AVZ 4.30 http://z-oleg.com/secur/avz/
File name | PID | Description | Copyright | MD5 | Information
c:\program files\lavasoft\ad-aware 2007\aawservice.exe | Script: Quarantine, Delete, BC delete, Terminate 1804 | Ad-Aware 2007 Service | Copyright (C) 2007 | ?? | 593.34 kb, rsAh, | created: 3/19/2008 5:08:58 PM, modified: 3/19/2008 5:08:58 PM Command line: "C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe" c:\program files\aim\aim.exe | Script: Quarantine, Delete, BC delete, Terminate 3712 | AOL Instant Messenger | Copyright © 1996-2005 America Online, Inc. | ?? | 65.59 kb, rsAh, | created: 12/21/2005 9:05:20 PM, modified: 8/5/2005 4:08:26 PM Command line: "C:\Program Files\AIM\aim.exe" -cnetwait.odl c:\windows\explorer.exe | Script: Quarantine, Delete, BC delete, Terminate 692 | Windows Explorer | © Microsoft Corporation. All rights reserved. | ?? | 1009.00 kb, rsAh, | created: 9/7/2004 2:53:54 PM, modified: 6/13/2007 6:23:07 AM Command line: C:\WINDOWS\Explorer.EXE c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe | Script: Quarantine, Delete, BC delete, Terminate 3704 | GoogleToolbarNotifier | Copyright © 2005-2007 | ?? | 67.24 kb, rsAh, | created: 6/21/2007 8:28:28 AM, modified: 6/21/2007 8:28:28 AM Command line: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" c:\program files\internet explorer\iexplore.exe | Script: Quarantine, Delete, BC delete, Terminate 1520 | Internet Explorer | © Microsoft Corporation. All rights reserved. | ?? | 611.00 kb, rsAh, | created: 9/7/2004 3:15:27 PM, modified: 2/29/2008 4:55:46 AM Command line: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" http://login.yahoo.com/config/reset_cookies_token?.token=6p5KUOkW3ggXAwMK5fMdMHu2Qp6jsZTI0M_QUbpH1TLC.IvcwsUtsdeJZ6.9Aak7rznVCVUHuwbkxYG76ISaF0NdsMAetADC75by6pe1wb2ym6IbwENRXzPJOIIRd4LX0fiEGlgheJ5TzCujE.lfppwUjOXEBzBlilJjl8J9jLQqKt_ohakAs9Qvjgf2AC_bBpuFem5z6ritzOybE5jvqoF2nax75Y2MZJbvBZwk5D9hsSzfOe1edh6wMRyKDMPpnh_1mKIVZVJ2JVy7WOoeaV_08VfNLQuwQ76W5bwUeXZg7nH4c5zo60Nb4pzYHYGkmgGAzfbHha7zbncELer4Qyriu2rzQv0FB1iWhwoB6wWnqRdoj3P4i.eLiYtbe7ZcKE0fp5gJV.e_A86o3Ngk1MoZfr7c2ULnPkvG4oQW3TEI7.f1j6CBFWb_PBfj64XCp1Yi1NZ78kbiaw1LBOsR3VgfoCs3k4sHtWf.usdkjj9Sjb0rhybalSA0KEIb3.pE2FRF73fApTc5ykPLukqT4i39KpmynC7jb13Iyt3jlurfsjdk1CoaWFHPYO.lX1cafWP61my2GPcstldQ3Ow- &.done=http://us.rd.yahoo.com/messenger/client/%3fhttp://mail.yahoo.com/ c:\program files\quicktime\qttask.exe | Script: Quarantine, Delete, BC delete, Terminate 3632 | QuickTime Task | Copyright Apple Inc. 1989-2007 | ?? | 276.00 kb, rsAh, | created: 4/27/2007 9:41:54 AM, modified: 4/27/2007 9:41:54 AM Command line: "C:\Program Files\QuickTime\qttask.exe" -atboottime c:\program files\symantec antivirus\rtvscan.exe | Script: Quarantine, Delete, BC delete, Terminate 212 | Symantec AntiVirus | Copyright 1991 - 2005 Symantec Corporation. All rights reserved. | ?? | 1666.19 kb, rsAh, | created: 4/17/2005 1:30:40 PM, modified: 4/17/2005 1:30:40 PM Command line: "C:\Program Files\Symantec AntiVirus\Rtvscan.exe" c:\windows\system32\spoolsv.exe | Script: Quarantine, Delete, BC delete, Terminate 808 | Spooler SubSystem App | © Microsoft Corporation. All rights reserved. | ?? | 56.50 kb, rsAh, | created: 9/7/2004 2:54:01 PM, modified: 6/10/2005 7:53:32 PM Command line: C:\WINDOWS\system32\spoolsv.exe c:\program files\sony\sony picture utility\volumewatcher\spuvolumewatcher.exe | Script: Quarantine, Delete, BC delete, Terminate 656 | Media Check Tool | Copyright 2006 Sony Corporation | ?? | 336.00 kb, rsAh, | created: 12/31/2007 9:27:57 AM, modified: 1/15/2007 2:23:48 PM Command line: "C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe" /nobaloononstart c:\program files\superantispyware\superantispyware.exe | Script: Quarantine, Delete, BC delete, Terminate 3848 | SUPERAntiSpyware | Copyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 1447.23 kb, rsAh, | created: 2/29/2008 4:03:46 PM, modified: 2/29/2008 4:03:46 PM Command line: "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" c:\program files\spybot - search & destroy\teatimer.exe | Script: Quarantine, Delete, BC delete, Terminate 3896 | System settings protector | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | ?? | 2048.33 kb, RSAH, | created: 12/18/2005 10:02:51 PM, modified: 1/28/2008 11:43:40 AM Command line: "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" c:\progra~1\webshots\webshots.scr | Script: Quarantine, Delete, BC delete, Terminate 2708 | Webshots Photo Manager | Copyright (C) 2006 | ?? | 1612.00 kb, rsAh, | created: 12/18/2005 6:07:26 PM, modified: 10/9/2006 1:56:34 PM Command line: C:\PROGRA~1\Webshots\Webshots.scr /t c:\windows\system32\winlogon.exe | Script: Quarantine, Delete, BC delete, Terminate 864 | Windows NT Logon Application | © Microsoft Corporation. All rights reserved. | ?? | 490.50 kb, rsAh, | created: 9/7/2004 2:54:02 PM, modified: 8/10/2004 8:00:00 AM Command line: winlogon.exe c:\progra~1\yahoo!\messen~1\yahoom~1.exe | Script: Quarantine, Delete, BC delete, Terminate 3800 | Yahoo! Messenger | (c) 1998-2007 Yahoo! Inc. All rights reserved. | ?? | 3721.23 kb, rsAh, | created: 12/15/2006 11:45:17 AM, modified: 12/17/2007 6:13:36 PM Command line: "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet c:\progra~1\yahoo!\browser\ycommon.exe | Script: Quarantine, Delete, BC delete, Terminate 680 | YCommon Exe Module | Copyright 2003-2006 Yahoo! Inc. | ?? | 196.00 kb, rsAh, | created: 12/30/2007 6:29:17 PM, modified: 3/3/2006 3:18:10 PM Command line: C:\PROGRA~1\Yahoo!\browser\ycommon.exe -Embedding c:\program files\yahoo!\yahoo! music jukebox\ymetray.exe | Script: Quarantine, Delete, BC delete, Terminate 276 | Yahoo! Music Jukebox Tray Application | Copyright © Yahoo! 2058-2007 | ?? | 53.23 kb, rsAh, | created: 2/5/2008 3:29:20 PM, modified: 2/5/2008 3:29:20 PM Command line: "C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe" yahoomusicengine -preload c:\windows\zhotkey.exe | Script: Quarantine, Delete, BC delete, Terminate 3600 | Multimedia Keyboard Driver | Copyright (c) 2004. | ?? | 530.50 kb, rsAh, | created: 9/7/2004 5:43:07 PM, modified: 5/17/2004 9:30:04 PM Command line: "C:\WINDOWS\zHotkey.exe" Detected:44, recognized as trusted 34
| |
Module name | Handle | Description | Copyright | MD5 | Used by processes
C:\Program Files\AIM\aim.exe | Script: Quarantine, Delete, BC delete 4194304 | AOL Instant Messenger | Copyright © 1996-2005 America Online, Inc. | ?? | 3712
| C:\Program Files\AIM\AIM_xmlp.dll | Script: Quarantine, Delete, BC delete 536870912 | | | -- | 3712
| C:\Program Files\AIM\aimapi.dll | Script: Quarantine, Delete, BC delete 310378496 | AIM API DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\AIMAX.dll | Script: Quarantine, Delete, BC delete 306708480 | | | -- | 3712
| C:\Program Files\AIM\AimCoreSvcs.dll | Script: Quarantine, Delete, BC delete 310902784 | Rendezvous External Applications Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\aimres.dll | Script: Quarantine, Delete, BC delete 311951360 | Aim Resources | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\AimSecondarySvcs.dll | Script: Quarantine, Delete, BC delete 311427072 | File Xfer Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\AIMToday.dll | Script: Quarantine, Delete, BC delete 268435456 | | | -- | 3712
| C:\Program Files\AIM\alertui.ocm | Script: Quarantine, Delete, BC delete 307232768 | Rendezvous External Applications Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\ATE32.dll | Script: Quarantine, Delete, BC delete 301989888 | Rich Text Control DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\ateima32.dll | Script: Quarantine, Delete, BC delete 302514176 | Image Encoder/Decoder DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\browse.ocm | Script: Quarantine, Delete, BC delete 290455552 | Browser Interface Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\buddyui.ocm | Script: Quarantine, Delete, BC delete 287834112 | Buddy-List UI Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\chatui.ocm | Script: Quarantine, Delete, BC delete 296747008 | Chat Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\CoolBos.dll | Script: Quarantine, Delete, BC delete 1074790400 | CoolBos Component Server | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\CoolBucky.dll | Script: Quarantine, Delete, BC delete 1075052544 | CoolBucky Component Server | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\CoolHttp.dll | Script: Quarantine, Delete, BC delete 1076625408 | CoolHttp Component Server | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\CoolSecNss.dll | Script: Quarantine, Delete, BC delete 1076363264 | CoolPeer Component Server | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\CoolSocket.dll | Script: Quarantine, Delete, BC delete 1076101120 | CoolSocket Component Server | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\DUNZIP32.dll | Script: Quarantine, Delete, BC delete 805306368 | DynaZIP-32 Multi-Threading UnZIP DLL | Copyright © 1995 - 2002 by Inner Media, Inc. All Rights Reserved. | -- | 3712
| C:\Program Files\AIM\icbmui.ocm | Script: Quarantine, Delete, BC delete 288882688 | Instant-Message UI Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\idlemon.dll | Script: Quarantine, Delete, BC delete 469762048 | Idle Monitor DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\inetsocket.dll | Script: Quarantine, Delete, BC delete 306184192 | INETsocket DLL | Copyright (C) 1998 | -- | 3712
| C:\Program Files\AIM\locateui.ocm | Script: Quarantine, Delete, BC delete 289931264 | Locate UI Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\miscui.ocm | Script: Quarantine, Delete, BC delete 292028416 | MiscUI Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\nspr4.dll | Script: Quarantine, Delete, BC delete 30212096 | NSPR Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\nss3.dll | Script: Quarantine, Delete, BC delete 19005440 | NSS Base Library | Copyright © 1994-2001 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\nssckbi.dll | Script: Quarantine, Delete, BC delete 31719424 | | | -- | 3712
| C:\Program Files\AIM\NTP.ocm | Script: Quarantine, Delete, BC delete 308281344 | N2P interface module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\oscarui.dll | Script: Quarantine, Delete, BC delete 304087040 | UI Utilities DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\osclogin.ocm | Script: Quarantine, Delete, BC delete 286261248 | Login Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\oscmail.ocm | Script: Quarantine, Delete, BC delete 308805632 | Rendezvous External Applications Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\oscmain.ocm | Script: Quarantine, Delete, BC delete 285212672 | Main Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\oscore.dll | Script: Quarantine, Delete, BC delete 303562752 | Core Services DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\oscres.dll | Script: Quarantine, Delete, BC delete 305135616 | | | -- | 3712
| C:\Program Files\AIM\oscsrch.ocm | Script: Quarantine, Delete, BC delete 299368448 | Oscar Search Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\plc4.dll | Script: Quarantine, Delete, BC delete 19791872 | PLC Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\plds4.dll | Script: Quarantine, Delete, BC delete 19857408 | PLDS Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\popup.ocm | Script: Quarantine, Delete, BC delete 294125568 | Popup Ads Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\proto.ocm | Script: Quarantine, Delete, BC delete 285736960 | Protocol Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\rtvideo.dll | Script: Quarantine, Delete, BC delete 12517376 | AOL Live Video | Copyright © 1996-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\rvapps.ocm | Script: Quarantine, Delete, BC delete 300417024 | Rendezvous External Applications Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\sb.dll | Script: Quarantine, Delete, BC delete 1670905856 | SB | Copyright (C) America Online, Inc. 1999 - 2004 | -- | 3712
| C:\Program Files\AIM\smime3.dll | Script: Quarantine, Delete, BC delete 30539776 | NSS S/MIME Library | Copyright © 1994-2001 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\softokn3.dll | Script: Quarantine, Delete, BC delete 19398656 | NSS PKCS #11 Library | Copyright © 1994-2001 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\ssl3.dll | Script: Quarantine, Delete, BC delete 30408704 | NSS SSL Library | Copyright © 1994-2001 Netscape Communications Corporation | -- | 3712
| C:\Program Files\AIM\startup.ocm | Script: Quarantine, Delete, BC delete 296222720 | Startup Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\stats.ocm | Script: Quarantine, Delete, BC delete 299892736 | | | -- | 3712
| C:\Program Files\AIM\ticker.ocm | Script: Quarantine, Delete, BC delete 300941312 | Ticker Module | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\WNDUTILS.dll | Script: Quarantine, Delete, BC delete 304611328 | UI Utilities DLL | Copyright © 1996-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\Xpcs.dll | Script: Quarantine, Delete, BC delete 1074003968 | Xpcs Runtime Library | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\Xprt.dll | Script: Quarantine, Delete, BC delete 1073741824 | Xprt Runtime Library | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\xprt5.dll | Script: Quarantine, Delete, BC delete 3473408 | XPRT Runtime Library | Copyright (c) 1998-2005 America Online, Inc. | -- | 3712
| C:\Program Files\AIM\Xptl.dll | Script: Quarantine, Delete, BC delete 1074266112 | Xptl Runtime Library | Copyright (c) 1998-2004 America Online, Inc. | -- | 3712
| C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll | Script: Quarantine, Delete, BC delete 14548992 | ewido anti-spyware guard | Copyright © 2005 Anti-Malware Development a.s. | -- | 692
| C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\gtn.dll | Script: Quarantine, Delete, BC delete 268435456 | GoogleToolbarNotifier | Copyright © 2005-2008 | -- | 3704
| C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll | Script: Quarantine, Delete, BC delete 12582912 | GoogleToolbarNotifier | Copyright © 2005-2008 | -- | 3704, 1520
| C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll | Script: Quarantine, Delete, BC delete 1845493760 | | | -- | 1520
| C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll | Script: Quarantine, Delete, BC delete 18546688 | dBShell Module | Copyright 2005 | -- | 692
| C:\Program Files\QuickTime\qttask.exe | Script: Quarantine, Delete, BC delete 4194304 | QuickTime Task | Copyright Apple Inc. 1989-2007 | ?? | 3632
| C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe | Script: Quarantine, Delete, BC delete 4194304 | Media Check Tool | Copyright 2006 Sony Corporation | ?? | 656
| C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcherLOC.DLL | Script: Quarantine, Delete, BC delete 268435456 | Media Check Tool | Copyright 2006 Sony Corporation | -- | 656
| C:\Program Files\Spybot - Search & Destroy\advcheck.dll | Script: Quarantine, Delete, BC delete 51642368 | Dateiüberprüfungs-Bibliothek | © 2003-2008 Safer Networking Limited. Alle Rechte vorbehalten. | -- | 3896
| C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe | Script: Quarantine, Delete, BC delete 4194304 | System settings protector | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | ?? | 3896
| C:\Program Files\SUPERAntiSpyware\deupx.dll | Script: Quarantine, Delete, BC delete 268435456 | deupx.dll | Copyright (C) 2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 3848
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete 14745600 | ShellExecuteHook | (c) Copyright 2004-2006 SuperAdBlocker.com | -- | 692
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete 268435456 | SUPERAntiSpyware WinLogon Processor | Copyright (C) 2005-2007 SUPERAntiSpyware.com and SUPERAdBlocker.com | -- | 864
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete 4194304 | SUPERAntiSpyware | Copyright (C) 2005-2008 by SUPERAntiSpyware.com and SUPERAdBlocker.com | ?? | 3848
| C:\Program Files\Yahoo!\Common\YIeTagBm.dll | Script: Quarantine, Delete, BC delete 1646264320 | IE Shortcuts | Copyright (C) 2005 Yahoo! Inc. | -- | 1520
| C:\Program Files\Yahoo!\Messenger\ft60.dll | Script: Quarantine, Delete, BC delete 1611137024 | File Transfer Module | (c) 2003-07 Yahoo! Inc. All rights reserved. | -- | 3800
| C:\Program Files\Yahoo!\Messenger\YPagerChecker.dll | Script: Quarantine, Delete, BC delete 1627979776 | Yahoo! Messenger Checker | (c) 2005-07 Yahoo! Inc. All rights reserved. | -- | 1520
| C:\Program Files\Yahoo!\Messenger\ypagerps4.DLL | Script: Quarantine, Delete, BC delete 1628110848 | YPagerPS Module (COM Interface) | (c) 1998-2006 Yahoo! Inc. All rights reserved. | -- | 3800, 680
| C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Lang\att-en-us\ymetray-att-en-us.dll | Script: Quarantine, Delete, BC delete 268435456 | | | -- | 276
| C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe | Script: Quarantine, Delete, BC delete 4194304 | Yahoo! Music Jukebox Tray Application | Copyright © Yahoo! 2058-2007 | ?? | 276
| C:\PROGRA~1\COMMON~1\ArcSoft\MPEGEN~1\ArcSpl.ax | Script: Quarantine, Delete, BC delete 44105728 | MPGSplitter Filter | Copyright (C) ArcSoft Co. 2002-2006 | -- | 3712
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\ccEraser.dll | Script: Quarantine, Delete, BC delete 1831862272 | Symantec Eraser Engine | Copyright (c) 2000-2007 Symantec Corporation. All rights reserved. | -- | 212
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\ecmsvr32.dll | Script: Quarantine, Delete, BC delete 1761869824 | Symantec Engine Common Object Model Server | Copyright (C) 1991-2006 Symantec Corporation. | -- | 212
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\NAVENG32.DLL | Script: Quarantine, Delete, BC delete 1764491264 | AV Engine | Copyright (C) 1991-2007 Symantec Corporation. | -- | 212
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\NAVEX32a.DLL | Script: Quarantine, Delete, BC delete 1762656256 | AV Engine | Copyright (C) 1991-2007 Symantec Corporation. | -- | 212
| C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL | Script: Quarantine, Delete, BC delete 1090519040 | | | -- | 1520
| C:\PROGRA~1\SPYBOT~1\SDHelper.dll | Script: Quarantine, Delete, BC delete 64684032 | SBSD IE Protection | © 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten. | -- | 692, 1520
| C:\PROGRA~1\Webshots\Webshots.scr | Script: Quarantine, Delete, BC delete 4194304 | Webshots Photo Manager | Copyright (C) 2006 | ?? | 2708
| C:\PROGRA~1\Yahoo!\MESSEN~1\clientmanager.dll | Script: Quarantine, Delete, BC delete 1610874880 | | | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\GIPSVoiceEngineDLL_MD.dll | Script: Quarantine, Delete, BC delete 1611399168 | | | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\id3lib.dll | Script: Quarantine, Delete, BC delete 1612054528 | ID3lib Dynamic Link Library | Copyright © 2002 Thijmen Klok | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\libexpat.dll | Script: Quarantine, Delete, BC delete 1612840960 | | | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\nspr4.dll | Script: Quarantine, Delete, BC delete 1613234176 | NSPR Library | Copyright © 1996-2000 Netscape Communications Corporation | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\pcre.dll | Script: Quarantine, Delete, BC delete 1709965312 | Pcre: Perl-compatible regular-expression library | © 2001 University of Cambridge | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\res_msgr.dll | Script: Quarantine, Delete, BC delete 1614479360 | Resource Module | (c) 1998-2007 Yahoo! Inc. All rights reserved. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\RGX.dll | Script: Quarantine, Delete, BC delete 1615790080 | RGX | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\rmc_audio.dll | Script: Quarantine, Delete, BC delete 1615986688 | rmc_audio | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE | Script: Quarantine, Delete, BC delete 4194304 | Yahoo! Messenger | (c) 1998-2007 Yahoo! Inc. All rights reserved. | ?? | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YAlertCenterM.DLL | Script: Quarantine, Delete, BC delete 1618345984 | Yahoo! Alert Center | (c) Yahoo! Inc. All rights reserved. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YCPFoundation.dll | Script: Quarantine, Delete, BC delete 1618542592 | YCPFoundation | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YCPSSL.dll | Script: Quarantine, Delete, BC delete 1619591168 | YCPSSL | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YHTTP.dll | Script: Quarantine, Delete, BC delete 1620377600 | YHTTP | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YImage.dll | Script: Quarantine, Delete, BC delete 1620639744 | YImage Module | (c) 2004-07 Yahoo! Inc. All rights reserved. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YIniDom.dll | Script: Quarantine, Delete, BC delete 1620967424 | YIniDom | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\ylog.dll | Script: Quarantine, Delete, BC delete 1621032960 | ylog | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\ymdm_audio.dll | Script: Quarantine, Delete, BC delete 1621098496 | ymdm_audio | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YML.dll | Script: Quarantine, Delete, BC delete 1621426176 | YML Module | (c) 2003-07 Yahoo! Inc. All rights reserved. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\ymsdk.dll | Script: Quarantine, Delete, BC delete 1621491712 | ymsdk | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YMSGLite.dll | Script: Quarantine, Delete, BC delete 1626931200 | YMSGLite | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\YPluginRegistry.dll | Script: Quarantine, Delete, BC delete 1628241920 | YPluginRegistry | Copyright (C) 2007, Yahoo! Inc | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll | Script: Quarantine, Delete, BC delete 1628766208 | yui Dynamic Link Library | Copyright (C) 2007 Yahoo! Inc. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\yv_res.dll | Script: Quarantine, Delete, BC delete 1646526464 | Voice Resources Module | (c) 2005-07 Yahoo! Inc. All rights reserved. | -- | 3800
| C:\PROGRA~1\Yahoo!\MESSEN~1\yvoiceui.dll | Script: Quarantine, Delete, BC delete 1646723072 | YVoiceUI Module | (c) 2005-07 Yahoo! Inc. All rights reserved. | -- | 3800
| c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll | Script: Quarantine, Delete, BC delete 1676673024 | Microsoft .NET IE MIME Filter | © Microsoft Corporation. All rights reserved. | -- | 1520
| C:\WINDOWS\system32\Macromed\Common\SwSupport.dll | Script: Quarantine, Delete, BC delete 1761607680 | Director Support | Copyright © 1985-2004 Macromedia, Inc. | -- | 3800
| C:\WINDOWS\system32\mdimon.dll | Script: Quarantine, Delete, BC delete 10092544 | Microsoft® Document Imaging | Copyright (C) Microsoft Corp. 2001-2004 | -- | 808
| C:\WINDOWS\system32\mscoree.dll | Script: Quarantine, Delete, BC delete 2030043136 | Microsoft .NET Runtime Execution Engine | © Microsoft Corporation. All rights reserved. | -- | 1520
| C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll | Script: Quarantine, Delete, BC delete 14155776 | Microsoft® Document Imaging | Copyright (C) Microsoft Corp. 2001-2004 | -- | 808
| C:\WINDOWS\system32\WgaLogon.dll | Script: Quarantine, Delete, BC delete 21102592 | Windows Genuine Advantage Notification | © 1995-2006 Microsoft Corporation | -- | 864
| C:\WINDOWS\zHotkey.exe | Script: Quarantine, Delete, BC delete 4194304 | Multimedia Keyboard Driver | Copyright (c) 2004. | ?? | 3600
| Modules detected:525, recognized as trusted 411
| |
Module | Base address | Size in memory | Description | Manufacturer
.sys | Script: Quarantine, Delete, BC delete F74F1000 | 018000 (98304) |
| C:\WINDOWS\system32\drivers\Afc.sys | Script: Quarantine, Delete, BC delete F798D000 | 008000 (32768) | Arcsoft(R) ASPI Shell | (C) Arcsoft, Inc. 1999-2005. All rights reserved.
| C:\WINDOWS\System32\Drivers\AnyDVD.sys | Script: Quarantine, Delete, BC delete F7995000 | 005000 (20480) | AnyDVD Filter Driver | Copyright 2002 - 2006 SlySoft, Inc.
| C:\WINDOWS\System32\Drivers\cdudf_xp.SYS | Script: Quarantine, Delete, BC delete F677C000 | 048000 (294912) | CD-UDF NT Filesystem Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\WINDOWS\System32\Drivers\dump_atapi.sys | Script: Quarantine, Delete, BC delete F6868000 | 018000 (98304) |
| C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS | Script: Quarantine, Delete, BC delete F7B75000 | 002000 (8192) |
| C:\WINDOWS\System32\Drivers\dvd_2K.SYS | Script: Quarantine, Delete, BC delete F79C5000 | 006000 (24576) | DVD-RAM AddOn Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\WINDOWS\System32\Drivers\DVDVRRdr_xp.SYS | Script: Quarantine, Delete, BC delete F6747000 | 023000 (143360) | DVDVR Filesystem Reader Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\Program Files\ewido anti-spyware 4.0\guard.sys | Script: Quarantine, Delete, BC delete F7CF2000 | 001000 (4096) |
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\naveng.sys | Script: Quarantine, Delete, BC delete B911E000 | 013000 (77824) | AV Engine | Copyright (C) 1991-2007 Symantec Corporation.
| C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080504.003\navex15.sys | Script: Quarantine, Delete, BC delete B9131000 | 0D9000 (888832) | AV Engine | Copyright (C) 1991-2007 Symantec Corporation.
| C:\WINDOWS\System32\Drivers\pwd_2k.SYS | Script: Quarantine, Delete, BC delete F6A89000 | 01D000 (118784) | Win2000 Framework for Packet Write Driver | Copyright (c) 1994-2005 Sonic Solutions
| C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS | Script: Quarantine, Delete, BC delete F78F5000 | 007000 (28672) | SASDIFSV | Copyright (C) 2006
| C:\Program Files\SUPERAntiSpyware\SASENUM.SYS | Script: Quarantine, Delete, BC delete F78DD000 | 005000 (20480) | SuperAntiSpyware | (C) Copyright 2004-2006
| C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys | Script: Quarantine, Delete, BC delete F656B000 | 020000 (131072) | SASKUTIL.SYS | Copyright (C) 2006
| C:\WINDOWS\System32\Drivers\sunkfilt39.sys | Script: Quarantine, Delete, BC delete F78D5000 | 008000 (32768) | SunkFilt39 | Copyright 2002 - 2005
| C:\WINDOWS\System32\Drivers\UDFReadr.SYS | Script: Quarantine, Delete, BC delete F66DB000 | 032000 (204800) | CD-UDF NT Filesystem Reader Driver | Copyright (c) 1994-2005 Sonic Solutions
| Modules detected - 165, recognized as trusted - 148
| |
File name | Status | Startup method | Description
C:\PROGRA~1\Webshots\Webshots.scr | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Control Panel\Desktop, scrnsave.exe
| C:\PROGRA~1\Webshots\Webshots.scr | Script: Quarantine, Delete, BC delete Active | File system.ini | C:\WINDOWS\system.ini, boot, SCRNSAVE.EXE
| C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Yahoo! Pager
| C:\Program Files\AIM\aim.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, AIM
| C:\Program Files\Picasa2\PicasaMediaDetector.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_USERS, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, Picasa Media Detector
| C:\Program Files\PrintMaster Platinum 17\Remind.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk,
| C:\Program Files\QuickTime\qttask.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, QuickTime Task
| C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
| C:\Program Files\SUPERAntiSpyware\SASWINLO.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName
| C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SUPERAntiSpyware
| C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\Owner\Start Menu\Programs\Startup\, C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk,
| C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\RunOnce, Spybot - Search & Destroy
| C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SpybotSD TeaTimer
| C:\Program Files\Webshots\Launcher.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\Owner\Start Menu\Programs\Startup\, C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Webshots.lnk,
| C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk,
| C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {57B86673-276A-48B2-BAE7-C6DBB3020EB8}
| C:\Program Files\palmOne\Hotsync.exe | Script: Quarantine, Delete, BC delete Active | Shortcut in Autoruns folder | C:\Documents and Settings\All Users\Start Menu\Programs\Startup\, C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk,
| C:\WINDOWS\system32\mlJDsSMG.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B3102264-D09D-4322-B625-503FBF18DD7E}
| C:\WINDOWS\system32\wmsdkns.exe | Script: Quarantine, Delete, BC delete -- | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit
| C:\WINDOWS\zHotkey.exe | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, CHotkey
| WgaLogon.dll | Script: Quarantine, Delete, BC delete Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName
| autocheck autochk * lsdelete | Script: |