Results of system analysis

AVZ 4.30 http://z-oleg.com/secur/avz/

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\program files\lavasoft\ad-aware\aawservice.exe
Script: Quarantine, Delete, BC delete, Terminate
1848Ad-Aware ServiceCopyright (C) 2008??597.33 kb, rsAh,
created: 5/12/2008 12:38:28 PM,
modified: 6/17/2008 7:37:03 PM
Command line:
"C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe"
c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
2512Application Layer Gateway Service© Microsoft Corporation. All rights reserved.??43.50 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\System32\alg.exe
c:\program files\panda security\panda internet security 2008\apvxdwin.exe
Script: Quarantine, Delete, BC delete, Terminate
1416Platinum permanent protection© Panda 2007??397.30 kb, rsAh,
created: 11/23/2007 9:30:59 AM,
modified: 7/23/2007 7:30:42 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
c:\program files\panda security\panda internet security 2008\avengine.exe
Script: Quarantine, Delete, BC delete, Terminate
1540Enhanced On-Access Anti-Malware Protection.© Panda Software 2007??94.30 kb, rsAh,
created: 11/23/2007 9:30:11 AM,
modified: 7/6/2007 3:14:10 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE"
c:\documents and settings\barry\desktop\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
3572???????????? ??????? AVZ???????????? ??????? AVZ??716.50 kb, rsAh,
created: 6/21/2008 1:00:10 PM,
modified: 4/6/2008 5:22:00 PM
Command line:
"C:\Documents and Settings\Barry\Desktop\avz4\avz.exe"
c:\program files\common files\logishrd\lqcvfx\cocimanager.exe
Script: Quarantine, Delete, BC delete, Terminate
3500Camera Control Interface(c) 1996-2007 Logitech. All rights reserved.??394.27 kb, rsAh,
created: 7/25/2007 5:02:32 PM,
modified: 7/25/2007 5:02:32 PM
Command line:
"C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe" -Embedding
c:\program files\common files\logishrd\lcommgr\communications_helper.exe
Script: Quarantine, Delete, BC delete, Terminate
1616  ??550.77 kb, rsAh,
created: 7/25/2007 5:02:54 PM,
modified: 7/25/2007 5:02:54 PM
Command line:
"C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
c:\windows\system32\csrss.exe
Script: Quarantine, Delete, BC delete, Terminate
1024Client Server Runtime Process© Microsoft Corporation. All rights reserved.??6.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
c:\windows\system32\ctfmon.exe
Script: Quarantine, Delete, BC delete, Terminate
648CTF Loader© Microsoft Corporation. All rights reserved.??15.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
"C:\WINDOWS\system32\ctfmon.exe"
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
492Windows Explorer© Microsoft Corporation. All rights reserved.??1009.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 6/13/2007 6:23:07 AM
Command line:
C:\WINDOWS\Explorer.EXE
c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
3544FirefoxMozilla Corporation??7481.11 kb, rsAh,
created: 12/29/2006 10:10:05 AM,
modified: 4/17/2008 4:42:15 PM
Command line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
c:\program files\java\jre1.6.0_05\bin\jusched.exe
Script: Quarantine, Delete, BC delete, Terminate
1788Java(TM) Platform SE binaryCopyright © 2004??141.39 kb, rsAh,
created: 4/18/2008 6:47:26 AM,
modified: 2/22/2008 4:25:21 AM
Command line:
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
1104LSA Shell (Export Version)© Microsoft Corporation. All rights reserved.??13.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\lsass.exe
c:\program files\common files\logishrd\lvcomser\lvcomser.exe
Script: Quarantine, Delete, BC delete, Terminate
1668Logitech Video COM Service(c) 1996-2007 Logitech. All rights reserved.??182.52 kb, rsAh,
created: 7/20/2007 1:38:54 AM,
modified: 7/20/2007 1:38:54 AM
Command line:
"C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe"
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
Script: Quarantine, Delete, BC delete, Terminate
1916Machine Debug Manager© Microsoft Corporation. All rights reserved.??314.57 kb, rsAh,
created: 6/20/2003 12:25:00 AM,
modified: 6/20/2003 12:25:00 AM
Command line:
"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
c:\program files\panda security\panda internet security 2008\pavbckpt.exe
Script: Quarantine, Delete, BC delete, Terminate
3216PavBckPT Aplicación© Panda Software 2007??109.30 kb, rsAh,
created: 11/23/2007 9:30:44 AM,
modified: 7/26/2007 8:47:30 AM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe" C:\Program Files\Panda Security\Panda Internet Security 2008\
c:\program files\panda security\panda internet security 2008\pavfnsvr.exe
Script: Quarantine, Delete, BC delete, Terminate
280Panda Function Service© Panda 2007??169.30 kb, rsAh,
created: 11/23/2007 9:30:37 AM,
modified: 7/12/2007 12:47:26 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe"
c:\program files\common files\panda software\pavshld\pavprsrv.exe
Script: Quarantine, Delete, BC delete, Terminate
1476Panda Process Protection ServiceCopyright © Panda Software International 2007??61.55 kb, rsAh,
created: 11/23/2007 9:22:14 AM,
modified: 6/14/2007 11:38:02 AM
Command line:
"C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe"
c:\program files\panda security\panda internet security 2008\pavsrv51.exe
Script: Quarantine, Delete, BC delete, Terminate
1896Enhanced On-Access Anti-Malware Service.© Panda Software 2007??144.80 kb, rsAh,
created: 11/23/2007 9:30:14 AM,
modified: 7/16/2007 4:14:22 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe"
c:\program files\spyware doctor\pctsauxs.exe
Script: Quarantine, Delete, BC delete, Terminate
2564PC Tools Auxiliary ServiceCopyright 2008 PC Tools. All rights reserved.??329.88 kb, rsAh,
created: 5/25/2008 8:41:35 PM,
modified: 4/10/2008 3:14:26 PM
Command line:
"C:\Program Files\Spyware Doctor\pctsAuxs.exe"
c:\program files\spyware doctor\pctssvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2780PC Tools Security ServiceCopyright © 2008 PC Tools. All rights reserved.??993.38 kb, rsAh,
created: 5/25/2008 8:41:35 PM,
modified: 4/17/2008 2:19:02 PM
Command line:
"C:\Program Files\Spyware Doctor\pctsSvc.exe"
c:\program files\spyware doctor\pctstray.exe
Script: Quarantine, Delete, BC delete, Terminate
2020PC Tools Tray ApplicationCopyright © 2008 PC Tools. All rights reserved.??1081.88 kb, rsAh,
created: 5/25/2008 8:41:34 PM,
modified: 4/10/2008 3:14:30 PM
Command line:
"C:\Program Files\Spyware Doctor\pctsTray.exe"
c:\program files\panda security\panda internet security 2008\psctrls.exe
Script: Quarantine, Delete, BC delete, Terminate
680Panda Software Controler© Panda 2007??165.30 kb, rsAh,
created: 11/23/2007 9:31:49 AM,
modified: 7/12/2007 12:47:30 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe"
c:\program files\panda security\panda internet security 2008\firewall\pshost.exe
Script: Quarantine, Delete, BC delete, Terminate
140Panda Host ServiceCopyright © 2007 Panda Software??221.55 kb, rsAh,
created: 11/23/2007 9:30:23 AM,
modified: 4/4/2007 12:45:08 PM
Command line:
"c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE"
c:\program files\panda security\panda internet security 2008\psimsvc.exe
Script: Quarantine, Delete, BC delete, Terminate
2156Panda Interface Manager Service© Panda Software 2007??106.05 kb, rsAh,
created: 11/23/2007 9:30:53 AM,
modified: 5/24/2007 11:31:26 AM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe"
c:\program files\panda security\panda internet security 2008\antispam\pskmssvc.exe
Script: Quarantine, Delete, BC delete, Terminate
1232Anti-malware protection service library executable© Panda Software 2007??65.55 kb, rsAh,
created: 11/23/2007 9:30:32 AM,
modified: 1/15/2007 3:42:16 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe"
c:\program files\logitech\quickcam\quickcam.exe
Script: Quarantine, Delete, BC delete, Terminate
1760  ??1980.27 kb, rsAh,
created: 7/25/2007 5:06:30 PM,
modified: 7/25/2007 5:06:30 PM
Command line:
"C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
c:\windows\runservice.exe
Script: Quarantine, Delete, BC delete, Terminate
224  ??2.50 kb, rsAh,
created: 3/18/2007 11:31:50 AM,
modified: 3/18/2007 11:31:50 AM
Command line:
C:\WINDOWS\runservice.exe
c:\windows\system32\services.exe
Script: Quarantine, Delete, BC delete, Terminate
1092Services and Controller app© Microsoft Corporation. All rights reserved.??105.50 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\services.exe
c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
632Spooler SubSystem App© Microsoft Corporation. All rights reserved.??56.50 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 6/10/2005 7:53:32 PM
Command line:
C:\WINDOWS\system32\spoolsv.exe
c:\program files\panda security\panda internet security 2008\srvload.exe
Script: Quarantine, Delete, BC delete, Terminate
2040Panda AntiSpam Trainer© Panda Software 2008??89.30 kb, rsAh,
created: 11/23/2007 9:30:18 AM,
modified: 6/20/2007 1:32:28 PM
Command line:
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1468Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1708Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost.exe -k NetworkService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
964Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1268Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost -k DcomLaunch
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
1344Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost -k rpcss
c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
4004Generic Host Process for Win32 Services© Microsoft Corporation. All rights reserved.??14.00 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\program files\spybot - search & destroy\teatimer.exe
Script: Quarantine, Delete, BC delete, Terminate
752System settings protector© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.??2048.33 kb, RSAH,
created: 6/17/2008 7:17:32 PM,
modified: 1/28/2008 11:43:40 AM
Command line:
"C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
c:\program files\panda security\panda internet security 2008\tpsrv.exe
Script: Quarantine, Delete, BC delete, Terminate
1496TPSrv Application© Panda Software 2007??395.30 kb, rsAh,
created: 11/23/2007 9:30:38 AM,
modified: 7/2/2007 1:14:38 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe"
c:\program files\panda security\panda internet security 2008\webproxy.exe
Script: Quarantine, Delete, BC delete, Terminate
2396Internet resident proxy© Panda Software 2007??81.55 kb, rsAh,
created: 11/23/2007 9:30:19 AM,
modified: 6/7/2007 5:29:22 PM
Command line:
"C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe" oso_XGCGLR
c:\windows\system32\winlogon.exe
Script: Quarantine, Delete, BC delete, Terminate
1048Windows NT Logon Application© Microsoft Corporation. All rights reserved.??490.50 kb, rsAh,
created: 8/4/2004 8:00:00 AM,
modified: 8/4/2004 8:00:00 AM
Command line:
winlogon.exe
Detected:43, recognized as trusted 19
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Documents and Settings\Barry\Application Data\Mozilla\Firefox\Profiles\x8w6tm76.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
Script: Quarantine, Delete, BC delete
46596096  --3544
C:\Documents and Settings\Barry\Application Data\Mozilla\Firefox\Profiles\x8w6tm76.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
Script: Quarantine, Delete, BC delete
30212096  --3544
C:\Program Files\Common Files\LogiShrd\LComMgr\BRSkypePlugin.dll
Script: Quarantine, Delete, BC delete
42401792LCM Skype Plugin(c) 1996-2007 Logitech. All rights reserved.--1616
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
Script: Quarantine, Delete, BC delete
4194304  ??1616
C:\Program Files\Common Files\LogiShrd\LComMgr\DevMngr.dll
Script: Quarantine, Delete, BC delete
268435456  --3500, 1616, 1760
C:\Program Files\Common Files\LogiShrd\LComMgr\LogiCordless.dll
Script: Quarantine, Delete, BC delete
34078720  --1616
C:\Program Files\Common Files\LogiShrd\LComMgr\LogiCordless4001.dll
Script: Quarantine, Delete, BC delete
36503552  --1616
C:\Program Files\Common Files\LogiShrd\LComMgr\LogiVOIPDevicePlugin.dll
Script: Quarantine, Delete, BC delete
39976960  --1616
C:\Program Files\Common Files\LogiShrd\LComMgr\YahooPlugin.dll
Script: Quarantine, Delete, BC delete
42795008LCM Yahoo Plugin(c) 1996-2007 Logitech. All rights reserved.--1616
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
Script: Quarantine, Delete, BC delete
4194304Camera Control Interface(c) 1996-2007 Logitech. All rights reserved.??3500
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManagerPS.dll
Script: Quarantine, Delete, BC delete
23068672COCI Manager Proxy Stub(c) 1996-2007 Logitech. All rights reserved.--3500, 1760
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
Script: Quarantine, Delete, BC delete
4194304Logitech Video COM Service(c) 1996-2007 Logitech. All rights reserved.??1668
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSCli.dll
Script: Quarantine, Delete, BC delete
23265280Medusa Hardware Enumerator(c) 1996-2007 Logitech. All rights reserved.--3500, 1616, 1668, 1760
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSPS.dll
Script: Quarantine, Delete, BC delete
23920640  --3500, 1616, 1668, 1760
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
Script: Quarantine, Delete, BC delete
122683392Panda Process Protection ServiceCopyright © Panda Software International 2007??1476
C:\Program Files\Common Files\Panda Software\PavShld\PAVSHLD.DLL
Script: Quarantine, Delete, BC delete
1034027008PavShldCopyright © Panda Software International 2007--1416, 1540, 280, 1896, 680, 2156, 1232, 2040, 1496, 2396
C:\Program Files\Common Files\Panda Software\PavShld\PROCPROT.DLL
Script: Quarantine, Delete, BC delete
1050673152PandaShield LibraryCopyright © Panda Software International 2007--1416, 1540, 280, 1896, 680, 2156, 1232, 2040, 1496, 2396
C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
268435456PC Tools Layered Service ProviderCopyright PC Tools Research Pty Ltd 2006.--2512, 1416, 3572, 3544, 1104, 2780, 632, 2040, 1468, 1708, 964, 1344, 2396
C:\Program Files\Lavasoft\Ad-Aware\CEAPI.dll
Script: Quarantine, Delete, BC delete
268435456CEAPI Dynamic Link LibraryCopyright (C) 2008--1848
C:\Program Files\Logitech\QuickCam\EFVal.dll
Script: Quarantine, Delete, BC delete
28704768  --3500, 1616, 1760
C:\Program Files\Logitech\QuickCam\LAppRes.dll
Script: Quarantine, Delete, BC delete
268435456  --1760
C:\Program Files\Logitech\QuickCam\LogiMail.dll
Script: Quarantine, Delete, BC delete
18677760Mail Library(c) 1996-2007 Logitech. All rights reserved.--1760
C:\Program Files\Logitech\QuickCam\Quickcam.exe
Script: Quarantine, Delete, BC delete
4194304  ??1760
C:\Program Files\Mozilla Firefox\components\jar50.dll
Script: Quarantine, Delete, BC delete
1610678272 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Mozilla Firefox\components\myspell.dll
Script: Quarantine, Delete, BC delete
1610874880 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Mozilla Firefox\components\spellchk.dll
Script: Quarantine, Delete, BC delete
1610940416 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Mozilla Firefox\firefox.exe
Script: Quarantine, Delete, BC delete
4194304FirefoxMozilla Corporation??3544
C:\Program Files\Mozilla Firefox\freebl3.dll
Script: Quarantine, Delete, BC delete
1611202560NSS freebl Library --3544
C:\Program Files\Mozilla Firefox\js3250.dll
Script: Quarantine, Delete, BC delete
1611464704Netscape 32-bit JavaScript ModuleCopyright Netscape Communications. 1994-96--3544
C:\Program Files\Mozilla Firefox\nspr4.dll
Script: Quarantine, Delete, BC delete
1612316672NSPR LibraryCopyright © 1996-2000 Netscape Communications Corporation--3544
C:\Program Files\Mozilla Firefox\nss3.dll
Script: Quarantine, Delete, BC delete
1612513280NSS Base Library --3544
C:\Program Files\Mozilla Firefox\nssckbi.dll
Script: Quarantine, Delete, BC delete
1612906496NSS Builtin Trusted Root CAs --3544
C:\Program Files\Mozilla Firefox\plc4.dll
Script: Quarantine, Delete, BC delete
1613234176PLC LibraryCopyright © 1996-2000 Netscape Communications Corporation--3544
C:\Program Files\Mozilla Firefox\plds4.dll
Script: Quarantine, Delete, BC delete
1613299712PLDS LibraryCopyright © 1996-2000 Netscape Communications Corporation--3544
C:\Program Files\Mozilla Firefox\smime3.dll
Script: Quarantine, Delete, BC delete
1613430784NSS S/MIME Library --3544
C:\Program Files\Mozilla Firefox\softokn3.dll
Script: Quarantine, Delete, BC delete
1613561856NSS PKCS #11 Library --3544
C:\Program Files\Mozilla Firefox\ssl3.dll
Script: Quarantine, Delete, BC delete
1613824000NSS SSL Library --3544
C:\Program Files\Mozilla Firefox\xpcom.dll
Script: Quarantine, Delete, BC delete
1613955072 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Mozilla Firefox\xpcom_compat.dll
Script: Quarantine, Delete, BC delete
1614020608 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Mozilla Firefox\xpcom_core.dll
Script: Quarantine, Delete, BC delete
1614151680 License: MPL 1.1/GPL 2.0/LGPL 2.1--3544
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssrv.dll
Script: Quarantine, Delete, BC delete
268435456Anti-malware protection service library© Panda Software 2007--1232
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
Script: Quarantine, Delete, BC delete
4194304Anti-malware protection service library executable© Panda Software 2007??1232
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\WINSPAMCATCHER.dll
Script: Quarantine, Delete, BC delete
4325376Mailshell Anti-Spam SDKCopyright © 2007 Mailshell.com All Rights Reserved--1232
C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE
Script: Quarantine, Delete, BC delete
1019871232Platinum permanent protection© Panda 2007??1416
C:\Program Files\Panda Security\Panda Internet Security 2008\AVCIC.DLL
Script: Quarantine, Delete, BC delete
1049100288Panda Interface Manager Communication Client© Panda Software 2007--1416, 280
C:\Program Files\Panda Security\Panda Internet Security 2008\avengdll.dll
Script: Quarantine, Delete, BC delete
738197504On-Access Anti-Malware Scanner Library.© Panda Software 2006--1896
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
Script: Quarantine, Delete, BC delete
721420288Enhanced On-Access Anti-Malware Protection.© Panda Software 2007??1540
C:\Program Files\Panda Security\Panda Internet Security 2008\BORLNDMM.DLL
Script: Quarantine, Delete, BC delete
1610612736Borland Memory ManagerCopyright © 1996,1999 Inprise Corporation--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\ComFltNT.dll
Script: Quarantine, Delete, BC delete
968491008CommFilt© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\Config.dll
Script: Quarantine, Delete, BC delete
62259200Configuration Library© Panda Software 2008--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\CPDLL.DLL
Script: Quarantine, Delete, BC delete
24903680cpdllCopyright © Panda Software. All rights reserved.--280
c:\program files\panda security\panda internet security 2008\firewall\apflctrl.dll
Script: Quarantine, Delete, BC delete
268435456apflctrlCopyright © 2007, Panda Software--140
c:\program files\panda security\panda internet security 2008\firewall\DPIFTran.dll
Script: Quarantine, Delete, BC delete
1262485504Panda Network Manager DPIF Translator© Panda Software 2006--280
c:\program files\panda security\panda internet security 2008\firewall\dsaflt.dll
Script: Quarantine, Delete, BC delete
574554112Firewall Rules Analyzer© Panda Software 2006--140
c:\program files\panda security\panda internet security 2008\firewall\fnetctrl.dll
Script: Quarantine, Delete, BC delete
18546688fnetctrlCopyright © 2007, Panda Software--140
c:\program files\panda security\panda internet security 2008\firewall\IdsFlt.dll
Script: Quarantine, Delete, BC delete
574029824Intrusion Detection System© Panda Software 2006--140
c:\program files\panda security\panda internet security 2008\firewall\netflt.dll
Script: Quarantine, Delete, BC delete
573505536Network Interceptor© Panda Software 2006--140
C:\Program Files\Panda Security\Panda Internet Security 2008\Firewall\PNMApi.dll
Script: Quarantine, Delete, BC delete
1260388352Panda Network Manager API© Panda Software 2006--280
c:\program files\panda security\panda internet security 2008\firewall\PNMATDI.dll
Script: Quarantine, Delete, BC delete
29884416pnmatdiCopyright © 2007, Panda Software--140
c:\program files\panda security\panda internet security 2008\firewall\PNMSRV.DLL
Script: Quarantine, Delete, BC delete
1264779264Panda Network Manager Service© Panda Software 2006--140
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
Script: Quarantine, Delete, BC delete
4194304Panda Host ServiceCopyright © 2007 Panda Software??140
c:\program files\panda security\panda internet security 2008\firewall\smsflt.dll
Script: Quarantine, Delete, BC delete
575078400Stealth Mode System© Panda Software 2006--140
c:\program files\panda security\panda internet security 2008\firewall\wnmflt.dll
Script: Quarantine, Delete, BC delete
18808832WIFI Network Monitor© Panda Software 2006--140
C:\Program Files\Panda Security\Panda Internet Security 2008\GWStore.dll
Script: Quarantine, Delete, BC delete
738328576Goodware store library© Panda Software 2007--1896
C:\Program Files\Panda Security\Panda Internet Security 2008\icl_cfg.dll
Script: Quarantine, Delete, BC delete
1102708736Internet Resident Configuration© Panda Software 2007--1416, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\Icl_mtr.dll
Script: Quarantine, Delete, BC delete
1052835840Internet Resident Monitor© Panda Software 2006--1416, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\icl_trf.dll
Script: Quarantine, Delete, BC delete
1052704768Internet resident activity© Panda Software 2006--1416, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\LangM5.dll
Script: Quarantine, Delete, BC delete
1029505024 © Panda Software 2008--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\libxml2.dll
Script: Quarantine, Delete, BC delete
268435456  --3216, 280
C:\Program Files\Panda Security\Panda Internet Security 2008\LocalSrv.dll
Script: Quarantine, Delete, BC delete
1051328512Biblioteca de vínculos dinámicos LocalSrv© Panda Software 2008--2040
C:\Program Files\Panda Security\Panda Internet Security 2008\memvfile.dll
Script: Quarantine, Delete, BC delete
638582784Anti-malware protection access library© Panda Software 2007--1540
C:\Program Files\Panda Security\Panda Internet Security 2008\ParserFW.dll
Script: Quarantine, Delete, BC delete
280756224Firewall Rules Parser© Panda Software 2007--280
C:\Program Files\Panda Security\Panda Internet Security 2008\Pavale.dll
Script: Quarantine, Delete, BC delete
268435456Pavale.dll© Panda Software 2006--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PavAmw.dll
Script: Quarantine, Delete, BC delete
1034354688Plugin Antimalware© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
Script: Quarantine, Delete, BC delete
4194304PavBckPT Aplicación© Panda Software 2007??3216
C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2008\PavCNet.dll
Script: Quarantine, Delete, BC delete
1343422464PavCNet Dynamic Link Library(c) 2006 Panda Software. All rights reserved.--1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PAVCNTRS.DLL
Script: Quarantine, Delete, BC delete
281018368Panda Counters Module© Panda Software 2006--280, 1896
C:\Program Files\Panda Security\Panda Internet Security 2008\pavexcfg.dll
Script: Quarantine, Delete, BC delete
1084424192 © Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
Script: Quarantine, Delete, BC delete
1035337728Panda Function Service© Panda 2007??280
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFtp.dll
Script: Quarantine, Delete, BC delete
1047003136Plugin FTP© Panda Software 2006--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PavHttp.dll
Script: Quarantine, Delete, BC delete
1047592960Plugin HTTP© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pavim.dll
Script: Quarantine, Delete, BC delete
974127104PAVIM(c) Panda Software 2006--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PavLsp.dll
Script: Quarantine, Delete, BC delete
1102053376Internet Resident Layered Service Provider© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PavMiCli.dll
Script: Quarantine, Delete, BC delete
1041498112PavMiCli© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PavNntp.dll
Script: Quarantine, Delete, BC delete
1046806528Plugin NNTP© Panda Software 2006--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll
Script: Quarantine, Delete, BC delete
251658240Outlook Express Integration© Panda Software 2008--1416, 3572, 3500, 1616, 492, 3544, 3216, 1760, 2040, 752
C:\Program Files\Panda Security\Panda Internet Security 2008\Pavpop3.dll
Script: Quarantine, Delete, BC delete
1046609920Plugin POP3© Panda Software 2006--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\Pavscr.dll
Script: Quarantine, Delete, BC delete
27787264Panda Script Blocking© Panda Software 2008--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PavSInet.dll
Script: Quarantine, Delete, BC delete
1044643840PavSInet Dynamic Link Library© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PavSmtp.dll
Script: Quarantine, Delete, BC delete
1046413312Plugin SMTP© Panda Software 2006--2396
C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2008\PavSRU.dll
Script: Quarantine, Delete, BC delete
268435456PavSRU© 2006 Panda Software. All rights reserved.--1496
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
Script: Quarantine, Delete, BC delete
704643072Enhanced On-Access Anti-Malware Service.© Panda Software 2007??1896
C:\Program Files\Panda Security\Panda Internet Security 2008\PAVSRVDL.DLL
Script: Quarantine, Delete, BC delete
687865856On-Access Anti-Malware Communication Provider.© Panda Software 2007--1416, 280, 1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PavTftp.dll
Script: Quarantine, Delete, BC delete
1048051712Plugin TFTP© Panda Software 2006--2396
C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2008\PavTPU.dll
Script: Quarantine, Delete, BC delete
1345191936Panda Library© Panda Software 2007--1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PavVt.dll
Script: Quarantine, Delete, BC delete
268435456PavVerifyTrust Dynamic Link Library© 2006 Panda Software. All rights reserved.--1896, 2156, 1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PavWMAIL.dll
Script: Quarantine, Delete, BC delete
1032388608Plugin Webmail© Panda Software 2006--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\Platc.DLL
Script: Quarantine, Delete, BC delete
1048707072 © Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PLATCTRL.BPL
Script: Quarantine, Delete, BC delete
33751040PlatCtrl© Panda Software 2006--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\Plats.dll
Script: Quarantine, Delete, BC delete
1049362432 © Panda Software 2007--280
C:\Program Files\Panda Security\Panda Internet Security 2008\PNDCTRLB.BPL
Script: Quarantine, Delete, BC delete
34603008 © Panda Software 2007--1416
C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2008\prot5dll.dll
Script: Quarantine, Delete, BC delete
1027473408pfsf© Panda Software 2006--1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PROTEXC.DLL
Script: Quarantine, Delete, BC delete
1031602176ProtExc© Panda 2007--280
C:\Program Files\Panda Security\Panda Internet Security 2008\PSAEng.dll
Script: Quarantine, Delete, BC delete
42663936AdminSecure Alerts Engine© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PSAUI.dll
Script: Quarantine, Delete, BC delete
37945344AdminSecure Alerts User Interface© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
Script: Quarantine, Delete, BC delete
282591232Panda Software Controler© Panda 2007??680
C:\Program Files\Panda Security\Panda Internet Security 2008\PSImFltr.dll
Script: Quarantine, Delete, BC delete
968687616Panda Interface Manager Plugin [Main Request Filter]© Panda Software 2007--2156
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
Script: Quarantine, Delete, BC delete
4194304Panda Interface Manager Service© Panda Software 2007??2156
C:\Program Files\Panda Security\Panda Internet Security 2008\pskads.dll
Script: Quarantine, Delete, BC delete
621150208Anti-malware protection service library© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskahk.dll
Script: Quarantine, Delete, BC delete
1389297664Anti-malware protection service library© Panda Software 2007--1540, 1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKALLOC.dll
Script: Quarantine, Delete, BC delete
603979776Anti-malware protection support library© Panda Software 2007--1416, 1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskas.dll
Script: Quarantine, Delete, BC delete
637534208Anti-malware protection access library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskavs.dll
Script: Quarantine, Delete, BC delete
625999872Anti-Malware Protection Service Library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKCMP.dll
Script: Quarantine, Delete, BC delete
606076928Anti-malware Protection Support Library© Panda Software 2007--1416, 1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskfss.dll
Script: Quarantine, Delete, BC delete
621674496Anti-malware protection service library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKHTML.dll
Script: Quarantine, Delete, BC delete
605028352Anti-malware protection support library© Panda Software 2007--1416, 1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskmcf.dll
Script: Quarantine, Delete, BC delete
621281280Anti-malware protection service library© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\pskmdfs.dll
Script: Quarantine, Delete, BC delete
620756992Anti-malware protection service library© Panda Software 2007--1540, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskmfs.dll
Script: Quarantine, Delete, BC delete
621019136Anti-malware protection service library© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskmscln.dll
Script: Quarantine, Delete, BC delete
608239616Anti-malware protection service library© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKPACK.DLL
Script: Quarantine, Delete, BC delete
604372992Anti-malware protection support library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskscf.dll
Script: Quarantine, Delete, BC delete
620888064Anti-malware protection service library© Panda Software 2007--2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskscs.dll
Script: Quarantine, Delete, BC delete
623116288Anti-malware protection service library© Panda Software 2007--1540
C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2008\pskudna.dll
Script: Quarantine, Delete, BC delete
622854144Anti-malware protection service library© Panda Software 2007--1496
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKUTIL.dll
Script: Quarantine, Delete, BC delete
604241920Anti-Malware Protection support library© Panda Software 2007--1416, 1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKVFILE.dll
Script: Quarantine, Delete, BC delete
604110848Anti-malware protection support library© Panda Software 2007--1416, 1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\pskvfs.dll
Script: Quarantine, Delete, BC delete
621412352Anti-malware protection service library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSKVM.DLL
Script: Quarantine, Delete, BC delete
622329856Anti-malware protection service library© Panda Software 2007--1540, 1496, 2396
C:\Program Files\Panda Security\Panda Internet Security 2008\PSWLabel.dll
Script: Quarantine, Delete, BC delete
973799424Biblioteca de vínculos dinámicos PSWLabel© Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\PSWLRes.dll
Script: Quarantine, Delete, BC delete
902496256PSWLRes. Panda Software S.L.© Panda 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\RsdnApi.dll
Script: Quarantine, Delete, BC delete
1027997696 © Panda Software 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\SCANOBJS.DLL
Script: Quarantine, Delete, BC delete
1049231360Panda Internet Security 2008© Panda Software 2005-2008--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
Script: Quarantine, Delete, BC delete
1047396352Panda AntiSpam Trainer© Panda Software 2008??2040
C:\Program Files\Panda Security\Panda Internet Security 2008\StoreMan.dll
Script: Quarantine, Delete, BC delete
268435456StoreMan© Panda Software 2008--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\TPConf.DLL
Script: Quarantine, Delete, BC delete
1342570496TPConf Dynamic Link Library© Panda Software 2007--1416, 280
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
Script: Quarantine, Delete, BC delete
4194304TPSrv Application© Panda Software 2007??1496
C:\Program Files\Panda Security\Panda Internet Security 2008\UTILPLAT.DLL
Script: Quarantine, Delete, BC delete
1024851968Biblioteca auxiliar© Panda 2007--1416
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
Script: Quarantine, Delete, BC delete
1045626880Internet resident proxy© Panda Software 2007??2396
C:\Program Files\Spybot - Search & Destroy\advcheck.dll
Script: Quarantine, Delete, BC delete
58064896Dateiüberprüfungs-Bibliothek© 2003-2008 Safer Networking Limited. Alle Rechte vorbehalten.--752
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Script: Quarantine, Delete, BC delete
4194304System settings protector© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.??752
C:\Program Files\Spyware Doctor\avengine\PCTAVEng.dll
Script: Quarantine, Delete, BC delete
152109056PC Tools Engine DLL for Windows NT/2000/XPCopyright PC Tools Research Pty Ltd 2006-2007--2780
C:\Program Files\Spyware Doctor\avengine\SDAVgate.dll
Script: Quarantine, Delete, BC delete
151715840Spyware Doctor Call GateCopyright (C) 2006 PC Tools Research--2780
C:\Program Files\Spyware Doctor\BH.dll
Script: Quarantine, Delete, BC delete
61538304 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\cdialogs.dll
Script: Quarantine, Delete, BC delete
9371648Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2020
C:\Program Files\Spyware Doctor\commhlpr.dll
Script: Quarantine, Delete, BC delete
3670016Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\CommLib.dll
Script: Quarantine, Delete, BC delete
6684672Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780, 2020
C:\Program Files\Spyware Doctor\CommOM.dll
Script: Quarantine, Delete, BC delete
5242880Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780, 2020
C:\Program Files\Spyware Doctor\filehlpr.dll
Script: Quarantine, Delete, BC delete
3932160Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\FileStorage.sdp
Script: Quarantine, Delete, BC delete
50987008Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\IDBLib.sdp
Script: Quarantine, Delete, BC delete
51511296Database LibraryCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\ikdll.dll
Script: Quarantine, Delete, BC delete
3473408Kernel Interface DLLCopyright (c) PCTools Research Pty Ltd. 2006--2780, 2020
C:\Program Files\Spyware Doctor\Immunizer.sdp
Script: Quarantine, Delete, BC delete
59768832 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\inethlpr.dll
Script: Quarantine, Delete, BC delete
7798784Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\klg.dat
Script: Quarantine, Delete, BC delete
1509949440Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--1848, 2512, 1416, 1540, 3572, 3500, 1616, 1024, 648, 492, 1788, 1104, 1668, 1916, 3216, 280, 1476, 1896, 2564, 2020, 680, 140, 2156, 1232, 1760, 224, 1092, 632, 2040, 1468, 1708, 964, 1268, 1344, 4004, 752, 1496, 2396, 1048
C:\Program Files\Spyware Doctor\Localizer.sdp
Script: Quarantine, Delete, BC delete
59899904Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\NetworkLayer\InterfaceDLL.dll
Script: Quarantine, Delete, BC delete
187432960PC Tools Network engineCopyright (C) 2007--2780
C:\Program Files\Spyware Doctor\NetworkLayer\PCTCFHook.dll
Script: Quarantine, Delete, BC delete
151519232PCTOOLS Content Filter Wrapper DLLCopyright (C) 2007--2780
C:\Program Files\Spyware Doctor\NfyMan.sdp
Script: Quarantine, Delete, BC delete
61407232Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\PCTMime.dll
Script: Quarantine, Delete, BC delete
144375808PCTMime Dynamic Link LibraryCopyright (C) PC Tools 2007 --2780
C:\Program Files\Spyware Doctor\PCToolsComponents.bpl
Script: Quarantine, Delete, BC delete
145686528 Copyright © 2008 PC Tools. All rights reserved.--2780, 2020
C:\Program Files\Spyware Doctor\pctsAuxs.exe
Script: Quarantine, Delete, BC delete
4194304PC Tools Auxiliary ServiceCopyright 2008 PC Tools. All rights reserved.??2564
C:\Program Files\Spyware Doctor\pctsSvc.exe
Script: Quarantine, Delete, BC delete
4194304PC Tools Security ServiceCopyright © 2008 PC Tools. All rights reserved.??2780
C:\Program Files\Spyware Doctor\pctsTray.exe
Script: Quarantine, Delete, BC delete
4194304PC Tools Tray ApplicationCopyright © 2008 PC Tools. All rights reserved.??2020
C:\Program Files\Spyware Doctor\PCTWSC.dll
Script: Quarantine, Delete, BC delete
268435456PCTWSC Dynamic Link LibraryPC Tools Copyright (C) 2008--2780
C:\Program Files\Spyware Doctor\plugins\Browsers.SDP
Script: Quarantine, Delete, BC delete
143523840Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\cookie.sdp
Script: Quarantine, Delete, BC delete
143851520Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\email.sdp
Script: Quarantine, Delete, BC delete
144113664Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\grAV.sdp
Script: Quarantine, Delete, BC delete
144769024Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\grfiles.SDP
Script: Quarantine, Delete, BC delete
144965632Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\grImmunizer.SDP
Script: Quarantine, Delete, BC delete
145293312Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\grregistry.SDP
Script: Quarantine, Delete, BC delete
145489920Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\KLGuard.SDP
Script: Quarantine, Delete, BC delete
146407424Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\Network.SDP
Script: Quarantine, Delete, BC delete
146931712Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\Process.SDP
Script: Quarantine, Delete, BC delete
148373504Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\ScriptEngine.SDP
Script: Quarantine, Delete, BC delete
148897792 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\SDNET.SDP
Script: Quarantine, Delete, BC delete
149291008 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\Site.sdp
Script: Quarantine, Delete, BC delete
149880832Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\plugins\StartUp.SDP
Script: Quarantine, Delete, BC delete
150142976Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\pwindow.dll
Script: Quarantine, Delete, BC delete
10092544Popup Window HelperCopyright © 2008 PC Tools. All rights reserved.--2020
C:\Program Files\Spyware Doctor\quarantine.sdp
Script: Quarantine, Delete, BC delete
337641472 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\RebootManager.sdp
Script: Quarantine, Delete, BC delete
64094208Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\RegHelper.dll
Script: Quarantine, Delete, BC delete
3801088Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\rtl100.bpl
Script: Quarantine, Delete, BC delete
1374814208Borland Component PackageCopyright © 1997-2006 Borland Software Corporation--2780, 2020
C:\Program Files\Spyware Doctor\scaneng.sdp
Script: Quarantine, Delete, BC delete
64290816 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\sdcore.dll
Script: Quarantine, Delete, BC delete
8192000Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\SDExtra.sdp
Script: Quarantine, Delete, BC delete
53936128 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\SDInfo.sdp
Script: Quarantine, Delete, BC delete
51838976Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780, 2020
C:\Program Files\Spyware Doctor\Settings.sdp
Script: Quarantine, Delete, BC delete
51380224Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\SH.dll
Script: Quarantine, Delete, BC delete
146145280 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\smumhook.dll
Script: Quarantine, Delete, BC delete
1668153344 Copyright © 2008 PC Tools. All rights reserved.--1848, 2512, 1416, 1540, 3572, 3500, 1616, 1024, 648, 492, 1788, 1104, 1668, 1916, 3216, 280, 1476, 1896, 2564, 2020, 680, 140, 2156, 1232, 1760, 224, 1092, 632, 2040, 1468, 1708, 964, 1268, 1344, 4004, 752, 1496, 2396, 1048
C:\Program Files\Spyware Doctor\stasks.sdp
Script: Quarantine, Delete, BC delete
65667072Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\SysAccess.dll
Script: Quarantine, Delete, BC delete
3276800Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780, 2020
C:\Program Files\Spyware Doctor\SystemMonitor.sdp
Script: Quarantine, Delete, BC delete
65863680 Copyright © 2008 PC Tools. All rights reserved.--2780
C:\Program Files\Spyware Doctor\vcl100.bpl
Script: Quarantine, Delete, BC delete
1375731712Borland Component PackageCopyright © 1997-2006 Borland Software Corporation--2780, 2020
C:\Program Files\Spyware Doctor\whitelist.sdp
Script: Quarantine, Delete, BC delete
73334784Spyware Doctor ComponentCopyright © 2008 PC Tools. All rights reserved.--2780
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Script: Quarantine, Delete, BC delete
45154304SBSD IE Protection© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.--492
C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Script: Quarantine, Delete, BC delete
1677721600YMMAPI ModuleCopyright © 2001-2006 Yahoo! Inc.--1760
C:\WINDOWS\mmfs.dll
Script: Quarantine, Delete, BC delete
268435456License Control ServiceCopyright © 1998-2005 ViaTech Technologies Inc.--224
C:\WINDOWS\runservice.exe
Script: Quarantine, Delete, BC delete
4194304  ??224
C:\WINDOWS\system32\avldr.dll
Script: Quarantine, Delete, BC delete
696254464On-Access Antivirus Scanner Sync.© Panda Software 2006--1048
C:\WINDOWS\SYSTEM32\PAVSHOOK.DLL
Script: Quarantine, Delete, BC delete
1344667648PavSHook Dynamic Link Library© Panda Software 2007--1848, 2512, 3572, 3500, 1616, 648, 492, 3544, 1788, 1104, 1668, 1916, 1476, 2564, 2780, 2020, 1760, 224, 1092, 632, 2040, 1468, 1708, 964, 1268, 1344, 4004, 752, 1048
C:\WINDOWS\system32\systools.dll
Script: Quarantine, Delete, BC delete
1348861952SYSTOOLS© Panda Software, all rights reserved--1848, 2512, 3572, 3500, 1616, 648, 492, 3544, 1788, 1104, 1668, 1916, 1476, 2564, 2780, 2020, 1760, 224, 1092, 632, 2040, 1468, 1708, 964, 1268, 1344, 4004, 752, 1496, 1048
Modules detected:490, recognized as trusted 288

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\WINDOWS\system32\Drivers\APPFLT.SYS
Script: Quarantine, Delete, BC delete
F7A9B000010000 (65536)Panda APPFLTCopyright © 2007, Panda Software
C:\WINDOWS\system32\drivers\av5flt.sys
Script: Quarantine, Delete, BC delete
A975A000017000 (94208)
C:\WINDOWS\system32\Drivers\cercsr6.sys
Script: Quarantine, Delete, BC delete
F8702000008000 (32768)DELL CERC SATA1.5/6ch Miniport DriverCopyright 2003 Adaptec, Inc. All rights reserved.
C:\WINDOWS\system32\DRIVERS\COMFiltr.sys
Script: Quarantine, Delete, BC delete
F87CA000007000 (28672)COMFiltr© Panda Software 2006
C:\WINDOWS\system32\Drivers\cpoint.sys
Script: Quarantine, Delete, BC delete
F887A000005000 (20480)cPointCopyright © Panda Software 2005
C:\WINDOWS\system32\Drivers\DSAFLT.SYS
Script: Quarantine, Delete, BC delete
F7AAB00000B000 (45056)© Panda Software 2006
C:\WINDOWS\System32\Drivers\dump_atapi.sys
Script: Quarantine, Delete, BC delete
AA6A8000018000 (98304)
C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Script: Quarantine, Delete, BC delete
F89E8000002000 (8192)
C:\WINDOWS\system32\Drivers\fnetmon.SYS
Script: Quarantine, Delete, BC delete
F891A000004000 (16384)Panda FNetMonCopyright © 2007, Panda Software
C:\WINDOWS\system32\Drivers\IDSFLT.SYS
Script: Quarantine, Delete, BC delete
AAD1900002E000 (188416)Intrusion Detection System© Panda Software 2006
C:\WINDOWS\system32\Drivers\ikfilesec.sys
Script: Quarantine, Delete, BC delete
F84C200000E000 (57344)File Security Device DriverCopyright (c) PCTools Research Pty Ltd. 2006
C:\WINDOWS\system32\drivers\iksysflt.sys
Script: Quarantine, Delete, BC delete
AAFAB000015000 (86016)System Filter Device DriverCopyright (c) PCTools Research Pty Ltd. 2006
C:\WINDOWS\system32\drivers\iksyssec.sys
Script: Quarantine, Delete, BC delete
AAF94000017000 (94208)System Security Device DriverCopyright (c) PCTools Research Pty Ltd. 2006
C:\WINDOWS\system32\drivers\KCOM.SYS
Script: Quarantine, Delete, BC delete
F86B200000E000 (57344)
C:\WINDOWS\system32\Drivers\mchInjDrv.sys
Script: Quarantine, Delete, BC delete
F8B83000001000 (4096)
C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
Script: Quarantine, Delete, BC delete
AAE9C00001F000 (126976)Panda TDI FilterCopyright © 2007, Panda Software
C:\WINDOWS\system32\DRIVERS\PavProc.sys
Script: Quarantine, Delete, BC delete
A9C9900002B000 (176128)Panda Process Protection driver© Panda Software 2007
C:\WINDOWS\system32\PavSRK.sys
Script: Quarantine, Delete, BC delete
F874A000008000 (32768)
C:\WINDOWS\system32\PavTPK.sys
Script: Quarantine, Delete, BC delete
F7A3B00000B000 (45056)
C:\WINDOWS\system32\drivers\pctfw2.sys
Script: Quarantine, Delete, BC delete
AAEE3000026000 (155648)PC Tools TDI DriverCopyright (C) 2006
C:\WINDOWS\system32\Drivers\ShlDrv51.sys
Script: Quarantine, Delete, BC delete
F882A000008000 (32768)PandaShield driverCopyright © Panda Software International 2007
C:\WINDOWS\system32\Drivers\SMSFLT.SYS
Script: Quarantine, Delete, BC delete
F8822000008000 (32768)© Panda Software 2006
C:\WINDOWS\system32\drivers\symlcbrd.sys
Script: Quarantine, Delete, BC delete
F8732000006000 (24576)Symantec Core ComponentCopyright (C) 2003
C:\WINDOWS\system32\Drivers\WNMFLT.SYS
Script: Quarantine, Delete, BC delete
F881A000006000 (24576)© Panda Software 2006
Modules detected - 143, recognized as trusted - 119

Services

ServiceDescriptionStatusFileGroupDependencies
aawservice
Service: Stop, Delete, Disable
Lavasoft Ad-Aware ServiceRunningC:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
Script: Quarantine, Delete, BC delete
ShellSvcGroupRpcSS
LicCtrlService
Service: Stop, Delete, Disable
LicCtrl ServiceRunningC:\WINDOWS\runservice.exe
Script: Quarantine, Delete, BC delete
  
LVCOMSer
Service: Stop, Delete, Disable
LVCOMSerRunningC:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
Script: Quarantine, Delete, BC delete
 RPCSS
Panda Software Controller
Service: Stop, Delete, Disable
Panda Software ControllerRunningC:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
Script: Quarantine, Delete, BC delete
 RPCSS
PAVFNSVR
Service: Stop, Delete, Disable
Panda Function ServiceRunningC:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
Script: Quarantine, Delete, BC delete
  
PavPrSrv
Service: Stop, Delete, Disable
Panda Process Protection ServiceRunningC:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
Script: Quarantine, Delete, BC delete
  
PAVSRV
Service: Stop, Delete, Disable
Panda anti-virus serviceRunningC:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
Script: Quarantine, Delete, BC delete
 RpcSs
pmshellsrv
Service: Stop, Delete, Disable
Panda Antispam EngineRunningC:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
Script: Quarantine, Delete, BC delete
  
PSHost
Service: Stop, Delete, Disable
Panda Host ServiceRunningc:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
Script: Quarantine, Delete, BC delete
 RPCSS
PSIMSVC
Service: Stop, Delete, Disable
Panda IManager ServiceRunningC:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
Script: Quarantine, Delete, BC delete
  
sdAuxService
Service: Stop, Delete, Disable
PC Tools Auxiliary ServiceRunningC:\Program Files\Spyware Doctor\pctsAuxs.exe
Script: Quarantine, Delete, BC delete
  
sdCoreService
Service: Stop, Delete, Disable
PC Tools Security ServiceRunningC:\Program Files\Spyware Doctor\pctsSvc.exe
Script: Quarantine, Delete, BC delete
  
TPSrv
Service: Stop, Delete, Disable
Panda TPSrvRunningC:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
Script: Quarantine, Delete, BC delete
TruPreventCryptSvc
Apple Mobile Device
Service: Stop, Delete, Disable
Apple Mobile DeviceNot startedC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
Script: Quarantine, Delete, BC delete
 Tcpip
iPod Service
Service: Stop, Delete, Disable
iPod ServiceNot startedC:\Program Files\iPod\bin\iPodService.exe
Script: Quarantine, Delete, BC delete
 RpcSs
LVPrcSrv
Service: Stop, Delete, Disable
Process MonitorNot startedC:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
Script: Quarantine, Delete, BC delete
AudioGroup 
LVSrvLauncher
Service: Stop, Delete, Disable
LVSrvLauncherNot startedC:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
Script: Quarantine, Delete, BC delete
  
Detected - 101, recognized as trusted - 84

Drivers

ServiceDescriptionStatusFileGroupDependencies
APPFLT
Driver: Unload, Delete, Disable
App Filter PluginRunningC:\WINDOWS\system32\Drivers\APPFLT.SYS
Script: Quarantine, Delete, BC delete
 +TDI
AvFlt
Driver: Unload, Delete, Disable
Antivirus Filter DriverRunningC:\WINDOWS\system32\drivers\av5flt.sys
Script: Quarantine, Delete, BC delete
  
ComFiltr
Driver: Unload, Delete, Disable
Panda Anti-DialerRunningC:\WINDOWS\system32\DRIVERS\COMFiltr.sys
Script: Quarantine, Delete, BC delete
  
cpoint
Driver: Unload, Delete, Disable
Panda CPoint DriverRunningC:\WINDOWS\system32\Drivers\cpoint.sys
Script: Quarantine, Delete, BC delete
TDI 
DSAFLT
Driver: Unload, Delete, Disable
DSA Filter PluginRunningC:\WINDOWS\system32\Drivers\DSAFLT.SYS
Script: Quarantine, Delete, BC delete
 NETIMFLT
FNETMON
Driver: Unload, Delete, Disable
NetMon Filter PluginRunningC:\WINDOWS\system32\Drivers\fnetmon.SYS
Script: Quarantine, Delete, BC delete
 +TDI
IDSFLT
Driver: Unload, Delete, Disable
Ids Filter PluginRunningC:\WINDOWS\system32\Drivers\IDSFLT.SYS
Script: Quarantine, Delete, BC delete
 NETIMFLT
IKFileSec
Driver: Unload, Delete, Disable
File Security DriverRunningC:\WINDOWS\system32\drivers\ikfilesec.sys
Script: Quarantine, Delete, BC delete
FSFilter Anti-VirusFltMgr
IKSysFlt
Driver: Unload, Delete, Disable
System Filter DriverRunningC:\WINDOWS\system32\drivers\iksysflt.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
IKSysSec
Driver: Unload, Delete, Disable
System Security DriverRunningC:\WINDOWS\system32\drivers\iksyssec.sys
Script: Quarantine, Delete, BC delete
Boot Bus ExtenderIKSysFlt
NETFLTDI
Driver: Unload, Delete, Disable
Panda Net Driver [TDI Layer]RunningC:\WINDOWS\system32\Drivers\NETFLTDI.SYS
Script: Quarantine, Delete, BC delete
PNP_TDITCPIP
PavProc
Driver: Unload, Delete, Disable
Panda Process Protection DriverRunningC:\WINDOWS\system32\DRIVERS\PavProc.sys
Script: Quarantine, Delete, BC delete
  
PavSRK.sys
Driver: Unload, Delete, Disable
PavSRK.sysRunningC:\WINDOWS\system32\PavSRK.sys
Script: Quarantine, Delete, BC delete
  
PavTPK.sys
Driver: Unload, Delete, Disable
PavTPK.sysRunningC:\WINDOWS\system32\PavTPK.sys
Script: Quarantine, Delete, BC delete
  
pctfw2
Driver: Unload, Delete, Disable
pctfw2RunningC:\WINDOWS\system32\drivers\pctfw2.sys
Script: Quarantine, Delete, BC delete
PNP_TDITcpip
ShldDrv
Driver: Unload, Delete, Disable
Panda File Shield DriverRunningC:\WINDOWS\system32\Drivers\ShlDrv51.sys
Script: Quarantine, Delete, BC delete
  
SMSFLT
Driver: Unload, Delete, Disable
SMS Filter PluginRunningC:\WINDOWS\system32\Drivers\SMSFLT.SYS
Script: Quarantine, Delete, BC delete
 NETIMFLT
WNMFLT
Driver: Unload, Delete, Disable
Wifi Monitor Filter PluginRunningC:\WINDOWS\system32\Drivers\WNMFLT.SYS
Script: Quarantine, Delete, BC delete
 NETIMFLT
sym_hi
Driver: Unload, Delete, Disable
sym_hiNot startedsym_hi.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
sym_u3
Driver: Unload, Delete, Disable
sym_u3Not startedsym_u3.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symlcbrd
Driver: Unload, Delete, Disable
symlcbrdRunningC:\WINDOWS\system32\drivers\symlcbrd.sys
Script: Quarantine, Delete, BC delete
  
Abiosdsk
Driver: Unload, Delete, Disable
AbiosdskNot startedAbiosdsk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
abp480n5
Driver: Unload, Delete, Disable
abp480n5Not startedabp480n5.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
adpu160m
Driver: Unload, Delete, Disable
adpu160mNot startedadpu160m.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Aha154x
Driver: Unload, Delete, Disable
Aha154xNot startedAha154x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78u2
Driver: Unload, Delete, Disable
aic78u2Not startedaic78u2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
aic78xx
Driver: Unload, Delete, Disable
aic78xxNot startedaic78xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
AliIde
Driver: Unload, Delete, Disable
AliIdeNot startedAliIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
amsint
Driver: Unload, Delete, Disable
amsintNot startedamsint.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc
Driver: Unload, Delete, Disable
ascNot startedasc.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3350p
Driver: Unload, Delete, Disable
asc3350pNot startedasc3350p.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
asc3550
Driver: Unload, Delete, Disable
asc3550Not startedasc3550.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Atdisk
Driver: Unload, Delete, Disable
AtdiskNot startedAtdisk.sys
Script: Quarantine, Delete, BC delete
Primary disk 
Avg7Core
Driver: Unload, Delete, Disable
AVG7 KernelNot startedC:\WINDOWS\System32\Drivers\avg7core.sys
Script: Quarantine, Delete, BC delete
AVG 
cd20xrnt
Driver: Unload, Delete, Disable
cd20xrntNot startedcd20xrnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
cercsr6
Driver: Unload, Delete, Disable
cercsr6Not startedC:\WINDOWS\system32\Drivers\cercsr6.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Changer
Driver: Unload, Delete, Disable
ChangerNot startedChanger.sys
Script: Quarantine, Delete, BC delete
Filter 
CmdIde
Driver: Unload, Delete, Disable
CmdIdeNot startedCmdIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
Cpqarray
Driver: Unload, Delete, Disable
CpqarrayNot startedCpqarray.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dac960nt
Driver: Unload, Delete, Disable
dac960ntNot starteddac960nt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
dpti2o
Driver: Unload, Delete, Disable
dpti2oNot starteddpti2o.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
hpn
Driver: Unload, Delete, Disable
hpnNot startedhpn.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
i2omgmt
Driver: Unload, Delete, Disable
i2omgmtNot startedi2omgmt.sys
Script: Quarantine, Delete, BC delete
SCSI Class 
i2omp
Driver: Unload, Delete, Disable
i2ompNot startedi2omp.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ini910u
Driver: Unload, Delete, Disable
ini910uNot startedini910u.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
lbrtfdc
Driver: Unload, Delete, Disable
lbrtfdcNot startedlbrtfdc.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
LVPr2Mon
Driver: Unload, Delete, Disable
Logitech LVPr2Mon DriverNot startedC:\WINDOWS\system32\drivers\LVPr2Mon.sys
Script: Quarantine, Delete, BC delete
AudioGroup 
mraid35x
Driver: Unload, Delete, Disable
mraid35xNot startedmraid35x.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
PCIDump
Driver: Unload, Delete, Disable
PCIDumpNot startedPCIDump.sys
Script: Quarantine, Delete, BC delete
PCI Configuration 
PDCOMP
Driver: Unload, Delete, Disable
PDCOMPNot startedPDCOMP.sys
Script: Quarantine, Delete, BC delete
  
PDFRAME
Driver: Unload, Delete, Disable
PDFRAMENot startedPDFRAME.sys
Script: Quarantine, Delete, BC delete
  
PDRELI
Driver: Unload, Delete, Disable
PDRELINot startedPDRELI.sys
Script: Quarantine, Delete, BC delete
  
PDRFRAME
Driver: Unload, Delete, Disable
PDRFRAMENot startedPDRFRAME.sys
Script: Quarantine, Delete, BC delete
  
perc2
Driver: Unload, Delete, Disable
perc2Not startedperc2.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
perc2hib
Driver: Unload, Delete, Disable
perc2hibNot startedperc2hib.sys
Script: Quarantine, Delete, BC delete
Filter 
ql1080
Driver: Unload, Delete, Disable
ql1080Not startedql1080.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Ql10wnt
Driver: Unload, Delete, Disable
Ql10wntNot startedQl10wnt.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql12160
Driver: Unload, Delete, Disable
ql12160Not startedql12160.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1240
Driver: Unload, Delete, Disable
ql1240Not startedql1240.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ql1280
Driver: Unload, Delete, Disable
ql1280Not startedql1280.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
Simbad
Driver: Unload, Delete, Disable
SimbadNot startedSimbad.sys
Script: Quarantine, Delete, BC delete
Filter 
Sparrow
Driver: Unload, Delete, Disable
SparrowNot startedSparrow.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc810
Driver: Unload, Delete, Disable
symc810Not startedsymc810.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
symc8xx
Driver: Unload, Delete, Disable
symc8xxNot startedsymc8xx.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
TosIde
Driver: Unload, Delete, Disable
TosIdeNot startedTosIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
ultra
Driver: Unload, Delete, Disable
ultraNot startedultra.sys
Script: Quarantine, Delete, BC delete
SCSI miniport 
ViaIde
Driver: Unload, Delete, Disable
ViaIdeNot startedViaIde.sys
Script: Quarantine, Delete, BC delete
System Bus Extender 
WDICA
Driver: Unload, Delete, Disable
WDICANot startedWDICA.sys
Script: Quarantine, Delete, BC delete
  
Detected - 209, recognized as trusted - 141

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, LogitechCommunicationsManager
C:\Program Files\Logitech\QuickCam\Quickcam.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, LogitechQuickCamRibbon
C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, APVXDWIN
C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SCANINICIO
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, SpybotSD TeaTimer
C:\Program Files\Spyware Doctor\pctsTray.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, ISTray
appmgmts.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}, DLLName
autocheck autochk *lsdelete
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager, BootExecute
avldr.dll
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avldr, DLLName
Autoruns items detected - 60, recognized as trusted - 50

Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Script: Quarantine, Delete, BC delete
BHOSBSD IE Protection© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten.{53707962-6F74-2D53-2644-206D7942484F}
Delete
c:\program files\google\googletoolbar1.dll
Script: Quarantine, Delete, BC delete
BHOGoogle IE Client ToolbarCopyright © 2000-2006{AA58ED58-01DD-4d91-8333-CF10577473F7}
Delete
c:\program files\google\googletoolbar1.dll
Script: Quarantine, Delete, BC delete
ToolbarGoogle IE Client ToolbarCopyright © 2000-2006{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Delete
C:\Microgaming\Poker\DoylesRoomMPP\MPPoker.exe
Script: Quarantine, Delete, BC delete
Extension moduleMicrogaming Poker EngineCopyright (c) Microgaming 1998 - 2003{725E77D3-B919-4eef-8EEE-D09DE618B6C1}
Delete
C:\Microgaming\Poker\DoylesRoomMPP\MPPoker.exe
Script: Quarantine, Delete, BC delete
Extension moduleMicrogaming Poker EngineCopyright (c) Microgaming 1998 - 2003{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Delete
Extension module{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
Delete
Elements detected - 13, recognized as trusted - 7

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
deskpan.dll
Script: Quarantine, Delete, BC delete
Display Panning CPL Extension{42071714-76d4-11d1-8b24-00a0c9068ff3}
Shell extensions for file compression{764BF0E1-F219-11ce-972D-00AA00A14F56}
Encryption Context Menu{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}
Taskbar and Start Menu{0DF44EAA-FF21-4412-828E-260A8728E7F1}
rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Script: Quarantine, Delete, BC delete
Autoplay for SlideShow{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
User Accounts{7A9D77BD-5403-11d2-8785-2E0420524153}
"C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"
Script: Quarantine, Delete, BC delete
OpenOffice.org Column Handler{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
"C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"
Script: Quarantine, Delete, BC delete
OpenOffice.org Infotip Handler{087B3AE3-E237-4467-B8DB-5A38AB959AC9}
"C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"
Script: Quarantine, Delete, BC delete
OpenOffice.org Property Sheet Handler{63542C48-9552-494A-84F7-73AA6A7C99C1}
"C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"
Script: Quarantine, Delete, BC delete
OpenOffice.org Thumbnail Viewer{3B092F0C-7696-40E3-A80F-68D74DA84210}
DllRegShlExt extension{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
C:\Program Files\Yahoo!\Common\YMMAPI.dll
Script: Quarantine, Delete, BC delete
Yahoo! MailYMMAPI ModuleCopyright © 2001-2006 Yahoo! Inc.{5464D816-CF16-4784-B9F3-75C0DB52B499}
C:\WINDOWS\lcmmfu.cpl
Script: Quarantine, Delete, BC delete
eLicense ControlLCMMFUCopyright © 1998-2007 ViaTech Technologies Inc.{EB47FF00-225E-11D2-9E1D-00A0C9AB0EEE}
iTunes{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
C:\Program Files\Panda Security\Panda Internet Security 2008\PavOLE.dll
Script: Quarantine, Delete, BC delete
Panda AntivirusPAVOLE© Panda Software 2008{65756541-C65C-11CD-0000-4B656E696100}
Elements detected - 207, recognized as trusted - 192

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 9, recognized as trusted - 9

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
C:\Program Files\Panda Security\Panda Internet Security 2008\PlaTasks.exe
Script: Quarantine, Delete, BC delete
Basic clean-up.jobThe task has not yet run.PlaTasks. Panda Software S.L.© Panda 2007
C:\Program Files\Panda Security\Panda Internet Security 2008\PlaTasks.exe
Script: Quarantine, Delete, BC delete
Basic clean-up1.jobThe task has not yet run.PlaTasks. Panda Software S.L.© Panda 2007
Elements detected - 2, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ManufacturerStatusEXE fileDescriptionGUID
Detected - 3, recognized as trusted - 3
Transport protocol providers (TSP, LSP)
ManufacturerEXE fileDescription
PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [TCP/IP]]]C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
Copyright PC Tools Research Pty Ltd 2006.(1, 0, 91, 0)
PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [UDP/IP]]]C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
Copyright PC Tools Research Pty Ltd 2006.(1, 0, 91, 0)
PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [RAW/IP]]]C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
Copyright PC Tools Research Pty Ltd 2006.(1, 0, 91, 0)
PAV_LAYERED over [PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [TCP/IP]]]]C:\Program Files\Panda Security\Panda Internet Security 2008\pavlsp.dll
Script: Quarantine, Delete, BC delete
© Panda Software 2007(7, 5, 21, 501)
PAV_LAYERED over [PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [UDP/IP]]]]C:\Program Files\Panda Security\Panda Internet Security 2008\pavlsp.dll
Script: Quarantine, Delete, BC delete
© Panda Software 2007(7, 5, 21, 501)
PAV_LAYERED over [PCTOOLS over [PAV_LAYERED over [MSAFD Tcpip [RAW/IP]]]]C:\Program Files\Panda Security\Panda Internet Security 2008\pavlsp.dll
Script: Quarantine, Delete, BC delete
© Panda Software 2007(7, 5, 21, 501)
PCTOOLS CONTENT FILTER PROVIDERC:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
Copyright PC Tools Research Pty Ltd 2006.(1, 0, 91, 0)
PAV_LAYEREDC:\Program Files\Panda Security\Panda Internet Security 2008\pavlsp.dll
Script: Quarantine, Delete, BC delete
© Panda Software 2007(7, 5, 21, 501)
Detected - 21, recognized as trusted - 13
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.012402[1344] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.022726[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.047235[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1033LISTENING0.0.0.039134[2512] c:\windows\system32\alg.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1039ESTABLISHED127.0.0.11040[3544] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1040ESTABLISHED127.0.0.11039[3544] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1041ESTABLISHED127.0.0.11042[3544] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1042ESTABLISHED127.0.0.11041[3544] c:\program files\mozilla firefox\firefox.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1188CLOSE_WAIT72.246.19.1180[1416] c:\program files\panda security\panda internet security 2008\apvxdwin.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1189CLOSE_WAIT89.108.66.15680[3572] c:\documents and settings\barry\desktop\avz4\avz.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6083LISTENING0.0.0.057526[2040] c:\program files\panda security\panda internet security 2008\srvload.exe
Script: Quarantine, Delete, BC delete, Terminate
 
31595LISTENING0.0.0.0141[2396] c:\program files\panda security\panda internet security 2008\webproxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
123LISTENING----[1468] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
123LISTENING----[1468] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
500LISTENING----[1104] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1043LISTENING----[1708] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1044LISTENING----[1708] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1045LISTENING----[1708] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1114LISTENING----[1708] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[964] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[964] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
4500LISTENING----[1104] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18001LISTENING----[2396] c:\program files\panda security\panda internet security 2008\webproxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18002LISTENING----[2396] c:\program files\panda security\panda internet security 2008\webproxy.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Delete
http://www.apple.com/qtactivex/qtplugin.cab
C:\Program Files\Yahoo!\Common\Yinsthelper.dll
Script: Quarantine, Delete, BC delete
YInstHelper ModuleCopyright © 2001-2007 Yahoo! Inc. All rights reserved.{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
Delete
C:\Program Files\Yahoo!\Common\Yinsthelper.dll
{512FC5A1-7DE1-43F1-BC0C-371622FCB409}
Delete
http://www.nanoscan.com/as/cabs/ascstubie.cab
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
Delete
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
Elements detected - 9, recognized as trusted - 5

Control Panel Applets (CPL)

File nameDescriptionManufacturer
C:\WINDOWS\lcmmfu.cpl
Script: Quarantine, Delete, BC delete
LCMMFUCopyright © 1998-2007 ViaTech Technologies Inc.
C:\WINDOWS\system32\pavcpl.cpl
Script: Quarantine, Delete, BC delete
PavCPLCopyright © Panda Software 2006
Elements detected - 27, recognized as trusted - 25

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 15, recognized as trusted - 15

HOSTS file

Hosts file record

127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 32, recognized as trusted - 29

Suspicious objects

FileDescriptionType
C:\WINDOWS\system32\drivers\iksysflt.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\system32\DRIVERS\PavProc.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\system32\Drivers\ShlDrv51.sys
Script: Quarantine, Delete, BC delete
Suspicion for RootkitKernel-mode hook
C:\WINDOWS\SYSTEM32\PAVSHOOK.DLL
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL
C:\WINDOWS\system32\systools.dll
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL
C:\Program Files\Spyware Doctor\smumhook.dll
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL
C:\Program Files\Spyware Doctor\klg.dat
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL
C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL
C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Script: Quarantine, Delete, BC delete
Suspicion for KeyloggerSuspicion for Keylogger or Trojan DLL


AVZ Antiviral Toolkit log; AVZ version is 4.30
Scanning started at 6/21/2008 1:03:05 PM
Database loaded: signatures - 171373, NN profile(s) - 2, microprograms of healing - 56, signature database released 20.06.2008 23:50
Heuristic microprograms loaded: 370
SPV microprograms loaded: 9
Digital signatures of system files loaded: 71156
Heuristic analyzer mode: Medium heuristics level
Healing mode: enabled
Windows version: 5.1.2600, Service Pack 2 ; AVZ is launched with administrator rights
System Restore: Disabled
1. Searching for Rootkits and programs intercepting API functions
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
Function kernel32.dll:CopyFileExW (66) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CopyFileExW blocked
Function kernel32.dll:CreateFileMappingW (82) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateFileMappingW blocked
Function kernel32.dll:CreateProcessInternalW (101) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateProcessInternalW blocked
Function kernel32.dll:CreateRemoteThread (104) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateRemoteThread blocked
Function kernel32.dll:MoveFileWithProgressW (611) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function MoveFileWithProgressW blocked
Function kernel32.dll:TerminateProcess (839) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function TerminateProcess blocked
Function kernel32.dll:WriteProcessMemory (917) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function WriteProcessMemory blocked
 Analysis: ntdll.dll, export table found in section .text
Function ntdll.dll:LdrLoadDll (70) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function LdrLoadDll blocked
Function ntdll.dll:NtClose (111) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtClose blocked
Function ntdll.dll:NtCreateFile (123) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtCreateFile blocked
Function ntdll.dll:NtCreateKey (127) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtCreateKey blocked
Function ntdll.dll:NtCreateSection (137) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtCreateSection blocked
Function ntdll.dll:NtDeleteFile (150) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtDeleteFile blocked
Function ntdll.dll:NtDeleteKey (151) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtDeleteKey blocked
Function ntdll.dll:NtDeleteValueKey (153) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtDeleteValueKey blocked
Function ntdll.dll:NtDuplicateObject (156) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtDuplicateObject blocked
Function ntdll.dll:NtEnumerateKey (159) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtEnumerateKey blocked
Function ntdll.dll:NtEnumerateValueKey (161) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtEnumerateValueKey blocked
Function ntdll.dll:NtOpenFile (204) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtOpenFile blocked
Function ntdll.dll:NtQueryMultipleValueKey (250) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtQueryMultipleValueKey blocked
Function ntdll.dll:NtQueryValueKey (267) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtQueryValueKey blocked
Function ntdll.dll:NtReadFile (273) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtReadFile blocked
Function ntdll.dll:NtRenameKey (283) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtRenameKey blocked
Function ntdll.dll:NtSetInformationFile (315) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtSetInformationFile blocked
Function ntdll.dll:NtSetValueKey (338) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtSetValueKey blocked
Function ntdll.dll:NtTerminateProcess (348) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtTerminateProcess blocked
Function ntdll.dll:NtUnloadKey (354) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtUnloadKey blocked
Function ntdll.dll:NtWriteFile (366) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtWriteFile blocked
Function ntdll.dll:NtWriteFileGather (367) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtWriteFileGather blocked
Function ntdll.dll:NtWriteVirtualMemory (369) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function NtWriteVirtualMemory blocked
 Analysis: user32.dll, export table found in section .text
Function user32.dll:AttachThreadInput (12) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function AttachThreadInput blocked
Function user32.dll:BeginDeferWindowPos (13) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function BeginDeferWindowPos blocked
Function user32.dll:CreateAcceleratorTableW (78) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateAcceleratorTableW blocked
Function user32.dll:DispatchMessageA (162) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function DispatchMessageA blocked
Function user32.dll:DispatchMessageW (163) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function DispatchMessageW blocked
Function user32.dll:GetAsyncKeyState (243) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function GetAsyncKeyState blocked
Function user32.dll:GetKeyState (290) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function GetKeyState blocked
Function user32.dll:GetKeyboardState (295) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function GetKeyboardState blocked
Function user32.dll:SetWindowsHookExA (651) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function SetWindowsHookExA blocked
Function user32.dll:SetWindowsHookExW (652) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function SetWindowsHookExW blocked
Function user32.dll:TranslateMessage (683) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function TranslateMessage blocked
 Analysis: advapi32.dll, export table found in section .text
Function advapi32.dll:ChangeServiceConfig2A (54) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function ChangeServiceConfig2A blocked
Function advapi32.dll:ChangeServiceConfig2W (55) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function ChangeServiceConfig2W blocked
Function advapi32.dll:ChangeServiceConfigA (56) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function ChangeServiceConfigA blocked
Function advapi32.dll:ChangeServiceConfigW (57) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function ChangeServiceConfigW blocked
Function advapi32.dll:CloseServiceHandle (64) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CloseServiceHandle blocked
Function advapi32.dll:ControlService (68) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function ControlService blocked
Function advapi32.dll:CreateServiceA (102) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateServiceA blocked
Function advapi32.dll:CreateServiceW (103) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function CreateServiceW blocked
Function advapi32.dll:DeleteService (177) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function DeleteService blocked
Function advapi32.dll:LsaAddAccountRights (338) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function LsaAddAccountRights blocked
Function advapi32.dll:LsaRemoveAccountRights (385) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function LsaRemoveAccountRights blocked
Function advapi32.dll:OpenServiceA (430) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function OpenServiceA blocked
Function advapi32.dll:OpenServiceW (431) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function OpenServiceW blocked
Function advapi32.dll:StartServiceA (576) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function StartServiceA blocked
Function advapi32.dll:StartServiceW (579) intercepted, method CodeHijack (method not defined)
 >>> Rootkit code in function StartServiceW blocked
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=07B380)
 Kernel ntkrnlpa.exe found in memory at address 804D7000
   SDT = 80552380
   KiST = 805011FC (284)
Function NtCreateKey (29) intercepted (80618E86->AAFB27A6), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtCreateProcess (2F) intercepted (805C5F8E->AAFAF794), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtCreateProcessEx (30) intercepted (805C5ED8->AAFAFF1E), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtDeleteKey (3F) intercepted (80619316->AAFB31F0), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtDeleteValueKey (41) intercepted (806194E6->AAFB342A), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtRenameKey (C0) intercepted (806188AC->AAFB412A), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtSetValueKey (F7) intercepted (80617546->AAFB383C), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateProcess (101) intercepted (805C776C->A9C9AA70), hook C:\WINDOWS\system32\DRIVERS\PavProc.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtTerminateThread (102) intercepted (805C7966->A9C99E40), hook C:\WINDOWS\system32\DRIVERS\PavProc.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtWriteVirtualMemory (115) intercepted (805A85A2->AAFAE384), hook C:\WINDOWS\system32\drivers\iksysflt.sys
>>> Function restored successfully !
>>> Hook code blocked
Functions checked: 284, intercepted: 10, restored: 10
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
\FileSystem\ntfs[IRP_MJ_CREATE] = F882D7D0 -> C:\WINDOWS\system32\Drivers\ShlDrv51.sys
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = F882DC70 -> C:\WINDOWS\system32\Drivers\ShlDrv51.sys
 Checking - complete
2. Scanning memory
 Number of processes found: 43
 Number of modules loaded: 461
Scanning memory - complete
3. Scanning disks
4. Checking  Winsock Layered Service Provider (SPI/LSP)
 LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\WINDOWS\SYSTEM32\PAVSHOOK.DLL --> Suspicion for Keylogger or Trojan DLL
C:\WINDOWS\SYSTEM32\PAVSHOOK.DLL>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
File quarantined succesfully (C:\WINDOWS\SYSTEM32\PAVSHOOK.DLL)
C:\WINDOWS\system32\systools.dll --> Suspicion for Keylogger or Trojan DLL
C:\WINDOWS\system32\systools.dll>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
File quarantined succesfully (C:\WINDOWS\system32\systools.dll)
C:\Program Files\Spyware Doctor\smumhook.dll --> Suspicion for Keylogger or Trojan DLL
C:\Program Files\Spyware Doctor\smumhook.dll>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
File quarantined succesfully (C:\Program Files\Spyware Doctor\smumhook.dll)
C:\Program Files\Spyware Doctor\klg.dat --> Suspicion for Keylogger or Trojan DLL
C:\Program Files\Spyware Doctor\klg.dat>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
File quarantined succesfully (C:\Program Files\Spyware Doctor\klg.dat)
C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll --> Suspicion for Keylogger or Trojan DLL
C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll>>> Behavioural analysis 
  1. Reacts to events: mouse
C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll>>> Neural net: file with probability 99.80% like a typical keyboard/mouse events interceptor
File quarantined succesfully (C:\Program Files\Panda Security\Panda Internet Security 2008\pavoepl.dll)
C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll --> Suspicion for Keylogger or Trojan DLL
C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll>>> Behavioural analysis 
 Behaviour typical for keyloggers not detected
File quarantined succesfully (C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll)
Note: Do NOT delete suspicious files, send them for analysis  (see FAQ for more details),  because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious programs
 Checking disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
 >>  Abnormal SCR files association
 >>  Abnormal REG files association
 >>  Service termination timeout is out of admissible values
 >>  HDD autorun are allowed
 >>  Autorun from network drives are allowed
 >>  Removable media autorun are allowed
Checking - complete
Files scanned: 97949, extracted from archives: 78804, malicious software found 0, suspicions - 0
Scanning finished at 6/21/2008 1:34:43 PM
!!! Attention !!! Recovered 10 KiST functions during Anti-Rootkit operation
This may affect execution of several programs, so it is strongly recommended to reboot
Time of scanning: 00:31:43
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
Creating archive of files from Quarantine
Creating archive of files from Quarantine - complete
System Analysis in progress

Script commands
Add commands to script:
Additional operations:
File list