BE9E9010), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtSetInformationFile (C2) intercepted (804A91FA->BE9E6010), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtSetValueKey (D7) intercepted (80513DF4->BE9F0E67), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Function NtTerminateProcess (E0) intercepted (804E312C->BE9EF8E0), hook C:\WINNT\System32\vsdatant.sys, driver recognized as trusted
Functions checked: 248, intercepted: 22, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
2. Scanning memory
 Number of processes found: 29
Analyzer: process under analysis is 552 C:\WINNT\system32\LEXBCES.EXE
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
Analyzer: process under analysis is 628 C:\WINNT\system32\LEXPPS.EXE
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Located in system folder
[ES]:Loads RASAPI DLL - may use dialing ?
Analyzer: process under analysis is 1296 C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
Analyzer: process under analysis is 1316 C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
[ES]:Application has no visible windows
Analyzer: process under analysis is 1324 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[ES]:Contains network functionality
[ES]:Application has no visible windows
[ES]:Registered in autoruns !!
 Number of modules loaded: 281
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
>>> C:\Program Files\WildTangent\Apps\CDA\CDALogger0402.dll HSC: suspicion for Spy.WindTangent
>>> C:\WINNT\wt\webdriver\4.1.1\webdriver.dll HSC: suspicion for Spy.WindTangent
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry Service)
>> Services: potentially dangerous service allowed: TlntSvr (Telnet)
>> Services: potentially dangerous service allowed: Messenger (Messenger)
>> Services: potentially dangerous service allowed: Alerter (Alerter)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>>> Security: Internet Explorer allows automatic queries of ActiveX administrative elements
>> Security: terminal connections to the PC are allowed
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Internet Explorer - automatic queries of ActiveX operating elements are allowed
Checking - complete
Files scanned: 310, extracted from archives: 0, malicious software found 0, suspicions - 0
Scanning finished at 2/10/2008 10:07:21 AM
Time of scanning: 00:00:44
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list